Three key takeaways
- AI adoption was widespread among the firms surveyed. Every respondent was either already using AI or planning to introduce it.
- The strongest business case is improving customer outcomes and operational efficiency. Firms are using AI for fraud detection, document analysis, customer service, risk management and decision support.
- Governance cannot be added later. Privacy, cybersecurity, staff capability, transparency and human oversight need to be addressed before higher-risk AI systems are deployed.
Artificial intelligence is already changing how New Zealand financial services firms work.
The Financial Markets Authority’s paper, Understanding Artificial Intelligence in Financial Services, provides an early view of how deposit takers, insurers, asset managers and financial advice providers are adopting AI. It shows an industry that is interested in the opportunities but cautious about introducing technology that could affect customers, confidential data or financial decisions.
The research was based on responses from 13 regulated entities. Although the sample was relatively small, the findings offer useful insight for financial services organisations considering how to adopt AI responsibly.
AI adoption is moving from experimentation to practical use
Nine of the 13 organisations surveyed were already using AI in at least one part of their operations. Most of those organisations were already seeing benefits, while the others expected benefits within the following 12 months. All respondents planned to use AI in the future.
The most common reasons for adopting AI were:
- improving customer outcomes
- increasing operational efficiency
- detecting fraud
- strengthening risk management
- improving data analysis
- accelerating decision-making
The findings suggest that financial services firms are not adopting AI simply because it is new. Most are looking for practical applications that solve identifiable business problems. Examples included using AI to analyse customer documents, identify unusual behaviour, support software development, automate standard documents, summarise customer interactions and help staff find information more quickly. Machine-learning tools were also being used for fraud detection, cybersecurity monitoring, predictive modelling, product pricing and personalisation.
Customer service is likely to be the next major area of growth
Every respondent identified customer service as an area in which they expected to use AI in the future. This could include AI-assisted customer support, faster information retrieval, document summarisation, personalised communications and tools that help staff respond to customer questions.
Three of the five larger deposit takers also indicated an interest in using AI for credit underwriting and decision-making.
These uses could improve speed and consistency, but the level of risk will depend on what the AI system is doing. An internal productivity tool that summarises meeting notes presents different risks from a system that recommends whether a customer should receive credit, insurance or financial advice. The greater the potential impact on a customer, the stronger the organisation’s testing, oversight and accountability arrangements should be.
The paper highlights the risks associated with AI-supported decision-making, including bias, discrimination and limited transparency.
Existing governance provides a foundation, but it may not be enough
More advanced respondents were beginning to adapt their existing governance structures. Some were repurposing established frameworks, while one larger firm had created an AI-specific subcommittee to assess third-party tools. That is a sensible starting point. AI does not remove existing legal or professional obligations.
However, existing policies may need to be updated to address risks that are more specific to AI, such as:
- inaccurate or fabricated outputs
- bias within training data or models
- limited ability to explain a result
- inappropriate use of confidential information
- dependence on a small number of technology providers
- rapid changes to third-party AI services
- staff placing too much trust in automated recommendations
The risks most frequently identified by respondents were staff training, cybersecurity and data privacy. Transparency, regulatory compliance, discrimination and fairness were also widely recognised. Several firms had introduced additional controls, including AI-specific governance frameworks, restricted access, data masking, performance monitoring and limited data retention. One larger organisation had established a dedicated committee to assess third-party AI tools. Others used existing governance groups across data, compliance, technology, procurement and operational risk.
Practical example: AI-assisted communications
One organisation described using generative AI to prepare initial drafts of customer communications. The AI did not make the final decision about what would be sent. Its output went through the organisation’s normal human review, risk and compliance processes.
This is a useful example of responsible implementation. The technology supports the employee, but accountability remains with the organisation and the people reviewing the output.
Human review should not, however, become a simple approval step. Reviewers need enough time, information and expertise to identify errors, misleading language, missing context or unfair outcomes.
The FMA supports innovation, but remains focused on outcomes
The FMA describes itself as technology-neutral and supportive of innovation. Its position is not that financial services firms should avoid AI. Instead, the regulator wants firms to use technology in ways that support fair, efficient and transparent financial markets and produce positive outcomes for customers.
That means an organisation should be able to explain:
- why it is using an AI system
- what customer or business problem it addresses
- what information the system uses
- what risks have been identified
- how the system has been tested
- when human review is required
- who remains accountable for the result
The FMA’s research also indicates that many AI-related risks are likely to be addressed through existing regulatory expectations. Firms should therefore avoid assuming that the absence of a dedicated New Zealand AI law means there are no requirements governing AI use.
Depending on the use case, existing obligations relating to privacy, fair dealing, conduct, information management, operational resilience, outsourcing and professional responsibility may continue to apply.
What this means for your organisation
The following are practical implications drawn from the research. They are not formal FMA guidance.
1. Identify where AI is already being used
Start with an organisation-wide inventory.
Include approved systems, free online tools, features embedded within existing software, automated decision systems and AI services supplied by third parties.
This often reveals that AI adoption is already further advanced than senior management realises.
2. Assess each use according to its potential impact
A low-risk administrative tool should not require the same level of review as an AI system that affects customer eligibility, pricing, advice or access to services.
Create a proportionate assessment process based on the sensitivity of the information, the importance of the decision and the potential harm if the system is wrong.
3. Set clear rules for data and third-party platforms
Staff should understand what information may and may not be entered into an AI system.
Before approving a third-party tool, assess its security, data location, retention settings, contractual terms, model-training practices, access controls and incident response arrangements.
4. Define meaningful human oversight
Document which outputs require review, who is qualified to review them and what evidence must be retained.
Higher-risk decisions should not become automated simply because an AI product can technically perform the task.
5. Train staff and monitor outcomes
Training should cover more than how to write prompts.
Staff need to understand confidentiality, privacy, bias, hallucinations, verification, recordkeeping and when not to rely on AI.
Organisations should also monitor how approved systems perform in practice, including whether they produce errors, inconsistent results or unintended customer impacts.
Responsible adoption creates the strongest foundation
The FMA’s research shows that New Zealand financial services firms see significant value in AI. It also shows that the industry’s more mature organisations are not treating adoption as a simple software implementation.
They are defining business problems, testing use cases, reviewing third-party providers, training staff and placing AI within established risk and accountability structures.
That cautious approach should not be viewed as a barrier to innovation. Good governance gives organisations greater confidence to expand successful uses while protecting customers, staff and the organisation itself.
Source
Financial Markets Authority, Understanding Artificial Intelligence in Financial Services, July 2024.
Qualification
The FMA paper reports the views of a small sample of regulated entities and describes research undertaken in 2024. It is an occasional research paper rather than formal regulatory guidance and should not be treated as a substitute for legislation, professional advice or current FMA requirements.

