UK solutions · FCA SYSC · ICO Article 22 · Consumer Duty

FCA SYSC, ICO Article 22
and Consumer Duty —
covered.

The EU AI Act is the loudest deadline, but UK FCA-regulated firms face three overlapping obligations on AI agent activity. UK-specific export packs cover SYSC operational resilience, ICO automated decision-making, and Consumer Duty fair-value evidence in one platform.

FCA SYSC 4 · 8 · 15 ICO Article 22 Consumer Duty PRIN 12 Operational Resilience SS1/21

In this section

FCA SYSC

Senior Management Arrangements, Systems and Controls — SYSC 4 and SYSC 8 require operational resilience evidence for material outsourced services and critical functions, including AI-driven services.

ICO Article 22 (UK GDPR)

Where an automated decision has legal or similarly significant effect on a data subject, you must provide meaningful information about the logic involved — and Article 12 of the UK GDPR requires you to demonstrate compliance.

FCA Consumer Duty

Firms must evidence fair outcomes for retail customers. Where AI is in the decisioning loop, the firm must be able to show how a specific decision was made and on what data.

Why UK firms can't just wait for the EU deadline.

The EU AI Act creates the loudest extraterritorial pressure on UK firms, but the domestic obligations apply already. An ICO subject access request can land tomorrow. The FCA can ask about your AI agent governance at any supervisory review. Consumer Duty applies whether the AI is in scope of the AI Act or not.

What we ship for UK firms

FAQUK regulator questions, answered

Frequently asked, by UK CISOs.

Does Agent Audit cover FCA SYSC operational resilience for AI?

Yes. Our FCA SYSC export pack maps every receipt to the obligations under SYSC 4, SYSC 8 and SYSC 15A — including evidence of testing, monitoring, third-party AI service oversight, latency p95/p99, degraded-service windows and incident response. The pack is generated tenant-wide.

What about ICO Article 22 — automated individual decision-making?

Our ICO SAR pack is available today. For any named data subject it returns every action the agent took on their behalf, the lawful basis claimed at the time, the model and tools involved, and whether the decision had a legal or similarly significant effect under Article 22(1).

How does this fit with Consumer Duty?

Consumer Duty requires you to evidence that AI-driven decisions are delivering good outcomes for retail customers. Agent Audit's receipts capture decision outcome, confidence, and routing — which feed directly into the "fair value" and "consumer understanding" outcomes the FCA expects firms to demonstrate.

Is the data residency UK-only?

By default, yes. Managed cloud customers can pin storage to London (UK) or Frankfurt (EU). Enterprise customers can bring their own S3 bucket in any AWS region, or self-host the entire backend on-premises.

Will my auditor accept the pack format?

The packs are co-designed with compliance officers at FCA-regulated beta partners and reviewed by an independent AI assurance firm. Each pack ships with a verifiable hash-chain proof and an RFC 3161 notarisation receipt, both of which auditors can independently re-verify without contacting us.

Further reading: Article 12 vs SOC 2 — what each one actually covers · Retention vs notarisation · SCIM + SSO procurement checklist.

Built for the regulators you actually answer to.

We've co-designed our UK packs with compliance officers at FCA-regulated firms. The format matches what your supervisors expect.