Security & Compliance

FCA and AI: What Compliance Officers Need to Know

|10 min read

The Financial Conduct Authority is not waiting for dedicated AI legislation before setting expectations. Through a combination of discussion papers, feedback statements, and the application of existing regulatory frameworks, the FCA has made clear that firms using AI must demonstrate robust governance, transparency, and accountability. For compliance officers, the challenge is translating these evolving expectations into practical operational frameworks, particularly as AI adoption accelerates across UK financial services.

This article provides a practical overview of the FCA's current position on AI, the key regulatory frameworks that apply, and a step-by-step compliance framework that compliance officers can implement. Whether your firm is exploring AI for the first time or already deploying models in production, understanding the regulatory landscape is essential.

The FCA's Evolving Stance on AI

The FCA first set out its thinking on AI in Discussion Paper DP5/22, "Artificial Intelligence and Machine Learning," published in October 2022. This paper explored the benefits and risks of AI in financial services and invited industry feedback on a range of governance questions. The subsequent Feedback Statement FS2/23, published in 2023, confirmed the FCA's direction of travel: it intends to regulate AI primarily through existing frameworks rather than creating entirely new rules.

This approach has significant implications. It means the FCA expects firms to apply the Senior Managers and Certification Regime (SM&CR), Consumer Duty, operational resilience requirements, and existing systems and controls rules to their AI activities. There is no "AI exemption", if you are using AI to serve customers, manage risk, or make business decisions, the same regulatory standards apply as for any other operational process.

The FCA has also signalled that it views AI risk through the lens of outcomes. It is less concerned with the specific technology and more concerned with whether the outcomes for consumers and markets are fair, transparent, and well-governed. This outcome-focused approach aligns directly with the Consumer Duty framework.

Consumer Duty and AI

The Consumer Duty, which came into full force in July 2023 for open products and services (and July 2024 for closed products), is arguably the most significant regulatory framework affecting AI use in financial services. It requires firms to deliver good outcomes for retail customers across four areas, each of which has direct implications for AI deployment.

Products and Services

Firms must ensure that products and services are designed to meet the needs of the target market and do not cause foreseeable harm. When AI is used in product design - for example, algorithmic pricing of insurance products or AI-driven portfolio construction, the firm must demonstrate that the AI does not create products that are systematically disadvantageous to certain customer groups.

That is a monitoring obligation rather than a testing one. A pricing model that looks fair at launch can develop discriminatory patterns as it learns from new data. How much of that monitoring can be automated, and which judgements have to stay with a person, is the subject of FCA Compliance Automation with AI: What to Automate, What to Keep Human.

Price and Value

The price and value outcome requires firms to ensure that the price a customer pays is reasonable relative to the benefits they receive. AI-driven dynamic pricing introduces particular risks here. If an AI model adjusts prices based on customer characteristics that correlate with protected characteristics, even without directly using those characteristics as inputs, the result could be pricing that the FCA views as delivering poor value to vulnerable customer segments.

Compliance officers should ensure that AI pricing models are subject to regular fair value assessments that specifically analyse outcomes across different customer demographics, including vulnerable customers.

Consumer Understanding

Firms must ensure that communications equip customers to make effective decisions. When AI generates customer-facing content, whether that is marketing copy, product explanations, or advice summaries, the firm is responsible for the accuracy, clarity, and appropriateness of that content. AI hallucinations in customer communications are not a technical curiosity; they are a potential Consumer Duty breach.

Any AI-generated content that reaches customers should pass through validation processes that are at least as rigorous as those applied to human-authored content. In many cases, they should be more rigorous, given the known propensity of large language models to generate plausible but incorrect information.

Consumer Support

The consumer support outcome requires that customers can access support that meets their needs. AI chatbots and automated support tools are increasingly common, but firms must ensure that these tools do not create barriers to effective support. Customers must be able to escalate to a human when the AI cannot resolve their issue. The AI must not provide incorrect guidance that leads to customer detriment. And vulnerable customers must be identified and routed appropriately, something that AI can actually help with if properly implemented.

Operational Resilience and Third-Party Risk

The FCA's operational resilience framework (PS21/3) requires firms to identify their important business services and ensure they can continue to operate within defined impact tolerances during severe but plausible disruptions. AI introduces specific operational resilience considerations that compliance officers must address.

Third-party dependency risk: If your firm relies on a public AI API for a business-critical function, say, real-time fraud detection or client onboarding, that API is a critical third-party dependency. The FCA expects firms to understand and manage the risks associated with such dependencies. What happens if the API goes down? What if the provider changes their terms or pricing? What if they suffer a data breach?

Concentration risk: The FCA has specifically flagged concentration risk in cloud and AI services. If multiple firms in a sector rely on the same small number of AI providers, a disruption at one provider could have systemic implications. Firms should consider diversification strategies and, where possible, reduce dependency on single providers.

Business continuity: Firms must have documented business continuity plans that cover AI service disruption. This means identifying which business processes depend on AI, defining manual fallback procedures for each, testing those fallback procedures regularly, and ensuring staff are trained to operate without AI when necessary.

Deploying AI within your own infrastructure, rather than depending on external APIs - significantly reduces third-party operational resilience risk. When AI runs in your private cloud environment, you control the availability, scaling, and failover mechanisms directly.

Senior Management Accountability Under SM&CR

The Senior Managers and Certification Regime makes individual senior managers personally accountable for the areas of the firm's business within their responsibility. When AI systems make or influence regulated decisions, the question of accountability becomes critical.

The FCA has indicated that AI does not change the fundamental accountability framework, a senior manager cannot delegate accountability to an algorithm. If an AI system produces an outcome that causes customer harm or breaches regulations, the relevant senior manager is accountable for the governance, oversight, and controls that should have prevented that outcome.

Practically, a senior manager does not need the mathematics of transformer architectures. They do need to know what data the system uses, what decisions it influences, what controls sit around it, and what could go wrong. What that evidence pack looks like, and how it holds up in a supervisory conversation, is set out in How an AI Model Audit Works for FCA-Regulated Firms.

Audit Trail Requirements

The FCA expects firms to be able to explain and justify decisions that affect customers. When those decisions are influenced by AI, the firm needs an audit trail that connects the AI's input, processing, and output to the final decision. This is not just a compliance requirement, it is essential for responding to customer complaints, regulatory enquiries, and internal reviews.

In practice that means capturing six things for every material AI-assisted decision: the inputs and where they came from, the model version that produced the output, the raw output before anyone edited it, the human review, the final decision, and the outcome for the customer. The logging standard is set out in full in How an AI Model Audit Works for FCA-Regulated Firms, and the artefacts the FCA, the ICO and your own internal audit will each ask for are covered in Auditable AI Automation: Meeting FCA and ICO Expectations.

All of this is easier when AI runs inside your own infrastructure, where you control logging, retention, and access. Public AI APIs typically provide limited logging that may not meet FCA expectations.

Model Risk Management

While the FCA has not published specific model risk management rules for AI (unlike the PRA's SS1/23 for internal models at larger firms), it expects all firms to apply principles of sound model governance. For AI models used in regulated activities, this means implementing a governance framework that covers the full model lifecycle.

Four disciplines carry that framework: an inventory of every model in use, independent validation before anything is deployed, monitoring that detects drift after it is, and formal change management around any modification, including a prompt change or a foundation-model update. Each is a substantial piece of work in its own right, and we have written up how to run them step by step in How an AI Model Audit Works for FCA-Regulated Firms.

A Practical Compliance Framework

Based on the FCA's expectations and our experience working with regulated firms, here is a practical framework that compliance officers can use to govern AI adoption.

  1. Establish an AI governance committee: Create a cross-functional group including compliance, risk, technology, and business stakeholders to oversee AI strategy and deployment. This committee should report to the board and have clear terms of reference.
  2. Define an AI use policy: Document which AI use cases are permitted, which require additional approval, and which are prohibited. This policy should cover both firm-deployed AI and employee use of external AI tools (shadow AI).
  3. Map AI to SM&CR responsibilities: Every AI system touching a regulated activity needs a named senior manager, with statements of responsibilities updated to say so.
  4. Implement a pre-deployment assessment process: Regulatory impact, Consumer Duty, data protection, operational resilience and model validation, assessed formally before anything goes live. Our guide to GDPR compliance for AI covers the data protection assessment.
  5. Build audit trail infrastructure: Tamper-proof logging of inputs, outputs and decision context, retained for the required period. See Auditable AI Automation: Meeting FCA and ICO Expectations for the artefact list.
  6. Establish ongoing monitoring: Thresholds for accuracy, bias and customer outcomes, with automated alerting when they are breached and re-validation when they stay breached.
  7. Create a consumer outcome testing framework: Assess whether AI-driven processes deliver good outcomes across every customer segment, vulnerable customers included, feeding the Consumer Duty annual review. Which parts of this can sensibly be automated, and which cannot, is the subject of FCA Compliance Automation with AI.
  8. Address third-party AI risk: Due diligence on data security, resilience, concentration risk and exit planning. What to ask a vendor, and the traps in generic compliance products, are covered in AI Software for FCA Compliance. Also consider whether private VPC deployment removes the risk instead of managing it.
  9. Train staff at all levels: Ensure front-line staff understand the AI tools they use and their limitations. Ensure senior managers understand their accountability obligations. Ensure compliance staff can effectively oversee AI governance.
  10. Document everything: Maintain comprehensive records of AI governance decisions, risk assessments, monitoring outcomes, and remediation actions. When the FCA asks "how do you govern AI?" the answer should be a structured body of evidence, not a verbal explanation.

The Case for Private Infrastructure

Many of the compliance challenges outlined above are significantly easier to address when AI models run within your own private cloud infrastructure rather than through public APIs.

You control the logging, so the audit trail is yours to define. There is no dependency on a third party's uptime and no concentration risk from shared infrastructure. Client data never leaves your environment, which removes the sub-processor assessments and the retention questions rather than managing them. And a senior manager who can point at infrastructure the firm controls has a far easier time evidencing the reasonable steps SM&CR asks for.

Our Secure AI Platform deploys leading models inside your own AWS environment with that compliance infrastructure built in.

Looking Ahead: 2026 and Beyond

The regulatory landscape for AI in financial services is expected to evolve significantly over the next twelve to twenty-four months. Several developments are worth monitoring.

The FCA is expected to publish more detailed guidance on AI governance, potentially including specific expectations for model risk management that go beyond current principles-based guidance. The FCA has indicated it is considering thematic reviews of AI use in specific areas, including consumer credit decisioning and wealth management. Firms that have robust governance in place will be well-positioned; those that do not may face supervisory action.

The EU AI Act, which began phased implementation in 2025, will influence UK thinking even post-Brexit. While the UK is not directly subject to the Act, firms serving EU customers will need to comply, and the Act's risk-based classification framework may inform future UK regulation. Financial services AI applications are likely to fall into the "high-risk" category under the Act, triggering requirements for risk management, data governance, transparency, and human oversight.

The Bank of England and PRA are also developing their supervisory approach to AI, particularly for larger firms. The PRA's focus on model risk management (SS1/23) is likely to expand to cover AI models more explicitly, and dual-regulated firms should prepare for aligned but potentially distinct requirements from both the FCA and PRA.

Additionally, the Digital Regulation Cooperation Forum (DRCF), which brings together the FCA, ICO, CMA, and Ofcom, is developing coordinated approaches to AI oversight. This means firms should expect consistent regulatory themes around transparency, accountability, and consumer protection across multiple regulators.

"The firms that invest in AI governance now are not just managing regulatory risk, they are building the operational foundations that will allow them to adopt AI confidently and at pace as the technology evolves. Governance is not a brake on innovation; it is what makes sustainable innovation possible."

Getting Started

If you are a compliance officer grappling with AI governance, the most important step is to start with visibility. You cannot govern what you cannot see. Conduct an audit of all AI usage across your firm, including unofficial use of public AI tools by employees, and map each use case against the framework outlined above.

From there, prioritise the highest-risk use cases (those that directly affect customer outcomes or involve sensitive data) and build out your governance framework incrementally. Perfection is not required from day one, but evidence of a structured, documented approach to AI governance is what the FCA will look for.

Go Deeper: Practical Guides for FCA-Regulated AI

This overview sets the regulatory frame. The guides below go deeper on the specific questions compliance and operations teams ask most often when they move from policy to implementation:

We work with FCA-regulated firms across wealth management, insurance, and financial advice to design and implement AI governance frameworks and secure deployment infrastructure. Whether you need help with strategy, architecture, or implementation, our team understands the intersection of AI technology and financial regulation. Get in touch to discuss your firm's needs, or browse our full range of services to see how we can help.

Ready to transform your business with AI?

Book a free initial alignment call to discuss how Evolve AI can help your organisation harness AI safely and compliantly.

Book Strategy Session