Skip to content
CyberTalks: AI in Banking and Financial Services — When Governance Gaps Become Liabilities

CyberTalks: AI in Banking and Financial Services — When Governance Gaps Become Liabilities

Events

Published on July 20, 2026

On 9 July 2026, Cisometric, in collaboration with ISACA Indonesia Chapter, gathered professionals from banking, fintech, risk, compliance, audit, and IT governance at The Grand Mansion, Menteng, for our latest #CyberTalks session: AI in Banking and Financial Services: When Governance Gaps Become Liabilities.

The premise was simple, and a little uncomfortable: AI is already running inside financial institutions. The governance around it, in many cases, is not. This session set out to examine what happens in that gap, and what it takes to close it.

Why This Matters Now

AI is no longer a pilot project in financial services. It is already embedded across banking, payment systems, insurance, fintech, corporate finance, and capital markets, powering everything from customer service and fraud detection to KYC, payment processing, credit scoring, claims management, investment management, and process automation.

But adoption has outpaced oversight.

Drawing on ISACA's AI Pulse Poll 2026, the session highlighted a recurring pattern: organizations are using AI in genuinely practical ways, yet still struggle with policy, skill building, and risk management. Governance, in other words, is lagging behind adoption, even as AI risks become increasingly visible.

For banking and financial services, that lag is not a minor operational detail. It touches privacy, security, compliance, operational resilience, and, ultimately, customer trust.

The Risks 

Much of the discussion focused on the risks that come with Generative AI, several of which are already surfacing in real deployments:

  • Prompt injection: manipulating a model's behavior through crafted inputs

  • Hallucination: confident outputs that simply aren't true

  • Copyright infringement: exposure through training data and generated content

  • Data leakage: sensitive information escaping through model interactions

  • Deepfake and identity misuse: a direct threat to identity verification processes

  • Harmful content generation: reputational and regulatory exposure

  • Lack of explainability: decisions that cannot be traced or justified

What connects these risks is that none of them are solved by better technology alone. They require clear ownership, human oversight, controls, and accountability, which is exactly why AI governance cannot be treated as a purely technical problem.

Governance and Best Practices

The session then moved from problems to structure, introducing governance references and approaches that help organizations build something more deliberate than ad hoc policy, including:

  • AI management systems

  • Risk management frameworks

  • AI system governance

  • AI principles

A risk-based approach featured prominently: rather than applying uniform controls everywhere, organizations can classify AI systems by potential impact and calibrate the level of control accordingly. Not every model carries the same weight, and governance should reflect that.

AI Governance in Indonesian 

The conversation also turned closer to home, touching on existing references around AI governance and AI ethics guidelines in Indonesia.

As local adoption grows, organizations need more than an awareness of global best practices,  and they also need to understand where AI governance in Indonesia is heading, and build with that direction in mind.

The Key Takeaway

If there was one message that carried through the session, it was that AI governance is not a document. It is not a policy filed away for the next audit, or a procedure that exists only on paper.

Governance has to become a living system, one that shapes how people, processes, and technology actually work day to day. AI should support human decision-making, not quietly absorb the accountability that comes with it.

Done well, strong AI governance does double duty. It mitigates financial, legal, and reputational risk, while enabling innovation that is responsible and sustainable rather than reckless.

Conclusion

As AI becomes further embedded in banking and financial services, the conversation around governance needs to move from principle to practice.

Through this #CyberTalks session, Cisometric and ISACA Indonesia Chapter encouraged financial institutions to look beyond adoption, and start building the governance, controls, and accountability required to use AI responsibly.

If you're exploring how your organization can strengthen its AI governance, risk posture, and regulatory readiness, schedule a consultation with our team today, click here.

For more updates on digital scams, cybersecurity insights, and expert tips, follow our social media:

LinkedIn: Cisometric

Instagram: @cisometric

Youtube: @Cisometric

You may like this...

We use cookies to enhance your browsing experience, analyse site traffic, and deliver relevant content. Choose which cookies you allow. Privacy Policy