The FCA's Mills Review, released in January, has prompted internal audit teams to quickly assess its implications. With feedback due by 24 February, many are questioning how to engage with the review and audit AI deployments under current frameworks. If you're in this position, you're not alone.
Should Your Firm Respond to the Call for Input?
Consider your AI usage and future plans. If your firm uses AI for credit decisions, fraud detection, chatbots, or financial crime monitoring, you should respond. The Mills Review will influence how the FCA applies existing obligations, like the Consumer Duty and SMCR, to AI systems. This will affect your audit scope and risk assessments.
The review closes on 24 February, with recommendations expected this summer. By not responding, you risk letting others shape the regulatory landscape you'll audit against. Compliance and risk teams should draft responses, and internal audit should ensure these reflect operational realities.
How to Audit AI Systems Without Full Explainability
A key challenge is auditing AI systems that lack explainability, especially those using complex machine learning. SMCR requires senior managers to understand and control risks, but many AI models don't allow for traditional control testing.
Focus on the governance layer. Ensure the firm has documented the AI system's purpose, data usage, decisions influenced, and the responsible SMCR senior manager. Test whether that manager can articulate the model's limitations, bias risks, and monitoring approach. If not, there's a control deficiency.
Audit the monitoring controls: How does the firm detect anomalous outputs? What triggers human review? How often is the model retrained, and who approves changes? These controls are crucial, even if the algorithm itself is a "black box."
Key Risks to Test in AI Deployments
Focus on three main risk categories:
Bias and Fairness: AI-driven credit assessments can perpetuate biases if training data is flawed. Test for disparate impact across protected characteristics. Request bias testing documentation and remediation records.
Consumer Harm from Inaccurate Outputs: The Mills Review highlights AI chatbots providing unclear responses to vulnerable customers. Analyze customer complaint data for AI-related patterns. Verify defined error rates and performance monitoring.
Regulatory Perimeter Creep: The FCA is concerned about AI systems offering services similar to regulated activities without falling under regulation. If your AI recommends products or manages portfolios, audit whether these activities qualify as regulated advice.
Applying Consumer Duty to AI Tools
The FCA will continue using existing frameworks rather than creating AI-specific regulations. Consumer Duty expectations around fair value, consumer understanding, support, and product governance apply to AI services.
Audit whether AI tools meet the four Consumer Duty outcomes. For instance, does the AI pricing model deliver fair value? Can consumers understand AI recommendations? Is there adequate support for AI errors?
The Mills Review questions if Consumer Duty expectations should change due to AI's impact. Until new guidance is issued, assume the current framework applies fully.
Preparing for Regulatory Changes
Create an AI inventory if you don't have one. Document each AI system's purpose, data processed, influenced decisions, and responsible SMCR senior manager. Include vendor-provided AI tools.
For each system, document the risk assessment: potential failures, monitoring processes, and error escalation paths. This documentation will be crucial when the FCA issues new guidance.
Track your firm's response to the Mills Review. Internal audit should review this submission, as you'll likely audit against the commitments made.
Addressing Third-Party AI Risk
The House of Commons Treasury Committee recently suggested designating major AI and cloud providers as critical third parties. This would give regulators direct oversight.
Audit your firm's due diligence on AI vendors. Ensure vendor risk assessments cover model governance, data handling, bias testing, and service continuity. If relying on a third-party AI provider, verify their controls beyond marketing claims.
The Treasury Committee expects progress on this recommendation by 2026, making third-party AI risk a growing audit focus.
Further Resources
The FCA's call for input outlines four focus areas: technology evolution, market impact, consumer trends, and regulatory approach. Use these as a framework for your AI audit plan.
The Treasury Committee's January 2026 report offers insights into regulatory gaps under consideration. It's a valuable resource alongside the Mills Review.
If your firm hasn't assigned an SMCR senior manager for AI governance, address this gap now. The FCA expects senior managers to oversee AI deployment, and you can't audit accountability that's not assigned.




