Question 1 of 15
Q_STR_01Has the board formally chartered a cross-functional Group AI Governance Committee to oversee AI deployments?
Question 2 of 15
Q_STR_02Is there an active registry tracking all AI use cases, differentiating between internal tools and customer-facing models?
Question 3 of 15
Q_ETH_01Are customer-facing chatbots equipped with automated notifications informing users they are interacting with AI?
Question 4 of 15
Q_ETH_02Does the bank perform algorithmic bias and fairness testing on models used for credit scoring or automated fraud flagging?
Question 5 of 15
Q_DAT_01Is customer PII actively masked, anonymized, or tokenized before being processed by third-party vendor AI models?
Question 6 of 15
Q_DAT_02Are AI models and data stores partitioned locally within each country to prevent unauthorized cross-border data leakage?
Question 7 of 15
Q_RSK_01Is there a documented risk-tiering matrix that classifies AI systems from low to high/prohibited risk profiles?
Question 8 of 15
Q_RSK_02Does the AML/Fraud AI system generate localized Explainable AI feature-importance scores for regulatory audit trails?
Question 9 of 15
Q_RSK_03Is a formal Human-in-the-Loop protocol enforced before AI-flagged suspicious activities are filed as SARs?
Question 10 of 15
Q_TEC_01Are generative AI productivity tools and LLMs isolated within the bank’s secure regional cloud tenant rather than public SaaS?
Question 11 of 15
Q_TEC_02Are real-time toxicity guardrails, prompt-injection blocks, and hallucination filters active on consumer-facing chatbots?
Question 12 of 15
Q_PEO_01Have front-line compliance staff and customer service agents received training on AI risks, limitations, and escalation paths?
Question 13 of 15
Q_PRC_01Does the bank run automated quarterly model drift and calibration checks on fraud detection algorithms?
Question 14 of 15
Q_PRC_02Is there a mandatory vendor due diligence framework evaluating third-party AI supply chain and training data lineage?
Question 15 of 15
Q_MET_01