How do FCA and CySEC brokers make their AI systems compliant?
FCA and CySEC brokers make AI systems compliant by building on a three-layer architecture — policy, retrieval, evals — with the compliance envelope designed first, not retrofitted. Every AI-touched customer surface (marketing, retention, onboarding, comms) must map to a specific control, and every automated decision must produce an audit-loggable reasoning chain. The pattern survives supervision better than manual processes.
FCA and CySEC brokers make AI systems compliant by building on a three-layer architecture — policy, retrieval, evals — with the compliance envelope designed first, not retrofitted. Every AI-touched customer surface (marketing, retention, onboarding, comms) must map to a specific control, and every automated decision must produce an audit-loggable reasoning chain. The pattern survives supervision better than manual processes.
Compliance is architecture, not review
The most common failure mode we see is treating compliance as a review gate at the end. That is where AI pilots die. Compliance survives when it is architecture — a policy layer defining what the AI is allowed to do, retrieval scoped to approved sources, and evals continuously proving the system stays within the envelope.
Related questions
Does the FCA have specific AI rules?
Not a standalone AI rulebook. Consumer Duty, SM&CR, financial-promotion regs, model risk management principles and vulnerable-customer standards all apply. The three-layer architecture maps to all of them by construction.
CySEC-specific expectations?
Governance and audit-trail depth, particularly around client-facing automation. The same architecture applies.
SMF ownership of AI?
Named SMF holder responsible per system, documented in the policy layer.
How is this different from manual?
Stronger audit trail, faster to evidence, easier to sign off on new automations once the envelope is in place.
How does the £15k Diagnostic address this?
The Diagnostic includes a control-mapping artefact against your regulator that becomes the foundation for the build.
Compliance-safe AI is not slower AI. It is faster, because once the envelope is in place, new automations ship in weeks not quarters.
The £15k AI Diagnostic produces the control map and the costed build plan.