AI governance and adoption in UK financial services
UK regulators have taken an outcomes-based approach to AI: there is no separate AI rulebook, so existing obligations do the work. Consumer Duty, governance accountability, model risk management and operational resilience all bite on AI deployments, depending on the firm's permissions and how it uses AI. This hub explains how firms evidence that.
Who regulates this: FCA, PRA, Bank of England, ICO
Last reviewed: 18 August 2026
Where the risk sits
Consumer Duty and fair outcomes
AI used in pricing, marketing, servicing or collections must produce good outcomes for retail customers, including vulnerable ones, and the firm must be able to evidence that with outcomes monitoring, where Consumer Duty applies to the business.
Model risk management
Models that inform material decisions need inventory, validation, performance monitoring and documented limitations, particularly at PRA-regulated firms in scope of model risk expectations. Generative models are harder to validate and often lack stable behaviour across versions.
Governance accountability for AI-driven processes
Where the Senior Managers and Certification Regime applies to a firm, a senior manager holds accountability for the business area an AI system supports, as part of their existing responsibilities — this is not a separate AI-specific duty, and its scope depends on the firm's SM&CR status. Diffuse ownership between technology, risk and the business is a common gap regardless.
Third-party and operational resilience
Reliance on a small number of model providers concentrates risk. Firms in scope of operational resilience rules need exit plans, impact tolerances and evidence that important business services survive a provider outage.
Controls that make a rollout defensible
- AI and model inventory mapped to important business services and accountable owners
- Pre-deployment validation plus ongoing monitoring for drift and disparate outcomes
- Consumer Duty outcomes testing on any customer-facing AI decisioning, where the Duty applies
- Documented exit and fallback plan for each model provider
- Audit trail of prompts, outputs and human overrides for regulated decisions
This page is guidance, not legal, clinical, financial or other professional advice. It is general information about UK regulatory context and does not account for your specific circumstances. Take professional advice before acting. See our editorial policy.
Sources
Frequently asked questions
Does the FCA require approval before using AI?
There is no separate AI approval regime. Firms apply existing rules — governance, consumer outcomes, model risk and resilience — and must be able to demonstrate compliance on request.
Can generative AI be used in customer communications?
Yes, with review. Communications must be clear, fair and not misleading, so most firms keep human sign-off on any output that reaches a customer.