AI in financial services: control, evidence and regulation

As AI becomes embedded across financial services, TCC explains why governance maturity, not AI capability, is now the limiting factor, and what firms need to prove to regulators about control and accountability.

What happened?

AI has moved quickly from the margins of financial services into everyday operations, shaping how firms detect fraud, onboard customers, assess creditworthiness and interact with clients. Much of this momentum has been driven by commercial opportunity rather than regulation, with faster decisions, lower costs and richer insight prompting firms to move ahead even as questions about risk, data quality and oversight began to surface.

Policy and supervision are now catching up. The UK Government’s AI Opportunities Action Plan signals continued support for innovation, while the FCA has set out in its 2026-27 annual work programme its ambition to become a more data-led regulator, including using AI to support supervision, analyse firm submissions and identify harm.

Adoption is now widespread, as the Treasury Select Committee’s recent inquiry underlines, particularly among larger institutions. What varies far more than adoption is governance maturity, with many firms still relying on control frameworks designed for traditional, rules-based systems.

Why does it matter?

Existing regulatory frameworks, including Consumer Duty, SM&CR and operational resilience, still apply, but the emphasis is shifting towards how firms evidence compliance when decision-making is less visible and outcomes are shaped by systems that evolve over time.

The FCA’s engagement on AI has been deliberate and iterative, including initiatives such as the Mills Review examining whether existing regimes remain fit for purpose, rather than proposing wholesale new rules. Supervisory tools are also evolving, with greater use of testing environments, deeper dialogue with firms and growing focus on systemic technology risk reflected in regimes such as Critical Third Parties.

Who is affected?

This affects any regulated firm using AI in credit assessment, fraud detection, onboarding or client interactions, along with the senior managers and boards accountable under SM&CR for demonstrating oversight of the systems, suppliers and teams involved.

Key risks

  • Mainstream generative AI and large language model tools are effective at text extraction and summarisation, but are not designed to support regulated decision-making.
  • These models can silently resolve conflicts, obscure data lineage, and produce confident-sounding outputs that are incomplete or wrong.
  • Firms often end up increasing human oversight rather than reducing it, spending more time validating outputs and evidencing compliance.
  • Unclear data ownership, inconsistent documentation and fragile oversight models become harder to justify once decisions are made at speed and scale.

Actions to take

  1. Separate the use of generative AI for text extraction and summarisation from purpose-built predictive AI models used for regulated decisions.
  2. Invest in a reliable, explainable and auditable data foundation before scaling AI further.
  3. Strengthen governance, evidencing and operational oversight through advisory input, interim leadership and managed services as needed.
  4. Prepare for closer supervisory engagement, including testing environments and scrutiny under regimes such as Critical Third Parties.

Wider implications

The most difficult challenges rarely appear at the point of adoption; they emerge later, once AI is embedded in business-critical processes, when questions of fairness, oversight and accountability move from policy debate into day-to-day practice.

As Joe Norburn, CEO of TCC Group and Recordsure, has noted, the real question for firms is no longer whether AI can deliver value, but whether they can prove to themselves, their boards and their regulators that it is being used safely, transparently and at scale.

Recommendations

TCC supports firms through a combination of advisory services, interim leadership and managed services: advisory teams help boards and senior managers interpret regulatory expectations and design proportionate AI governance, interim leaders embed compliance and controls during periods of change, and managed services provide human-in-the-loop oversight where judgement and evidencing remain critical.

This is complemented by Recordsure’s AI-driven analytics, built for regulated environments, which operate on trusted, structured data to provide explainable insights, consistent management information and auditable evidence for both regulatory engagement and internal assurance.

Supporting sources

  1. AI in financial services: control, evidence and regulation

Frequently asked questions

What is the Mills Review?

An FCA initiative examining whether existing regulatory regimes remain fit for purpose as AI becomes more deeply embedded in financial services.

Why do generative AI and large language model tools struggle with regulated decisions?

They are not designed to support regulated decision-making and can silently resolve conflicts, obscure data lineage and produce confident but incorrect outputs.

What should firms prioritise to prepare for closer AI scrutiny?

A reliable, explainable and auditable data foundation, along with clearer governance and defensible evidencing mechanisms.

Who commented on AI accountability in the article?

Joe Norburn, CEO of TCC Group and Recordsure.

Ready to strengthen your compliance?

Speak to our experts about your regulatory challenges.