💼 Skilly Work · Financial services · Central Bank of Ireland

The Central Bank expects AI governance you can evidence.

The AI Act and the Central Bank both demand governance, accountability and human oversight, but neither is met by proof that your people can actually use AI responsibly. Skilly Work scores how your workforce really uses AI and turns it into an audit-ready record. Prove your people, not just your technology, are AI ready.

Why this matters now

AI is a supervisory priority in Irish financial services

The Government has designated the Central Bank of Ireland as the market surveillance authority for high-risk AI use cases in the financial services within its remit. The domestic legislation implementing this, the Regulation of Artificial Intelligence Bill 2026, is progressing and is targeted for August 2026. The Central Bank’s Regulatory & Supervisory Outlook names AI as a supervisory priority and expects firms to demonstrate AI governance, accountability, human oversight and ongoing monitoring. The Digital Omnibus (Regulation (EU) 2026/1744, in force July 2026) centralised EU enforcement over general-purpose AI models and very large platforms in the AI Office, but supervision of how a regulated firm deploys AI stays with its sectoral authority, which here is the Central Bank. DORA raises the bar separately: the Digital Operational Resilience Act (Regulation (EU) 2022/2554) has been in application since January 2025, makes resilience training compulsory across EU financial entities, and the Central Bank is Ireland’s competent authority for it. The supervisory question has moved from whether training was completed to whether it worked. A completion certificate demonstrates none of that. A record of how your people actually behave does.

The mapping

What the Central Bank expects, and what Skilly Work evidences

Eleven expectations, three clusters. Each one-liner is the evidence Skilly Work gives you; open a row for the detail and the honest boundary of what stays your control.

Oversight & accountability

Who is watching, and who answers

Board and senior-management oversight of AI useDirectors run the same cycle; the board dashboard proves it.

Directors and senior managers reflect like staff, and the board dashboard shows participation and competency by level. Oversight is evidenced at the top of the house, not just asserted in a policy.

Human oversight of material AI-enabled decisionsThe habit Hold the decision is scored: who keeps what human.

The evidence pack shows where the judgement about what to keep human, above all decisions about customers, is strong or thin, by role and risk.

It evidences that people understand where oversight is needed; the oversight control itself stays yours.

Clear accountability for AI decisionsEvery reflection is timestamped to a named person.

Each person carries a standing on each habit and a full scored record, so accountability for how AI is used traces to people, not an aggregate.

Risk, data & transparency

Day-to-day control of AI use

Risk management and risk awarenessSector scenario reflections build awareness; live risks raise alerts.

Reflections come in a financial-services scenario pack: credit and claims decisions about customers, consumer-protection fairness, disclosure when AI is in the loop and customer-data ring-fencing, alongside AI bias, unverified output and over-reliance. A live risk raises an alert with a severity and an action to close, which joins the audit trail.

This is workforce risk awareness and people-side risk surfacing, not your model-risk-management framework.

Data governance in day-to-day useThe habit Ring-fence scores control of what goes into AI tools.

The risk screen also catches data exposure and shadow AI, evidencing that people understand and apply your data-handling rules.

It is not itself a data-governance framework; it evidences the behaviour your framework requires.

Resilience-trained people (DORA)DORA makes resilience training compulsory; Skilly evidences it worked.

The Digital Operational Resilience Act (Regulation (EU) 2022/2554, in application since January 2025) makes ICT security awareness and digital operational resilience training compulsory for all employees and senior management (Article 13(6)), and requires the management body to keep the knowledge and skills to understand ICT risk (Article 5(4)). Where those duties meet day-to-day AI use, the record shows the behaviours the training exists to produce: checking where a tool sends data, catching shadow AI, and questioning the assumption that a vendor has already verified an output.

Skilly Work is not the resilience training programme or an ICT control; it evidences that the understanding the training assumes was assessed rather than assumed.

Transparency about AI decision-makingThe habit Acknowledge scores openness about AI use.

Scored against your own disclosure norms, in line with Article 50 of the EU AI Act, live from August 2026.

Controls over third-party AI providersCovers external tools and shadow AI, against your own policy.

Skilly reads your AI policy, so feedback references your approved tools and vendors, not generic ones.

It evidences responsible staff use of third-party tools; it does not perform vendor due diligence.

Ongoing evidence

Tracked over time, export-ready

Monitoring and validation across the AI lifecycleQuarterly cycles track capability over time, not once.

Trends by team and role show whether capability is actually improving, cycle over cycle. Capability is tracked, not certified once.

A responsible-AI culture, and continuous improvementA recurring practice keeps responsible use visible; honesty stays safe.

Owning a near miss you caught yourself is scored as awareness, not marked down, so people reflect candidly, cycle after cycle.

Evidence for internal audit and supervisory reviewEverything exports as an audit-ready pack, after human review.

Standing on each habit, the scored reflection record with any manager overrides, and the risk log with actions taken, per person and per cohort.

Where Skilly Work fits

The evidence layer for people, not a substitute for your controls

Skilly Work evidences the people dimension of AI governance. It does not provide your model-risk controls, technical documentation, cybersecurity controls or the governance framework itself. Those remain your firm’s own controls, and the Central Bank supervises them directly. What Skilly Work closes is the gap those controls cannot: proving that your people understand and apply them. Governance and technology make AI safe to deploy. Skilly Work evidences that your workforce uses it well.

For internal audit and supervisory review

What you can put on the table

When a supervisor or internal auditor asks how your people use AI, Skilly Work lets you answer with a record rather than an assertion.

Participation across the workforce, and separately for board and senior management.

Competency standing on each SHARP habit, broken down by business unit and role.

Where applied judgement is thin, framed as a development plan, not just a score.

The AI-risk log: alerts raised, their severity, and the action taken to close each one.

Trends across cycles, showing whether capability is improving over time.

The commitment record: each person's committed next step, and whether it stuck, cycle over cycle.

Per-person evidence packs, produced after human review, for named-individual accountability.

Evidence that staff reflected against your own AI policy, not a generic course.

Reflection prompts in financial-services vocabulary (credit and claims decisions, consumer-protection fairness, customer-data ring-fencing), with every prompt instructing the writer not to identify any customer or account.

Questions personalised to your organisation and each team's function: a wealth desk, a credit team and customer service each see their own scenario for the same habit, tuned to role seniority, with every variant approved by your compliance manager before an employee sees it.

Not CBI-regulated? Choose your supervisory context

This page maps the record to the Central Bank of Ireland, but the governing body is a setting, not a rebuild. Pick yours and every evidence pack adapts its framing:

FCA (United Kingdom)

The FCA has no standalone AI rulebook; it supervises AI through existing frameworks. Packs frame the record for SM&CR accountability, the Consumer Duty and SYSC: per-person evidence of how staff actually use AI, for the named senior managers who own the outcomes. The FCA’s Conduct Rules training expectations point the same way: role-relevant, practical understanding rather than a one-off module, with the rules extending to serious non-financial misconduct from September 2026 (PS25/23).

CBUAE (United Arab Emirates)

The Central Bank of the UAE’s guidance on responsible AI adoption (February 2026) sets five principles for licensed financial institutions, including effective human oversight and governance and accountability. Packs frame the record for those principles, evidencing the people dimension.

QCB (Qatar)

The Qatar Central Bank’s Artificial Intelligence Guideline (September 2024) makes the board and senior management accountable for AI outcomes, requires an AI register disclosed to the QCB annually and mandates a human oversight protocol for any AI system. Packs frame the record for those duties, evidencing the people dimension.

Statutory references adapt with the context: EU AI Act articles apply for Ireland/EU; the FCA, CBUAE and QCB contexts use those regulators’ own frameworks. Skilly Work evidences the people dimension of AI governance; it does not itself deliver regulatory compliance.

A worked example

A fund administrator rolls out Microsoft Copilot

A CBI-regulated fund administrator gives its operations team a generative-AI assistant. In a supervisory review, the questions come quickly.

  • How are staff trained to use it, and did the training change behaviour?
  • How do they recognise an unreliable or hallucinated output?
  • Who decides what the tool is trusted with, and what stays human?
  • How is human oversight of material decisions evidenced?
  • Can you show competence across your team, not just a course completion?

Skilly Work does not answer these on its own; your technical controls and governance framework do. What it adds is the workforce evidence: a scored, timestamped record that your operations team can spot unreliable output, know what to keep human, ring-fence what goes into the tool and disclose AI use, refreshed each quarter and exportable for the review.

Where capability plans fail

Built for the two weak points: the pipeline and the managers

🎓 The entry-level pipeline has changed

A new analyst is now asked to interpret a credit assessment or a claims triage an AI tool largely produced, without the years of gradual exposure that used to build that judgement. Skilly Work makes the ramp visible: scenario questions are tuned to role seniority, the same habits are scored from a person’s first cycle, and trends by role and team show whether judgement is growing as fast as the responsibility being handed over.

⏱️ Managers with no spare hours

The people expected to embed judgement on the ground have the least capacity to run another programme. Skilly Work does not ask them to. Each manager gets one quarterly digest, sent only when something is actionable, listing team completion and the reflections awaiting their note or override. Follow-up is automatic: from the second cycle of a habit, each person’s prompt opens by asking whether their last committed next step stuck.

Start with one team, one quarter

A structured pilot in one team hands you a real evidence pack you can show your board, risk function or the Central Bank. Try the interactive demo now with no sign-up, or request early access to stand up a first cycle.

Skilly Work is a workforce-evidence product, not legal or regulatory advice. A firm evaluating it will form its own view of how it fits its obligations under the EU AI Act and Central Bank of Ireland supervisory expectations. Skilly Work is in early-access preview.