Indonesia - AI Ethics Guidelines

Guidelines for Responsible and Trustworthy Artificial Intelligence Ethics in the Financial Technology Industry

Panduan Kode Etik Kecerdasan Buatan yang Bertanggung Jawab dan Terpercaya di Industri Teknologi Finansial

Indonesia

RAI-ID-NA-PKEKBXX-2023
In Force(In Force)
GuidelineGovernance and OversightRisk ManagementData Protection and Privacy
Export PDF

In November 2023 OJK (Indonesia Financial Services Authority), together with four fintech associations (AFTECH, AFSI, AFPI, ALUDI), published a voluntary sectoral Code of Ethics for the responsible and trustworthy use of Artificial Intelligence in the fintech industry. The guidance sets out high-level principles (beneficial, fair & accountable, transparent & explicable, robust & secure) and recommended institutional, governance, risk-management and operational practices for fintech firms and associations operating in Indonesia.

Summary

Background and Purpose: In late 2023 the Otoritas Jasa Keuangan (OJK), in collaboration with four industry associations — Asosiasi Fintech Indonesia (AFTECH), Asosiasi Fintech Syariah Indonesia (AFSI), Asosiasi Fintech Pendanaan Bersama Indonesia (AFPI), and Asosiasi Layanan Urun Dana Indonesia (ALUDI) — issued the "Panduan Kode Etik Kecerdasan Buatan (Artificial Intelligence/AI) yang Bertanggung Jawab dan Terpercaya di Industri Teknologi Finansial" to provide a sector-specific behavioural framework for AI adoption in Indonesian fintech. The framework is intended primarily as a code of conduct reference for associations and their members and as an industry best-practice guide to mitigate the risks of AI while promoting beneficial innovation. The OJK published a press release announcing the launch on 24 November 2023 and added the guidance to its publications on 4 December 2023. (Primary source: OJK publication and press release).

Core Principles: The guidance organizes its content around four foundational principles commonly found in international AI ethics instruments: (1) beneficial (AI should create positive value for customers and financial inclusion), (2) fair and accountable (avoidance and mitigation of bias and discriminatory outcomes; governance and stakeholder accountability), (3) transparent and explicable (appropriate disclosure and explainability to users and supervisors), and (4) robustness and security (operational resilience, cybersecurity, model testing and validation). The document references international materials such as the OECD AI Principles and NIST AI Risk Management Framework as inputs to the approach.

Scope and Audience: The code targets fintech service providers and market participants operating in Indonesia, including P2P lenders, digital lending platforms, payment platforms, insurtech, digital banks and affiliated service providers that develop, deploy or procure AI systems in customer-facing or back-office functions. Although framed for fintech, the guidance notes cross-sectoral implications (including areas such as insurtech and health-finance partnerships) and encourages associations to convert the guidance into sector or member-specific codes of conduct.

Governance and Operational Expectations: The guidance emphasizes board and senior management responsibility for AI governance, documented AI policy and risk appetite, dedicated oversight (e.g., AI committees or designated officers), integration with existing Governance-Risk-Compliance frameworks, regular AI risk assessments, lifecycle documentation, model validation and testing, human oversight and escalation channels, consumer protection measures including clear disclosures, data protection and retention policies, vendor and third-party assurance, and incident reporting. It stresses alignment with applicable Indonesian data protection rules and broader OJK prudential expectations.

Implementation & Monitoring: The guidance recommends risk-classification of AI use-cases, pre-deployment testing, periodic post-deployment monitoring, and maintenance of explainability records to support internal audit and regulatory inquiries. Associations are asked to translate the guidance into codes of conduct, member standards and training curricula; OJK anticipates supervisory dialogue and potential incorporation of guidance principles into future regulations or supervisory expectations (for example, POJK 3/2024 on Financial Sector Technological Innovation and related SE/SEOJKs dealing with sandboxing and registration).

Enforcement and Legal Effect: The document is a non-binding sectoral code of ethics (guidance) rather than a prescriptive regulation. However, the guidance signals OJK's supervisory interest: non-compliance with the principles may influence supervisory assessments and enforcement actions under existing statutory/regulatory powers (e.g., prudential, consumer protection and licensing regulations). The guidance therefore functions as both a baseline for voluntary industry self-regulation and as a reference point for supervisors in assessing governance and operational soundness of AI-enabled fintech services.

Relationship to International Standards: The guidance expressly cites OECD AI Principles and the NIST AI RMF, positioning the Indonesian fintech code as harmonized with international practice while tailored to local market and regulatory realities. It also anticipates ongoing international cooperation and knowledge exchange.

Key outcomes: The guidance lists recommended actions (governance structures, risk assessments, documentation, explainability, testing, data governance, cybersecurity, consumer disclosures, vendor management, training, monitoring and reporting). It leaves detailed thresholds, mandatory conformity assessment regimes, and monetary penalties to OJK's formal rulemaking and existing supervisory toolkit. The framework is expected to evolve with regulatory developments such as POJK 3/2024 and subsequent SEOJK/SE/OJK guidance on registration, sandboxing and cybersecurity for ITSK (Innovasi Teknologi Sektor Keuangan).

Full article

Read full text ↗

Overview

The "Panduan Kode Etik Kecerdasan Buatan (AI) yang Bertanggung Jawab dan Terpercaya di Industri Teknologi Finansial" is a sectoral guidance published jointly by OJK and four fintech associations to promote trustworthy AI use in Indonesia's fintech ecosystem. Launched at the 5th Indonesia Fintech Summit & Expo (IFSE) on 24 November 2023 and published on the OJK publications portal in early December 2023, the document sets out high-level principles and recommended governance, operational and monitoring arrangements for fintech firms that develop, deploy or procure AI systems. The guidance draws upon and references international instruments such as the OECD AI Principles and the NIST AI Risk Management Framework, tailoring those concepts to the Indonesian fintech context. The guidance is designed as a code of conduct that associations can convert into member standards, and as an industry reference point that OJK may use in supervisory dialogue. The official OJK announcement and publication are available on the OJK site: OJK publication: Panduan Kode Etik AI (Dec 4, 2023).

Definitions

The guidance defines key terms to ensure common understanding across the fintech sector, including "Artificial Intelligence/AI" (systems that perform tasks typically requiring human intelligence), "AI lifecycle" (design, development, testing, deployment, monitoring, and retirement), "operator/owner" (entities responsible for model decisions), "human oversight" (procedures ensuring meaningful human control), and "high-impact use-cases" (AI applications that significantly affect customers' rights or access to financial services). It clarifies that AI in fintech includes predictive credit scoring models, automated underwriting, fraud detection engines, personalized recommendations, conversational agents (chatbots), and algorithmic decisioning for onboarding or pricing. Definitions reference internationally accepted conceptions to enable alignment with cross-border guidance.

Governance and Institutional Framework

The guidance emphasizes senior management and board-level accountability for AI adoption and risk oversight. Firms are expected to incorporate AI governance into existing Governance-Risk-Compliance (GRC) frameworks, appoint designated AI owners or committees, maintain documented AI policies, and align incentives to promote responsible AI behaviour. Associations are encouraged to develop member codes of conduct and training programs. OJK positions itself as a convenor and supervisory partner rather than an immediate rulemaking authority in this publication; nevertheless, the guidance signals that OJK supervisory assessments will consider adherence to these governance expectations. The guidance also cross-references OJK's broader supervisory architecture for ITSK and sandboxing (see related OJK publications and POJK developments) and provides a framework for institutional roles across product teams, risk/compliance functions, internal audit, and external vendors. For the official OJK press release see: OJK press release (Nov 24, 2023).

Key Focus Areas

The guidance organizes operational expectations into distinct focus areas: 1) Principles and ethics (beneficial outcomes, fairness/accountability, transparency/explainability, robustness/security); 2) Risk assessment (identifying, classifying and prioritizing AI risk across the lifecycle); 3) Data governance (privacy-by-design, consent, provenance, minimization, retention limits and quality); 4) Model development and validation (testing, bias detection, performance metrics, stress and adversarial testing); 5) Human oversight and appeals (mechanisms for human review and dispute resolution); 6) Cybersecurity and resilience (secure development lifecycle, access controls, incident response); 7) Vendor and third-party management (assurance clauses, audits and SLAs); 8) Consumer protections and disclosures (clear information to customers on AI-driven decisions and channels for redress); and 9) Documentation & audit trails (complete development, testing, versioning and deployment records). The guidance provides practical illustrations for fintech-relevant use-cases such as credit scoring, pricing, onboarding automation, and fraud detection, emphasizing especially those use-cases that affect access to essential financial services.

Implementation Framework

The implementation section recommends a staged approach: initial gap assessment and policy adoption; classification of AI use-cases by risk and materiality; design and deployment of governance structures (AI committee, AI owner, risk sign-off gates); pre-deployment testing and third-party assurance for high-risk models; customer-facing disclosures and complaint handling; continuous monitoring with performance and fairness metrics; and formal periodic review (including trigger-based re-validation). The guidance provides templates and checklists for associations to adopt as their own member codes of conduct and encourages capacity building (training for boards, risk teams, and product developers). It also encourages firms to leverage regulatory sandboxes for controlled testing where appropriate and notes that existing OJK sandbox and registration mechanisms under the evolving ITSK regulatory framework may be relevant for certain AI-enabled innovations.

Monitoring and Evaluation

Monitoring requirements are oriented to both technical performance and governance effectiveness. Firms should implement automated monitoring signals (data drift, model accuracy, false positive/negative rates across demographic segments), periodic fairness audits, and incident logbooks. The guidance recommends establishing KPIs for AI risks and governance maturity, and setting escalation triggers for supervisory reporting or rollback. Associations are expected to collect anonymized industry-level insights to inform sector risk intelligence sharing and capacity building. OJK indicates that it will monitor industry adoption and may incorporate key elements into future supervisory expectations or formal rulemaking.

Penalties, Liability, and Appeals

As a voluntary code of ethics, the guidance itself does not create new statutory penalties; however non-compliance with the principles may be relevant to OJK's supervisory judgment under existing laws and regulations governing licensing, consumer protection, market integrity and prudential standards. The guidance explicitly recommends that firms maintain consumer-facing appeals and redress channels, keep records to support liability and remediation decisions, and ensure contracts with third parties allocate liability and incident response obligations. While the guidance does not prescribe monetary fines, it foresees supervisory actions under existing OJK powers (e.g., warnings, orders to remediate, license restrictions, or referrals where statutory breaches are identified).

Relationship to Other Instruments

The guidance is positioned as complementary to OJK’s regulatory program for ITSK (Financial Sector Technological Innovation) and the regulatory sandbox regime. It references international standards (OECD and NIST) as intellectual inputs, while remaining explicitly aligned with Indonesian law (including data protection, consumer protection, and prudential regulation). The guidance anticipates interaction with POJK No. 3 of 2024 (Penyelenggaraan ITSK) and subsequent SEOJK/SEOJK rulemaking on registration, sandbox mechanisms and cybersecurity guidance. Associations and firms are encouraged to align their codes with this guidance and to incorporate any sector-specific legal obligations that already apply to licensed financial services firms.

International Alignment

The code explicitly cites international frameworks to ensure interoperability and to avoid regulatory fragmentation. By referencing the OECD AI Principles and the NIST AI RMF, OJK signals an intention to harmonize domestic fintech practices with global best practice while retaining flexibility to address local market and legal conditions. The guidance supports cross-border fintech activities by advocating for transparency on model provenance, data sharing constraints and vendor oversight, which are critical for multi-jurisdictional operations and international cooperation on AI risk management.

Implementation Timeline

MilestoneTarget DateNotes
Launch (IFSE)2023-11-24Public launch at IFSE 2023 (OJK + associations)
Publication on OJK portal2023-12-04Guidance added to OJK publications library
Association conversion to codes2024 (ongoing)Associations to adapt guidance into member codes of conduct
Supervisory integration2024-2025OJK to reference guidance in supervisory dialogue and rulemaking

Sources and References

SourceType
OJK press release: OJK bersama asosiasi fintech luncurkan Panduan Kode Etik AI (Nov 24, 2023)Primary Source
OJK publication: Panduan Kode Etik Kecerdasan Buatan (Dec 4, 2023)Primary Source
AFTECH / fintech.id announcement (IFSE 2023)Primary Source

Requirements for a company

What an organisation has to do under Indonesia - AI Ethics Guidelines, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

14
  • Identify, classify, and prioritize AI risks across the entire AI lifecycle.Fintech firms developing, deploying, or procuring AI systems.
  • Implement robust data governance, including privacy-by-design, consent, and quality.Fintech firms developing, deploying, or procuring AI systems.
  • Conduct thorough testing, bias detection, performance metric evaluation, and stress testing for AI models.Fintech firms developing, deploying, or procuring AI systems.
  • Establish clear mechanisms for human review, dispute resolution, and customer appeals for AI-driven decisions.Fintech firms deploying AI systems.
  • Implement secure development lifecycle, access controls, and incident response for AI systems.Fintech firms developing, deploying, or procuring AI systems.
  • Provide clear information to customers about AI-driven decisions and available redress channels.Fintech firms deploying AI systems.
  • +8 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Indonesia - AI Ethics Guidelines, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Fintech firms developing, deploying, or procuring AI systems.Identify, classify, and prioritize AI risks across the entire AI lifecycle.
Risk assessment (identifying, classifying and prioritizing AI risk across the lifecycle)
Before placing on marketKey Focus AreasCritical
2Fintech firms developing, deploying, or procuring AI systems.Implement robust data governance, including privacy-by-design, consent, and quality.
Data governance (privacy-by-design, consent, provenance, minimization, retention limits and quality)
Key Focus AreasCritical
3Fintech firms developing, deploying, or procuring AI systems.Conduct thorough testing, bias detection, performance metric evaluation, and stress testing for AI models.
Model development and validation (testing, bias detection, performance metrics, stress and adversarial testing)
Before placing on marketKey Focus AreasCritical
4Fintech firms deploying AI systems.Establish clear mechanisms for human review, dispute resolution, and customer appeals for AI-driven decisions.
Human oversight and appeals (mechanisms for human review and dispute resolution)
Before placing on marketKey Focus AreasCritical
5Fintech firms developing, deploying, or procuring AI systems.Implement secure development lifecycle, access controls, and incident response for AI systems.
Cybersecurity and resilience (secure development lifecycle, access controls, incident response)
Key Focus AreasCritical
6Fintech firms deploying AI systems.Provide clear information to customers about AI-driven decisions and available redress channels.
Consumer protections and disclosures (clear information to customers on AI-driven decisions and channels for redress)
Before placing on marketKey Focus AreasCritical
7Fintech firms developing, deploying, or procuring AI systems.Integrate AI governance into existing Governance-Risk-Compliance frameworks.
Firms are expected to incorporate AI governance into existing Governance-Risk-Compliance (GRC) frameworks
Governance and Institutional FrameworkImportant
8Fintech firms developing, deploying, or procuring AI systems.Appoint designated AI owners or committees responsible for AI oversight.
appoint designated AI owners or committees
Governance and Institutional FrameworkImportant
9Fintech firms developing, deploying, or procuring AI systems.Maintain documented policies for AI development, deployment, and use.
maintain documented AI policies
Governance and Institutional FrameworkImportant
10Fintech firms procuring AI systems.Include assurance clauses, audit rights, and service level agreements in contracts with AI vendors.
Vendor and third-party management (assurance clauses, audits and SLAs)
Before contracting with vendorsKey Focus AreasImportant
11Fintech firms developing, deploying, or procuring AI systems.Maintain complete records of AI development, testing, versioning, and deployment.
Documentation & audit trails (complete development, testing, versioning and deployment records)
Key Focus AreasImportant
12Fintech firms deploying AI systems.Implement automated monitoring for data drift, model accuracy, fairness metrics, and incident logging.
Firms should implement automated monitoring signals (data drift, model accuracy, false positive/negative rates across demographic segments)
Monitoring and EvaluationImportant
13Fintech firms deploying AI systems.Conduct formal periodic reviews and trigger-based re-validation of AI models.
formal periodic review (including trigger-based re-validation)
Implementation FrameworkImportant
14Fintech associations.Develop member codes of conduct and training programs for responsible AI use.
Associations are encouraged to develop member codes of conduct and training programs.
2024 (ongoing)Governance and Institutional FrameworkImportant

© Regulations.AI · updated on 13-Jun-2026