2024-08-19

Added · Updated

Consumer Protection in respect of Use of Generative Artificial Intelligence

The Hong Kong Monetary Authority issues guiding principles requiring authorized institutions to maintain board accountability and robust governance for all Big Data Analytics and Artificial Intelligence applications. Institutions must ensure fairness by preventing discrimination and unjustified denial of services while incorporating manual intervention mechanisms to mitigate irresponsible automated decisions. Furthermore, banks are mandated to provide transparent disclosures regarding BDAI usage, establish customer review mechanisms, and implement strict data privacy protections including privacy by design and informed consent protocols.

Hong Kong Monetary Authority logo

Hong Kong

Hong Kong Monetary Authority

Click to view thumbnail

– 5 – Annex 1 Guiding Principles in the HKMA circular “Consumer Protection in respect of Use of Big Data Analytics and Artificial Intelligence by Authorized Institutions” dated 5 November 2019

  1. Governance and accountability The board and senior management of authorized institutions should remain accountable for all the BDAI-driven decisions and processes. Accordingly, they should ensure, among others: (a) appropriate governance, oversight and accountability framework which is established and documented; (b) appropriate level of explainability of the BDAI models including any algorithms (i.e. no black-box excuse), and that the models can be understood by the authorized institutions; (c) adherence to the consumer protection principles set out in the Code of Banking Practice, Treat Customers Fairly Charter and other applicable regulatory requirements, as in the case of providing conventional banking products and services. BDAI applications should also be consistent with the corporate values and ethical standards of authorized institutions which should include, among others, upholding customer-centric culture and principles; and (d) proper validation before launch of BDAI applications, and thereafter on￾going reviews, to ensure the reliability, fairness, accuracy and relevance of the models, data used and the results.
  2. Fairness Authorized institutions should ensure that BDAI models produce objective, consistent, ethical and fair outcomes to customers, which include ensuring, among others: (a) compliance with the applicable laws, including those relevant to discrimination; (b) customer access to basic banking services are not denied unjustifiably which will be against the spirit of financial inclusion;

– 6 – (c) customers’ financial capabilities, situation and needs, including their level of digital literacy, are taken into account; (d) the models used for the BDAI-driven decision are robust and have appropriately weighed all relevant variables; and (e) the possibility of manual intervention to mitigate irresponsible lending decisions where necessary (e.g. in cases involving higher risks or impacts from the automated decision). 3. Transparency and disclosure Authorized institutions should provide appropriate level of transparency to customers regarding their BDAI applications through proper, accurate and understandable disclosure. Accordingly, they should, among others: (a) make clear to customers, prior to service provision, that the relevant service is powered by BDAI technology and of the associated risks; (b) provide proper disclosure to customers so that customers could understand the approach of authorized institutions to using customer data; (c) make available a mechanism for customers to enquire and request reviews on the decisions made by the BDAI applications, and ensure that any related complaint handling and redress mechanism for BDAI-based products and services are accessible and fair; (d) provide explanations on what types of data are used, and what factors or how the models affect the BDAI-driven decisions, upon customers’ request and where appropriate. For the avoidance of doubt, such explanations to customers are not required for systems used for monitoring and prevention of frauds or money laundering / terrorist financing activities; (e) carry out appropriate consumer education to enhance consumers’ understanding on BDAI technology in banking services; and (f) ensure that relevant customer communications are clear and simple to understand.

– 7 – 4. Data privacy and protection Authorized institutions should implement effective protection measures to safeguard customer data. Accordingly, they should, among others: (a) if personal data are collected and processed by BDAI applications:

  • ensure compliance with the Personal Data (Privacy) Ordinance (“PDPO”) including the 6 Data Protection Principles, any relevant codes of practice issued or approved by the Privacy Commissioner for Personal Data (“PCPD”) giving practical guidance on compliance with the PDPO, and any other applicable local and overseas statutory or regulatory requirements;
  • pay regard to the relevant good practices issued by the PCPD related to BDAI and Fintech, including, among others, the “Ethical Accountability Framework” (the “Framework”), the “Data Stewardship Accountability, Data Impact Assessments and Oversight Models” in support of the Framework, and the “Information Leaflet on Fintech”; (b) consider embedding data protection in the design of a product or system from the outset (i.e. “privacy by design”) and collecting and storing only the minimum amount of data for the minimum amount of time (i.e. “data minimisation”); and (c) where request for consent to the collection and use of personal data in relation to a banking product or service powered by BDAI technology is required, ensure that such consent is as clear and understandable as possible in the interests of ensuring informed consent.

More like this from HKMA

HKMA published 11 documents in the last 30 days. We email you each new one the day it's published.

Share