The FCA just made vendor self-certification worthless
New guidance on AI model governance for regulated firms is now live. If you’re using generative AI for customer communication, credit decisions, or investment advice, you need documented model risk frameworks, quarterly bias testing, and audit trails for every decision.
The Financial Conduct Authority published guidance on AI model risk management on 14 August 2026, applying to all FCA-regulated firms using generative AI for customer-facing decisions or communications. The FCA now requires model cards and quarterly independent bias testing, and vendor self-certification is no longer acceptable.
The model governance requirement
All AI models used for customer decisions must have a documented governance framework. Self-certification, “the vendor said it’s safe”, does not satisfy this requirement.
The FCA requires every regulated firm using AI models for customer-facing decisions to maintain a documented model governance framework, covering the model lifecycle from development through decommissioning, model risk classification by customer impact, documented testing and bias validation before deployment, audit trails recording model inputs, outputs and decisions, regular bias testing at minimum quarterly for customer-facing models, model cards documenting technical specifications and known limitations, and escalation procedures for identified bias or model degradation.
These are not optional best practices. They are regulatory requirements, and firms that do not implement them are in breach of FCA guidance.
What a model card contains
A model card is a datasheet. It documents what the model does, how well it does it, and what it does badly. The FCA requires you to maintain this for every customer-facing model.
The FCA requires a model card for each customer-facing AI system, covering the training data, including what it was trained on, when, by whom, and whether it’s representative of your customer base with known biases; performance metrics, including accuracy, benchmarks, whether accuracy varies by demographic, and drift over time; known limitations, including what the model does poorly and what it is not designed for; and bias testing results, including methodology used and whether results are within acceptable tolerance.
The model card must be created by the firm, not outsourced to the vendor. The vendor provides technical details; the firm validates them and certifies them in the model card.
Vendor obligations
Vendors now need to invest in audit-ready documentation. Firms that don’t provide it will face customer churn to competitors offering better governance documentation.
If you’re licensing an AI model, the vendor must now provide model governance documentation suitable for FCA compliance: technical specifications covering architecture, training approach and data sources, bias testing results from independent third-party auditors, known model limitations and failure modes, performance benchmarks on standard datasets, and attestation that the model was not trained on data obtained without consent or in violation of copyright.
Most AI vendors today do not provide this. They provide a licence, an API, and generic assurances that the model has been tested extensively. The FCA is saying that is insufficient, and vendors will need to either create model governance documentation and have it independently audited, or partner with auditing firms that can certify it on their behalf.
Why self-certification is no longer enough
Pre-guidance, vendor risk was dispersed: “we use an AI vendor, they’re responsible for accuracy.” Post-guidance, the firm is responsible.
Before this guidance, a firm could justify AI deployment by saying the vendor assures the model is accurate and unbiased. That is no longer acceptable. The FCA guidance is explicit: vendor assurance of model safety is not equivalent to documented model governance.
A vendor can say the model has been tested and is good, but the firm must still verify the vendor’s claims with independent testing, maintain audit logs of model decisions in production, conduct quarterly bias testing with independent auditors, and document all of it in the model card. If an AI model makes discriminatory decisions, the firm is liable to the regulator and to customers, regardless of vendor assurances.
The implementation timeline
Third-party auditing of AI models costs GBP 20,000 to 50,000 per model. Quarterly bias testing adds another GBP 10,000 per model per year.
A typical timeline for a single AI model: weeks 1 to 2 gathering vendor documentation and identifying gaps, weeks 3 to 4 testing model performance on firm-specific data, weeks 5 to 8 engaging an independent auditor to validate testing and bias assessment, weeks 9 to 12 developing the model card and setting up audit logging in production, and weeks 13 to 16 deploying the model with the governance framework in place and a quarterly bias testing schedule established.
That assumes a single model used for one function such as credit decisions. A firm using five customer-facing models faces six to nine months of work to achieve full FCA compliance, and the cost compounds across every model in production.
What to renegotiate
“Vendor will provide: (1) complete audit logs of all model inputs and outputs, (2) 60 days’ notice before model changes, (3) documentation suitable for FCA model governance compliance, and (4) indemnity for vendor-side failures.”
If you license AI models from vendors, renegotiate four things. Output logging and audit trails should be a contractual deliverable with a defined retention period and your right of access, not a feature the vendor may deprecate. Advance notice of material model or prompt changes, typically 60 days, gives you time to re-test and update your model card before a change reaches production. Testing and documentation obligations should require the vendor to provide or facilitate third-party bias testing and share detailed information about training data and known limitations; push on this as non-negotiable for FCA compliance. And indemnity for model output should reach vendor-specific failures such as missing audit logs, missed notice deadlines, or a materially degraded model deployed without approval, even though no vendor will indemnify every inaccurate output given models are inherently probabilistic.
Questions this raises
Six questions the FCA’s model governance guidance tends to prompt, answered directly.
What is a model card?
A documented datasheet of an AI model covering training data, performance metrics, known limitations, and bias testing results. The FCA requires one for every customer-facing model.
Who certifies the model card?
The regulated firm is responsible for certifying the model card is accurate. Most firms hire independent auditors to verify vendor claims before publishing it.
Can we rely on vendor assurances instead of independent testing?
No. Vendor self-certification is no longer acceptable under FCA guidance. The firm must independently test the model and maintain documented evidence of that testing.
How long does FCA model governance implementation take?
Typically 90 to 180 days per model, and 6 to 9 months for a firm using multiple models, covering vendor documentation review, independent testing, auditor validation and audit logging setup.
What should we negotiate with AI vendors?
Audit logging, 60 days’ notice of model changes, FCA-compliant documentation, and indemnity for vendor-side failures such as missing logs or an undisclosed materially degraded model.
Is our current AI vendor indemnity sufficient?
Probably not. Review vendor agreements specifically for audit logging rights, testing rights, advance notice of model changes, and indemnity that reaches model output, since standard tech vendor indemnities usually exclude it.
Sources
- Financial Conduct Authority, AI Model Risk Management Guidance, 14 August 2026.
- FCA, Model Governance and Bias Testing Standards, August 2026.
- FCA, Third-Party Auditor Requirements for AI Model Validation, August 2026.
Building FCA-compliant model governance?
Eliga provides embedded commercial and technology counsel to scaling businesses. We help regulated firms audit AI vendor agreements, implement model cards, set up audit logging, and renegotiate contracts to meet FCA requirements.
This page is general information about UK commercial and technology law. It is not legal advice and does not create a solicitor-client relationship. Take specific advice on anything you are about to negotiate or sign.

