Prepared for: Northbank Trust Company (illustrative) — an independently owned Trust Company, 32 staff, Jersey.
Prepared by: Change AI Consortium
Roadmap horizon: 30 days to a board-signed-off plan, then 90 days to first delivery.
Accountable owner: Head of Risk and Compliance, reporting to the board monthly on progress against this roadmap. AI decisions are not left to individual staff or to IT; one named role holds the plan.
Five opportunities, ranked by priority, each carrying a technical deliverable and a business deliverable, a risk, an impact and an owner.
| Opportunity | Technical deliverable | Business deliverable | Risk | Impact | Owner |
|---|---|---|---|---|---|
| 1. Client onboarding review support | AI-assisted first read of onboarding documents against the firm's own checklist, output reviewed by staff before any decision. | Staff training on how to brief and check the tool, and when to override it. | Medium — document misread could delay onboarding, not cause client harm on its own | High | Head of Client Services |
| 2. Internal policy drafting support | AI-assisted first draft of internal policy updates from regulatory source material, never published without a named sign-off. | A short reviewer's checklist, so a human always checks the draft against the source before it becomes policy. | Low — nothing reaches a client or a regulator unreviewed | Medium | Head of Risk and Compliance |
| 3. Correspondence drafting | AI-assisted first draft of routine, non-client-data correspondence templates. | A style guide so drafts sound like the firm, not like a generic assistant. | Low | Medium | Office Manager |
| 4. Board reporting pack assembly | AI-assisted collation of the monthly board pack from existing internal reports, formatting only, no new analysis generated. | A named reviewer confirms every figure against source before the pack is circulated. | Medium — a wrong figure reaching the board is a real error, caught by the review step | Medium | Company Secretary |
| 5. Client-matter AI use | Deliberately not scoped this phase. No client data, including anything covered by legal professional privilege, goes into an AI tool until the governance and technical controls in section 4 are in place and tested. | A board decision, recorded in minutes, on if and when this phase opens, with named conditions. | High — confidentiality and privilege are the firm's top concern | High | The Board |
Every opportunity in the first four rows keeps AI away from client data and privileged material entirely, and keeps a named human checking the output before it goes anywhere. Client-matter use, the highest-value and highest-risk opportunity, is named and scoped, not started, until the controls below are proven on lower-risk work first. This is a deliberate ordering decision, not caution for its own sake.
1. Purpose. This policy sets out how Northbank Trust Company uses AI tools, so that every member of staff knows what is allowed, what is not, and who to ask.
2. Scope. Covers any AI tool used in the course of work, whether provided by the firm or brought by an individual. Personal AI accounts may not be used for firm business.
3. What AI may be used for. Drafting support on internal, non-client-data material only: policy drafts, internal correspondence templates, report formatting. Every output is reviewed by a named person before it is used or sent.
4. What AI may not be used for. Any client data, any matter covered by legal professional privilege, or any regulated decision, until the board records a specific, minuted decision to open that use, with named controls in place.
5. Approved tools. Only tools on the approved list, held by the Head of Risk and Compliance, may be used. Requests to add a tool go through that role.
6. Ownership. The Head of Risk and Compliance owns this policy, reviews it quarterly, and reports on its use to the board monthly.
7. Breach. A breach of this policy is reported to the Head of Risk and Compliance the same day it is noticed. This is a learning process, not a disciplinary trap, for the first year of use.
Each opportunity in section 2 is reviewed 90 days after it starts against one plain question: is this saving real time, and is the output still being checked properly? An opportunity that fails either test is paused, not quietly continued. This is how the roadmap avoids the most common failure seen across the sector: AI deployed with no clear use case and no way to judge whether it is working.