You are not against AI, and what you are against is AI that nobody in the business has thought through.
If you are a CRO or Head of Risk in an FCA or PRA-regulated business, you have spent the last two years getting your operational resilience house in order. You have mapped your important business services, defined impact tolerances and demonstrated you can operate within them, and the 31 March 2025 deadline has passed with you in compliance.
And now the CEO wants to introduce AI across the business, and your job is not to block it. Your job is to make sure it is done properly, with governance, accountability and a clear understanding of the risks.
The regulatory context is evolving fast
On 18 March 2026, the FCA and PRA published their finalised rules on operational incident and third-party reporting, taking effect from March 2027. Firms now need to report operational incidents that exceed prescribed thresholds and to maintain a register of material third-party arrangements. If your business is introducing AI capabilities, particularly those that rely on third-party models, cloud-based APIs or external vendors, these new requirements are directly relevant. Each AI vendor relationship is potentially a material third-party arrangement, each AI-dependent process is potentially an important business service and each AI failure is potentially a reportable incident.
This does not mean you should not adopt AI, and it means that you need to design the governance framework before you deploy the technology rather than after.
The CRO's AI checklist
1. Model risk and explainability
Every AI system that influences a business decision needs a model risk assessment covering who owns the model, how it was trained and what its known limitations are. That assessment also needs to establish whether you can explain the outputs of the system to the regulator if you are challenged on them.
For generative AI (large language models like GPT and Claude), explainability is particularly challenging because these models are probabilistic and do not follow deterministic rules. If you are using them for customer-facing decisions, claims assessment or regulatory reporting, you need a clear governance wrapper: human review thresholds, output validation and audit trails.
2. Data governance
AI systems are only as good as the data they consume, and if your data is inconsistent, incomplete or poorly governed, AI will amplify those problems. Before deploying any AI capability, confirm that the training data is appropriate and representative, that customer data is being processed in compliance with GDPR and your privacy policies and that data lineage and provenance are documented.
3. Third-party risk
Most mid-market businesses will use AI through third-party vendors rather than building in-house, and each vendor relationship needs to be assessed under your existing third-party risk management framework and the new FCA/PRA third-party reporting requirements.
The key questions are where the data is processed and stored and what happens if the vendor suffers an outage. You also need to know whether you have contractual rights to audit and whether the vendor relationship is one you would need to report under the new rules.
4. Operational resilience alignment
If an AI capability supports an important business service, it falls within your operational resilience framework, and that means asking whether you can operate within your impact tolerances if the AI system fails. It also means establishing whether you have a manual fallback and whether the dependency is documented in your business service mapping.
5. Consumer Duty alignment
If AI is used in customer-facing processes (pricing, claims, complaints and vulnerability identification) it must support good customer outcomes, and you need to demonstrate that it does not create bias or unfair outcomes. You also need to evidence that vulnerable customers are identified and treated appropriately, and your CCO will be asking these questions, so make sure you can answer them.
6. Board reporting and accountability
Under SM&CR, board reporting and accountability for AI risk must be explicit, starting with a clear answer on who owns it. Your board risk reports then need to include AI-specific risk indicators, and a governance committee or forum needs to oversee AI deployment.
7. Change management and testing
Every AI deployment should go through your existing change management process rather than bypass it because "it's just a pilot." Pilots have a way of becoming permanent, and the governance that was not applied at the start becomes impossible to retrofit.
What a good governance framework looks like
The businesses that do this well do not create a separate "AI governance" process, extending their existing risk management, change management and operational resilience frameworks to cover AI instead. This is more practical, more sustainable and more aligned with what the regulator expects.
It means adding AI-specific questions to your existing risk assessments, adding AI vendor relationships to your third-party register and including AI-dependent services in your operational resilience mapping. It also means ensuring that someone at senior management level is accountable for AI risk, with the authority and information to exercise that accountability properly.
Our experience
Oxygen Bubbles was founded by a CTO who has held SMF24 accountability for two UK insurers, led cyber maturity uplift to ISO 27001 and strengthened operational resilience across a portfolio of regulated businesses. That experience means we do not treat governance as an afterthought, and we design it into every AI initiative from the start.
Our Breathe engagement includes a governance and risk dimension alongside the capability and opportunity assessment. You do not get a roadmap that your risk team then has to pick holes in, and what you get is a roadmap that your risk team helped shape.
If you want the full checklist, get in touch and we will share it.
If your CEO is driving the AI conversation, share this governance perspective with them: The Blockbuster Question: Is Your Business Model Ready for the AI Era?
If your CCO needs the Consumer Duty angle, share this: How AI Can Help You Evidence Consumer Duty Outcomes