The FCA and PRA on AI: Existing Rules, No New Rulebook
9 min read · updated August 11, 2026
There is no FCA AI sourcebook and the FCA has said there will not be one for now. The regulatory answer for a UK firm deploying a model is assembled from provisions written for other purposes, and it is more demanding than a dedicated rule would probably have been.
The stated position
The Financial Conduct Authority set out its approach in its AI Update, published on 22 April 2024 in response to the UK government’s request that regulators explain how they would implement the white paper principles. Its position is that the existing framework is technology-agnostic and outcomes-based, that AI is therefore already within scope, and that the FCA would prefer to clarify application than to add rules. The Bank of England and the FCA had reached the same place through discussion paper DP5/22 on artificial intelligence and machine learning, published in October 2022, and feedback statement FS2/23 in October 2023, which reported that respondents largely did not want a bespoke regime and did want clarity on how existing requirements map. The FCA’s AI material is published on its own site.
SM&CR: somebody is accountable by name
The Senior Managers and Certification Regime is the mechanism that makes the “existing framework” answer bite. Under the regime a senior manager holds a statement of responsibilities and a duty of responsibility: if a contravention occurs in an area for which they are responsible, they are accountable unless they took such steps as a person in their position could reasonably be expected to take. There is no AI-specific senior management function, and the FCA has not created one — which means AI accountability attaches to whichever existing function owns the business area, typically SMF24 for operations, or the relevant chief executive or head of business line.
The consequence firms most often miss is that the regime does not permit the responsibility to be located in a vendor. If a model supplied by a third party produces an outcome that breaches a rule, the accountable individual is inside the firm. That is why the practical output of an AI governance project in a UK firm is usually a change to a statement of responsibilities and to the management responsibilities map, not a new policy document. SYSC 4 and SYSC 5 sit underneath, requiring robust governance arrangements, effective risk management and competent staff.
The Consumer Duty and model-driven outcomes
The Consumer Duty in PRIN 2A, in force for open products from 31 July 2023 and for closed products from 31 July 2024, is the provision with the widest reach over consumer-facing AI. It sets a cross-cutting obligation to act to deliver good outcomes for retail customers, supported by four outcomes: products and services, price and value, consumer understanding, and consumer support.
- Consumer understanding requires communications to be likely to be understood by the customers who receive them, and to be tested where appropriate. A model generating personalised communications at scale makes the testing obligation harder, not easier, because there is no fixed artefact to test.
- Price and value reaches algorithmic pricing directly: a firm must be able to show the price is reasonable relative to the benefits, and differential pricing that a model has learned but nobody can explain is difficult to defend on that basis.
- Consumer support requires that a customer should not face unreasonable barriers, which is the provision an AI-only support channel with no route to a human runs into.
- The vulnerability expectations that run through the Duty require firms to respond to characteristics of vulnerability. A model optimised on average outcomes will systematically underserve the tail, and the Duty asks about the tail.
The Duty also requires monitoring of outcomes and an annual board assessment of whether the firm is delivering them. That is an evidence obligation, and it is the one most likely to require a firm to instrument its model outputs by customer segment.
Outsourcing, resilience and critical third parties
A hosted model is outsourcing or a material third-party arrangement, and the rules are well developed. SYSC 8 governs outsourcing for FCA-regulated firms; the PRA’s supervisory statement SS2/21 on outsourcing and third party risk management, effective from March 2021, sets out expectations on materiality assessment, contractual rights including audit and access, exit planning and register maintenance. Operational resilience rules from PS21/3 required firms to identify important business services, set impact tolerances and be able to remain within them by the end of the transitional period in March 2025.
On top of that sits the critical third parties regime, introduced by the Financial Services and Markets Act 2023 and implemented by the Bank, PRA and FCA in policy statement PS16/24 published in November 2024, with rules applying from 1 January 2025. It allows HM Treasury to designate a third party whose failure would threaten financial stability or confidence, and subjects designated firms to direct requirements. Cloud providers were the motivating case; concentration in model provision is plainly capable of raising the same question, and whether a model provider gets designated is an open matter rather than a settled one.
What the regulators have not answered
Three genuine gaps. First, explainability: neither regulator has said what standard of explanation satisfies the Consumer Duty for a decision a firm cannot decompose, and the FCA has been explicit that it is not setting a technical bar. Second, the boundary between a tool and a regulated activity — when a model’s output to a customer becomes a personal recommendation under COBS, engaging the advice perimeter, is a question firms are currently answering conservatively because there is no clarifying statement. Third, the interaction with data protection: an explanation good enough for the FCA may involve processing that the ICO would question, and neither regulator has published a joint position resolving it. See the ICO’s own AI guidance for the other half of that problem, and the white paper approach for why the UK ended up with regulators answering separately.