AI Governance for Financial Institutions (AICB Framework)
Malaysian banks already use AI for credit scoring, fraud detection, chatbots, collections and marketing, and the governance around it is catching up. The Chief Risk Officers' Forum under the Asian Institute of Chartered Bankers has produced an industry AI Governance Framework built on seven guiding principles: fairness, ethical use, accountability, transparency, explainability, reliability and security. It covers the scope of AI to govern, board and senior management accountability, independent validation, AI inventories, lifecycle controls and data protection. The framework is explicit that it is guidance and that adoption is at each bank's discretion. The legally binding requirements come from elsewhere, including the PDPA and JPDP's April 2026 guideline on automated decision-making and profiling, and BNM's policy documents on technology risk, outsourcing and fair treatment.
This two-day course is for CROs, model risk and technology risk teams, compliance, data science leads and the directors who oversee them. It uses the AICB framework as the organising structure and maps each principle to the binding requirements that sit around it, so institutions can build one AI governance programme rather than several. Day two is practical: an AI inventory, a risk tiering exercise and a validation plan for real banking use cases. For the PDPA angle in more depth, see Automated Decision-Making and Profiling.
HRD Corp SBL-Khas Claimable
Programme Agenda
Day 1, 9:00 AM - 9:15 AM
Welcome and Programme Overview
Introduction to the session, objectives, and housekeeping.
Day 1, 9:15 AM - 10:15 AM
The AI Governance Landscape for Financial Institutions
The AICB CRO Forum framework and its non-binding status, the JPDP ADMP guideline, and the BNM policy documents that already reach AI through technology risk, outsourcing and fair treatment of consumers.
Day 1, 10:15 AM - 10:30 AM
Break
Day 1, 10:30 AM - 11:30 AM
What Counts as AI and What to Govern
The framework's definition elements, the focus on predictive and probabilistic models rather than simple rule-based systems, and building an inventory of AI use across the institution, including vendor tools.
Day 1, 11:30 AM - 12:30 PM
Fairness and Ethical Use
Avoiding harmful bias and unjustified differential treatment, the use of personal attributes as inputs, fairness metrics in testing and validation, and alignment with fair treatment of financial consumers.
Day 1, 12:30 PM - 1:30 PM
Lunch
Day 1, 1:30 PM - 3:15 PM
Accountability and Governance Structures
Board and senior management accountability, approval of AI use by a competent internal authority, using existing committees or a dedicated one, and accountability for externally sourced AI under outsourcing and third-party rules.
Day 1, 3:15 PM - 3:30 PM
Break
Day 1, 3:30 PM - 4:45 PM
Transparency and Explainability
Disclosure to affected customers proportionate to materiality, explaining decisions without exposing proprietary or security-critical information, documentation and traceability of datasets and decisions, and what to do when explainability is limited.
Day 1, 4:45 PM - 5:00 PM
Day 1 Close
Recap and what to review before day two.
Day 2, 9:00 AM - 9:15 AM
Day 1 Review
Recap of day one and the questions it left open.
Day 2, 9:15 AM - 10:15 AM
Reliability and Security
Testing, validation, stress testing and reassessment of models, monitoring drift, incident and change management, and security and privacy controls across the AI lifecycle, including open-source components.
Day 2, 10:15 AM - 10:30 AM
Break
Day 2, 10:30 AM - 12:30 PM
Risk Tiering and Independent Validation
Tiering AI applications by materiality, matching controls and validation depth to each tier, and designing independent validation that genuinely challenges the model.
Day 2, 12:30 PM - 1:30 PM
Lunch
Day 2, 1:30 PM - 3:15 PM
Generative AI and Third-Party Models
Governing large language models, chatbots and copilots, due diligence on foundation-model providers, data leakage risk, and contractual protections.
Day 2, 3:15 PM - 3:30 PM
Break
Day 2, 3:30 PM - 4:45 PM
Workshop: Inventory, Tiering and Validation Plan
Teams build an AI inventory for a case bank, tier four use cases including credit scoring and a customer chatbot, and design the validation and board reporting for the highest-risk one.
Day 2, 4:45 PM - 5:00 PM
Wrap-Up and Q&A
Key takeaways, next steps, and close.
Key Outcomes
- Explain the AICB framework's seven principles and its non-binding status
- Map each principle to the binding PDPA and BNM requirements around it
- Build and maintain an AI inventory across internal and vendor tools
- Tier AI applications by materiality and scale controls accordingly
- Design independent validation and ongoing monitoring for AI models
- Report on AI risk to senior management and the board
Training Mode Physical / Online / Hybrid / e-learning
HRD Corp SBL-Khas Claimable
Level Intermediate. For CROs, model and technology risk, compliance, data science and analytics leads, and directors in banks, insurers and other financial institutions.
Duration 2 Days (16 Hours) | 9:00 AM to 5:00 PM daily
Venue In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)
Assessment An AI inventory, tiering and validation plan for a case bank, plus a written knowledge check
Certificate Certificate of Completion issued to all participants upon full attendance