The Mills Review – what FCA-regulated firms should do now on AI, outsourcing and operational resilience
July 08, 2026
The Mills Review – what FCA-regulated firms should do now on AI, outsourcing and operational resilienceJuly 08, 2026 BackgroundThe FCA has been actively considering the implications of AI in financial services for several years and has consistently favoured adapting existing regulatory frameworks rather than introducing a standalone AI regime. Through initiatives such as its AI Lab, the FCA has sought to support innovation while understanding the opportunities and risks presented by AI in financial services. In early 2026, the FCA Board commissioned Sheldon Mills to conduct a strategic review into how advances in AI could transform retail financial services by 2030 and beyond. The review was published on 6 July and draws on over 140 written submissions and extensive engagement with financial services firms, technology companies, academia, consumer groups, and fellow regulators. Its central finding is clear: financial services are shifting from human-led, episodic activity towards AI-enabled, continuous, and delegated models. For FCA-regulated firms, the key message is not that a new AI rulebook is imminent. Rather, firms deploying AI (whether internally, through outsourced services or via third-party technology platforms) should be able to demonstrate that their existing governance, accountability, operational resilience and Consumer Duty frameworks remain effective as AI systems become increasingly autonomous. The Mills Review introduces an "AI autonomy spectrum" (see page 13 of the Mills Review) to illustrate how the human role changes as AI systems become more capable and autonomous. As firms move from AI-assisted decision-making towards greater delegation, questions of accountability, governance and oversight become increasingly important. Key Takeaways for FCA Regulated Firms
The full text of the Mills Review can be found here: The Mills Review: AI and the future of retail financial services Practical Steps for FCA Regulated FirmsFirms do not need to wait for further FCA guidance before taking these steps; they flow directly from existing expectations on governance, accountability, outsourcing, operational resilience and Consumer Duty. 1. Map AI use cases and accountabilityBoards and senior managers should map current and planned AI use cases against the autonomy spectrum and ensure that clear accountability sits with named individuals under SM&CR. Particular attention should be paid to use cases moving towards higher levels of autonomy, where oversight and governance become increasingly important. 2. Refresh AI governance and risk managementGovernance and model risk management frameworks should evolve to address AI-specific risks including model drift, data bias, hallucinations, and emergent behaviours, particularly where firms are deploying increasingly capable or autonomous systems. 3. Update operational resilience assessmentsOperational resilience frameworks should identify AI dependencies, particularly on third-party model providers, cloud infrastructure and other critical technology suppliers, and ensure that appropriate impact tolerances, contingency arrangements and scenario testing are in place. 4. Strengthen third-party risk managementFirms remain responsible for outcomes even where AI capabilities are provided through outsourced services, cloud platforms, foundation models or other third-party technology providers. Firms should understand and actively manage dependencies on external providers, including governance, resilience, access to data, model change and concentration risk. 5. Reassess Consumer Duty complianceConsumer Duty obligations apply equally to AI-enable customer journeys. Firms should assess whether outcomes remain fair, foreseeable and capable of effective oversight as personalisation and delegation increase. 6. Review supplier and AI contracting arrangementsFirms should review technology and outsourcing contracts supporting AI-enabled services to ensure they provide appropriate transparency, governance, audit, incident notification and regulatory access rights, particularly where critical services rely on external AI models or infrastructure. Finally, model risk management and governance frameworks should evolve to address general-purpose and frontier AI models, with particular focus on opacity, model drift, concentration risk, and the potential for correlated failures across the sector. Firms that take these steps now will be better placed to demonstrate effective governance, accountability and operational resilience as AI becomes increasingly embedded in products, services and customer journeys. Latest Insights
Latest News
Latest Events
firm news July 10, 2026 Eversheds Sutherland advises OCBC on the landmark secondary dual listing of... client news July 10, 2026 Setting sail: Eversheds Sutherland advises senior management of D-Marin on ... client news July 09, 2026 Eversheds Sutherland advises Costello Medical on transition to employee own... firm news July 01, 2026 Eversheds Sutherland lands lateral partner-led Paris Funds team, as its wid... virtual UAE - Employment law in the Dubai International Financial Centre September 10, 2026 9.30am - 1.30pm (GMT) Virtual in-person Managing AI use in the workplace: what every UK HR team needs to know September 10, 2026 9.30am - 1.00pm (BST) London, United Kingdom in-person Basic foundations of US employment law September 17, 2026 9.30am - 4.30pm (GMT) London, United Kingdom in-person 2026 BDC Roundtable September 23, 2026 Washington DC, United States |