The UK Financial Conduct Authority (FCA) alongside the Bank of England’s Prudential Regulation Authority (PRA) have issued comprehensive supervisory guidance enforcing strict governance, model risk management, and executive personal accountability for artificial intelligence across the financial services sector.
Executive accountability under the Senior Managers Regime (SM&CR)
Under the strengthened framework, the deployment of machine learning algorithms, automated underwriting, and generative customer assistants cannot operate within regulatory ambiguity:
- Named Senior Manager responsibility: Regulated firms must allocate formal statutory responsibility for AI governance to an approved Senior Management Function (SMF). Senior executives face direct disciplinary sanctions and personal enforcement action if deployed models produce unlawful bias, deceptive marketing, or unverified hallucinations.
- Consumer Duty enforcement: Under the overarching Consumer Duty, financial institutions must actively prove that AI systems provide fair value and prevent foreseeable harm. Automated credit scoring or insurance pricing tools that unfairly disadvantage protected consumer groups will be treated as systemic regulatory breaches.
- Mandatory Model Risk Management (SS1/23): PRA Supervisory Statement SS1/23 on Model Risk Management is strictly extended to all machine learning and generative pipelines. Firms must maintain an unbroken inventory of models, conduct rigorous independent pre-deployment testing, and continuously monitor for concept drift.
Practical obligations for financial institutions and legal teams
Regulated entities deploying AI customer interactions or analytical engines must immediately implement the following protocols:
- Algorithmic audit trails and explainability: Financial institutions must maintain transparent documentation justifying the technical parameters and data inputs of every model impacting consumer outcomes or credit eligibility.
- Testing through the FCA AI Lab: Firms introducing novel agentic AI workflows are encouraged to utilize sandbox facilities and regulatory testing environments to validate consumer protections before public rollout.
- Third-party vendor due diligence: Relying on third-party foundational model providers does not discharge the regulated firm’s legal obligations; firms must retain comprehensive contractual oversight and robust disaster recovery fallbacks.
