AI Regulation Tracker · HKMA · Circular

What does HKMA High-level Principles on Artificial Intelligence say about AI in banking?

Published Nov 1, 2019 · Last reviewed Oct 5, 2026

The HKMA's "High-level Principles on Artificial Intelligence", issued to all Authorized Institutions on 1 November 2019, are the foundation of Hong Kong's supervisory approach to AI in banking. The letter sets 12 principles in three groups (governance, application design and development, and on-going monitoring and maintenance), starting with board and senior management accountability for the outcomes of AI applications. It follows an HKMA survey of AI use by banks in Q3 2019, is principle-based so as not to inhibit AI development, and has no stated end date; the HKMA's 19 August 2024 circular on generative AI refers to it as the circular that will be updated from time to time. A bank adopting AI should map each application to the 12 principles and apply them in proportion to its risk.

OFFICIAL TEXT: brdr.hkma.gov.hk ↗ · IN FORCE · HKMA

DocumentHKMA High-level Principles on Artificial Intelligence — High-level Principles on Artificial Intelligence (HKMA circular to all Authorized Institutions, 1 November 2019)
Issued byHong Kong Monetary Authority — Hong Kong's banking regulator and de facto central bank (circulars to Authorized Institutions under the Banking Ordinance, Cap. 155)
TypeCircular
StatusIn force
PublishedNov 1, 2019
Applies toAll Authorized Institutions (banks, restricted licence banks and deposit-taking companies) in Hong Kong, addressed to their chief executives. Banks are expected to take the principles into account when designing and adopting AI and big data analytics applications and may apply them proportionately to the nature and risk of each application.
Official sourcebrdr.hkma.gov.hk ↗
Use casesAI governance (general) · Model risk management · Third-party & vendor AI · Cybersecurity · Data & privacy · Fair lending & discrimination

What are the key points of HKMA High-level Principles on Artificial Intelligence?

  • Principle 1 (governance): the board and senior management remain accountable for all AI-driven decisions and must put a proper governance framework and risk management measures in place; roles of the three lines of defence in developing and monitoring AI must be clearly defined.
  • Principles 2 to 8 (application design and development): sufficient expertise (2), appropriate explainability with "no black-box excuse" (3), data of good quality (4), rigorous model validation before deployment, preferably with an independent party (5), auditability through audit logs and documentation (6), management oversight of third-party vendors (7), and being ethical, fair and transparent (8).
  • Principle 8 expects banks to ensure AI-driven decisions do not discriminate or show unintentional bias against any group of consumers, and to tell consumers before service provision that a service is powered by AI technology and of the risks involved.
  • Principles 9 to 12 (on-going monitoring and maintenance): periodic reviews and on-going monitoring, including re-validation where appropriate (9), compliance with data protection requirements including the Personal Data (Privacy) Ordinance (10), effective cybersecurity measures against threats such as data poisoning and adversarial attacks (11), and risk mitigation and contingency plans (12).
  • Principle 12 gives examples of mitigating controls (human-in-the-loop mechanism, prudent risk limits, sample quality assurance checks) and requires contingency measures that can promptly suspend AI applications and trigger fall-back procedures such as human intervention or conventional processes.
  • The principles are high-level because the HKMA is mindful that overly prescriptive or rigid requirements may inhibit further development of AI-related technologies; banks may apply them in a proportionate manner.
  • The HKMA said it would keep the principles under periodic review and plans to issue separate guidance on consumer protection in AI use, which followed in the circular of 5 November 2019.
  • The letter was signed by Raymond Chan, Executive Director (Banking Supervision), and refers to a Q3 2019 survey showing AI use spreading from chatbots and personalised marketing to operational automation, cyber and fraud risk management.

What did HKMA High-level Principles on Artificial Intelligence change for banks?

The letter gave the HKMA a single reference text on AI risk management for banks, issued after its Q3 2019 survey of AI use. It is the baseline to which the HKMA's later circulars on generative AI, AML monitoring and the GenA.I. Sandbox point.

What do the HKMA's High-level Principles on Artificial Intelligence require of banks?

The HKMA's circular of 1 November 2019 sets out 12 high-level principles that banks are expected to take into account when designing and adopting AI and big data analytics applications. They cover governance (board and senior management stay accountable for AI-driven decisions), application design and development (expertise, explainability, data quality, model validation, auditability, vendor oversight and fairness) and on-going monitoring and maintenance (periodic review, data protection, cybersecurity and contingency plans). The principles are proportionate: banks apply them according to the nature of their AI applications and the level of risk, and the HKMA chose a high-level form so as not to inhibit AI-related technologies. They remain the HKMA's reference text for risk management of AI, including generative AI, which the HKMA's 19 August 2024 circular points back to.

RuleAuthorityWhat it requiresApplies
Principle 1 — Board and senior management accountable for the outcome of AI applicationsHKMARemain accountable for all AI-driven decisions, put in place a proper governance framework and risk management measures, and define the roles of the three lines of defence.Since 1 November 2019
Principle 3 — Appropriate level of explainabilityHKMADesign AI applications so they are explainable to relevant parties (no black-box excuse), at a level commensurate with their materiality.Since 1 November 2019
Principle 4 — Using data of good qualityHKMAAdopt a data governance framework with defined data quality metrics (accuracy, completeness, timeliness, consistency) and escalate data quality issues for timely rectification.Since 1 November 2019
Principle 5 — Rigorous model validationHKMAValidate and test trained AI models before production use, preferably involving an independent party such as the second or third line of defence or an external consultant.Since 1 November 2019
Principle 7 — Management oversight of third-party vendorsHKMAPerform due diligence on vendors that develop AI applications and run vendor management controls, including periodic reviews of the services provided.Since 1 November 2019
Principle 8 — Being ethical, fair and transparentHKMAEnsure AI-driven decisions do not discriminate or show unintentional bias against any group of consumers, and tell consumers before service provision that the service is powered by AI and of the risks involved.Since 1 November 2019
Principle 9 — Periodic reviews and on-going monitoringHKMAReview AI applications periodically (for example re-validation) and monitor them continuously because model behaviour may change after deployment.Since 1 November 2019
Principle 11 — Effective cybersecurity measuresHKMAEnsure security controls can deal with AI-specific attacks such as data poisoning and adversarial attacks, and stay abreast of emerging threats.Since 1 November 2019
Principle 12 — Risk mitigation and contingency planHKMAApply risk-mitigating controls (human-in-the-loop, prudent limits, sample quality assurance) and keep contingency measures that can promptly suspend AI applications and trigger fall-back procedures.Since 1 November 2019

The letter sits at the front of a small set of HKMA instruments. The consumer-protection circular of 5 November 2019 expands the transparency, fairness and data-privacy aspects for customer-facing big data analytics and AI, and the circular of 19 August 2024 extends both to generative AI. The AML circular of 9 September 2024 cites the 2019 principles when asking banks to consider AI in ML/TF monitoring.

The HKMA supervises these expectations through its ordinary banking supervision and, for innovation, through engagement: the GenA.I. Sandbox gives banks targeted supervisory feedback on AI pilots, and the HKMA has said it will consider the need for further guidance based on Sandbox trials. The letter itself states no penalty or reporting deadline.

WHAT THIS MEANS IN PRACTICE

  • Map every AI and machine learning application, including vendor-supplied ones, to the 12 principles and record the proportionality judgement for each.
  • Name accountable board and senior management owners for AI outcomes and document how the three lines of defence split development, validation and monitoring.
  • Build audit logs, documentation, data quality metrics and independent validation into the design phase, not after go-live.
  • Tell customers before service provision when a service is powered by AI, and keep a tested switch-off and fall-back route for each AI application.
  • Include AI-specific attack scenarios (data poisoning, adversarial inputs) in cyber testing and vendor due diligence.

Do the HKMA High-level Principles on Artificial Intelligence apply to banks?

Yes. The circular is addressed to the chief executive of all Authorized Institutions and says banks are expected to take the principles into account when designing and adopting AI and big data analytics applications. They may apply them in a proportionate manner reflecting the nature of their AI applications and the level of risk involved.

Are the HKMA's AI principles binding?

The letter is supervisory guidance in the form of a circular, not legislation, and states that the principles are high-level in nature. It does not specify penalties. Banks are nonetheless expected to take them into account, and the HKMA's later circulars build on them.

Is the HKMA's 2019 AI circular still current?

Yes. The HKMA's Banking Regulatory Document Repository lists it as a current circular, and the HKMA's circulars of 19 August 2024 and 20 September 2024 refer back to it. The 2024 circular says it will be updated from time to time in the light of market development and practical experience.

How do the HKMA's AI principles compare with the EU AI Act or SR 26-2?

The HKMA letter is a short, technology-neutral set of 12 principles applied proportionately, whereas the EU AI Act is binding regulation with risk categories and penalties. The HKMA principles on validation (5) and monitoring (9) overlap with model risk management guidance such as the Federal Reserve's SR 26-2, but the letter does not set out a full model risk framework.

DateDocumentStatus
Mar 5, 2026HKMA GenA.I. Sandbox++ joint circular — Joint Circular on the Expansion of Generative Artificial Intelligence Sandbox (HKMA, SFC, Insurance Authority and MPFA, 5 March 2026)In force
Sep 20, 2024HKMA GenA.I. Sandbox circular — Generative Artificial Intelligence Sandbox (HKMA circular inviting applications to the GenA.I. Sandbox, 20 September 2024)In force
Sep 9, 2024HKMA circular on AI for monitoring of suspicious activities — Use of Artificial Intelligence for Monitoring of Suspicious Activities (HKMA circular, 9 September 2024)In force
Aug 19, 2024HKMA GenAI consumer protection circular — Consumer Protection in respect of Use of Generative Artificial Intelligence (HKMA circular, 19 August 2024)In force
Nov 5, 2019HKMA BDAI consumer protection principles — Consumer Protection in respect of Use of Big Data Analytics and Artificial Intelligence by Authorized Institutions (HKMA circular, 5 November 2019)In force
Sep 30, 2026SB 947 — Employment: Automated Decision Systems (No Robo Bosses Act)Final

Follow every document these regulators publish

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning