The AI governance strengthening guidelines recently issued by financial regulators go beyond simple technical guidance, demanding risk-based lifecycle management. Even when using AI, financial institutions are not exempt from legal liability, meaning executives must bear direct responsibility. This article outlines the core content of the guidelines and five actionable steps that can be implemented immediately in practice.
Key Points of the AI Governance Strengthening Guidelines – What Financial Institutions Need to Do Now

1. Scope of Application and Key Requirements

The guidelines apply equally to all domestic financial institutions, including banks, securities firms, insurance companies, and asset management companies. The primary requirement is to conduct risk assessments across the entire lifecycle of AI systems—from design to operation and decommissioning—and to document the results. Furthermore, it is explicitly stated that CEOs and executives must bear ultimate responsibility for AI-related decision-making. Consequently, establishing a governance framework and clearly defining scopes of responsibility are essential first steps.
2. What Is Risk-Based Lifecycle Management?

Risk-based lifecycle management involves checking data quality and potential bias before deploying an AI model and continuously monitoring for performance drift and signs of misuse after launch. For example, a loan underwriting model should track monthly changes in approval rates and delinquency rates; if abnormal trends are detected, immediate decisions regarding retraining or suspension of use must be made. Systematic management is achievable by creating a regular inspection checklist and requiring responsible departments to submit monthly inspection reports.
3. Three Practical Actions Executives Must Prioritize

First, establish a dedicated AI governance team and clarify reporting obligations. Second, conduct company-wide AI ethics training at least once a year and maintain records of completion. Third, undergo an independent review by an external expert agency once a year and report the results to the board of directors. Creating a checklist for these three items and reviewing it at the beginning of each quarter ensures full compliance with the guidelines’ requirements.
4. A Practical Calculation Example for Real-World Application
Suppose a bank uses an AI model for 10,000 loan applications per month. If the model’s error rate is 0.5%, there is a possibility of 50 errors occurring each month. If these errors cause disadvantages to customers, financial institutions may face monetary damages and legal liability. Therefore, reducing the monthly error rate to 0.1% or less by shortening the retraining cycle to two weeks and logging results in the risk management system can significantly reduce expected losses.
5. Pre-Action Checklist
– Documentation of data sources and bias review results completed before AI usage – Establishment of model performance monitoring metrics (KPIs) and automated alert functions – Existence of an organizational chart clearly defining governance responsible parties and reporting lines – Maintenance of records for internal training completion at least once a year – Existence of external review plans and recent result reports
6. The First Step You Can Take Right Now
Starting today, gather responsible personnel from relevant departments to create a list of AI systems and verify whether current risk assessment documents exist for each system. If documents are missing, start by creating a simple checklist (data sources, model purpose, performance metrics) and reporting it to team leaders. This small task serves as the first step in laying the foundation for governance.