Your sector, in the FAQ

Financial services regulation, answered in full.

Consumer Duty, SS1/23, DORA, Solvency II and SM&CR, applied to decisions an agent makes rather than to the model that makes them.
questions in this group, each answered in full
7
pages the answers are written on, every one linked
1
questions across the whole FAQ
1424

7 questions on financial services regulation, answered by Tenhaw, a UK AI consultancy and AI delivery partner based in London. Nothing here is a summary: each answer is the exact text from the page that owns it, and every group links back to that page for the context around it.

Elsewhere in the FAQ
7 questions

Financial Services

Answered on Financial Services, and rendered here in the same words.

Read the page these answers live on →

How do banks govern AI agent decisions?

By mapping accountability for each agent decision onto a named individual with matching authority, defining explicit human-in-the-loop points for consequential or irreversible decisions, and extending model risk governance to cover systems that compose models at runtime. Under SM&CR the accountability cannot rest with the system, so the operating model has to resolve it to people before deployment.

Does Consumer Duty apply to decisions made by AI agents?

Yes, if your firm is in scope. It attaches to outcomes, not mechanisms, so it makes no distinction between a person, a rules engine or an agent. The four outcomes still have to be delivered and evidenced, products and services, price and value, consumer understanding and consumer support, alongside the obligations to act in good faith and avoid foreseeable harm. Two consequences follow. The outcome measure has to be emitted as the system runs rather than reconstructed later, and vulnerability handling has to be an explicit route to a human, because a confidence score describes the model's certainty, not the customer's circumstances. The first is what our London specialty insurance proof of concept builds, recording provenance per field as the pipeline runs.

What does the FCA expect when an AI agent makes a customer-facing decision?

The FCA has not published an AI rulebook and has said it does not intend to, so what it expects is what it already expects. A named senior manager accountable under SM&CR. Governance and controls proportionate to the risk. Evidence that the Consumer Duty outcomes are being delivered and monitored, including for customers with characteristics of vulnerability. And the ability to explain a decision to the customer who received it and to a supervisor afterwards. The practical test is whether you can answer who was accountable, what testing was done, what the system actually decided and where the record is, from artefacts the programme produced anyway rather than from an archaeology exercise months later.

How does SS1/23 apply to agentic systems?

SS1/23 took effect on 17 May 2024 for UK banks, building societies and PRA-designated investment firms with internal model permissions, and it uses a deliberately broad definition of a model, covering any quantitative method turning input into output for use in a decision. A language model inside a decision path meets that definition without needing a special case. An agentic workflow is usually several models plus prompts, retrieval corpora and tool permissions, and every one of those changes its behaviour. So the practical work is to treat them as versioned artefacts with named owners, put the system on the model inventory, and agree its risk classification with the second line before you build. Then design so independent validation is possible: reproducible evaluation sets, recorded provenance, and change control that fires on a prompt change rather than only on a model upgrade. Insurers are outside the formal scope and raise it anyway, because the PRA treats the principles as good practice more widely.

Does DORA cover AI suppliers?

Yes, where the supplier provides ICT services supporting a financial function of an entity in scope, and DORA has applied since 17 January 2025. That brings the AI vendor, and usually the model providers underneath it, into ICT third-party risk management: an entry on the register of information, contract terms covering audit and access rights, conditions on subcontracting, and a documented exit strategy, with a direct oversight regime for designated critical providers on top. UK-only firms are not in scope of DORA itself, and meet similar questions through the operational resilience regime and the critical third parties regime. Exit is the question that actually changes an architecture. If the provider is unavailable, changes its terms, or a supervisor tells you to move, what breaks? Programmes built tightly around one provider's proprietary features have answered that by accident, and badly.

What does Solvency II require of AI in underwriting?

It does not name AI, and it binds it anyway, through governance and through data. The system of governance requires the four key functions to be effective, the ORSA has to reflect the firm's real risk profile, and data used for technical provisions must be accurate, complete and appropriate, with the actuarial function accountable for saying so. If an agent enriches submission data and that enrichment reaches pricing or reserving, someone has to be able to trace every field back to its source, which makes provenance an engineering requirement rather than a documentation exercise. Internal model firms add a model change policy and validation. And using a supplier for a critical or important operational function is outsourcing, with the notification and contractual duties that follow. Tenhaw holds no actuarial capability, and our specialty insurance work is a proof of concept feeding business intelligence, not a rated pricing model.

How does SM&CR affect AI agent deployment?

It requires a named senior manager to be accountable for the outcomes of the function, including those produced by agents. In practice this means the operating model must specify which decisions agents may take autonomously, which require human approval, and who holds accountability at each point, documented before deployment rather than reconstructed after an incident.

All sectors

If the sources do not answer it, a call will.

Talk it through
The rest of the FAQ

1424 questions, grouped by subject

Every question answered anywhere on tenhaw.com sits in one of 51 groups. This is one of them.

All 1424questions, and every group →

Or ask the question directly and skip the categories.

Talk it through
book a call

Still have a question?

A 30-minute discovery call with James Rooney. Bring the question this page did not answer. You'll leave with a rough scope whether you engage us or not.

most start with a fixed-price AI Readiness Audit · £44,000 · 4 weeks · working prototypes

// pick a slot · cal.com/tenhaw/professional-servicesLIVE CALENDAR

Calendar not loading? Open it on cal.com or email hello@tenhaw.com.