Raffles Consulting Services

Family office agentic AI approval and data controls

Family office agentic AI controls should limit data access, require approval for high-impact actions and preserve a reviewable activity trail.

Family office agentic AI controls should be set before an AI system can read confidential records or act through email, banking, portfolio, legal or administrative tools. Start with a narrow task, restrict the data and actions available, require human approval for high-impact steps and keep logs that an independent reviewer can understand.

An assistant that only drafts a meeting summary presents a different risk from an agent that can send instructions, change records or initiate a payment workflow. The control design should follow the capability and possible harm, not the product’s marketing label.

Map every family office agentic AI workflow

The IMDA Model AI Governance Framework for Agentic AI, published on 22 January 2026, addresses systems that can reason, plan and take actions with greater independence. It emphasises meaningful human accountability, bounded autonomy, secure deployment and transparent interaction.

For this reason, list each proposed workflow from input to final action. Show the user, agent, model, data source, tool, external party and system changed. Record whether the agent can only recommend, can prepare an action for approval or can execute without another person.

Include hidden dependencies. A calendar agent may also read email. A document agent may reach a cloud drive containing passports, wills and shareholder records. A portfolio agent may call a market-data service and then write to an investment system. The workflow map should expose those connections.

Classify harm before deciding autonomy

Rate each action by confidentiality, financial effect, legal effect, reversibility and impact on a person. Sending a draft to an internal reviewer is usually easier to reverse than transmitting instructions to a bank or external counsel.

In practice, reserve high-impact actions for human approval. Examples include payments, trades, changes to beneficiaries, release of personal data, acceptance of legal terms, regulatory filings and deletion of records. The approver should see the source information, proposed action and material uncertainty before confirming.

The Singapore Government and Google AI Agents Sandbox findings identify human oversight, customisation, cybersecurity and privacy as common risk themes. They note that higher-risk actions may need pre-approval, while reversible lower-risk actions may permit later review.

Limit data to the task

Create an approved data catalogue for each workflow. State which folders, record types and fields the agent may read, which it may write and what it must never access. Use separate environments for public research, internal operations and highly confidential family or identity data.

At the same time, do not place a general AI account across the whole document repository. Use role-based access, time-limited credentials and service accounts dedicated to the workflow. Remove unused connectors and test whether inherited folder permissions expose more information than intended.

Redact or tokenise sensitive fields when the full value is unnecessary. A scheduling task may need availability but not passport copies. A spending summary may need categories and amounts but not banking credentials. Keep prompts and outputs under the same retention and access policy as the source data they contain.

Control tools and external instructions

An agent can be manipulated by content it reads. A message, webpage or document may contain instructions that conflict with the user’s task. Treat external content as data and prevent it from changing system rules, permissions or approval requirements.

As a result, allow only named tools, actions and destinations. Use amount limits, recipient allow-lists, read-only modes and transaction previews. Require a second person for changes involving money, ownership, access rights or legal commitments.

The CSA Guidelines on Securing AI Systems call for security across the AI lifecycle. Apply ordinary security controls as well: supplier due diligence, patching, multi-factor authentication, secrets management, monitoring, backup and incident response.

Test before using live family data

Build a test set with ordinary cases, ambiguous requests, malicious instructions, missing data and requests outside authority. Include similar names, unusual currencies, changed bank details and documents containing hidden or conflicting instructions.

For example, measure whether the agent refuses prohibited actions, asks for approval at the right point, identifies uncertainty and produces an accurate log. Test failure recovery. An agent that stops halfway should not leave an external message sent and an internal record unchanged.

Use synthetic or authorised test information first. Move to limited live data only after the owner accepts the residual risk. Increase autonomy gradually and require a new review when the model, tools, permissions or workflow changes.

Control Evidence Failure to test
Workflow boundary Approved map of data, tools and actions Agent reaches an unapproved system
Human approval Action preview and approver log High-impact action executes without review
Data access Permission matrix and access test Confidential file is visible unnecessarily
Instruction security Adversarial test results External text changes the agent’s task
Recovery Rollback and incident exercise Partial action cannot be reconciled

Make accountability visible

Name a business owner, technical owner, data owner and final approver for each workflow. The family council or board should know who can pause the system and who decides whether an incident must be escalated.

In addition, keep logs of user requests, retrieved sources, tool calls, approvals, changes and final outcomes. Protect the logs from alteration and limit access because they may contain the same sensitive information as the underlying task.

Tell staff and affected service providers when they are interacting with an AI-supported process where that matters to their decisions. Create a channel for correcting an output and a method to trace which downstream records need repair.

Review suppliers and contracts

Ask the provider where data is processed, whether prompts or outputs train shared models, how subcontractors are used, how access is logged, what retention applies and how data is deleted. Confirm incident notification, audit rights, service continuity and export arrangements.

For this reason, contract terms should match the technical settings. A promise not to train on customer data is not enough if an administrator can enable a conflicting feature. Preserve configuration evidence and review it after product updates.

The family office governance guide is the pillar cornerstone. The ransomware recovery guide covers restoration, and the payment verification guide covers high-risk instructions. The Family Office and UHNW Advisory hub connects the library.

A useful agent should make a defined task easier without gaining a vague mandate over the family office. If the team cannot show its data boundary, approval point and activity trail, the system is not ready for confidential or high-impact work.