Insight · 28 July 2026
The FCA calls the Mills Review the first of its kind. It tells firms what to evidence, but not how. Here is my answer.
I went into the Mills Review looking for the sentence where the FCA explains a set of controls or points to an established standard.
It isn’t there. The Review finds that AI will sharpen cyber risk by 2030, and that it is more likely to accelerate existing fraud typologies than create a wholly new category of crime. What it never does is name the standard that risk should be managed against.
The Review, published on 6 July and described by the FCA as the first work of its kind initiated by a regulator globally, examines how AI reshapes retail financial services out to 2030. It rests on 140 written submissions and a survey of just over five thousand UK consumers.
The Review recommends no new rules for firms. Its seven priority recommendations point the other way, at the regulator: secure the perimeter, scale the AI Lab, and build an AI-enabled agentic supervisory model that can watch outcomes across firms continuously rather than episodically.
No new rulebook might sound like reassurance. Is it?
What the Review actually found
Three findings matter for anyone running governance or security in a regulated firm.
First, the consumer shift. One in five UK adults today, roughly eleven million people, say they are likely to use AI that acts on its own inside goals they have set. Two thirds worry about data misuse, weak protection when things go wrong, and a small number of firms gaining power over their finances. When asked what would happen if something went wrong after using a general-purpose AI service for financial advice, only 40 per cent correctly identified that there is no formal route to recourse. That mismatch between perceived authority and actual protection will surface in complaints functions first.
Second, cyber. The work here is thorough. AI is more likely to accelerate existing fraud typologies than create a wholly new category of crime. Cloned voices, synthetic identities, scams tailored to one person, faster exploitation of existing weaknesses across onboarding, payment rails, telecoms and platforms. Firms that skimped on fundamentals get progressively more exposed, because capable models cut the cost of finding the flaw that was always present. The same capability runs both ways. Well-governed AI improves detection and triage. Badly governed AI manufactures false assurance, which is worse than none, because someone signs it.
Third, and least remarked on: the Review maps existing regulation against an autonomy spectrum, from AI seen as a tool at Level 1 to AI acting autonomously within pre-set boundaries at Level 5, showing the frameworks straining in a specific order. Operational resilience is the only regime the Review never shows operating cleanly. It strains from Level 1. The perimeter follows at Level 2, advice and guidance at Level 3. The Senior Managers and Certification Regime (SM&CR) and the Consumer Duty hold the longest, because they attach to a named individual and a demonstrable outcome rather than to a boundary drawn around a firm. Beyond Level 4, the Review says plainly, certain frameworks will require adaptation.
No new rules means the old ones do more work
The Review is unambiguous that accountability stays with senior managers in regulated firms. Across those submissions, firms consistently pressed for it to stay exactly there. So the operative text already exists. It repays reading as though the AI were somebody you had hired.
SC1: reasonable steps to ensure the business you are responsible for is controlled effectively. SC2: reasonable steps to ensure it complies with the relevant requirements and standards of the regulatory system. SC3: reasonable steps to ensure any delegation of your responsibilities is to an appropriate person, and that you oversee the discharge of it effectively. And the sixth individual conduct rule, which applies to all conduct rules staff where the Duty covers the firm’s activities: act to deliver good outcomes for retail customers.
SC3 is the one almost nobody has re-read since their first AI system went live. Delegation to a system is still delegation. "Appropriate person" and "oversee the discharge effectively" do not get easier when the recipient has no legal personality and a model provider ships changes on its own schedule.
The fact there are no new rules is not the finding. The finding is that the existing rules are now the AI rules, and AI is now part of a firm’s organisational responsibilities.
The gap the Review leaves open
The FCA has named an evidence requirement, but nowhere does it state the standard that the evidence must meet.
The Review observes only that in the absence of comprehensive frameworks, firms often look to voluntary standards from bodies such as NIST and ISO. There it names the bodies, not their standards, and endorses neither. ISO/IEC 42001 appears nowhere in its 147 pages. On its own AI Lab it is deliberate: the capability should inform firms and supervision "without becoming a certification function".
Good and poor practice is coming, later this year, informed by the AI Input Zone that closed in June. The FCA has already said what it asked firms about: how they oversee and govern AI, how they test models and monitor outcomes, how they ensure fair treatment for customers including those with features of vulnerability, and how they explain AI-driven decisions.
Read those four questions again. The FCA has said it will not introduce new regulations for AI, so what is coming is supervisory observation, not a conformity scheme. It will say what good looks like. Every one of the four is answered with a record, and that is still the thing nobody has told you how to build.
So a senior manager must evidence effective control of AI under SC1, compliance under SC2 and overseen delegation under SC3, against no stated benchmark. Their choice of standard, and the defence of that choice, sits with those named on the Statement of Responsibilities.
Which standard fills it
Test the standards that could be candidates against what the SM&CR actually demands: a repeatable, auditable record of control, produced continuously, owned by a named individual.
The EU AI Act is law, not a management system. It allocates obligations by role, reaches a UK firm only through EU market placement, EU-facing output or an EU-established entity, and gives you duties rather than a method. The NIST AI Risk Management Framework is useful as an analysis method, but it is voluntary guidance with no certification mechanism, no audit cycle and no management clause structure. It tells you how to think about the risk. It does not produce the record. ISO/IEC 27001 produces the record, but its scope is information security. It has no view on model behaviour, data provenance for training, impact on the people subject to AI decisions, or human oversight of autonomous action.
ISO/IEC 42001 is the only candidate built for the job: a certifiable management system standard specifically for AI, and since July 2025 the certification bodies have had their own rulebook, ISO/IEC 42006, which is what makes one accredited certificate mean the same as another.
On its own, 42001 would be another silo. Integrated into an existing 27001 ISMS it becomes something better, because both standards share the same harmonised structure. One management review. One internal audit programme. One document control system. One corrective action process. Two regimes, and one record.
My recommendation, and the one I would defend: ISO/IEC 42001 integrated with ISO/IEC 27001 as the evidence engine, with the NIST AI RMF shaping the risk analysis and, where it does the job better, the controls themselves. Not because certification impresses the FCA, but because the integrated system produces, as routine output, exactly the record the SM&CR demands.
Clause 6.1.3 allows that substitution. What it does not allow is skipping the comparison. Every Annex A control you leave out has to be named and justified in the Statement of Applicability, and an auditor reads those justifications more closely than anything else in the file.
A standards reader might note that ISO/IEC 38507 and ISO/IEC 38500 sit above this at the governing body layer. They are guidance. They tell a board how to direct and monitor. They produce no record, and they are not a substitute for the management system. The board directs with them; the firm evidences with 42001 and 27001. This piece is about the layer that produces the evidence, because that is the layer the SM&CR leans on.
How it bolts onto the governance you already run
The mapping is tighter than it looks. Clause by clause.
Clause 5 of 42001 requires leadership to assign AI roles, responsibilities and authorities. That maps directly onto the Statement of Responsibilities. The SMF holder who owns each AI deployment is named in the management system, not inferred from an org chart after something has gone wrong.
Clause 6 requires AI risk assessment and an AI system impact assessment, assessing consequences for the people subject to the system, not only for the firm. ISO/IEC 42005 is the guidance on doing that well. Point that at customer-facing deployments and it becomes the mechanism behind Consumer Duty outcomes testing: a documented, repeatable answer to whether the system delivers good outcomes for retail customers and not an annual attestation written from memory.
Clause 8 and the Annex A controls cover operational planning, human oversight, supplier management and lifecycle logging. This is most closely aligned with SC3. The standard does not hand you a delegation regime, but the management system is where you build and evidence one: what each system may do, within what bounds, reviewed when and withdrawn how. That is delegation inside your own walls. The consumer-facing version, mandates that travel between firms, is a different problem, and no standard solves it yet. Supplier controls carry the same discipline out to the model provider, which is where the Review says the concentration risk sits.
Clause 9 gives you monitoring, internal audit and management review. Feed those into existing board risk committee reporting and second line assurance, and AI becomes a standing line in the governance the firm already runs, not a special agenda item. Clause 10, nonconformity and corrective action, is your bridge to incident management and to SC4’s disclosure duty: when something goes wrong, the record of what, who and what changed already exists.
For a firm that already runs an ISO/IEC 27001 information security management system, this is machinery it operates today, extended through ISO/IEC 42001 to cover the part it has actually deployed. For a firm that doesn’t have 27001 yet, it is the same machinery built once, for two regimes at the same time, instead of retrofitted one at a time later.
The honest limit
ISO/IEC 42001 does not remedy everything, and anyone who tells you it does has not implemented one. The Review’s hardest problems sit at Levels 4 and 5 (see the spectrum above): agent identity that travels between firms, pre-authorised and revocable consumer mandates, liability allocation when an autonomous agent transacts. No published standard resolves them. The nearest work is recent and unfinished, concept papers and standards initiatives rather than published requirements. My belief is that they will be resolved in law and scheme rules.
Certification is evidence that a management system exists. It is not evidence that it works.
Certification is evidence that a management system exists. It is not evidence that it works. What the integrated system gives a senior manager is narrower and more useful: the record. What each system does, who approved it, on what basis, under what review, with what evidence of outcome. Built once, for two regimes, before the FCA’s evidence-led response arrives and asks for it.
The Review says the pace is uncertain and the direction is clear, but it leaves the standard question open. Somebody has to close it for their own firm. The ever-increasing cyber risk due to AI is the reason to do it before the questions get asked.