Policies

The rules the platform runs on: the PDPA, banking secrecy, the Bank’s Model Risk Management policy, RMiT and third-party risk, each with the platform control that enforces it.

LifecycleAll nine stages

Assets classifiedin force

100%

every catalogue asset carries a classification

Models in validation cycleaction open

96%

4 Tier 2 models overdue for revalidation

Privacy assessments on filein force

12/12

all High-risk models in production covered

Audit coveragein force

24 months

immutable, queryable, scoped by business unit

Data residency by construction

Residency is not a clause in a contract here: customer data, the compute that trains on it and the inference served from it all sit in Google Cloud Malaysia, and the platform has no path that moves production data out.

The Group lakehouse, Vertex AI and Gemini on Vertex AI sit inside Google Cloud Malaysia. The Singapore build region sends code in but receives no customer data, and external AI APIs receive no customer data in prompts.GOOGLE CLOUD MALAYSIAProduction workloads and customer dataGroup lakehouseBigQuery · Dataplex lineage and qualityVertex AIPipelines · registry · endpointsGemini on Vertex AIServed in-region · grounded on Bank dataEgress-controlled · customer data stays in-regionSingapore regionbuild, test, non-sensitive pilotscode in · no customer data outExternal AI APIspublic GenAI endpointsno customer data in prompts
  • Production and customer data stay in Google Cloud Malaysia
  • Singapore is for platform build, testing and non-sensitive pilot data only
  • No customer data in prompts; Gemini is served on Vertex AI in-region
  • Every access to customer data is purpose-bound, attributable and logged

Policies in force

Each policy is a live constraint in the validation and access paths, not a document filed elsewhere.

Personal data protection

Personal Data Protection Act 2010 (PDPA), as amended 2024

Every asset carries a classification (Internal / Confidential / Strictly Confidential) assigned at registration and re-checked on each version. Access to personal data requires a stated purpose, a bounded period and an accountable business unit. Purpose limitation is enforced through entitlements: a grant covers the declared use only, and reuse for a new purpose is a new request.

  • ✓ Classification assigned at registration, reviewed quarterly
  • ✓ Purpose-bound, time-bound entitlements
  • ✓ PII scanning on every dataset load and every GenAI prompt
  • ✓ Privacy impact assessment before a High-risk model goes live

Banking secrecy

Banking secrecy under the Financial Services Act 2013

Customer information is secret by default. Strictly Confidential data, meaning anything that identifies a customer or their accounts, is visible only to named grantees for a stated purpose, with the data owner's consent recorded through the Data Governance Committee. Derived assets (models, features, embeddings) inherit the strictest classification of their training data unless a documented de-identification review lowers it.

  • ✓ Data owner consent for customer-level data
  • ✓ Classification inheritance for derived models
  • ✓ Masking by default; unmasked fields named in the grant
  • ✓ Watermarked, logged downloads

Model Risk Management policy

Alliance Bank policy · owned by Model Risk Management, Group Risk

Models are tiered by materiality (Tier 1 / 2 / 3). Model Risk Management, as the second line, validates every model independently before first use, sets the monitoring thresholds, and revalidates on a cycle set by the tier. Credit decision models are fairness-tested and carry a documented explainability method for adverse outcomes. A model is replaced only after a champion–challenger comparison. The approach draws on BNM's work on responsible AI in the financial sector and Malaysia's National Guidelines on AI Governance and Ethics.

  • ✓ Model tier set at intake from a structured questionnaire
  • ✓ Independent validation before first use; periodic revalidation
  • ✓ Fairness tests on credit decisions, re-run on every retrain
  • ✓ Explainability for adverse outcomes, to the customer and the RM

Technology risk and change

BNM Risk Management in Technology (RMiT)

A model in production is a system under Group IT's change management, not a notebook. Promotion needs a change record with test evidence and a rollback plan; a High-risk model also needs Model Risk Management approval on record. Owners carry versioning duties while the model serves traffic: a changelog per release, a retrain SLA triggered by measured drift, and a notice period before an endpoint is withdrawn.

  • ✓ Change record with rollback plan for every production promotion
  • ✓ Retrain SLA: proposal within 10 working days of PSI > 0.25, shipped within 45
  • ✓ Deprecation notice: 90 days for production endpoints, 30 for staging
  • ✓ Named fallback before any model is suspended or withdrawn

Third-party and outsourcing risk

BNM Policy Document on Outsourcing · Alliance Bank third-party risk policy

Vendor models and data providers are approved by Group Risk before they enter the catalogue. Due diligence covers where data is processed, sub-processors, model provenance and exit terms. A vendor that would touch customer data needs the data owner's sign-off and an outsourcing assessment. Vendors are paid under licence; they are monitored like any in-house model.

  • ✓ Vendor approval before first use, with a review date
  • ✓ Data-location terms: production data stays in the MY region
  • ✓ Licence scan on every vendor artefact
  • ✓ Same validation and monitoring as in-house models

Controls in force

Every policy duty maps to a mechanism and a screen. 7 of 12 run unattended, the rest hold a deliberate human checkpoint.

Triggers and rules
DutyPolicyEnforcing controlVisible in productMode
Purpose limitationPersonal data protectionGated access request with a stated purpose and bounded durationAsset card · Access monitoringhuman gate
Entitlement expiryPersonal data protectionRenewal nudge at 30 days, endpoint revocation on lapseEntitlement expiry panel · Automation ruleautomated
PII detectionPersonal data protectionPII scan on every dataset load and GenAI prompt; steward sign-off on any hitPublishing pipeline · Dataset health scoreautomated
Customer data consentBanking secrecyData owner consents to every grant on customer-level Strictly Confidential dataGovernance · Approval queuehuman gate
Classification inheritanceBanking secrecyDerived asset inherits the strictest upstream tier and gates itselfModel card lineage · Automation ruleautomated
Data residencyTechnology risk and changeEgress scanner blocks and quarantines transfers outside Google Cloud MalaysiaAccess monitoring · flagged eventsautomated
Independent validationModel Risk Management policyValidation gate: registration blocked until Model Risk signs the opinionPublishing pipeline stage 4human gate
Fairness on credit decisionsModel Risk Management policyFairness suite re-run on every retrain, results attached to the versionModel card metrics · MLOps pipelineautomated
Drift & retrain SLATechnology risk and changeWeekly PSI and CSI job opens a pre-filled retrain proposal for the ownerMLOps drift posture · Automation ruleautomated
Deprecation & fallbackTechnology risk and changeRetirement review with a named replacement and consumer noticeGovernance · Retirement tabhuman gate
Vendor approvalThird-party and outsourcing riskVendor artefacts blocked from the catalogue until Group Risk approves the vendorPublishing pipeline · Asset cardhuman gate
Accountability recordAll policiesImmutable audit entry for every access, validation and governance decisionGovernance · Audit logautomated

Enforcement is automated where it can be

Policy that depends on someone remembering to apply it is not policy. Classification inheritance, PII scanning, egress blocking, entitlement expiry, and drift-triggered retrain proposals all run unattended on the platform: 7 of 12 controls on this page fire without a human in the loop, and every firing writes to the audit trail. The rules themselves are inspectable and toggleable in the Triggers and rules.

What stays human is deliberate, not residual: consenting to use of customer-level data, signing a model's validation opinion, approving a production change, approving a vendor, and suspending a model other teams depend on. Those carry accountability that cannot be delegated to a rule, so the platform routes them to the data owner, Model Risk Management, Group IT or Group Risk by name, and Internal Audit reads the record afterwards.