Faulty transactions passed through
Faulty transactions remaining after controls
| Comparison metric | OFF | ON | Governance effect |
|---|---|---|---|
| Same baseline by design | |||
| Applications processed same portfolio | 100,000 | 100,000 | Same by design |
| Gross requested facility value same synthetic portfolio value | IDR 6.78 tn | IDR 6.78 tn | Same by design |
| Fault-affected transaction population same injected-fault transaction population | 57,254 | 57,254 | Same by design |
| Requested facility value linked to fault-affected population same injected-fault facility-value population | IDR 3.98 tn | IDR 3.98 tn | Same by design |
| Outcome comparison | |||
| Straight-through decisions lower can reflect intentional governance friction | 71,603 | 52,980 | Reduced by 18,623 (26.01%) |
| Straight-through rate automation retained | 71.60% | 52.98% | -18.62 pp |
| Total HITL volume human review volume | 28,397 | 38,542 | Increased by 10,145 (35.73%) |
| Faulty transactions reaching outcome stage lower is better; governance should intercept, redirect or contain these cases before final outcome | 57,254 | 1,055 | Reduced by 56,199 (98.16%) |
| Residual facility-value risk after controls gross requested facility value linked to the remaining faulty transaction population; not expected credit loss | IDR 3.98 tn | IDR 75.38 bn | Reduced by IDR 3.90 tn (98.10%) |
| Final decisions changed vs clean reference decision impact | 2,235 | 97 | Reduced by 2,138 (95.66%) |
| Facility value linked to changed decisions OFF exact; ON estimated from remaining changed-decision proportion | IDR 161.71 bn | IDR 7.02 bn | Reduced by IDR 154.69 bn (95.66%) |
| Control interventions governance action | 0 | 56,199 | Introduced 56,199 |
| Blocked actions least-privilege enforcement | 0 | 5,000 | Introduced 5,000 |
| Blocked AI decisions decision control | 0 | 15,000 | Introduced 15,000 |
| Fallback to approved configuration model/config containment | 0 | 40,000 | Introduced 40,000 |
| Held before booking final-integrity control | 0 | 10,145 | Introduced 10,145 |
| Unauthorized actions executed lower is better | 5,000 | 0 | Reduced by 5,000 (100.00%) |
| Adverse decisions without reason explainability / conduct control | 812 | 24 | Reduced by 788 (97.04%) |
| Decile | Loans | Average facility | Total facility | Approval | STP | Affected by faults | Still remaining | Share of residual value |
|---|---|---|---|---|---|---|---|---|
| D1 LOW_TICKET | 10,138 | IDR 11.3 mn | IDR 114.99 bn | 80.23% | 75.08% | 5,275 IDR 59.50 bn | 101 IDR 1.12 bn | 1.48% |
| D2 LOW_TICKET | 9,778 | IDR 19.7 mn | IDR 192.56 bn | 80.32% | 74.96% | 4,952 IDR 97.83 bn | 93 IDR 1.86 bn | 2.47% |
| D3 LOW_TICKET | 10,151 | IDR 26.8 mn | IDR 272.34 bn | 80.21% | 74.02% | 5,839 IDR 157.18 bn | 101 IDR 2.70 bn | 3.58% |
| D4 CORE_MASS | 10,013 | IDR 34.3 mn | IDR 343.53 bn | 80.34% | 74.22% | 5,893 IDR 202.11 bn | 100 IDR 3.43 bn | 4.55% |
| D5 CORE_MASS | 9,946 | IDR 42.8 mn | IDR 426.16 bn | 79.80% | 73.03% | 5,763 IDR 246.82 bn | 97 IDR 4.16 bn | 5.52% |
| D6 CORE_MASS | 9,924 | IDR 53.1 mn | IDR 526.78 bn | 80.42% | 73.00% | 5,861 IDR 311.33 bn | 105 IDR 5.58 bn | 7.40% |
| D7 CORE_MASS | 10,049 | IDR 66.3 mn | IDR 665.78 bn | 79.10% | 71.99% | 5,951 IDR 394.79 bn | 109 IDR 7.30 bn | 9.68% |
| D8 UPPER_MASS | 9,868 | IDR 84.7 mn | IDR 836.12 bn | 78.95% | 70.97% | 5,798 IDR 490.56 bn | 110 IDR 9.30 bn | 12.34% |
| D9 UPPER_MASS | 10,090 | IDR 116.4 mn | IDR 1.17 tn | 79.10% | 67.80% | 5,979 IDR 696.10 bn | 127 IDR 14.83 bn | 19.68% |
| D10 HIGH_TICKET | 10,043 | IDR 221.8 mn | IDR 2.23 tn | 76.41% | 61.02% | 5,943 IDR 1.32 tn | 112 IDR 25.09 bn | 33.28% |
| Segment | Loans | Average facility | Total facility | Affected cases | Residual cases | Residual facility value | Residual value share |
|---|---|---|---|---|---|---|---|
| LOW_TICKET | 30,067 | IDR 19.3 mn | IDR 579.88 bn | 16,066 | 295 | IDR 5.68 bn | 7.54% |
| CORE_MASS | 39,932 | IDR 49.1 mn | IDR 1.96 tn | 23,468 | 411 | IDR 20.47 bn | 27.16% |
| UPPER_MASS | 19,958 | IDR 100.7 mn | IDR 2.01 tn | 11,777 | 237 | IDR 24.14 bn | 32.02% |
| HIGH_TICKET | 10,043 | IDR 221.8 mn | IDR 2.23 tn | 5,943 | 112 | IDR 25.09 bn | 33.28% |
| Treatment route | Cases | Facility value linked to cases | What happens | Owner | When the case can close |
|---|---|---|---|---|---|
| Correct + reprocess CORRECTIVE | 260 24.64% of residual cases | IDR 18.49 bn 24.53% of residual facility value | Correct data, reason code, threshold or rule issue and re-run the affected application through the approved decision path. | Credit Operations + AI Governance | Corrected inputs/rules evidenced and reprocessed result passes applicable controls. |
| Hold + human review CONTAINMENT + HUMAN REVIEW | 579 54.88% of residual cases | IDR 40.83 bn 54.17% of residual facility value | Prevent automatic finalisation and assign the application to an accountable human reviewer. | Credit Operations / Underwriting | Human decision recorded with rationale; case either corrected/reprocessed or approved/declined under delegated authority. |
| Incident investigation DETECTIVE + CORRECTIVE | 46 4.36% of residual cases | IDR 3.55 bn 4.71% of residual facility value | Open an incident/root-cause investigation, preserve evidence, identify affected population and implement preventive actions. | AI Governance + Credit Risk / Incident Management | Root cause confirmed, actions completed, affected population treated and retest/closure evidence approved. |
| Stop before booking / disbursement PREVENTIVE + CONTAINMENT | 130 12.32% of residual cases | IDR 9.68 bn 12.84% of residual facility value | Keep the case from booking or disbursement while the high-risk exception is investigated and resolved. | Credit Risk + Operations | Exception cleared or application cancelled/declined; no uncontrolled disbursement occurs. |
| Post-booking remediation CORRECTIVE + CUSTOMER REMEDIATION | 40 3.79% of residual cases | IDR 2.83 bn 3.75% of residual facility value | For a case already booked, review the account, correct terms/data where required and apply customer/credit remediation and enhanced monitoring. | Credit Operations + Conduct / Customer Remediation | Customer/account remediation completed, approvals evidenced and account monitoring updated. |
Protocol: Register agent + owner + purpose + environment + risk tier → Grant only required data/tools/actions → Time-bound elevated privilege → Periodic recertification → Detect permission creep / expiry → Revoke or re-approve with evidence
Control test: 8/8 agents registered; 17 grants reviewed; 2 excess/expired detected and revoked; 0 unresolved.
Why it matters: Least privilege is not a one-time access matrix. Permissions can creep or outlive their business need.
Protocol: Bind identity to environment → Separate test/prod credentials and network routes → Deny production API/data access from non-production identity → Log boundary violations → Escalate repeated attempts
Control test: 3/3 unauthorized boundary attempts blocked; zero production escape.
Why it matters: A test agent must not silently become a production actor simply because it has a reachable endpoint.
Protocol: Discover unregistered AI/provider invocation → Match against approved inventory → Assess data/system access + intended use → Assign risk tier → Approve / restrict / reject → Onboard approved tool to IAM + logging → Periodically reassess
Control test: 1/1 unregistered provider attempts blocked; linked RC12 scope 5,000 applications.
Why it matters: Discovery alone does not govern shadow AI; the organization needs a decision and onboarding/rejection lifecycle.
Protocol: Approved source / registry → Pinned version → Artifact/model/feature hash check → Provider identity check → Dependency / release manifest review → Block mismatch → Fallback to last-known-good configuration → Record remediation evidence
Control test: 4 components checked; 1 mismatch blocked; last-known-good retained.
Why it matters: An approved model can still be paired with an unapproved dependency, provider or release artifact.
| Operating metric | Result | Status | What the evidence proves | Evidence source |
|---|---|---|---|---|
| AI agent inventory completeness | 8/8 | PASS | Every simulated agent has an owner, purpose, environment and risk tier before it can operate. | Agent registry snapshot |
| High-risk permission recertification | 17 grants reviewed | PASS | Access is periodically re-justified; two expired/excess grants were detected and revoked. | Access recertification + revocation log |
| Test / production boundary control test | 3/3 blocked | PASS | Non-production identities were prevented from becoming production actors. | Boundary-test / denied-access log |
| Shadow AI / unregistered-provider containment | 1/1 blocked | PASS | The unregistered provider attempt was discovered, assessed and blocked before escape; linked RC12 scope = 5,000 applications. | Provider discovery + approval/rejection record |
| AI component integrity gate | 4 checked; 1 mismatch blocked | PASS | The release candidate is checked beyond model version alone; a mismatch triggers block + known-good fallback. | Release manifest + hash/provider attestation + fallback record |
| Governance controls with explicit evidence trace | 8/8 | PASS | Each platform/system governance control records a trace statement showing what was checked and the result. | Governance control trace |
| Evidence-ledger sample completeness | 25 sampled events | PASS | Sampled decision/control events contain model, policy, AI output, governance output, oversight, intervention and evidence-hash fields. | Evidence ledger |
| Kill-switch control test | TRIGGERED + CONTROLLED FALLBACK | PASS | The test proves targeted suspension of the affected AI auto-finalisation path while cases continue through HITL/fallback. | Kill-switch event + routing/fallback log |
| Residual-case treatment assignment | 1055/1055 assigned | PASS | Every known residual faulty case is assigned a treatment path instead of being allowed to proceed automatically or remain unmanaged. | Residual-case treatment / case-management assignment log |
| Controlled restart protocol | NORMAL_AFTER_CONTROLLED_REACTIVATION | PASS | Restart is only allowed after incident analysis, corrective action, revalidation and independent approval. | Restart approval / revalidation record |
| Risk | Control | Framework mapping | ToD + rationale | ToE + rationale | Overall | Residual | How to improve |
|---|---|---|---|---|---|---|---|
| RC09 | SoD Gate + Independent Model Approval | BAI06 Managed IT Changes; MEA02 Managed System of Internal Control; MEA04 Managed Assurance COSO: Control Environment, Control Activities, Monitoring Activities | ADEQUATE (100.00%) Four-eyes segregation prevents the model developer from approving the same change; independent approval is required before release. 7/7 required design attributes are present. No design attribute is missing in the simulated control specification. | EFFECTIVE (100.00%) Simulation evidence: 1 intercepted / 1 tested; 0 exceptions. Pass rate 100.00% meets the Effective threshold ≥ 98%. | EFFECTIVE | 0 | Maintain independent approval and periodically recertify SoD; make self-approval technically impossible rather than policy-only. |
| RC01 | SoD + GATE 3 Model Registry | BAI06 Managed IT Changes; BAI10 Managed Configuration; MEA02 Managed System of Internal Control; MEA04 Managed Assurance COSO: Risk Assessment, Control Activities, Monitoring Activities | ADEQUATE (100.00%) The active model/version/hash is checked against the approved registry before automated decisioning, with a fallback to the last approved model. 7/7 required design attributes are present. No design attribute is missing in the simulated control specification. | EFFECTIVE (100.00%) Simulation evidence: 1 intercepted / 1 tested; 0 exceptions. Pass rate 100.00% meets the Effective threshold ≥ 98%. | EFFECTIVE | 0 | Add signed artifact/hash verification at deployment and automated rollback to last approved version. |
| RC02 | GATE 3 + HOTL Monitor | APO12 Managed Risk; BAI06 Managed IT Changes; MEA01 Managed Performance and Conformance Monitoring; MEA04 Managed Assurance COSO: Risk Assessment, Control Activities, Monitoring Activities | ADEQUATE (100.00%) Pre-deployment validation plus post-deployment performance monitoring jointly address calibration defects before and after release. 7/7 required design attributes are present. No design attribute is missing in the simulated control specification. | EFFECTIVE (100.00%) Simulation evidence: 20,000 intercepted / 20,000 tested; 0 exceptions. Pass rate 100.00% meets the Effective threshold ≥ 98%. | EFFECTIVE | 0 | Add monthly calibration-by-cohort monitoring, outcome backtesting and independent validation after material change. |
| RC03 | GATE 2 + GATE 3 | APO13 Managed Security; APO14 Managed Data; DSS06 Managed Business Process Controls; MEA02 Managed System of Internal Control COSO: Control Environment, Control Activities, Information & Communication | ADEQUATE (100.00%) Data-purpose and feature allow-list gates prevent unapproved proxy features from entering the approved scoring feature set. 7/7 required design attributes are present. No design attribute is missing in the simulated control specification. | EFFECTIVE (100.00%) Simulation evidence: 10,000 intercepted / 10,000 tested; 0 exceptions. Pass rate 100.00% meets the Effective threshold ≥ 98%. | EFFECTIVE | 0 | Automate feature-store allow-list checks and data-purpose attestations at every model release. |
| RC11 | GATE 3 Lineage / Hash Control | BAI06 Managed IT Changes; BAI10 Managed Configuration; MEA01 Managed Performance and Conformance Monitoring COSO: Control Activities, Monitoring Activities | ADEQUATE (100.00%) Hash and lineage checks detect material configuration changes even when the displayed version label is unchanged. 7/7 required design attributes are present. No design attribute is missing in the simulated control specification. | EFFECTIVE (100.00%) Simulation evidence: 1 intercepted / 1 tested; 0 exceptions. Pass rate 100.00% meets the Effective threshold ≥ 98%. | EFFECTIVE | 0 | Cryptographically sign model/config artifacts; alert on threshold/config changes even when version label is unchanged. |
| RC12 | IAM + GATE 3 Provider Registry | APO10 Managed Vendors; APO12 Managed Risk; APO13 Managed Security; MEA03 Managed Compliance with External Requirements COSO: Risk Assessment, Control Activities, Information & Communication | ADEQUATE (100.00%) Provider registry and access controls prevent an unregistered external model/provider from being invoked by the Decision Agent. 7/7 required design attributes are present. No design attribute is missing in the simulated control specification. | EFFECTIVE (100.00%) Simulation evidence: 1 intercepted / 1 tested; 0 exceptions. Pass rate 100.00% meets the Effective threshold ≥ 98%. | EFFECTIVE | 0 | Add egress allow-list, provider attestation and shadow-AI discovery/alerting. |
| RC08 | Dual IAM Permission Gates | APO13 Managed Security; DSS05 Managed Security Services; DSS06 Managed Business Process Controls; MEA02 Managed System of Internal Control COSO: Control Environment, Control Activities | ADEQUATE (100.00%) Dual permission gates constrain both human→agent invocation and agent→data/tool/action permissions under least privilege. 7/7 required design attributes are present. No design attribute is missing in the simulated control specification. | EFFECTIVE (100.00%) Simulation evidence: 5,000 intercepted / 5,000 tested; 0 exceptions. Pass rate 100.00% meets the Effective threshold ≥ 98%. | EFFECTIVE | 0 | Move to JIT/JEA permissions, short-lived scoped tokens and periodic user/agent access recertification. |
| RC04 | GATE 4 + HITL | APO12 Managed Risk; DSS06 Managed Business Process Controls; MEA02 Managed System of Internal Control COSO: Risk Assessment, Control Activities | ADEQUATE (100.00%) Decision uncertainty thresholds route near-threshold or low-confidence cases to HITL instead of allowing unsupported STP. 7/7 required design attributes are present. No design attribute is missing in the simulated control specification. | PARTIALLY EFFECTIVE (94.00%) Simulation evidence: 3,967 intercepted / 4,220 tested; 253 exceptions. Pass rate 94.00% is below Effective 98% but meets Partially Effective ≥ 90%. | PARTIALLY EFFECTIVE | 253 | Tune uncertainty/OOD referral thresholds and review false-approval/false-decline trade-offs using backtesting. |
| RC10 | GATE 4 Explainability | DSS06 Managed Business Process Controls; MEA02 Managed System of Internal Control; MEA03 Managed Compliance with External Requirements COSO: Control Activities, Information & Communication | ADEQUATE (100.00%) The adverse-decision gate requires a valid reason code before finalisation, making explainability an executable control. 7/7 required design attributes are present. No design attribute is missing in the simulated control specification. | PARTIALLY EFFECTIVE (97.04%) Simulation evidence: 788 intercepted / 812 tested; 24 exceptions. Pass rate 97.04% is below Effective 98% but meets Partially Effective ≥ 90%. | PARTIALLY EFFECTIVE | 24 | Make reason-code completeness a hard pre-finalisation condition and sample adverse decisions for quality, not only presence. |
| RC05 | GATE 6 Authority | EDM03 Ensured Risk Optimization; APO12 Managed Risk; DSS06 Managed Business Process Controls; MEA02 Managed System of Internal Control COSO: Control Environment, Control Activities | ADEQUATE (100.00%) Delegated-authority service hard-stops automated decisions above the approved automation limit and routes them to human authority. 7/7 required design attributes are present. No design attribute is missing in the simulated control specification. | EFFECTIVE (100.00%) Simulation evidence: 5,390 intercepted / 5,390 tested; 0 exceptions. Pass rate 100.00% meets the Effective threshold ≥ 98%. | EFFECTIVE | 0 | Bind every automated decision to a central authority service with hard fail-closed behavior and immutable authority evidence. |
| RC06 | GATE 5 HITL Override | DSS06 Managed Business Process Controls; MEA01 Managed Performance and Conformance Monitoring; MEA02 Managed System of Internal Control COSO: Control Environment, Control Activities, Monitoring Activities | ADEQUATE (100.00%) Override governance requires rationale, evidence and authority before a human reversal can become final. 7/7 required design attributes are present. No design attribute is missing in the simulated control specification. | INEFFECTIVE (88.02%) Simulation evidence: 713 intercepted / 810 tested; 97 exceptions. Pass rate 88.02% is below the Partially Effective threshold 90%. | INEFFECTIVE | 97 | Require structured override rationale/evidence, peer-rate anomaly monitoring and temporary restriction for repeat outliers. |
| RC07 | HOTL Monitor + Kill Switch | EDM03 Ensured Risk Optimization; APO12 Managed Risk; MEA01 Managed Performance and Conformance Monitoring; MEA02 Managed System of Internal Control COSO: Risk Assessment, Monitoring Activities | ADEQUATE (100.00%) Portfolio HOTL monitoring plus kill-switch authority is designed to detect systemic cohort drift and contain its portfolio-level magnitude. 7/7 required design attributes are present. No design attribute is missing in the simulated control specification. | INEFFECTIVE (33.37%) Simulation evidence: 341 intercepted / 1,022 tested; 681 exceptions. Pass rate 33.37% is below the Partially Effective threshold 90%. | INEFFECTIVE | 681 | Shorten monitoring latency, add cohort calibration/fairness triggers and pre-agreed kill-switch/restart criteria. |
| Model metric | Approved/reference | Observed/faulted path | Preferred |
|---|---|---|---|
| AUC How well the score ranks borrowers who default versus those who do not; 0.5 is random ranking and higher is better. | 0.6106 | 0.603 | higher |
| Gini A discrimination measure derived from AUC; higher means stronger rank ordering. | 0.2212 | 0.2061 | higher |
| KS Maximum separation between cumulative good and bad borrower distributions; higher means stronger discrimination. | 0.1606 | 0.1494 | higher |
| Average PD Average predicted probability of default across the portfolio. | 25.508 | 25.182 | context |
| Observed default rate Synthetic realised default rate used as the common outcome set for backtesting. | 26.549 | 26.549 | same outcomes |
| Calibration gap (pp) Difference between average predicted PD and realised default rate; closer to zero means better calibration. | -1.041 | -1.367 | closer to 0 |
| ECE (%) Expected calibration error across probability buckets; lower means predicted probabilities align better with outcomes. | 1.102 | 1.466 | lower |
| Brier score Mean squared error of probability forecasts; lower means better probabilistic accuracy. | 0.18855 | 0.18966 | lower |
| Error direction | OFF | ON |
|---|---|---|
| False approval vs clean reference Observed path APPROVES a case the clean reference would DECLINE — credit-loss / adverse-selection direction. | 1,164 | 20 |
| False decline vs clean reference Observed path DECLINES a case the clean reference would APPROVE — missed-good-business direction. | 1,071 | 77 |
Governance OFF vs ON is a controlled governance-state experiment, not a substitute for a model champion/challenger test.
| Risk event/theme | Inherent occurrence probability | Residual occurrence probability | Likelihood improvement | Time horizon | Financial impact anchor | Management insight |
|---|---|---|---|---|---|---|
| MODEL_AND_CHANGE | 40.00% band 30–50% | 3.00% band 0–5% | 92.50% 37.0 percentage-point reduction | 12 months | IDR 56.80 bn Direct financial anchor; not expected loss. | Controls reduce the configured 12-month occurrence likelihood from 40.0% to 3.0% (92.5% relative reduction). A residual 3.0% probability remains that a material model or configuration change event could occur within the next 12 months. The direct financial anchor is IDR 56.80 bn and the final impact category is 4 (High impact); non-financial consequences may increase severity. |
| DATA_AND_ACCESS | 40.00% band 30–50% | 3.00% band 0–5% | 92.50% 37.0 percentage-point reduction | 12 months | IDR 25.27 bn Direct financial anchor; not expected loss. | Controls reduce the configured 12-month occurrence likelihood from 40.0% to 3.0% (92.5% relative reduction). A residual 3.0% probability remains that an unauthorized data, privileged-access or unapproved-provider event could occur within the next 12 months. The direct financial anchor is IDR 25.27 bn and the final impact category is 5 (Very High impact); non-financial consequences may increase severity. |
| DECISION_AND_CONDUCT | 40.00% band 30–50% | 10.00% band 5–15% | 75.00% 30.0 percentage-point reduction | 12 months | IDR 0 Direct financial anchor; not expected loss. | Controls reduce the configured 12-month occurrence likelihood from 40.0% to 10.0% (75.0% relative reduction). A residual 10.0% probability remains that an unresolved decision-quality or conduct event could occur within the next 12 months. The direct financial anchor is IDR 19.63 bn and the final impact category is 3 (Moderate impact); non-financial consequences may increase severity. |
| AUTHORITY_AND_HUMAN | 22.00% band 15–30% | 10.00% band 5–15% | 54.50% 12.0 percentage-point reduction | 12 months | IDR 64.44 bn Direct financial anchor; not expected loss. | Controls reduce the configured 12-month occurrence likelihood from 22.0% to 10.0% (54.5% relative reduction). A residual 10.0% probability remains that an authority-bypass or unsupported-human-override event could occur within the next 12 months. The direct financial anchor is IDR 64.44 bn and the final impact category is 4 (High impact); non-financial consequences may increase severity. |
| FAIRNESS_AND_PORTFOLIO | 40.00% band 30–50% | 22.00% band 15–30% | 45.00% 18.0 percentage-point reduction | 12 months | IDR 15.21 bn Direct financial anchor; not expected loss. | Controls reduce the configured 12-month occurrence likelihood from 40.0% to 22.0% (45.0% relative reduction). A residual 22.0% probability remains that a cohort calibration or fairness-drift event could occur within the next 12 months. The direct financial anchor is IDR 15.21 bn and the final impact category is 3 (Moderate impact); non-financial consequences may increase severity. |
| Risk theme | Inherent | Residual + movement | Facility value footprint | Appetite metric | Appetite | Warning | Breach | Current | Status | Risk response | Control posture + immediate action | Escalation |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| MODEL_AND_CHANGE | High impact × Probable likelihood Risk position before the simulated governance/control treatment. | High impact × Improbable likelihood Likelihood ↓ through pre-deployment prevention and fallback Residual = risk remaining after controls. | IDR 1.71 tn linked to affected cases Direct decision-value anchor: IDR 56.80 bn → Low financial anchor. IDR 0 facility value remains linked to residual cases. Systemic model/change failure can affect portfolio integrity beyond direct decision-value impact. | Unauthorized material model/configuration change reaching production Metric used by management to judge whether this risk is tolerable. | 0 events Target maximum residual level accepted in normal operation. | 0 events Early-warning level that requires management attention before breach. | 1 events Threshold requiring formal response/restriction/escalation. | 0 events Observed value from this simulation run. | WITHIN APPETITE | ACCEPT Accept residual risk within appetite. Monitoring is maintained as an oversight/control activity, not treated as a separate risk-response category. | PREVENTIVE + RECOVERY Maintain release approval, approved model registry, independent validation and fallback readiness. If an unapproved change is detected, block the release and fall back to the last approved configuration. | Model Risk / AI Governance; Risk Committee if a confirmed escape occurs. |
| DATA_AND_ACCESS | Very High impact × Probable likelihood Risk position before the simulated governance/control treatment. | Very High impact × Improbable likelihood Likelihood ↓ through least privilege, allow-lists and provider registry Residual = risk remaining after controls. | IDR 1.36 tn linked to affected cases Direct decision-value anchor: IDR 25.27 bn → Low financial anchor. IDR 0 facility value remains linked to residual cases. Privacy, security, data-purpose and regulatory consequences can be severe even where direct credit decision value is limited. | Unauthorized privileged action, prohibited feature or unapproved provider escaping controls Metric used by management to judge whether this risk is tolerable. | 0 events Target maximum residual level accepted in normal operation. | 0 events Early-warning level that requires management attention before breach. | 1 events Threshold requiring formal response/restriction/escalation. | 0 events Observed value from this simulation run. | WITHIN APPETITE | ACCEPT Accept residual risk within appetite. Monitoring is maintained as an oversight/control activity, not treated as a separate risk-response category. | PREVENTIVE + DETECTIVE Maintain least-privilege access, feature/provider allow-lists and periodic access recertification. If an exception is detected, deny the action/provider, revoke excess privilege and isolate the affected path. | Security + Data Governance + AI Governance; executive notification for confirmed data exposure. |
| DECISION_AND_CONDUCT | Moderate impact × Probable likelihood Risk position before the simulated governance/control treatment. | Moderate impact × Remote likelihood Likelihood ↓ through uncertainty referral and adverse-reason gate Residual = risk remaining after controls. | IDR 355.83 bn linked to affected cases Direct decision-value anchor: IDR 0 → Very Low financial anchor. IDR 19.63 bn facility value remains linked to residual cases. Customer treatment, explainability and conduct consequences can raise impact above direct financial value. | Unresolved decision / conduct exceptions as % of applications Metric used by management to judge whether this risk is tolerable. | 0.1 % applications Target maximum residual level accepted in normal operation. | 0.2 % applications Early-warning level that requires management attention before breach. | 0.25 % applications Threshold requiring formal response/restriction/escalation. | 0.277 % applications Observed value from this simulation run. | BREACH | MITIGATE Reduce residual risk until it returns within appetite; restrictions and escalation are implementation actions, not separate risk-response categories. | DETECTIVE + CORRECTIVE Route uncertain cases to HITL and hold adverse decisions lacking a valid reason code. | Credit Risk / Conduct / AI Governance until residual rate returns within appetite. |
| AUTHORITY_AND_HUMAN | High impact × Occasional likelihood Risk position before the simulated governance/control treatment. | High impact × Remote likelihood Likelihood ↓ through hard authority service and override evidence Residual = risk remaining after controls. | IDR 483.22 bn linked to affected cases Direct decision-value anchor: IDR 64.44 bn → Low financial anchor. IDR 7.65 bn facility value remains linked to residual cases. Authority bypass and unsupported override create governance/accountability consequences beyond direct facility value. | Residual authority / unsupported override exceptions as % of applications Metric used by management to judge whether this risk is tolerable. | 0.05 % applications Target maximum residual level accepted in normal operation. | 0.1 % applications Early-warning level that requires management attention before breach. | 0.2 % applications Threshold requiring formal response/restriction/escalation. | 0.097 % applications Observed value from this simulation run. | ABOVE APPETITE | MITIGATE Reduce residual risk until it returns within appetite; restrictions and escalation are implementation actions, not separate risk-response categories. | PREVENTIVE + DETECTIVE Remove automated authority outside limits; challenge unsupported overrides and route to senior authority. | Credit Risk management; Risk Committee if breach threshold is exceeded. |
| FAIRNESS_AND_PORTFOLIO | High impact × Probable likelihood Risk position before the simulated governance/control treatment. | Moderate impact × Occasional likelihood Likelihood ↓ and impact ↓ through HOTL detection, kill switch and affected-cohort containment Residual = risk remaining after controls. | IDR 72.12 bn linked to affected cases Direct decision-value anchor: IDR 15.21 bn → Very Low financial anchor. IDR 48.10 bn facility value remains linked to residual cases. Systemic cohort fairness and regulatory/customer harm can raise impact above direct facility-value impact. | Absolute cohort approval-rate drift versus reference Metric used by management to judge whether this risk is tolerable. | 3 percentage points Target maximum residual level accepted in normal operation. | 5 percentage points Early-warning level that requires management attention before breach. | 8 percentage points Threshold requiring formal response/restriction/escalation. | 17.02 percentage points Observed value from this simulation run. | BREACH | MITIGATE Reduce residual risk until it returns within appetite; restrictions and escalation are implementation actions, not separate risk-response categories. | DETECTIVE + CONTAINMENT + CORRECTIVE Temporarily suspend AI auto-finalisation for the affected cohort/path, route those cases to HITL or approved fallback, and investigate drift/fairness drivers. | Risk Committee / senior management while outside appetite. |
| RC | Root cause | Risk response | Control type | Immediate action | Control change | Restriction | Owner | Retest method | Expected result | Closure criteria |
|---|---|---|---|---|---|---|---|---|---|---|
| RC04 | Low-uncertainty-confidence STP misrouting | MITIGATE ERM response strategy: accept, mitigate, transfer or avoid. Monitoring/restriction/escalation are implementation actions, not separate response categories. | DETECTIVE + CORRECTIVE How the control acts: preventive, detective, corrective, containment or recovery. | Route near-threshold/uncertain cases to HITL. | Tune uncertainty/OOD referral threshold using false-approval/false-decline trade-off. | Mandatory HITL while residual exception rate is above appetite. | AI Governance / Credit Risk | Same seed/comparable population → reinject low-confidence misrouting → rerun ToE; target ≥98% pass and residual rate within appetite. | ToD remains adequate; ToE ≥98% or approved threshold; residual risk within theme-specific appetite. | Evidence of completed action + successful retest + residual risk within appetite + independent/challenge sign-off where required |
| RC10 | Missing adverse-decision reason code | MITIGATE ERM response strategy: accept, mitigate, transfer or avoid. Monitoring/restriction/escalation are implementation actions, not separate response categories. | PREVENTIVE + DETECTIVE How the control acts: preventive, detective, corrective, containment or recovery. | Hold adverse decisions missing a valid reason code. | Hard pre-finalisation reason-code completeness and quality checks. | No adverse decision finalisation without usable explanation. | AI Governance / Credit Risk | Inject missing/invalid reason codes; target ≥98% interception and residual rate within appetite. | ToD remains adequate; ToE ≥98% or approved threshold; residual risk within theme-specific appetite. | Evidence of completed action + successful retest + residual risk within appetite + independent/challenge sign-off where required |
| RC06 | Unsupported human override | MITIGATE ERM response strategy: accept, mitigate, transfer or avoid. Monitoring/restriction/escalation are implementation actions, not separate response categories. | DETECTIVE + CORRECTIVE How the control acts: preventive, detective, corrective, containment or recovery. | Challenge unsupported overrides and require evidence before finalisation. | Structured rationale/evidence plus peer-rate anomaly monitoring. | Restrict repeat outlier reviewers pending investigation. | AI Governance / Credit Risk | Replay override anomalies; target ≥98% effective interception and residual exception rate ≤ theme appetite. | ToD remains adequate; ToE ≥98% or approved threshold; residual risk within theme-specific appetite. | Evidence of completed action + successful retest + residual risk within appetite + independent/challenge sign-off where required |
| RC07 | Cohort calibration / fairness drift | MITIGATE ERM response strategy: accept, mitigate, transfer or avoid. Monitoring/restriction/escalation are implementation actions, not separate response categories. | DETECTIVE + CONTAINMENT + CORRECTIVE How the control acts: preventive, detective, corrective, containment or recovery. | Suspend affected auto-decision path and make HITL mandatory for the cohort. | Tighter cohort drift/fairness monitoring, recalibration and kill-switch criteria. | No controlled restart until independent validation and appetite re-entry. | AI Governance / Credit Risk | Reinject cohort drift with same monitoring checkpoint; verify trigger latency, containment, fairness drift ≤3pp and ToE ≥98% before restart. | ToD remains adequate; ToE ≥98% or approved threshold; residual risk within theme-specific appetite. | Evidence of completed action + successful retest + residual risk within appetite + independent/challenge sign-off where required |