2024-08-19
Added · Updated
The Hong Kong Monetary Authority issues guiding principles requiring authorized institutions to maintain board accountability and robust governance for all Big Data Analytics and Artificial Intelligence applications. Institutions must ensure fairness by preventing discrimination and unjustified denial of services while incorporating manual intervention mechanisms to mitigate irresponsible automated decisions. Furthermore, banks are mandated to provide transparent disclosures regarding BDAI usage, establish customer review mechanisms, and implement strict data privacy protections including privacy by design and informed consent protocols.
– 5 – Annex 1 Guiding Principles in the HKMA circular “Consumer Protection in respect of Use of Big Data Analytics and Artificial Intelligence by Authorized Institutions” dated 5 November 2019
– 6 – (c) customers’ financial capabilities, situation and needs, including their level of digital literacy, are taken into account; (d) the models used for the BDAI-driven decision are robust and have appropriately weighed all relevant variables; and (e) the possibility of manual intervention to mitigate irresponsible lending decisions where necessary (e.g. in cases involving higher risks or impacts from the automated decision). 3. Transparency and disclosure Authorized institutions should provide appropriate level of transparency to customers regarding their BDAI applications through proper, accurate and understandable disclosure. Accordingly, they should, among others: (a) make clear to customers, prior to service provision, that the relevant service is powered by BDAI technology and of the associated risks; (b) provide proper disclosure to customers so that customers could understand the approach of authorized institutions to using customer data; (c) make available a mechanism for customers to enquire and request reviews on the decisions made by the BDAI applications, and ensure that any related complaint handling and redress mechanism for BDAI-based products and services are accessible and fair; (d) provide explanations on what types of data are used, and what factors or how the models affect the BDAI-driven decisions, upon customers’ request and where appropriate. For the avoidance of doubt, such explanations to customers are not required for systems used for monitoring and prevention of frauds or money laundering / terrorist financing activities; (e) carry out appropriate consumer education to enhance consumers’ understanding on BDAI technology in banking services; and (f) ensure that relevant customer communications are clear and simple to understand.
– 7 – 4. Data privacy and protection Authorized institutions should implement effective protection measures to safeguard customer data. Accordingly, they should, among others: (a) if personal data are collected and processed by BDAI applications: