Responsible AI Governance in APAC BFSI: The Control That Cannot Say No
Most AI governance in APAC financial services sits in a document. Documents describe. They do not decline. The distance between a control that is described and one that can decline is now a large unmanaged exposure on the BFSI technology balance sheet - and it is invisible to every instrument boards currently use to look at it.

Three pieces of evidence converge.
One. APRA's letter to all regulated entities of 30 April 2026 requires an "inventory of AI tooling and AI use cases", visibility over "the full AI supply chain, including material, third-party and fourth-party dependencies", and - the operative clause - "continuous validation or monitoring in place to detect issues such as model drift, bias, failure modes", monitoring that "should be continuous and proportionate to the criticality of the use case." Continuous monitoring is not a policy statement. It is a system requirement, now written down by a prudential regulator.
Two. ASIC's review of 23 Australian licensees found 57% of AI use cases were less than two years old or in development and 61% of licensees planned to increase AI use within twelve months - while only one appeared to have uplifted governance before that increase. The least mature "relied entirely on their existing frameworks."
Three. Gartner, 11 March 2026, dates the failure mode: "By 2030, 50% of AI agent deployment failures will be due to insufficient AI governance platform runtime enforcement for capabilities and multisystem interoperability." Not insufficient policy. Insufficient runtime enforcement.
The construct this article contributes is enforcement locus - the lowest layer at which a stated control can refuse an action. It is the first property in this series that answers where, and the only property of an AI control a supervisor can test without taking your word for anything.
Introduction
Every APAC BFSI board has seen the AI slide. Fairness, accountability, transparency, explainability, human oversight. It is accurate, it was reviewed by legal, and the organization believes every word of it.
Ask one question of that slide: which of these can stop a transaction?
In most institutions, none. The principles are real; the controls that would implement them live somewhere else - a platform backlog, a vendor roadmap, a model risk procedure that runs quarterly against a system that changes weekly. The slide describes intent. The runtime describes fact. Nobody is looking at the second, because there is no slide for it.
That gap is not neglect. The documents exist, the committee meets, the policy was approved. The failure is one of locus: the control was written at a layer with no power to act.
Industry Context
Three things have shifted in the last year, and together they make the documentary approach untenable.
Supervisors have started specifying systems, not sentiments. APRA's April letter is the clearest example in the region: an inventory, supply-chain visibility to the fourth party, contracts delivering "transparency, auditability and assurance", security testing across AI-generated code, and continuous monitoring proportionate to criticality. Each is a thing you build, not a thing you assert. MAS's proposed guidelines, consulted on between 13 November 2025 and 31 January 2026, take the same shape - "accurate and up-to-date AI inventories", and a risk-materiality assessment across impact, complexity and reliance.
A regulator has published an architecture. In July 2026 MAS and industry partners released a white paper on safeguards for agentic finance at runtime; the title concedes the argument. When a central bank's contribution to AI risk management is a technical control architecture rather than a set of expectations, the direction of travel is not ambiguous.
And the documentary regime got slower while deployment did not. The EU's Digital Omnibus on AI was approved by the European Parliament on 16 June 2026 by 423 votes to 57, with 174 abstentions, deferring the AI Act's high-risk obligations to 2 December 2027 for stand-alone systems and 2 August 2028 for embedded ones. Nothing in that vote deferred a single model in production. Boards pacing their control build to a compliance deadline have been handed more time to be exposed.
One counterweight belongs here rather than in a footnote: the direction is not universal. Bank Negara Malaysia's discussion paper - the most detailed treatment any APAC regulator has published on AI - contains no inventory or register requirement at all. APRA requires one, MAS proposes one, BNM does not. A group operating across all three cannot run one control posture off one regulator.
Current Challenges
The board is looking at the wrong artefact, and the numbers say so. The AICD's Director's Guide to AI Governance, published June 2026 with the Human Technology Institute, draws on a late-2025 survey of 419 directors and senior executives. 90% of organizations use or plan to use AI, up from 64% in 2022, and 32.5% already report at least one agentic use case - but only 21.8% place responsibility for AI governance at board level, against 52.9% at CEO level and 46.1% with the CTO, CIO or CDO. Ninety per cent adoption, thirty-two per cent agentic, twenty-two per cent board ownership.
Policies are written about AI without being written for it. ASIC found nearly all licensees produced policies referencing risks relevant but not specific to AI - privacy, security, data quality. Only 12 of 23 referenced fairness, discrimination or bias; only 10 documented disclosure requirements for affected consumers. A policy that inherits its risk taxonomy from the pre-AI estate cannot generate a control that recognizes an AI failure when it happens.
Third-party models are where documentary control fails hardest. ASIC found that for 13 of the 23 licensees, half or more of the models in their AI use cases were third-party developed - and for four, all of them were. One licensee could not identify the AI technique used for all its models, reporting that vendors "are hesitant to provide details beyond standard marketing literature", and produced no supplier policy or documented validation process. You cannot write a governance document that reaches inside a vendor's model. You can refuse traffic to a vendor endpoint that has not returned a monitoring result this quarter.
And agents break the assumption the documentary model rests on - that a control is checked by a person, at a moment, before something happens. Agentic systems act between the moments. Forrester reports around three-quarters of enterprise leaders adopting agentic AI and 49% of security decision-makers naming it a concern. NIST's cybersecurity center of excellence proposed in February 2026 that AI agents be given identities and authorizations under zero-trust principles, with policy-based access control and a means to "create, update and revoke agent identities across systems." Not an ethics document - an identity and access design, which is the point.
Key Trends
1. Expectations are migrating from principles to inventories, telemetry and supply-chain maps - artefacts a system produces, not artefacts a committee approves.
2. Continuous is displacing periodic. APRA's language is explicit; sample-based annual review is being written out.
3. Agent identity is becoming the control surface. An agent that can be issued credentials can be scoped, logged and revoked. One that cannot is governed by nothing.
4. The compliance calendar and the risk calendar have decoupled. The EU deferral is the clearest instance, and it will be misread as breathing room.
5. Machine-verifiable governance is forecast as mainstream. Gartner: "By 2030, 50% of organizations will use autonomous AI agents to interpret governance policies and technical standards into machine-verifiable data contracts, automating compliance and governance policy enforcement."
Strategic Analysis: enforcement locus
Enforcement locus (n.) - the lowest layer of the technology stack at which a stated control is able to refuse an action. It is a placement property. It answers a single question about any control you have written down: where does this actually bind?
It is deliberately a different kind of property from this series' earlier constructs. Contest coverage measures completeness. Disclosure floor is binary admissibility. Evidentiary distance is ordinal. Reversibility horizon is a decision property. Retained capacity is persistence. Integration tail is dispersion. Single-answer swing is sensitivity. Enforcement locus is placement.
There are four loci, and every AI control you have sits at exactly one.
Locus 0 - Document. A sentence in a policy, standard or board minute. It can be quoted. It cannot refuse anything. Cost to violate: zero, until someone audits.
Locus 1 - Process. A required human step: an approval gate, a review board, a sign-off. It refuses only when someone is present, and only at the frequency the process runs. Between meetings it is Locus 0.
Locus 2 - Platform. A control in the pipeline: a deployment check, a registry entry required before promotion, a scan that must pass. It refuses reliably, at build time. It cannot see what happens after release.
Locus 3 - Runtime. A control in the request path: an identity the model or agent must present, a scope it cannot exceed, a monitor that can quarantine, a log written whether or not anyone reads it. It refuses at the moment of action, continuously, with no human in the room.
The test is one sentence, and any executive can apply it in a board meeting: at three in the morning on a public holiday, with no human available, which of our AI controls can still say no? Every control that cannot is at Locus 0 or 1, whatever the policy says.
This is the bridge from last week. Wednesday argued that a figure without a stated population, basis and window is inadmissible. Thursday applied it to our own numbers. Friday published an instrument whose six load-bearing questions each demand a number with a denominator. A policy document has no denominators. An architecture diagram does - every arrow is a call that either happens or is refused, and the ratio between them is countable. That is why the board slide should change shape: not because architecture is more impressive, but because it is the only representation of AI governance that yields countable facts.
The counter-argument, at full strength. First: encoding governance in the runtime makes it brittle and slow - every policy change becomes a release, and the business routes around it. Second: not everything that matters can be encoded. Fairness, proportionality and consumer harm are judgements, and a system that refuses at Locus 3 has moved a judgement into an engineering artefact where nobody can see it being made.
Both are correct; neither is an argument for Locus 0. A policy nobody can enforce is not faster, merely unmeasured. And enforcement locus is a claim about where a control binds, not that everything belongs at Locus 3. Judgement belongs at Locus 1, deliberately and visibly. What this exposes is mechanical controls sitting at Locus 0 because nobody asked the question.
The same control, four times

Read the right-hand column. Locus 0 produces a sentence. Locus 3 produces denominators. That is the whole difference between the slide you have and the slide you need.
Real-World Examples
Australia - the failure that had a policy. On 11 August 2026 APRA announced that Bendigo and Adelaide Bank had admitted breaching its obligations under the Banking Executive Accountability Regime, with an $8 million penalty proposed, subject to court approval. The matter concerned a March 2023 attack affecting approximately 257 accounts and 286 unauthorized transactions totaling around $490,000. APRA's stated basis: the bank failed to run a systematic testing program for customer authentication controls as required by the prudential standard on information security. Penetration testing in 2020 had identified the weaknesses; they were not remediated before the attack. This is not an AI case and we do not present it as one. It is the cleanest demonstration of the pattern: the control existed, the deficiency was documented, accountability attached to named individuals - and none of that refused a single transaction. Substitute "model" for "authentication control" and the fact pattern transfers unaltered.
Singapore - where the platform layer pays. DBS disclosed that as at May 2025 it had deployed over 1,500 AI models across 370 use cases, and that its model repository and data platform cut time-to-market for AI initiatives from fifteen months to just under three. Note what did the work: not a policy refresh, a repository. The infrastructure that makes 1,500 models governable is the infrastructure that makes them fast - the commercial case for Locus 2 and 3, and the reason this is not a cost conversation.
Central banks - the honest baseline. The BIS Irving Fisher Committee surveyed 60 jurisdictions between September and November 2024: 32% had no AI policy and 33% were developing one - while 75% already restricted AI tool usage through access controls and filtering solutions. Three-quarters reached for a Locus 3 control before most had finished writing the Locus 0 one. The population is central banks, not regulated firms, and we do not transfer the statistic. The sequencing is the point.
Japan - governance published, arithmetic absent. Tokio Marine Holdings established a group AI governance policy in June 2025 and disclosed in June 2026 an internal "AI-HUB", set up in October 2024 to centrally oversee group AI initiatives. A serious board-level commitment publishing no model count, no inventory figure and no review cycle - the regional norm, not a criticism. Other than DBS, we located no APAC bank or insurer disclosing a countable AI governance figure at all.
Actionable Recommendations
- Score every AI control in your register against the four loci this quarter. One column added to a document you already have. The distribution is the finding.
- Apply the three-in-the-morning test to your ten highest-materiality use cases. Take the answer to the board as a count, not a narrative.
- Move the inventory from Locus 0 to Locus 2 first. Highest-value single move available, now an explicit APRA expectation, and it converts a document that decays into a gate that cannot be bypassed.
- Give agents identities before you give them scope. Credential, scope, log, revoke - in that order.
- Extend the locus test to third parties and demand a monitoring artefact, not a certificate. Where half or more of your models are vendor-built, your Locus 3 control is the contract clause making a monitoring feed a delivery obligation.
- Do not re-plan against the EU deferral. The obligations moved. Your exposure did not.
- Put one countable number on next quarter's AI board slide - inventory coverage as a percentage of known AI calls. If you cannot produce it, that is the report.
sourceCode Perspective
We build the layers this article argues for, so read the recommendations knowing that.
Three qualifications. Locus is not maturity - a firm with everything at Locus 3 and no judgement at Locus 1 has automated its blind spots, and we have seen that failure more often than the opposite. The four-locus model is our construct, not a standard: face validity from delivery work and nothing beyond it, and unlike a maturity score it claims to predict no outcome. Its merit is that it is cheap to apply and hard to answer dishonestly. And most institutions should not start at Locus 3 - the move from 0 to 2 holds nearly all the available risk reduction and fits inside one planning cycle.
What we stand behind is narrower. An institution that can state what proportion of its AI calls carry a credential bound to an inventory record, and what happens to the rest, can answer a supervisor in a sentence. One that can only produce a policy will spend that meeting describing its intentions.
Conclusion
The AI slide in the next board pack will be reviewed, approved and filed, and it will be accurate. That is the problem with it.
A policy describes what the institution intends. An architecture describes what it will permit. Only one is testable at three in the morning, and only one produces numbers a director can count. APRA has asked for continuous monitoring. MAS has published a runtime architecture. Gartner has dated the agent deployments that will fail for want of runtime enforcement. The instruments are converging on one layer, and it is not the one most board packs describe.
Ask your next AI slide the only question that separates a control from a sentence: can it say no?
FAQ
What is governance-as-code in financial services? Expressing an AI governance control as an enforceable technical artefact - a deployment gate, an agent credential, a scope limit, a continuous monitor - rather than as a statement in a policy document. The test is whether the control can refuse an action without a human present.
What is an enforcement locus? The lowest layer at which a stated control can refuse an action. There are four: Locus 0 (document), Locus 1 (process), Locus 2 (platform, refusing at build time) and Locus 3 (runtime, refusing at the moment of action). It is a placement property - it answers where a control binds, not how strong it is.
Does any APAC regulator require an AI inventory? Yes. APRA's letter to industry of 30 April 2026 requires APRA-regulated entities to maintain an inventory of AI tooling and AI use cases. MAS's proposed guidelines, consulted on from 13 November 2025 to 31 January 2026, would require accurate and up-to-date AI inventories but have not been issued. Bank Negara Malaysia's discussion paper contains no inventory requirement.
Have the MAS Guidelines on AI Risk Management been issued? No. As at 12 August 2026 they remain in proposed form. The consultation paper was issued on 13 November 2025 and closed on 31 January 2026, and a 12-month transition period after issuance is proposed. MAS has published no finalization date. Claims circulating that the guidelines are already binding rules, or that finalization is confirmed for Q4 2026, are not supported by any regulator source.
Did the EU AI Act's high-risk deadlines change? Yes. The Digital Omnibus on AI was approved by the European Parliament on 16 June 2026 by 423 votes to 57 with 174 abstentions, deferring high-risk obligations to 2 December 2027 for stand-alone systems and 2 August 2028 for systems embedded in products. The deferral affects compliance timelines, not deployed risk.
What proportion of boards own AI governance? On the Australian evidence, a minority. The AICD and Human Technology Institute survey of 419 directors and senior executives, fielded in late 2025, found AI governance responsibility placed at board level by 21.8% of respondents, against 90% of organizations using or planning to use AI.
Should every AI control move to runtime? No. Judgement-based controls - proportionality, fairness assessments, consumer-harm decisions - belong at Locus 1, deliberately and visibly. The construct exists to expose mechanical controls sitting at Locus 0 because nobody asked where they bind. For most institutions the highest-value move is from Locus 0 to Locus 2, not to Locus 3.
What is the fastest way to test our own position? Ask, of your ten highest-materiality AI use cases: at three in the morning on a public holiday, with no human available, which of these controls can still refuse an action? Report the count, not the narrative.