CIMB actively explores and applies emerging technologies such as AI to improve operational efficiency and support data-driven decision-making. The adoption of AI is guided by the Group’s Technology Risk Management Framework and AI Governance Framework. This framework supports the safe assessment, design and deployment of AI solutions while protecting corporate and customer data. They are complemented by supporting policies, including the Emerging Technology Risk Policy, the AI Governance and Model Risk policies, as well as Data Protection and Management policies. Together, these policies provide structured oversight as we expand the use of AI across the Group, strengthening risk management while enabling responsible innovation.
Oversight of data and AI usage is provided by the Group Data and AI Governance Committee, jointly chaired by Group Data and AI and Group Risk’s senior management. The committee oversees the application of data and AI across CIMB’s products, systems and processes, ensuring responsible and consistent use aligned with the principles of fairness, explainability, transparency, reliability and accuracy. The committee meets six times a year to deliberate on and agree CIMB’s position on emerging AI issues. It complements existing risk and management committees rather than replacing them, with all AI-related proposals and issues continuing to follow existing governance and approval processes through the relevant risk and product committees.
This oversight is further supported by existing security and privacy frameworks across the Group. The AI Governance Framework draws on input from the Group’s various product, risk and technology committees, with issues addressed either through these forums or through dedicated working groups. Matters of significance are reported to the Group Executive Committee and, as appropriate, escalated to the relevant risk committees.