What the FCA Actually Expects From Your AML AI Models

What is AI model governance in AML?
Model governance is the evidence a firm can produce that any AI system materially influencing a compliance decision was validated before deployment, operates within documented parameters, is monitored on an ongoing basis, and produces outputs that can be traced back to a specific decision. It is not a vendor contract clause or an ISO certificate filed away by procurement. It is an operational capability the firm must be able to demonstrate on demand.

Deploying AI in an AML workflow is not the same as governing it. Most regulated firms have done the first. Very few have done the second in a way that would hold up to regulatory scrutiny. The gap is not between what the regulator wants and what firms know about. It is between what firms believe they have implemented and what they have actually implemented.

Is deploying AI in an AML workflow the same as governing it?

No. Deployment means the system is running and producing outputs. Governance means the firm can prove, for any decision the system influenced, that it was validated before deployment, monitored since, and reviewed by a qualified person before that decision was made. Most firms have the first. Few can fully evidence the second.

What the FCA Actually Expects

The FCA’s Financial Crime Guide makes clear that systems and controls used to detect and investigate financial crime must be appropriate to the nature and scale of the firm’s activity. Where AI systems are influencing alert generation, risk scoring, or investigation outcomes, the firm must be able to demonstrate those systems are fit for purpose and that it understands how they reach their outputs. The FCA’s Feedback Statement on AI and Machine Learning (FS23/6) reinforces this, noting that firms deploying AI in regulated activities must maintain governance frameworks that include model documentation, validation, and human oversight. For AML specifically, this expectation has been live for some time.

The SMCR Angle Most MLROs Have Not Fully Addressed

There is an accountability dimension to AI model governance that is specific to SMCR-regulated firms, and it is one that many MLROs have not yet fully worked through.

Under the Senior Managers and Certification Regime, the MLRO is personally accountable for the adequacy of the firm’s AML systems and controls. Where AI systems are embedded in those controls, influencing which alerts are generated, how customer risk is scored, or what investigation guidance is applied, the MLRO’s accountability extends to those systems.

The practical question is pointed: if the FCA asked your MLRO to explain, in detail, how a specific AI-influenced investigation decision was reached, could they identify which model produced the input, confirm it was validated and operating within its documented parameters, and show that a qualified person reviewed the output first? For many firms, the honest answer is no, not because the MLRO is negligent, but because the AI tools in use were procured and deployed without the governance infrastructure required to make that answer yes.

An MLRO who cannot answer that question is carrying regulatory risk they may not have formally accepted. The named-accountability structure is a UK feature, but it is not a uniquely UK problem: compliance officers under US, EU and Middle East AML frameworks carry an equivalent version of this exposure whenever an unaudited AI system sits inside a control they are personally answerable for.

What Explainability Requires Operationally


What does explainability actually require, in practice?

Explainability is not a general description of how the model works, appended to a vendor contract or filed in a compliance policy. It is an operational capability: the ability to trace the basis for any compliance decision back through the AI-generated input that contributed to it, including which system generated the flag, what data it used, and what a qualified human reviewer did with the output. The audit trail must be decision-level, not model-level. Firms most often go wrong here by mistaking a vendor’s technical explanation of the model for the firm’s own evidence that a specific decision was properly reviewed.

Operational test: Can your investigation system produce, for any closed case, a complete record of which AI outputs were surfaced to the investigator, what the review noted, and the documented basis for the final decision? If that chain breaks at the AI output stage, the audit trail is incomplete, and that is the question a skilled FCA supervisor will ask.

What Genuine Model Governance Requires

RequirementWhat it means in practice
Model inventoryDocumented purpose, inputs, outputs and known limitations for each AI component
Independent validationTesting by a function independent of the deploying team, across the firm’s actual customer population, including low-frequency typologies
Ongoing performance monitoringDefined metrics with thresholds that trigger review, not a one-off sign-off at go-live
Human oversight at the decision pointA documented review that can be demonstrated, not a checkbox
Case-level rationale trailAI outputs linked to human review linked to the final decision, for every case

Most firms can evidence some of these. Few can evidence all of them. It is the completeness of the framework, not the presence of individual elements, that determines whether model governance is genuinely in place.

The EU AI Act, and Why This Is Not Only a UK Question


Does the EU AI Act matter if a firm only operates in the UK?

Only if that firm has no EU operations, EU-facing customers, or EU-regulated counterparties at all, which is rare in practice. For most UK firms with any EU exposure, the Act already applies, and it previews the direction the FCA itself is moving in.

The EU AI Act classifies AI systems used to assess credit risk, determine access to financial services, and conduct risk assessments of individuals in regulated contexts as high-risk under Annex III. AI models used in AML risk scoring and investigation triage sit squarely within this frame for firms with EU operations or EU-facing customer activity, and are subject to human oversight provisions, transparency and documentation obligations, and logging of outputs for the operational lifetime of the system.

UK firms operating in the EU are already within scope. US firms face their own version of this pressure through federal banking regulators’ model risk management expectations (SR 11-7 and its successors), and Middle East regulators, including the UAE Central Bank, have been building comparable AI governance requirements into their own supervisory frameworks. FATF’s guidance on AI in AML/CFT identifies human oversight and explainability as prerequisites for responsible AI deployment, treating these as standards the international regulatory community already expects. Treating AI governance as someone else’s concern, whichever regime a firm sits under, is a short shelf-life position.

The Gap Between Belief and Reality

The practical problem is that many firms have moved faster on AI deployment than on AI governance. A vendor tool was procured, integrated, and is now in use, with a reference to model validation somewhere in the procurement file and an ISO certificate the CISO signed off. That is not model governance for AML purposes.

The Bank of England and FCA’s joint survey on machine learning in financial services found that governance frameworks have lagged behind deployment pace, with gaps in model documentation, ongoing performance monitoring, and escalation protocols most commonly identified. FCA supervisory attention on model risk in financial crime has increased materially since 2023, and its Artificial Intelligence and Machine Learning policy position signals a regulator moving toward formal model risk expectations, not away from them.

For financial institutions using AI in AML workflows, the question is not whether the regulator will scrutinise model governance. It is whether they will find something defensible when they do. The time to build that infrastructure is before the supervisory review, not during it.

At TechnoXander, our AML Investigation Intelligence Platform is built with traceable investigative rationale and documented human oversight at every decision point, so that model governance is a feature of the system, not a retrospective exercise. Speak to our team to understand what audit-ready AI governance looks like in an investigation workflow.

About Author:

Sonal Bomb, CEO of TechnoXander, professional portrait highlighting leadership, innovation, and company vision.

Sonal Bomb

Sonal Bomb specialises in payments regulation, fraud prevention, and compliance frameworks across the UK and EU. She works closely with banks and PSPs on implementing Verification of Payee (VoP), Confirmation of Payee (CoP), and Open Banking requirements, translating evolving regulatory mandates into practical payment infrastructure.

VoP • CoP • Open Banking • PSD2/PSD3 • Payment Fraud Prevention • FiDA

LinkedIn Profile
Tags :
Social Share with Tooltip

Related Post

What the FCA Actually Expects From Your AML AI Models

What the FCA Actually Expects From Your AML AI Models

What is AI model governance in AML? Model governance is the…

Rules Know the Last Crime. Investigators Need to Understand the Next One.

Rules Know the Last Crime. Investigators Need to Understand the Next One.

What is AML typology recognition? AML Typology recognition is the process…

Your AML Business Case Has a Missing Layer (and It’s the One That Gets You Fined)

Your AML Business Case Has a Missing Layer (and It’s the One That Gets You Fined)

What is the business case for AML investigation AI? A complete…