For all the discussion about artificial intelligence in financial services, perhaps the more interesting question is not whether firms will use it, because increasingly that feels inevitable, but whether the governance and assurance surrounding its use is evolving at the same speed.
The Mills Review is important in this respect because it reflects a regulatory conversation that is beginning to move beyond whether AI should be permitted and towards the much harder question of how organisations remain accountable for decisions when technology becomes an increasingly important part of making them.
For lenders this matters enormously. Financial services has spent decades building compliance and audit frameworks around processes that were largely designed, operated and supervised by people. Policies were written, authorities established, samples reviewed and decisions tested against an understood set of rules. Even where technology was involved, there was usually a reasonably clear distinction between the system that processed information and the individual ultimately responsible for interpreting it.
AI begins to blur that distinction as models might identify patterns, prioritise cases, interpret documentation, highlight anomalies or increasingly contribute to a recommendation. None of this necessarily removes human responsibility, but it does change what an auditor or compliance function needs to understand in order to determine whether the resulting decision was appropriate.
Technology can make decisions more consistent without necessarily making them better, and that is a fact that is likely to become increasingly important for compliance teams.
The question is no longer simply whether the correct process was followed but whether we understand how the process reached the answer in the first place, and that changes our notions of assurance in a process.
Traditional audit has often relied upon sampling historic decisions and checking them against policy. That remains important, but an AI-enabled environment arguably requires something more continuous. Firms need to understand what information models are using, whether that information remains appropriate, how outcomes are changing over time and whether seemingly rational decisions are beginning to produce unintended consequences.
Importantly, this is not simply a technology issue because a perfectly functioning model can still produce the wrong outcome if it is trained on inappropriate information or asked the wrong question. Equally, a model may consistently apply a policy that itself creates an undesirable customer outcome. Technology can make decisions more consistent without necessarily making them better, and that is a fact that is likely to become increasingly important for compliance teams.
Human decision-making has always contained inconsistency and AI offers the possibility of reducing some of it, but consistency creates its own challenge because an error can now be repeated thousands of times rather than occurring occasionally. Experienced underwriters bring judgement, context and sometimes an entirely appropriate degree of discretion to a case. In this example, it’s easy to see how quickly scale changes the nature of compliance risk.
It also changes the importance of governance because firms need to be able to demonstrate who owns an AI-enabled process, who is responsible for challenging it, what happens when its behaviour changes and where human intervention remains necessary. Somebody must still be accountable for the outcome.
This is where, I suspect, the implications of the Mills Review may prove more profound than another layer of AI regulation. The direction of travel appears to recognise that financial institutions will increasingly use these technologies and that attempting to prescribe every possible application is unlikely to work. Responsibility consequently moves back towards firms themselves and towards their ability to demonstrate effective governance, oversight and judgement.
For boards, risk committees, compliance teams and internal auditors, that means AI cannot simply sit within the technology function because if it influences customer outcomes, credit decisions, affordability assessments, servicing, collections or communications then it becomes part of the organisation’s risk and control environment and needs to be treated accordingly.
Audit will therefore need to evolve from asking whether the system did what it was supposed to do towards asking whether what it was supposed to do remains appropriate, which requires a different type of assurance. It means looking not only at individual decisions but at patterns of decisions, understanding changes in data and behaviour, and testing whether controls continue to work as models, markets and customers change.
AI may ultimately make some forms of decision-making easier to audit rather than harder, especially where human judgement can be remarkably difficult to reconstruct. We can record the outcome and perhaps the rationale, but unconscious assumptions, inconsistencies and individual interpretation are much harder to identify retrospectively. Properly governed technology creates data, patterns and evidence that can be interrogated at scale.
The opportunity is therefore not simply to control AI but to use the transparency it can create to improve assurance more broadly. Technology is exceptionally good at consistency and increasingly good at identifying patterns, but wisdom, context and the willingness to challenge an apparently logical answer remain human responsibilities.
The institutions that navigate this successfully will not be those that choose between people and technology. They will be those that understand what each is good at and construct their governance accordingly. For lenders, the next stage of AI adoption therefore needs to be accompanied by an equally serious conversation about assurance. The question for compliance and audit is no longer whether AI is coming into the decision-making process but whether the controls around it are ready when it does.





