
The Bank of England and its Prudential Regulation Authority are increasing engagement with regulated financial institutions on the implementation and supervision of artificial intelligence, highlighting both industry support for the current framework and emerging concerns around model governance, risk management and implementation practices.
The results of a series of roundtables and discussions in 2025, including sessions dedicated to the risks of AI and machine learning models, will shape the evolution of expectations for responsible use within banks, insurance companies, and other businesses.
Three roundtables held in late 2025 under the auspices of the PRA brought together representatives from a range of regulated sectors, including challenger banks, large UK-focused banks, and global systemically important banks and insurers, to discuss the opportunities and challenges posed by AI adoption.
Watchdogs from the Financial Conduct Authority and the Treasury also participated, reflecting interest among regulators in how companies are implementing AI into core functions.
Participants broadly expressed support for the PRA’s current regulatory framework as it relates to AI, noting that the regulator’s principled, results-based policies and supervisory statements provide ample room for companies to innovate while maintaining sound risk practices.
Supervisory Statement on Model Risk Management 1 23 was selected by several attendees as a realistic enabler of responsible AI adoption.
However, constraints and practical hurdles also surfaced during the discussions. The companies said second-line risk functions remain cautious in their use of AI, suggesting that as AI and more autonomous systems become more prevalent, existing model risk management approaches may become unsustainable.
This reflects feedback across the industry that governance frameworks are struggling to keep up with rapidly evolving technology.
In another session hosted by PRA in October 2025, chief risk officers and senior model risk experts from 21 regulated entities engaged with supervisors on the implementation of AI and ML technologies in the context of implementing supervisory expectations in SS1 23.
These conversations focus on how companies are applying model governance, validation, explainability, and oversight of third-party AI or outsourced models, reinforcing regulators’ focus on governance and risk management, rather than just AI as an innovation tool.
The message to technology teams, QA professionals, and testing departments is clearly that effective model risk management and rigorous testing practices need to keep up with AI adoption.
This means not only ensuring that AI systems deliver the expected results, but also documenting governance frameworks, validation results, and control structures that support responsible use and prepare for supervisory inspection.
Governance and risk constraints
Specific governance and risk constraints were highlighted in the discussion. Companies noted that traditional approaches to modeling risk, often built around well-understood static statistical models, may not be sustainable in situations where AI and agent systems rapidly change behavior and introduce opacity and uncertainty.
This makes it imperative for QA teams to develop new validation strategies for algorithm performance, transparency, and robustness in the face of evolving data inputs and decision logic.
Despite the industry’s cautious stance, many participants still did not see the need for detailed AI-specific regulatory guidance or norms, instead supporting regulators to share their observations on good practices and opportunities to define what responsible adoption looks like.
This reflects a broader theme in regulatory engagement that balances enabling innovation with operational resilience and safeguarding governance.
For QA and software testing teams at banks and financial companies, these discussions suggest several areas for strengthening supervisory interest governance, including model selection and validation, explainability and auditability of AI output, alignment of risk management frameworks and technology lifecycles, and the ability to monitor model drift, bias, or failure over time.
In fact, quality assurance now includes not only software correctness, but also model performance, resilience, and compliance with risk principles based on regulatory expectations.
PRA’s engagement with enterprises shows that as AI becomes more deeply embedded in front, middle, and back office functions, governance, testing, and control frameworks will become central to responsible implementation.
Effective quality assurance in this environment goes beyond validating outputs and requires documenting robust governance practices, demonstrating controls, and preparing for oversight scrutiny that focuses on how AI systems are managed, tested, and governed in real-world production environments.


Interested in becoming a QA Financial subscriber?
It’s completely free
* Receive our weekly newsletter every Wednesday * Receive priority invitations to forum events *
Register here now
Regulation and compliance
Looking for news about the regulations and compliance requirements that drive the development of software quality engineering in financial companies? Visit our dedicated site Click here for the Regulations and Compliance page.
read more
Watch now


QA Financial Podcast

