The question that most compliance functions are now confronting is not whether to use AI tools, but how to govern that use responsibly, consistently and in a way that will withstand regulatory scrutiny. Generic AI governance frameworks produced for enterprise-wide IT governance purposes are not well-suited to the specific context of a compliance function, where the stakes of a poorly-reviewed output are not reputational but regulatory and legal.

This guide offers a practical framework for compliance teams rather than theoretical principles. It is intended to be adapted to a firm's specific context rather than adopted wholesale, and it reflects the kinds of questions that regulators are likely to ask when AI use in compliance functions becomes a standard area of supervisory focus.

Starting point: what problem are you governing?

Before building a governance framework, compliance teams need to be clear about what they are actually governing. AI tools in a compliance context currently span a wide range of tasks: drafting assistance for SARs, EDD narratives, board reports and policies; research support for regulatory updates and enforcement analysis; screening assistance for sanctions and adverse media; training content generation; and increasingly, integration with transaction monitoring and risk-scoring systems where AI-powered components are embedded in vendor platforms.

Each of these use cases carries different accountability implications, different review requirements and different risk profiles. A governance framework that treats all of them identically will be too restrictive for low-risk drafting assistance and insufficiently rigorous for AI-assisted decisions in regulatory submission processes. The starting point for any effective governance framework is a clear taxonomy of how AI is being used, or is proposed to be used, across the compliance function.

The accountability principle

The foundational principle on which all other governance decisions should rest is that accountability for every compliance decision remains with the compliance professional responsible for that decision, regardless of the role that AI tools played in producing the output on which that decision was based. This is not merely a philosophical position: it reflects the regulatory reality that the FCA, OFSI and other UK regulators hold individuals and firms accountable for their compliance decisions, not the tools they used to support them.

In practical terms, this means that every AI-assisted output used in a regulated compliance process, including SARs submitted to the NCA, EDD files, risk assessments and board reports, must be reviewed, approved and owned by a named, qualified compliance professional before it is used or filed. The review is not a formality: it requires the reviewer to engage with the substance of the output and to be in a position to stand behind its accuracy and completeness independently of the AI tool that contributed to it.

Compliance teams that have not internalised this principle, and that are treating AI-generated output as a reduced-review product, are creating accountability gaps that will be exposed under regulatory scrutiny.

Designing the policy

An AI use policy for a compliance function should address five core questions. First, which tasks is AI permitted to assist with, and which are restricted or prohibited? Firms that draw no distinction between tasks, permitting AI assistance across all compliance activities including regulatory submissions, are taking on accountability risks that a proportionate policy would manage. Second, what review process is required for AI-assisted output before it is used, and how is that review documented? Third, who is responsible for maintaining and updating the prompt libraries, templates and AI workflows used in the compliance function, and what quality assurance applies to them? Fourth, how will the firm identify and respond to a materially incorrect or misleading AI output? Fifth, how will the firm demonstrate to a regulator, if asked, that it governs AI use responsibly?

The policy does not need to be lengthy or technically complex. What it needs to be is operationally specific, clearly communicated to everyone in the compliance function, and consistently applied with documented evidence of application.

Prompt governance: the overlooked element

One of the most practically important, and most commonly overlooked, elements of AI governance in a compliance context is the governance of prompts. The prompts used to instruct AI tools in compliance workflows are not incidental: they determine the quality, relevance and regulatory fitness of the output. Prompts that are poorly constructed, out of date, or designed for a different regulatory context will reliably produce output that requires more intensive remediation than a well-governed prompt library would generate.

Compliance teams should maintain a documented library of approved prompts for their standard use cases. That library should be subject to review and update when regulatory requirements change, when the AI tool itself is updated or replaced, and when operational experience reveals that particular prompts are generating unreliable or inconsistent output. Responsibility for maintaining the prompt library should be clearly assigned, not treated as an informal shared resource.

Vendor AI: a distinct governance challenge

Many compliance teams use AI without knowing it, because the transaction monitoring systems, sanctions screening tools and risk-scoring platforms that firms operate routinely incorporate AI-powered components. The governance obligations that apply to a compliance team using a general-purpose language model directly apply equally, and in some respects more acutely, to AI-powered features in vendor-supplied compliance technology.

Firms should understand what AI components are present in the technology they use for compliance purposes, how those components are trained and updated, what the vendor's own governance framework covers, and what obligations flow to the firm when AI-assisted outputs from those tools feed into regulatory decisions. The FCA's expectations around model governance and algorithmic accountability are relevant here, and firms that have not assessed their vendor AI exposure are likely to have an undocumented governance gap.

Preparing for regulatory scrutiny

The FCA has not yet published specific AI governance requirements for compliance functions, but its broader AI publications, including the joint Discussion Paper with the Bank of England and the PRA, and its supervisory approach to algorithmic systems in financial services, indicate clearly that AI governance in regulated functions will become a standard area of supervisory focus. The firms that will be best placed when that scrutiny arrives are those that have already built, documented and operated a governance framework, not those that begin responding when the question is asked.

The governance framework described in this guide is not the only approach, and it is not the final answer. What it is, is a starting point that is operationally grounded, proportionate to the actual risks that AI use presents in a compliance context, and capable of being evidenced under regulatory review.