The FCA Mills Review: Why agentic AI demands a new approach to operational oversight
The publication of the FCA Mills Review signals a fundamental shift in how the regulator intends to monitor the financial services sector. It is moving toward an AI-enabled supervisory model that will scrutinize agentic AI deployments with unprecedented precision.
The shift toward agentic supervision
The FCA's landmark Mills Review represents a turning point for retail financial services. By detailing a vision for an AI-enabled supervisory model, the regulator has signalled that it will no longer rely solely on static reports or traditional audits. Instead, it intends to deploy its own technological tools to track the behaviour of agentic AI systems within firms. For investment managers and fund administrators, this means that the internal logic, decision paths, and operational boundaries of your AI agents will soon be subject to live, data-driven scrutiny.
The challenge of visibility
Many firms struggle to define the exact boundaries of their existing automation. When you introduce agentic AI, which consists of systems capable of autonomous decision-making and cross-platform execution, the complexity of monitoring grows exponentially. If you cannot explain the specific sequence of events that led to a machine-driven outcome, you will be unable to satisfy the regulator that your governance frameworks are robust. Relying on superficial process documentation is no longer sufficient when the regulator is looking at granular, high-frequency operational evidence.
Why traditional mapping fails
Standard process mapping often captures only the idealised version of a workflow. In a regulated environment, however, the gap between the design and the reality of how work gets done is where the greatest risks reside. Firms often attempt to bridge this by relying on event logs, but these rarely capture the nuanced, cross-departmental interactions that define modern financial services. Process mapping without event logs is essential for creating an accurate baseline that reflects how your team actually works, rather than how you think it works.
Aligning your AI strategy with regulatory expectations
Before any deployment, you must be able to prove value and risk mitigation. This requires a shift in how you select use cases. Instead of pursuing theoretical efficiencies, firms should adopt a methodology that focuses on deciding where AI belongs by scoring specific tasks for automation potential and regulatory risk. By performing an AI opportunity assessment before writing any code, you ensure that your deployment aligns with both business objectives and the high standards of conduct expected by the FCA.
The role of operational resilience
The Mills Review underscores the importance of maintaining oversight even as systems become more autonomous. This is closely linked to broader mandates, such as DORA operational resilience process mapping, where the focus is on maintaining continuous services under stress. If your AI agents are integral to your operations, their failure or errant behaviour constitutes an operational resilience failure. Proving that you understand the dependencies and risks of these agents is not just a technical task but a core requirement for compliance.
Preparing your firm for the future
Firms that take a proactive stance on AI readiness will be better positioned to navigate the coming wave of regulatory scrutiny. This is not about slowing down innovation. It is about building an evidenced workflow that allows for auditability. By mapping your current operational reality and pressure-testing your assumptions, you can deploy AI with confidence. If you are ready to evaluate your readiness or discuss how to approach these complex workflows, you can reach out to gerry.murtagh@pinpointproof.com or book a conversation to explore how to build an evidenced AI strategy.
Questions this article raises.
What does the FCA mean by an agentic supervisory model?
The FCA intends to use its own AI technologies to supervise firms by observing and analysing the behaviour of agentic AI systems directly. This move indicates a shift toward real-time, data-driven regulatory oversight rather than periodic, document-based reporting.
Why is standard process mapping insufficient for AI compliance?
Standard mapping often documents theoretical processes rather than the actual, messy reality of daily operations. When deploying AI, regulators require proof that you understand the precise, evidenced workflow, including how autonomous agents interact with existing systems and data.
How can firms prepare for increased regulatory scrutiny of AI?
Firms should prioritise auditing their current operational workflows before automating. By identifying clear, low-risk areas for AI application and building an evidenced record of how these processes function, firms can demonstrate robust governance to the regulator.
Know where to start.
Prove it worked.
Book a thirty-minute walkthrough. Bring one process; we will show you what its map, scores and opportunity register look like.
Pick a time that suits you. No form to fill in first.