Posts

What happens when AI gets an affordability calculation wrong and who is liable

Image
  On 6 July 2026, the FCA published the Mills Review, its assessment of how artificial intelligence will reshape retail financial services by 2030. It opens with almost exactly this question. When an AI system arranges a customer's mortgage, moves their savings, or recommends a pension, who answers if it goes wrong. For a mortgage business, that is not an abstract question about the future. It is a question about what happens the day an affordability tool gets a case wrong, a customer is either approved for something they cannot sustainably repay or declined for something they could have afforded, and somebody has to explain what happened. The short answer, and the one the FCA has now restated twice this year in different forms, is that the answer has not changed. The tool does not carry the liability. The firm does. The regulator's position is not new, it is just being said more plainly The FCA has never built a separate rulebook for AI, and it has said clearly it does not int...

Consumer Duty audits are catching brokers out, what a defensible file actually looks like

Image
  A broker can walk into a file review feeling confident and still walk out with a list of findings. That has been happening more often since the Financial Conduct Authority told mortgage intermediaries, in a portfolio letter sent to chief executives in January 2025, that embedding the Consumer Duty properly would be its main supervisory focus for the following two years. Eighteen months on, the regulator has published enough findings across enough sectors to make one thing clear. A file that looks compliant and a file that is defensible are not always the same document. The gap between the two is where most of the trouble sits. A file can have every box ticked, every disclosure attached, every signature in place, and still fail to explain itself when someone outside the firm actually reads it. That is the standard now being applied, and it is worth understanding exactly what it involves before it gets applied to yours. What the regulator has actually been finding The January 2025 ...

The Loaded Premium Scandal: How a Quarter of the UK Protection Market Is Silently Overcharging Customers

Image
  Two commission models - one honest, one not There is a critical distinction in the UK protection insurance market that most customers will never hear about, because nobody in the distribution chain has any incentive to explain it to them. It is the distinction between enhanced commission and loaded premiums. Understanding the difference is essential, because one of these models works in the customer’s interest and the other works directly against it. The first model, enhanced commission is straightforward and, frankly, legitimate. Large mortgage clubs such as TMA and Paradigm distribute enormous volumes of protection business. Because they place thousands of policies per year with each insurer, they have the commercial leverage to negotiate enhanced commission rates for their member firms. An insurer might pay a standard indemnity commission of 200% of the annualised premium index (API) to a small directly authorised firm but offer 250% API through a major mortgage club. The crit...

The Precision Paradox: Why AI in regulated finance is a high-stakes tightrope walk

Image
  The Seduction is real. So is the risk. When I see the excitement around the latest wave of Agentic AI tools, I feel two things simultaneously: genuine admiration for what the technology can do, and a cold, quiet dread about where it is being deployed. That dread is not cynicism. It is experience. Tools like Clawbot and its contemporaries have arrived with enormous fanfare, and they deserve some of it. They reason across documents. They synthesise complex data. They converse with a fluency that genuinely mimics expertise. For a growth-hungry founder, they feel like the ultimate shortcut: deploy fast, scale faster, worry about the details later. But here is the uncomfortable truth that nobody in the demo room wants to say out loud: in a regulated industry, "cool" is a liability. The security architecture underpinning many of these models is, at best, immature. At worst, it is entirely unfit for the environments in which it is being deployed. The FCA and the Prudential Regulat...