Blog · AI Governance

SYSC AI Compliance Requirements: A 2026 Guide for Firms

AETHER Pulse·13 July 2026·10 min read

SYSC AI Compliance Requirements: A 2026 Guide for Firms

Woman reviewing SYSC AI compliance documents

SYSC AI compliance requirements are defined as the governance, accountability, and control obligations that FCA-regulated firms must meet when deploying AI systems, mapped directly to the Senior Management Arrangements, Systems and Controls sourcebook. The FCA does not apply a separate AI rulebook. Instead, it applies existing frameworks including SYSC, SM&CR (Senior Managers and Certification Regime), and Consumer Duty to AI, with a focus on outcomes and accountability. For compliance officers at regulated firms, this means AI governance is not a standalone workstream. It sits inside the same control architecture you already operate, and the FCA is actively testing whether that architecture works in practice.

1. What are the core SYSC AI compliance requirements?

SYSC AI compliance requirements center on three obligations: documented governance, named accountability, and evidence of operational effectiveness. The FCA's principle-based approach expects firms to apply core principles including safety, transparency, fairness, and accountability in their own contexts, rather than conform to a prescriptive AI rulebook. That flexibility is real, but it does not reduce the burden. It shifts the burden onto you to demonstrate that your controls work.

Consumer Duty extends this obligation into AI-driven decisions. The FCA requires firms to test AI outputs for fairness and suitability when AI affects product design, pricing, eligibility, or customer support. Failure to meet Consumer Duty outcome standards through AI carries direct enforcement risk. Compliance officers must treat AI governance as an outcomes question, not a documentation exercise.

Close-up of hands entering AI fairness data

2. How governance and accountability structures work under SYSC

SM&CR requires a named Senior Manager to own AI deployment and oversight. The FCA recognizes specific Senior Management Functions for this purpose, including SMF24, SMF4, and SMF18 depending on the role and scope of oversight. Outsourcing AI does not transfer accountability away from that named individual. Delegating AI functions to an IT team or an external vendor leaves the Senior Manager fully liable.

AI systems must be risk-tiered before deployment. The FCA expects a four-level scale from minimal to material impact, with governance intensity matched to potential consumer harm and operational complexity. Material-risk AI requires board approval and formal attestation. That is not a formality. It is a documented decision trail the FCA can request.

SYSC mandates three control layers for every AI system:

  • Pre-deployment assessment. Risk classification, Data Protection Impact Assessment (DPIA), bias testing, and sign-off by the accountable Senior Manager.
  • In-flight monitoring. Continuous performance tracking against defined KPIs, with escalation triggers for model drift or output degradation.
  • Post-deployment audit. Tamper-evident records retained for at least seven years, including model versions and decision rationales.

Pro Tip: Assign a single named owner to each AI system in your risk register. The FCA will ask who is accountable. "The AI team" is not an acceptable answer.

3. How firms must manage AI risk and maintain operational control

Risk-based classification drives the intensity of oversight. Not all AI needs the same scrutiny, but governance intensity must match the potential for consumer harm and operational complexity. A low-risk internal scheduling tool requires far less documentation than a credit-scoring model affecting thousands of customers.

Continuous monitoring is mandatory, not optional. From september 2026, voice AI deployments require immutable, queryable logging per call rather than simple transcripts. The FCA's Code of Conduct rules treat AI-mediated communications as equivalent to human communications. Logs must include model prompts, version numbers, and decision rationale. A transcript alone does not satisfy this requirement.

The table below maps AI risk levels to the minimum governance controls the FCA expects:

Risk levelExample use caseMinimum governance controls
MinimalInternal scheduling, document formattingBasic inventory entry, annual review
LowCustomer FAQ chatbotInventory, DPIA, quarterly monitoring
SignificantFraud detection, eligibility screeningBoard briefing, continuous monitoring, DPIA
MaterialCredit decisions, automated adviceBoard approval, attestation, full audit trail

Operational resilience frameworks must incorporate AI dependencies. The FCA expects scenario testing for AI-enabled cyber attacks, vendor outages, and data compromise as part of business continuity planning. An AI system that fails during a market stress event is an operational resilience failure, not just a technology incident.

4. What documentation and evidentiary standards support SYSC AI compliance

The FCA's supervisory reviews increasingly test controls in practice, focusing on authority, resource adequacy, and operational integration. Paper compliance does not pass. The FCA assesses whether your compliance function has real influence, real resources, and real access to information about AI systems.

Your AI inventory is the foundation of your evidence position. The FCA expects it to be audit-ready within hours of a supervisory request. Each entry must include:

  • Model owner and named Senior Manager accountable for the system
  • Version history and last review date
  • Data classes processed and Consumer Duty mapping
  • Risk tier and associated governance controls
  • Links to DPIAs, test results, and remediation logs

Evidence packs for FCA review must go beyond the inventory. They should include risk register entries, bias and fairness test results, board reporting records, incident logs, and any remediation actions taken. The FCA treats gaps in this documentation as evidence of governance failure, not administrative oversight.

From september 2026, voice AI logs must be versioned, immutable, and queryable by call. This is a specific technical requirement, not a general principle. Firms using AI in customer-facing voice channels must build or procure logging infrastructure that meets this standard before the deadline.

Pro Tip: Run a mock supervisory request exercise quarterly. Ask your team to produce the full evidence pack for your three highest-risk AI systems within four hours. The gaps you find are the gaps the FCA will find.

5. How firms should address third-party risks and outsourcing in AI under SYSC

Third-party AI services count as outsourcing under SYSC 8. This means due diligence, contractual safeguards, ongoing monitoring, and resilience planning apply to every AI vendor relationship, including cloud-based model providers and open-source components embedded in your systems. The regulated firm retains full responsibility for the outputs those systems produce.

Effective third-party AI governance requires:

  • Vendor due diligence. Assess the AI supplier's own governance practices, data handling standards, and incident response capabilities before contracting.
  • Contractual audit rights. Secure the right to audit vendor AI systems and receive notification of material model changes or incidents.
  • Resilience mapping. Include all third-party AI dependencies in your operational resilience mapping and business continuity scenarios.
  • Open-source risk controls. Treat open-source AI components as third-party dependencies. Maintain a software bill of materials and track known vulnerabilities.
  • Ongoing monitoring. Review vendor performance against defined SLAs and escalate material changes to the accountable Senior Manager.

The FCA does not accept "our vendor handles it" as a governance position. Accountability remains with the regulated firm regardless of how AI functions are structured or procured. Your outsourcing register must reflect every AI dependency, and your Senior Manager must be able to speak to each one.

Key takeaways

SYSC AI compliance requirements demand operational evidence of governance, not just documented policies, with named accountability, risk-tiered controls, and audit-ready records as the minimum standard.

PointDetails
Named Senior Manager accountabilityAssign a specific SMF to every material AI system; outsourcing does not transfer liability.
Four-level risk tieringClassify each AI system from minimal to material; match governance intensity to consumer harm potential.
Seven-year audit trailsRetain tamper-evident records including model versions and decision rationales for at least seven years.
Voice AI logging deadlineFrom september 2026, voice AI logs must be immutable, versioned, and queryable per call.
Third-party AI as outsourcingApply SYSC 8 due diligence and audit rights to every AI vendor, including open-source components.

The gap between policy and practice is where firms get caught

The firms I see struggle most with SYSC AI compliance are not the ones with bad intentions. They are the ones with excellent policy documents and weak operational reality. The governance framework looks complete on paper. The AI inventory exists. The risk register has entries. But when you pull on any thread, the controls are not actually running. The monitoring KPIs are defined but nobody reviews them. The board receives AI updates, but those updates contain no meaningful risk data.

The FCA's evolving supervisory approach is moving from reviewing policies to testing whether those policies produce real outcomes. That shift changes what compliance officers need to prioritize. The question is no longer "do we have a policy?" It is "can we prove the policy is working?"

Cross-functional collaboration is the piece most firms underinvest in. AI governance requires compliance, legal, technology, and the business to operate from the same evidence base. When those functions work from separate records, the FCA sees inconsistency. Inconsistency reads as a control failure. The firms that perform best in supervisory reviews are the ones where the compliance officer and the Chief Technology Officer can produce the same answer to the same question about any AI system, without coordinating first.

— Eleye

Aetherpulse: audit-ready AI governance for FCA-regulated firms

Regulated firms face a specific problem: the FCA expects AI governance evidence on demand, but most governance tooling either requires deep integration into production systems or produces records that cannot withstand scrutiny.

https://aetherpulse.app

Aetherpulse connects through OAuth metadata only, touching no customer data, and builds a live inventory and identity graph of your AI agents. It generates tamper-evident, HMAC-SHA256 signed evidence packs that map directly to SYSC, SM&CR, and Consumer Duty requirements. Compliance officers can produce a complete audit pack for any AI system within hours, not days. The platform surfaces risk concentration and financial exposure across your AI estate, giving your Senior Managers the visibility they need to meet their attestation obligations. Aetherpulse is built for the UK and EU regulatory environment and is live at aetherpulse.app.

FAQ

What does SYSC require for AI governance in 2026?

SYSC requires firms to apply a three-layer control framework to AI systems: pre-deployment assessment, continuous in-flight monitoring, and post-deployment audit trails retained for at least seven years. Governance intensity must match the risk tier of each AI system.

Who is accountable for AI under SM&CR?

A named Senior Manager, typically SMF24, SMF4, or SMF18 depending on the firm's structure, holds personal accountability for AI deployment and oversight. Outsourcing AI functions to vendors or internal IT teams does not remove that accountability.

What records does the FCA expect for voice AI from september 2026?

From september 2026, voice AI deployments must produce immutable, versioned, and queryable logs per call, including model prompts, version numbers, and decision rationale. Simple call transcripts do not meet this standard.

Does Consumer Duty apply to AI-driven decisions?

Consumer Duty applies directly to AI-driven decisions affecting product design, pricing, eligibility, and customer support. Firms must test AI outputs for fairness and suitability, and failure to meet outcome standards carries enforcement risk.

How does SYSC 8 apply to third-party AI vendors?

SYSC 8 classifies third-party AI services as outsourcing arrangements, requiring due diligence, contractual audit rights, ongoing monitoring, and inclusion in operational resilience mapping. The regulated firm retains full responsibility for all outputs produced by vendor AI systems.

Recommended

Working on Article 26 readiness, deployer-side governance evidence, or AI agent risk at a regulated firm? We'd value 15 minutes of your perspective.

Start a conversation