TL;DR

HM Treasury has published its Financial Services AI Adoption Plan, written by Starling Bank’s group chief information officer Harriet Rees together with Rohit Dhawan, who heads analytics and AI work at Lloyds. Four recommendations stand out: an industry-run voluntary assurance scheme for externally supplied AI, sector-wide sharing of incidents and near misses, tighter oversight of the most important AI and cloud vendors, and scenario exercises spanning multiple sectors.

Beyond testing the model

The plan’s central move is to push assurance past model performance. Firms may have to show not only that a system behaves within agreed limits, but that the rules and internal policies shaping its decisions have been converted into logic that can be tested consistently. The document frames the difficulty as one of accessibility and consistent application rather than any shortage of regulatory support.

Calvern James, who runs the UK arm of Rulemapping Group, posted that the governance problem sits above the model entirely. Firms are pouring money into approval processes, bias controls and monitoring, he noted — then asked whether the regulatory reasoning behind the decisions those systems inform gets anything like the same scrutiny. He set out three layers needing to connect: a model’s technical capability, the boundaries an institution places on it, and the evidence that outcomes actually followed approved reasoning.

That distinction bites hardest in credit decisions, fraud detection, customer support and payments, where a technically correct output can still breach the rules if whoever built the process read the underlying policy wrongly.

Third parties and agentic payments

A proposed assurance framework covering third-party AI would let accredited assessors judge external models against agreed standards, potentially working much like a SOC 2 audit protocol. Certification would not transfer responsibility: a model passing a common standard can still behave differently once wired into one bank’s data and workflows.

For agentic payments, the recommended trust framework rests on three things — legal accountability, Know Your Agent checks, and authentication between machines. Testing teams would need repeatable validation covering transaction ceilings, consent, revocation and human intervention.

Looking forward

A 2024 survey by the Bank of England and FCA found three quarters of responding financial firms already using AI, with the typical firm expecting its use cases to more than double inside three years. This lands days after Andrew Bailey told banks to demonstrate AI resilience through testing, and alongside a Moody’s warning about dependence on a handful of model and cloud providers. The direction is consistent: UK financial regulators keep converting AI adoption into an evidence obligation.