In January, the Treasury Select Committee asked the FCA to publish practical guidance on the accountability and level of assurance expected from senior managers, under the Senior Managers and Certification Regime, for harm caused through the use of AI. The Committee set a deadline of the end of 2026. The guidance has not yet arrived.
The natural reading of that gap is that senior managers have time. The opposite is closer to the truth. Guidance describes a standard. It does not create the evidence that a particular individual met it. When the guidance lands, it will be applied to conduct that has already happened, and the senior manager named on a Statement of Responsibilities will be asked what they were doing during the period before the standard was written down.
What the record actually contains
The word "assurance" does a lot of work in the Committee's recommendation and very little of it is self-explanatory. In practice, a senior manager's AI oversight record is not a policy document and not a technical log. It is a sequence of dated entries recording specific acts of judgement.
A usable entry names the system and the decision point, the recommendation put to the senior manager, what they asked before deciding, what they required as a condition of approval, and what they explicitly did not accept. A deployment approved subject to a human review threshold, with the threshold stated, is a different record from a deployment approved. A model change waved through on the basis of a vendor assurance, with the assurance named and its limits noted, is a different record from silence.
None of this requires the senior manager to explain the model. That distinction matters, because the objection most often raised against holding individuals accountable for AI outcomes is that no senior manager can fully explain a system's internals. They cannot, and they are not being asked to. They are being asked to evidence their own oversight of it, which is entirely within their competence and almost never recorded with the same rigour as the technical artefacts sitting underneath.
The gap that opens while waiting
Consider the sequence in which these records get requested. A consumer complains that an automated decision caused them detriment. A supervisor opens an examination into a firm's AI deployment. An incident review asks how a system reached production. In each case, the first question is not what the model did. It is who authorised it and on what basis.
A senior manager who has been maintaining a contemporaneous record answers that question by producing it. A senior manager who has not answers it by reconstructing, and reconstruction under section 174 of the Companies Act, which requires directors to exercise reasonable care, skill and diligence, is the weaker position by some distance. The duty is assessed against what the individual actually did, evidenced, not against what the firm's policy said should happen. An account assembled after the request describes the same events and carries none of the same weight.
The exposure created by waiting is therefore not a future exposure. It accrues now, quietly, in the months during which decisions are being taken and not recorded, and it cannot be repaired later, because the one property the record needs is the one that cannot be added retrospectively.
Why the model already exists
The regime has already solved this problem once. A Statement of Responsibilities works as evidence because it is filed with the regulator, which fixes its date outside the firm's control. The firm cannot quietly redraft it after the fact, and that single property is what makes a supervisor able to rely on it.
The same logic applies to the oversight record. Entries anchored by something the organisation does not administer, an external attestation, a regulatory submission, a board filing whose date is fixed by the act of filing, make a categorically different claim from entries held in a document store the firm controls. The mechanism matters less than the property. What matters is that the date is not the firm's to assert.
The position on the day it lands
Guidance sets a standard. It does not manufacture the evidence that a named individual met it. When the FCA publishes, the senior manager holding a year of dated, anchored records of their own AI oversight is in the position the guidance exists to produce: demonstrably ready, without having been told what the standard would be. The senior manager holding none is explaining the gap.
There is nothing in that first position a firm needs permission to build.
Regulatory references: SM&CR (SYSC, FCA Handbook); Companies Act 2006 section 174; House of Commons Treasury Committee, AI in Financial Services, HC 684 (20 January 2026); EU AI Act Article 50 for continuity of the evidentiary argument.
The Roche-Review is the weekly publication of Dr Ivan Roche FRSS FRSA MInstP, Founder of Otopoetic Limited. Subscribe at roche-review.com.


