Mills Review: enhancing AI governance in financial services

Article

By: Supriya Manchanda, Tim Reid

AI is becoming central to financial services operations, with growing autonomy and limited transparency over how the models work. Supriya Manchanda and Tim Reid examine what the Mills Review means for AI governance and board oversight.
Contents

With greater adoption across the financial services sector, the conversation has swiftly moved from whether to adopt AI, to how to govern it effectively. The FCA recognises this and has published the Mills Review to assess how AI, particularly agentic AI, will reshape retail financial services by 2030. Boards need to review the findings and ensure their AI governance and oversight practices continue to align with the FCA’s evolving expectations. 

New AI regulation isn’t needed

The FCA doesn’t plan to introduce new regulations to manage the risks associated with AI. Instead, it expects boards to manage AI under existing frameworks such as the Senior Managers and Certification Regime (SM&CR), Consumer Duty, and SYSC, which will be adapted over time. As such, Boards need to consider how these frameworks apply to AI use across core operations such as customer service, credit decisioning, fraud detection, compliance monitoring and product design. 

Crucially, responsibility can’t be delegated to algorithms, vendors or specialists. Boards remain accountable for explainability, risk management and effective challenge, even for complex or outsourced systems. 

Article
SM&CR reform – less paperwork, same accountability
Read more
SM&CR reform – less paperwork, same accountability

How the market’s changing 

The Mills Review identified four ways that AI will reshape the market by 2030. Firms will transform their operations as AI takes on a broader range of tasks, with increasing degrees of autonomy. Consumer journeys will shift from human-led to agent-led, changing how people access and act on financial products. Market power and competition will evolve too, as AI capabilities becomes a differentiating factor between firms. Meanwhile, financial crime and cyber security threats and defence capabilities will accelerate. Boards need to keep pace with this transformation to ensure smooth adoption across the market, while ensuring good outcomes for consumers. 

The autonomy spectrum – key implications for AI governance 

The Mills Review views AI adoption through an autonomy spectrum of five human roles, from operator to collaborator, to consultant, approver and observer. At the lower end, AI supports human judgement. At the higher end, AI systems act continuously within set parameters, with humans monitoring outcomes rather than making individual decisions.  

From a governance perspective, this creates a significant challenge. Traditionally, Boards ask management to demonstrate risk management, evidence effective controls and show accountability. But as AI systems become more complex, autonomous and dependent on third-party model providers, management won’t find it as easy to show their workings and Boards may struggle to provide effective challenge.   

Article
Non-financial misconduct – embedding the new rules
Read more
Non-financial misconduct – embedding the new rules

Managing the risks 

Moving forward, Boards need a good understanding of where the firm’s AI use sits on the autonomy spectrum to ensure their AI governance and risk frameworks keep pace. This may require a degree of upskilling to understand the emerging risks from AI and to support effective challenge.  

Boards will have different exposures, according to their individual business models and operating environment, but some key considerations are listed below.  

Outcome evidencing 

As AI systems move from supporting human decisions towards preparing and executing them, firms must demonstrate how good outcomes are delivered, how controls operate and whether consumer understanding, fair value and suitability can still be shown. Boards need to ask management not just what AI is doing, but how the firm knows it is working as intended, and how it will know when it is not. 

Third-party reliance 

Deploying third-party AI models and infrastructure introduces risks that sit partly outside firms’ direct control, including model drift, data bias, hallucinations and emergent behaviours. The Mills Review notes that firms will increasingly require more dynamic approaches to model governance, monitoring and assurance, supported by end-to-end controls across the AI lifecycle. Boards need assurance that management has mapped these dependencies and that adequate controls exist across the full delivery chain.  

Systemic and financial crime risks 

Shared reliance on similar models and infrastructure could generate correlated behaviour and common points of failure across the financial system. AI is also amplifying fraud and cyber risks, making attacks faster, cheaper and more persuasive. Boards need to satisfy themselves that their firms’ defences are keeping pace, and that management is engaging with sector-wide intelligence-sharing and coordination mechanisms. 

Evidencing reasonable steps under SM&CR 

It could also be tricky to evidence reasonable steps under SM&CR. Boards must ensure that individual responsibilities for managing and overseeing these new risks are clear in their firms’ SM&CR documentation. Most, if not all, Senior Manager Function holders will inevitably have some AI oversight responsibilities going forward, which must be clearly set out in their statement of responsibilities. 

Maximing the opportunity 

Looking beyond risk management, Boards also need to maximise the value of AI to help the firm identify, and address, gaps in the market. For example, the Mills Review highlights the link between AI and Consumer Duty, noting that better use of data and personalisation could help address the information gaps that often lead to poor financial decisions. Better consumer outcomes aren't just a regulatory requirement; building customer satisfaction and loyalty are also good for business. 

Similarly, Boards and senior managers who treat AI governance as a genuine priority will continue to align with the FCA’s thinking. This will build trust with the regulator and allow firms to use compliance as a competitive advantage. With no prescriptive rules in place, firms that view this work as a compliance exercise could risk management by crisis instead. 

Article
Corporate governance in financial services
Read more
Corporate governance in financial services

Practical steps for the Board 

In time, these activities will present a stronger blueprint for what good AI implementation looks like. But in the meantime, AI adoption and capabilities are moving fast, leaving many firms’ oversight processes on the backfoot. Board members need to assess how these changes have affected their responsibilities, and how to pivot to an operating environment that’s more complex, more automated and more interconnected than current regulations were designed for. Drawing on the Mills Review's thinking, boards can take five key steps, as outlined below. 

Ask for meaningful management information 

Boards should request regular reporting on AI performance, control effectiveness, model drift and outcomes testing. A report that confirms the use of AI is different from one that confirms it’s working safely and delivering good consumer outcomes. Every board pack should cover what could go wrong, how the board would know, and key activities to remedy it. 

Build sufficient AI literacy 

Board members don’t need a technical understanding of how AI models work, but they do need to know what AI the firm uses, what risks it carries, and the firm's appetite for those risks. Training should reflect each director's role and the firm's specific AI footprint. Without that grounding, boards can’t provide effective challenge.  

Monitor the autonomy spectrum 

Boards should understand where the firm sits across different AI use cases, and where each is heading. Higher autonomy use-cases warrant greater scrutiny, with AI governance frameworks adapted to match. Continuous update cycles call for more frequent review than traditional control testing allows. 

Challenge third-party reliance 

Boards should understand their third-party AI dependencies and how they’re governed. This includes contingency planning for business and operational resilience if a provider changes, degrades or fails. Controls need to extend across the full AI supply chain and not stop at the firm's own systems. 

Apply AI to the three lines of defence 

AI can support all three lines, but it’ll requires stronger evidence of control in each. Boards need to challenge whether second-line risk and compliance functions have the capability to monitor AI-driven activity effectively, and whether internal audit has adapted its methodology to cover AI governance. 

For further information on the Mills Review or AI governance, contact Supriya Manchanda or Tim Reid.