Banking

AI compliance in banking

AI in a bank must be explainable, auditable, and governed. Regulators do not care how clever the technology is. They care whether the bank can explain why it made a decision, who is accountable, and how it is controlled.

By Zakir Hoosen, Director, Fuzzelogic Solutions. Board-level guidance in plain English.

Compliance is not a technology problem. It is a governance problem. A bank that uses AI and cannot explain it to a regulator is non-compliant, regardless of how good the technology is. A bank that can explain every decision, every process, and every control is compliant, regardless of how simple the technology is.

This guide covers what regulators expect from banking AI, what the research says, and the practical steps a board should take.

What regulators expect

The expectation is straightforward. If AI makes or influences a decision that affects a customer, the bank must be able to explain that decision. Not in technical language. In plain English. To a customer, to a regulator, or to a court.

The Jersey Financial Services Commission issued AI governance guidance in July 2026. The Guernsey Financial Services Commission is moving in the same direction. The EU AI Act is already in force. The direction is clear: boards are expected to know what AI does in their business, who is responsible for it, and how it is controlled.

In plain language, a regulator will ask:

  1. What AI does the bank use?
  2. What decisions does it make or influence?
  3. Who is accountable for each decision?
  4. Can the bank explain why the system made a particular decision?
  5. How does the bank know the system is still working as intended?

If your board cannot answer those five questions, you have a compliance gap.

What the research says

The research is unflattering. Most organisations are not ready.

"21% of organisations have no AI governance at all, and governance and risk is the fastest growing barrier to adoption."

Source: Deloitte, State of AI in the Enterprise

One in five organisations has no governance. In banking, that is a compliance failure waiting to happen. The regulator does not need to find a problem with the technology. The regulator only needs to find a problem with the governance.

"61% of CEOs say boards are rushing AI transformation, and around 40% of boards lack an informed view of how AI changes growth strategy."

Source: BCG, CEOs and Boards are aligned on AI in theory but divided in practice

Boards are rushing. Compliance is not keeping up. The gap between what the board approved and what the regulator expects is the compliance risk.

The compliance framework

Fuzzelogic uses five tests for AI-readiness, which map directly to compliance requirements in banking.

  1. Reachable. Can the data the AI needs actually be found when it needs it? If not, the system is working on incomplete information. That is a data compliance issue.
  2. Trustworthy. Do you know the data is accurate, current, and complete? If not, the system is working on bad information. That is a data quality compliance issue.
  3. Explainable. Can someone explain why the system made a particular decision? If not, the bank cannot explain it to a regulator. That is a conduct compliance issue.
  4. Changeable. Can the system be changed when the rules change? If not, the bank is locked into a system that cannot adapt. That is a regulatory compliance issue.
  5. Governed. Has someone decided what the system may and may not do? If not, the system is operating without the controls a regulator expects. That is a governance compliance issue.

Each test maps to a compliance requirement a banking board should understand. If the board cannot pass the test, the compliance is not in place.

What a banking board should do

First, build the audit trail. Every AI decision must be traceable. Who made the decision? What data was used? What rules were applied? What was the outcome? If the audit trail does not exist, the compliance does not exist.

Second, test the explainability. Take a sample of AI decisions and ask the team to explain each one in plain English. If the answer is "the model decided," the system is not explainable. If the answer is a technical explanation that a customer would not understand, the system is not explainable enough.

Third, set the review cycle. Compliance is not a one-time event. The rules change. The data changes. The system changes. The board must set the dates, assign the people, and stick to them.

Fourth, document everything. Regulators do not just want to see that you are compliant. They want to see the evidence. If it is not documented, it did not happen.

"Nearly 8 in 10 organisations report no significant bottom line gains from agentic AI."

Source: McKinsey, Rewired to Outcompete

Most AI implementations do not deliver. The compliance cost is real. The return is not. A board that does not plan for compliance cost is planning for a loss.

The honest version

Fuzzelogic is an Isle of Man firm that has spent nineteen years modernising banking, insurance, healthcare, retail, manufacturing, and government platforms. We have worked with nine regulated financial institutions. We tell boards what most consultants will not: the honest answer is sometimes that AI should not touch a process at all, and when that is the case, we put it in writing.

Your systems were built for a world before AI. Most can get there. We tell you which ones cannot.

Start with the assessment. Two to four weeks, fixed price, and you own the verdict and the roadmap whether or not we build any of it. When you are ready to talk AI, call Fuzzelogic Solutions and ask for Zak. www.FuzzelogicSolutions.com | info@FuzzelogicSolutions.com | +44 (0)1624 618950

Read next: AI governance for banking boards and AI risk management in banking.

Start with the assessment

Two to four weeks, fixed price, and you own the verdict and the roadmap whether or not we build any of it.

Get in touch

When you are ready to talk AI, call Fuzzelogic Solutions and ask for Zak.

www.FuzzelogicSolutions.com | info@FuzzelogicSolutions.com | +44 (0)1624 618950