Investreet Financial Logo 2

South Korea Watchdog Develops Framework to Test AI Risks in Finance.

South Korea Watchdog Develops Framework to Test AI Risks in Finance.

South Korea’s Financial Security Institute has completed the country’s first dedicated framework for evaluating the reliability and safety of artificial intelligence used by financial firms, the institute confirmed on Aug. 12.

The framework is designed to identify risks tied to AI deployment in financial services, including hallucinations, system malfunctions and security breaches, the institute said.

It described the move as a response to the expanding use of AI in core banking functions, which has accelerated after regulators eased network separation rules governing how financial systems connect to outside networks.

The institute said existing oversight tools were not built to address the specific risks posed by AI models, including unreliable outputs and cyber incidents linked to machine-learning systems, prompting the need for standards tailored to the financial sector.

To design the framework, the institute drew on domestic regulations including the Financial Services Commission’s AI guidelines for the financial industry, the Financial Supervisory Service’s AI risk management framework, and South Korea’s AI Basic Act.

It also referenced international benchmarks, including ISO/IEC 42001, the global standard for AI management systems, and Inspect, an evaluation tool developed by the United Kingdom’s AI Safety Institute.

The evaluation system is built around 10 criteria organized under two broad categories: reliability and safety.

Under the reliability pillar, assessors will examine model performance management, data quality, fairness and bias, and explainability.

This includes checking whether firms have set appropriate performance thresholds, whether they continuously monitor for hallucinations and performance decline, and whether the data used to train and run the models is accurate, complete and consistent, the institute said.

The reliability category also covers how firms control bias once a model is in live use, whether customers receive clear explanations of AI-driven decisions, and whether channels exist for customers to challenge those decisions or seek redress.

The safety pillar covers six areas: threats specific to AI systems, detection of and response to AI-targeted attacks, protection of AI assets, vetting of external models and data, scalability of security governance, and ongoing security verification.

In practice, this means testing whether firms can detect and block adversarial attacks through input screening, and whether they properly manage risks tied to AI models, related assets and open-source components, according to the institute.

It also includes vetting externally sourced models and data for safety, securing the AI supply chain, guarding against internal data leakage, and complying with rules on cross-border data transfers.

The Financial Security Institute plans to hold an online briefing for financial firms on Aug. 14 to introduce the framework, followed by a survey in September to gauge demand among institutions. Pilot testing will run in the second half of 2026 to refine the evaluation criteria, the institute said.

Full evaluations are set to begin in 2027, starting with the institute’s own member companies before a possible extension to the broader financial sector, according to the institute.

The Financial Security Institute is also considering whether the framework could eventually serve as a formal certification system for AI safety and reliability under the AI Basic Act, the law that provides South Korea’s overarching legal structure for AI governance.

The initiative reflects a broader push by South Korean authorities to tighten oversight of AI as banks, insurers and other financial firms increasingly deploy the technology in areas such as customer service, credit decisions and fraud detection.

Regulators globally have grown more focused on AI-related risks in finance, including the potential for models to generate false or misleading information, commonly referred to as hallucinations, and the cybersecurity risks that come with integrating AI into sensitive systems.

South Korea’s AI Basic Act, which lays out the country’s general framework for regulating artificial intelligence, has provided a legal basis for sector-specific rules such as the one now being developed for finance.

The Financial Services Commission and the Financial Supervisory Service, the two main financial regulators, have separately issued guidance on AI risk management that the institute incorporated into its new framework.

administrator

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *