What happens when AI gets an affordability calculation wrong and who is liable


 On 6 July 2026, the FCA published the Mills Review, its assessment of how artificial intelligence will reshape retail financial services by 2030. It opens with almost exactly this question. When an AI system arranges a customer's mortgage, moves their savings, or recommends a pension, who answers if it goes wrong. For a mortgage business, that is not an abstract question about the future. It is a question about what happens the day an affordability tool gets a case wrong, a customer is either approved for something they cannot sustainably repay or declined for something they could have afforded, and somebody has to explain what happened.

The short answer, and the one the FCA has now restated twice this year in different forms, is that the answer has not changed. The tool does not carry the liability. The firm does.

The regulator's position is not new, it is just being said more plainly

The FCA has never built a separate rulebook for AI, and it has said clearly it does not intend to. Its approach is to apply the frameworks that already exist, Consumer Duty, the Senior Managers and Certification Regime, and the systems and controls sourcebook, to whatever tool a firm is using, whether that tool is a spreadsheet, a person, or a model. In evidence to the Treasury Committee, FCA executive director David Geale told MPs that firms and individuals remain, in his words, "on the hook" for harm caused by AI under the Senior Managers regime. The FCA's Chief Data, Information and Intelligence Officer, Jessica Rusu, made a related point to the same committee, arguing that Consumer Duty and the Senior Managers regime together already give the regulator "enough regulatory bite" that a bespoke AI rulebook is not needed.

The Mills Review, led by FCA executive director Sheldon Mills, reaches the same conclusion for the years ahead. Its central finding is that accountability does not move as AI takes on more of the work. The review sets out what it calls an autonomy spectrum, five roles a human can occupy relative to an AI system, running from operator and collaborator through to consultant, approver, and observer. As firms move further along that spectrum, letting AI do more with less direct human involvement, the review's argument is that the existing rules still apply. They simply become harder to evidence.

Where the affordability decision actually sits in the chain

It helps to separate three things that get blurred together when people talk about AI liability.

The first is what the customer is owed. If an affordability tool produces a wrong outcome, the customer's complaint goes to the firm that gave them the recommendation, and from there to the Financial Ombudsman Service if it is not resolved. It does not go to the company that built the software. The customer has a relationship with the regulated firm, not with the vendor behind it, and that does not change because a model was involved somewhere in the process.

The second is what the regulator expects internally. Under the Senior Managers regime, every authorised firm needs at least one Senior Manager whose Statement of Responsibilities explicitly covers oversight of the AI systems used in customer facing decisions. In larger firms this tends to sit with the Chief Operations Function, who is generally responsible for the integrity of technology systems, and the Chief Risk Function, who owns model risk, data quality risk, and bias risk. Smaller firms do not need that structure, but they do need to be able to name the person who owns it. Under the duty of responsibility in the Financial Services and Markets Act, that named individual can be held personally accountable if a breach occurs and they failed to take reasonable steps to prevent or catch it. Not knowing that an AI tool was involved in a particular process is no longer treated as a defence.

The third is the vendor relationship, and this is where the confusion usually starts. Bringing in an outside AI provider does not transfer accountability away from the firm. The firm remains responsible for its own due diligence on the vendor, for the contractual terms it agrees, and for ongoing oversight of how the tool actually performs once it is live. If the vendor's tool turns out to be at fault, whatever the firm can recover from that vendor is a private, commercial matter, shaped by whatever indemnities, liability caps, and insurance were negotiated into the contract. It has no bearing on what the firm owes the customer. Those are two separate conversations, and the FCA treats them as two separate conversations too.

What reasonable steps looks like for an affordability tool specifically

Consumer Duty is explicit that where AI is used to assess eligibility, which is exactly what an affordability calculation is, firms need to be able to show how customer outcomes were considered before the tool went live and how they are monitored afterwards. In practice, for an affordability tool, that tends to come down to four things.

Whether the tool was tested against the cases that are hardest to get right before it was deployed, irregular income, self employment, multiple income streams, rather than only the straightforward ones.

Whether there is a named person who can explain, months after the fact, why a specific case was accepted or declined.

Whether performance is being monitored on an ongoing basis, not just signed off once at launch, since a model's behaviour can shift as it is retrained or updated.

And whether a human reviewer can actually see the reasoning behind a given output, rather than only the output itself. This is the same explainability point behind what this platform has called Glass Box AI, and it matters here for a very practical reason. A firm that can show its reasoning can correct a wrong decision quickly. A firm that only has an output has to reconstruct the reasoning from scratch, usually under regulatory pressure, which is a much harder position to be in.

What actually happens when a case goes wrong

Strip away the AI framing and the sequence looks familiar. A customer complains that they were approved for a mortgage they could not afford, or declined for one they could have managed. The complaint goes to the firm, and if unresolved, to the Financial Ombudsman Service. If the FCA takes an interest, the questions it asks are about governance rather than about the model itself, who signed off the tool, what testing evidence exists, and whether outcomes have been monitored since launch. The named Senior Manager then has to demonstrate that reasonable steps were taken, which is a different and lower bar than demonstrating the tool was never wrong. Every affordability process, human or automated, gets some cases wrong. The exposure is not in being wrong occasionally. It is in being unable to show who was watching for it, what they tested beforehand, and what they would have caught.

That is the shift worth paying attention to. Roughly three in four UK financial services firms are already using AI somewhere in their operations, according to the FCA and Bank of England's own joint survey. The question the regulator is now asking is not whether firms are using it. It is whether they can point to the person who owns it.

This piece explains the regulatory framework as it currently stands and is not legal advice on any specific case. Firms should take their own legal and compliance advice before relying on it.

Comments

Popular posts from this blog

The Loaded Premium Scandal: How a Quarter of the UK Protection Market Is Silently Overcharging Customers

How to use automation to convert more mortgage leads

7 things to look for in a Mortgage SaaS Platform