Financial Companies in the AI era: control, accountability and what you can safely automate

Financial Companies in the AI era: control, accountability and what you can safely automate

Large firms are pushing hard on generative and agentic AI. McKinsey’s State of AI work shows near-universal use but thin enterprise value until workflows are redesigned; its agent pieces point to multi-agent “factories” with humans supervising at scale. Bain argues for AI-native process redesign and — critically — governance that lives in the runtime control plane, not a policy PDF. PwC’s FS surveys highlight workforce shrinkage plans without role redesign, shadow AI, and confused ownership when agents cause harm. Baringa’s Mills Review commentary treats autonomy as a spectrum and pushes SM&CR, Consumer Duty and operational resilience into continuous monitoring.

None of that removes UK regulatory duties. The FCA’s published approach is that it does not plan a separate AI rulebook. Existing frameworks — Principles, SYSC organisational and risk controls, outsourcing, operational resilience, Consumer Duty and SM&CR — already apply. The Mills Review (July 2026) sharpens the same point for retail finance: agentic systems need named accountability, not a new statute. This article turns those themes into practical questions for operational, risk and compliance teams.

Can I remove my back office and front office?

Short answer: you can reshape both. You should not pretend you can delete them.

Front office (sales, advice, dealing, relationship management) and back office (settlement, reconciliations, client money, reporting, case handling) are where regulated outcomes land. Agents can draft, triage, extract, reconcile candidates and assemble packs. They cannot hold your permissions, own your customer outcomes, or sit in the chair when the FCA asks who decided.

McKinsey’s agent work on credit memos and financial crime shows large productivity ranges when agents prepare analysis and humans supervise. Bain’s warning matters more for regulated firms: if you automate “workflow debt”, you accelerate error and make unwind harder. Redesign the process first — what must stay human, what is human-plus-AI, what can run with tight guardrails — then automate.

Illustrative view of high time-cost front- and back-office work in FS. Ticks are a working judgement for a typical UK FCA-authorised firm — not a licence to automate. Weighting: Consumer Duty / SM&CR accountability, irreversibility, accuracy needs, complexity of judgement, and failure impact. Re-score against your own permissions and important business services.

# Function Area AI only AI + human review Staying human
1 Internal email / meeting-note triage and CRM draft updates Front office
2 First-draft research, pitch or credit-memo narrative from approved sources Front office
3 KYC/CDD document checklist, pack assembly and gap list Front office
4 Suitability / personal recommendation and advice rationale Front office
5 Retail product, pricing or next-best-action recommendations to the client Front office
6 Confirmation matching and break triage (candidate matches + draft comments) Back office
7 Nostro / depot / trade reconciliation candidate matching Back office
8 Client money / CASS reconciliation sign-off and breach assessment Back office
9 Regulatory return / control-evidence pack assembly from system extracts Back office
10 Payment release, settlement instruction or SAR / escalation decision Back / FO control

How to read the ticks

  • AI only — low accountability surface if wrong; easy to reverse; mainly internal; still keep sampling and logging.
  • AI + human review — high volume and structured enough for agents, but a named person must approve before client, market or regulator impact.
  • Staying human — advice, client-facing recommendations, CASS/client money judgement, irreversible money movement, or decisions the FCA will treat as owned by an SMF/certified person. Agents may prepare inputs; they do not decide.

FCA lens (UK): there is no exemption for “the model did it”. Relevant hooks include:

Item What this means
Principles skill, care and diligence; organisation and control (Principles 2 and 3).
SYSC systems and controls, risk management, and (where applicable) outsourcing under SYSC 8 and related guidance such as FG16/5. Cloud LLM providers, model APIs and managed “AI desks” are third parties.
Operational resilience (SYSC 15A) if AI supports an important business service, map the dependency, set impact tolerances, and test failure modes (including provider outage, model drift and poisoned data).
SM&CR a senior manager still owns the business area. Delegation to an agent is not delegation of accountability.
Consumer Duty where AI touches products, pricing, communications, servicing or complaints, customer outcomes remain yours.

Treat vendor AI like any material outsourcing: due diligence, access and audit rights, exit, incident reporting, data residency and concentration risk. If the same model underpins several important services, that is a resilience and concentration issue, not an IT footnote.

Are you still using it to summarise your emails?

Email summarisation is fine as a personal productivity tool. It is not an AI strategy.

The useful shift — the one McKinsey, Bain and PwC all circle — is from chat about work to agents inside work: sifting registers, drafting control evidence, building small tools your team actually runs, flagging exceptions against your policy text, and keeping an audit trail. Bain’s “people first” point is blunt: agents need clear rules and handoffs; humans can paper over fuzzy process, agents cannot.

If your only live use case is “summarise my inbox”, you have bought a faster notepad. Ask instead: which recurring control or ops bottleneck produces volume, structured evidence and a named owner?

How can I gain a sense of control?

Control is an operating design, not a feeling.

Step Design
Inventory List live AI uses (including shadow tools): owner, data classes, autonomy level, customer impact.
Tier More autonomy and higher impact need heavier governance — a drafting aid is not a credit decision engine (PwC agent guidance).
Contracts for agents Allowed tools, data scopes, stop conditions, escalation and logging.
Human gates Define where a person must approve before action (payments, client communications, regulatory filings, credit, SAR decisions).
Observability Prompts, context, outputs, tool calls, overrides — if you cannot reconstruct what happened, you cannot defend it.
Kill switches Disable a use case or vendor path without taking the whole firm offline.

Bain’s governance writing is blunt: when agents act without review, controls must live in identity, behaviours, context, observability and accountability — including tested kill switches — not in a slide titled “AI principles”. The winning pattern for regulated firms is controlled scale on a few high-value workflows, not a firm-wide “AI free-for-all”.

Who will have responsibility?

Under SM&CR, people remain responsible. An agent is a tool (or a third-party service), not a certified individual.

Name for each material use case:

Item What this means
Business owner accountable for outcomes in the SMF/certification chain.
Model / product owner change control, evaluation, drift, retirement.
Data owner lawful basis, retention, access, quality.
Technology / security owner platform, identity, secrets, logging.
Risk / compliance challenger independent view on consumer harm, financial crime, conduct and resilience.

When several agents chain together (McKinsey’s multi-agent credit or KYC factories), write down the handoff map. Cascading errors are a governance problem as much as a model problem. PwC and the FSB-style sound-practice discussions both flag agent speed: wrong actions can propagate faster than human supervision unless you design for it.

Can you have a cheaper workforce?

You can often have a different cost shape: fewer hours on first-pass drafting and sifting; more hours on exception handling, oversight and redesign. Strategy houses publish large productivity ranges for agent-supported analysis; PwC’s FS survey work also shows many leaders planning a smaller workforce while skipping process redesign — treat published ranges as directional, not a budget line until you measure them on *your* data and controls.

What does not work in regulated FS:

  • Cutting headcount before the control environment can absorb agent error rates.
  • Replacing SMF capacity or certified roles with a model.
  • Assuming “cheaper offshore + AI” somehow reduces outsourcing and resilience duties — it usually increases them.

Cheap labour without judgement is how you buy cheap incidents. Invest in training people to supervise agents, design workflows and challenge outputs.

What happens when things go wrong?

Plan for three failure modes.

1. Local error — wrong summary, bad extraction, hallucinated citation. Contained if human gates and sampling catch it. 2. Process failure — agent writes to the wrong system, emails a client, books a trade, closes a case. Needs permissions, dual control and rapid revoke. 3. Systemic / correlated failure — many teams on the same model, same prompt pattern, same vendor outage, or same poisoned corpus. Outputs fail together. Important business services breach impact tolerances at once. Market or customer harm scales.

That third mode is why operational resilience and third-party concentration matter for AI. Cyber risk rises in parallel: AI-assisted phishing, faster vulnerability discovery, and attack paths that chain across suppliers. UK authorities have been explicit that frontier AI cyber threats sit inside existing resilience and governance expectations — update scenarios, not invent a parallel rulebook.

When something goes wrong, supervisors will ask for: who owned it, what the agent was allowed to do, what it actually did, how you detected it, how customers were treated, and what you changed. Build the evidence path before the incident.

Cyber security risks are increasing

Treat AI as both a target and a tool for attackers.

Item What this means
Prompt injection and data leakage into training or vendor logs.
Secrets and customer data in prompts.
Over-privileged agents with write access to core systems.
Supply-chain risk in models, plugins and “agent marketplaces”.
AI-accelerated social engineering against your staff.

Map AI into your existing cyber, identity and third-party programmes. Restrict tool use, segregate environments, monitor anomalous agent behaviour, and test incident playbooks that include “disable the agent fleet”.

What happens to all the people who just do SQL queries and Excel manipulation in your organisation?

They do not disappear when you plug in a model. Much of what looks like “just SQL and spreadsheets” is actually judgement sitting on institutional memory: which joins are trusted, which reconciliations always break on month-end, which client quirks never made it into the data dictionary. Discount that and you automate the wrong answer faster.

Item What this means
Accountability is still real someone still owns the number that goes to the board, the regulator or the customer. An agent that wrote the query does not sit in the SM&CR chair.
They know the data — don’t discount corporate history AI does not inherit your war stories, failed migrations or the reason that one static table is still patched by hand. People who have lived the data do.
Remember you are still serving humans ops, risk, compliance and clients need explanations they can challenge, not a black-box “the model said so”.
AI can spectacularly blow up wrong grain, silent truncation, hallucinated joins, prompt injection into a finance workflow. An experienced human in the loop is not nostalgia; it is a control.

The practical move is redesign, not denial: keep the people who understand the books close to exception handling, data stewardship and sign-off, and use AI to draft, triage and propose — not to own the outcome unsupervised.

Where are your graduates going to learn now?

If juniors no longer grind through every extract and pivot table, you still need a deliberate path for them to build judgement. Otherwise you hollow out the next generation of control owners while the tools look productive in year one.

Item What this means
Test cases they need to be trained on curated failures, edge cases and “almost right” outputs that teach when not to trust the model.
Disaster recovery and resilience for cyber attacks and AI failure playbooks for model outage, poisoned data, vendor concentration and degraded mode when the assistant is wrong or unavailable.
Regular in-person meetings with senior and middle management so graduates hear how the business actually runs, not only how the ticket queue looks.
Q&A sessions run by each department current issues and how data flows through the organisation, end to end.
Relevant skills libraries SQL and Excel still matter, alongside prompt discipline, control design, evidence packs and reading a regulatory expectation into an operating process.
Mentoring programmes that actually work not a logo on an intranet page: paired time with people who still own the numbers, review AI outputs together, and teach when to challenge the machine.

Firms that treat AI as a headcount shortcut without a learning system will feel it later in audit findings, brittle ops and nobody left who can explain the books.

With more data comes more scrutiny

When everyone can pull a dump and dress it as a deck, “I have charts” stops being a differentiator. Scrutiny goes up, not down: boards, audit and regulators will ask sharper questions about provenance, definitions and whether the picture matches the books.

Pressure point What this means
Pretty slides are not value If anyone can get data and make a polished pack from it, the value add is judgement — framing, challenge and decision quality — not the chart art.
Analysts still hold the vision Data analysts still have the vision and structure you need to stay in control: what to measure, what to ignore, and how the story hangs together under stress.

Statistics, damn statistics. More data does not mean more truth.

Risk What this means
Data can be wrong We see it everywhere — broken feeds, stale static, silent duplicates. Treating the extract as gospel is how AI scales an error.
Field-level misunderstanding Field-level data is often misunderstood by the business: same label, different meaning across products, books or regions.
Unknown unknowns We don’t know what we don’t know — and AI will not invent the missing control question for you.
Ask the right question Finding the right structured question to ask will matter more than ever: bad prompts on bad grain produce confident nonsense.

Where AI hits capital markets activities

The familiar capital-markets operating-model map — same activity boxes, connecting lines and engagement explanations — with GRT branding and an AI-impact colour overlay (high / medium / low) on each activity.

Red = high AI impact · Orange = medium · White = low. Explanations around the edge keep the original support examples (anonymised client type). Illustrative discussion frame only.

GRT capital markets operating model with AI impact colour coding and engagement callouts

How GRT Consulting can help

GRT Consulting works with operational, risk and compliance teams who need AI that survives contact with FCA expectations — not slideware.

We help you:

Item What this means
Deploy targeted, low-cost agents that sift your data and build real tools inside your teams not generic chatbots.
Find bottlenecks where volume, evidence and ownership make agent support worthwhile.
Adopt new work practices redesigned workflows, human gates, observability and kill switches.
Train teams to use and supervise agents so productivity gains do not outrun control.
Address data security and third-party risk inventories, SYSC/outsourcing overlays, resilience mapping and practical cyber hygiene for AI use cases.

If you want a structured conversation about where agents belong in your FS operating model — and where they do not — contact us.

T: +44 20 3695 9251 E: info@grtconsult.com Web: grtconsult.com


Sources

.., 10th September 2026

GRT Consulting

Speak to us about how we can help you

T: +44 20 3695 9251

E: info@grtconsult.com

Submit Request for Proposal