An AI agent can gather transaction evidence, draft a customer explanation or propose the next control. It should not become an invisible decision-maker that blocks access to money, rejects a scam claim or changes an investment without a clearly authorised rule and accountable firm. Fraud prevention and wealth support are different regulated journeys; combining them under “financial AI” obscures their risks.
For this revision, regulatory sources were checked through 31 July 2026. The guide focuses on UK-regulated retail financial services. FCA, PRA and Payment Systems Regulator requirements apply according to firm, activity and payment system; not every source applies to every organisation. Permissions, product rules, contractual duties and overseas law may add obligations. Obtain regulatory and legal advice for the actual service.
Define the agent’s authority in business terms
List each proposed action, its financial effect and who can reverse it. Separate:
- read-only evidence retrieval;
- summarising and drafting;
- recommending a queue or next step;
- executing a reversible internal action;
- communicating a decision;
- restricting an account or payment;
- reimbursing or rejecting a claim; and
- recommending, arranging or transacting an investment.
Start with the first two categories. A broad instruction such as “protect the customer” can cause an agent to freeze legitimate activity, reveal a fraud concern or offer unregulated advice. Convert goals into approved policies, thresholds, limits and escalation routes.
Map authority at tool level. Reading a case note, adding an internal tag, sending a customer message and stopping a payment are separate permissions even when one workflow performs them in sequence. Require fresh approval when a proposed action crosses a financial, regulatory or customer-impact threshold. Expire delegated authority after the case or shift, and make revocation immediate.
Test retries and partial completion. An agent that times out after initiating a transfer, reimbursement or restriction must check the authoritative state before trying again. Use idempotency controls and reconciliation so a recovery process cannot duplicate money movement or contradict a customer communication.
The FCA said in June 2026 that it would use existing frameworks—including the Consumer Duty, SM&CR and governance expectations—rather than create a separate AI rulebook in its financial-services AI approach. Technology does not move responsibility from the firm or relevant Senior Manager to the supplier.
Keep fraud detection as an evidence workflow
Fraud models identify patterns associated with prior cases. They do not observe criminal intent. An alert can result from travel, accessibility needs, a new device, a family member helping or a legitimate unusual purchase.
Maintain a case record with:
- triggering event and model version;
- underlying facts and timestamps;
- data-quality and identity checks;
- linked alerts and rationale;
- customer contact and vulnerability needs;
- analyst decisions and counter-evidence;
- action, limit and duration;
- reimbursement route where relevant; and
- closure, appeal and learning outcome.
The FCA’s current fraud expectations page points firms to SYSC, the Financial Crime Guide and mandatory reimbursement requirements. It expects firms to protect customers, prevent their systems being used to move fraud proceeds and secure customer data.
Our payments fraud and reconciliation guide covers payment-event matching. Do not let an anomaly score create an unreconciled ledger action.
Design customer intervention around harm
Use risk bands for proportionate responses. Low-confidence cases may need passive monitoring; stronger evidence may justify a step-up check; an imminent high-impact loss may require a short hold under an approved policy. Each step should have an owner, maximum duration and customer route.
| Agent proposal | Required evidence | Human or deterministic control |
|---|---|---|
| Request verification | Defined anomaly and secure channel | Approved message and accessibility route |
| Delay a payment | Policy threshold and legal basis | Time limit and escalation |
| Restrict account | Multi-source risk evidence | Authorised reviewer |
| Submit scam claim | Customer facts and payment record | Customer confirmation |
| Reject reimbursement | Applicable exclusion and evidence | Specialist decision and explanation |
| Close relationship | Whole-case assessment | Senior approval and appeal |
Test false positives as customer harm, not an operational nuisance. Measure access interruption, complaints, vulnerability outcomes and time to release a legitimate payment. Avoid explanations that reveal detection rules in a way that enables abuse, but give enough information for a customer to understand and contest an outcome.
The PSR’s consolidated APP scams reimbursement policy statement explains the Faster Payments reimbursement requirement and points to the definitive legal instruments. Scope, exceptions, sending and receiving provider duties require careful application. A classifier cannot replace claim investigation.
Separate wealth education, guidance and advice
A conversational interface can explain a product, organise a customer’s stated goals or retrieve approved information. It can also cross into personal recommendation or arrangement when it tells a person what to buy, sell or hold based on their circumstances.
Define permitted intents and responses. The system should identify when the conversation requires:
- regulated advice;
- suitability or appropriateness assessment;
- vulnerable-customer support;
- complaint handling;
- financial-promotion approval;
- tax or legal advice; or
- emergency fraud support.
Route those cases to the authorised service. Do not hide a personalised recommendation behind “education” or a generic disclaimer. Record the information used, product universe, fees, conflicts, risk assumptions and source version.
The FCA’s Consumer Duty overview centres good retail outcomes, good faith, foreseeable harm and support. Evaluate the complete journey: understanding, price and value, products and services, and support. A fluent agent that steers a customer toward a more profitable product can still produce poor outcomes.
Our personal-[finance AI guide](/blog/personal-finance-ai-wealth-management-uk) addresses consumer tools. A regulated firm remains responsible when it embeds similar functions into a financial service.
Govern models, rules and language together
Create one inventory covering statistical models, deterministic rules, language models, retrieval sources and agent tools. Record purpose, owner, materiality, data, validation, limitations, approval, dependencies and change history.
The PRA’s April 2026 version of SS1/23 on model risk management applies to specified PRA-regulated firms and sets principles for identification, governance, development, independent validation and risk mitigants. Other firms can learn from the structure without claiming formal applicability.
Validate each layer:
- rules against approved policy examples;
- predictive models out of time and by relevant subgroup;
- language outputs for factuality and unsupported promises;
- retrieval for completeness, entitlement and version;
- tool calls for limits, idempotency and authorisation;
- end-to-end journeys under delay, retry and partial outage; and
- human review for real ability to disagree.
The FCA’s Financial Crime Guide update emphasises risk-based systems, monitoring, governance and remediation. Do not reduce an assessment to whether one model’s headline metric improved.
Apply data-protection safeguards to significant decisions
Fraud and wealth journeys use transaction, behavioural, device and inferred vulnerability data. Map purpose, lawful basis, recipients, retention, international transfers and rights. Prevent model-training reuse unless a compatible, lawful and transparent route supports it.
All data-protection provisions of the Data (Use and Access) Act 2025 were in force by 19 June 2026, according to the ICO’s DUAA organisational guidance. The Act broadened circumstances for significant solely automated decisions using non-special-category data while preserving safeguards. Special-category data remains more restricted.
At the cutoff, the ICO had closed consultation on updated automated-decision guidance but final detailed guidance should be checked before launch. Identify when there is meaningful human involvement. A reviewer who rubber-stamps a score or lacks evidence, authority and time does not provide meaningful intervention.
Give affected people information, a route to make representations, human intervention and contest where required. Complete a DPIA for likely high-risk processing. Test inferred health, ethnicity or vulnerability signals carefully; inference itself can create special-category data.
Secure agents against fraudsters and suppliers
Agents face prompt injection in emails, chat, documents and transaction references. Treat retrieved content as data. Do not allow it to change system policy, tool permissions or payee details. Separate instruction channels from customer text.
Use strong service identity, least privilege, transaction limits, dual control for high-impact actions and tamper-evident logs. Bind every tool call to case, user, policy version and idempotency key. Block free-form generation of bank details or authentication links.
The FCA, Bank of England and Treasury joint statement on frontier AI and cyber resilience calls for access management, network security, data protection and resilience. Test model and supplier outage, compromised retrieval, stolen credentials and malicious tool output.
Contracts should cover model and subprocessor changes, audit evidence, incidents, data use, vulnerability response, service continuity, exit and regulatory cooperation. A vendor “human in the loop” claim does not explain the firm’s real control.
Measure outcomes without invented savings
For fraud operations, measure:
- confirmed loss and prevented loss with documented counterfactuals;
- legitimate payments delayed or blocked;
- alert precision by scenario;
- missed cases found through other channels;
- analyst time and queue age;
- reimbursement timeliness and reversal;
- customer complaints and distress; and
- subgroup and vulnerability outcomes.
For wealth journeys, measure comprehension, appropriate routing, unsuitable recommendation findings, abandonment, repeat contacts, complaints, fee and conflict disclosure, and outcomes across customer groups. Do not use click-through, product sale or assets gathered as proof of customer benefit.
Run a controlled comparison. Fraud prevalence, campaigns and reporting shift over time; markets also change investment outcomes. State the denominator, time horizon and uncertainty behind any performance claim.
Use a 90-day controlled programme
Days 1–30: define one read-only use case, regulatory perimeter, Senior Manager, customer harm scenarios, data map, model inventory and baseline. Label representative cases including vulnerability and false-positive examples.
Days 31–60: run in shadow mode. Test prompt injection, policy conflicts, missing data, duplicate tool calls, model drift, supplier outage and appeal. Validate fraud and wealth use cases separately.
Days 61–90: allow recommendations in one supervised queue with transaction authority disabled. Audit every adverse action, customer explanation and override. Compare losses, friction, service quality, model cost and staff workload. Compliance, risk, security and business owners decide whether to expand.
Define finance pause gates
Pause the affected agent or action when:
- it moves money, changes an investment or restricts an account outside authority;
- a legitimate-customer false-positive threshold is exceeded;
- scam-claim or complaint deadlines are at risk;
- advice, guidance and information boundaries cannot be enforced;
- significant decisions lack meaningful review or contest;
- subgroup or vulnerable-customer outcomes deteriorate;
- policy, product or model versions cannot be reconstructed;
- prompt injection or credential compromise reaches a tool;
- the supplier cannot support regulatory evidence or safe recovery; or
- human reviewers routinely accept outputs without examining facts.
Agentic finance should make evidence, authority and customer outcomes more visible. It must not convert a probability or generated paragraph into unaccountable control over a person’s money.



