Legal services built around your needs.

AI can make a good control environment faster and more effective. It can also make a poor one fail at scale.
The FCA’s latest Wealth Management Survey provides a useful illustration. It found that 13% of firms were already using in-house or third-party AI tools, rising to 45% when firms considering adoption over the following 12 months were included.
At the same time, the FCA continued to identify weaknesses in areas including expected transaction data, source-of-wealth verification, PEP checks and sanctions screening.
Those findings are specific to wealth management, but the underlying issue is much broader. For regulated financial services firms, some of the most important questions about AI are not really new technology questions at all. They are familiar questions about data, systems and controls, accountability, third-party dependency and operational resilience.
AI does not fix a weak control framework. It can magnify it.
If a firm does not have complete client data, does not understand expected client activity or has weak source-of-wealth controls, greater automation will not necessarily improve the underlying decision-making. In some cases, it may simply allow poor decisions to be made more quickly and across a larger number of clients.
That matters particularly in financial crime controls, where AI tools may depend heavily on the quality, consistency and completeness of the data provided to them.
Before relying on AI to improve a control, I would first want to understand how well that control is working today. Is the client data complete? Is risk classification consistent? Is ongoing monitoring effective? Is there a clear escalation process when something does not look right?
The sophistication of the technology cannot compensate for weaknesses in those fundamentals.
Boards and senior managers are not expected to understand the technical operation of every AI model or component. They do, however, need enough information to understand how AI affects the areas for which they are responsible, to satisfy themselves that responsibility and expertise are clearly allocated, and to challenge whether the relevant controls are working as intended.
In practice, I would want to know:
For a senior manager, the SMCR question is therefore not whether they understand the code. It is whether they have taken reasonable steps to understand and oversee the risks within their area of responsibility.
The risk is not limited to a firm’s own use of AI. The Bank of England has warned that frontier AI may make cyber-attacks faster and easier to carry out, make outages more disruptive and allow criminals to create more convincing scams.
For regulated firms, the significant change may be the speed at which vulnerabilities can be identified and exploited. A framework designed around slower-moving threats may come under strain where there is less time to detect an issue, contain it and recover, which places greater pressure on existing obligations around systems and controls, operational resilience, incident response and governance.
The underlying obligations may be familiar. The time available to discharge them may not be.
Outsourcing technology does not, of itself, make a firm more vulnerable. The issue is dependency, concentration and resilience, and the practical question is a straightforward one: what stops working tomorrow if this provider fails?
Answering that question means understanding which important business services depend on the provider, whether viable alternatives exist, how quickly services could be restored, whether concentration risk has been identified and tested, and what the operational consequences of provider failure would be.
Concentration makes this more pressing: large parts of the sector may depend on the same cloud providers, managed service providers or other critical third parties, so a vulnerability affecting one provider could affect several regulated firms at once, and AI may increase the speed at which those vulnerabilities are exploited.
Outsourcing the technology does not outsource the regulatory responsibility.
For many UK financial services firms, the immediate challenge is unlikely to be a completely new set of AI-specific regulatory obligations. It is whether existing obligations around financial crime, governance, outsourcing, operational resilience and senior management accountability can still be discharged effectively as automation increases and the threat environment moves faster.
That means the fundamentals become more important, not less: good data, clear ownership, effective controls, meaningful management information, resilient third-party arrangements and escalation that actually works.
AI does not remove the need for good governance. It raises the cost of getting it wrong.
The firms best placed to benefit from AI will not necessarily be those that adopt it fastest. They will be those that understand what the technology is doing, what it depends on, who is accountable for it and how they will know when it is not working as intended.
Arbor Law works with financial services firms to assess how new technology affects the regulatory framework they already operate within.
In practice, we can help firms:
The objective is not governance for governance’s sake. It is to ensure that the control framework remains proportionate, intelligible and capable of supporting the way the business is actually using technology.
FAQs
Test the underlying control first. That means establishing whether client data is accurate and complete, whether risk classification is applied consistently, whether ongoing monitoring is effective and whether escalation actually happens when something does not look right. If a control is not working properly today, automating it is unlikely to make it work tomorrow.
Senior managers may be accountable where AI affects an area for which they hold regulatory responsibility. They are not expected to have detailed technical knowledge of the model itself, but they are expected to take reasonable steps: understanding how the technology affects the controls they are responsible for, ensuring ownership and oversight are clearly allocated, and receiving management information good enough to allow them to challenge what is happening.
No. Regulatory responsibility remains with the regulated firm. Outsourcing creates dependency, and often concentration risk where many firms rely on the same providers, so a firm needs to understand which important business services depend on a provider, what would stop working if it failed, how quickly services could be restored and whether that has been tested.
There is not currently a single standalone FCA rulebook governing the use of AI across financial services. Existing requirements on governance, systems and controls, financial crime, outsourcing and operational resilience continue to apply, and remain relevant to how a firm’s use of AI is governed and supervised.









