Skip to main content

CS-Product Module: AI

Claire Hartley - APAC Compliance Challenge

APAC’s New Compliance Challenge

APAC’s New Compliance Challenge:
Managing Innovation Across a Fragmented Regulatory Region

Asia-Pacific is entering a more demanding phase of compliance, regulatory and data protection oversight.

The challenge is no longer simply keeping pace with new legislation. Organisations must now manage an increasingly complex combination of national privacy laws, data localisation requirements, international transfer restrictions, artificial intelligence governance and sector-specific regulation.

Unlike the European Union, APAC does not operate under one harmonised regulatory framework. Each jurisdiction has its own legal requirements, regulatory priorities and enforcement approach. A control that is appropriate in Singapore may not be sufficient in Australia, China, India, Indonesia or New Zealand.

This fragmentation creates a significant challenge for organisations operating across multiple APAC markets.

AI and Automated Decision-Making

Artificial intelligence is becoming inseparable from data protection and regulatory compliance.

In July 2026, Singapore’s Personal Data Protection Commission published guidance addressing how personal data should be collected and used throughout the generative AI lifecycle. This includes web scraping, reusing existing customer data, allocating responsibilities between AI providers and users, managing retention and responding to individual rights requests.

Australia is also introducing new transparency requirements for automated decision-making. From 10 December 2026, regulated organisations will need to disclose certain uses of personal information in computer-generated decisions that could significantly affect an individual’s rights or interests.

For financial services organisations, these developments create particular challenges. AI and automated models may influence credit, fraud, identity, affordability and customer-management decisions. Organisations must therefore be able to explain not only what a model does, but also how data is selected, how risk is assessed and where human oversight is applied.

Biometrics and Identity Data

Biometric information is also receiving greater regulatory attention.

New Zealand’s Biometric Processing Privacy Code introduces specific rules governing the collection and use of facial, fingerprint, voice, behavioural and other biometric information. Organisations already using biometric processing must transition to the new requirements by 3 August 2026.

This reflects a wider regional trend. Identity verification and fraud-prevention technology can deliver substantial benefits, but regulators increasingly expect organisations to demonstrate necessity, proportionality, transparency, security and appropriate retention.

Data Transfers and Local Requirements

Cross-border data transfers remain another major area of complexity.

APAC organisations frequently rely on global cloud infrastructure, regional service providers and international data sources. However, the legal mechanisms for transferring personal data differ significantly between jurisdictions.

Some countries require contractual safeguards. Others may require regulatory assessments, certifications, local storage or additional controls for particular categories of information. Organisations therefore cannot rely on one global transfer mechanism without first assessing the law, data and processing activity in each relevant market.

The practical challenge is knowing where information is located, how it moves, which providers can access it and which organisation is accountable at every stage.

How Provenir Meets These Demands

Provenir addresses these challenges through a global Compliance, Regulatory and Data Protection, or CRDP, framework that combines central governance with jurisdiction-specific regulatory analysis.

CRDP provides independent oversight and challenge across Provenir’s platform and works alongside Information Security, Product, Engineering, Technology and Legal. This enables regulatory requirements to be considered throughout product development, contracting, implementation and ongoing customer support rather than only at the final compliance review stage.

Provenir’s approach includes:

  • – privacy and data protection assessments for new technologies, products and processing activities;
  • – governance of international transfers, subprocessors and regional data flows;
  • – due diligence and risk assessment for vendors and data providers;
  • – defined incident identification, escalation, investigation and notification processes;
  • – data-minimisation, retention and access-control requirements;
  • – regulatory monitoring across the countries in which Provenir and its customers operate;
  • – documented accountability for AI, model governance and automated decision-making.

Provenir also uses a structured lines-of-defence model. Operational teams own and manage their controls, CRDP provides policy, advice, monitoring and challenge, and independent certification and assurance activity provides further scrutiny.

Privacy governance is embedded within how Provenir designs, deploys and operates its platform. This includes clear controller and processor role allocation, data-processing agreements, privacy impact assessments, international transfer safeguards, subprocessor oversight and breach-management procedures.

AI governance is similarly integrated across CRDP, Product, Engineering and Information Security. Provenir’s framework addresses purpose, accountability, data governance, fairness, transparency, human oversight, security and continuing monitoring, with reference to ISO/IEC 42001 and emerging regulatory requirements.

The platform itself supports this governance approach by bringing data, models and decisioning into a controlled environment. This gives customers greater visibility over decision strategies, testing, deployment and performance, while allowing them to apply their own regulatory policies and risk controls.

From Compliance Obligation to Market Confidence

The most successful organisations in APAC will not be those that attempt to apply one policy everywhere.

They will be those that establish consistent global governance while retaining the flexibility to respond to local laws, regulatory expectations and customer requirements.

For Provenir, strong CRDP governance is not separate from innovation or commercial growth. It provides the structure required to deploy data and AI responsibly, support customers across different regulatory environments and enter new markets with greater confidence.

In a region defined by rapid technological development and regulatory diversity, this ability to combine innovation with demonstrable control is becoming a significant competitive advantage.

Claire Hartley, Chief Compliance Officer Group DPO, Provenir

Claire Hartley

Written By

Chief Compliance Officer Group DPO, Provenir

Latest Resources

FAQ

Decision Management ...

Decision Management Implementation FAQs for Enterprise Banks Implementing a
260817 - BLOG Closing Fraud Gap - FeatureIMG - EN 61409

Beyond Detection: Cl...

Beyond Detection:Closing the Fraud Prevention Gap Financial services providers
260726 - BLOG eyeDP - FeatureIMG - 61058

Beyond Data: Why Dec...

Beyond Data:Why Decisioning Needs Document Intelligence Financial services providers
Fraud in Telco: Provenir Experts Answer Frequently Asked Questions

Fraud in Telco: Prov...

Fraud in Telco:Provenir Experts Answer Frequently Asked Questions 1.
260722 - ARTICLE Mike - FeatureIMG - 60958

AI governance in fin...

AI governance in financial services:What "governed" means in practice
Latam Compliance Challenge for Decisioning

LATAM Next Complianc...

From Data Protection to Decisioning Accountability:What LATAM Regulation Means
Banks Architecture Gap - Provenir

The Architecture Gap...

Decisioning ArchitectureThe Architecture Gap: Banking's Next Competitive Battleground Banks
BLOG Andy

The Real Cost of Ven...

The Real Cost of Vendor Dependency in Credit Decisioning

Continue reading

260722 - ARTICLE Mike - FeatureIMG - 60958

AI governance in financial services

AI governance in financial services:
What “governed” means in practice

Artificial intelligence has reached the point where its presence is assumed. Every software platform is adding AI capabilities, established technology providers are layering intelligence onto products that have existed for decades, and entirely new companies are emerging with AI at their core. For financial institutions, however, this technological acceleration creates a different conversation. The question is no longer whether AI can be adopted; it is whether it can be adopted without losing control of the decisions that matter most.

Banking has always been built on trust. Every lending decision, fraud investigation, affordability assessment or customer interaction carries consequences that extend far beyond technology. They affect customers’ financial lives, an institution’s reputation, and confidence in the financial system itself. AI undoubtedly has the potential to improve these outcomes, but the same capability that creates value can just as easily amplify poor decisions if it is introduced without the discipline to govern it properly.

What Lies Beneath the Surface

At Provenir, we often think of AI adoption as an iceberg. Above the surface sit the capabilities that attract the headlines: automation, personalisation, natural language interfaces and dramatically faster decision-making. Beneath the surface lies the work that determines whether those capabilities create sustainable value or introduce new operational risks: bias that only emerges at scale, model drift, over-reliance on AI recommendations, and systems that perform well in pilots but struggle under the complexity of production. These are rarely failures of AI itself; they are failures of governance.

For Tier 1 financial institutions, this matters because they are not trying to become AI companies. They have spent decades building resilient decisioning infrastructure capable of supporting millions of customers under demanding regulatory standards. Their challenge is to strengthen that foundation with AI, not replace it. The objective is to improve customer outcomes without compromising the control, resilience and accountability that already exist.

Regulation as an Enabler

Regulation, including the EU AI Act, can be an enabler rather than a barrier. Good regulation defines the conditions under which innovation can scale responsibly. By requiring traceability, human oversight, documentation and accountability, it gives organisations a framework for deploying AI safely in the processes that matter most.

Ultimately, the conversation should never begin with the technology. It should begin with the outcome. Customers never experience a large language model. They experience whether a loan was approved fairly, whether fraud was detected quickly, whether a complaint was handled appropriately, or whether they were treated with empathy during financial difficulty. The technology only has value if those customer outcomes improve.

What “Governed AI” Really Means

Governance is not simply connecting an LLM into a workflow. It encompasses everything that surrounds it: how the solution was designed, how it was tested, how fairness was assessed, how performance is monitored, how drift is detected, whether every decision can be traced, explained and audited, and how long the supporting evidence is retained. These are the questions that compliance officers, auditors and regulators increasingly need institutions to answer with confidence.

Perhaps the most important principle is that accountability never transfers to the technology. AI may generate recommendations and automate increasingly sophisticated tasks, but it is never accountable for the outcomes it produces. That responsibility always remains with people. As AI becomes more capable, human accountability becomes more important, not less.

Balancing Value and Risk

Every AI decision is ultimately a balance between value and risk. Governance is what allows organisations to shift that balance, reducing risk while increasing the value that AI can safely deliver. It provides the confidence to introduce AI where it creates meaningful improvements while recognising that, in some situations, a more traditional approach may still be the better choice.

This is why it’s important to think of governance as a conscious series of design choices rather than a checklist of controls. There are situations where a human should remain directly involved in every decision, such as managing vulnerable customers, because judgement and accountability extend beyond what AI should provide independently. There are others, such as transaction monitoring, where automation can safely operate at scale, provided robust monitoring, alerting and escalation mechanisms remain in place.

The objective should never be to maximise automation for its own sake. It should be to maximise customer outcomes while managing risk appropriately. In some situations, AI should support a person in making the final decision, keeping a human firmly in the loop. In others, it can safely automate routine decisions, provided robust monitoring and governance remain in place. And there will always be situations where AI is not the right technology at all. The decision should always reflect the balance between value, risk and the controls available to manage that risk.

The Next Stage of AI Literacy

In many respects, this is simply the next stage of a journey that financial services has travelled before. Banks first developed risk literacy, then data literacy, and now AI literacy. The institutions that succeed will not necessarily be those deploying the most AI, but those that understand where it creates genuine value, where traditional approaches remain more appropriate, and how to combine both within a governance framework that customers, regulators and boards can trust.

Mike Holmes

Mike Holmes

Written By

Head of Data Science, Provenir

Latest Blogs

FAQ

Decision Management ...

Decision Management Implementation FAQs for Enterprise Banks Implementing a
260817 - BLOG Closing Fraud Gap - FeatureIMG - EN 61409

Beyond Detection: Cl...

Beyond Detection:Closing the Fraud Prevention Gap Financial services providers
260726 - BLOG eyeDP - FeatureIMG - 61058

Beyond Data: Why Dec...

Beyond Data:Why Decisioning Needs Document Intelligence Financial services providers
Fraud in Telco: Provenir Experts Answer Frequently Asked Questions

Fraud in Telco: Prov...

Fraud in Telco:Provenir Experts Answer Frequently Asked Questions 1.
260722 - ARTICLE Mike - FeatureIMG - 60958

AI governance in fin...

AI governance in financial services:What "governed" means in practice
Latam Compliance Challenge for Decisioning

LATAM Next Complianc...

From Data Protection to Decisioning Accountability:What LATAM Regulation Means
Banks Architecture Gap - Provenir

The Architecture Gap...

Decisioning ArchitectureThe Architecture Gap: Banking's Next Competitive Battleground Banks
BLOG Andy

The Real Cost of Ven...

The Real Cost of Vendor Dependency in Credit Decisioning

Continue reading

Dotz

Customer Story: Dotz

Dotz was founded in 2000 with the goal of connecting consumers and retailers through a points-based loyalty program. Over the years, the company expanded its customer base and diversified its services, becoming a digital platform that delivers benefits directly to users.

In April 2022, Dotz announced the acquisition of 49% of the credit fintech Noverde, which specializes in credit solutions for individuals through B2B2C partnerships. This acquisition strengthened Dotz’s financial services strategy and expanded its product portfolio, including personal credit, cards and BNPL solutions.

  • Industry
  • Region
  • Countries

    São Paulo​ Brazil​

  • Line of Business
  • Solution
  • Module
  • Infrastructure
  • ROI
  • Competition

Customer Timeline
Land MRR: $16,289
Land PS: $137,905
Expand MRR: ~$21K
Expand PS: $70K
  • Opportunity Created
    July 6, 2024
  • Opportunity Won
    April 30, 2025
  • Go-Live
    Last week of October Technical Go-Live

    1st week of November Full Go-Live

  • Customer Expansion
    • In Progress: DS – Ongoing discussions (risk model, fraud and offer hyper-personalization)
    • Future: Case management for suspected and investigated fraud
    • Future: Credit recovery initiatives (collection)
Initial Opportunity Details

  • Customer Challenge

    The company currently operates with a legacy solution that requires significant effort from the technology team while providing minimal autonomy to business areas. This setup limits agility, hinders the achievement of strategic goals and reduces alignment with corporate directives.

    There is a need to enhance customer portfolio management by channeling clients into the Financial Services funnel to drive profitability. In addition, the company plans to expand its portfolio with the launch of new products, such as Personal Loan, BNPL (Buy Now, Pay Later) and a proprietary Credit Card, strengthening its growth strategy and revenue diversification.

  • Provenir Impact

    • Accelerating Customer Base Monetization Provenir enables the integration and orchestration of data from multiple sources, allowing greater personalization of financial product offers to Dotz customers. With faster and more accurate decision-making, Dotz can expand cross-sell and up-sell opportunities, increasing conversion into higher-margin products such as BNPL and proprietary credit cards. The platform becomes a cornerstone of Dotz’s strategy to transform into a Financial Services Hub, positioning the company as a leader in customer loyalty with strong monetization through financial services.
    • Risk Reduction and Improved Credit Quality The use of AI and machine learning enables more precise credit decisions, with greater ability to assess risk profiles in real time. This translates into lower delinquency rates, improved operational efficiency, and greater predictability of results. Dotz will strengthens its credibility with financial partners and investors, consolidating its position as a reliable and sustainable platform in the medium and long term.
    • Agility and Innovation in Product Launches Provenir’s low-code solution enables agile workflow development, providing autonomy for rapid adjustments without heavy reliance on IT. Dotz gains speed in testing, adapting, and launching new financial products, staying aligned with market trends and consumer needs. This positions Dotz as an innovative and competitive player, capable of scaling new business models and creating differentiation against traditional banks and emerging fintechs.
  • Competitors

    Oscilar
  • Why We Won

    • Strength and Strategic Alignment
      Provenir has distinguished itself through its robustness as a company, with extensive international experience and a comprehensive solution that is fully aligned with the client’s current needs and prepared to sustain long-term growth.
    • Robust Solution with AI
      Provenir’s decisioning platform is fully scalable, enabling the agile development of workflows, integrated orchestration with internal systems, databases, alternative data sources, and bureaus—ensuring greater efficiency, operational flexibility and agility in addressing new demands.
  • Pain Points

    • Pricing
    • Fast implementation
    • Flexibility in building strategies
    • Easy integration with other systems and databases
    • AI functionality
Customer Growth

Growth Opportunities

Case Management for Suspected Fraud

We are organizing a meeting with Dotz’s new Head of Fraud Prevention to explore the adoption of Provenir’s Case Management solution to support the investigation of suspected fraud cases. With this initiative, Dotz will benefit from faster and more automated processes, greater accuracy in risk identification, a significant reduction in financial losses and strengthened governance and customer trust, creating a stronger foundation for sustainable business growth.

Credit Recovery Initiatives (Collection)

Our expansion project includes the development of new debt collection use cases supported by Provenir’s decisioning platform. This initiative will enable greater automation and intelligence in credit recovery processes, with personalized strategies, dynamic customer prioritization, increased recovery rates, reduced operational costs and stronger customer relationships.

Expansion

Data Science Initiative

We are in discussions with Dotz regarding the development of customized models for credit, fraud and offer personalization. The Provenir Data Science team conducted preliminary studies using historical customer data to challenge the current model. The results were satisfactory and very promising.

This initiative aims to improve decision intelligence, automate insight extraction and drive smarter, data-driven strategies.

Example Decisioning Flows
  • Application

    Step 1

    • Portal/App
    • Core Systems and Data
    • Application Submission/Amendment
  • Eligibility

    Step 2

    • Blacklist Data
    • Fraud & ID Data
  • Credit Checks

    Step 3

    • History Data
    • Bureau Data
    • Alternative Data
  • Analytics

    Step 4

    • PD Model Analytics
  • Decisioning

    Step 5

    • Recommend & Highlight
    • Eligibility/Rules/Affordability
OTHER CUSTOMER STORIES

Continue reading

charter logo

Customer Story: Charter

charter logo

Charter Communications is a leading broadband connectivity company and cable operator, headquartered in Stamford, Connecticut. With an annual revenue of $55 billion, Charter provides high-speed internet, video, mobile, and voice services to millions of customers across 41 U.S. states.

As a trusted provider, Charter serves 57 million homes and connects 500 million IP devices to its robust network. The company also powers businesses with 300,000 fiber-lit commercial office buildings, ensuring seamless connectivity and innovation. Recognized for excellence, Charter has been ranked #1 in customer satisfaction by JD Power within its peer group, reflecting its commitment to delivering high-quality service and superior customer experience.

  • Industry
  • Region
  • Countries

    United States

  • Line of Business
  • Solution
  • Module
  • Infrastructure
  • ROI
  • Competition

Customer Timeline
Land MRR: $62K
Land PS: $462K
Expand MRR: $100K
Expand PS: $250K
  • Opportunity Created
    June 28, 2024
  • Opportunity Won
    January 21, 2025
  • Go-Live
    Estimated July 2025
  • Customer Expansion
    • Collections/Delinquency Mitigation
    • Portfolio Management (upsell/cross sell)
    • TRMA Sponsorship
    • Case Study
Initial Opportunity Details

  • Customer Challenge

    • Charter has seen application fraud rates spike significantly over the past three years.
    • Antiquated systems prevented Charter from effectively mitigating application fraud
    • Experian FraudNet Solution cost over $1M a year to support and was ineffective.
    • New senior executive team hired to rebuild Charter fraud onboarding infrastructure
    • Charter Data Science team was handcuffed by poor analytics, testing capabilities, and decentralized workflow tools.
  • Provenir Approach

    Profiling Engine

    Aggregation of specific values over a time period.

    • “Grouping of Activity” / “Buckets of Behavior”
    Examples:
    • IP Address 168.192.1.1 has been on 10 transactions over the past 6 hours
    • Location 123 has had a median order amount of $5,222 over the past 180 days
    Python Model Deployment

    Provenir provides the Charter Data Science team a platform to deploy, execute, test, monitor models they build to detect Fraud and Risk.

  • Provenir Impact

    • Reduced customer friction and losses, while optimizing operations through a stable, reliable, and scalable platform to support analytics and reporting needs.
    • Fraud and credit abuse controls prior to order submission will enable more accurate real-time decisioning.
    • $1M immediate annual cost reduction with the elimination of the Experian FraudNet tool.
    • The platform will enable risk assessment functionalities like testing rule performance and fraud decisioning through advanced ML models
    • Centralized Rule and Model Governance
  • Competitors

    Experian (incumbent), FICO, DataVisor, Socure, Visa (risk product) and Pega
  • Why We Won

    • Provenir Solution: Provenir Profiling Engine provided the most compelling/complete solution for Charter
    • Our Team: Fraud Expertise + Implementation Certainty
    • Decision Intelligence and Advanced AI/ML
      Centralized Rules and Model Governance
  • Pain Points

    • Decentralized fraud controls
    • Poor Analytics and Reporting
    • Infrastructure Downtime
    • Inability to leverage AI and Advanced Learning models
Customer Growth

Growth Opportunities

Organic Volume Growth – Charter’s expecting significant geographic expansion over next 3-5 years.

Expansion

  • Portfolio Management/Account Management
  • Collections – Charter has seen a rise in delinquencies and customer churn
Example Decisioning Flows
  • New Application

    Decisioning

    Orders received for two channels:

    1.Ship to Home
    or
    2.In Store

  • Internal/external Data Calls

    Decisioning

    Data Vendors

    • Ekata
    • SentiLink
    • Datafiniti
    • Nuance
    • RevSprings
    • UPS/FedEx
    • Citrix
    • Authentic ID
  • Real-Time Fraud Checks

    Decisioning

    Rules and Lookups

    • Negative List
    • Velocity Checks
    • Email, Billing, Device, Attempts, etc.
    • Feature Aggregation
    • Blacklist
    • Valid/Deceased SSN
    • Fraud Prevention Scenarios
    • SMB Orders
    • Positive Lists
  • Scoring and Risk Models

    Decisioning

    Analytical Models

    • Models built by Charter Data Scientists in KC
    • Champion / Challenge
    • Ongoing Feature Engineering
  • Manual Review Exceptions

    Decisioning

    Alert Review

    • Red / Yellow / Green Risk Assignment
    • Fraud, Credit, Sanctions, Affordability Analyst and Underwriter Reviews
OTHER CUSTOMER STORIES

Continue reading

banco promerica

Customer Story: Banco Promerica

Banco Promerica Costa Rica is part of Grupo Promerica that boasts an impressive presence across eight Central & South American countries, serving over 2.6 million clients with a robust network of branches and ATMs. With total assets exceeding US$18 billion and equity surpassing US$1.45 billion, they represent a valuable addition to our growing client base in the banking industry.

  • Industry
  • Region
  • Country

    Costa Rica

  • Line of Business
  • Solution
  • Module
  • Infrastructure
  • ROI
  • Competition

Customer Timeline
Land MRR: $18K
Land PS: $91,140
Expand MRR/PS: N/A
  • Opportunity Created
    August 4, 2023
  • Opportunity Won
    February 13, 2024
  • Go-Live
    In Implementation
  • Customer Expansion
    • Expansion planned for additional countries
Initial Opportunity Details

  • Customer Challenge

    To support their ambitious plans, Promerica needed a more flexible decision engine solution to manage their credit policies and decision-making. Their current process is highly manual, lacking the flexibility required to support their digital lending goals. A gap existed between their strategic objectives and the technical capabilities necessary to quickly implement decision rules tailored to their risk appetite and data requirements, and to scale as needed.

    The transition to a robust digital onboarding offering is a strategic imperative.

  • Provenir Approach

    Through process automation, our platform will enable a new era of efficiency. With simplified data access at its core, we ensure that decision-makers have immediate access to the right data, empowering them to make smarter credit risk decisions with confidence and precision.

    Furthermore, our low-code intuitive UI represents a paradigm shift, placing the power of customization and adaptation firmly in the hands of Promerica’s business users. Together, these pillars form the foundation upon which our solution will deliver unparalleled value, driving success and growth for Promerica in the dynamic landscape of modern business.

  • Provenir Impact

    After the implementation is completed, the internal objectives that we have set for ourselves include:

    • To streamline the digital onboarding process, allowing consumers to apply in real-time with a significant improvement in underwriting speed, reducing processing time from days or hours to minutes or seconds.
    • To enable rapid, low-effort access to any data source for improved accuracy and efficiency in Promerica’ s credit risk decision-making. The initial milestone will focus on real-time integration with Equifax. Currently, this integration operates through a manual approach.
  • Competitors

    GDS Link, FICO, In-House.
  • Why We Won

    • External Data augmentation via Marketplace and APIs
    • Integrations to Internal Databases
    • Flexibility: “On-the-fly” changes
    • User friendly visual interface
    • Ability to manage real time and batch mode for applications
  • Pain Points

    • Streamlining digital onboarding
    • Data integration
    • Flexibility to adapt credit policies
Customer Growth

Growth Opportunities

The current priority is focused on completing the implementation of this first phase in Costa Rica. After this implementation, the objective is to replicate the experience in the rest of geographies to standardize the Digital Onboarding initiative.

Expansion

The plan not only considers expansion through the incorporation of additional use cases but also focuses on standardization across the eight countries where Promerica has presence in Central and South America. This initiative will strengthen our collaboration and ensure sustainable joint growth throughout the region.
Example Decisioning Flows
  • New Application

    Decisioning

  • Validation

    Decisioning

    Internal Database
  • Aggregate & Orchestrate

    Decisioning

    equifax
    sugef
    Internal Databases
  • Exclusion Rules

    Decisioning

  • Decisioning

    Decisioning

    Application Rules
OTHER CUSTOMER STORIES

Continue reading