The shift from assistance to action
Financial-services firms are moving quickly from AI that helps people draft, search and summarise to AI that can influence, initiate and, in bounded settings, execute operational actions.
That shift creates a different governance challenge. When AI contributes to a customer communication, complaint outcome, compliance case, affordability workflow, payment instruction, investment process or change to a customer record, the firm must answer more fundamental questions.
- Who gave the system authority to act?
- What boundaries governed its behaviour?
- Who remains accountable for the outcome?
- What evidence exists of what happened?
- How can the firm intervene if an outcome is harmful, inaccurate or outside approved limits?
The governance gap
Most firms already have important elements of control: information security, access management, data protection, third-party risk, model-risk or testing practices, Consumer Duty governance, operational resilience, GRC tooling and application logs.
These matter, but they do not necessarily create a coherent accountability record for a material AI-enabled action. As AI shifts from assistance to action, accountability needs to operate at the level of the deployed use case and, for material events, the action itself.
- A model may have been assessed before deployment, without showing which prompt, data source, tool permission or policy rule applied when an outcome occurred.
- An engineering log may show an API call succeeded, without showing whether the action was within an approved business mandate.
- Technology may own the system while Compliance owns the policy, but nobody may clearly own the real-world customer or operational outcome.
Five executive questions
- What authority has this AI system actually been given? Distinguish AI that assists from AI that recommends, initiates or executes an action. Know the approved mandate, prohibited actions, thresholds and human-approval requirements.
- Who is accountable for the outcome? Identify the business owner, executive sponsor, first-line operator, Technology/Data owner, independent Risk and Compliance challenge, and those authorised to approve changes, accept exceptions or suspend use.
- What can the system see, use and do? Map the model, instructions, data, retrieval, tools, permissions, human hand-offs and controls across the workflow.
- Can the firm reconstruct a material action? Retain enough evidence to understand the action sequence, decision context, controls in force and human involvement.
- Can the firm intervene and learn? Define proportionate ways to require human approval, restrict authority, suspend a workflow and activate a safe fallback, then monitor exceptions, overrides, complaints, errors and remediation.
A practical maturity model
| Position | What it looks like | Priority action |
|---|---|---|
| Unseen | AI activity is decentralised and not reliably inventoried. | Create a use-case inventory and identify accountable owners. |
| Documented | Policies or assessments exist but practical authority is unclear. | Define permitted autonomy, decision rights and approval thresholds. |
| Governed | Key controls exist but evidence is fragmented and retrospective. | Standardise evidence, approvals, exceptions and change controls. |
| Assurable | Material workflows are traceable, challengeable and reviewable. | Improve outcome monitoring and independent assurance. |
| Controlled autonomy | Bounded actions operate within observable limits and tested intervention paths. | Scale carefully while retaining oversight and resilience. |
What to do now
- Create one view of live, planned and shadow AI use cases.
- Prioritise workflows that influence or initiate customer, financial, compliance or operational actions.
- Define permitted autonomy and explicit decision boundaries.
- Assign accountable ownership and independent challenge.
- Set a risk-proportionate evidence standard.
- Design and test intervention, fallback and remediation paths.