Nothing on this investigation gets to stay unlabelled.

Every claim across this investigation (the regulatory floor, the control architecture, the scenario model, the blockers) is one of four things: a legal fact, a supervisory expectation, a modelling assumption, or an open hypothesis. This page is that classification made explicit and versioned, superseding the hub's "What's Still Open" summary as the detailed reference. That section now just points here.

Last reviewed: 2026-07-24

What each label actually means.

Legal fact

A citable, binding rule: legislation, the PRA Rulebook, or the FCA Handbook.

Supervisory expectation

A regulator's stated proportionate expectation: real, but not a binding rule.

Modelling assumption

A number or structure this investigation proposes to test, not asserts as established.

Open hypothesis

An unresolved question this investigation hasn't answered yet.

The load-bearing claims across the whole investigation.

Every open question already flagged on individual pages (ledger-integrity, the control architecture, the scenario model, the landscape annex) is folded in here, in one place, rather than left scattered across the section.

ClaimClassificationWhereSource
The FCA/PRA require one identifiable, individually accountable CEO, non-delegable to a model or vendor.Legal factControl architecture[12](opens in a new tab)
A named, individually accountable MLRO is a hard legal requirement under the Money Laundering Regulations 2017.Legal factMLRO role perspective[13](opens in a new tab)
UK GDPR Article 37(6) explicitly permits a DPO to be fulfilled on a service-contract basis, not necessarily in-house.Legal factDPO role perspective[23](opens in a new tab)
The PRA model risk management standard SS1/23 formally applies only to firms with PRA-approved internal models for regulatory capital purposes, not universally to every AI-native bank.Legal factThe StakesN/A
CRO and COO can be proportionate, even part-time, roles at the smallest scale. Dedicated leadership becomes harder to avoid only as the bank grows.Supervisory expectationControl architecture[15](opens in a new tab)
Internal Audit is a required function, but a non-significant firm may outsource it rather than employ an in-house SMF5.Supervisory expectationControl architecture[18](opens in a new tab)
The phase-one baseline is deliberately narrow: digital-only, no branches, simple deposit/lending products, no advice, no internal-model capital approval.Modelling assumptionThe FrameN/A
Illustrative frontier-automation FTE totals: 46.5 (small, 50k customers), 237 (medium, 500k), 2,156 (large, 5M).Modelling assumptionScenario modelN/A
Automation compresses each scenario by roughly the same proportion: customer scale, not automation level, drives the difference between scenarios.Modelling assumptionScenario modelN/A
The small-scenario function rows sum to 46, not the 46.5 the source research states as the total: an unresolved half-FTE gap.Open hypothesisScenario modelN/A
"Sentinel" and "Nexus" are named as Backbase Banking OS components in the source material, not independently confirmed as current product names.Open hypothesisLedger integrity[14](opens in a new tab)
Whether any live UK-regulated bank runs the Decision Token pattern in production, rather than a sandbox or pilot, is unknown.Open hypothesisLedger integrityN/A
The control architecture's role mapping (including reading "CIA" as Chief Internal Auditor) hasn't been checked against the FCA/PRA's current Prescribed Responsibilities allocation.Open hypothesisControl architectureN/A
The Five-Phase Blueprint is a synthesis of the four blockers, not a tested or costed implementation plan any founding team has executed end to end.Open hypothesisLicensure blueprintN/A
Every Industry Landscape claim (Catena Labs' funding, BEYLA's AWS migration, Aveni's raise, and the rest) is an unverified vendor or industry report, not evidence for the headcount question.Open hypothesisIndustry Landscape (annex)N/A

All twenty-three citations, one register.

Extends the `verified`/`kind` tracking already used per-citation across the section. This is the same 23 sources cited on the hub and its sub-pages, now with a classification alongside whether each has actually been re-checked.

#TitlePublisherKindClassificationVerified
1The Mills Review: AI and the future of retail financial services(opens in a new tab)FCAregulatorySupervisory expectationNo
2Financial Stability in Focus: Artificial intelligence in the financial system(opens in a new tab)Bank of EnglandregulatorySupervisory expectationNo
3AI-Native Financial Infrastructure: Rebuilding finance's core systems for the agentic era(opens in a new tab)Anthemis GroupindustryOpen hypothesisNo
4SMCR Compliance for AI Agents | What the FCA Expects(opens in a new tab)AvenivendorOpen hypothesisNo
5AI in Banking | Accountability & Consumer Duty(opens in a new tab)AvenivendorOpen hypothesisNo
6Agent Commerce Kit (ACK)(opens in a new tab)Catena Labs / GitHubvendorOpen hypothesisNo
7Intellect Design Arena Launches AI Digital Banking Platform for UK & Europe(opens in a new tab)Intellect Design ArenavendorOpen hypothesisNo
8Circle co-founder to build new 'AI-native' bank(opens in a new tab)Banking DiveindustryOpen hypothesisNo
9From Hiring Challenge to FCA Readiness(opens in a new tab)W Talent UKvendorOpen hypothesisNo
10Lloyds and Nationwide-backed Aveni raises £12m(opens in a new tab)FinTech GlobalindustryOpen hypothesisNo
11Supercharged Sandbox Showcase (Cohort 1)(opens in a new tab)FCA InnovationregulatorySupervisory expectationNo
12Senior Managers and Certification Regime(opens in a new tab)FCAregulatoryLegal factNo
13The Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017(opens in a new tab)legislation.gov.ukregulatoryLegal factNo
14AI compliance in banking: build governance into architecture(opens in a new tab)BackbasevendorOpen hypothesisNo
15New Bank Start-up Unit: authorisation and mobilisation guidance(opens in a new tab)Bank of EnglandregulatorySupervisory expectationNo
16Financial Services and Markets Act 2000, Schedule 6 (Threshold Conditions)(opens in a new tab)legislation.gov.ukregulatoryLegal factNo
17SS1/21 – Operational resilience: Impact tolerances for important business services(opens in a new tab)Bank of England / PRAregulatorySupervisory expectationNo
18SS2/21: Outsourcing and third party risk management(opens in a new tab)Bank of England / PRAregulatorySupervisory expectationNo
19The Consumer Duty(opens in a new tab)FCAregulatoryLegal factNo
20Guidance on AI and data protection (automated decision-making)(opens in a new tab)ICOregulatorySupervisory expectationNo
21Banking Act 2009, Part 1 (Special Resolution Regime)(opens in a new tab)legislation.gov.ukregulatoryLegal factNo
22FCA Handbook: SYSC (Senior Management Arrangements, Systems and Controls)(opens in a new tab)FCAregulatoryLegal factNo
23Data protection officers: accountability and governance guidance(opens in a new tab)ICOregulatorySupervisory expectationNo

Every "Verified" column reads "No." That's not an oversight: it's the honest current state. The primary-source verification pass this implies is real regulatory and legal research, not a quick pass inside a normal build session.

This register grows as the investigation does.

Every future page (the remaining role perspectives, the remaining blockers) adds its claims here too, not just its own "What's Still Open" list.