AI governance can no longer sit with the technology team alone
The Financial Conduct Authority has warned that artificial intelligence is evolving faster than regulation can keep pace, and a reported one in five UK adults now say they would trust AI to make financial decisions. For the firms deploying it, the pressure is to show that their systems are accurate, explainable and able to withstand scrutiny from regulators and customers alike.
Martin Tombs is field chief technology officer for EMEA at Qlik, a data integration and analytics company, and works with large financial institutions on their data and AI strategies. In written answers to The Datatech Times he argues that governance, not capability, is now the harder problem, and that it cannot be left to the technology department.
"As AI becomes more deeply embedded across the financial sector, it is no longer confined to individual use cases," Tombs says. "From customer service to compliance and internal operations, AI now closely connects to the systems that reinforce decisions across multiple departments. That means governance can no longer sit solely with technology departments because effectiveness depends on closer collaboration between the teams developing and managing AI and those using its outputs day to day." What firms need, he says, is "a coordinated approach to accountability with clear ownership across data, risk and business functions."
In practice that might mean AI helping retail banking colleagues identify changing customer needs and service trends, supporting lending teams in analysing financial information, or helping compliance teams pick out unusual activity that warrants investigation, with accountability for the outcome sitting where the decision is taken.
Starting with the technology
Asked about the most common mistakes he sees when AI is deployed in regulated environments, he starts with the order of operations. "Many organisations make the mistake of starting with the technology rather than the business outcome. The most successful companies begin by thinking about what they are trying to achieve, and then use AI to redesign the way the business operates, not the other way around."
Without that outcome, he says, AI narrows to automating existing processes and reducing manual effort. "Those initiatives often produce measurable efficiency gains and quick wins, but they are only the first step. A key mistake is assuming those improvements alone will create lasting competitive advantage. Most businesses are pursuing similar use cases, meaning boosts to productivity quickly become the baseline rather than a point of differentiation." The organisations getting the most value are rethinking how work gets done, which in a regulated industry has to include governance and risk frameworks: replacing periodic reviews with real-time decision making, identifying customers who need support before they get in touch, or building AI into products from the outset rather than bolting it on afterwards.
Why governance is the harder problem
"The capabilities of AI are expanding rapidly and becoming increasingly accessible, meaning the technology itself is no longer the primary differentiator. As AI gains access to sensitive data, connected systems and business-critical decisions, the greatest challenge becomes governing how systems are developed and deployed."
That is acute in financial services, he says, where AI can influence access to credit, lending decisions, fraud detection and financial advice, often through third-party providers and inside complex regulatory frameworks. "As a result, regulators, boards and customers increasingly expect firms to demonstrate clear accountability for how AI is used. Organisations need to understand how decisions are reached, maintain oversight of third-party AI providers and be able to address issues when they arise."
Rising consumer trust raises the bar rather than lowering it. "If customers are willing to rely on AI for advice, firms must prove that their systems deserve that trust. That means demonstrating that AI is transparent and secure, and providing evidence that it consistently produces accurate results and performs consistently across different customer groups. Confidence in AI should be matched by confidence in the controls surrounding it." Customers are far less likely to accept an opaque decision or an unexplained error when AI is involved, he says. "If someone is declined for a loan, receives an unsuitable recommendation or has a legitimate payment blocked, the firm should be able to show what informed that outcome, identify who is accountable and ensure a person can review it."
Explainability as a commercial question
"Explainability has become a commercial issue because firms need to understand not only what their AI systems are doing, but why they are producing particular outcomes." That visibility, he says, lets a firm see what is driving customer behaviour, investigate issues more quickly and make better-informed decisions. He gives the example of opening a bank account, which runs through identity verification, onboarding, digital registration and first transactions; understanding why decisions are made at each stage, and where issues arise, lets a bank fix problems faster and find better outcomes for customers. The same applies across fraud detection, anti-money laundering and customer risk. "For financial institutions operating across complex legacy systems, a lack of visibility into how AI reaches decisions can lead to slower decision-making, higher operational costs and missed commercial opportunities."
Agentic AI sharpens the requirement. "The emergence of agentic systems marks a shift from AI that recommends actions, to AI that can take action autonomously. Autonomous agents can approve transactions, update customer records, trigger payments or interact with other systems with minimal human intervention." That raises the bar for explainability, he says. "Firms need to know which agent acted, what data it accessed, why a decision was made and how that decision can be audited or altered. Without that visibility, investigating incidents and demonstrating regulatory compliance becomes significantly harder." Governance therefore has to give end-to-end visibility across data, models and agents, and in financial services the consequences of getting it wrong arrive faster and cost more.
Where a firm that is behind should start
"The starting point is clear data lineage. Organisations need to understand where data comes from and how it informs AI outputs. Without that visibility, firms will struggle to explain or validate AI-driven decisions under increasing regulatory scrutiny." Data quality is equally important. "Even the most advanced AI models will produce unreliable results if they are trained on incomplete or poorly governed information, so providing strong data is a crucial first step." As AI spreads through processes, he says, poor data reinforces inaccurate patterns and makes errors harder to detect.
For firms that are behind on secure AI adoption, his advice is not to buy more tools. "The priority should be improving the quality and visibility of the data they already have, rather than simply deploying more AI tools. That means identifying the datasets that will improve decision-making and implementing the governance needed to use them consistently across the organisation. With those foundations in place, firms can scale AI with greater confidence and produce more reliable outcomes."