Bring all your client data up to date - get ready for AMLA with EC Review Find out more

The FCA Mills Review: what it means for KYC and corporate digital identity

By Howard Wimpory | 3 hours ago
FCA Mills Review

On July 6, 2026, the Financial Conduct Authority (FCA) published the Mills Review. It sets out how artificial intelligence (AI) will reshape retail financial services by 2030 and beyond. Sheldon Mills (Executive Director, FCA) led the work. It is the first review of its kind commissioned by a financial regulator anywhere in the world.

The headline finding lands differently depending on who reads it. For retail firms, it signals that agentic AI is now a supervisory priority. Agentic AI means systems that can recommend, initiate and execute financial decisions within agreed limits.

For Know Your Customer (KYC), onboarding and corporate compliance teams, the Review sits outside its direct scope. But it offers something else. It is an early, detailed preview of how regulators everywhere are likely to think about AI, accountability and trust.

What is the FCA Mills Review

The FCA Board asked Mills to lead the Review in January 2026. The process drew on written submissions from firms, trade bodies, consumer groups and technology providers. It also drew on commissioned research, including a survey of more than 5,000 UK financial services consumers. The FCA compared international approaches to AI regulation too.

Its central conclusion is notable for what it does not recommend. The Review does not propose a new AI rulebook. Instead, it finds the FCA’s existing framework remains broadly fit for purpose. That framework includes the Consumer Duty, the Senior Managers and Certification Regime (SM&CR), and the operational resilience and Critical Third Parties (CTP) regime. What has to change is how actively the FCA applies it as AI adoption is accelerating fast.

The seven priority recommendations

The Review sets out seven priority recommendations for the FCA Board to consider:

  1. Secure and adapt the regulatory perimeter to keep pace with AI tools that influence decisions from outside regulated activity.
  2. Strengthen system-wide coordination and oversight as AI use grows across regulators.
  3. Monitor the transition to autonomous models and adapt regulatory frameworks as capability advances.
  4. Scale up the FCA’s AI Lab, including its sandbox and live testing programs.
  5. Enable the foundations for agentic finance. This lays groundwork for AI systems acting on behalf of firms and consumers.
  6. Build and adopt an AI-enabled agentic supervisory model to give the FCA near real-time visibility of outcomes across firms.
  7. Develop a trusted, public-interest AI-enabled financial capability service as quality guidance should not be limited to those who can pay for premium tools.

Accountability does not shift

One finding matters more than any other for compliance leaders. As AI systems take on more of the work, accountability does not move with them. The Review confirms the SM&CR still applies as firms adopt more autonomous AI. A senior manager remains answerable for outcomes. That holds true even when a model’s behaviour sits partly outside the firm’s direct control.

That is a deliberately conservative position. It is also the right one. But it creates a practical problem. Senior managers cannot be accountable for outcomes they cannot evidence. The real risk agentic AI introduces isn’t a system acting on its own, it is accountability quietly losing contact with execution, as AI agents make decisions faster than any human can track them.

And they cannot evidence outcomes that rest on data they cannot verify in real time. That gap sits between the accountability regulators expect and the data foundation firms actually have. It is where the Mills Review’s logic reaches well beyond retail banking.

Why this matters beyond retail banking

The Mills Review is scoped to retail financial services. But two of its recommendations describe a problem corporate KYC and onboarding teams already know well.

The perimeter and findings point directly at third-party dependency. Firms lean more heavily on external AI, data and technology providers to power decisioning. As they do, resilience and accountability questions around those providers get sharper, not softer. For a bank’s KYC operation, the same logic applies. It covers every automated data source, screening feed and AI-assisted judgment call built into onboarding and due diligence.

The Review also pushes for foundations for agentic finance and an agentic supervisory model. Corporate banking is already living through something similar. AI agents may soon recommend, flag or act on financial relationships. Is that agent a bank’s internal co-pilot, or a future FCA supervisory tool? Either way, it needs a reliable answer to one basic question. Who, exactly, is this customer, and can that be trusted right now, not at last year’s periodic review.

Trusted data is the foundation agentic AI needs

An AI agent is only as good as the data it acts on. That is easy to state and hard to operationalize. It gets harder for corporate customers. Ownership structures and risk signals change continuously, not on a fixed review cycle.

This is precisely the problem corporate digital identity (CDI) is built to solve. CDI builds a real-time, structured digital risk profile for each corporate customer. It draws on authoritative public data, registries and private customer information. That gives any system acting on the data, human or AI, a current, evidence-based answer. It replaces a static snapshot. Encompass’s EC360 platform builds this profile continuously. The underlying facts a bank relies on for onboarding, due diligence and ongoing monitoring stay accurate as circumstances change. They are not just accurate at the point they were last checked.

As agentic AI moves from pilot to production across financial services, this kind of foundation matters more. A verified, current data foundation is no longer a nice-to-have. It determines whether an AI-assisted decision can be defended. That defense may need to hold up to a regulator, or a senior manager, after the fact.

Having trustworthy data is only half the problem, though. AI agents also need a safe, governed way to reach it. That channel should give structured, verifiable answers. It should not require a model to interpret documents or scrape static exports. And it should leave a clear audit trail behind every decision. Hiding decision logic behind a cleaner interface weakens regulatory control; done well, the underlying infrastructure brings that logic to the fore, giving teams and regulators clearer sight of risk, not less.

What “reasonable steps” looks like for an AI-assisted decision

The SM&CR has never required a senior manager to perform every task personally. It has always allowed for delegation, outsourcing, and complex technology, provided accountability and oversight remain clear. Agentic AI does not break that principle. It raises the evidential bar for it.

For a KYC or onboarding decision touched by AI, that means a senior manager should be able to demonstrate four things:

What the system is designed to do. Which decisions it influences, what it is prohibited from doing, and where a human judgment call is still mandatory.
What drives its outputs. The data, rules, or thresholds shaping a risk score or a due diligence outcome.
What controls sit around it. Escalation triggers, override rights, and who can intervene when something looks wrong.
• Whether the outcomes hold up. Testing for bias, error, or drift against the firm’s risk appetite and regulatory obligations.

This is not a new legal test. It’s closer to the standard already applied to model risk management, extended to systems that now execute rather than just recommend. For KYC teams, it means the underlying data and the audit trail behind every AI-assisted decision need to answer these four questions on demand, not after the fact.

What firms should do now

Firms do not need to wait for a corporate-facing equivalent of the Mills Review. They can start acting on its logic now. Three steps are worth prioritizing:

  • Map where AI already touches KYC and onboarding decisions. Confirm a named senior manager can evidence and stand behind each outcome.
  • Review third-party and vendor AI dependencies through an operational resilience lens, not just a procurement one. This aligns with the CTP thinking the review reinforces.
  • Assess whether your underlying customer data is current enough to support AI-assisted decisions. Accuracy as of the last periodic review is no longer enough.

How Encompass approaches this

This is the kind of infrastructure the Mills Review asks the industry to build toward: AI systems acting on verified facts, inside clear governance boundaries rather than outside them.

Encompass’s EC360 platform builds a real-time CDI profile, so the facts a bank relies on for onboarding, due diligence, and ongoing monitoring stay current rather than accurate only as of the last check.

Encompass has also built a Model Context Protocol (MCP) server for EC360, giving AI agents and co-pilots a structured, permissioned, and traceable way to query that data directly, rather than interpreting documents or working from static exports. Every query is auditable by design, which matters to a compliance function proving it met its obligations, and just as much to an AI system trying to act on good information.

 

Frequently asked questions

What is the FCA Mills Review?

It is the Financial Conduct Authority’s review into how AI will reshape UK retail financial services by 2030. Sheldon Mills led it. The FCA published it on July 6, 2026.

Does the Mills Review introduce new AI rules?

No. It concludes the existing framework remains fit for purpose. That includes the Consumer Duty and the SM&CR. Instead, it sets out seven priority recommendations for how the FCA applies and strengthens that framework.

Does the Mills Review apply to corporate KYC and AML?

Not directly. It is scoped to retail financial services. But its findings on third-party dependency, accountability and data foundations apply elsewhere too. They matter just as much for corporate onboarding, KYC and anti-money laundering (AML) functions.

Who remains accountable when AI is involved in a financial decision?

The named senior manager, under the SM&CR. The review is explicit on this point. Accountability does not shift to the AI system or its provider as autonomy increases.

Encompass Corporation

Encompass helps banks build the real-time, verified corporate digital identity that AI-assisted KYC and onboarding decisions depend on. We also build the governed infrastructure that lets AI systems act on it safely.

Want to talk through what the Mills Review means for your KYC operation? Get in touch with the Encompass team.

 
Author: Howard Wimpory

Howard works with Tier 1 banks to digitally transform their KYC onboarding and refresh processes. He has held a number of executive-level operational roles with a major global bank including leading their wholesale KYC Onboarding and Refresh functions. His most recent role prior to Encompass was as Managing Director, Group Financial Crime Operations position at Barclays Bank, where amongst other functions, he was accountable for leading KYC Remediation of Corporate and Investment Bank Client records to FCA committed timeline.

LinkedIn Profile | Howard Wimpory

You also might be interested in

west
east

Discover corporate digital identity from Encompass

 

Find out more