How Do Risk Teams Report on AI Usage to Regulators?
Risk teams report on AI usage to regulators by maintaining a structured inventory of AI systems in use, documenting their purpose, risk classification and oversight arrangements, and presenting this through existing governance channels such as risk committees and Senior Manager attestations. Traditional methods rely on manual data collection and periodic review; AI-supported tools can help identify undeclared AI usage and keep records current, but the responsibility for accuracy and sign-off remains with accountable individuals.
Key takeaways
- Regulators expect firms to know where AI is used and to explain governance arrangements around it, not just to disclose that AI exists.
- An AI system inventory, covering purpose, data, risk level and ownership, is the foundation of most reporting approaches.
- Traditional reporting relies heavily on manual departmental declarations, which often miss shadow AI usage.
- AI-supported discovery and documentation tools can reduce the manual burden, but human sign-off and accountability remain essential.
Every risk and compliance function in a regulated firm eventually faces the same question from a supervisor: where, exactly, is AI being used across the business, and who is responsible for it?
Answering that question is harder than it sounds. AI tools are often adopted department by department, sometimes with formal sign-off, sometimes simply because a team found a useful piece of software. Trading desks, client services, operations and marketing may all be using AI in different ways, at different times, with little central visibility.
UK regulators, including the FCA and PRA, do not expect firms to avoid AI. They expect firms to understand it, govern it and be able to explain it clearly when asked.
That expectation places risk teams in a demanding position: building an accurate, current and defensible picture of AI usage across an organisation that was rarely designed to track it centrally in the first place.
Why Regulators Care About AI Usage Reporting
Regulatory interest in AI usage is not about the technology itself. It is about accountability, operational resilience and consumer protection.
Supervisory expectations in UK financial services generally build on existing frameworks rather than introducing entirely new ones. Firms are expected to demonstrate that AI systems, like any other operational tool or model, are understood, appropriately governed and subject to clear ownership under arrangements such as the Senior Managers and Certification Regime.
Regulators are particularly interested in whether a firm can answer three questions with confidence: what AI is in use, what it is used for, and who is accountable for its outcomes. A firm that cannot answer these questions raises concerns about its broader control environment, regardless of how well any individual AI tool performs.
This is why AI usage reporting has become a natural extension of existing model risk management and operational resilience obligations, rather than a standalone regulatory novelty.
Traditional Approaches to Building an AI Usage Report
Most risk teams have historically approached this task using methods adapted from existing governance processes.
Common traditional approaches include:
- Spreadsheet-based inventories, maintained centrally and updated periodically.
- Departmental questionnaires, asking business unit heads to declare AI tools in use.
- Periodic audits or attestations, often tied to annual risk cycles.
- Extension of existing model risk frameworks, treating AI tools as a subset of models already subject to governance.
These approaches are workable and remain appropriate in many firms, particularly smaller organisations with limited AI adoption. However, they depend heavily on people accurately remembering and declaring what they use.
Departmental self-declaration, in particular, tends to understate actual usage. Teams may not think of a drafting assistant or a data classification tool as "AI," or may simply forget to mention a tool that has become part of routine work. The result is an inventory that looks complete but is not.
Where AI Helps Risk Teams Report More Effectively
This is where AI-supported tools can genuinely help, not by generating the report itself, but by improving the quality and completeness of the underlying evidence.
Practical applications include:
- Scanning software usage, API calls and system logs to identify AI tools that have not been formally declared.
- Classifying detected tools by likely risk level, based on their function and the data they process.
- Drafting structured documentation from raw inventory data, saving risk analysts time on repetitive write-ups.
- Flagging inconsistencies between departmental declarations and observed usage, so these can be investigated.
Used this way, AI acts as a discovery and drafting aid, surfacing information that would otherwise rely on manual chasing and interpretation. It does not decide what counts as acceptable use, what risk rating applies, or what should be reported to the board or regulator. Those judgements remain with risk and compliance professionals, who understand the wider business context that a detection tool cannot see.
Operational Considerations for Ongoing Reporting
AI usage reporting is not a one-off exercise completed ahead of a supervisory visit. It is a continuous governance discipline.
Keeping a report current and defensible requires attention to several practical issues:
- Clear ownership. Every AI system in the inventory should have a named owner accountable for its use and oversight, not just a department label.
- Regular refresh cycles. Inventories should be reviewed on a defined schedule, not only when a regulator asks.
- Shadow AI detection. Processes should actively look for undeclared tools rather than assuming self-declaration is complete.
- Audit trail. Every change to the inventory, and every sign-off, should be recorded in a way that can withstand later scrutiny.
Firms that treat this as an ongoing discipline, rather than a periodic scramble, tend to produce reports that hold up well under supervisory questioning. Firms that treat it as a compliance exercise to be repeated once a year tend to find gaps at the worst possible moment.
Example
A mid-sized London-based asset manager is preparing for a routine FCA supervisory visit. The risk team is asked to provide a current inventory of all AI tools used across the business, including trading support tools, client communication drafting tools, and back-office reconciliation systems, along with an explanation of how each is governed.
The risk team uses an AI-assisted discovery tool to cross-check departmental declarations against actual software and API usage logs, uncovering two undeclared AI tools in use within client services. The final report, reviewed and signed off by the Head of Risk and Compliance, presents a complete and current picture to the regulator, with clear ownership recorded against every system listed.
FAQs
-
Do all AI tools need to be reported to regulators, even low-risk ones?
Most governance frameworks use a risk-based approach. Low-risk tools are typically recorded in the AI inventory but do not require the same level of scrutiny as higher-risk uses, which might influence financial decisions, client outcomes or regulatory obligations. The key is that the inventory itself remains complete, regardless of risk level.
-
What is "shadow AI" and why does it matter for reporting?
Shadow AI refers to AI tools adopted by staff or departments without formal approval or central visibility. It matters for reporting because it creates a genuine gap between what a firm believes it uses and what is actually in use, undermining the accuracy of any report presented to a regulator unless it is actively identified.
-
Can AI tools generate the regulatory report themselves?
AI tools can help draft, structure and populate reports from underlying inventory data, which saves significant manual effort. However, accountability for the accuracy and completeness of the submission rests with the named senior individuals who review and sign it off, not with the tool that helped produce it.
Turn the Skills Compact into action
Get in touch for a free consultation on turning the Skills Compact into a practical AI skills plan for your teams.