Can a handful of humans effectively govern and steward a UK-regulated retail bank?

This page is an evolving investigation into whether a small human core can effectively govern and steward a UK-regulated retail bank (retaining real control, challenge, escalation authority, and evidential accountability), no matter how much of the underlying operation is performed by autonomous AI Agents. Headcount is an output of that governance question, not the goal: as the next section sets out, it isn't a single fixed number but a regulatory control floor plus a scale-dependent exception-handling layer.

Last updated: 2026-07-23

Solved in plain view, one beat at a time.

This page doesn't lead with a finished answer. It works through the problem in the open, in this order:

  1. The stakes: why getting this wrong is personal, not just corporate.
  2. The frame: how every claim below is labelled, and which of three different questions it's actually answering.
  3. The vocabulary: a shared scale for how autonomous is autonomous.
  4. The decision rights: that scale, applied to eight real decisions, not left as an abstraction.
  5. The structure: a concrete answer, the minimum viable org chart.
  6. The decomposition: four separable problems standing in the way (one conditional on product scope).
  7. The synthesis: four governing decisions, then the execution sequence that follows once they're made.
  8. What's still open: what this investigation hasn't resolved yet.
  9. The field: an annex on who's attempting pieces of this, not evidence for the argument above.
  10. Sources: everything above, cited.

Getting this wrong is personal, not just corporate.

Under the UK's Senior Managers & Certification Regime (SM&CR), a designated Senior Manager carries personal, non-delegable civil and criminal liability for regulatory failures in their business areas. If an autonomous algorithm causes consumer harm, the manager cannot deflect blame to the model or a third-party vendor. They must prove they took reasonable steps.

This investigation calls the model it's testing Minimum Viable Human Oversight: the smallest human core that can retain effective governance (control, challenge, escalation authority, and evidential accountability) over a UK-regulated retail bank, while satisfying the SM&CR, the Consumer Duty, and, where applicable, the PRA's model risk management standard SS1/23. SS1/23 formally applies only to firms with PRA-approved internal models for regulatory capital purposes. It's cited here as a design-discipline reference, not asserted as a universal legal requirement for every AI-native bank. The next section sets out exactly how this investigation labels its own claims and answers, before getting into vocabulary, structure, and the blockers themselves.

How every claim below is labelled, and which question it's actually answering.

A page like this one drifts easily into treating "minimum headcount" as a single number to be revealed. It isn't. Every substantive claim from here on is labelled against two frames: which layer of obligation it belongs to, and which of three genuinely different questions about headcount it's answering.

Legal floor

Binding requirements: legislation, the PRA Rulebook, the FCA Handbook, data protection law. Not proportionate, not optional, just required.

Supervisory floor

What regulators expect, proportionately, of new and growing banks. Real, but not the same as a binding legal minimum.

Design frontier

How far AI, outsourcing, and re-engineering can compress headcount without breaching the two floors above. This is where the actual experiment happens.

Regulatory minimum

What's required to be authorised and stay compliant.

Plausible steady-state

What a working digital bank would actually run with, day to day.

Prudent for growth

What's needed to scale without repeatedly failing control, resilience, or conduct expectations.

This investigation's phase-one scope, locked: digital-only, UK-incorporated, non-systemic, no branches. Current accounts, instant-access savings, debit cards, Faster Payments/Bacs access via a sponsor or agency model, simple unsecured consumer lending. Explicitly out of scope for now: advised investment products, complex SME banking, mortgages, cash services, and internal-model capital approval. Any of these can be added later, but only as an explicit, stated change to the scope, not a silent assumption.

The Autonomy Spectrum (Levels 1–5)

The landmark Mills Review (FCA, July 2026) frames the transition of the human role across a five-tier autonomy spectrum. Levels 1–3 are well-served by existing frameworks. Levels 4 and 5 (where this investigation operates) introduce deep challenges for accountability, consumer protection, and systemic risk. The next section ties these levels to specific, real decisions, before moving on to the concrete question of what the org chart itself looks like.

Level 1 · Established

Human as Operator

The human performs the task, using AI merely as an on-demand tool (e.g. generating summaries of complex product terms).

Level 2 · Established

Human as Collaborator

The human and the AI plan and execute actions together, with continuous human input and refinement.

Level 3 · Established

Human as Consultant

The AI analyses options and makes recommendations, while the human retains final decision-making power.

Level 4 · Frontier

Human as Approver

The AI prepares, formats, and initiates transactions or client communications, which the human must actively authorise before execution.

Level 5 · Frontier

Human as Observer

The AI acts continuously on its own within agreed parameters, logging its activity for retrospective human monitoring.

The spectrum applied to real decisions, not just described.

The autonomy levels above are vocabulary; this is where they become load-bearing. Not every decision a bank makes gets to use the full spectrum just because the bank overall operates at Level 4/5. Each decision type has its own ceiling, keyed to legal significance, customer harm potential, and reversibility.

DecisionAutonomy ceilingLegal significanceHarm potentialReversibilityWhy
Balance and transaction history enquiriesLevel 5: Human as ObserverLowLowHighRead-only information with no transactional or legal consequence.
Routine payment execution within the customer's own accountLevel 5: Human as ObserverModerateModerateModerateMoney moves, but only within customer-authorised parameters, gated by the ledger-integrity Decision Token control. See ledger-integrity →
Credit approval strictly within pre-set policy limitsLevel 4: Human as ApproverHighHighModerateThe Consumer Credit Act and affordability rules apply; a human designed and can override the policy boundary, but doesn't review each individual approval.
Declining a credit application, or any other adverse automated decisionLevel 3: Human as ConsultantHighHighLowUK GDPR Article 22 gives a right to meaningful human review of solely-automated decisions with legal or similarly significant effects. See regulatory floor →
Vulnerable-customer identification and support pathwayLevel 3: Human as ConsultantHighHighModerateConsumer Duty specifically targets outcomes for vulnerable customers. AI can flag signals, but a human designs and owns the support approach. See regulatory floor →
Changes to a live credit, fraud, or pricing modelLevel 3: Human as ConsultantHighHighModerateWhere SS1/23 applies, model changes need risk-function challenge before going live, not after. See ledger-integrity →
Prudential regulatory return submissionLevel 3: Human as ConsultantHighHighLowThe CFO personally attests to accuracy; restating a submitted return is costly and reputationally damaging. See CFO →
Suspicious Activity Report filing and transaction "consent" decisionsLevel 2: Human as CollaboratorHighHighLowThe MLRO's personal criminal liability makes this the least automatable decision in the whole investigation. See MLRO →

Eight decision types, not an exhaustive list: the pattern generalises, but every additional decision type needs its own honest ceiling, not an assumed one. The next section turns from decisions to people: the org chart these ceilings imply.

The minimum viable org chart, anchored in SM&CR.

Not an invented org chart: each role below maps to a specific Senior Management Function (SMF) under the SM&CR, chosen because a specific regulatory obligation makes that human irreducible, not because of habit or hierarchy.

RoleSM&CR functionWhy this human can't be removed
CEOSMF1: Chief ExecutiveOverall responsibility for the firm's conduct; the FCA/PRA require one identifiable, individually accountable person at the top, non-delegable to a model or vendor.
CFOSMF2: Chief FinanceBank of England new-bank guidance expects a CEO, Board Chair, and another executive (usually a CFO) before authorisation, and a functioning executive team including finance at full authorisation. Owns prudential reporting, capital and liquidity planning, and the accounts.
CROSMF4: Chief RiskOwns the risk framework and risk-appetite sign-off. At the smallest scale this can be a proportionate, even part-time, function. Dedicated risk leadership becomes much harder to avoid only once the bank grows. Where the PRA's model risk management standard SS1/23 applies (firms with PRA-approved internal models specifically), it adds personal accountability for model risk decisions.
COOSMF24: Chief OperationsOperational resilience obligations (SS1/21, SS2/21) require someone accountable for the resilience of important business services, including the AI infrastructure itself. The source research treats the SMF24 designation itself as "if applicable": at the smallest scale this accountability can sit with another executive rather than a dedicated COO.
MLROSMF17: Money Laundering Reporting OfficerA named, individually accountable human is a hard legal requirement under the Money Laundering Regulations 2017, closer to an absolute floor than any other role here.
Compliance OversightSMF16Owns regulatory compliance sign-off, including the advice-boundary escalations described under the blockers below.
DPO / Privacy LeadNot an SM&CR function: UK GDPR Art. 37Not a Senior Management Function at all: a separate UK GDPR requirement, triggered wherever core activities involve large-scale, regular and systematic monitoring or large-scale special-category processing. For a digital-only retail bank running continuous transaction monitoring, a DPO is highly likely in practice even though the precise legal trigger depends on the processing design. Article 37(6) explicitly permits the role to be fulfilled on a service-contract basis, not necessarily in-house.
Head of Internal AuditSMF5Independent assurance over the whole control environment is a required function, but in a non-significant firm it doesn't need to be a fully in-house SMF5. It can be outsourced to an external internal-audit provider, so long as oversight responsibility for that provider is allocated to another existing SMF.
NEDs (Chair, Chair of Risk, Chair of Audit, Senior Independent Director)SMF9 / SMF10 / SMF11 / SMF14Independent challenge of the executive is the entire point of a NED. At minimum, at least two independent minds must participate in major policy and strategy decisions. The specific four-way split shown here can be proportionate at the smallest scale, but independent challenge itself cannot disappear or be automated.

This mapping is a proposed starting point, not yet checked against the FCA/PRA's current Prescribed Responsibilities allocation. See "What's Still Open" below. Each role is planned to grow into its own dedicated page, exploring exactly how AI agents handle everything else within that role's remit.

The next section breaks down what actually stands in the way of this structure working in practice.

Four Core Blockers to AI-Native Banking

The org chart above only holds together if four structural barriers get resolved at the architectural level. Each blocker has a defined resolution path emerging from industry pilots and regulatory sandbox programmes, design-frontier work, sitting on top of the ten regulatory-floor obligations rather than replacing any of them.

Stochastic Execution vs. Deterministic Ledgers

The problem: AI models are probabilistic and can generate different outputs given identical inputs. Direct write-access to a core ledger introduces risk of transaction hallucinations, unauthorised cash movements, or reconciliation failures.

Resolution: Bifurcate the architecture: decouple the stochastic intelligence layer from the deterministic execution engine using a middleware gateway that requires a cryptographically signed, single-use Decision Token for every transactional action.

Conversational Perimeter Overstepping & the Advice Gap

The problem: Under FCA COBS 9A, providing a "personal recommendation" constitutes regulated financial advice requiring formal suitability assessments and licensed human sign-off. A conversational agent could inadvertently cross this boundary.

Resolution: Deploy domain-specific SLMs with built-in semantic guardrails. Implement a real-time semantic monitoring engine that detects boundary overstepping, steers the agent back to informational guidance, and escalates suitability cases to licensed humans.

Conditional: Not applicable to this investigation's locked baseline scope. See "The Frame" above: the phase-one product set is deliberately non-advised. This blocker only becomes live if a future product-scope decision adds advice-adjacent activities.

Financial Crime Detection & Threat-to-Control Latency

The problem: Money launderers and automated fraud networks operate at machine speed. Traditional AML systems rely on rigid rulesets with change-management cycles that take months, creating a critical latency gap.

Resolution: Build a dynamic, network-based financial crime detection loop using agentic platforms that replace static alerts with real-time behavioural analytics, compressing threat-to-control cycles from months to hours.

Critical Third-Party Concentration & Model Drift

The problem: Reliance on a small number of US hyperscalers for model hosting creates severe concentration risk. Financial models are also prone to drift, degrading accuracy over time as customer behaviour and markets shift.

Resolution: Adopt an "AI Factory" model on sovereign, air-gapped infrastructure using self-hosted open-source foundation models. Implement continuous drift monitoring with automated alerts and a deterministic rule-based fail-safe for core operations.

Four choices that govern this project: locked, or still open.

Per deep-research-report.md's own framing: before any execution sequence means anything, four scope decisions need an explicit answer. Two are locked here; two are still open.

DecisionStatusCurrent position
Charter scopeOpenImplicitly assumed throughout as a full licensed deposit-taking bank: the FSCS and resolution-regime content on the regulatory floor only makes sense under that assumption. Not yet confirmed as a deliberate choice against the alternative (an EMI, BaaS overlay, or lending platform that wouldn't carry the same prudential obligations).
Product simplicityLockedDigital-only, no branches, current accounts, instant-access savings, debit cards, sponsor-based payments access, simple unsecured consumer lending. Advised investment products, complex SME banking, mortgages, cash services, and internal-model capital approval are explicitly out of scope: see "The Frame" above.
Outsourcing postureOpenThe control architecture identifies which functions can legitimately be outsourced (Internal Audit, the DPO), but this investigation hasn't yet decided whether the scenario model's headcount figures assume those functions are actually outsourced or kept in-house at the smallest scale.
AI decision boundaryOpenThe Autonomy Spectrum is shared vocabulary, not yet a decision. Converting it into a formal decision-rights matrix (tied to legal significance, customer harm potential, and reversibility) is Tranche 6, not done yet.

Once those are set: a five-phase execution sequence

Recombining the four resolved blockers and the org structure above into a sequence a real founding team could execute, to secure authorisation from the FCA and PRA and launch an AI-native regulated bank under Minimum Viable Human Oversight, downstream of the decisions above, not a replacement for making them.

  1. Phase 1: Core System Isolation & Deterministic Decoupling Construct a bifurcated backend that fully decouples the stochastic AI layer from the double-entry ledger. Every transaction requires a cryptographically signed, single-use Decision Token through an immutable middleware gateway.
  2. Phase 2: Machine-to-Machine Trust & Verification Protocols Build identity and payment layers around open W3C standards (DIDs, VCs). Every autonomous agent receives a Decentralised Identifier and Verifiable Credential, cryptographically linking it to its human controller.
  3. Phase 3: Secure Entry into FCA Innovation Sandbox Cohorts Apply for and participate in the FCA Supercharged Sandbox and AI Live Testing initiatives. Use controlled environments to stress-test conversational agents and underwriting models against adversarial inputs and model drift.
  4. Phase 4: Deploy the Automated Machine-Led Compliance Layer Deploy a parallel shadow assurance platform powered by specialised financial SLMs (e.g. Aveni FinLLM) monitoring 100% of live interactions. Automatically generate real-time evidence packs and escalate anomalies to human supervisors.
  5. Phase 5: Establish the SM&CR Accountability Map & Governance Framework Align the automated GRC platform with the Senior Managers & Certification Regime. Assign personal ownership of all algorithmic outcomes to designated Senior Management Functions (SMF24, SMF4, SMF16) with continuous regulator-ready evidence packs.

A page that only shows resolved-sounding answers is advocacy.

Every claim across this investigation is classified as a legal fact, a supervisory expectation, a modelling assumption, or an open hypothesis, including the specific open questions this section used to list inline (the org-structure mapping, the industry-landscape claims, the sandbox pilots, the untested blueprint). That detail now lives in one versioned place rather than being split across every page's own "still open" note.

Who's attempting pieces of this, not evidence for the headcount question.

This section is reference material, not part of the minimum-human argument itself. A distinct cohort of fintech startups, technology providers, and transitioning licensed institutions is actively establishing architectural precedents for AI-native banking: useful for understanding what's technically being attempted, not proof of what's legally or prudently required. None of these entries are cited in support of any headcount or governance claim made elsewhere on this page. Every claim below is still cited: see the "Unconfirmed" markers and the sources section for what's been re-checked and what hasn't.

Open-source protocol

Catena Labs

Agent Commerce Kit (ACK-ID & ACK-Pay) built on W3C standards for verifiable AI identities and machine-to-machine payments. Reported to have raised $48M. [6, 8]

Unconfirmed, pending verification.

FCA Sandbox participant

BEYLA

"The Hive" real-time living memory with a Digital C-Suite of specialised AI humans. Reported to have refactored from GCP to AWS for UK regulatory standards. [9, 11]

Unconfirmed, pending verification.

Shadow assurance

Aveni

FinLLM suite of specialised financial SLMs providing Agent Assure: continuous machine-led shadow auditing, piloted in the FCA Supercharged Sandbox. [4, 5, 10, 11]

Unconfirmed, pending verification.

BaaS transformation

Solaris

Reported to be rebuilding core banking-as-a-service processes around autonomous AI agents, with human supervisors acting as compliance controllers.

Unconfirmed, pending verification.

Cognitive platform

Intellect Design Arena

AI Digital Banking platform across seven cognitive dimensions, reportedly targeting a 20% cost-to-income reduction and 22–28% return on equity. [7]

Unconfirmed, pending verification.

Financial crime

Napier AI

"Theseus" network-based AML detection combining cross-border datasets with graph-based visualisation and audit-ready case summaries. [11]

Unconfirmed, pending verification.

References & Further Reading

This investigation is grounded in regulatory publications, live sandbox programmes, and industry architecture. None of the sources below have been independently re-confirmed by Axiom Verity beyond transcription from the original research brief. Treat every citation as pending verification (see "What's Still Open" above).

Primary & regulatory sources

#TitlePublisherLink
1The Mills Review: AI and the future of retail financial servicesFCAView source →(opens in a new tab)
2Financial Stability in Focus: Artificial intelligence in the financial systemBank of EnglandView source →(opens in a new tab)
11Supercharged Sandbox Showcase (Cohort 1)FCA InnovationView source →(opens in a new tab)
12Senior Managers and Certification RegimeFCAView source →(opens in a new tab)
13The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017legislation.gov.ukView source →(opens in a new tab)
15New Bank Start-up Unit: authorisation and mobilisation guidanceBank of EnglandView source →(opens in a new tab)
16Financial Services and Markets Act 2000, Schedule 6 (Threshold Conditions)legislation.gov.ukView source →(opens in a new tab)
17SS1/21 – Operational resilience: Impact tolerances for important business servicesBank of England / PRAView source →(opens in a new tab)
18SS2/21: Outsourcing and third party risk managementBank of England / PRAView source →(opens in a new tab)
19The Consumer DutyFCAView source →(opens in a new tab)
20Guidance on AI and data protection (automated decision-making)ICOView source →(opens in a new tab)
21Banking Act 2009, Part 1 (Special Resolution Regime)legislation.gov.ukView source →(opens in a new tab)
22FCA Handbook: SYSC (Senior Management Arrangements, Systems and Controls)FCAView source →(opens in a new tab)
23Data protection officers: accountability and governance guidanceICOView source →(opens in a new tab)

Industry & vendor references

Cited for the specific landscape claims above, company and third-party sources, not regulatory ones.

#TitlePublisherLink
3AI-Native Financial Infrastructure: Rebuilding finance's core systems for the agentic eraAnthemis GroupView source →(opens in a new tab)
4SMCR Compliance for AI Agents | What the FCA ExpectsAveniView source →(opens in a new tab)
5AI in Banking | Accountability & Consumer DutyAveniView source →(opens in a new tab)
6Agent Commerce Kit (ACK)Catena Labs / GitHubView source →(opens in a new tab)
7Intellect Design Arena Launches AI Digital Banking Platform for UK & EuropeIntellect Design ArenaView source →(opens in a new tab)
8Circle co-founder to build new 'AI-native' bankBanking DiveView source →(opens in a new tab)
9From Hiring Challenge to FCA ReadinessW Talent UKView source →(opens in a new tab)
10Lloyds and Nationwide-backed Aveni raises £12mFinTech GlobalView source →(opens in a new tab)
14AI compliance in banking: build governance into architectureBackbaseView source →(opens in a new tab)

This investigation is just beginning.

Future updates will add a dedicated page for the org structure above and one page per role, deep-dive pages for each of the four blockers, an interactive autonomy spectrum, a verification pass on every citation above, and a dated commentary log tracking how the research evolves with new regulatory guidance.