Your sector, in the FAQ

Financial services regulation, answered in full.

Consumer Duty, SS1/23, DORA, Solvency II and SM&CR, applied to decisions an agent makes rather than to the model that makes them.

questions in this group, each answered in full
7
pages the answers are written on, every one linked
1
questions across the whole FAQ
316

7 questions on financial services regulation, answered by Tenhaw, a UK AI consultancy and AI delivery partner based in London. Nothing here is a summary: each answer is the exact text from the page that owns it, and every group links back to that page for the context around it.

7 questions

Financial Services

Answered on Financial Services, and rendered here in the same words.

Read the page these answers live on →

How do banks govern AI agent decisions?

By mapping accountability for each agent decision onto a named individual with matching authority, defining explicit human-in-the-loop points for consequential or irreversible decisions, and extending model risk governance to cover systems that compose models at runtime. Under SM&CR the accountability cannot rest with the system, so the operating model has to resolve it to people before deployment.

Does Consumer Duty apply to decisions made by AI agents?

Yes, if your firm is in scope of the Duty. It attaches to outcomes, not to mechanisms, so it makes no distinction between a decision made by a person, a rules engine or an agent. The four outcomes still have to be delivered and evidenced, products and services, price and value, consumer understanding and consumer support, alongside the cross-cutting obligations to act in good faith, avoid foreseeable harm and support customers in pursuing their financial objectives. The design consequences are concrete: the outcome measure has to be emitted by the system as it runs rather than reconstructed later, and vulnerability handling has to be an explicit route to a human, because a confidence score describes the model's certainty and not the customer's circumstances. Tenhaw has not delivered an agentic system into a customer-facing journey in an FCA-regulated firm.

What does the FCA expect when an AI agent makes a customer-facing decision?

The FCA has not published an AI rulebook and has said it does not intend to, so what it expects is what it already expects. A named senior manager accountable under SM&CR. Governance and controls proportionate to the risk. Evidence that the Consumer Duty outcomes are being delivered and monitored, including for customers with characteristics of vulnerability. And the ability to explain a decision to the customer who received it and to a supervisor afterwards. The practical test is whether you can answer who was accountable, what testing was done, what the system actually decided and where the record is, from artefacts the programme produced anyway rather than from an archaeology exercise months later.

How does SS1/23 apply to agentic systems?

SS1/23 took effect on 17 May 2024 for UK banks, building societies and PRA-designated investment firms with internal model permissions, and it uses a deliberately broad definition of a model: a quantitative method turning input into output for use in a decision. A language model inside a decision path meets that definition without needing a special case. An agentic workflow is usually several models plus prompts, retrieval corpora and tool permissions, all of which change behaviour, so the practical work is treating those as versioned artefacts with named owners, entering the system on the model inventory, agreeing its risk classification with the second line before you build, and designing so independent validation is possible: reproducible evaluation sets, recorded provenance, and change control that fires on a prompt change rather than only on a model upgrade. Insurers are outside the formal scope and raise it anyway, because the PRA treats the principles as good practice more widely.

Does DORA cover AI suppliers?

Yes, where the supplier provides ICT services supporting a financial function of an entity in scope, and DORA has applied since 17 January 2025. That brings the AI vendor, and usually the model providers underneath it, into ICT third-party risk management: an entry on the register of information, contract terms covering audit and access rights, conditions on subcontracting, and a documented exit strategy, with a direct oversight regime for designated critical providers on top. UK-only firms are not in scope of DORA itself, and meet similar questions through the operational resilience regime and the critical third parties regime. The question that actually changes an architecture is exit: if the provider is unavailable, changes its terms, or a supervisor tells you to move, what breaks. Programmes built tightly around one provider's proprietary features have answered that by accident, and badly.

What does Solvency II require of AI in underwriting?

It does not name AI, and it binds it anyway, through governance and through data. The system of governance requires the four key functions to be effective, the ORSA has to reflect the firm's real risk profile, and data used for technical provisions must be accurate, complete and appropriate, with the actuarial function accountable for saying so. If an agent enriches submission data and that enrichment reaches pricing or reserving, someone has to be able to trace every field back to its source, which makes provenance an engineering requirement rather than a documentation exercise. Internal model firms add a model change policy and validation. And using a supplier for a critical or important operational function is outsourcing, with the notification and contractual duties that follow. Tenhaw holds no actuarial capability: our specialty insurance work is a proof of concept feeding business intelligence, not a rated pricing model.

How does SM&CR affect AI agent deployment?

It requires a named senior manager to be accountable for the outcomes of the function, including those produced by agents. In practice this means the operating model must specify which decisions agents may take autonomously, which require human approval, and who holds accountability at each point, documented before deployment rather than reconstructed after an incident.

All sectors

The rest of the FAQ

316 questions, grouped by subject

Every question answered anywhere on tenhaw.com sits in one of 39 groups. This is one of them.

All 316questions, and every group →

Still have a question?

A 30-minute discovery call with James Rooney. Bring the question this page did not answer. You'll leave with a rough scope whether you engage us or not.

30 minutesWith James personallyNo obligation

Most organisations start with a fixed-price Agent-Readiness Audit · £30k–£90k · 6–8 weeks