The AI Learning Hub Journal

Front, Middle and Back Office

One tool, three consequences — and three different people answeringthe technology is identical; the consequence, the regulatory hook and the accountable person all differ the same summarisation assistant identical capability, identical output FRONT OFFICE the customer and the market bear it· a wrong client message is a mis-selling and conduct exposure, not a drafting error· anything shading toward a recommendation engages the advice regime that applies: MiFID II suitability in the EU; Regulation Best Interest and the fiduciary standard in the US· assisted communications are still retained, supervised business records· algorithmic trading: testing, risk limits and a halt that has actually been exercisedsurfaces outward — it leaves the firm MIDDLE OFFICE the firm bears it, quietly· risk measurement, limit monitoring, validation and surveillance· you do not lose money on the day — you stop knowing your own exposure, and find out at the worst possible moment· a surveillance tool that under-flags manufactures the appearance of a clean booksilent until the moment it is expensive BACK OFFICE the firm bears it, visibly· reconciliation breaks and settlement errors· misstated ledgers and inaccurate regulatory returns — all reportable events· under many regimes the wrong return is itself a breach, independent of the error behind ita correction then carries two problems, not one THE MEANINGFUL UNIT IS THE SPECIFIC USE IN A SPECIFIC PLACE where does the output land? which duty attaches there? whose consequence when it is wrong? MIDDLE-OFFICE FAILURES DO NOT LOSE MONEY ON THE DAY — THEY REMOVE YOUR KNOWLEDGE OF YOUR EXPOSURE first question on any proposal: whose consequence is it when this output is wrong?
The risk lives in where the output lands, not in the model — so a blanket firm-wide position on AI is useless.

Same Technology, Three Different Risk Profiles

A summarisation assistant is not one risk. Placed in front of a client it is a conduct and communications matter. Placed in risk management it affects whether exposure is measured correctly. Placed in operations it affects settlement and reporting accuracy. The technology is identical; the consequence, the regulatory hook and the person who answers for it all differ. This is why firm-wide statements about whether AI is allowed tend to be useless — the meaningful unit is the specific use in a specific place. When a proposal arrives, the first question is not what model it uses but where in the institution its output lands and who is holding the consequence when it is wrong.

  • The risk lives in where the output lands, not in the model or the capability itself
  • One technology can be a conduct issue, a risk-measurement issue or an operations issue
  • Blanket firm-wide positions on AI collapse on contact with specific use cases
  • First question on any proposal: whose consequence is it when this output is wrong?

Front Office: The Customer and the Market Bear It

Client-facing and revenue-generating uses carry the consequence outward. A drafted client message that misstates a product feature is a mis-selling exposure, not a typo. Anything shading toward a recommendation engages the advice regime that applies — MiFID II suitability in the EU; in the US, Regulation Best Interest for retail broker-dealer recommendations and the adviser fiduciary standard — and those duties are owed by a licensed person, not a tool. Communications generated or assisted by a tool are still business communications: in US securities regulation firms must retain and supervise them, and enforcement over unmonitored channels has been substantial. In trading, EU algorithmic-trading rules impose systems-and-controls duties: testing, risk limits and the ability to halt.

  • A wrong client message is a mis-selling and conduct exposure, not a drafting error
  • Recommendation duties are jurisdictional: MiFID II suitability in the EU, Regulation Best Interest and the adviser fiduciary standard in the US
  • Assisted communications remain retained, supervised business records — in US securities regulation, explicitly so
  • Algorithmic-trading controls assume a halt that works — check whether yours has ever been exercised, not just designed

Middle and Back Office: The Firm Bears It Quietly

Middle-office failures are dangerous because they are silent. If a tool assisting risk measurement, limit monitoring, validation or surveillance is wrong, the firm does not lose money immediately — it simply stops knowing its own exposure, and finds out at the worst moment. Surveillance is the sharpest case: a system that quietly under-flags creates the appearance of a clean book. Back-office failures are more visible but not less serious. Reconciliation breaks, settlement errors, misstated ledgers and inaccurate regulatory returns are all reportable events, and under many regimes submitting incorrect data to a supervisor is treated as a breach in its own right, independently of the error that caused it. In both zones the firm absorbs the consequence before anyone outside notices.

  • Middle-office errors do not lose money on the day — they remove your knowledge of your own exposure
  • A surveillance tool that under-flags manufactures the appearance of a clean book
  • Back-office errors surface as breaks, misstated ledgers and inaccurate regulatory returns
  • Under many regimes the wrong return is itself a breach, so a correction carries two problems rather than one

Prefer slides, quizzes, and saved progress? Read this lesson in the library — free, no sign-up.