The FCA's approach to AI is principles-based: firms need to be able to explain how a model works and demonstrate ongoing monitoring. Provenance-gated retrieval — citing only verified sources, refusing when it can't — is one concrete way to satisfy that for customer-facing systems.
A common gap: firms deploying LLMs for customer-facing answers can't show where a specific answer's underlying facts came from, or prove the model declined to answer when it should have.
Auditing the retrieval pipeline, implementing provenance tracking for citations, and building a refusal-first gate so the system declines rather than guesses when source confidence is insufficient.
Related real work:
RegTech retrieval for FCA-regulated firms, provenance-gated citations, refusal-first answer gate
No. This is technical work on the system itself — retrieval, provenance, refusal behavior. Regulatory sign-off remains your compliance team's call.
Standard audits review documentation. This verifies the actual retrieval pipeline and runtime refusal behavior, not just the policy describing them.
Access to your technical documentation and a diagnostic call about what needs verifying and why it matters to your specific system.