Go Back

3 Signals Compliance Leaders Should Take From the FCA’s Mills Review

The FCA’s Mills Review is one of the clearest statements yet about AI adoption in financial services. While much of the discussion has focused on the report’s vision for AI-enabled supervision, its more immediate implications for compliance leaders are equally significant: how AI should be governed, where it should be trusted, and how human expertise should evolve alongside it.

Three messages stand out.

1. The Autonomy Spectrum Is a Governance Framework

One of the most significant contributions of the Mills Review is its autonomy spectrum. It describes how organizations can move from AI supporting individual tasks to AI operating within defined boundaries under human oversight. Rather than treating autonomy as a single concept, the framework recognizes different levels of responsibility and control.

For compliance teams, this matters because the discussion is no longer about whether AI can assist with investigations or surveillance. The more important question is how organizations can safely increase autonomy while maintaining accountability.

The framework reinforces an important principle: Greater autonomy requires stronger governance.

The report presents the Consultant and Approver levels as practical models for many AI-enabled workflows. At these stages, AI carries more of the operational workload while people retain responsibility for decisions that require judgment. This provides a practical framework for how compliance functions can evolve as AI capabilities mature.

The framework also reinforces an important principle: Greater autonomy requires stronger governance. As AI assumes more responsibility, firms need explainability, auditability, and configurable controls to understand and govern how decisions are made. Greater autonomy also depends on evidence that the system continues to perform as intended. Ongoing integrated evaluation allows firms to identify changes in performance and determine whether the level of autonomy granted to the system remains appropriate.

Autonomy should therefore be earned and maintained through evidence. The more responsibility firms delegate to AI, the more important it becomes to demonstrate that its decisions remain reliable, explainable, and aligned with the judgment of the compliance professionals ultimately accountable for them.

2. Continuous Compliance Is Becoming the New Operating Model

The Mills Review also signals a broader shift in how compliance should operate.

For many firms, surveillance remains largely episodic. Alerts are reviewed after they are generated. Investigations begin after risk has been identified. Evidence is assembled periodically to support supervisory reviews.

The report points toward a different model. AI enables continuous monitoring, allowing firms and regulators to identify patterns, assess emerging risks, and respond much earlier in the process.

This shift reflects the reality of today’s compliance environment. Communication channels continue to expand, data volumes continue to grow, and risk evolves faster than periodic review cycles were designed to accommodate.

AI also changes both the volume and scope of surveillance. More accurate detection can reduce unnecessary alerts, giving analysts more time to focus on complex cases that require human judgment. At the same time, AI can analyze activity across communications and channels, connecting signals that may appear innocuous in isolation but become meaningful as a pattern develops.

This broader, ongoing analysis is what enables a more continuous approach to surveillance. Rather than evaluating communications primarily as individual events, AI can identify patterns as they emerge across activity and over time, while investigation and judgment remain with compliance professionals. Agentic systems can support this process across the workflow by analyzing communications, evaluating evidence, identifying related cases, and recommending next steps.

3. Human Judgment Becomes Even More Valuable

Perhaps the most important message in the Mills Review is that human judgment remains central throughout this evolution. The report consistently emphasizes that AI should support supervisors by identifying issues earlier and providing better information, while people continue to exercise oversight and make the decisions that matter most.

This perspective is important because many discussions about AI still focus on replacement rather than enablement.

In practice, the greatest value comes from combining AI’s ability to process information at scale with the expertise of experienced compliance professionals. AI can review large volumes of communications, identify relationships across datasets, and discover emerging risks far more quickly than manual processes. Compliance teams then apply judgment where it has the greatest impact, including evaluating complex cases, interpreting context, and making defensible decisions.

The Mills Review offers a practical vision for how AI-enabled compliance can evolve.

From a technical perspective, human judgment also plays an important role in determining whether an AI system continues to perform as intended. This requires monitoring and evaluating decisions in production and sampling a proportion of outcomes for human review. That feedback provides an ongoing measure of alignment with human judgment, helps identify drift, and creates a basis for improving the system as conditions, data, and risks evolve.

Effective oversight is designed into the workflow from the beginning. Organizations need clear escalation criteria, configurable controls, transparent decision logic, and ongoing quality assurance. Together, these mechanisms allow human expertise to be applied to the cases that require judgment and to the ongoing evaluation of the AI itself.

As AI capabilities continue to advance, human expertise becomes more focused on the areas where it delivers the greatest value. That is a positive development for both compliance teams and the organizations they protect.

Looking Ahead

The Mills Review offers a practical vision for how AI-enabled compliance can evolve. Greater autonomy requires evidence, continuous operations require effective controls, and human judgment remains central to both.

For compliance leaders, the challenge is to demonstrate not only what their AI can do, but why it can be trusted to do it.

Learn how Shield is helping financial institutions build governed, AI-powered compliance operations that strengthen oversight while keeping human judgment at the center.


Subscribe

Follow Us

Subscribe to our newsletter

Gain access to exclusive insights, industry influencers, and thought leaders in

Digital Communications Governance and Archiving (DCGA).