Home / Boards / Financial services boards
The Boards sectionBoards · Oversight · Sessions · Fluency · The Twelve · Board questions
By regime · financial servicesFinancial services is the one sector where the accountability question is already answered on paper. Under the Senior Managers and Certification Regime a named individual holds responsibility for a function, personally, in writing. The Consumer Duty asks firms to deliver good outcomes for retail customers and to be able to evidence that they have. Neither says anything about artificial intelligence, and the FCA has said it does not plan to introduce extra regulations for AI and will rely on existing frameworks.
Rahim Hirji advises chief executives, boards and leadership teams, in person worldwide and online. He is an independent advisor on AI and human judgement, the author of SuperSkills (Kogan Page, 2026), and has run, grown, bought and advised businesses with AI in them. He also speaks, to senior rooms rather than conferences. He founded the skills platform EtonX, later acquired by Eton College, and led Quizlet’s international growth across more than 60 countries.
Published, broadcast and bylinedPublished by Kogan Page, part of Hachette UK · On air with the BBC, 11 appearances across three months in 2026, including the World Service and Radio 5 Live · Bylined in The Observer and The European Business Review · The record
SM&CR puts a name against a function. That is a stronger starting point than most sectors have, and financial services boards tend to arrive at this conversation further along than boards elsewhere.
The Consumer Duty asks for outcomes and for evidence of them, which is the same shape of obligation: not that you had a process, but that it worked. Relying on existing frameworks rather than writing new ones is a deliberate regulatory choice, and it means the existing frameworks have to carry weight they were not designed for.

A senior manager is accountable for a model-assisted decision. The regime does not ask whether that person, or anyone reporting to them, could recognise a plausible wrong output before it reached a customer. It does not ask how often anyone has overridden the model, or what happened to the person who did.
The awkward version of the question, and the one a risk committee should put: if a model-assisted decision went to the Ombudsman, who reconstructs the reasoning, from what, and how long does it take? Which senior manager is accountable sets that out.
Which customer-facing or capital-relevant decisions now have a model in the chain. Which SM&CR function each of those sits under. Whether the named individual has ever seen an output from it that they judged wrong, and what they did.
And one question that is cheap to ask and unusually informative: how many overrides were recorded last quarter? A rate of zero on a system making thousands of decisions is not evidence that the system is right.
I do not write AI risk registers, map controls against the EU AI Act, run conformity assessments, build governance frameworks or draft committee papers. Firms that do that work properly exist and several of them are very good. This is the question those exercises leave open: whether the people named in your framework could actually detect a wrong answer, whether anyone has ever overridden a system, and what the organisation could still do if it stopped.
Regulatory position last checked: September 2026. If you are reading this much later, check the dates before you rely on them.
It covers the function, and the function does not change because a model is doing part of it. A named senior manager remains accountable. What the regime does not establish is whether that accountability is operable: whether the person, or their team, could detect a wrong output in time to act on it.
It has said it does not plan to introduce extra regulations for AI and will rely on existing frameworks. That is a live position rather than a permanent one, and this page carries a check date for that reason.
No. Model risk management is a discipline with its own specialists, and this is not it. This is the human half: whether the people your model risk framework names as the check could operate as one.
The regime differs in detail and the question does not. Wherever a named individual is accountable for an outcome a model helped produce, the same four things have to be establishable: what the model does, who checks it, how often they disagree, and what happens if it stops.
A reply within 24 hours, and a conversation before anything is proposed.
Enquire or email rahim@thesuperskills.com
The argument is at board oversight of AI, the twelve questions are at what a board should ask about AI, and the offer is at board advisory. The parent page for all of this is AI keynote speaker. Browse every topic, audience and region, or take the speaker pack to whoever is running the day. Every engagement delivered so far, with the dates checkable at each organiser, is at the speaking record.
If this was useful and you want a small amount of it each week, that is what the letter is for. Weekly essays on AI, capability and the future of work. Read by 25,000 people, every week since 2017. Free, and one click to stop.
Opens Substack to confirm. No pitch in it, unsubscribe in one click, and nobody follows up because you read something.
Running an event, or responsible for how AI arrives in your organisation? Keynotes · Advisory · Boards · Enquire