See how Trussed maps to FCA in minutes

    No generic demo, just the controls relevant to your program.

    Book a session
    Financial Services Compliance

    UK FCA AI Governance for Financial Firms: What Regulators Expect

    The FCA has not issued AI-specific rules. It applies its existing technology-neutral, outcomes-based framework, including SM&CR, Consumer Duty, and the SYSC systems-and-controls sourcebook, to AI systems in the same way it applies them to any other technology. Firms are expected to map each AI use case to these existing rule sets, assign senior manager accountability, monitor customer outcomes on an ongoing basis, and evidence governance and risk management practices consistent with themes raised in the joint Bank of England/FCA AI Public-Private Forum.

    In short

    The FCA has not issued AI-specific rules. It applies its existing technology-neutral, outcomes-based framework, including SM&CR, Consumer Duty, and SYSC, to AI systems in the same way it applies them to any other technology. Firms are expected to map each AI use case to these rule sets, assign senior manager accountability, monitor customer outcomes on an ongoing basis, and evidence governance practices consistent with themes raised by the joint Bank of England/FCA AI Public-Private Forum (AIPPF).

    The Financial Conduct Authority has been consistent in its position that artificial intelligence does not require a new, dedicated rulebook. Instead, it applies its existing technology-neutral, outcomes-based framework to AI systems in the same way it applies those rules to any other technology or process a firm might use. For firms, this means the starting point is not "what does the FCA say about AI," but "which existing rule sets does this particular AI use case engage."

    A Technology-Neutral Regulatory Posture

    Because the FCA has not introduced AI-specific rules, firms are expected to identify which established frameworks, principally SM&CR, Consumer Duty, and SYSC, apply to each AI system they deploy, rather than waiting for bespoke AI guidance to arrive. This position is reinforced by the joint Bank of England/FCA AI Public-Private Forum (AIPPF), which has repeatedly highlighted data quality, governance, and model risk management as recurring supervisory themes that extend naturally from existing regulation into AI use cases.

    FrameworkWhat it means for AI systems
    SM&CRSenior managers remain accountable for AI-driven outcomes within their area of responsibility.
    Consumer DutyAI-influenced decisions and communications must meet the same outcome standards as any other process.
    SYSC / PRINAI use cases are governed through existing systems-and-controls and high-level principles, not a dedicated AI rulebook.
    AIPPF ThemesData quality, governance, and model risk management are recurring focus areas for supervisors.

    SM&CR: Senior Manager Accountability for AI Outcomes

    Under the Senior Managers and Certification Regime, accountability for outcomes produced by an AI system sits with the Senior Manager Function holder responsible for the relevant area of the business, not with the technology itself. Firms should be able to identify which SMF holder is accountable for each AI system in use and demonstrate that reasonable steps have been taken to understand and oversee its outputs. In practice, this means maintaining a clear mapping of AI systems to accountable individuals, rather than treating AI oversight as a separate workstream sitting outside the existing accountability structure.

    Consumer Duty and AI-Driven Customer Outcomes

    Where AI systems influence customer-facing decisions or communications, those outcomes must meet the same standards that Consumer Duty imposes on any other business process. Because Consumer Duty is framed as an ongoing obligation rather than a point-in-time compliance exercise, firms need mechanisms to monitor AI-driven customer outcomes continuously, not only at the point an AI system is first deployed. This ongoing monitoring requirement is one of the more operationally demanding aspects of applying Consumer Duty to AI.

    Model Risk Management and Operational Resilience

    Beyond conduct-focused rules, firms are expected to align their use of AI with SYSC systems-and-controls requirements and, where relevant, with the model risk management principles set out in PRA SS1/23, even where a firm is not a dual-regulated bank. Operational resilience considerations also apply: firms should understand the third-party and vendor dependencies that AI tools introduce and maintain oversight and audit mechanisms proportionate to the risk those dependencies present.

    Governance Questions Firms Should Be Able to Answer

    These are the practical questions a supervisor, or an internal audit function, is likely to ask when reviewing how a firm governs its use of AI.

    • Can we map each AI system we use to the specific FCA rule sets it engages, including SM&CR, Consumer Duty, SYSC, and operational resilience?
    • Which Senior Manager Function holder is accountable for outcomes produced by each AI system, and can they evidence reasonable steps taken?
    • How do we monitor AI-driven customer outcomes on an ongoing basis to meet Consumer Duty obligations?
    • Do our model risk management practices align with PRA SS1/23 principles even where we are not a dual-regulated bank?
    • What oversight and audit mechanisms exist for AI tools supplied by third-party vendors?

    Evidencing Controls in Practice

    Meeting FCA expectations in practice requires operational controls that produce evidence, not just policy documents. This includes maintaining an inventory of AI use cases mapped to accountable senior managers, logging decisions and human review points for consumer-facing AI, and preserving audit trails that show ongoing monitoring rather than one-time sign-off.

    Runtime governance and policy enforcement mechanisms, including agent identity, least-privilege permissions, tool approval workflows, and audit logging, help firms generate this evidence continuously as AI systems operate, rather than reconstructing it after the fact. These controls do not replace the governance judgment required under SM&CR or Consumer Duty. They support it by making senior manager oversight and outcomes monitoring demonstrable to a supervisor.

    Turn FCA Governance Expectations Into Operational Evidence

    Trussed AI provides runtime governance and monitoring for AI agents, helping firms maintain audit logs, enforce least-privilege access, and evidence oversight aligned with SM&CR and Consumer Duty obligations.

    Request a Demo