Insights · 2026-07-10
Family office data and AI: keeping owner wealth inside the boundary
A family office or private holding group runs several legal entities under one owner with one back office. The books are not ordinary corporate data: they are the owner's private affairs in double-entry form — wealth, related-party flows, family arrangements that are nobody else's business. That is why the finance team's quiet veto kills most AI proposals: the data cannot go to someone else's cloud.
The veto is correct. The mistake is concluding that AI is therefore off the table.
The boundary is the design constraint
Start from the constraint instead of fighting it: whatever the system does, the books, the analysis, and the model stay inside infrastructure the family controls. Access is purpose-based and role-based. Nothing trains on the data. Nothing phones home.
Inside that boundary, the useful work is the unglamorous kind — normalising several ledgers into one store, running deterministic checks across entities, preparing the pre-close review the small team never has time to do properly. Multi-entity groups feel this hardest: consolidations and intercompany flows are exactly where manual review runs out of hours.
Small team, high stakes
The typical family office finance function is a handful of people carrying work that would occupy a department in a listed company. The case for AI here is not headcount replacement — there is no headcount to replace. It is coverage: checks that now run across every entity and every period, instead of wherever the team's limited review hours landed.
The controller still dispositions every exception. What changes is how much of the ledger actually gets looked at.
What to insist on
Deployment inside your own environment. Read-only access to the books. Every figure traceable to source rows. A named human approving anything that matters, and an audit trail a reviewer can inspect. If a vendor hesitates on any of these, the hesitation is the answer.