Category: FCA | Reading time: 12
The scenario
A wealth manager at a mid-sized FCA-regulated firm asks ChatGPT to draft a suitability letter for a 68-year-old retired client moving £400,000 into equity-heavy portfolios. The AI returns a confident, well-structured letter. The adviser glances at it, edits a few details, and sends it.
Six months later the markets correct, the client is down 30%, and complains.
Be careful about what that loss proves, because on its own it proves very little. A 30% fall does not establish that the recommendation was unsuitable, that the client was exposed to more risk than they could bear, or that the firm breached anything. Suitability is assessed against the client's objectives, risk tolerance, capacity for loss, time horizon, knowledge and experience, and existing assets, as they stood when the recommendation was made. Markets falling is not evidence of a defective process.
What the loss does is create a demand for evidence. The firm will have to show its suitability assessment, its advice process, its communications, its supervision and its controls. That is where the AI question becomes uncomfortable, and it is worth noticing that the regulated issue is not the letter. It is the personal recommendation and the suitability assessment underneath it. A carefully reviewed letter does not cure an unsuitable recommendation.
The defence that will not work
The instinctive response is that the AI generated the letter, and it is an industry-standard tool.
That is not a defence, and it is worth being precise about why.
The FCA published its AI Update on 22 April 2024, setting out that its existing regulatory framework already covers firms' use of technology, including AI.1 Its current AI approach page says the same and emphasises accountability for senior managers.2 It followed DP5/22, Artificial Intelligence and Machine Learning, published jointly on 11 October 2022 by the Bank of England, including the Prudential Regulation Authority, and the FCA.3 The FCA's own numbering of that same paper is DP22/4. The joint feedback statement, PRA FS2/23 and FCA FS23/6, followed on 26 October 2023.4
The FCA has also run AI Live Testing, which focuses on governance, risk management, monitoring and evaluation of AI systems in their deployment context.5 It is a voluntary collaboration programme, not an enforcement route and not a certification.
The accurate statement of the position is narrower than the usual headline. The FCA has not created an exemption from conduct, governance, supervision, suitability or consumer protection requirements merely because a firm used an AI tool. Where AI is used in a regulated process, the firm remains responsible for complying with the rules applicable to that process, and cannot displace those obligations by attributing an output to an external model.
That is different from saying the firm is liable for every result any AI produces. It is not, and an article that says so is easy to dismiss.
The rule people cite, and the rule that actually bites
Two distinct things get run together here, and the distinction is material.
Individual Conduct Rule 2, at COCON 2.1.2R, requires that you act with due skill, care and diligence.6 It applies to conduct rules staff generally, which includes both certification staff and senior managers. It is not a senior manager rule.
Reasonable steps is a separate set of obligations. The Senior Manager Conduct Rules sit at COCON 2.2 and apply to senior conduct rules staff.7 SC1, at COCON 2.2.1R, requires reasonable steps to ensure that the business you are responsible for is controlled effectively. SC2, at COCON 2.2.2R, requires reasonable steps to ensure that business complies with the relevant requirements and standards of the regulatory system. SC3 covers delegation and oversight of what is delegated. SC4 covers disclosure to the regulators.
So the operative question for a senior manager is not framed by Conduct Rule 2 at all. It is: can you demonstrate the reasonable steps you took to ensure that the AI-assisted process in your area met the standards your responsibilities make you accountable for?
Personal accountability is not automatic on the existence of an AI-generated output. It turns on the individual's actual responsibilities, the firm's governance arrangements, whether a relevant breach occurred, whether the person was responsible for the area concerned, what steps a person in that position could reasonably have been expected to take, and the quality of monitoring, challenge, escalation and supervision.
A Statement of Responsibilities is important evidence of scope, and the FCA requires it to set out the aspects of the firm's affairs for which the person is responsible, consistent with the firm's governance arrangements and with other senior managers' statements.8 But it does not necessarily define the whole factual scope of what someone was responsible for.
Four controls that make reasonable steps demonstrable
The FCA has not published a prescriptive checklist for AI use under SM&CR. There is no rule requiring a documented validation step before every AI-generated output, no rule requiring prompt and response retention, and anyone telling you otherwise is inventing it.
What follows is a defensible set of controls, proportionate to risk, not a set of FCA requirements. For a client-facing suitability communication, which sits at the high-risk end, all four are worth having. For a low-risk internal draft, most of them are not.
Authoritative source grounding. Control what information the system may draw on. Do not assume a general-purpose model knows or will apply your current policies, suitability framework or risk thresholds. The regulatory question is not whether the model used generic training data. It is whether the overall process produced a compliant, suitable and fair outcome, and grounding is how you make that likely rather than lucky.
Review and approval proportionate to risk. A firm should be able to demonstrate an appropriate review and approval process, sized to the risk of the use case. For a suitability letter, that means a documented and repeatable check against approved guidelines rather than an adviser's unrecorded glance.
Records sufficient to reconstruct the material steps. For higher-risk AI-assisted workflows, retaining enough to reconstruct what was asked, what came back, what changed and what was sent may be the most practical way to evidence governance later. The obligations that make this matter come from a combination of record keeping, suitability records, systems and controls, outsourcing and third party risk, complaints handling and data protection, rather than from any single AI rule.Named human ownership. Identify accountable human owners for the AI-assisted process, with oversight arrangements proportionate to risk and consistent with the relevant Statements of Responsibilities. An AI tool cannot hold an SMF responsibility. Responsibility stays allocated to approved individuals and to the firm.
Where a material AI-assisted workflow lacks proportionate grounding, review, ownership, monitoring and records, that gap makes it harder for the firm and for the relevant senior manager to evidence that appropriate reasonable steps were taken, particularly if a breach or customer harm occurs. That is a weaker claim than "you are exposed", and it is the one that survives challenge.
Three questions to test your own position
If your firm uses ChatGPT, Copilot, Claude, Gemini or a sector platform anywhere in a client-facing workflow:
Is the AI grounded in your current, approved firm information, or in whatever the model already knew?
Is the level of human review, approval and record keeping proportionate to the risk and the customer impact of each use case?
Could you reconstruct the material steps in the process if the FCA, the Financial Ombudsman Service or the client asked about it in eighteen months?
If the honest answer to any of these is no for a high-risk workflow, the evidence supporting reasonable steps is thinner than it needs to be.
What a documented approach looks like
SAFE™ and V.E.R.I.F.Y.™ are the methodologies I use for this. They are not regulator-endorsed standards. No proprietary framework is, and any supplier claiming otherwise is overstating their position.
SAFE™ is a structured approach to grounding AI deployments on a firm's approved knowledge, with input controls and output validation, mapped to the applicable SYSC requirements, Consumer Duty outcomes in PRIN 2A, and, where they apply to the firm, the operational resilience rules in SYSC 15A.9
That qualification is doing real work. Operational resilience is not universal. SYSC 15A does not apply to a firm whose registered or head office is outside the UK, and it does not apply across every category of FCA-regulated firm. The rules came into force on 31 March 2022 with a transitional period that ended on 31 March 2025. PS21/3 is the policy statement that made them, and is useful background, but it is not the operative source.10 Whether an AI process engages operational resilience at all depends on whether it supports an important business service.
V.E.R.I.F.Y.™ is a six-step output validation protocol, Validate, Examine, Reference, Interrogate, Freshness, Yield, designed to produce a documented trail for AI-assisted outputs.
Both are ways of documenting the kind of reasonable steps the regime points toward. Neither is compliance itself, and neither is proof that a firm has complied with anything.
The bottom line
The FCA has not softened SM&CR for AI. Existing rules apply, and accountability stays where the regime put it, with the senior managers responsible for the relevant business activity, in the way their Statements of Responsibilities and the facts of the case determine.
The fact that a recommendation came from a model does not by itself displace the firm's obligations or the responsibilities allocated under SM&CR. It is, however, highly relevant to control design, to supervision, to causation, and to the evidence a supervisor will examine.
The firms treating SM&CR as the specification for how to deploy AI defensibly are ahead of the ones treating it as a brake. The difference will not show up until someone is asked to evidence reasonable steps, and by then the records either exist or they do not.
References
References checked against the FCA Handbook and primary sources on 16 August 2026.
This article is general guidance, not legal advice. How SM&CR accountability applies in a specific firm depends on that firm's governance arrangements, its Statements of Responsibilities and the allocation of prescribed responsibilities. Whether a particular recommendation was suitable is a question of fact. Both are questions for your compliance function and legal counsel.
Footnotes
Financial Conduct Authority, AI Update, 22 April 2024, stating that the existing regulatory framework covers firms' use of technology including AI: https://www.fca.org.uk/publication/corporate/ai-update.pdf ↩
Financial Conduct Authority, Our approach to AI: https://www.fca.org.uk/firms/innovation/ai-approach ↩
DP5/22: Artificial Intelligence and Machine Learning, published 11 October 2022 jointly by the Bank of England, including the Prudential Regulation Authority, and the Financial Conduct Authority. The FCA's own numbering of the same paper is DP22/4: https://www.bankofengland.co.uk/prudential-regulation/publication/2022/october/artificial-intelligence ↩
FS2/23 and FS23/6: Artificial Intelligence and Machine Learning, joint feedback statement on DP5/22, published 26 October 2023: https://www.bankofengland.co.uk/prudential-regulation/publication/2023/october/artificial-intelligence-and-machine-learning ↩
Financial Conduct Authority, AI Live Testing, a voluntary programme focused on governance, risk management, monitoring and evaluation in deployment context. It is not an enforcement or certification process: https://www.fca.org.uk/news/blogs/ai-live-testing-how-it-can-support-safe-and-responsible-ai-deployment ↩
FCA Handbook, COCON 2.1.2R, Individual Conduct Rule 2, act with due skill, care and diligence. Applies to conduct rules staff, which includes senior managers as well as certification staff: https://www.handbook.fca.org.uk/handbook/COCON/2/1.html ↩
FCA Handbook, COCON 2.2, Senior manager conduct rules. SC1 at COCON 2.2.1R, SC2 at COCON 2.2.2R, SC3 and SC4 following. Applies to senior conduct rules staff members: https://www.handbook.fca.org.uk/handbook/COCON/2/2.html ↩
FCA Handbook, SUP 10C.11, Statements of responsibilities: https://www.handbook.fca.org.uk/handbook/SUP/10C/11.html ↩
FCA Handbook, SYSC 15A, Operational resilience. In force 31 March 2022, transitional period ended 31 March 2025. Application is limited and firms should check the application provisions in SYSC 15A.1: https://www.handbook.fca.org.uk/handbook/SYSC/15A/ ↩
Financial Conduct Authority, Policy Statement PS21/3, Building Operational Resilience, the policy statement that made the SYSC 15A rules: https://www.fca.org.uk/publications/policy-statements/ps21-3-building-operational-resilience ↩
