The Mills Review, Governance of AI, and the C-Suite's Secret Weapon
The Mills Review in the UK reveals the direction of travel for the banking industry when it comes to AI governance
The Financial Conduct Authority has just published the Mills Review, which it commissioned from executive director Sheldon Mills to explore how advances in AI could transform retail financial services. The review outlines seven recommendations for the FCA relating to adapting the regulatory perimeter, strengthening oversight, and the foundational framework needed for agentic finance.
What makes this significant for the C-suite goes beyond what it asks of the FCA. It is what it reveals about the direction of travel for the banking industry.
Whilst the report started with a question about how AI will transform financial services by 2030 and beyond, the stark reality is that the AI era has already arrived, and use has gone far beyond early predictions. For every move customers make, banking CEOs are adapting their entire operating models to address the three forces of AI, regulation and loyalty at once, and at scale.
Key Takeaways
- AI has moved from experiment to operating model. The Mills Review makes clear that AI is no longer a future consideration for financial services, but a live force reshaping governance, customer journeys and competitive strategy.
- Governance must be embedded, not bolted on. Banks will need decisioning architectures that make controls, accountability, auditability and escalation part of the system itself rather than a layer that sits alongside it.
- Agentic customers will change the basis of competition. As consumers increasingly delegate financial choices to AI agents, banks will need to win on real-time, personalised and policy-compliant outcomes rather than brand loyalty or inertia.
- Connected decision intelligence is becoming a C-suite priority. Leaders are already simplifying operating models and sharpening accountability so that strategy, KPIs and AI-enabled execution can align across the organisation.
- Financial crime risk will scale with AI adoption. Fragmented point solutions will struggle against faster, more persuasive threats, making ecosystem-level intelligence and centralised decisioning critical to resilience.
The Systemic Driver: Advances in AI are Accelerating
Mills states it plainly within his Executive Summary: "The central shift is from human-led, episodic financial activity towards services that are AI-enabled, continuous and delegated. AI will operate inside firms, through consumer interfaces, across markets and within regulators. It will affect how products are designed, distributed, monitored and governed."
Within his report, he reviews how roles that have historically been performed by humans are now shifting to delivery through AI, and analyses what this means for meeting regulatory requirements. At one end of the spectrum, the human simply becomes an observer, as the AI system "acts continuously within boundaries set in advance, with the human monitoring outcomes rather than deciding".
Mills highlights how the acceleration in AI adoption is striking. Agentic AI, which was "effectively absent from related surveys two years ago, is now being piloted or deployed by more than half" of industry respondents, he says. FICO sees the same trend and has begun preparing our customers for it – see Your Customer’s AI Agents Are Coming – Are You Ready?
System Shift 1: The Transformation of Firms
Deploying AI into individual product lines, or operational functions such as underwriting, credit risk, fraud, or customer support, can boost model control by improving accuracy and reducing hallucination.
But bank operations also need to think more widely about how they connect AI across the organisation if they are to maximise the value delivered. As analytic sophistication increases across functions, the value of signals and decision interdependencies compounds. Value is either lost between silos or propagates through interconnected decision intelligence. It’s why outcome awareness across the entire organisation is key, regardless of whether the human in the loop acts as an operator, or an observer.
Mills puts the commercial case plainly:
"Governance is likely to become an enabler of capability. Firms that can demonstrate auditability, explainability where needed, robust testing, clear permissions, effective monitoring and escalation will be able to deploy AI more confidently. Firms that cannot do so may be slower to adopt or may expose consumers and markets to greater risk. As our next chapter outlines, trust is a key barrier to customer adoption of AI use cases in finance, so acquiring a reputation for trusted AI processes could win business."
~With the above in mind, FICO Platform has been architected to deliver these types of governance obligations. See - Is Your Decisioning Infrastructure Ready for the Next Era of Commerce? | FICO
As Mills states, "It is not enough to say that a person remains in the loop. Firms will need to be clear about what the person is expected to do, what information they receive, when they can intervene, how challenge is recorded and how escalation works." This governance challenge remains unsolved for many organisations, and is cited as the key reason why only 5% of AI models make it from pilots into production.
One area I challenge is Mills' assertion that as AI becomes embedded across every function, "Managing integrated AI-enabled systems will become a core capability and may no longer work through periodic reviews but operate continuously alongside the systems it is designed to control."
I agree that governance must extend beyond point-of-deployment validation into live monitoring of consumer decisions, and continuous outcome tracking ahead of aggregate level model performance. It's the assertion that all of this should operate alongside the systems instead of inside the systems that we should challenge.
Mills' assertion works for organisations that operate with the architectural principle of having built AI on top of existing infrastructure. This is where seams exist between regulation, policy, model development, deployment, decision execution and monitoring. Those seams are where control gaps live and compound in a multi-model, agentic environment. Monitoring alongside these systems is the only solution.
However, AI systems are increasingly becoming the operating system. AI and decisioning architectures are built with the foundations of API first, built-in governance, trust by design, and agentic-ready. Management can be embedded within the AI-enabled systems as opposed to alongside them.
Within FICO Platform, for example, a bank’s policy can be codified to close the gap between what the bank says it does and what it actually delivers through agentic authoring. Human judgement and accountability goes on the record, with policies referenced, outcomes modelled and the reasons for decisions becoming fully traceable. In production, agents autonomously run outcome-aware monitoring and simulations over your customer data, so that the bank can proactively evaluate adherence to protocols and reorient towards optimal outcomes.
There is a subtler problem specific to agentic systems, which may have led Mills to state this management should take place alongside, rather than inside the system. Sean Baseman, Chief Architect at FICO, puts it directly:
"Everyone assumes governance makes an agentic system more trustworthy. I've watched it do the opposite. Add oversight to a reasoning system and you don't just constrain the bad outputs. You constrain the system's confidence about what it's allowed to say plainly. Push it hard enough and it stops giving you a clean wrong answer. It gives you a hedged, qualified, technically defensible one that's harder to catch, because now the uncertainty is spread across the whole response instead of concentrated in one wrong claim. That's a worse failure mode, not a better one. A confident wrong answer gets caught. A governed, hedged, half-right one survives review.
This isn't an argument against governance. It's an argument against governance that stops at the output. If you only constrain what the system says, you've taught it to say less wrong things more carefully, not to reason more soundly. The hallucination didn't go away. It got quieter. The fix isn't less governance or more governance. It's governance that acts earlier, on the reasoning path itself, not just the sentence at the end of it."
This level of reasoning comes from developing models based on carefully curated data, where analytic teams mitigate bias and ensure decisions are auditable, trustworthy and hallucination free, as opposed to imposing constraints over the top of those models. Whereas many industry commentators focus on governance and guardrails, it’s clear to me that we need to step all the way back to the way that models reason, rather than putting the emphasis on what happens alongside them.
System Shift 2: New Consumer Journeys
Mills said that "By 2030, many financial consumer journeys may start with AI. Instead of searching for a product, comparing options and then choosing a provider, consumers may begin with an AI agent that helps them understand their needs, compare the market and act on their behalf."
Mills’ own report found that 1 in 5 UK adults are already open to AI making decisions on their behalf. Gartner’s research shows that by April 2027, 40% of adults will be using AI agents for this purpose.
With an AI agent in their hands, customer intent gets translated into the search for value-based outcomes. Demand is strongest where customers feel choices involve high-stakes decisions or have complexity such as debt advice, pensions or investment decisions. The advice gap (only 9% of consumers use traditional advice) and the protection gap (just 30% hold life or income protection) will no longer be permanent features of the market. They are problems an agentic economy will systematically dismantle.
For every consumer agent seeking an outcome, there will be a bank agent running on the other side of that interaction. It will connect intelligence, orchestrate workflows, eliminate the value gaps and control gaps that fragmented architectures leave behind. The banks that win in this environment are those with a decisioning infrastructure that can receive an agent's request, evaluate it against live customer data, and respond with a personalised, policy-compliant decision in milliseconds, whilst simultaneously driving performance towards the bank’s own KPIs. These capabilities are already setting the new standard for the delivery of hyper-personalised customer outcomes.
For a demonstration of this in action, see this demo from my colleagues at FICO: Managing the Agentic Customer - FICO World 26 | FICO
System Shift 3: A Reshaped Competition Landscape
Brand loyalty, relationship stickiness, and switching friction were the traditional moats of retail banking, but they have been getting systematically removed over the years. Current account switching in the UK is up 43% over last year. Multi-banking is now commonplace, and for major incumbents, silent attrition is already a major challenge.
The pace of switching is set to accelerate further, as AI agents lack brand affinity or inertia. The challenge every banking CEO needs to address is what it takes for an AI agent to prefer your bank over your competitors, as those that meet customer intent with personalised and optimised outcomes are going to be the winners in this AI era.
Underpinning this is whether your bank's decisioning infrastructure can respond to an agent's query with the right decision, at the right time, in the right manner. Banks delivering these hyper-personalised experiences and building customer advocacy are already seeing 1.7x the growth of organisations that cannot meet these demands.
This gap is set to accelerate as the current wave of AI-driven competitive separation happens. This is hugely beneficial for the population. It does have the unintended consequence of creating a two-tier market for those customers who have greater access to quality AI. The customers it could help most fail to receive the services that deliver the highest benefits. How this tension plays out in practice is yet to be seen.
System Shift 4: Amplified Financial Crime and Cyber Risk
Mills dedicates significant attention to AI-amplified financial crime. AI will make attacks "faster, cheaper, more scalable and more persuasive – and at the same time harder to spot and stop." Mills rightly highlights the limitations of firm-level and ecosystem-level responses in detecting and responding to these threats.
A bank running fragmented point solutions internally, lacking in co-ordination with suppliers and ecosystem participants, is more prone to risk, as patterns will be less visible by the time exposures have scaled.
This is where a centralised decisioning architecture that sees the entire customer base and decision estate across a bank's supplier ecosystem can deliver significant advantages. These benefits are compounded when ecosystem participants share intelligence through consortia and marketplaces. The network effects compound further still. The banks that invest into their wider ecosystem connectivity are seeing the largest reductions in fraud and scam losses.
The C-Suite Is Already Responding
As Mills puts it: "The productivity opportunity therefore depends on trust. AI-enabled transformation will support growth only if firms can deploy systems that remain controlled, accountable and resilient."
Global bank CEOs who are furthest ahead already understand this:
- Georges Elhedery at HSBC has been explicit about eliminating complexity and moving from shared ownership of KPIs to individual executives being accountable, with decision-making flowing top down through the organisation.
- CS Venkatakrishnan at Barclays has made simplification an explicit strategic pillar, alongside becoming better by investing in customer experience.
- Jane Fraser at Citi restructured the entire organisation to shorten the distance between decision and accountability, and is re-imagining how major processes will be designed through AI, rather than using AI as a tool to better automate existing processes .
- Jamie Dimon has written that bureaucracy kills companies, cites that AI is a genuine technological shift that will affect every function, application and process in the business, but there is a need to be aware of the serious new risks this technology brings.
- Ana Botín at Santander has committed to more than €1 billion of annual business value from data and AI, with hyper-personalised customer journeys as the stated delivery mechanism.
Every one of these leaders is trying to collapse the distance between where strategy is set and where decisions get executed. Accountability is being sharpened with individual executives taking clearer ownership of KPIs, the AI models, and AI agents that orient performance towards them.
Delivered in the right way, the C-suite can amplify their bank’s strengths, governance and accountability. Using an AI platform, KPIs and operating protocols can be cascaded down the organisation with better precision. Real-time outcome awareness of those decisions can become the norm for business owners. Banks can close the control gaps that surfaced in siloed operating models.
If banks are to realise AI driven benefits at scale, the secret weapon of the bank CEO could be the centralised decision intelligence platform.

Explore Responsible AI with FICO
- Read about FICO Focused Foundational Models for AI
- Read the latest report from Corinium and FICO on the State of Responsible AI in Financial Services
- Download our AI Playbook: A Step-by-Step Guide for Achieving Responsible AI
Frequently Asked Questions
Popular Posts
Has the Reporting of Rental Data to the Credit Reporting Agencies (CRAs) Increased?
FICO Score 10T includes rental data, but consumers can only experience the benefit of this to the extent that their rental data is reported to the CRAs
Read more
Average U.S. FICO® Score at 716, Indicating Improvement in Consumer Credit Behaviors Despite Pandemic
The FICO Score is a broad-based, independent standard measure of credit risk
Read more
FICO Statement on FHFA and FHA Updates to Credit Score Modernization
FICO supports FHFA’s announcement that the long-anticipated historical data for FICO® Score 10T will be released to the mortgage market.
Read moreTake the next step
Connect with FICO for answers to all your product and solution questions. Interested in becoming a business partner? Contact us to learn more. We look forward to hearing from you.