Skip to content
McCullochRegulatory Compliance

Firm policy

Responsible Use of Artificial Intelligence

MRC advises organisations on AI governance and the EU AI Act. We hold our own use of artificial intelligence to the standard we set for the organisations we advise. These are the principles that govern it.

EU AI Act Art 14 · ISO/IEC 42001

Human accountability and oversight

A named individual is accountable for every output that AI assists. Artificial intelligence supports professional judgement; it does not replace it, and no client deliverable is issued without human review.

EU AI Act Art 50

Transparency

We are open about where AI materially assists our work. Analytical outputs produced with AI assistance are identified as such, to clients and, where relevant, to the authorities that review them.

EU AI Act risk management · ISO/IEC 42001

Fairness and reliability

AI-assisted analysis is checked for bias, error, and robustness before it informs a decision. The limitations of a model are treated as part of the analysis rather than an afterthought.

UK GDPR · EU GDPR

Data protection and confidentiality

Client, safety, and personal data are never entered into consumer or open AI tools. We use only approved tools under appropriate contractual and security terms, consistent with the UK and EU GDPR.

Approved tools and data handling

We maintain a list of approved AI tools and the terms on which each may be used. Personal data, client-confidential material, and regulated safety data are handled only within approved, contractually-governed environments. Where a tool is not approved, or where the data is sensitive, the matter is escalated before any use.

How we use AI in our work

Where AI assists our work, it does so under these principles. Our safety-data analytics, for example, are developed in line with the EU AI Act and applicable data-protection law, keeping the models that support safety decisions governed and defensible. In every case, a qualified adviser remains responsible for the result.

Governance

These principles are owned by the firm's principal, reviewed at least annually, and reaffirmed by anyone acting on the firm's behalf. Last reviewed September 2026.

We help clients build the same framework

The principles above are the standard we apply to ourselves. We put the same governance in place for the organisations we advise, mapped to the EU AI Act, data protection law, and recognised standards.