Technology risk, change management, access control and third-party technology risk, applied to every model release.
BNM on responsible AI Current
Accountability stays with the Bank, fairness and explainability for customer outcomes, and board oversight of AI risk.
BNM outsourcing and third-party risk Current
A vendor model or data feed is approved, contracted and monitored like any other material third party.
PDPA 2010 2010, amended 2024
Purpose limitation, notice and consent, and security of personal data, carried by the platform rather than by agreement.
FSA 2013 secrecy 2013
Customer information is disclosed only where the law permits, so access to customer-level data is a named decision.
National Guidelines on AI Governance and Ethics 2024
Fairness, reliability, safety, privacy, inclusiveness, transparency and accountability as the principles the Bank's policy points to.
Model Risk Management policy Bank policy
Tier 1/2/3 by materiality, independent validation before use, periodic revalidation, and champion–challenger for material models.
NIST AI RMF, mapped to screens that exist
GOVERNWho is accountable, and under what rulesPolicy centre, named validators and approvers
MAPWhat the system is, and what it could affectMateriality questions, model tier, model cards
MEASURETest it against those risksFairness tests, PSI and CSI, accuracy per segment
MANAGEAct on what you findGates, entitlements, retrain, suspend, retire
Across the lifecycle
Governance is not a stage in this list. It is what has to hold at every one of them.
01
Build & validate
The model developer
A team builds a model and puts it forward for use by the business.
Sensitivity questions answered, risk and model tier set
Data classification and lineage declared in Dataplex
Fairness tested, performance published per segment
Model card: intended and out-of-scope use
Independent validation by Model Risk for Tier 1 and 2
A named Model Risk validator signs the validation opinion before a Tier 1 or High-risk model is approved.
Without it: Anything can reach production, and nobody downstream can tell what it is safe to use for.
02
Discover
The consuming business unit
Another team finds it and works out whether it fits their problem before building their own.
Intended and out-of-scope use visible
Lineage back to training data
Performance per segment, not just headline
Without it: Teams adopt on a name and a headline number, or rebuild what already exists.
03
Experiment
The data scientist or analyst
They try it in the sandbox, on sample data, before committing anything.
Sandbox isolated, no egress
Synthetic or masked data only
Experiments logged against a person
Without it: Customer data gets pulled into a scratch environment and nobody can say where it went.
04
Test and evaluate
The adopting team
They evaluate it against their own customers, not the builder's.
Evaluation on the consumer's own portfolio
Fairness checked on the segments that matter for that use
Result recorded against the asset, not in a slide
Without it: A model built on the retail book is used on SME customers on the retail numbers.
05
Request access
The consuming business unit
They ask to use it for real, and say what for.
Purpose stated
End date fixed
Customer-level fields shown to the approver before signing
A named approver decides access above Internal; for customer-level data the data owner consents first.
Without it: Access becomes permanent and open-ended, and the use drifts from what was approved.
06
Deploy to production
The process owner
It is promoted to production and composed into a workflow that touches real customers.
Production change approved by Group IT, with rollback
Workflow inherits the strictest upstream classification
Human checkpoint present on any High-risk step
The platform will not activate a High-risk workflow that has no human checkpoint in it.
Without it: A model reaches customers through a change nobody reviewed as a whole.
07
Run and monitor
The MLOps team
It serves traffic, and the customers and economy it learned from keep changing.
PSI, CSI and performance measured weekly
Fairness re-run on every retrain
Early revalidation once a threshold trips
Complaint volume watched as a signal
Without it: Performance decays quietly, and the first signal anyone gets is a complaint or an audit finding.
08
Retire
The business owner
It is superseded by a challenger, suspended, or withdrawn.
Named replacement or fallback
Notice period
Every consumer told
Evidence retained after the endpoint closes
Suspending or retiring a model others depend on is a decision a person takes, not a rule.
Without it: An endpoint goes dark on the teams and processes that built on it.
How a model is tiered
Five questions at intake decide the risk tier, and the tier is what makes independent validation and human review mandatory.
The five questions, asked at submission
A model is sensitive when being wrong about it costs a customer something they cannot easily get back. The risk tier follows from the five answers, not from who is asking, and the tier is what switches human review on.
1
Does the output affect a customer's money, credit, access to a product, or treatment?
This is the whole question. Everything else adjusts the answer.
Raises the tier: Credit approval or limits, pricing, fraud blocks, account closure, collections treatment, or anything a customer can be refused by.
2
Does it use personal data, or data classified above Internal?
Customer data carries duties under the PDPA and banking secrecy regardless of what the model does with it.
Raises the tier: Named customers, MyKad numbers, account and transaction records, credit bureau data, voice recordings, or Strictly Confidential sources.
3
Can it act, or change an outcome, without a person confirming?
An automated decision has no natural point at which someone notices it was wrong.
Raises the tier: Straight-through approval, auto-decline, automatic card blocks, or an agent with write access.
4
How many customers does it touch, and how much money rides on it?
The same error rate means something different at ten cases a month and at a million, and at MYR 5,000 or MYR 5 million.
Raises the tier: Every applicant, every card transaction, a large share of the loan book, or any always-on channel.
5
If it is wrong, how easily is that found and undone?
Harm that surfaces only when a customer complains is harm the system will not correct by itself.
Raises the tier: No complaint or review route, no human review of declines, or an effect the customer cannot see.
MINIMAL
No effect on a customer's money or access, Internal data only, and a member of staff reads every output before it is used.
Model card with intended use
Classification recorded
Standard audit entries
Human in the loop: Not required. The human is already the consumer of the output.
LIMITED
It informs a decision about a customer, or uses data above Internal, but a person still decides and the effect is reversible.
Model card with intended and out-of-scope use
Fairness assessment at validation, re-run on every retrain
Performance published per customer segment
Purpose-bound, time-bound access
Human in the loop: Required at the decision, not at every inference. The person deciding sees the model's output as advice and can overrule it.
HIGH
It decides or materially shapes a customer's credit, money or access to a product, or it acts without confirmation, or it runs across a large share of customers on Strictly Confidential data.
Everything required at Limited
Independent validation by Model Risk Management before production
Privacy impact assessment before any production integration
Documented explainability method, with reason codes for adverse outcomes
A complaint and review route for any customer affected
Production change approved by Group IT, with a rollback plan
Periodic revalidation while it remains live
Human in the loop: Mandatory and enforced. The platform will not activate a High-risk model in a workflow that has no human checkpoint, and the validator and approver who sign are recorded against the decision.
Where reuse turns one flaw into many
The same twelve business units and workflows, with and without independent validation before reuse.
Hover any shape for what it means. The two rows are drawn identically on purpose: the model, the twelve teams and the reuse are the same in both. The only difference is the validation before release and the entitlement each team holds after it.
Across the Group
The same model moving outward: model, business unit, Group, regulator. Every ring keeps the obligations of the one inside it and adds one.
The full control surface
What model risk and AI governance has to cover across the Bank, with the state of each line today.
Not all of this is built. That is the point of showing it: the requirement surface is the size of the problem, and the state on each line says honestly where the platform is against it today.
18In the platform6Rule agreed, not yet enforced6Named scope30 requirements in scope
Classification and model tiering
Sensitivity questionnaire at intake
Model tier (1/2/3) drives validation depth and revalidation cycle
Data classification inherited by derived assets
Complete model inventory, including models outside the platform
Tier re-evaluated automatically when the use changes
Fairness and performance
Fairness suite at validation and on every retrain
Performance published per customer segment
Champion–challenger comparison before a new version replaces the old
Evaluation on the consumer's own portfolio before adoption
Fairness thresholds on credit decisions that block a release, not just warn
Human oversight
Named person on every reserved decision
Human checkpoint enforced on High-risk workflows
Approver sees the customer-level fields before signing
Complaint and review route for any customer affected by an automated decision
Override rate tracked per model and per agent as an oversight signal
Data protection and secrecy
PII scanning on every data load and every GenAI prompt
Purpose-bound, time-bound entitlements
Production and customer data kept in Google Cloud Malaysia
Privacy impact assessment before any High-risk production integration
Consent and PDPA purpose carried with the record
Transparency and evidence
Model card required before registration
Immutable audit entry naming actor, basis and time
Lineage from a live endpoint back to its training data
Reason codes for every adverse credit outcome
Customer-facing notice when a decision was AI-assisted
Lifecycle and third parties
Drift measured, early revalidation once it trips
Deprecation notice and named migration target
Incident path when a live model is found to be wrong
Vendor models reviewed under third-party and outsourcing risk
Coordinated recall across every business unit that reused a model