What Would an FCA Supervisor Expect to See? An AI Governance Evidence Checklist
FCA supervisors are not asking about AI governance in the abstract. They are asking specific questions in supervision visits that require specific answers backed by specific evidence. The firms that handle those questions well have one thing in common: they built the evidence before the question was asked.
This article reconstructs the questions an FCA supervisor is most likely to ask, drawn from FCA published guidance, Dear CEO letters, and the Consumer Duty and SYSC 8 frameworks, and describes precisely what evidence adequately answers each one.
FCA supervisors are not assessing governance frameworks. They are assessing governance evidence. Proof that oversight is operating in practice, not just described in policy.
The FCA's Current Posture on AI Governance
The FCA has been explicit that existing regulatory principles apply to AI even without AI-specific rules. SYSC 8 governs material third-party arrangements, which includes AI systems procured from vendors. Consumer Duty (PRIN 12) requires firms to demonstrate that products and services deliver good customer outcomes, including AI-assisted ones. Principle 3 requires firms to maintain adequate risk management systems and controls. What has changed in 2025 and 2026 is the FCA's supervisory attention. AI governance features in multi-firm reviews and individual firm visits with increasing frequency.
Question 1: What AI Systems Are You Using?
This is always the opening question, and it has two parts the FCA is actually interested in: what you approved, and how you know what is actually running.
Adequate evidence: a current AI agent inventory, dated and signed, covering formally approved tools and tools discovered through programmatic admin-level discovery. The inventory should show each system's name, vendor, data access scope, whether it processes personal data, and its risk classification.
The gap that exposes firms: an inventory maintained manually by IT that covers only sanctioned tools. When a supervisor asks how you identified the systems on the list, "we asked our IT team" is not adequate for a firm with complex Microsoft 365, Google Workspace, and Salesforce deployments where AI agents operate through OAuth grants IT did not approve.
What makes the answer adequate: the ability to demonstrate that the inventory was produced through systematic discovery (not self-reporting) and that it was current as of a specific date, evidenced by a signed, dated record.
Further reading: The AI Inventory Crisis Nobody Is Talking About is the pillar piece on discovery-based inventory.
Question 2: Who Is Responsible for Oversight of Each System?
The FCA expects firms to have named individuals with documented authority over each material AI system. Not a governance committee that holds collective responsibility, but specific people with the power and mandate to intervene.
Adequate evidence: a responsibility matrix showing the named oversight owner for each material AI system, the scope of their oversight responsibilities, and evidence that they have the authority and resources to intervene in or suspend the system's operation. Meeting records, escalation logs, and documented intervention decisions all constitute relevant evidence.
The gap that exposes firms: governance responsibility assigned to a function ("the AI governance team is responsible") without named individuals and without evidence that oversight is operationally active.
Question 3: How Do You Monitor These Systems?
This is where most firms' evidence is thinnest. Monitoring policies exist. Evidence that monitoring occurred is rarer.
Adequate evidence: records showing the monitoring cadence for each material AI system, what the monitoring covers, what findings were identified, and what actions were taken. For Consumer Duty purposes, monitoring records should include evidence of customer outcome review. For Article 26 purposes, monitoring records should cover the system's operation in the context of its risk classification.
The gap that exposes firms: monitoring described as quarterly but with no records showing what it involved, what it found, or what was done. Monitoring without a documented output is not evidence of monitoring. It is a monitoring policy.
"We have a quarterly AI governance review" is not evidence of monitoring. "Here are the records from our Q1 review, showing these findings, these actions, and this signed evidence pack" is evidence of monitoring.
Question 4: What Happens When Something Goes Wrong?
The FCA expects firms to have incident and exception management processes for AI systems, and evidence that those processes have been tested or invoked.
Adequate evidence: documented incident response procedures specific to AI systems, escalation paths, notification procedures, and records of any incidents identified and how they were handled. Where no incidents have occurred, evidence of testing or simulation of the response process is valuable.
Question 5: Can You Show Me Your AI Governance Documentation?
The final question integrates everything above. The FCA supervisor will ask to see the documentation, and its adequacy depends on whether it is evidence or records. Records describe what you do. Evidence proves that you did it.
Adequate evidence: signed evidence packs generated at regular cadences (monthly minimum) covering the AI agent inventory, risk classifications, monitoring findings, human oversight status, and cross-platform toxic-combination detections. Each pack signed at generation, verifiable as unaltered under examination.
Further reading: What Would You Show a Regulator Tomorrow? covers the five evidence categories regulators typically request.
The FCA AI Governance Evidence Checklist
Inventory
- Current, dated AI agent inventory covering approved and discovered systems
- Produced through programmatic discovery, not self-reporting only
- Signed and dated so currency can be verified under examination
Oversight
- Named individuals responsible for each material AI system
- Documented authority to intervene or suspend
- Evidence of oversight activity, not just oversight structure
Monitoring
- Documented monitoring cadence for each material system
- Records of monitoring activities with findings and actions
- Customer outcome monitoring records where Consumer Duty applies
Incident management
- AI-specific incident response procedures
- Records of incidents handled or process tested
Evidence packs
- Signed evidence packs at regular cadences
- Packs covering inventory, classifications, findings, and oversight status
- Signature verifiable as unaltered under examination
How AETHER Pulse Addresses FCA Supervision Readiness
AETHER Pulse provides the evidence infrastructure each of the five questions above requires. Its cross-platform discovery produces a signed, dated AI agent inventory. Its five-dimensional classification framework produces documented risk assessments. Its monthly signed evidence packs (HMAC-SHA256 signed, per-tenant keys) cover monitoring cadence, findings, oversight status, and FCA/ICO regulatory mapping. Every pack is verifiable, reproducible, and defensible under FCA supervision.
Published methodology: aetherpulse.app/methodology
Frequently Asked Questions
How much notice does the FCA give before an AI governance review?
Supervisory engagement can occur with varying levels of notice. Building evidence readiness before a request arrives is significantly more effective than retrospective documentation.
What if our AI governance programme is not yet complete?
A partially implemented programme with documented gaps and a credible remediation plan is a stronger regulatory position than undiscovered gaps. The FCA responds better to firms that understand their exposure and are actively addressing it.
Working on Article 26 readiness, deployer-side governance evidence, or AI agent risk at a regulated firm? We'd value 15 minutes of your perspective.
Start a conversation