Skip to main content
ISO 42001

ISO 42001 for UK Financial Services: FCA Expectations, Consumer Duty, and Automated Decisioning

By Alfred Obeng, Founder, Goldline Consultancy

ISO 42001 Lead Implementer (PECB) · ISO 42001 Lead Auditor (PECB) · ISO 27001 Senior Lead Implementer (PECB) · ISO 27001 Lead Auditor (PECB) · CISSP · PMP

10 min read

Contents

    A Head of Compliance at a UK lending firm described her quarter recently in three items. The FCA had raised AI in a supervisory conversation and asked how the firm oversees its models. An institutional client had sent a due diligence pack with a new AI governance section. And the board, having read a press story about algorithmic lending decisions, had asked what the firm's position was.

    Three questions, three audiences, three deadlines. She answered them separately, because they arrived separately. The three answers did not match.

    That is the pattern worth naming before anything else. These are not three questions. They are one question arriving through three doors: can this firm demonstrate that it governs the AI systems making or influencing decisions about customers. A firm that answers each door on its own terms produces inconsistent material, and inconsistency is precisely what a supervisor, a client's risk function, and a board audit committee are all trained to notice.

    Three questions arriving at the same time

    The supervisory question tends to be open. What AI are you using, who owns it, and how do you know it is working as intended. It is rarely a formal information request at first, which lulls firms into answering informally.

    The client due diligence question is narrower and more mechanical. It asks for documents: a policy, an inventory, a risk assessment, evidence of oversight. It is scored, and a weak answer costs commercial ground rather than regulatory ground.

    The board question is about exposure. If this goes wrong, who is accountable and what protects us. It is the only one of the three that asks about people rather than systems.

    A single governed management system answers all three from the same evidence base. Three separate exercises produce three documents that contradict each other on scope, ownership, and risk rating, and the contradiction surfaces at the worst possible moment.

    What the FCA has actually said

    The FCA's stated position has been that it does not intend to introduce a separate AI rulebook, and that its existing frameworks already apply to firms' use of AI. Firms should verify the current position, since regulatory approaches in this area have been evolving, but the direction has been consistent: AI is supervised through the regimes already in place rather than through new AI-specific rules.

    That is a lighter regulatory touch in form and a heavier one in substance. There is no checklist to complete. Instead, everything a firm is already accountable for continues to apply when the work is done by a model rather than a person. Treating customers fairly applies. Governance and controls expectations apply. Operational resilience expectations apply. Outsourcing and third party risk expectations apply to a vendor model in the same way they apply to a vendor process.

    The practical consequence is straightforward. The firm is accountable for the outcomes its AI systems produce. "The model decided it" is not a defence, and neither is "the vendor built it". Where a supervisor asks how a decision was reached and the firm cannot answer, the failure is a governance failure, not a technical one.

    Consumer Duty and automated decisioning

    Consumer Duty requires firms to deliver good outcomes for retail customers and to avoid causing foreseeable harm. It is an outcomes regime, which means the evidence it demands is outcome evidence.

    Where an AI system influences pricing, creditworthiness or affordability, product eligibility, claims handling, collections treatment, or customer communications, the firm has to be able to show that the outcomes are good across the customer base, including for customers with characteristics of vulnerability.

    Here is the practical difficulty. Demonstrating good outcomes from a model requires monitoring the outcomes, segmented in a way that would reveal a problem if one existed. Most firms monitor model performance, which is a different thing. Accuracy, drift, and stability tell you the model is behaving consistently. They do not tell you whether the customers on the wrong side of a threshold are receiving a good outcome.

    Firms that have not built outcome monitoring find themselves reconstructing it retrospectively when asked, from data that was never structured for the question. The reconstruction is slow, contestable, and thin. Building the monitoring before it is requested is materially cheaper than building it under a deadline.

    Senior manager accountability

    Under the Senior Managers and Certification Regime, named individuals hold personal accountability for the areas within their prescribed responsibilities. Where an AI system operates inside a senior manager's remit, that accountability sits with the individual. It does not transfer to the model, to the data science function, or to the vendor that supplied it.

    This is where AI governance stops being an abstraction. A senior manager asked to attest to the oversight of a system they did not build, cannot inspect, and receive no regular reporting on is exposed in a way that no amount of technical assurance resolves.

    A documented AI governance structure resolves it by answering the questions the regime asks. Who is accountable for this system. What decisions were escalated to them and when. What information do they receive, at what cadence, and is it sufficient to notice a problem. What authority exists to suspend or override the system, who holds it, and has it ever been exercised.

    Those are governance artefacts, not engineering artefacts. They are also exactly what a senior manager needs in front of them when the question arrives.

    Where the AI actually sits in a financial services firm

    Inventory work in a regulated firm reliably finds more than the firm counted. The categories to look through:

    Credit and affordability decisioning, including scorecards that have been quietly upgraded to machine learning. Pricing and underwriting models. Fraud and financial crime detection, including transaction monitoring and sanctions screening tuning. Customer service automation, chat, and call summarisation. Marketing, segmentation, and next best action. Document processing and identity verification. Investment, portfolio, and advice-adjacent tooling.

    And the category most firms miss entirely: vendor-supplied models embedded in core platforms. The core banking system, the collections platform, the CRM, the KYC provider, the claims system. Each may contain models the firm does not think of as its own AI, because nobody procured them as AI. They were features in a product. They still make decisions about customers, and the firm still owns the outcomes.

    What ISO 42001 evidences

    ISO 42001 specifies an AI management system. Implemented properly in a regulated firm, it produces a defined set of artefacts:

    An AI system inventory the firm can put in front of a supervisor without editing it first. Documented accountability mapped to named roles, which is the artefact SM&CR conversations need. A risk methodology that covers model risk, data risk, and outcome risk rather than forcing AI risk into a confidentiality, integrity, and availability shape it does not fit. Human oversight arrangements with documented authority to override, including what information the overseer receives. Monitoring of model performance and customer outcomes over time, with defined thresholds and a route from a breached threshold to a decision. Third party AI governance covering vendor-supplied models, including what the vendor has told you about training data and what it has not.

    State the limit plainly, because it is the most important sentence here. ISO 42001 certification is not regulatory compliance. The FCA does not recognise it, does not require it, and holding a certificate does not discharge any obligation under the Handbook. Its value is different: it is independent evidence that a governed system exists and operates, produced in a form that supervisors, clients, and boards all accept as structured rather than improvised.

    Where firms are exposed

    Four gaps come up repeatedly.

    Vendor models operating inside core platforms with no governance wrapper. The firm has an outsourcing assessment covering the supplier's security and resilience, and nothing covering the model's behaviour, its training data, or what happens when the vendor retrains it without notice.

    No outcome monitoring, so Consumer Duty evidencing is retrospective and thin. The firm can describe its intent and its controls. It cannot show the outcome distribution across customer segments over the last twelve months.

    Model documentation held by the data science team in a form no supervisor would accept. Notebooks, experiment logs, and a model card written for internal engineers. The information may all be there. It is not evidence until it is structured, approved, and versioned.

    No documented human oversight, so override authority is assumed rather than defined. Ask who can stop the model and the answer is usually a name, offered with hesitation, and no record of the authority ever having been granted.

    Sequencing for a regulated firm

    Most FCA-regulated firms already hold ISO 27001 or an equivalent control framework. That matters, because the AI management system layers onto the same management system spine: the governance forum, the policy approval route, the risk methodology, the internal audit programme, and the management review cadence already exist and need extending rather than rebuilding.

    The sequence that works:

    Inventory and classify first. This is not a formality. Firms consistently discover more AI than they counted, and the classification determines the size of everything that follows. Then the risk methodology, extended with an AI risk taxonomy that a model risk specialist and a compliance officer can both use. Then the controls, prioritised by the risk classification rather than by the order of the Annex. Then certification, if and when the commercial or supervisory case supports the cost.

    Firms that reverse this, starting with a certification date and working backwards, tend to certify a scope narrow enough to pass and too narrow to answer the three questions that started this article.

    An AI governance readiness assessment produces the inventory, the risk classification, and the board-ready roadmap that the supervisory question, the client due diligence question, and the board question all draw on. One evidence base, three consistent answers. Book a scoping call.

    Alfred Obeng

    Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.

    Related reading

    We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.