Skip to content
AI & Finance

Smartstream's AI model raises governance questions for UK banks

Smartstream says its Smart Agents can resolve reconciliation exceptions autonomously, not just flag them. UK firms stay fully accountable for outcomes, and key detail on authorisation limits and audit trails is not yet public.

By

Published
An old brass turnstile stands in an empty hall beside a tall stack of stamped ledger pages, with no attendant in the booth behind it.

Smartstream, a back-office technology provider to banks and asset managers, says its Smart Agents product can now investigate, classify and resolve reconciliation exceptions on its own, rather than simply flagging a mismatched trade or cash break for a human to sort out. The company announced general availability on 2 June 2026, pitching the tool at bank reconciliations, cash breaks, settlement exceptions and post-trade investigations.

That is a meaningful change in what software is allowed to do inside a UK bank's operations function. In Smartstream's own account, the alternative to autonomous handling is a system that matches records and flags the ones that don't tie out, leaving a person to decide what happens next. Its autonomous mode is designed to take some of those decisions itself, including internal and counterparty communications.

The shift matters now for two reasons. First, UK financial institutions remain fully accountable for outcomes in reconciliation and settlement regardless of which system performs the work, so a vendor's governance claims are the start of a compliance conversation, not the end of one. Second, the UK's move to next-day securities settlement from 11 October 2027 is compressing the overnight window for investigating exceptions, which makes autonomous processing attractive and makes the underlying controls more important to get right.

From flagging exceptions to resolving them

Smartstream describes two modes: an assistive mode, where the system supports a human investigator, and an autonomous mode, where it can act. In autonomous mode, an agent can investigate a break, classify its likely cause and resolve it, including contacting a counterparty, according to the company's launch material and product documentation.

That is a different risk profile from a system that only flags. Smartstream's own description confines the autonomous mode to investigating, classifying, resolving and communicating about exceptions. Whether an agent can also post ledger entries, release payments or amend settlement instructions, and how granular the client-set authority limits are, is not established in the public material. That is the central question for any UK firm considering the product.

What Smartstream's control model contains

Smartstream calls its approach policy-controlled autonomy, with four public elements: policy controls that set what an agent may do, human-in-the-loop oversight, maker-checker workflows, and user confirmation at points where the company says governance or judgement is required. It also says every agent action is logged and explainable, producing an audit trail.

Those are the right categories for a control framework, and the launch material and product FAQ confirm they exist as product capabilities. They do not specify how granular the policy controls are, how maker-checker separation is enforced, or what exactly triggers a confirmation gate rather than autonomous action. Smartstream's public documentation supports the existence of these controls; it does not establish their configuration detail, enforcement architecture or independent assurance.

Authorisation limits: the open questions

A UK operations or risk team evaluating this kind of tool would normally want to set authority limits by transaction value, account, counterparty, instrument or risk category, time window, data source and cumulative exposure. Smartstream's public material does not specify whether limits can be set at this level, or whether an agent has a distinct, governed identity rather than acting through a shared service account or borrowed human credentials.

Audit trails: what a regulator-grade record needs

Smartstream says its audit trail is complete and every action explainable. A UK firm relying on that description would typically need to know what fields the log captures: the prompt and input data, retrieved documents, the policy and model version in force at the time, tool calls made, any human approval or override, and errors or retries. It would also want to know the retention period, whether the log is tamper-evident, and whether it can be exported for the firm's own auditors and for supervisors.

None of that detail is available in the sources reviewed. FCA rules on outsourcing (SYSC 8) address a firm's continuing access to information and oversight arrangements where functions are outsourced, which is the kind of provision this detail would need to satisfy, but the public material does not connect Smartstream's logging design to those requirements. This is an evidential gap rather than a contradiction: Smartstream has not been shown to be wrong, only to have not yet shown its working.

Accountability stays with the firm

Under SYSC 8, a firm that outsources a critical or important operational function remains fully responsible for meeting its regulatory obligations, and senior personnel cannot delegate that responsibility away. The FCA has said that applicable requirements vary by firm type and activity, so a Smartstream deployment is not automatically a material outsourcing arrangement subject to every SYSC 8 provision; that depends on the contract and how central the service is to the firm.

Speaking on 24 June 2026, the FCA's chief executive said accountability for regulated activities and outcomes must remain clear as agentic systems enter financial services. A human-in-the-loop label on its own does not settle that question. A UK regulator would expect to see responsibility allocated to a named senior manager, evidence that oversight actually operates, and the ability to intervene, not simply a confirmation step somewhere in the workflow.

The FCA has also been explicit that it is not creating a distinct rulebook for agentic AI. Its January 2026 review into the long-term impact of AI on retail financial services and its published AI overview both point to applying existing frameworks, including outsourcing, senior managers' accountability, operational resilience, conduct and data rules. The FCA's own webpage, accessed 27 September 2026, cites figures that 75% of firms it surveyed or represented had adopted some form of AI and 84% had an individual accountable for their AI approach; the underlying sample and reference period are not stated, so these figures should be read as indicative rather than precise.

Operational resilience: what happens when something breaks

PRA Supervisory Statement SS1/21, effective from 31 March 2022 and applying to UK banks, building societies and PRA-designated investment firms among others, requires firms to identify important business services, set impact tolerances for disruption, and remain within those tolerances during a severe but plausible scenario. By 31 March 2025, firms in scope were expected to have sound systems in place for this.

Whether reconciliation counts as part of an important business service depends on each firm's own mapping and its assessment of potential harm from disruption. What is clear is that scalability under normal conditions is not the same test. A system that handles peak volumes smoothly does not demonstrate that a firm has a tested fallback if the agent, its model provider, Smartstream or a connected data source becomes unavailable at a settlement deadline, or that autonomous actions can be reversed safely. Smartstream's public material was not found to describe kill-switch, rollback, incident-notification or vendor-exit arrangements in the detail SS1/21 testing would require.

The T+1 clock is tightening

HM Treasury confirmed on 20 November 2025 that it had accepted 11 October 2027 as the date for mandatory UK T+1 securities settlement, subject to the required legislation. The Accelerated Settlement Technical Group's implementation design compresses the working day for post-trade teams considerably.

MilestoneUK timeApplies from
Allocations and confirmations completed23:59 on trade date (T+0)11 October 2027
CREST settlement system availabilityExtended to 21:00 on trade date (T+0)11 October 2027
Settlement instructions reach the central securities depository05:59 on T+111 October 2027
Firms to have relevant policies and procedures in place—31 December 2026

In an August 2026 blog post, the FCA said firms would need to speed up post-trade processes rapidly, including automation where appropriate, to prepare for T+1. The deadlines above leave a narrower overnight window for investigating breaks than firms have today. The verified evidence here concerns extended hours for the CREST settlement system, not a general lengthening of UK exchange trading hours, a distinction worth keeping straight when discussing "longer hours" in this context.

Reading the pilot numbers carefully

Smartstream's launch material reports that Tier 1 pilot deployments cut investigation time per exception from 14 minutes to 30 seconds, a reduction of about 97%, and that Tier 1 pilot clients projected 50% to 70% automation of relevant work within the first year. Both figures come from Smartstream's own announcement. The participating institutions, sample sizes, exception types and measurement methods are not disclosed, and the automation figure is explicitly a client projection rather than a realised, independently verified outcome. Readers should treat these as vendor-reported claims about pilot conditions, not as evidence of what a live, at-scale deployment will achieve inside a specific firm's control environment.

What to watch next

The practical test of Smartstream's governance model, or any comparable product, is not whether it describes the right categories of control but whether a specific UK firm can demonstrate granular authority limits, a complete and exportable audit trail, a named accountable senior manager, and a tested plan for when the system or a dependency fails. None of that is established by a vendor announcement alone. Firms considering this kind of deployment, and their advisers, would look to the FCA's SYSC 8 outsourcing rules, the PRA's SS1/21 operational-resilience expectations, and the Accelerated Settlement Technical Group's T+1 timetable for the obligations that apply to them, rather than to a supplier's own description of its controls.

Sources

  1. Smart Agents (opens in a new tab)

    Smartstream · Accessed

  2. Rethinking regulation for the age of AI (opens in a new tab)

    Financial Conduct Authority · · Accessed

  3. FCA Handbook: SYSC 8 Outsourcing (opens in a new tab)

    Financial Conduct Authority · Accessed

  4. Outsourcing and operational resilience (opens in a new tab)

    Financial Conduct Authority · Accessed

  5. AI: artificial intelligence in financial services (opens in a new tab)

    Financial Conduct Authority · Accessed

  6. SS1/21 Operational resilience: Impact tolerances for important business services (opens in a new tab)

    Prudential Regulation Authority, Bank of England · · Accessed

  7. Government response to Technical Group report (opens in a new tab)

    HM Treasury · · Accessed

  8. Accelerated Settlement Technical Group report (opens in a new tab)

    Accelerated Settlement Technical Group · · Accessed

  9. T+1 settlement: are firms ready for 2027? (opens in a new tab)

    Financial Conduct Authority · · Accessed