Is AI FCA compliant for UK financial services?
Yes — AI is FCA compliant for UK financial services when the firm can evidence three things: model governance under existing frameworks (SS1/23-style expectations, SYSC obligations), SMCR accountability for the senior manager responsible for the AI system, and Consumer Duty outcomes with a full audit trail. The FCA has repeatedly signalled a technology-neutral, outcomes-based stance; the compliance burden is on how you deploy AI, not on whether you can.
Yes — AI is FCA compliant for UK financial services when the firm can evidence three things: model governance under existing frameworks (SS1/23-style expectations, SYSC obligations), SMCR accountability for the senior manager responsible for the AI system, and Consumer Duty outcomes with a full audit trail. The FCA has repeatedly signalled a technology-neutral, outcomes-based stance; the compliance burden is on how you deploy AI, not on whether you can.
The FCA's stated position (in plain English)
The FCA has been consistent since its 2022 Discussion Paper (DP5/22 with the Bank of England and PRA) and its 2024 AI Update: it does not intend to introduce AI-specific rules for regulated firms in the near term. Its position is that existing frameworks — SYSC, SMCR, Consumer Duty, operational resilience, third-party risk — already require firms to govern AI properly, and the FCA will supervise on those existing hooks.
This is the opposite of a permissive stance. It means the FCA expects firms to work out how existing rules apply to AI, apply them properly and evidence the whole thing. A firm that treats AI as "just a black-box vendor tool" and skips the model-governance work is a firm that will fail a Section 166 review.
The four compliance surfaces every AI system must satisfy
- Model governance — Documented model risk framework covering intended use, training data, evaluation, monitoring, drift detection, human-in-the-loop controls and decommissioning. PRA SS1/23 sets the reference expectation; even non-PRA-regulated firms are increasingly held to a similar bar.
- SMCR accountability — A named senior manager (typically SMF16, SMF24 or SMF17 depending on function) explicitly accountable for the AI system, with the certification-regime staff who operate it identified and trained. The regulator wants to know exactly whose head is on the block.
- Consumer Duty — For any AI system that affects retail customer outcomes, evidence of the four outcomes (products & services, price & value, consumer understanding, consumer support) and demonstrable good outcomes across the customer base — not just individual cases.
- Operational resilience & third-party risk — AI systems are important business services under PS21/3 / PS6/24. Firms need mapped dependencies, tested tolerances, and third-party (vendor / cloud / model provider) risk assessments with exit plans.
Consumer Duty is the sharpest test
For any AI system touching retail customers, Consumer Duty is where compliance debates end up. The four outcomes require evidence: not just "the AI performed well on average" but "the AI produced good outcomes across the customer base, including for vulnerable customers, and where it produced poor outcomes we identified and remediated them".
A firm-owned AI system with a full audit trail is materially easier to defend under Consumer Duty than a black-box vendor tool. Firms should be able to answer, for any customer decision the AI proposed: what inputs did the model see, what was its proposed output, was there human sign-off, what was the actual outcome, and is that outcome consistent with good outcomes for that customer segment.
What a compliant firm-owned AI system looks like in practice
The pattern in production at compliant UK firms: firm-owned model governance framework (documented, versioned, reviewed quarterly), explicit SMCR mapping of every AI system to a named senior manager, human-in-the-loop for every retail-customer-affecting decision, full provenance from AI proposal back to source data, and monitored outcomes with automated drift detection and pre-agreed remediation triggers.
None of this is exotic. It is what serious firms already do for material models under SS1/23 and for any process that affects customer outcomes under Consumer Duty. Applying the same standard to AI systems is what makes them compliant.
FCA AI compliance: what evidence you need
| Surface | What the FCA expects | What good looks like |
|---|---|---|
| Model governance | Documented framework, evaluation, monitoring | SS1/23-style artefacts per model; quarterly reviews |
| SMCR accountability | Named senior manager per AI system | Explicit mapping in the Responsibilities Map |
| Consumer Duty | Evidence of good outcomes across segments | Firm-owned outcome monitoring with drift detection |
| Provenance / audit | Traceable decisions | Every AI proposal linked to source data + human sign-off |
| Operational resilience | Mapped dependencies, tested tolerances | AI systems in Important Business Services list |
| Third-party risk | Vendor + cloud + model provider assessments | Exit plans; concentration risk explicitly measured |
None of this is AI-specific — it is the existing FCA regime applied properly to AI systems.
How to build this in production
- 01
Map every AI system to an SMCR senior manager
Explicit accountability in the Responsibilities Map. Certification-regime staff who operate the system identified and trained.
- 02
Adopt a documented model governance framework
SS1/23-style artefacts per model: intended use, training data, evaluation, monitoring, drift detection, human-in-the-loop controls, decommissioning.
- 03
Bake provenance and audit into the system from day one
Every AI proposal linked to source data; every human sign-off captured with rationale; every model version logged.
- 04
Add Consumer Duty outcome monitoring
For any retail-affecting AI system: track outcomes across customer segments including vulnerable customers; pre-agreed remediation triggers on drift.
- 05
Include AI in operational resilience and third-party risk
Add AI systems to the Important Business Services list; test tolerances; assess model / cloud / vendor providers with exit plans.
Related questions
Has the FCA banned AI in any specific use case?
No. The FCA has not banned AI in any specific regulated activity. Its stance is technology-neutral: existing rules apply, and firms are expected to evidence how they meet them.
Do we need FCA pre-approval to deploy an AI system?
No, there is no AI-specific pre-approval regime for authorised firms. However, material AI systems in credit decisions, KYC / AML, or retail customer outcomes should be raised with your supervisor as a matter of course and are likely to be scoped into any Section 166 review.
How does Consumer Duty affect AI deployment?
For any AI system touching retail customers, Consumer Duty requires evidence of good outcomes across the customer base — not just aggregate performance. Firm-owned AI systems with full provenance and outcome monitoring are materially easier to defend than vendor black boxes.
Is using ChatGPT or Claude for regulated work compliant?
For internal drafting, research and non-customer-affecting workflows, using frontier AI through a governed enterprise route (with retention off, data-processing agreements in place, and audit) is acceptable. For customer-affecting decisions, firms should use a firm-owned, evaluated system with human sign-off — not ad-hoc consumer AI tools.
What about the EU AI Act if we operate in both UK and EU?
The EU AI Act adds a separate compliance surface for EU customers and staff, including high-risk classifications for credit scoring and biometric identification. UK firms operating in the EU need to comply with both regimes. The good news: a firm-owned AI system with proper governance typically satisfies both.
AI is FCA compliant when deployed with the same governance discipline the FCA expects across the rest of a firm's regulated activity. Firms that treat AI as a governance-lite shortcut will get a Section 166 review; firms that treat AI as a first-class regulated system will find the compliance surface entirely manageable.
If you want a firm-specific view of your AI compliance posture, start with the £15,000 Financial AI Blueprint — it includes an explicit compliance workstream tailored to your regulatory perimeter.