South Korea moves to police AI risk in finance

AI

The Financial Security Institute has built a new framework to help lenders and other financial firms manage the dangers posed by artificial intelligence.

According to Asia Business Daily, the system is designed to catch problems such as hallucinated outputs, technical failures and security breaches before they cause harm, and follows a pilot phase with financial institutions ahead of a full rollout.

The institute confirmed on 12 August that it had completed Korea’s first Financial AI Safety and Reliability Evaluation Framework, built specifically for firms operating in the financial industry. Full-scale evaluations under the new system are due to begin in 2027, once further testing has been carried out.

The initiative responds to a rapid expansion of AI use inside financial companies, a trend accelerated by the loosening of rules such as network separation requirements.

With AI now touching more core banking and financial functions, the institute concluded that standardised checks were needed to catch faults, unreliable outputs and cyber threats before they spread through critical systems.

To build the framework, the institute drew on a mix of domestic and international sources. Locally, it examined the Financial Services Commission’s AI guidelines for the financial sector, the Financial Supervisory Service’s AI Risk Management Framework, and the country’s AI Basic Act.

It also looked abroad, referencing the ISO/IEC 42001 AI management standard and Inspect, the evaluation tool built by the UK’s AI Safety Institute.

The resulting framework is split into ten evaluation points across two broad categories. The first covers reliability, examining how well firms manage model performance, data quality, bias and fairness, and the clarity of explanations given to customers about AI-driven decisions.

Assessors will check whether performance thresholds are properly set, whether hallucinations and performance drift are actively monitored, and whether customers have a route to challenge or seek redress for AI decisions that affect them.

The second category addresses safety, spanning six areas: threats unique to AI systems, detection and response to AI-targeted attacks, protection of AI-related assets, checks on external models and data sources, the scalability of security governance, and ongoing security verification.

This includes testing whether firms can spot and block adversarial attacks through input filtering, whether open-source components and supply chains carry hidden risks, and whether firms comply with rules restricting cross-border data transfers.

The institute plans to brief financial firms on the new system online on 14 August, followed by a demand survey in September. Pilot testing will continue through the second half of the year to refine the criteria further.

From next year, evaluations will begin with the institute’s own member companies before a possible wider rollout across the financial industry. The institute is also exploring whether the framework could eventually double as a formal certification system under the country’s AI Basic Act.

Read the daily RegTech news

Copyright © 2026 RegTech Analyst

Enjoyed the story? 

Subscribe to our weekly RegTech newsletter and get the latest industry news & research

Copyright © 2018 RegTech Analyst

Investors

The following investor(s) were tagged in this article.