AI-assisted assessment without losing accountability
Where intelligent assistance can reduce manual effort, and where expert oversight must remain decisive.

AI-assisted assessment without losing accountability
The RTS 6 self-assessment is exactly the kind of exercise firms now instinctively ask an AI tool to help with. It is long, it is annual, it draws on the same underlying facts every year, and much of it is narrative: explaining, article by article, why the firm considers itself compliant. That is precisely the sort of writing task large language models are good at.
It is also, on its own, a reasonable thing to want. The previous two pieces on this blog have already made the case that the self-assessment is too resource-intensive, too fragmented, and too reliant on reconstructing evidence after the fact. If AI can take some of that burden off Risk, Compliance and Technology, that is worth having.
The question here is narrower than whether firms should use AI on this exercise. Most already use it somewhere in the compliance function, and more will next year. The real question is what "using AI" has to look like for the resulting self-assessment, and the second-line review of it, to still be something the firm can stand behind.
Delegating drafting does not delegate accountability
Start with where the accountability sits, because AI does not change the answer.
RTS 6 already assumes an answer to this question in a related context. Where a firm outsources or uses third-party algorithms, ESMA's supervisory briefing is explicit that the firm remains fully and solely responsible for compliance with MiFID II and RTS 6, whoever wrote the code or operates the system. Responsibility is not something a firm can hand off along with the work.
The same logic now applies to AI, and UK regulators have said so directly. In oral evidence to the Treasury Committee's inquiry into AI in financial services, and in subsequent public remarks by its Chief Executive, the FCA has been consistent: there is no dedicated Senior Manager Function for AI, and responsibility for AI-driven outcomes sits within the existing accountability regime under the SM&CR. The regulator has been direct about it: delegating to algorithms "does not dilute liability."
Applied to the self-assessment, that principle does not move who owns the conclusion. Article 9 still places primary responsibility with the risk management function. Senior management still has to approve it. If AI helped draft the narrative behind a particular article, that does not create a new party to be accountable for what it says. The named individuals who already own the conclusion still own it, whether they typed every word themselves or not.
That is reassuring in one sense and demanding in another. Firms do not need to solve some novel AI-governance question before they can use these tools on the self-assessment. But the existing standard for what counts as an adequate, evidenced, defensible conclusion does not relax just because a machine helped produce it faster.
Fluent is not the same as grounded
The specific risk worth naming is one regulators have already flagged themselves. In the same Treasury Committee inquiry, both the FCA and the Bank of England pointed to validating AI-generated output, and catching the hallucinations generative tools are prone to, as a problem the industry has not solved yet.
Applied to a self-assessment, that risk takes a particular shape. Ask a general-purpose AI tool to draft the case for compliance with a given RTS 6 article without pointing it at anything specific, and it will produce something. The output will be fluent, well-structured, and will use the right vocabulary, because that is what these tools are built to do. Whether it accurately reflects the firm's actual controls, actual evidence and actual conclusion is a separate question the fluency does nothing to answer.
That is a worse failure mode than a blank page, not a better one. A blank page invites scrutiny. A confident, well-written paragraph tends to get read and approved. If second-line review is working from prose rather than the evidence the prose is supposed to represent, the independence and challenge described in the second-line review piece on this blog have nothing real to test. A reviewer can be as independent, technically capable and well-resourced as the rule requires, and still wave through a conclusion that was never actually grounded in anything.
AI can draft from evidence instead of inventing it
The fix is not to keep AI away from the self-assessment. It is to change what it is drafting from.
There is a real difference between asking a model to generate a compliance narrative from a prompt, and asking it to write up a narrative from a specific control, its documented rationale, and the evidence that the control operated during the assessment period. In the first case, the model is composing. In the second, it is assembling and explaining material that already exists and is already linked to a specific requirement, a specific owner and a specific evidence trail.
That distinction is only available to a firm whose self-assessment already runs on the kind of connected structure described in the first piece on this blog: requirement, scope, control, evidence and conclusion held together, rather than scattered across a spreadsheet, a SharePoint site and an inbox. Feed an AI tool that structure and its output is checkable, sentence by sentence, against something specific. Feed it a blank prompt and a general sense of what the firm does, and its output is checkable against nothing.
This is why AI assistance and better assurance turn out to be the same project rather than two separate ones. The work of connecting scope, controls and evidence has to happen either way, for a human writer or a machine one. Firms that have already done it get a genuine efficiency gain from AI. Firms that have not are asking a language model to paper over a gap that was always going to surface eventually, whether a regulator or an auditor found it first.
The AI's contribution has to be part of the record
The last piece is evidencing the process itself, not only the output.
The FCA has already acknowledged that firms will need clearer audit trails and human-in-the-loop protocols around AI, with further guidance expected. For a self-assessment, that is a natural extension of the auditable-conclusion chain from the second-line review piece on this blog, with two extra links for where AI sits:
Control → Rationale → Evidence of operation → Draft → Human review → Conclusion
AI can reasonably sit at the drafting step. It should not sit at the review or conclusion step, and the record should show which is which.
In practice, that means being able to show which parts of a self-assessment were AI-drafted from linked evidence, who reviewed that drafting against the underlying material, what was changed or queried before it was accepted, and who ultimately signed off. That is not a materially different standard from what second-line review already owes any other input to the self-assessment. It simply has to be applied to AI-generated text as deliberately as it would be applied to a spreadsheet a junior analyst put together, rather than waved through because it happens to read well.
Speed without losing the name behind the conclusion
None of this is an argument against using AI on the self-assessment. It is an argument for what has to be true first.
Accountability for RTS 6 was never going to move just because a new tool arrived to help write the document. The firm is still responsible. Risk management still owns the conclusion. Second line still has to challenge it, with enough context to do so meaningfully. What changes is this: AI can take on a genuine share of the drafting and evidencing burden, but only for firms whose scope, controls and evidence were already connected enough to give it something real to draft from.
Done that way, AI does not weaken the assurance chain. It moves faster along a chain that was already there.
Daniel Shearer, Founder of Cerylis
Daniel Shearer is the founder of Cerylis and a capital-markets compliance specialist with experience across investment banking, professional services and RegTech. His work has covered MiFID II and MiFIR, algorithmic and electronic trading governance, RTS 6, regulatory controls and wider markets compliance.