Financial services firms have spent two decades building governance around models, risk, and customer outcomes. The AI governance financial services firms need now is an extension of that structure, not a bolt-on to it. Most firms have not made that extension yet. The tools have moved faster than the frameworks meant to control them.
Boards often assume existing risk committees already cover this. They do not, not properly. A model risk framework built for credit scoring does not stretch to cover a chatbot summarising customer complaints or an underwriter using a generative tool to draft policy wording.
What the FCA Actually Expects From AI Governance in Financial Services
The FCA has not published a single AI rulebook. Instead, it expects firms to apply existing principles, senior manager accountability, consumer duty, and operational resilience, to AI use cases specifically. That means someone senior owns the outcome, not just the tool.
Firms that treat AI as an IT matter, rather than a governance matter, tend to miss this. The FCA’s guidance on artificial intelligence makes clear that accountability sits with the firm, not the vendor supplying the model. If a customer receives a poor outcome because an AI tool made an error, the regulator asks who approved that tool, not which company built it.
Customer-Facing AI Raises the Stakes
Internal AI use carries risk. Customer-facing AI carries reputational and regulatory risk at the same time. A chatbot giving incorrect information about a mortgage product, or a claims tool that quietly deprioritises certain customer segments, creates exactly the kind of consumer harm the Consumer Duty was designed to prevent.
Boards should ask a simple question before any customer-facing AI tool goes live. What happens when it gets something wrong, and how quickly will we know? Many firms cannot answer that yet.
Model Risk Does Not Disappear Because a Model Is AI
Traditional model risk management asks for validation, monitoring, and documented limitations. Generative AI models are harder to validate because their outputs vary and their reasoning is not always traceable. That does not mean the discipline gets relaxed. It means it gets harder to apply, and firms need to work out how.
Some firms have quietly excluded generative tools from model risk registers altogether, treating them as productivity software rather than decision-making tools. That is a mistake regulators are increasingly likely to spot.
The Gap Between Policy and Practice
Most regulated firms already have an AI policy of some kind. Fewer can show it is actually followed. Compliance teams write the document, staff sign an acknowledgement, and then everyday use of AI tools drifts away from what the policy describes.
This gap between paper governance and operational reality is where regulatory findings usually land. Boards should be asking pointed questions about how AI is actually used, not just what the policy says. Our piece on AI governance for boards: what leadership should be asking sets out the specific questions that tend to expose this gap early.
Suppliers Add a Layer Most Firms Have Not Mapped
Financial services firms rely heavily on third-party software, and increasingly that software has AI features embedded inside it. A core banking platform, a claims system, or a CRM tool may now make automated decisions the firm never explicitly approved.
Outsourcing rules already require oversight of critical suppliers. AI adds a new dimension to that oversight, because the risk is not just operational failure but algorithmic decision-making the firm did not design. Our piece on the hidden supplier risks in enterprise AI covers exactly where these blind spots tend to sit, and why supplier due diligence needs to change.
What Good Governance Looks Like in Practice
Good AI governance in financial services is not a longer policy document. It is clear ownership, documented approval routes for new AI tools, and monitoring that catches problems before a customer or a regulator does.
It also means treating AI governance as a live, ongoing exercise rather than a project with an end date. Firms that get this right tend to start with an honest assessment of where their current gaps actually sit, rather than assuming existing frameworks already cover it.
If your firm needs a clear, structured view of where its AI governance gaps sit, the AI Governance Gap Assessment is the right place to start.