# HKMA High-level Principles on Artificial Intelligence: High-level Principles on Artificial Intelligence (HKMA circular to all Authorized Institutions, 1 November 2019)

Source: https://www.bankingnewsai.com/ai-regulation/documents/hkma-high-level-principles-ai-2019
Last updated: Oct 5, 2026

The HKMA's "High-level Principles on Artificial Intelligence", issued to all Authorized Institutions on 1 November 2019, are the foundation of Hong Kong's supervisory approach to AI in banking. The letter sets 12 principles in three groups (governance, application design and development, and on-going monitoring and maintenance), starting with board and senior management accountability for the outcomes of AI applications. It follows an HKMA survey of AI use by banks in Q3 2019, is principle-based so as not to inhibit AI development, and has no stated end date; the HKMA's 19 August 2024 circular on generative AI refers to it as the circular that will be updated from time to time. A bank adopting AI should map each application to the 12 principles and apply them in proportion to its risk.

## At a glance

| Field | Value |
| --- | --- |
| Authority | [HKMA](https://www.bankingnewsai.com/ai-regulation/hkma) |
| Type | Circular |
| Status | In force |
| Published | Nov 1, 2019 |
| Applies to | All Authorized Institutions (banks, restricted licence banks and deposit-taking companies) in Hong Kong, addressed to their chief executives. Banks are expected to take the principles into account when designing and adopting AI and big data analytics applications and may apply them proportionately to the nature and risk of each application. |
| Official text | https://brdr.hkma.gov.hk/eng/doc-ldg/docId/getPdf/20191101-1-EN/20191101-1-EN.pdf |

## Key points

- Principle 1 (governance): the board and senior management remain accountable for all AI-driven decisions and must put a proper governance framework and risk management measures in place; roles of the three lines of defence in developing and monitoring AI must be clearly defined.
- Principles 2 to 8 (application design and development): sufficient expertise (2), appropriate explainability with "no black-box excuse" (3), data of good quality (4), rigorous model validation before deployment, preferably with an independent party (5), auditability through audit logs and documentation (6), management oversight of third-party vendors (7), and being ethical, fair and transparent (8).
- Principle 8 expects banks to ensure AI-driven decisions do not discriminate or show unintentional bias against any group of consumers, and to tell consumers before service provision that a service is powered by AI technology and of the risks involved.
- Principles 9 to 12 (on-going monitoring and maintenance): periodic reviews and on-going monitoring, including re-validation where appropriate (9), compliance with data protection requirements including the Personal Data (Privacy) Ordinance (10), effective cybersecurity measures against threats such as data poisoning and adversarial attacks (11), and risk mitigation and contingency plans (12).
- Principle 12 gives examples of mitigating controls (human-in-the-loop mechanism, prudent risk limits, sample quality assurance checks) and requires contingency measures that can promptly suspend AI applications and trigger fall-back procedures such as human intervention or conventional processes.
- The principles are high-level because the HKMA is mindful that overly prescriptive or rigid requirements may inhibit further development of AI-related technologies; banks may apply them in a proportionate manner.
- The HKMA said it would keep the principles under periodic review and plans to issue separate guidance on consumer protection in AI use, which followed in the circular of 5 November 2019.
- The letter was signed by Raymond Chan, Executive Director (Banking Supervision), and refers to a Q3 2019 survey showing AI use spreading from chatbots and personalised marketing to operational automation, cyber and fraud risk management.

## What changed for banks

The letter gave the HKMA a single reference text on AI risk management for banks, issued after its Q3 2019 survey of AI use. It is the baseline to which the HKMA's later circulars on generative AI, AML monitoring and the GenA.I. Sandbox point.

## Use cases it governs

- [AI governance (general)](https://www.bankingnewsai.com/ai-regulation/by-use-case#governance-general)
- [Model risk management](https://www.bankingnewsai.com/ai-regulation/by-use-case#model-risk)
- [Third-party & vendor AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#third-party-vendors)
- [Cybersecurity](https://www.bankingnewsai.com/ai-regulation/by-use-case#cybersecurity)
- [Data & privacy](https://www.bankingnewsai.com/ai-regulation/by-use-case#data-privacy)
- [Fair lending & discrimination](https://www.bankingnewsai.com/ai-regulation/by-use-case#fair-lending)

## What do the HKMA's High-level Principles on Artificial Intelligence require of banks?

The HKMA's circular of 1 November 2019 sets out 12 high-level principles that banks are expected to take into account when designing and adopting AI and big data analytics applications. They cover governance (board and senior management stay accountable for AI-driven decisions), application design and development (expertise, explainability, data quality, model validation, auditability, vendor oversight and fairness) and on-going monitoring and maintenance (periodic review, data protection, cybersecurity and contingency plans). The principles are proportionate: banks apply them according to the nature of their AI applications and the level of risk, and the HKMA chose a high-level form so as not to inhibit AI-related technologies. They remain the HKMA's reference text for risk management of AI, including generative AI, which the HKMA's 19 August 2024 circular points back to.

| Rule | Authority | What it requires | Status | Source |
| --- | --- | --- | --- | --- |
| Principle 1 — Board and senior management accountable for the outcome of AI applications | [HKMA](https://www.bankingnewsai.com/ai-regulation/hkma) | Remain accountable for all AI-driven decisions, put in place a proper governance framework and risk management measures, and define the roles of the three lines of defence. | Since 1 November 2019 | [HKMA High-level Principles on Artificial Intelligence](https://www.bankingnewsai.com/ai-regulation/documents/hkma-high-level-principles-ai-2019) |
| Principle 3 — Appropriate level of explainability | [HKMA](https://www.bankingnewsai.com/ai-regulation/hkma) | Design AI applications so they are explainable to relevant parties (no black-box excuse), at a level commensurate with their materiality. | Since 1 November 2019 | [HKMA High-level Principles on Artificial Intelligence](https://www.bankingnewsai.com/ai-regulation/documents/hkma-high-level-principles-ai-2019) |
| Principle 4 — Using data of good quality | [HKMA](https://www.bankingnewsai.com/ai-regulation/hkma) | Adopt a data governance framework with defined data quality metrics (accuracy, completeness, timeliness, consistency) and escalate data quality issues for timely rectification. | Since 1 November 2019 | [HKMA High-level Principles on Artificial Intelligence](https://www.bankingnewsai.com/ai-regulation/documents/hkma-high-level-principles-ai-2019) |
| Principle 5 — Rigorous model validation | [HKMA](https://www.bankingnewsai.com/ai-regulation/hkma) | Validate and test trained AI models before production use, preferably involving an independent party such as the second or third line of defence or an external consultant. | Since 1 November 2019 | [HKMA High-level Principles on Artificial Intelligence](https://www.bankingnewsai.com/ai-regulation/documents/hkma-high-level-principles-ai-2019) |
| Principle 7 — Management oversight of third-party vendors | [HKMA](https://www.bankingnewsai.com/ai-regulation/hkma) | Perform due diligence on vendors that develop AI applications and run vendor management controls, including periodic reviews of the services provided. | Since 1 November 2019 | [HKMA High-level Principles on Artificial Intelligence](https://www.bankingnewsai.com/ai-regulation/documents/hkma-high-level-principles-ai-2019) |
| Principle 8 — Being ethical, fair and transparent | [HKMA](https://www.bankingnewsai.com/ai-regulation/hkma) | Ensure AI-driven decisions do not discriminate or show unintentional bias against any group of consumers, and tell consumers before service provision that the service is powered by AI and of the risks involved. | Since 1 November 2019 | [HKMA High-level Principles on Artificial Intelligence](https://www.bankingnewsai.com/ai-regulation/documents/hkma-high-level-principles-ai-2019) |
| Principle 9 — Periodic reviews and on-going monitoring | [HKMA](https://www.bankingnewsai.com/ai-regulation/hkma) | Review AI applications periodically (for example re-validation) and monitor them continuously because model behaviour may change after deployment. | Since 1 November 2019 | [HKMA High-level Principles on Artificial Intelligence](https://www.bankingnewsai.com/ai-regulation/documents/hkma-high-level-principles-ai-2019) |
| Principle 11 — Effective cybersecurity measures | [HKMA](https://www.bankingnewsai.com/ai-regulation/hkma) | Ensure security controls can deal with AI-specific attacks such as data poisoning and adversarial attacks, and stay abreast of emerging threats. | Since 1 November 2019 | [HKMA High-level Principles on Artificial Intelligence](https://www.bankingnewsai.com/ai-regulation/documents/hkma-high-level-principles-ai-2019) |
| Principle 12 — Risk mitigation and contingency plan | [HKMA](https://www.bankingnewsai.com/ai-regulation/hkma) | Apply risk-mitigating controls (human-in-the-loop, prudent limits, sample quality assurance) and keep contingency measures that can promptly suspend AI applications and trigger fall-back procedures. | Since 1 November 2019 | [HKMA High-level Principles on Artificial Intelligence](https://www.bankingnewsai.com/ai-regulation/documents/hkma-high-level-principles-ai-2019) |

The letter sits at the front of a small set of HKMA instruments. The consumer-protection circular of 5 November 2019 expands the transparency, fairness and data-privacy aspects for customer-facing big data analytics and AI, and the circular of 19 August 2024 extends both to generative AI. The AML circular of 9 September 2024 cites the 2019 principles when asking banks to consider AI in ML/TF monitoring.

The HKMA supervises these expectations through its ordinary banking supervision and, for innovation, through engagement: the GenA.I. Sandbox gives banks targeted supervisory feedback on AI pilots, and the HKMA has said it will consider the need for further guidance based on Sandbox trials. The letter itself states no penalty or reporting deadline.

### What this means in practice

- Map every AI and machine learning application, including vendor-supplied ones, to the 12 principles and record the proportionality judgement for each.
- Name accountable board and senior management owners for AI outcomes and document how the three lines of defence split development, validation and monitoring.
- Build audit logs, documentation, data quality metrics and independent validation into the design phase, not after go-live.
- Tell customers before service provision when a service is powered by AI, and keep a tested switch-off and fall-back route for each AI application.
- Include AI-specific attack scenarios (data poisoning, adversarial inputs) in cyber testing and vendor due diligence.

## FAQ

### Do the HKMA High-level Principles on Artificial Intelligence apply to banks?

Yes. The circular is addressed to the chief executive of all Authorized Institutions and says banks are expected to take the principles into account when designing and adopting AI and big data analytics applications. They may apply them in a proportionate manner reflecting the nature of their AI applications and the level of risk involved.

### Are the HKMA's AI principles binding?

The letter is supervisory guidance in the form of a circular, not legislation, and states that the principles are high-level in nature. It does not specify penalties. Banks are nonetheless expected to take them into account, and the HKMA's later circulars build on them.

### Is the HKMA's 2019 AI circular still current?

Yes. The HKMA's Banking Regulatory Document Repository lists it as a current circular, and the HKMA's circulars of 19 August 2024 and 20 September 2024 refer back to it. The 2024 circular says it will be updated from time to time in the light of market development and practical experience.

### How do the HKMA's AI principles compare with the EU AI Act or SR 26-2?

The HKMA letter is a short, technology-neutral set of 12 principles applied proportionately, whereas the EU AI Act is binding regulation with risk categories and penalties. The HKMA principles on validation (5) and monitoring (9) overlap with model risk management guidance such as the Federal Reserve's SR 26-2, but the letter does not set out a full model risk framework.

## Related documents

- [HKMA GenA.I. Sandbox++ joint circular](https://www.bankingnewsai.com/ai-regulation/documents/hkma-genai-sandbox-plus-plus-2026) — Joint Circular on the Expansion of Generative Artificial Intelligence Sandbox (HKMA, SFC, Insurance Authority and MPFA, 5 March 2026) (Mar 5, 2026)
- [HKMA GenA.I. Sandbox circular](https://www.bankingnewsai.com/ai-regulation/documents/hkma-genai-sandbox-2024) — Generative Artificial Intelligence Sandbox (HKMA circular inviting applications to the GenA.I. Sandbox, 20 September 2024) (Sep 20, 2024)
- [HKMA circular on AI for monitoring of suspicious activities](https://www.bankingnewsai.com/ai-regulation/documents/hkma-ai-aml-monitoring-2024) — Use of Artificial Intelligence for Monitoring of Suspicious Activities (HKMA circular, 9 September 2024) (Sep 9, 2024)
- [HKMA GenAI consumer protection circular](https://www.bankingnewsai.com/ai-regulation/documents/hkma-genai-consumer-protection-2024) — Consumer Protection in respect of Use of Generative Artificial Intelligence (HKMA circular, 19 August 2024) (Aug 19, 2024)
- [HKMA BDAI consumer protection principles](https://www.bankingnewsai.com/ai-regulation/documents/hkma-bdai-consumer-protection-2019) — Consumer Protection in respect of Use of Big Data Analytics and Artificial Intelligence by Authorized Institutions (HKMA circular, 5 November 2019) (Nov 5, 2019)
- [SB 947](https://www.bankingnewsai.com/ai-regulation/documents/ca-sb-947-2026) — Employment: Automated Decision Systems (No Robo Bosses Act) (Sep 30, 2026)
- [Bailey: Frontier AI and the Question of Governance (Sep 2026)](https://www.bankingnewsai.com/ai-regulation/documents/boe-bailey-frontier-ai-governance-2026) — Frontier AI and the Question of Governance — Governor Andrew Bailey (Sep 30, 2026)
- [AB 1609](https://www.bankingnewsai.com/ai-regulation/documents/ca-ab-1609-2026) — Customer Service Chatbots (Right to Human Customer Service Act) (Sep 28, 2026)

Last reviewed Oct 5, 2026. Cite the official text (https://brdr.hkma.gov.hk/eng/doc-ldg/docId/getPdf/20191101-1-EN/20191101-1-EN.pdf) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/hkma-high-level-principles-ai-2019
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
