Back to Resources

    Regulatory insight

    What the Mills Review Means for AI Accountability in Financial Services

    A practical reading for leaders moving from AI experimentation towards accountable deployment.

    8-minute readBuildMoat executive resource

    The strategic signal

    The FCA’s Mills Review considers how AI could reshape retail financial services and the implications for consumers, firms, markets and regulation. It is an important strategic signal for firms developing AI-enabled products, operations and control functions.

    It does not create an immediate standalone AI rulebook for UK financial services. The FCA’s approach remains principles-based, outcomes-focused and technology-neutral. Existing expectations around governance, consumer outcomes, operational resilience, data, outsourcing and individual accountability continue to apply when a firm uses AI.

    The Review brings sharper attention to the transition from assistance toward autonomy. For firms, the practical implication is straightforward: AI-enabled activity needs to be governable in the context in which it is deployed.

    What the Review signals

    • Understanding where AI is influencing or making operational decisions
    • Monitoring the transition toward more autonomous models
    • Developing trusted foundations for agentic participation in financial services
    • Clarifying how AI agents may be authorised, identified and held accountable
    • Maintaining consumer protection and effective oversight as technology changes
    • Preparing for a more data- and technology-enabled model of supervision over time

    What it does not mean

    • Every firm must immediately deploy autonomous AI
    • Every AI use case needs the same level of governance
    • Existing accountability frameworks no longer matter
    • A software tool can certify compliance or replace management judgment
    • Firms should wait for a new AI-specific rulebook before establishing practical controls

    Practical questions for firms

    1. What is the use case and what outcome can it influence?
    2. Is the system assisting, recommending, initiating or executing an action?
    3. Who approved the permitted authority and who owns the outcome?
    4. Which data, tools, systems and third parties are involved?
    5. What evidence is retained for material actions and decisions?
    6. What controls apply when the system changes, fails or produces an unexpected outcome?
    7. Who can intervene, and what happens to customers and operations if the workflow is restricted or paused?

    What to do now

    1. Inventory live and planned AI use cases.
    2. Prioritise those with customer, financial, compliance or important-operational-service impact.
    3. Classify autonomy and set appropriate approval requirements.
    4. Map accountable ownership, independent challenge and intervention authority.
    5. Define minimum evidence and change-control requirements.
    6. Use a priority workflow to test whether governance works in practice.

    BuildMoat perspective

    The opportunity is not to treat AI as a wholly separate compliance domain. It is to make existing governance principles operational for AI-enabled actions. That means translating accountability into practical authority boundaries, evidence records, review routines and intervention paths.

    Move from regulatory signal to practical action

    Use BuildMoat’s AI Accountability Diagnostic to assess priority AI workflows, define permitted autonomy and identify the accountability, evidence and control gaps that require action.

    This resource provides practical governance guidance for discussion and planning. It is not legal advice, an audit, regulatory certification, a compliance score or a substitute for your firm’s own legal, regulatory, risk and governance decisions.