Compliance & governance
AI Audit Readiness: What UK Regulated Firms Must Show
AI audit readiness is not a product you buy or a certificate you display. It is the ability to show, at short notice, that every AI tool in your firm is governed, which tool, on whose data, who owns it, and how the output is checked. Here is what UK regulated firms actually need to hold, and why the deadline pressure is real this year.
By Jason Long · July 2026 · 7 min read
The short version
- AI audit readiness means being able to show, on demand, that every AI tool your firm uses is governed: which tool, on whose data, who is accountable, and how the output is checked. There is no certificate to buy, only evidence to hold.
- It matters now because the FCA has said it will publish a good and poor practice report for AI in financial services later in 2026, setting the bar firms will be measured against, and more than 75% of UK financial services firms already use AI (Mills Review, 6 July 2026).
- The same readiness applies outside finance: from the Data (Use and Access) Act 2025, the ICO now expects firms to evidence safeguards on automated decisions rather than rely on a blanket prohibition (ICO consultation closed 29 May 2026).
- Readiness is an evidence pack, not a technology project: a tool register, a one-page policy, a data-handling note per tool, and a named owner. A firm can assemble it in a weekend.
What is AI audit readiness? It is being able to demonstrate, on demand, that your firm’s AI use is governed: which tools are in use, what data each may touch, who is accountable, and how outputs are checked. It matters now because the FCA has said it will publish a good and poor practice report for AI in financial services later in 2026, the benchmark supervised firms will be measured against, and more than 75% of UK financial services firms already use AI (FCA, Mills Review, 6 July 2026).
Firms keep asking us how to get their AI "approved." No UK regulator approves AI tools. What they supervise is whether you can evidence that your use of AI is controlled. That reframes the whole exercise: readiness is not a technology project, it is an evidence pack, and an evidence pack is finishable.
Why "readiness" became urgent in 2026
The finance sector is furthest ahead, so watch it as the leading indicator. On 6 July 2026 the FCA published the final Mills Review, led by Sheldon Mills, examining how AI could transform retail financial services out to 2030. In parallel, the FCA’s AI Live Testing programme moved into its second cohort, eight firms including Barclays, Lloyds Banking Group and UBS, with trials that began in April 2026 and conclude by the end of the year; an evaluation report follows in Q1 2027 (FCA, 21 April 2026).
The practical signal for everyone else is the promised good and poor practice report. When a regulator publishes what "good" looks like, the firms that can already show their governance pass with a conversation; the firms that cannot start a scramble. Readiness is cheaper before that document lands than after.
It is not just a finance question
The same evidence expectation is arriving through data-protection law, which reaches every sector. The Data (Use and Access) Act 2025 reframed the UK rules on automated decision-making from a near-blanket prohibition into a right of challenge with safeguards, letting firms rely on any Article 6 lawful basis while keeping requirements for meaningful human involvement and decision-specific information. The ICO consulted on updated guidance to match, and that consultation closed on 29 May 2026. The shift is subtle but important: the burden moves from "are you allowed to do this?" to "can you evidence the safeguards?" That is an audit-readiness question by another name.
For the fuller map of how these regimes overlap, our guide to AI compliance for UK businesses untangles GDPR, the FCA and the EU AI Act into one checklist.
What an auditor or regulator actually looks for
Strip away the acronyms and the questions are the same across the FCA, the ICO, the SRA and the CQC. An audit-ready firm can answer all five without a meeting:
- Inventory. Which AI tools are in use, sanctioned or not? You cannot govern what you cannot see, and the most common failure we find first is shadow AI, staff using unapproved consumer tools on live work.
- Data handling. For each tool, does the vendor train on or retain your inputs? A free public chatbot and a tool contracted not to retain your data can produce the same draft, but only one is defensible.
- Accountability. Who owns each material AI use? Regulators expect a named person, not "the team."
- Human check. How is output reviewed before it reaches a client or a decision? "The AI said so" is not a defence in any regulated context.
- Policy. Is there a written rule staff actually follow, and does it match what they really do?
The distinction that saves you
Regulators supervise outcomes and governance, not the specific software. You do not need the "right" AI product. You need to show that whatever you use is inventoried, data-safe, owned, checked and covered by a policy. Separate the tool from the evidence and the readiness job becomes concrete.
The evidence pack, in a weekend
Readiness is four documents in most firms: a register of approved tools and permitted uses, a one-page AI policy staff will actually follow, a short data-handling note per tool, and a named owner. That is the pack that turns a regulator’s question into a two-minute answer. It is governance work, not a build, and a small firm can assemble the first version in a weekend. Finance firms will want to align theirs with the direction of travel in our guide to AI software for FCA compliance.
We work directly in FCA, SRA, ICO and CQC contexts and build the evidence pack around how your team actually operates. Our 90-minute AI readiness audit tells you, in plain English, exactly what you can already show and the two or three gaps to close before the regulator asks. Book a call to talk it through.
General information for UK firms, not legal, financial or compliance advice. Verify your obligations against current regulator guidance and, where needed, take professional advice. Last updated: 23 July 2026.
Sources
- FCA, Review into the long-term impact of AI on retail financial services (The Mills Review) — final review published 6 July 2026, led by Sheldon Mills, scope to 2030, "more than 75% of UK financial services firms are now using AI" — https://www.fca.org.uk/publications/calls-input/review-long-term-impact-ai-retail-financial-services-mills-review
- FCA, FCA announces second cohort for AI Live Testing (21 April 2026) — eight firms incl. Barclays, Lloyds Banking Group, UBS, Experian; testing began April 2026, concludes end 2026, evaluation report Q1 2027; "good and poor practice report for AI in financial services later in 2026" — https://www.fca.org.uk/news/press-releases/fca-announces-second-cohort-ai-live-testing
- ICO / Burges Salmon analysis, Automated decision-making: ICO consults on new guidance following DUAA reforms — DUAA 2025 reframes ADM from prohibition to a right of challenge with safeguards (any Article 6 basis; human involvement retained); consultation closed 29 May 2026 — https://www.burges-salmon.com/articles/102mruj/automated-decision-making-ico-consults-on-new-guidance-following-duaa-reforms/
Frequently asked
What is AI audit readiness?
It is the ability to show, at short notice, that your firm’s AI use is governed: a list of the tools in use, what data each one may touch, who is accountable, how outputs are checked, and the policy that binds it together. Regulators do not certify AI tools, so readiness is about evidence you hold, not a badge you obtain.
Does the FCA audit firms on their AI?
The FCA does not pre-approve AI software, but it supervises how regulated firms use it, and it has said it will publish a good and poor practice report for AI in financial services later in 2026. Its AI Live Testing programme, whose second cohort of eight firms (including Barclays, Lloyds and UBS) began in April 2026, is defining what good looks like. Being able to evidence your governance is how you stay on the right side of that line.
What documents prove AI audit readiness?
Four, in most firms: a register of approved tools and their permitted uses, a one-page AI policy fee-earners or staff will actually follow, a short data-handling note per tool (does the vendor train on or retain your data?), and a named accountable owner. Everything else builds on those.
Is AI audit readiness only a finance issue?
No. The Data (Use and Access) Act 2025 reframed UK rules on automated decision-making from a near-prohibition to a right of challenge with safeguards, so any firm making automated or profiling decisions must now evidence those safeguards. The ICO consulted on updated guidance that closed on 29 May 2026. The legal, care and accountancy sectors face the same evidence expectation under their own regulators.
Related insights
Want this sorted, properly?
Our 90-minute audit leaves you with a one-page action list: three things AI should be doing, what it will cost and what it will save. Keep the report either way.