What FCA AI Governance Already Requires
The UK regulates AI by sector, not by single statute. There is no separate "AI Act" for financial services to wait for, and that absence is often misread as a gap.
It is not a gap. The FCA and PRA apply frameworks you already operate under to your AI systems. FCA AI governance is the existing rulebook, pointed at a new kind of system.
Four frameworks do most of the work. Model risk management expectations cover how models are built, validated, and controlled. Operational resilience covers whether the service holds up. The Senior Managers and Certification Regime covers who is accountable. Consumer Duty covers outcomes for the customer.
If you run AI in a regulated UK firm, those four already apply. The question a supervisor asks is not whether you have a policy. It is whether you can show the controls worked.
SMCR Makes AI Accountability a Named Human
The Senior Managers and Certification Regime is the part most firms underweight. It attaches responsibility for outcomes to a specific person, not a working group.
That means high-risk AI systems need to map to a named Senior Manager whose prescribed responsibilities already cover the outputs. Illustratively, that might be SMF24 for operational resilience, SMF16 for compliance oversight, or SMF4 for risk. Treat these as accountability anchors to discuss with your legal team, not as legal advice.
The practical test is simple. If an AI-driven decision goes wrong, can you name the accountable person, and can that person produce evidence the system was controlled? UK bank AI governance lives or dies on that second half.
This is also where many programmes quietly fail. The accountability is documented, the runtime evidence is not, and the named individual is exposed.
The Consortium Is a Year Out. The Expectation Is Now.
On 8 June 2026, DSIT sized the UK AI assurance market at £1.01bn today, rising to £18.8bn by 2035, and launched the BCS-led AI Assurance Stakeholder Consortium to develop standards.
That work matters for the long term. But the consortium's standards are roughly a year away, and the FCA expectation is not. It applies now.
So firms cannot park AI assurance until the consortium reports. For the broader picture of how UK supervisory expectations sit against the EU regime, see our overview of UK AI assurance and our comparison of the UK and EU approaches.
What UK FS Firms Must Evidence Today
FCA AI expectations resolve into three things you must be able to show, on demand, per system. This is the evidence bar.
Tested before launch. Adversarial testing, prompt injection attempts, tool misuse cases, and a recorded threshold sign-off before the system reaches production. Our Test & Detect pillar covers this stage.
Monitored and enforced in production. Inline policy enforcement at the inference layer, drift detection, and a working escalation path when behaviour moves outside agreed limits. That is the job of Protect & Enforce.
Reconstructable on request. Continuous, time-stamped, attributable evidence that a supervisor can read after an incident. Prove & Comply produces this record across the full AI assurance lifecycle.
A signed policy sitting in a risk register is not proof of any of this.
Two Failure Modes Supervisors Will Spot
The first is PowerPoint Governance: a control framework that lives in a slide deck and a risk register, with no runtime evidence that any control actually fired. It reviews well and proves nothing.
The second is Agentic Theatre: an agent that performs cleanly in a demo, then meets uncurated production inputs with controls that were never enforced at runtime. The gap between the demo and the live system is exactly where incidents start.
Both pass a documentation review. Neither survives an incident review, which is the one that counts.
How Disseqt Maps FCA Accountability to Evidence
Disseqt is built to close the gap between named accountability and provable control. It maps FCA and SMCR responsibilities to three working pillars: Test & Detect. Protect & Enforce. Prove & Comply.
From one unified platform, you produce audit-ready AI evidence on demand, broken down by model version, workflow, input, and the policy that applied. When a supervisor asks what happened, you reconstruct it rather than reconstruct around it.
For financial services AI assurance specifically, that means the named Senior Manager can stand behind a system because the evidence stands behind them. See how this maps to your sector on our financial services page, and for sequencing the work, the UK AI assurance readiness playbook.
Bottom Line
UK financial services firms do not have the luxury of waiting for a new statute or a consortium standard. The FCA already expects AI that is tested before launch, controlled in production, and reconstructable after the fact, with a named human accountable throughout.
The firms that handle this well treat assurance as evidence, not paperwork. Disseqt is the Assurance Layer for Enterprise AI Operations, and it produces that evidence on demand.
FAQs
Is there a specific FCA AI regulation UK firms must follow?
No single AI statute. The FCA applies existing frameworks to AI, including model risk management, operational resilience, SMCR, and Consumer Duty. Those expectations are already live for financial services firms running AI.
Who is accountable for AI under SMCR?
A named Senior Manager, not a committee. Firms should map high-risk AI systems to the Senior Management Function whose prescribed responsibilities cover the outputs. The illustrative anchors are SMF24, SMF16, and SMF4, which you should confirm with your legal and compliance teams.
What counts as audit-ready AI evidence for the FCA?
Continuous, time-stamped, attributable records that show a system was tested before launch, monitored and enforced in production, and can be reconstructed on request. A signed policy document alone does not meet this bar.
Should we wait for the new UK AI assurance consortium standards?
No. The BCS-led consortium launched in June 2026 and its standards are roughly a year out. FCA AI expectations apply now, so financial services firms need to evidence assurance today rather than wait for the consortium timeline.
How does Disseqt support FCA AI governance?
Disseqt maps FCA and SMCR accountability to three pillars, Test & Detect, Protect & Enforce, and Prove & Comply, and produces audit-ready evidence on demand by model version, workflow, input, and policy from one unified platform.




