
Who's in the room when the model makes a conduct call?
Who's in the room when the model makes a conduct call?
Most AI governance committees in financial services look the same. Model risk is there, testing the technical soundness of what the model does. Technology is there, managing deployment and infrastructure. Legal is there. What's typically missing is anyone whose job is conduct and culture.
That gap matters more than it may at first appear, because AI isn't staying in its lane. It's increasingly involved in decisions that sit close to conduct: triaging surveillance alerts, scoring performance, flagging patterns in behaviour that might indicate non-financial misconduct. Model risk can tell you whether a model is statistically sound, well calibrated, performing as designed. It has no real mandate, and often no vocabulary, to ask whether the outcome is one the firm could defend to a regulator on conduct grounds, or whether people change how they behave once they know they're being scored by it. That's a different question from "does the model work." It's "does the firm still know what it's accountable for."
And accountability is exactly where this becomes hard to enforce if the room is wrong. The FCA, MAS, APRA and ASIC have been clear that delegating a decision to an algorithm doesn't transfer the liability. A named senior manager remains accountable for outcomes the model produces, including biased or harmful ones. But accountability isn't just a legal designation. It has to be exercised somewhere, by someone who actually understood the decision being made and could have intervened. If the only voices in AI governance are legal, model risk and technology, the person eventually held accountable for a conduct related outcome may never have had a genuine opportunity to shape or challenge it before it went live.
This isn't a call for another seat on a committee for its own sake. It's a recognition that conduct and culture require a particular kind of judgement, the same judgement that shows up in grey-area misconduct cases, and that judgement doesn't transfer to legal or model risk simply because they happen to be in the room. If accountability is going to mean anything when an AI-influenced decision is tested, the people who understand Conduct need to be part of shaping it, not briefed on it after the fact.
Look at your own AI governance committee, or RAI team. Who in that room is responsible for what the model does to the people it assesses?
