Financial services, FCA and PRA
The rules already applied. That is the hard part.
There is no separate AI rulebook to comply with, which sounds like relief and is not. It means AI has to be governed inside SYSC, inside operational resilience and inside Consumer Duty, using the framework you already have.
In short
For FCA and PRA regulated firms, EPX Intelligence extends the management system you already run so it covers AI: policy, risk and impact assessment on your existing methodology, the technical controls, and the evidence pack an assessor or a counterparty will ask for. Where you hold ISO/IEC 27001 already, most of the structure carries across and we work the delta.
What is driving it
Four pressures, none of them new legislation.
That is what makes this awkward. There is nothing to point at and comply with, so the work is inside frameworks your compliance lead already owns.
SYSC 13.7 and security governance
Expectations around managing technology and security risk have to be evidenced. ISO/IEC 27001 is the recognised way to do it, and AI now sits inside that same expectation rather than beside it.
Operational resilience
Important business services, impact tolerances and third party dependency. An AI system inside a critical process is a resilience question the moment it is switched on.
Consumer Duty outcomes
If AI touches advice, suitability or client communications, you need to show it supports good outcomes and that a human remains accountable for the judgement.
In your language
Your existing management system is the asset here. Most firms underestimate how much of the work it has already done.
If you hold ISO/IEC 27001, your scope statement, risk methodology, document control, internal audit programme, management review cycle and corrective action process all carry straight over to AI. What is genuinely new is the AI system inventory, the AI specific impact assessment, the model lifecycle controls and the third party model considerations.
The trap is running two systems. Firms that treat AI governance as a separate register and a separate review end up maintaining neither properly. One register, one review cycle, one owner.
The second trap is the personal data question. In an ungoverned rollout the material at risk is usually client personal data rather than intellectual property, which puts UK GDPR underneath the AI question rather than beside it.
This is general information rather than regulatory advice, and your compliance lead should form their own view on the position. What we bring is the technical delivery behind whatever they decide.
What you get asked, and what answers it
The question, and the document behind the answer.
Every row is something a client, an insurer or an assessor has put in writing to a firm like yours. The right hand column is what we produce so the answer is a document you can attach.
| What you are asked | What answers it |
|---|---|
| How is AI risk identified, assessed and managed in your firm? | The AI risk and impact assessment, on the same methodology as your existing information security risk register. |
| Which AI systems are in use, and who owns each one? | An AI system inventory with named owners, a purpose, a data flow and a review date for each entry. |
| Does AI touch any important business service? | The mapping of AI systems against your operational resilience important business services and impact tolerances. |
| Where AI supports advice or client communications, who is accountable? | The human review checkpoints and the accountability record, so a person remains answerable for the judgement. |
| What third party models do you rely on, and what is the exit plan? | The third party model register with the dependency assessment and the substitution route for each. |
| Are you certified to any AI standard? | Your current position stated accurately, plus the ISO/IEC 42001 readiness plan and its target date if you are pursuing one. |
Straight answers
Questions from firms like yours
Is there an FCA rule on AI we need to comply with?
There is no standalone AI rulebook, and the stated position has been that existing rules already apply. That is a higher bar rather than a lower one, because it means the work sits inside SYSC, operational resilience and Consumer Duty rather than in one new document you can point at. General information rather than regulatory advice, and your compliance lead should form the view.
We hold ISO 27001. How much of this do we already have?
A firm holding ISO/IEC 27001 already has more of an AI management system in place than it usually expects. Scope, risk methodology, internal audit, management review and corrective action all carry across. What is new is the AI system inventory, the AI specific impact assessment and the model lifecycle and third party model controls. On our own comparison of the two standards we put an existing 27001 holder at roughly 40 per cent of the way to 42001, and a gap assessment turns that estimate into a number for your firm.
We are an IFA with 45 staff. Are we too small?
An IFA with 45 staff is very unlikely to be too small for EPX Intelligence. Most of our clients are larger, but that is who has found us rather than a rule. If a provider, a network or a professional indemnity insurer has started asking how AI is governed, the size of the firm is not the deciding factor. If the honest answer is that you need something lighter, EPX IT sells a pared down AI Foundations engagement directly and we will point you there.
Does the EU AI Act affect us?
The EU AI Act can apply to a UK financial services firm that places AI systems on the EU market, or whose AI output is used in the EU, even without an EU establishment. In our own client conversations most firms are not aware of it yet. It is worth establishing your position now rather than inside a counterparty due diligence process.
Will you work alongside our compliance consultancy?
Happily, and it is often the best shape. They own the regulatory position and the relationship, we build the technical controls and the evidence underneath it. We do not give regulatory advice and we are not trying to.
The next step is a conversation
Bring us the due diligence pack.
Thirty minutes, no proposal attached. Bring the AI question a counterparty, a network or an insurer has actually put to you, and we will tell you what your existing management system already covers.