For FCA-authorised firms

Your teams are using AI. SM&CR assumes a Senior Manager has taken reasonable steps.

Under the Senior Managers & Certification Regime, a named individual is personally accountable for the risks in their area of responsibility. If AI is in the firm and nobody has mapped where it lives or what it touches, no reasonable steps have been taken — and the accountability is personal, not corporate. We fix that by mapping your AI usage and giving you a risk register within 30 days (max), before your next board report.

Book a 20-minute callFixed price · Delivered before your next board report

The duty you already have

You don’t need an AI rulebook for AI to be an accountability problem.

The FCA has said, repeatedly, that it will not write one. In early December 2025 Nikhil Rathi reaffirmed that the regulator will not introduce AI-specific rules, citing a technology that changes every three to six months. AI is governed through the frameworks you’re already subject to — SM&CR, the Consumer Duty, SYSC, and operational resilience. That sounds permissive. It is the opposite: the duty already bites, and nobody had to add a question to make it.

Reasonable steps are required

A Senior Manager must be able to demonstrate the steps taken to control their area effectively. Failure to enquire is not a defence — it is the breach. If AI risk sits in your area and you can't show where AI is, you can't show the steps.

Duty of Responsibility, FSMA 2000 s66A

AI is the thing nobody registered

It arrives inside software the firm already licenses — the research platform, the OMS, the CRM, the comms suite — and inside copilots individual staff switch on. Nobody logged it, nobody approved it, in the worst case nobody has asked. That is precisely the circumstance you ought to know.

Shadow AI

And the pressure is rising, not easing

In January 2026 the Treasury Committee criticised the regulators’ "wait-and-see" approach and recommended the FCA publish practical guidance on AI accountability and assurance by the end of 2026. The Mills Review reports to the FCA Board this summer. The direction of travel is one way.

Treasury Committee report, 20 January 2026

What you’re already attesting to

The questions are already in your governance documents. AI is what makes them hard to answer.

These aren’t new obligations. They’re the attestations, registers and board reports you already produce — and every one of them gets more uncomfortable once you accept that AI is in the firm and nobody has mapped where.

Statement of Responsibilities

Does any SMF's SoR allocate responsibility for AI use across the firm?

If AI risk isn't anyone's, whose reasonable steps are being tested when it goes wrong?

Risk management framework · SYSC

You attest that your risk framework is adequate. Does it name AI as a risk anywhere?

A framework can't be adequate to a risk it doesn't recognise.

Consumer Duty board report

For any retail-facing line: can you evidence that AI-assisted communications, research or client outputs deliver good outcomes and avoid foreseeable harm?

The board signs this once a year, and a named champion stands behind it.

Operational resilience self-assessment

Your impact tolerances assume you know where each important business service actually runs. Is AI embedded in one through a third party you haven’t mapped?

The FCA's March 2026 wholesale buy-side priorities flagged exactly this concentration risk on the buy side.

Outsourcing & third-party controls · SYSC 8

The model inside your OMS or research tool is a third party shaping decisions. Have you assessed it as one?

Or has it entered the firm without ever passing through your outsourcing controls?

Compliance monitoring programme

Does your monitoring plan test AI-assisted work at all?

A control you don't monitor is a control you can't evidence — and an answer you can't stand behind.

Phase one

AI Exposure Review

The reasonable steps, done properly. Know exactly where AI lives in the firm, what’s yours to govern, where the gaps are, and what closing them will involve. Two to four weeks. Fixed price. You keep the artefacts whether or not you go further.

AI footprint map

The enquiry, evidenced

One map per desk or function — front office, research, operations, distribution — consolidated into a single firm-wide view: where AI is used, in which processes, by whom, against which data and which clients. Including the tools nobody flagged.

AI systems register

Your single source of truth

The operational inventory of every AI system in the firm, with a named owner against each. The document your Compliance Oversight SMF points to, and the authorised-tools list your AI policy refers back to.

Gap list against SM&CR, Consumer Duty & operational-resilience expectations

What's missing, and what it exposes

Where the firm currently falls short on documented oversight, third-party assessment, data handling and the attestations you're already making — prioritised, with the exposure named plainly and mapped to the accountable SMF.

Costed plan for closing the gaps

Makes the next decision concrete

A fixed-price, evidence-based scope for the governance build, so the bigger decision is a known quantity rather than open-ended fees.

Duration
Two to four weeks
Price
Fixed, scaled to firm size and AUM
Guarantee
Artefacts delivered before your next board report, or you don’t pay
If you proceed
Fee credited against the build

Phase two · optional

Then: the build, and the training.

Phase one tells you what’s actually there. Phase two puts the governance in place — aligned with ISO/IEC 42001, without the weight or cost of a certification programme.

AI Governance Build

The policies, controls, records and evidence that let your Compliance Oversight SMF answer the FCA — and let you stand behind the attestations you already make.

  • SM&CR-aligned AI policy and authorised-tools list
  • Integrated risk register (AI × Consumer Duty × data protection)
  • Documented human-oversight and review controls, mapped to the accountable SMF
  • Third-party AI assessment fit for your SYSC 8 and operational-resilience files
  • Evidence pack for the board report and for an FCA thematic review

Front-office and operations training

Practical and role-level, not a compliance lecture — because the risk is a portfolio manager pasting a deal memo into a public model at nine in the evening.

  • What the approved tools are, and how to use them
  • Confidentiality, MNPI and inside information — what never leaves the firm
  • AI-assisted research and the duty not to mislead clients or the market
  • Attendance records you can evidence

Honest fit

Who this is for — and who it isn’t.

A good fit if

  • You’re FCA-authorised — asset manager, AIFM, fund ManCo or small MiFID firm, roughly up to 50 staff
  • You have no in-house risk or compliance function doing this actively
  • Your teams are using AI — with or without a policy
  • Nobody has formally mapped where, or written it down
  • An SMF is about to attest to something that touches it

Not a good fit if

  • You have a mature second line already running this
  • You’ve already mapped and registered your AI use
  • You want full ISO 42001 certification now — different engagement
  • You want a policy document with nothing behind it

Who you’d be working with

We don’t sell paperwork.

A policy that claims a control you don’t run is worse than none. Under SM&CR that isn’t a documentation problem — it’s an accountability one, and it sits with a named person. Everything we build is real, evidenced, and defensible.

Certified ISO/IEC 42001

Standards

Committee member, BSI & ISO technical committees

Delivery

Regulated, sensitive-data environments

Questions

What compliance leads ask us.

There's no AI question in our compliance monitoring plan.

There may not be. The reasonable-steps duty doesn't need one. Your SoR already allocates responsibility for the risks in your area, your risk framework already has to be adequate, and your board report already has to stand up. AI doesn't need its own line to make those harder to answer.

The FCA hasn't written AI rules. Why now?

Because it has said it won’t — and that’s the point. In December 2025 the FCA confirmed AI sits inside Consumer Duty, SM&CR, SYSC and operational resilience. The consequence doesn’t land on a premium; it lands on a Senior Manager’s practising approval. A "no new rules" position doesn’t reduce the exposure. It relocates it onto you.

We already have an AI policy.

Then you're ahead of most firms. The harder question is whether the policy matches what your desks actually do. A policy that doesn't reflect real usage is a written statement you can be measured against — and it isn't the reasonable steps either, because it describes what should happen rather than what does.

We handle this in-house.

Plenty of firms can, and if your second line is actively doing it, you don't need us. Where we earn our place is doing the initial search and build quickly, in the form the FCA expects, so your people stay on investment and client work.

Does this make us ISO 42001 certified?

No. This is a lightweight, ISO/IEC 42001-aligned governance baseline without the weight or cost of a certification programme. It’s the right foundation if you certify later — but the point is to let you answer your regulator and your board now.

Will this slow the desk down?

The opposite is the intention. Most firms are stuck between a blanket ban nobody follows and a free-for-all nobody can evidence. Approved tools, clear rules and an oversight trail are what let people use AI properly rather than quietly.

Before an SMF next attests

Has anyone actually mapped where AI is being used?

A 20-minute call. We’ll go through what your regime already requires you to control — and you’ll leave knowing whether you could evidence it. Whether or not you work with us.

Book a 20-minute call