Responsible AI

Responsible AI

Responsible AI at SCBX Group

 

Becoming an AI-driven Organization (AI-first Organization)

SCBX Group recognizes that Artificial Intelligence (AI) is becoming an important capability for financial services, technology operations, customer engagement, operational efficiency and decision-making support, and have committed to becoming an AI-driven organization (“AI-first”).

Additionally, SCBX Group also recognizes that the value of AI depends not only on innovation, but also on trust, accountability, resilience and the responsible use of data. As such the group approach AI as both a strategic enabler and a responsibility—ensuring that AI systems are designed, deployed and governed in a manner that upholds privacy, security, fairness, transparency and human oversight.

This is achieved through a combination of a Group-wide Responsible AI Policy, which acts as a framework to facilitate innovation, build trust in AI and mitigate risks across the AI lifecycle, covering usage, development, procurement, infrastructure, data governance, trust and safety, compliance and risk management. In addition to application of the policy in development of applicable AI programs.

 

Responsible AI Principles

SCBX Group’s approach to AI is anchored in six guiding principles:

Principle 1 – Strategic Alignment

Every AI initiative has a clear and legitimate business purpose and is directed towards beneficial outcomes for our customers, our organization and society.

Principle 2 – Responsible Innovation and Technical Excellence

We encourage purposeful experimentation while upholding high standards of technical excellence, safety and security, and learning continuously from both successes and failures.

Principle 3 – Human Centered Design

We design AI to prioritize human well-being and autonomy. Where customers interact with AI, we inform them clearly and, where feasible, offer the option to engage with a human.

Principle 4 – Human Oversight

We maintain meaningful human control over AI, with oversight measures proportionate to the risk, level of autonomy and context in which the AI is used.

Principle 5 – Responsible AI by Design

We embed responsible-AI practices throughout the AI lifecycle. AI-driven decisions are held to at least the same ethical standards as human-driven decisions.

Principle 6 – Risk and Compliance

We comply fully with applicable laws and regulations, proactively adopt recognized international standards, and apply a risk-based approach to governance and control.

Governance and Accountability

SCBX Group’s AI governance approach is anchored in group-level principles, clear accountability and risk-based oversight. The SCBX Group Responsible AI Policy applies to SCBX Public Company Limited and subsidiaries, and covers employees, permanent staff, contractors and third parties that collect, process, disclose, provide or consume data, services or technology as part of a contract. Subsidiaries are expected to adapt relevant requirements in alignment with the overarching Group principles.

The Responsible AI Policy was created by the Data & AI Center of Excellence, reviewed by subsidiaries and relevant SCBX functions including Risk, Legal, Compliance, Internal Audit, R&D and Centers of Excellence, endorsed through SCBX governance bodies and approved by the Board of Directors. The policy requires compliance by employees and relevant contractors, annual review or review upon major changes, and formal exception or waiver handling supported by risk and impact assessment, compensating actions and approval by authorized SCBX committees or the Board of Directors.

Responsible AI governance is further reinforced by SCBX’s broader control environment. The Technology Risk Management Policy recognizes technology risk as any risk to SCBX Group’s information technology, data and applications that may negatively impact business operations, and explicitly include emerging technologies such as AI, machine learning, cybersecurity and big data. The Information and Cybersecurity Policy apply a three-lines-of-defense governance model and establishes accountability for protecting data and systems. The Group Data Governance Policy recognizes data as a strategic asset and establishes governance principles and capabilities for availability, accountability, data quality, data classification, privacy, security, risk management, reporting and monitoring.



Responsible AI Lifecycle Controls

SCBX Group manages Responsible AI through policy requirements and governance principles across the AI lifecycle—from usage and development to procurement, infrastructure, data governance, monitoring and risk management.

Data privacy and personal data protection. The Responsible AI Policy identifies privacy and security risks that may arise when AI tools improperly collect, process, share, retain or generate confidential information, personal data, sensitive data or intellectual property. This is reinforced by the SCBX Data Privacy and Protection Policy, which sets minimum requirements for lawful collection, use and disclosure; accuracy; data minimization; storage limitation; purpose limitation; records of processing activities; overseas transfer controls; data subject rights; third-party privacy risk assessment; and reporting of suspected personal data breaches or incidents.

Data governance, quality and provenance. The Responsible AI Policy requires measures to manage data security, quality, provenance and privacy. The Group Data Governance Policy further supports this requirement by defining data governance as the exercise of authority and control over data assets, with principles and capabilities for data ownership, stewardship, classification, metadata, data quality, data security, data privacy, risk management, training, reporting and monitoring. These controls support more reliable, accountable and traceable use of data in AI-related activities.

Cybersecurity and technology resilience. AI safety and security are embedded in SCBX Group’s AI governance principles. The Responsible AI Policy requires protection of AI, model and system testing, evaluation and monitoring once deployed. The Information and Cybersecurity Policy reinforces this through requirements for confidentiality, integrity and availability of data and systems; identity and access management; role-based or attribute-based access control; zero-trust network access for remote access; endpoint security; data security; application security; cloud and infrastructure security; vulnerability management; incident reporting; awareness and training; and business continuity/disaster recovery planning. The Technology Risk Management Policy further supports AI-related resilience through technology risk appetite, annual review, risk identification, assessment, response, monitoring and reporting.



Fairness, Transparency and Human Oversight

SCBX Group commits that AI use, and development must align with the Group’s ethical standards, values and codes of conduct, including fairness and sustainability. The Responsible AI Policy requires risk management processes to identify and mitigate AI risks, with enhanced governance considerations where AI is used to provide services to customers. This establishes a foundation for considering fairness and potential bias as part of responsible AI risk management.

The Responsible AI Policy requires meaningful human oversight and human control over AI. AI-driven decision-making must be approved by an appropriate internal authority, and AI-driven decisions are required to be held to at least the same ethical standards as human-driven decisions. Where relevant, users and customers should be enabled to provide feedback so that AI can correct errors.

SCBX Group also seeks transparency across the AI lifecycle about data, models and systems, where feasible, including explainability of models and records of model performance. The Responsible  AI Policy requires that users and/or customers are aware when they are interfacing with AI. These principles support responsible engagement by helping stakeholders understand when AI is being used and by maintaining accountability for AI-supported outcomes.



Accountability, Boundaries and Third-Party AI

The Responsible AI Policy establishes accountability processes covering governance, internal capability and compliance strategy, and requires appropriate accountability for both internally developed and externally sourced AI models. This is important because responsibility for AI outcomes must remain clear even when AI capabilities are obtained from third parties.

SCBX Group encourages experimentation and AI use to increase revenue, reduce cost, improve efficiency, uplift customer experience and mitigate risks. At the same time, the Responsible AI Policy emphasizes safe, respectful and productive use. This establishes a policy boundary for responsible use, including controls against improper handling of confidential information, personal data, sensitive data and intellectual property.

Third-party AI is addressed through the Responsible AI Policy’s scope and procurement coverage, together with supporting privacy, cybersecurity, data governance and technology risk requirements. These policies collectively reinforce the need to manage AI-related risks across internal and external technology arrangements, including data protection, access control, system security, risk assessment and monitoring.



Implementation and Continuous Improvement

In 2026, SCBX Group will continue strengthening Responsible AI governance within the boundaries of its approved Responsible AI Policy and supporting privacy, data governance, cybersecurity and technology risk requirements. Key focus areas include embedding AI risk assessment into use-case approval, development, procurement and monitoring; clarifying responsibilities across business, technology, risk, compliance, legal, internal audit and Centers of Excellence; and improving documentation for data quality, privacy, cybersecurity, human oversight, model testing, monitoring, user/customer notification, exception management and third-party AI governance.

SCBX Group will also continue to strengthen internal coordination across AI, data, cyber, technology risk, privacy, legal and compliance functions. This integrated approach supports responsible innovation while maintaining accountability, trust and resilience as AI adoption evolves across the Group. Future disclosures may be strengthened through evidence-based examples of governance artifacts, approval checkpoints, control testing, monitoring practices, training and awareness activities, and incident or issue escalation processes, where such information is approved for public reporting.

Responsible AI Program

SCBX Group has established a Responsible AI Program to implement its Responsible AI Policy and Principles across the AI lifecycle. The program provides a structured framework that integrates governance, risk management, technical controls and human oversight into the design, development, procurement, deployment and ongoing monitoring of AI systems.

Through a risk-based and proportionate approach, the program helps ensure that AI technologies are deployed responsibly, while supporting innovation, protecting stakeholders, strengthening trust and promoting the ethical, secure and sustainable use of AI across the Group.

1. AI Governance for High-Risk AI Use Cases

SCBX Group implements a multi-layered governance framework to control access to sensitive AI technologies and to ensure the fair, lawful use of data throughout the AI lifecycle. This framework is built on three pillars — People, Process, and Technology — ensuring accountability, traceability, and alignment with responsible AI principles and regulations.

People
  • Defined roles and accountability: Access to sensitive AI capabilities (e.g., biometric recognition, predictive profiling, generative content tools) is restricted to designated personnel whose roles require it, based on a role-based access model.
  • Segregation of duties: Distinct individuals are responsible for requesting, approving, and auditing access and data use, preventing any single person from unilaterally deploying sensitive capabilities or unverified data sources.
Process
  • Tiered access classification: Refer to SCBX group AI governance policy, AI use cases are classified by risk level based on potential impact to fairness, IP infringement, privacy or Data governance, including data access rights, is guided by SCBX Group data governance and privacy policies and supporting standards.
  • Data quality and provenance review: Data sourcing processes include checks for data quality, accuracy, and lawful provenance, recognizing that restricted access to comprehensive, high-quality data can otherwise degrade model outcomes — the objective is to balance robust data access with respect for creators’ rights.
  • Incident response and escalation: A defined protocol exists for reporting, investigating, and remediating misuse — including unauthorized data use or IP infringement — with escalation to senior leadership and external regulators where required.
Technology
  • Automated monitoring and anomaly detection: Systems flag unusual access patterns or unverified data ingestion for review by Cyber COE teams.
  • Sandboxed/controlled environments: High-risk AI capabilities are tested in isolated environments before production use, with restricted export/output controls to prevent unauthorized data extraction or downstream IP exposure.
Outcome

This integrated People–Process–Technology approach ensures that sensitive AI capabilities are deployed only by authorized, trained personnel, under clearly defined and auditable circumstances, using data that is lawfully sourced and fairly licensed. SCBX Group is balancing two critical priorities: protecting the rights and generosity of content creators, and ensuring GenAI systems have access to sufficiently comprehensive, high-quality data to produce accurate, reliable outcomes. This is upheld in conform with Thai laws and regulations and reflects our broader dedication to responsible, trustworthy AI.

2. Transparency and AI Disclosure

SCBX Group is committed to ensuring transparency and accountability in the use of AI by clearly disclosing AI-generated or AI-assisted content, decisions, and interactions to users. This practice reinforces trust, protects consumer rights, and enables informed decision-making across all touchpoints where AI is deployed. Our approach is structured around People, Process, and Technology.

People
  • Defined ownership and accountability: Business units and product teams that deploy AI-generated content or AI-driven decisioning are accountable for ensuring appropriate disclosure, with oversight from the AI Governance body
  • Governance sign-off: Any new AI use case involving customer-facing content or decisions must be reviewed by the governance body to confirm appropriate disclosure mechanisms are in place prior to launch.
Process
  • Proactive interaction disclosure: Where users interact with an AI system, the system must proactively disclose that the user is engaging with AI rather than a human, at the outset of the interaction
Process
  • Monitoring and detection tools: Automated tools periodically scan customer-facing platforms to verify that AI-generated content and interactions carry the required disclosures.
Outcome

Through this integrated People–Process–Technology approach, SCBX Group ensures that customers and stakeholders can clearly distinguish AI-generated content from human-created content and are proactively informed when interacting with an AI system rather than a human. This transparency fosters trust, supports informed decision-making, and reinforces the Group’s commitment to responsible and accountable AI deployment

3. Monitoring and Continuous Improvement

SCBX Group recognizes that AI models can degrade in accuracy, reliability, and fairness over time due to shifts in data patterns, business context, or external conditions — a phenomenon known as model drift. To safeguard the ongoing reliability and relevance of our AI systems, we have embedded continuous performance monitoring into our AI governance framework, anchored in a clear Three Lines of Defense (3LoD) model and structured around People, Process, and Technology.

People
  • Clear accountability under the 3LoD model: Primary accountability for runtime monitoring and remediation sits with First Line of Defense (1LoD) AI/Model Owners and operators, who define monitoring metrics, thresholds, and alerting logic aligned to the model’s approved use case and risk tier.
  • Independent challenge and oversight: Second Line of Defense (2LoD) functions — Model Risk Management (MRM) and Tech Risk — provide independent review, challenge, and advisory input on the adequacy of monitoring metrics, and escalation support where material risk thresholds are breached, without defining use-case-specific metrics themselves.
Process
  • Proactive interaction disclosure: Where users interact with an AI system, the system must proactively disclose that the user is engaging with AI rather than a human, at the outset of the interaction
Process
  • Monitoring and detection tools: Automated tools periodically scan customer-facing platforms to verify that AI-generated content and interactions carry the required disclosures.
Outcome

Through this integrated People–Process–Technology approach, underpinned by a clear Three Lines of Defense governance model, SCBX Group ensures its AI models are continuously monitored for performance, reliability, fairness, and safety degradation — including concept drift, data drift, and agentic behavioral drift. Structured accountability, risk-proportionate monitoring, and robust technical controls enable early detection and timely, well-documented corrective action, safeguarding the reliability, fairness, and trustworthiness of our AI systems throughout their lifecycle.

4. Fairness and Bias Management

SCBX Group is committed to ensuring that its AI models treat all demographic groups equitably and do not perpetuate existing inequalities or introduce new forms of discrimination. This is achieved through a structured, risk-proportionate framework — anchored in a standardized AI Impact Assessment (AIIA) and Risk Tiering process — with bias and fairness evaluations embedded across the AI lifecycle.
Outcome

Through this integrated People–Process–Technology approach — anchored in a standardized AI Impact Assessment and Risk Tiering framework — SCBX Group ensures that AI models across all types and origins are systematically and proportionately evaluated for bias. Risk-calibrated governance, robust testing methodologies, and well-documented mitigation processes uphold ethical standards, safeguard against discriminatory outcomes, and reinforce stakeholder trust in the fairness and integrity of our AI systems.

 

5. Appeals and Contestability

SCBX Group is committed to ensuring that individuals and entities affected by AI-driven decisions have access to a transparent, accessible, and responsive appeals process. This mechanism reinforces accountability, empowers users with a meaningful voice in outcomes affecting them, and sustains trust in our use of AI — whether the underlying model is developed internally or procured from a third party.

SCBX Group ensures that individuals and entities affected by AI-driven decisions — whether generated by internally developed or vendor-procured AI/Models — have a clear, accessible, and responsive pathway to challenge those outcomes and seek redress.

By requiring sufficient vendor explanation capabilities for Other AI/Models procured models and applying compensating controls where such evidence falls short, we ensure appeals can be meaningfully assessed regardless of model origin. This appeals to mechanism reinforce accountability, surfaces systemic issues for continuous improvement, and strengthens stakeholder trust in the fairness and integrity of our AI-enabled decision-making.

 

6. Sustainable AI Data Centers/Models

As a holding company, SCBX Group does not own and operate a dedicated private data center but employs the use of AI infrastructure on public clouds of well-respected data centers from internationally recognized companies. During the selection process of data center providers, the group has integrated sustainability considerations in the selection process to ensure that data center providers have established robust ESG targets and commits to implement applicable programs such as energy-efficient hardware, optimizing algorithms for lower energy consumption, and using renewable energy sources. By selecting providers with such goals, SCBX Group can contribute to a broader sustainability goal.

 

7. Systems Verifications

All programs are designed, developed, procures, deploys and oversee in compliance with internationally recognized responsible-AI standards and is aligned with the Bank of Thailand’s Policy Framework on AI systems Risk Management (September 2025) and applicable laws. These allow for enhanced credibility, demonstrating commitment to responsible AI, and assure stakeholders that the organization strictly adheres to best practices and regulatory requirements.

Explore
Planting Digital Seed

ทำความรู้จัก เมล็ดพันธุ์ดิจิทัล

Explore
Planting
Digital Seed

ทำความรู้จัก เมล็ดพันธุ์ดิจิทัล

Explore
Planting Digital Seed

Get to know Digital Seeds

Explore
Planting
Digital Seed

Get to know Digital Seeds

  • ความปลอดภัยไซเบอร์

  • เส้นทางการเรียนรู้ของ Digital Employee

  • การสร้างสรรค์นวัตกรรม

  • ศูนย์กลางแห่งความเป็นเลิศ (CoE) 3 ด้าน

  • ดิจิทัลโซลูชันเพื่อลูกค้าทุกกลุ่ม