Insights

AI in financial services: the technology may be new, but the control questions are not

5 October 2026
·
5 minutes
Kate Bennett
Founding Partner
Overview

AI can make a good control environment faster and more effective. It can also make a poor one fail at scale.

The FCA’s latest Wealth Management Survey provides a useful illustration. It found that 13% of firms were already using in-house or third-party AI tools, rising to 45% when firms considering adoption over the following 12 months were included. 

At the same time, the FCA continued to identify weaknesses in areas including expected transaction data, source-of-wealth verification, PEP checks and sanctions screening.

Those findings are specific to wealth management, but the underlying issue is much broader. For regulated financial services firms, some of the most important questions about AI are not really new technology questions at all. They are familiar questions about data, systems and controls, accountability, third-party dependency and operational resilience.

AI does not fix a weak control framework. It can magnify it.

AI can make weak controls fail faster

If a firm does not have complete client data, does not understand expected client activity or has weak source-of-wealth controls, greater automation will not necessarily improve the underlying decision-making. In some cases, it may simply allow poor decisions to be made more quickly and across a larger number of clients.

That matters particularly in financial crime controls, where AI tools may depend heavily on the quality, consistency and completeness of the data provided to them.

Before relying on AI to improve a control, I would first want to understand how well that control is working today. Is the client data complete? Is risk classification consistent? Is ongoing monitoring effective? Is there a clear escalation process when something does not look right?

The sophistication of the technology cannot compensate for weaknesses in those fundamentals.

Senior managers remain accountable for the control environment

Boards and senior managers are not expected to understand the technical operation of every AI model or component. They do, however, need enough information to understand how AI affects the areas for which they are responsible, to satisfy themselves that responsibility and expertise are clearly allocated, and to challenge whether the relevant controls are working as intended.

In practice, I would want to know:

  • Who owns the AI use case internally?
  • Which existing processes and controls does it affect?
  • Who validates the output?
  • What management information reaches the relevant senior manager?
  • How are unexpected outcomes identified and escalated?
  • Who has authority to intervene if the technology is not operating as expected?

For a senior manager, the SMCR question is therefore not whether they understand the code. It is whether they have taken reasonable steps to understand and oversee the risks within their area of responsibility.

Frontier AI may shorten the time firms have to respond

The risk is not limited to a firm’s own use of AI. The Bank of England has warned that frontier AI may make cyber-attacks faster and easier to carry out, make outages more disruptive and allow criminals to create more convincing scams.

For regulated firms, the significant change may be the speed at which vulnerabilities can be identified and exploited. A framework designed around slower-moving threats may come under strain where there is less time to detect an issue, contain it and recover, which places greater pressure on existing obligations around systems and controls, operational resilience, incident response and governance.

The underlying obligations may be familiar. The time available to discharge them may not be.

Outsourcing creates dependencies that firms need to understand

Outsourcing technology does not, of itself, make a firm more vulnerable. The issue is dependency, concentration and resilience, and the practical question is a straightforward one: what stops working tomorrow if this provider fails?

Answering that question means understanding which important business services depend on the provider, whether viable alternatives exist, how quickly services could be restored, whether concentration risk has been identified and tested, and what the operational consequences of provider failure would be.

Concentration makes this more pressing: large parts of the sector may depend on the same cloud providers, managed service providers or other critical third parties, so a vulnerability affecting one provider could affect several regulated firms at once, and AI may increase the speed at which those vulnerabilities are exploited.

Outsourcing the technology does not outsource the regulatory responsibility.

The regulatory questions are familiar. The operating environment is not.

For many UK financial services firms, the immediate challenge is unlikely to be a completely new set of AI-specific regulatory obligations. It is whether existing obligations around financial crime, governance, outsourcing, operational resilience and senior management accountability can still be discharged effectively as automation increases and the threat environment moves faster.

That means the fundamentals become more important, not less: good data, clear ownership, effective controls, meaningful management information, resilient third-party arrangements and escalation that actually works.

AI does not remove the need for good governance. It raises the cost of getting it wrong.

The firms best placed to benefit from AI will not necessarily be those that adopt it fastest. They will be those that understand what the technology is doing, what it depends on, who is accountable for it and how they will know when it is not working as intended.

How Arbor Law can help

Arbor Law works with financial services firms to assess how new technology affects the regulatory framework they already operate within.

In practice, we can help firms:

  • map AI use cases against existing regulatory responsibilities;
  • identify which systems and controls are affected;
  • clarify senior management ownership and oversight;
  • assess outsourcing and third-party dependencies;
  • review governance, management information and escalation arrangements; and
  • consider whether existing financial crime and operational resilience frameworks remain appropriate as automation increases.

The objective is not governance for governance’s sake. It is to ensure that the control framework remains proportionate, intelligible and capable of supporting the way the business is actually using technology.

FAQs

What should financial services firms do before using AI in KYC and AML?

Test the underlying control first. That means establishing whether client data is accurate and complete, whether risk classification is applied consistently, whether ongoing monitoring is effective and whether escalation actually happens when something does not look right. If a control is not working properly today, automating it is unlikely to make it work tomorrow.

Are senior managers responsible for AI failures under SMCR?

Senior managers may be accountable where AI affects an area for which they hold regulatory responsibility. They are not expected to have detailed technical knowledge of the model itself, but they are expected to take reasonable steps: understanding how the technology affects the controls they are responsible for, ensuring ownership and oversight are clearly allocated, and receiving management information good enough to allow them to challenge what is happening.

Does outsourcing AI transfer regulatory responsibility to the provider?

No. Regulatory responsibility remains with the regulated firm. Outsourcing creates dependency, and often concentration risk where many firms rely on the same providers, so a firm needs to understand which important business services depend on a provider, what would stop working if it failed, how quickly services could be restored and whether that has been tested.

Does the FCA have specific AI rules for financial services firms?

There is not currently a single standalone FCA rulebook governing the use of AI across financial services. Existing requirements on governance, systems and controls, financial crime, outsourcing and operational resilience continue to apply, and remain relevant to how a firm’s use of AI is governed and supervised.

Written By
Kate Bennett
Kate Bennett
Founding Partner
Kate is a founding partner of Arbor Law and established the firm’s UAE practice. She is a senior corporate finance and financial services lawyer advising founders, boards, investors and regulated businesses on capital raising, M&A, governance, FCA regulatory matters, managed compliance and international expansion. Kate brings more than two decades of experience across private practice and senior in-house legal leadership, spanning the US, UK and international markets, including the Middle East, North Africa and Central and Eastern Europe. In private practice, she has advised on complex international transactions, major capital markets deals, corporate governance and regulatory compliance. She later owned those same matters from inside the business as General Counsel and Company Secretary to FTSE-listed companies, managing external counsel, advising boards and executive teams, and carrying responsibility for how legal, regulatory, governance and transactional decisions worked in practice. This gives her a rare combination of technical legal expertise, commercial judgement, board-level experience and first-hand understanding of how legal advice is used inside businesses. She began her career at Baker McKenzie in Chicago before relocating to London as a senior associate in the Capital Markets Group. She later moved in-house, serving as UK General Counsel and Group Company Secretary for two FTSE-listed companies, before returning to private practice as a founding partner of Arbor Law. Kate’s practice focuses on corporate finance, financial services regulation and strategic General Counsel support. She advises on capital raising, M&A, capital markets transactions, shareholder matters, governance, cross-border structuring and UK market entry. She has particular experience supporting financial services firms, investment businesses, corporate finance houses and international businesses entering the UK. Her work includes FCA authorisation support, MiFID-related advice, Appointed Representative structures, perimeter analysis, governance frameworks, compliance programmes and ongoing managed compliance support. Kate frequently acts as fractional or Virtual General Counsel to scaling and international businesses, particularly in the financial services sector. She supports leadership teams on regulatory strategy, inward investment, operational setup, managed compliance, commercial decision-making and growth. Kate founded Arbor to deliver the kind of legal support she believes ambitious businesses actually need: senior, commercially grounded advice without unnecessary complexity, opaque costs or traditional law firm layers. She is particularly committed to making BigLaw-calibre expertise accessible to SMEs, scaling businesses and international entrants, giving clients clear options, practical judgement and advice they can act on with confidence.
View full profile
Latest

News and insights