AI governance

Guidance has not kept up with AI

Jump to findings

41% say AI governance lacks practical implementation guidance

AI governance stands out as the area where organisations feel least supported by practical guidance. While firms broadly understand the direction of travel, many are still developing governance frameworks without clear implementation standards. As a result, organisations are making independent decisions about risk appetite, controls and oversight, increasing the likelihood of inconsistent approaches across the sector.

This matters because AI is evolving faster than both regulation and formal guidance. Rather than waiting for definitive frameworks, organisations are building governance as they go. Those that establish robust internal standards now are likely to be better positioned as regulatory expectations continue to mature.

AI governance leads the rankings, while crypto compliance comes second despite relatively low reported exposure. The findings suggest organisations are seeking practical guidance before emerging risks become widespread.

Organisations identifying a guidance gap are significantly more likely to invest in AI governance, suggesting awareness is translating into action rather than delaying decision-making.

Industry perspectives

Industry leaders reflect on the report’s key findings.

João Rijo Godinho Courinha, Fraud Management Global Product Manager, Worldline

“The nature of fraud has shifted. Rather than breaking into accounts, criminals now prefer to convince customers to transfer the money themselves. UK scam reimbursement rules already put part of that responsibility on UK banks. In the EU, PSR's Article 59 will bring a similar approach. We monitor billions of transactions per year across card issuing, acquiring and account payments, and we see the same scam scripts moving country to country. The banks that act early tend to fare better.”

About Worldline

Shakeel Aslam, Partner and GRC Team Lead, MHA

“A company register is not a due diligence file. Identity verification under ECCTA confirms that a person exists. It does not confirm who controls the company, or why the structure is shaped the way it is. Firms treating the November deadline as an administrative exercise have misread it. The duty to corroborate ownership, and to report discrepancies, has not moved anywhere.”

About MHA

Bradley Elliott, CEO, RelyComply

"The sector still treats compliance spend as loss mitigation, but the maths has flipped: the cheapest fine an institution will ever pay is the fraud it never lets through. As regulators tighten reimbursement liability, prevention becomes a margin question, not a compliance one. Expect boards, not compliance teams, to drive the next wave of anti-financial crime investment - and to demand consolidation."

About RelyComply

David Crawford, Chief Strategy & Transformation Officer, Pay.UK

“Fraud is no longer a challenge that financial institutions can solve alone. The organisations that make the greatest progress over the next few years will be those that combine real-time data sharing, cross-sector collaboration and shared accountability to disrupt criminals before fraud occurs, rather than reimbursing victims after the event.”

About Pay.UK

Regulatory pressure

Previous page

Investment priorities

Next page