Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
Blog

How Standard Chartered Is Grounding Its AI Ambitions in Data Governance

By TheFinanceBase Team8 min read

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Standard Chartered’s approach to scaling AI is built around a constraint: models should use data that is fit for a defined purpose, accessible under the right controls and subject to human accountability. The bank combines central governance and shared AI capabilities with business-led use cases, rather than treating a larger model or more prompts as proof of progress.

That approach matters to customers because banking AI can touch sensitive financial information and workflows involving service, risk and compliance. The bank describes a central AI Factory and stronger data foundations as part of its current model; its 2025 disclosures also put responsible-AI governance within the Chief Data Office and describe reporting to the Audit Committee. These are the bank’s stated controls, not a guarantee that every AI use is risk-free or compliant in every market.

From “data-driven” to data for a defined outcome

When Mohammed Rahim became Standard Chartered’s group chief data officer in December 2024, he described a shift away from using “data-driven” as a goal in itself. The emphasis, as reported in an April 2025 interview, was on using data to achieve a specific business or client outcome. That distinction is important: accumulating data does not make it useful for a model. It must be relevant to the task, sufficiently reliable, representative of the people or conditions involved, and permitted for that use.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For a bank, this is more than a data-quality exercise. Personal and financial information is sensitive, and its use may be constrained by privacy laws, security requirements and local data-residency rules. A model can also produce plausible but unsuitable results when its inputs are incomplete, stale or no longer representative. Standard Chartered’s stated approach treats governance as part of how AI is designed and operated, rather than a final compliance check.

A central AI Factory with business-led applications

Standard Chartered’s current public description identifies a centralised AI Factory as a capability for building and deploying AI solutions. The bank also describes data foundations, transparent governance and human accountability as pillars of its approach. An earlier report described a hub-and-spoke operating model: a central function supplies common standards, platform capabilities and oversight, while business teams develop use cases closer to their workflows.

The aim is to combine the advantages of central control and distributed execution. Central governance can make standards more consistent, reduce duplicated effort and improve enterprise-wide visibility. Business teams, meanwhile, are closer to the customer problems and operational details that determine whether an application is useful.

Neither side is sufficient alone. A purely central model can create approval bottlenecks or controls poorly matched to frontline work. Fully decentralised development risks inconsistent documentation, duplicated systems, weak monitoring and unapproved “shadow AI.” The reported model seeks a balance, but public disclosures do not establish that every team has the same degree of autonomy or that every AI workload runs on one platform. A central AI Factory should not be confused with a single central model for the entire bank.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Data foundations: access, suitability and drift

In April 2025, Standard Chartered described modernising its bank-wide data lake and developing a central AI platform. The reported design included access controls shaped by a user’s role, geography and data-residency requirements, as well as consideration of the balance between on-premises and cloud infrastructure. The underlying principle is to make data usable without making it universally visible.

That balance is especially important in a multinational bank. Bringing data together can improve discovery and reuse, but a central repository does not by itself settle questions about local law, purpose limitation, retention, deletion or cross-border transfers. Fine-grained permissions and jurisdiction-aware controls still have to be enforced. A single architecture must accommodate different rules and sensitivity levels.

Data also has to remain suitable after a model is deployed. The 2025 interview offered a travel-related example: during the Covid-19 period, travel data fell sharply. An algorithm using those records could stop offering air-miles credit cards, even if the underlying transaction data was accurate. In other words, correct data is not always representative data.

Monitoring for drift means asking whether the data and its relationship to the desired outcome still reflect current conditions. Has the customer population changed? Are some groups underrepresented? Has the environment changed? Is the model still producing useful results? Depending on the answer, a bank may need to change data inputs, features, thresholds, model logic or even the business policy—not simply refresh a database. Clear ownership is also needed for reviewing changes and deciding whether retraining or suspension is warranted.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SC GPT: broad enablement, not proof of impact

SC GPT illustrates the productivity-enablement layer of the strategy. Computer Weekly reported in April 2025 that the tool was available to 70,000 employees across 41 markets and had processed more than 150,000 prompts at the time of its interview. Those are historical rollout figures, not current usage statistics.

Standard Chartered’s current AI page describes SC GPT as a bespoke enterprise large language model used alongside enterprise software subscriptions. The page also says more than 50,000 employees have completed over 225,000 tailored AI training courses. Training-course totals are a separate measure and should not be conflated with SC GPT users or prompt volume.

These figures indicate an effort to build access and literacy; they do not, on their own, show improved productivity, customer outcomes or financial returns. An employee tool used for drafting or summarising should also not automatically be governed like a system that influences a credit decision, customer eligibility, fraud alert or hiring outcome. Controls should reflect the potential impact, sensitivity of the data, degree of autonomy and reversibility of a system’s output.

Practical use cases, from service assistance to risk

One specific example reported in 2025 was an AI assistant for contact-centre staff. It made policy documents queryable so an agent could find guidance on a complex question, such as the implications of repaying a loan early. The stated aim was quicker, more accurate customer service—not monetising the information itself.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Standard Chartered’s current public material lists approved or active use-case areas that include customer engagement, operational efficiency, risk management, onboarding, employee engagement, management reporting and talent acquisition. It also refers to cross-border trade, affluent-client advisory and engineering. These areas have different risk profiles: an assistant that helps an employee locate a policy is not equivalent to an automated system that affects a customer’s eligibility or a compliance decision. The bank’s disclosures identify areas of activity and intent, but do not provide quantified outcomes for each application.

The outcome test should therefore be concrete. Does an application reduce handling time or errors? Does it improve first-contact resolution, risk detection or compliance workflows? Does it preserve customer satisfaction and access? Without such evidence, the presence of a use case demonstrates deployment, not proven benefit.

Governance and human accountability

Standard Chartered’s 2025 Directors’ Report says responsible-AI governance is led by a dedicated team within the Chief Data Office, which centrally governs AI use cases. The bank says its approach aligns with the Monetary Authority of Singapore’s FEAT principles and the Hong Kong Monetary Authority’s BDAI guidelines. Those statements describe the bank’s alignment; they are not independent certification or a blanket assurance of compliance across all jurisdictions.

The same report says the Audit Committee receives twice-yearly reports on Data Risk, including responsible AI. Earlier reporting described a responsible-AI council drawing on data privacy, cyber security, architecture governance and risk management, with models assessed against a framework before deployment, particularly for privacy and potential bias. Together, these disclosures point to governance that should extend beyond a committee or pre-launch approval: use-case intake and classification, privacy and security review, model-risk assessment, bias testing, approval, monitoring, incident handling and senior oversight.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Human accountability is another stated principle. Standard Chartered says human judgement remains fundamental in risk management, regulatory compliance and client outcomes. In practical terms, employees need to verify outputs, understand when not to use AI, protect confidential information and escalate errors. A human reviewer is meaningful only if they have the information, time and authority to challenge a system—not merely a responsibility to approve its output.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Generative, agentic and third-party AI raise different risks

The 2025 interview said the bank was refreshing its responsible-AI framework to address generative AI, agentic AI and open-source models, including questions about hosting, bias and security. These categories bring distinct concerns:

  • Generative AI can hallucinate, expose data through prompts, produce unreliable summaries or be manipulated by prompt injection.
  • Agentic AI may take actions through connected tools, so excessive permissions, unclear workflow boundaries or weak human checkpoints can turn a mistaken answer into an operational error.
  • Open-source models require scrutiny of provenance, licensing, update cycles, security and who is responsible for support.
  • External foundation models and cloud services add supplier, data-processing, retention, model-change and service-availability questions.

The bank has not publicly stated a blanket rejection of open-source models. Its disclosures support the narrower point that these models and deployment choices need risk assessment.

Standard Chartered’s AI ecosystem is not solely an internal build. Its current AI page describes engineering use of GitHub Copilot, Claude Code and its aXess AI platform for agentic workflows and orchestration. The 2025 annual report says the bank signed a strategic partnership with Alibaba in July 2025 to deploy Alibaba Cloud AI technology in client service, sales intelligence, risk management and compliance. The partnership also broadens the stated commercial use cases to workforce upskilling.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

External technology can provide capabilities faster than building everything in-house, but it makes third-party governance essential. Buyers and operators need to know where data is processed, what leaves the institution, whether prompts or outputs are retained or used for model training, how model updates are tested, what audit rights exist, and what happens if terms or service availability change. Standard Chartered’s annual report recognises that specialist partnerships increase third-party and model risks and require enhanced due diligence.

What the approach does—and does not—establish

Standard Chartered’s disclosures show an evolving enterprise model: central governance and shared capabilities, business-oriented applications, a focus on governed data and stated human accountability. They do not establish that every system is centrally built, that every AI use has the same controls, or that the bank has published quantified returns from its deployments.

Nor does a large employee rollout, an AI Factory or a set of principles prove that outcomes are safe or effective. The relevant evidence is whether monitoring catches drift, access controls work across jurisdictions, employees can challenge outputs, supplier risks are managed and customer-impacting systems perform as intended. Governance should make useful applications possible at a risk-appropriate pace; it should not impose identical friction on a low-risk drafting assistant and a high-impact decision system.

The most meaningful measure of progress is therefore not the number of prompts, models or training courses. It is whether Standard Chartered can demonstrate better client service, operational efficiency, risk management and compliance while maintaining privacy, security and clear accountability.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sources: Computer Weekly’s April 2025 interview; Standard Chartered’s AI overview, 2025 Directors’ Report, 2025 Annual Report and annual-report discussion of AI and third-party risk.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.