In a regulated firm the question of who is accountable for an AI system has an answer the rest of the economy does not have. The Senior Managers and Certification Regime assigns responsibilities to named individuals, and the Financial Conduct Authority has been clear that it does not plan to write separate AI rules: it will rely on the frameworks already in place. That makes SM&CR the most specific accountability mechanism for AI in the UK, and it was designed before any of this.
The answer, in one line
Its published position is that it does not plan to introduce extra regulation for AI and will rely on existing frameworks, naming the Consumer Duty and senior manager accountability among them.
What the regulator has actually said#
The FCA's published position is that it will not introduce extra regulation for AI and will rely on existing frameworks, naming the Consumer Duty and senior manager accountability among them. That is a deliberate choice rather than a gap waiting to be filled, and firms hoping for an AI rulebook that resolves the ambiguity should plan on the basis that one is not coming.
The practical consequence: a firm cannot answer a supervisory question about an AI-driven outcome by describing the model. It has to name the senior manager within whose responsibilities the outcome sat, and show what reasonable steps that person took.
The question that has no default answer#
Where an AI system sits inside a business process, the responsibility usually follows the process rather than the technology. The senior manager accountable for the lending decision is accountable for it whether it was made by a credit committee or by a model. That sounds clean until three situations arrive, and all three are now common.
A system is procured by one function, operated by another and produces outcomes in a third. A general-purpose assistant is used across every function with no owner at all. And an agent takes a sequence of actions in which no single step looks like the decision. In each case the process no longer has one obvious owner, and the regime still requires one.
The firms that handle this well tend to have done one unglamorous thing: written down which outcomes the system determines, and mapped each to an existing senior management function rather than inventing a new one. The firms that handle it badly have a model inventory, which lists systems rather than outcomes and therefore maps to nobody.
Reasonable steps, when the thing acts on its own#
The duty of responsibility turns on whether a senior manager took the steps a reasonable person in that position would take to prevent a breach. Applied to a system that acts continuously, that phrase asks some awkward questions a firm is better off answering in advance.
Could you have known? A system with no logging, or with logging nobody reads, makes it hard to argue that anything was being overseen. Could you have stopped it, and would you? A stop that has never been rehearsed is a plan rather than a control, and the distinction matters more in a regulated firm than anywhere else: how to design a stop button people will use. And could your people have caught it? Oversight by a team that no longer performs the underlying task unaided is oversight in name, which is the argument at human in the loop is not a safeguard and the risk described at capability debt.
Four things to establish before the supervisor asks#
Which customer or market outcomes are determined by a system without a person deciding, and which senior management function each one maps to. Who can stop each system, how long a stop takes, and when it was last rehearsed. What evidence exists that oversight happened, as distinct from oversight having been assigned. And what the firm's definition of an AI incident is, written before there is one: what counts as a serious AI incident.
None of these is a model risk question, and a firm that routes all four to model risk management has answered a different question well.
Where the board sits in this#
SM&CR is an individual accountability regime and the board's job is not to absorb that accountability but to test it. The useful board question is not whether the firm has AI governance but whether a named individual could describe, without preparation, the outcomes their systems determine and the steps they take over them. What a board should be shown each meeting is set out at what management should report to the board about AI, and the wider argument is at board oversight of AI.
What this does not show#
This page is not regulatory advice and a firm should take its own. It describes how an existing regime meets a new technology rather than reporting any FCA determination about AI: no enforcement case has tested the duty of responsibility against an AI-driven outcome, so how a supervisor would weigh reasonable steps in that context is unknown. The FCA's stated approach, that it will rely on existing frameworks rather than write AI rules, was its published position in 2026 and positions change. Nothing here is specific to any firm's permissions, and the mapping of outcomes to senior management functions depends on a firm's own statements of responsibility.
Essay · SS-2026-293
Hirji, R. (2026). SM&CR and AI: which senior manager is accountable?. The SuperSkills evidence base, SS-2026-293. https://thesuperskills.com/research/smcr-and-ai-which-senior-manager-is-accountable. Last reviewed 22 September 2026.
An evidence review by Rahim Hirji, not peer-reviewed research. For a material claim, cite the underlying study as well; every study here carries its own permanent link.
How citations and IDs work