← Research
Research · Question

SM&CR and AI: which senior manager is accountable?

A firm cannot answer a supervisory question about an AI-driven outcome by describing the model. It has to name a person.

Last reviewed: 22 September 2026 · Next review due: 22 September 2027

The FCA has said it will rely on existing frameworks rather than write AI rules, which makes senior manager accountability the most specific AI accountability mechanism in the UK. What reasonable steps means when the system acts on its own. Not regulatory advice, and no enforcement case has yet tested the duty of responsibility against an AI-driven outcome.

Question this page answersAll 887 questions this research covers

In a regulated firm the question of who is accountable for an AI system has an answer the rest of the economy does not have. The Senior Managers and Certification Regime assigns responsibilities to named individuals, and the Financial Conduct Authority has been clear that it does not plan to write separate AI rules: it will rely on the frameworks already in place. That makes SM&CR the most specific accountability mechanism for AI in the UK, and it was designed before any of this.

The answer, in one line

Its published position is that it does not plan to introduce extra regulation for AI and will rely on existing frameworks, naming the Consumer Duty and senior manager accountability among them.

Share as a card

What the regulator has actually said#

The FCA's published position is that it will not introduce extra regulation for AI and will rely on existing frameworks, naming the Consumer Duty and senior manager accountability among them. That is a deliberate choice rather than a gap waiting to be filled, and firms hoping for an AI rulebook that resolves the ambiguity should plan on the basis that one is not coming.

The practical consequence: a firm cannot answer a supervisory question about an AI-driven outcome by describing the model. It has to name the senior manager within whose responsibilities the outcome sat, and show what reasonable steps that person took.

The question that has no default answer#

Where an AI system sits inside a business process, the responsibility usually follows the process rather than the technology. The senior manager accountable for the lending decision is accountable for it whether it was made by a credit committee or by a model. That sounds clean until three situations arrive, and all three are now common.

A system is procured by one function, operated by another and produces outcomes in a third. A general-purpose assistant is used across every function with no owner at all. And an agent takes a sequence of actions in which no single step looks like the decision. In each case the process no longer has one obvious owner, and the regime still requires one.

The firms that handle this well tend to have done one unglamorous thing: written down which outcomes the system determines, and mapped each to an existing senior management function rather than inventing a new one. The firms that handle it badly have a model inventory, which lists systems rather than outcomes and therefore maps to nobody.

Reasonable steps, when the thing acts on its own#

The duty of responsibility turns on whether a senior manager took the steps a reasonable person in that position would take to prevent a breach. Applied to a system that acts continuously, that phrase asks some awkward questions a firm is better off answering in advance.

Could you have known? A system with no logging, or with logging nobody reads, makes it hard to argue that anything was being overseen. Could you have stopped it, and would you? A stop that has never been rehearsed is a plan rather than a control, and the distinction matters more in a regulated firm than anywhere else: how to design a stop button people will use. And could your people have caught it? Oversight by a team that no longer performs the underlying task unaided is oversight in name, which is the argument at human in the loop is not a safeguard and the risk described at capability debt.

Four things to establish before the supervisor asks#

Which customer or market outcomes are determined by a system without a person deciding, and which senior management function each one maps to. Who can stop each system, how long a stop takes, and when it was last rehearsed. What evidence exists that oversight happened, as distinct from oversight having been assigned. And what the firm's definition of an AI incident is, written before there is one: what counts as a serious AI incident.

None of these is a model risk question, and a firm that routes all four to model risk management has answered a different question well.

Where the board sits in this#

SM&CR is an individual accountability regime and the board's job is not to absorb that accountability but to test it. The useful board question is not whether the firm has AI governance but whether a named individual could describe, without preparation, the outcomes their systems determine and the steps they take over them. What a board should be shown each meeting is set out at what management should report to the board about AI, and the wider argument is at board oversight of AI.

What this does not show#

This page is not regulatory advice and a firm should take its own. It describes how an existing regime meets a new technology rather than reporting any FCA determination about AI: no enforcement case has tested the duty of responsibility against an AI-driven outcome, so how a supervisor would weigh reasonable steps in that context is unknown. The FCA's stated approach, that it will rely on existing frameworks rather than write AI rules, was its published position in 2026 and positions change. Nothing here is specific to any firm's permissions, and the mapping of outcomes to senior management functions depends on a firm's own statements of responsibility.

Essay · SS-2026-293

Cite this page

Hirji, R. (2026). SM&CR and AI: which senior manager is accountable?. The SuperSkills evidence base, SS-2026-293. https://thesuperskills.com/research/smcr-and-ai-which-senior-manager-is-accountable. Last reviewed 22 September 2026.

An evidence review by Rahim Hirji, not peer-reviewed research. For a material claim, cite the underlying study as well; every study here carries its own permanent link.

How citations and IDs work
Questions answered on this page

Is the FCA writing new rules for AI?

Its published position is that it does not plan to introduce extra regulation for AI and will rely on existing frameworks, naming the Consumer Duty and senior manager accountability among them. Firms waiting for an AI rulebook that resolves the ambiguity should plan on the basis that one is not coming.

Who is accountable when an AI system produces a bad outcome?

Responsibility usually follows the business process rather than the technology, so the senior manager accountable for a lending decision is accountable whether it was made by a committee or a model. That breaks down where a system is procured by one function, operated by another and produces outcomes in a third, where a general-purpose assistant has no owner, or where an agent takes a sequence of actions in which no single step looks like the decision.

What does taking reasonable steps mean for an AI system?

In practice it raises three questions: could you have known, which depends on logging that someone actually reads; could you have stopped it and would you, which depends on whether the stop has ever been rehearsed; and could your people have caught it, which depends on whether the team still performs the underlying task unaided.

Is an AI model inventory enough?

No. An inventory lists systems, and accountability attaches to outcomes. The more useful artefact is a list of the outcomes each system determines without a person deciding, mapped to an existing senior management function.

In this hub

Judgement, oversight and accountability

Who decides, who checks, and who is answerable when the machine was involved.

Ask the evidence
What does the evidence actually show?What should our board be asking about this?Where does Rahim disagree with the consensus?
Bring this into your organisation

If this describes something happening in your teams, say so.

Keynotes, board sessions and advisory work, drawing on research across more than 200 organisations in 30 countries. Tell me the room, the date and the shift you need. A reply within 24 hours.

Start a conversation

Topics and audiences  ·  All research

Accountability under the regime attaches to a person, and AI makes it genuinely hard to say which person. Naming it, decision by decision, and recording why, is the work. If your senior managers can already each say which AI-assisted decisions sit in their statement of responsibilities, this is done. Board advisory.

This argument is one a board usually meets for the first time in the room. There is the boards and leadership version, and the full range of topics and audiences.

These questions are one of a set. Arranged for a board, with what each one is trying to establish: board oversight of AI. If the board would rather have the argument in the room than on a page, there is a board away day, and AI fluency for boards and leaders for the directors who want to be able to read the paper themselves.

Box of Amazing

Rahim’s free weekly letter on AI and human capability

If this was useful, the weekly letter is where the thinking happens first. Most of what ends up on this site starts there. Weekly essays on AI, capability and the future of work. Read by 25,000 people, every week since 2017. Free, and one click to stop.

Opens Substack to confirm. No pitch in it, unsubscribe in one click, and nobody follows up because you read something.