By: Raico Technology Ltd
Posted: 13 June 2026
At Raico Technology, we recently sat down with our Chief Compliance Officer, Angela Raib, to discuss a question that many financial services firms are now grappling with:
As AI becomes increasingly embedded within financial services, will the FCA need entirely new regulations, or can existing frameworks evolve to meet the challenge?
Angela, who previously held a Senior Associate position at the Financial Conduct Authority (FCA), believes the answer lies somewhere between the two.
“The FCA has traditionally adopted a technology-neutral approach to regulation,” she explains. “Rather than creating entirely new rules for every technological advancement, the regulator typically applies existing principles and frameworks to emerging risks. AI is no exception.”
However, the rapid evolution of AI—particularly the emergence of autonomous and agentic systems—raises important questions about how existing regulatory frameworks will operate in practice.
One of the most obvious starting points is the Senior Managers and Certification Regime (SM&CR).
The framework was designed to ensure accountability within financial services firms by clearly identifying who is responsible for key business functions and regulatory outcomes.
According to Angela, the principles behind SM&CR remain highly relevant in an AI-driven world.
“The fundamental question doesn't change simply because AI is involved,” she says. “The FCA will still want to know who is accountable when something goes wrong.”
Whether an AI system is approving loans, detecting fraud, conducting customer onboarding, or supporting investment decisions, responsibility cannot be delegated to an algorithm.
Someone within the organisation must remain accountable.
However, Angela believes AI may eventually create pressure for enhancements to existing certification requirements.
“We're reaching a point where senior leaders don't necessarily need to become AI engineers, but they do need sufficient understanding of AI risks, governance and controls to effectively discharge their responsibilities.”
This could lead to increased expectations around AI literacy, governance training and board-level oversight, particularly within firms making extensive use of advanced AI technologies.
The FCA's Consumer Duty already requires firms to deliver good outcomes for retail customers.
In many respects, Angela believes this framework is well-positioned to address many AI-related risks.
“Consumer Duty focuses on outcomes rather than technologies,” she explains. “Whether a decision is made by a human employee or supported by AI, firms are still responsible for ensuring customers receive fair treatment.”
Yet AI introduces unique challenges.
Algorithms can personalise products, automate communications and make decisions at a scale that was previously impossible. While this can improve efficiency and customer experience, it can also amplify errors, biases or poor practices.
For example, an AI model could unintentionally disadvantage certain customer groups, provide unsuitable recommendations or generate communications that create customer misunderstanding.
“The challenge for firms isn't simply implementing AI,” Angela notes. “It's demonstrating that they understand how those systems influence customer outcomes and that appropriate controls are in place.”
As AI adoption increases, the FCA may issue additional guidance to help firms interpret Consumer Duty obligations within AI-driven customer journeys, even if the underlying principles remain unchanged.
Another framework likely to become increasingly important is Operational Resilience.
The FCA already expects firms to identify important business services, establish impact tolerances and ensure they can continue operating during disruptions.
As organisations become more dependent on AI systems, resilience considerations become more complex.
“If an AI model fails, produces inaccurate outputs or becomes unavailable, what is the impact on critical services?” Angela asks.
Questions around model reliability, third-party AI providers, data quality and system dependencies will become central to operational resilience planning.
Financial institutions may eventually need to demonstrate not only that they can recover from traditional technology failures, but also that they can respond effectively to AI-specific incidents.
This could include governance over model drift, hallucinations, autonomous decision-making failures and cyber threats targeting AI systems.
While the FCA has largely focused on applying existing regulatory frameworks to AI, other jurisdictions are taking increasingly proactive approaches.
Dubai, for example, has publicly positioned itself as a global leader in AI adoption, with significant investment in AI-enabled public services and increasing expectations around AI integration across industries.
These developments highlight a broader global trend: AI is rapidly moving from experimental use cases toward becoming a core component of business operations.
“The conversation is no longer about whether firms will adopt AI,” Angela says. “It's about how quickly adoption occurs and how regulators ensure appropriate safeguards keep pace.”
Angela's view is that the FCA's existing frameworks provide a strong foundation for managing many AI-related risks today.
SM&CR already addresses accountability.
Consumer Duty already focuses on customer outcomes.
Operational Resilience already requires firms to manage critical service disruption.
However, as AI becomes more autonomous, interconnected and business-critical, firms should expect increasing regulatory scrutiny and potentially more detailed guidance.
“I don't believe we're necessarily heading towards a complete regulatory overhaul,” Angela concludes. “More likely, we'll see an evolution of existing frameworks, supported by additional guidance, supervisory expectations and industry best practice. The principles are already there—the challenge will be ensuring they remain effective as AI capabilities continue to develop.”
For firms embracing AI, the message is clear: regulatory expectations around accountability, governance, customer outcomes and resilience are not disappearing. If anything, they are becoming more important than ever.
1 January 2026
For many firms, the Financial Conduct Authority is still perceived primarily as a reactive...
Learn More
15 January 2026
For many organisations, NIS2 is still being approached as a cybersecurity directive — a technical upgrade, an IT-led compliance project, or a checklist of controls...
Learn More
29 January 2026
Operational resilience is often understood through incidents — outages, disruptions, cyber events...
Learn More