Skip to content

FRM Exam Part II · Advances in Artificial Intelligence: Implications for Capital Markets Activities

Regulation, Governance and Ethical Considerations of AI in Financial Markets

Updated 11 October 2026 · Fact-checked

AI regulation in financial markets applies existing rules on model risk, conduct and operational resilience to AI, plus new risk-based laws such as the EU AI Act. Firms must keep clear accountability, explainable and validated models, human oversight, and controls against bias, manipulation and collusion. You answer by matching the risk to the right control.

Understand Regulation, Governance and Ethical Considerations

Most supervisors do not write one big rulebook for AI in finance. They apply existing rules on model risk, outsourcing, data, conduct and operational resilience to AI use. The aim is technology-neutral supervision: the same risk gets the same expectation, whether a human or an algorithm creates it.

Some jurisdictions add AI-specific law. The EU AI Act is the best-known example. It is risk-based: it bans a small set of unacceptable practices, imposes strict duties on high-risk uses, and lighter transparency duties on others. In finance, credit scoring of individuals is a typical high-risk use. High-risk duties include risk management, data quality, documentation, logging, human oversight, accuracy and robustness. Do not claim that all financial AI is high-risk.

Governance turns these expectations into practice. The board and senior management own AI risk appetite. Accountability must sit with named people, not with the algorithm. Firms extend model risk management to AI: inventory of models, validation independent of developers, effective challenge, ongoing monitoring for drift, and change control. The three lines of defense apply. Business units own the risk, risk and compliance oversee it, and internal audit assures it. Third-party and vendor models stay the firm's responsibility.

Ethical issues are examined as risks with controls. Fairness: models trained on biased data can discriminate against groups, even without using protected attributes, because other variables act as proxies. Explainability: opaque models make it hard to justify decisions to customers, auditors and supervisors. Privacy and data quality: poor or unrepresentative data produces poor outputs.

Market integrity is the capital markets angle. Trading algorithms can manipulate markets, for example through spoofing-like behavior learned by reinforcement learning, even if no one programmed it. Several AI agents may also reach tacit collusion, such as keeping spreads wide, without any communication. Herding on similar models and shared vendors can amplify shocks and create concentration risk. Regulators therefore expect pre-deployment testing, kill switches, surveillance and clear responsibility for outcomes.

Key formulas to remember

Technology-neutral principle
Same risk → same supervisory expectation, regardless of whether AI is used
Existing model risk, conduct and resilience rules already cover AI. Do not assume a new law is always needed.
EU AI Act risk tiers
Unacceptable (prohibited) > High-risk (strict duties) > Limited (transparency) > Minimal
Credit scoring of individuals is a typical high-risk case. Duties scale with risk.
Core governance controls
Inventory + independent validation + effective challenge + monitoring + human oversight + accountability
Use this list to build answers on how a firm should govern AI models.
Accountability rule
Accountability stays with the firm and named senior managers, never with the model or the vendor
Applies to third-party and outsourced AI as well.

How to solve Regulation, Governance and Ethical Considerations questions

Most questions give a scenario and ask for the best regulatory or governance response. Use this sequence.

  1. 1Identify the AI use: trading, credit decision, surveillance, customer advice or vendor model.
  2. 2Name the main risk: bias, opacity, manipulation, collusion, herding, data quality, third-party concentration or cyber.
  3. 3Link the risk to the regime: model risk rules, conduct rules, operational resilience, or a risk-based AI law like the EU AI Act.
  4. 4Pick the control that targets that risk directly: bias testing, explainability, kill switch, surveillance, independent validation, or exit plans.
  5. 5Check who is accountable: the board and senior management, with three lines of defense.
  6. 6Eliminate options that shift responsibility to the vendor or the algorithm, or that claim AI needs no oversight.
  7. 7Choose the answer that is proportionate, risk-based and keeps a human in control.

Quickest way: Risk-to-control matching

When to use it: Use when the options list several plausible controls and time is short.

  1. Underline the risk word in the stem (bias, collusion, opacity, vendor).
  2. Match it: bias → fairness testing and data review; opacity → explainability and documentation; collusion or manipulation → surveillance and pre-deployment testing; vendor → due diligence and exit plan.
  3. Reject any option that removes human oversight or transfers accountability.
  4. Prefer the option that is risk-based over one that is blanket.

Common mistakes in Regulation, Governance and Ethical Considerations

  • Saying AI is mostly unregulated until new AI laws arrive.

    Students focus on the EU AI Act and forget existing rules.

    Fix: State that model risk, conduct and resilience rules already apply, and AI-specific laws add to them.

  • Treating all financial AI as high-risk under the EU AI Act.

    Overgeneralizing from the credit scoring example.

    Fix: Remember the tiers. Duties depend on the use, and only listed uses are high-risk.

  • Assuming removing protected attributes guarantees fairness.

    It sounds logical.

    Fix: Proxy variables can still reproduce bias. Test outcomes across groups.

  • Believing collusion needs communication between traders.

    Human collusion rules suggest an agreement.

    Fix: AI agents can learn tacit collusion from market feedback alone. This is why outcome-based surveillance matters.

  • Placing accountability with the vendor or the model developer.

    Third-party risk is confused with transfer of responsibility.

    Fix: The firm and its senior managers stay accountable. Vendors support but do not replace oversight.

  • Choosing the most accurate model without regard to explainability.

    Performance is seen as the only goal.

    Fix: Governance requires a balance. Where decisions affect customers or capital, explainability and validation can outweigh a small accuracy gain.

Worked examples

Example 1

A bank deploys a vendor-built machine learning model to approve consumer loans. Approval rates for one demographic group are much lower, though the model does not use that attribute. Which response best fits supervisory expectations? (A) Rely on the vendor's assurance (B) Test outcomes across groups, investigate proxy variables, and have independent validation review the model (C) Remove the model's documentation to protect IP (D) Accept the result because the attribute is excluded

Show the solution
  1. Risk: unfair outcomes from proxy variables, a fairness and conduct issue. Individual credit scoring is also a typical high-risk use under the EU AI Act.
  2. Option A fails: accountability stays with the bank.
  3. Option C fails: documentation is required for validation and supervisors.
  4. Option D fails: excluding an attribute does not prevent proxy discrimination.
  5. Option B tests outcomes, finds proxies and uses independent validation, which matches model risk and fairness expectations.

Answer: B

Example 2

Two firms use reinforcement-learning market-making agents. Spreads widen in both and stay wide, with no communication between firms. What is the best description and response?

Show the solution
  1. Identify the behavior: parallel outcomes without agreement point to tacit algorithmic collusion.
  2. Its cause is that agents learn that higher spreads are rewarded and that undercutting is punished.
  3. Absence of communication does not make it harmless, because market integrity and competition concerns still arise.
  4. Controls: test agents in simulation before deployment, monitor spreads and behavior against benchmarks, set limits and a kill switch.
  5. Accountability remains with each firm's senior management, who must explain and be able to intervene.

Answer: Tacit algorithmic collusion. Firms should use pre-deployment testing, outcome-based surveillance, kill switches and clear senior-management accountability.

Exam tips

  • Expect scenario questions: name the risk first, then pick the matching control.
  • Know the EU AI Act as risk-based, with high-risk duties such as oversight, documentation and data quality.
  • Link AI governance to model risk ideas: validation, effective challenge, monitoring.
  • For market integrity, remember manipulation and tacit collusion can emerge without intent.
  • Wrong options often shift accountability to vendors or claim exemptions for AI.

Practice questions from Advances in Artificial Intelligence: Implications for Capital Markets Activities

Regulation, Governance and Ethical Considerations: frequently asked questions

What is the EU AI Act in simple terms?

It is a risk-based law that bans some AI practices, sets strict duties for high-risk uses and lighter duties for others. In finance, credit scoring of individuals is a typical high-risk use.

How should firms govern AI models?

Extend model risk management to AI. Keep an inventory, validate independently, challenge assumptions, monitor for drift, and keep human oversight. Senior management and the board remain accountable.

Can AI manipulate markets or collude without being told to?

Yes, learning algorithms can discover manipulative or collusive behavior through trial and reward. Regulators therefore expect testing, surveillance and the ability to switch systems off.

Does a firm remain responsible when it uses a vendor's AI model?

Yes. Outsourcing does not transfer accountability. The firm must do due diligence, monitor performance and plan for failure or exit.