Can a handful of humans effectively govern and steward a UK-regulated retail bank?
This page is an evolving investigation into whether a small human core can effectively govern and steward a UK-regulated retail bank (retaining real control, challenge, escalation authority, and evidential accountability), no matter how much of the underlying operation is performed by autonomous AI Agents. Headcount is an output of that governance question, not the goal: as the next section sets out, it isn't a single fixed number but a regulatory control floor plus a scale-dependent exception-handling layer.
Last updated: 2026-07-23
Solved in plain view, one beat at a time.
This page doesn't lead with a finished answer. It works through the problem in the open, in this order:
- The stakes: why getting this wrong is personal, not just corporate.
- The frame: how every claim below is labelled, and which of three different questions it's actually answering.
- The vocabulary: a shared scale for how autonomous is autonomous.
- The decision rights: that scale, applied to eight real decisions, not left as an abstraction.
- The structure: a concrete answer, the minimum viable org chart.
- The decomposition: four separable problems standing in the way (one conditional on product scope).
- The synthesis: four governing decisions, then the execution sequence that follows once they're made.
- What's still open: what this investigation hasn't resolved yet.
- The field: an annex on who's attempting pieces of this, not evidence for the argument above.
- Sources: everything above, cited.
Getting this wrong is personal, not just corporate.
Under the UK's Senior Managers & Certification Regime (SM&CR), a designated Senior Manager carries personal, non-delegable civil and criminal liability for regulatory failures in their business areas. If an autonomous algorithm causes consumer harm, the manager cannot deflect blame to the model or a third-party vendor. They must prove they took reasonable steps.
This investigation calls the model it's testing Minimum Viable Human Oversight: the smallest human core that can retain effective governance (control, challenge, escalation authority, and evidential accountability) over a UK-regulated retail bank, while satisfying the SM&CR, the Consumer Duty, and, where applicable, the PRA's model risk management standard SS1/23. SS1/23 formally applies only to firms with PRA-approved internal models for regulatory capital purposes. It's cited here as a design-discipline reference, not asserted as a universal legal requirement for every AI-native bank. The next section sets out exactly how this investigation labels its own claims and answers, before getting into vocabulary, structure, and the blockers themselves.
How every claim below is labelled, and which question it's actually answering.
A page like this one drifts easily into treating "minimum headcount" as a single number to be revealed. It isn't. Every substantive claim from here on is labelled against two frames: which layer of obligation it belongs to, and which of three genuinely different questions about headcount it's answering.
Legal floor
Binding requirements: legislation, the PRA Rulebook, the FCA Handbook, data protection law. Not proportionate, not optional, just required.
Supervisory floor
What regulators expect, proportionately, of new and growing banks. Real, but not the same as a binding legal minimum.
Design frontier
How far AI, outsourcing, and re-engineering can compress headcount without breaching the two floors above. This is where the actual experiment happens.
Regulatory minimum
What's required to be authorised and stay compliant.
Plausible steady-state
What a working digital bank would actually run with, day to day.
Prudent for growth
What's needed to scale without repeatedly failing control, resilience, or conduct expectations.
The Autonomy Spectrum (Levels 1–5)
The landmark Mills Review (FCA, July 2026) frames the transition of the human role across a five-tier autonomy spectrum. Levels 1–3 are well-served by existing frameworks. Levels 4 and 5 (where this investigation operates) introduce deep challenges for accountability, consumer protection, and systemic risk. The next section ties these levels to specific, real decisions, before moving on to the concrete question of what the org chart itself looks like.
Human as Operator
The human performs the task, using AI merely as an on-demand tool (e.g. generating summaries of complex product terms).
Human as Collaborator
The human and the AI plan and execute actions together, with continuous human input and refinement.
Human as Consultant
The AI analyses options and makes recommendations, while the human retains final decision-making power.
Human as Approver
The AI prepares, formats, and initiates transactions or client communications, which the human must actively authorise before execution.
Human as Observer
The AI acts continuously on its own within agreed parameters, logging its activity for retrospective human monitoring.
The spectrum applied to real decisions, not just described.
The autonomy levels above are vocabulary; this is where they become load-bearing. Not every decision a bank makes gets to use the full spectrum just because the bank overall operates at Level 4/5. Each decision type has its own ceiling, keyed to legal significance, customer harm potential, and reversibility.
| Decision | Autonomy ceiling | Legal significance | Harm potential | Reversibility | Why |
|---|---|---|---|---|---|
| Balance and transaction history enquiries | Level 5: Human as Observer | Low | Low | High | Read-only information with no transactional or legal consequence. |
| Routine payment execution within the customer's own account | Level 5: Human as Observer | Moderate | Moderate | Moderate | Money moves, but only within customer-authorised parameters, gated by the ledger-integrity Decision Token control. See ledger-integrity → |
| Credit approval strictly within pre-set policy limits | Level 4: Human as Approver | High | High | Moderate | The Consumer Credit Act and affordability rules apply; a human designed and can override the policy boundary, but doesn't review each individual approval. |
| Declining a credit application, or any other adverse automated decision | Level 3: Human as Consultant | High | High | Low | UK GDPR Article 22 gives a right to meaningful human review of solely-automated decisions with legal or similarly significant effects. See regulatory floor → |
| Vulnerable-customer identification and support pathway | Level 3: Human as Consultant | High | High | Moderate | Consumer Duty specifically targets outcomes for vulnerable customers. AI can flag signals, but a human designs and owns the support approach. See regulatory floor → |
| Changes to a live credit, fraud, or pricing model | Level 3: Human as Consultant | High | High | Moderate | Where SS1/23 applies, model changes need risk-function challenge before going live, not after. See ledger-integrity → |
| Prudential regulatory return submission | Level 3: Human as Consultant | High | High | Low | The CFO personally attests to accuracy; restating a submitted return is costly and reputationally damaging. See CFO → |
| Suspicious Activity Report filing and transaction "consent" decisions | Level 2: Human as Collaborator | High | High | Low | The MLRO's personal criminal liability makes this the least automatable decision in the whole investigation. See MLRO → |
Eight decision types, not an exhaustive list: the pattern generalises, but every additional decision type needs its own honest ceiling, not an assumed one. The next section turns from decisions to people: the org chart these ceilings imply.
The minimum viable org chart, anchored in SM&CR.
Not an invented org chart: each role below maps to a specific Senior Management Function (SMF) under the SM&CR, chosen because a specific regulatory obligation makes that human irreducible, not because of habit or hierarchy.
| Role | SM&CR function | Why this human can't be removed |
|---|---|---|
| CEO | SMF1: Chief Executive | Overall responsibility for the firm's conduct; the FCA/PRA require one identifiable, individually accountable person at the top, non-delegable to a model or vendor. |
| CFO | SMF2: Chief Finance | Bank of England new-bank guidance expects a CEO, Board Chair, and another executive (usually a CFO) before authorisation, and a functioning executive team including finance at full authorisation. Owns prudential reporting, capital and liquidity planning, and the accounts. |
| CRO | SMF4: Chief Risk | Owns the risk framework and risk-appetite sign-off. At the smallest scale this can be a proportionate, even part-time, function. Dedicated risk leadership becomes much harder to avoid only once the bank grows. Where the PRA's model risk management standard SS1/23 applies (firms with PRA-approved internal models specifically), it adds personal accountability for model risk decisions. |
| COO | SMF24: Chief Operations | Operational resilience obligations (SS1/21, SS2/21) require someone accountable for the resilience of important business services, including the AI infrastructure itself. The source research treats the SMF24 designation itself as "if applicable": at the smallest scale this accountability can sit with another executive rather than a dedicated COO. |
| MLRO | SMF17: Money Laundering Reporting Officer | A named, individually accountable human is a hard legal requirement under the Money Laundering Regulations 2017, closer to an absolute floor than any other role here. |
| Compliance Oversight | SMF16 | Owns regulatory compliance sign-off, including the advice-boundary escalations described under the blockers below. |
| DPO / Privacy Lead | Not an SM&CR function: UK GDPR Art. 37 | Not a Senior Management Function at all: a separate UK GDPR requirement, triggered wherever core activities involve large-scale, regular and systematic monitoring or large-scale special-category processing. For a digital-only retail bank running continuous transaction monitoring, a DPO is highly likely in practice even though the precise legal trigger depends on the processing design. Article 37(6) explicitly permits the role to be fulfilled on a service-contract basis, not necessarily in-house. |
| Head of Internal Audit | SMF5 | Independent assurance over the whole control environment is a required function, but in a non-significant firm it doesn't need to be a fully in-house SMF5. It can be outsourced to an external internal-audit provider, so long as oversight responsibility for that provider is allocated to another existing SMF. |
| NEDs (Chair, Chair of Risk, Chair of Audit, Senior Independent Director) | SMF9 / SMF10 / SMF11 / SMF14 | Independent challenge of the executive is the entire point of a NED. At minimum, at least two independent minds must participate in major policy and strategy decisions. The specific four-way split shown here can be proportionate at the smallest scale, but independent challenge itself cannot disappear or be automated. |
This mapping is a proposed starting point, not yet checked against the FCA/PRA's current Prescribed Responsibilities allocation. See "What's Still Open" below. Each role is planned to grow into its own dedicated page, exploring exactly how AI agents handle everything else within that role's remit.
The next section breaks down what actually stands in the way of this structure working in practice.
Four Core Blockers to AI-Native Banking
The org chart above only holds together if four structural barriers get resolved at the architectural level. Each blocker has a defined resolution path emerging from industry pilots and regulatory sandbox programmes, design-frontier work, sitting on top of the ten regulatory-floor obligations rather than replacing any of them.
Stochastic Execution vs. Deterministic Ledgers
The problem: AI models are probabilistic and can generate different outputs given identical inputs. Direct write-access to a core ledger introduces risk of transaction hallucinations, unauthorised cash movements, or reconciliation failures.
Resolution: Bifurcate the architecture: decouple the stochastic intelligence layer from the deterministic execution engine using a middleware gateway that requires a cryptographically signed, single-use Decision Token for every transactional action.
Conversational Perimeter Overstepping & the Advice Gap
The problem: Under FCA COBS 9A, providing a "personal recommendation" constitutes regulated financial advice requiring formal suitability assessments and licensed human sign-off. A conversational agent could inadvertently cross this boundary.
Resolution: Deploy domain-specific SLMs with built-in semantic guardrails. Implement a real-time semantic monitoring engine that detects boundary overstepping, steers the agent back to informational guidance, and escalates suitability cases to licensed humans.
Conditional: Not applicable to this investigation's locked baseline scope. See "The Frame" above: the phase-one product set is deliberately non-advised. This blocker only becomes live if a future product-scope decision adds advice-adjacent activities.
Financial Crime Detection & Threat-to-Control Latency
The problem: Money launderers and automated fraud networks operate at machine speed. Traditional AML systems rely on rigid rulesets with change-management cycles that take months, creating a critical latency gap.
Resolution: Build a dynamic, network-based financial crime detection loop using agentic platforms that replace static alerts with real-time behavioural analytics, compressing threat-to-control cycles from months to hours.
Critical Third-Party Concentration & Model Drift
The problem: Reliance on a small number of US hyperscalers for model hosting creates severe concentration risk. Financial models are also prone to drift, degrading accuracy over time as customer behaviour and markets shift.
Resolution: Adopt an "AI Factory" model on sovereign, air-gapped infrastructure using self-hosted open-source foundation models. Implement continuous drift monitoring with automated alerts and a deterministic rule-based fail-safe for core operations.
Four choices that govern this project: locked, or still open.
Per deep-research-report.md's own framing: before any execution sequence means anything, four scope decisions need an explicit answer. Two are locked here; two are still open.
| Decision | Status | Current position |
|---|---|---|
| Charter scope | Open | Implicitly assumed throughout as a full licensed deposit-taking bank: the FSCS and resolution-regime content on the regulatory floor only makes sense under that assumption. Not yet confirmed as a deliberate choice against the alternative (an EMI, BaaS overlay, or lending platform that wouldn't carry the same prudential obligations). |
| Product simplicity | Locked | Digital-only, no branches, current accounts, instant-access savings, debit cards, sponsor-based payments access, simple unsecured consumer lending. Advised investment products, complex SME banking, mortgages, cash services, and internal-model capital approval are explicitly out of scope: see "The Frame" above. |
| Outsourcing posture | Open | The control architecture identifies which functions can legitimately be outsourced (Internal Audit, the DPO), but this investigation hasn't yet decided whether the scenario model's headcount figures assume those functions are actually outsourced or kept in-house at the smallest scale. |
| AI decision boundary | Open | The Autonomy Spectrum is shared vocabulary, not yet a decision. Converting it into a formal decision-rights matrix (tied to legal significance, customer harm potential, and reversibility) is Tranche 6, not done yet. |
Once those are set: a five-phase execution sequence
Recombining the four resolved blockers and the org structure above into a sequence a real founding team could execute, to secure authorisation from the FCA and PRA and launch an AI-native regulated bank under Minimum Viable Human Oversight, downstream of the decisions above, not a replacement for making them.
- Phase 1: Core System Isolation & Deterministic Decoupling Construct a bifurcated backend that fully decouples the stochastic AI layer from the double-entry ledger. Every transaction requires a cryptographically signed, single-use Decision Token through an immutable middleware gateway.
- Phase 2: Machine-to-Machine Trust & Verification Protocols Build identity and payment layers around open W3C standards (DIDs, VCs). Every autonomous agent receives a Decentralised Identifier and Verifiable Credential, cryptographically linking it to its human controller.
- Phase 3: Secure Entry into FCA Innovation Sandbox Cohorts Apply for and participate in the FCA Supercharged Sandbox and AI Live Testing initiatives. Use controlled environments to stress-test conversational agents and underwriting models against adversarial inputs and model drift.
- Phase 4: Deploy the Automated Machine-Led Compliance Layer Deploy a parallel shadow assurance platform powered by specialised financial SLMs (e.g. Aveni FinLLM) monitoring 100% of live interactions. Automatically generate real-time evidence packs and escalate anomalies to human supervisors.
- Phase 5: Establish the SM&CR Accountability Map & Governance Framework Align the automated GRC platform with the Senior Managers & Certification Regime. Assign personal ownership of all algorithmic outcomes to designated Senior Management Functions (SMF24, SMF4, SMF16) with continuous regulator-ready evidence packs.
A page that only shows resolved-sounding answers is advocacy.
Every claim across this investigation is classified as a legal fact, a supervisory expectation, a modelling assumption, or an open hypothesis, including the specific open questions this section used to list inline (the org-structure mapping, the industry-landscape claims, the sandbox pilots, the untested blueprint). That detail now lives in one versioned place rather than being split across every page's own "still open" note.
Who's attempting pieces of this, not evidence for the headcount question.
This section is reference material, not part of the minimum-human argument itself. A distinct cohort of fintech startups, technology providers, and transitioning licensed institutions is actively establishing architectural precedents for AI-native banking: useful for understanding what's technically being attempted, not proof of what's legally or prudently required. None of these entries are cited in support of any headcount or governance claim made elsewhere on this page. Every claim below is still cited: see the "Unconfirmed" markers and the sources section for what's been re-checked and what hasn't.
Catena Labs
Agent Commerce Kit (ACK-ID & ACK-Pay) built on W3C standards for verifiable AI identities and machine-to-machine payments. Reported to have raised $48M. [6, 8]
Unconfirmed, pending verification.
BEYLA
"The Hive" real-time living memory with a Digital C-Suite of specialised AI humans. Reported to have refactored from GCP to AWS for UK regulatory standards. [9, 11]
Unconfirmed, pending verification.
Aveni
FinLLM suite of specialised financial SLMs providing Agent Assure: continuous machine-led shadow auditing, piloted in the FCA Supercharged Sandbox. [4, 5, 10, 11]
Unconfirmed, pending verification.
Solaris
Reported to be rebuilding core banking-as-a-service processes around autonomous AI agents, with human supervisors acting as compliance controllers.
Unconfirmed, pending verification.
Intellect Design Arena
AI Digital Banking platform across seven cognitive dimensions, reportedly targeting a 20% cost-to-income reduction and 22–28% return on equity. [7]
Unconfirmed, pending verification.
Napier AI
"Theseus" network-based AML detection combining cross-border datasets with graph-based visualisation and audit-ready case summaries. [11]
Unconfirmed, pending verification.
References & Further Reading
This investigation is grounded in regulatory publications, live sandbox programmes, and industry architecture. None of the sources below have been independently re-confirmed by Axiom Verity beyond transcription from the original research brief. Treat every citation as pending verification (see "What's Still Open" above).
Primary & regulatory sources
| # | Title | Publisher | Link |
|---|---|---|---|
| 1 | The Mills Review: AI and the future of retail financial services | FCA | View source →(opens in a new tab) |
| 2 | Financial Stability in Focus: Artificial intelligence in the financial system | Bank of England | View source →(opens in a new tab) |
| 11 | Supercharged Sandbox Showcase (Cohort 1) | FCA Innovation | View source →(opens in a new tab) |
| 12 | Senior Managers and Certification Regime | FCA | View source →(opens in a new tab) |
| 13 | The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 | legislation.gov.uk | View source →(opens in a new tab) |
| 15 | New Bank Start-up Unit: authorisation and mobilisation guidance | Bank of England | View source →(opens in a new tab) |
| 16 | Financial Services and Markets Act 2000, Schedule 6 (Threshold Conditions) | legislation.gov.uk | View source →(opens in a new tab) |
| 17 | SS1/21 – Operational resilience: Impact tolerances for important business services | Bank of England / PRA | View source →(opens in a new tab) |
| 18 | SS2/21: Outsourcing and third party risk management | Bank of England / PRA | View source →(opens in a new tab) |
| 19 | The Consumer Duty | FCA | View source →(opens in a new tab) |
| 20 | Guidance on AI and data protection (automated decision-making) | ICO | View source →(opens in a new tab) |
| 21 | Banking Act 2009, Part 1 (Special Resolution Regime) | legislation.gov.uk | View source →(opens in a new tab) |
| 22 | FCA Handbook: SYSC (Senior Management Arrangements, Systems and Controls) | FCA | View source →(opens in a new tab) |
| 23 | Data protection officers: accountability and governance guidance | ICO | View source →(opens in a new tab) |
Industry & vendor references
Cited for the specific landscape claims above, company and third-party sources, not regulatory ones.
| # | Title | Publisher | Link |
|---|---|---|---|
| 3 | AI-Native Financial Infrastructure: Rebuilding finance's core systems for the agentic era | Anthemis Group | View source →(opens in a new tab) |
| 4 | SMCR Compliance for AI Agents | What the FCA Expects | Aveni | View source →(opens in a new tab) |
| 5 | AI in Banking | Accountability & Consumer Duty | Aveni | View source →(opens in a new tab) |
| 6 | Agent Commerce Kit (ACK) | Catena Labs / GitHub | View source →(opens in a new tab) |
| 7 | Intellect Design Arena Launches AI Digital Banking Platform for UK & Europe | Intellect Design Arena | View source →(opens in a new tab) |
| 8 | Circle co-founder to build new 'AI-native' bank | Banking Dive | View source →(opens in a new tab) |
| 9 | From Hiring Challenge to FCA Readiness | W Talent UK | View source →(opens in a new tab) |
| 10 | Lloyds and Nationwide-backed Aveni raises £12m | FinTech Global | View source →(opens in a new tab) |
| 14 | AI compliance in banking: build governance into architecture | Backbase | View source →(opens in a new tab) |
This investigation is just beginning.
Future updates will add a dedicated page for the org structure above and one page per role, deep-dive pages for each of the four blockers, an interactive autonomy spectrum, a verification pass on every citation above, and a dated commentary log tracking how the research evolves with new regulatory guidance.