Artificial Intelligence Guideline (Regulating the use of Artificial Intelligence by QCB Licensed Entities)
Regulates the use of artificial intelligence by QCB-licensed entities. Held and monitored; not yet summarised from the document itself.
- 7 Corporate Governance — The board and senior management remain accountable for AI outcomes, including decisions AI systems make on the Entity's behalf. The board approves tolerated AI exposure and assigns accountability; senior management needs technology-risk competence and must keep the board informed. AI risk sits inside enterprise risk management, and systems must produce fair, ethical, consistent outcomes with precautions against unintentional or undeclared bias. [text held as ocr]
- 10 Register — Every QCB-regulated entity must keep an updated register of all its AI system arrangements and disclose the full register to QCB annually and on request. Each entry records high-risk classification, the entity's role (user or provider), a functional category, the human-oversight protocol, and — for purchased, licensed or outsourced systems — provider, contract and substitutability details. High-risk systems need a maintained life-cycle description and dated risk assessments. [text held as ocr]
- 11 AI Approval — Official QCB approval is required before launching a new AI system as a provider, before any material modification of an existing one, and before signing any high-risk AI purchase, licensing or outsourcing agreement. QCB may route a system through a sandbox evaluation before granting approval. [text held as ocr]
- 13 Human Oversight of AI — Every AI system must run under a named human-oversight protocol. High-risk systems must be designed for effective oversight by natural persons, with a trained, authorised Supervisor able to understand the system's limits, interpret its output, decide not to use or to override it, and stop it. Fully autonomous systems need prior QCB approval, built-in guard rails the AI cannot override, and a Supervisor able to shut them down; AI-assisted decision-making requires trained operators. [text held as ocr]
- 20 Customer Information and Consent — Customers must be told when they are interacting with an AI system, in accurate, plain-language disclosure, informed of AI-driven products' risks and limitations, given usage instructions, and — on request — clear explanations of the data and factors behind AI decisions and whether a decision is reversible. Consent to AI risks should be collected before service; IP, source code and fraud-detection models are excluded from disclosure. [text held as ocr]
- 21 Customer Rights and Recourse — Customers must be able to question AI decisions and request review of decisions made with no human intervention. The entity must offer a two-choice process — supply corrected data and resubmit, or have a qualified human decision-maker review a negative AI decision — with complaints handled through standard channels. [text held as ocr]