AI Governance Starts with Reality - Davies

AI Governance Starts with Reality

Governance is often presented as a way of controlling risk. Increasingly, it may become a way of creating value.

Why Understanding What You Have Is the Only Sensible Place to Start

Good governance and smart investment are not two separate conversations. Firms that treat them separately do not just create compliance theatre. They systematically misallocate capital. One produces governance frameworks built in isolation from commercial reality. The other produces investment decisions made without understanding what already exists.

An effective approach to governance does both simultaneously. By understanding what is already happening across the organisation, what the existing technology stack already does, and what problems people are actually trying to solve, governance and investment begin to inform each other naturally. Firms are not building rules for hypothetical AI. They are governing real usage, real tools and real risk.

The risk is not that firms fail to adopt AI. It is that they adopt it in ways they do not fully understand.

That misunderstanding often starts with a flawed assumption: governance begins when a firm decides to adopt AI. In reality, adoption is already happening. Employees are using AI to solve problems. Existing platforms are embedding AI capabilities into day-to-day workflows. Governance is not catching up with a future state. It is catching up with a present one.

The challenge therefore is not designing governance from a blank sheet of paper. It is bringing visibility, structure and accountability to something that already exists.

More importantly, the challenge is organisational rather than technological. Technology teams, compliance functions and front-office teams often view AI through different lenses, with different priorities and concerns. The objective is not to reduce governance, but to make it more effective by aligning accountability, decision-making and risk ownership around a common approach.

 

Start the Conversation Without the Threat

The instinct when discovering ungoverned AI usage is to shut it down. It is an understandable response. It can also send a clear message to employees: experimentation is not welcome. At a time when organisations are trying to build AI capability, that may be the opposite signal they intend to send.

This is not an argument for blindly supporting all AI usage. Some applications will require immediate containment, particularly where client data or regulatory exposure is involved. The point is different: before governance can be effective , firms need to understand what is already happening.

The conversation needs to be forward looking. What tools do people find useful? What problems are they trying to solve? Where does AI genuinely help and where does it fall short? That framing encourages honesty rather than defensiveness. It acknowledges that some of the most valuable lessons about AI adoption are already sitting inside the organisation.

Employees are not waiting for governance frameworks before using AI. They are already using whatever tools help them work more effectively. Understanding that is where governance begins.

 

Audit What You Already Have

Leadership teams often believe they understand their technology stack. In reality, they rarely have full visibility into either the AI capabilities embedded within existing platforms or the tools employees are experimenting with day-to-day.

That gap between approved systems and actual behaviour is where a hidden AI layer emerges. Portfolio management systems begin generating commentary. CRMs surface next-best-action recommendations. Compliance tools automate document review. At the same time, employees experiment with new tools, compare outputs and discover practical ways to improve how work gets done.

Capability is arriving from two directions simultaneously: through existing technology contracts and through employee-led experimentation. In both cases, it often develops ahead of formal governance, procurement decisions or leadership awareness.

Understanding what existing platforms already do with AI, and how employees are already using it, helps identify genuine capability gaps rather than creating duplication. Before spending money on new solutions, firms should understand the solutions they may already possess.

 

Map Use Cases Before Writing Rules

Not all AI is equal. Treating it as if it creates more risk, not less.

Once firms understand where AI is already being used and what problems people are trying to solve, the next step is understanding the consequences of those use cases. Effective governance is therefore tiered, with governance intensity reflecting actual risk rather than assumed risk.

Consider the range of applications across a typical wealth management firm. AI drafting client communications carries low consequences if it makes an error because a human reviews the output before anything reaches a client. . . AI informing a suitability recommendation is a different matter entirely. Errors affect client outcomes directly. Same organisation. Same technology category. Completely different governance requirements.

Frameworks that govern both identically are not protecting clients. They are creating unnecessary process overhead in one instance and insufficient scrutiny in another.

 

Govern the Use Case, Not the Tool

There is an understandable temptation to standardise around a single AI platform. Governance is simpler, procurement becomes easier, and costs are easier to manage.

But different AI models genuinely excel at different tasks. A model built for nuanced long-form analysis may be poorly suited to rapid data processing. A tool optimised for client communication may underperform on compliance documentation review.

The starting point should therefore be the use case, not the tool. Once firms understand the outcome they are trying to achieve, they can make informed decisions about the technology best suited to support it.

This does not mean every use case requires a different platform. It means technology decisions should be driven by business need rather than the assumption that one tool will always be the right answer.

The standards that matter, including data handling, explainability, audit trails, and thresholds for human oversight, should travel with the use case rather than being attached to a specific tool. That distinction is what makes governance workable practical than obstructive.

 

Invest Correctly, Not Comprehensively

The work of understanding existing usage, mapping use cases and defining acceptable levels of risk is not just a governance exercise. It is what enables informed investment decisions.

AI investment without use-case clarity does not just increase cost. It reduces return on capital.

There is a genuine cost challenge here that boards are beginning to feel. Token costs, API fees and compute requirements can become significant, particularly for firms experimenting broadly rather than deploying selectively. Budgets are increasingly consumed by initiatives that have not yet demonstrated sufficient return at current economics.AI investment is not limited to technology. Firms also need to invest in the people responsible for using, challenging and overseeing AI-driven processes. The value created by AI is ultimately determined by the quality of the decisions made around it.

The temptation is to wait. As the technology continues to mature, many of today’s AI-related costs are likely to reduce. The economics will almost certainly look different in the future. But firms waiting for better economics are handing competitors a head start that may prove difficult to overcome.

The organisations that have already identified their highest-value use cases, built workflows and proven where AI creates value will be able to scale efficiently as costs compress. The organisations that wait will be starting from scratch while their competitors build on what already works.

The answer is not to delay adoption, nor to spend indiscriminately. It is to invest deliberately in use cases where ROI already justifies current costs, then expand as economics improve. Use-case clarity is not just a governance question.

It is what makes AI investment commercially defensible.

 

Evidencing Is Not Optional

Consumer Duty shifted compliance from process to outcome. It is no longer sufficient to have good governance processes. Firms must be able to demonstrate positive client outcomes.

AI creates both a challenge and an opportunity.

Firms must understand and explain how AI influences recommendations, decisions, and client interactions. At the same time, AI creates the potential to capture far richer evidence than many existing processes allow. Interactions can be logged; recommendations can be recorded alongside supporting rationale and vulnerability indicators can be tracked with greater consistency than manual approaches.

But only if evidencing is designed in from the start.

Firms deploying AI without clear evidencing requirements often discover retrospectively that they have powerful systems generating outputs they cannot fully explain. More concerningly, they may find themselves unable to reconstruct how a particular recommendation, assessment or decision was reached months or years later. At that stage, retrofitting transparency becomes expensive and disruptive

The opportunity is substantial. Audit trails currently assembled manually can become part of normal operations. But that advantage exists only when evidencing and retention are designed into the process from the beginning. Firms must be able to reconstruct not just an outcome, but how that outcome was reached using the information available at the time.

In a Consumer Duty environment, explaining how an outcome was reached may become just as important as the outcome itself.

 

Build for Evolution, Not Just Today

Governance must be dynamic. It cannot remain a point-in-time exercise. AI capabilities are evolving faster than regulatory guidance. The FCA’s approach to AI governance is developing, not settled. Frameworks designed solely to satisfy today’s requirements accumulate risk quietly because the environment around them continues to change.

The governance framework is not a document to file after initial approval. It requires ownership, regular review, and genuine reassessment as AI capabilities and regulatory expectations evolve. Treat it as a living document with accountability for keeping it current.

This applies not only to policies and controls, but also to the assumptions underpinning them. Low-risk use cases today may become more significant tomorrow as adoption increases. Tools that meet governance requirements today may evolve in ways that require reassessment. Governance must therefore be capable of adapting as quickly as the environment it is designed to oversee.

Effective governance ultimately depends on people. It cannot rely solely on technical specialists. It requires individuals capable of combining technological understanding with business context, risk awareness and judgement.

The firms that approach governance as an ongoing capability rather than a one-time exercise will be best positioned to respond to both regulatory change and technological innovation.

 

Governance as a Mechanism for Value

Every firm’s answer will be different. The mistake is believing governance begins with a framework. It begins with understanding what is actually happening across the organisation.

The technology already exists. The usage is already happening. Good governance is not about accepting every use case or tool. It is about understanding enough to make deliberate decisions about where AI should create value, where it should not, which technologies are appropriate and what level of governance each application requires.

Firms that approach governance as a compliance exercise risk creating governance theatre: frameworks that exist on paper but have little influence on how AI is actually used.

The firms that treat governance as a mechanism for deciding where AI should create value will do something different. They will invest more selectively, govern more intelligently and learn faster than their competitors.

The difference will define who captures the value of AI in wealth management – and who is left

Governance is often presented as a way of controlling risk. Increasingly, it may become a way of creating value.

The firms that understand what AI is already doing across their organisation, govern it intelligently and invest where it creates genuine advantage will learn faster than their competitors.

Governance is not what slows transformation.

Done properly, it becomes what enables it.

 

Meet the expert

Roshni Patel

Principal Consultant

Asset & Wealth Management

Operating Strategy & Transformation

I hold firm belief that projects succeed when people believe in them, actively cultivating a positive attitude and inspiring teams to strive for success.