The FCA plans no extra AI rules and relies on regimes you already answer to. In healthcare, the National Commission's recommendations ask providers to demonstrate AI readiness.
AI Governance in UK Financial Services and Healthcare
By James Cotton · Last updated · 7 min read
Part of our topic guides on AI Governance & Data Strategy and AI Skills for Business.
By James Cotton, Founder, iO-Sphere
Financial services: what the FCA has said
The FCA's own page, AI and the FCA: our approach, first published in September 2025 and updated in February 2026, is direct: "We do not plan to introduce extra regulations for AI. Instead, we'll rely on existing frameworks." It names two of those frameworks as relevant to the safe use of AI, the Consumer Duty and the Senior Managers and Certification Regime (SM&CR). SM&CR is where accountability lands.
The FCA set out how in its AI Update of April 2024. Any use of AI in relation to an activity, business area or management function of a firm "would fall within the scope of a SMF manager's responsibilities", and senior managers must take reasonable steps to ensure the business they are responsible for is effectively controlled. AI gets no separate home. Whoever holds the function it touches answers for it.
The regulator has held that position since. The Mills Review, its review of the impact of AI in retail financial services dated 6 July 2026, kept it: the review's chair, Ashley Alder, said the principles-based approach "relying on the Consumer Duty and Senior Managers Regime" has been critical.
What has grown is supervised testing. The FCA's AI Live Testing programme announced its second cohort on 21 April 2026, eight firms including two high-street banks, and its evaluation report is due in the first quarter of 2027.
Financial services: what the survey shows
The Bank of England and the FCA asked firms directly. Their November 2024 survey, "Artificial intelligence in UK financial services 2024", found 75% of firms already using AI and a further 10% planning to within three years. Accountability was mostly in place: 84% reported an accountable person for their AI framework.
Understanding was thinner. The same firms split 46% reporting only "partial understanding" of the AI they use against 34% reporting "complete understanding", and a third of use cases were third-party implementations built outside the firm that runs them. Next to the 84%, that describes names on frameworks resting on incomplete knowledge of how the systems behave. The FCA's senior manager position covers any use of AI, bought or built, and a 2026 survey is under way with no results yet.
Banks and building societies with models: PRA SS1/23
The PRA's supervisory statement SS1/23 on model risk management principles took effect on 17 May 2024 and covers risks from AI and machine learning used in modelling. It applies to banks, building societies and PRA-designated investment firms with internal-model approval. Principle 2 allocates responsibility for the model risk framework to the most appropriate Senior Management Function holder, so for an in-scope firm an AI model arrives inside a framework one senior person already owns.
Healthcare: the sandbox and the National Commission
Healthcare began with a sandbox. The MHRA's AI Airlock is its regulatory sandbox for AI as a medical device; phase 2 ran from April 2025 to May 2026 with seven innovators, and on 8 April 2026 the programme secured £3.6m over three years. The MHRA is careful to say that sandbox reports "do not constitute formal guidance".
The MHRA launched the National Commission into the Regulation of AI in Healthcare on 26 September 2025, and its recommendations for a future regulatory framework followed on 10 September 2026. Recommendation 14 proposes staged authorisation, working with providers that "demonstrate sufficient AI readiness", defined as "the necessary knowledge, capabilities and capacity to deploy the relevant device safely". Recommendation 18 calls for "strong governance arrangements for implementation and monitoring".
These are recommendations and not yet in force. NHS organisations deploying AI now are pointed to the AI and Digital Regulations Service, run jointly by NICE, the MHRA, the CQC and the Health Research Authority and currently in beta.
Data protection: what the ICO has said
If an AI system touches personal data, the ICO's guidance applies. Its accountability page says that "in the vast majority of cases, the use of AI will involve a type of processing likely to result in a high risk", which means a data protection impact assessment (DPIA) is required.
The same page says who cannot hold that responsibility for the business: "You cannot delegate these issues to data scientists or engineering teams." Set beside the FCA's senior manager position, it points the same way, towards the people running the business. The ICO has had the page under review since the Data (Use and Access) Act, so its wording may change.
The ICO applies in every regulated sector
This page quotes the regulators of financial services and healthcare. In any other regulated sector, the ICO position above still applies wherever AI touches personal data, alongside whatever your own regulator has published on AI.
What a supervisor asks, and what a capable team answers
Put the regulators' words together and they turn into a handful of questions a supervisor can ask any firm using AI. The first is who owns this model. A capable team answers with a name and a function: the senior manager whose area the AI touches, as the FCA's position requires, or at an in-scope bank the Senior Management Function holder that SS1/23 gives the model risk framework. Mapping who holds which piece is covered in who is responsible for AI governance.
The second question goes to that person: how would you know it was wrong? The answer is specific to the use: which cases the model gets wrong, who is harmed when it does, and what the team watches in order to notice. That is the question the survey's gap between accountable people and complete understanding would fail, and it is harder to answer when the model came from a supplier, as a third of use cases did.
Then comes the request to see who checked it. The answer is a record: the DPIA made before go-live, each review of an output, and each change made when a supplier updated the model, kept in the shape a governance framework provides and kept current by the people doing the work.
Last, did the people who checked it understand what they were looking at? A capable team points to decisions, such as a credit analyst who flagged drift in a bought-in model or a clinician who logged where a tool was confidently wrong. That is the knowledge and capability the National Commission's readiness definition names, and it has to exist across the team doing the work. The apprenticeship standard for the practitioners who own this is ST0967, the Data Protection and Information Governance Practitioner standard.
Our Data & AI Governance apprenticeship trains those practitioners on it, for the day a supervisor opens with the first question: who owns this model?
Frequently asked questions
Do we need a dedicated Senior Manager for AI?
No dedicated role is prescribed. The FCA's 2024 position puts AI inside the responsibilities of whichever Senior Management Function holder already covers the activity it touches, so the practical work is mapping: list each AI use, pair it with the senior manager whose function covers it, and make sure that person can show the reasonable steps they have taken.
What should the record of who checked what contain?
Enough for a later reviewer to follow each check: which AI system was checked and which version, the date, who did the check, what the output was compared against (a source record, a policy rule, a sample of past decisions), and the outcome, including what was changed if the check failed. The DPIA records the decision to go live; this record shows the system being watched afterwards.
If a supplier built our model, who answers to the FCA for its output?
A senior manager at your firm does. The FCA's April 2024 wording covers any use of AI in relation to a firm's activity, business area or management function, and it names no exception for a model someone else built, which matters because third-party implementations made up a third of AI use cases when the Bank of England and the FCA surveyed firms in 2024. For many firms, the model a senior manager answers for is one their own staff did not build.
Is there a UK AI regulator?
There is no single UK AI regulator; the UK works through its existing sector regulators. For the sectors on this page that means the FCA and PRA in financial services, the MHRA alongside NICE, the CQC and the Health Research Authority in healthcare, and the ICO wherever personal data is involved.
Want to own AI governance in your organisation?
Our Level 4 Data & AI Governance programme builds the frameworks that make data trustworthy and AI accountable, funded through the Growth & Skills Levy.