MAS steers debate on ethics of AI, Big Data; kicks off industry consult
Intel from sector likely to shape regulatory guidelines amid rising use of AI and machine learning by financial institutions
Singapore
THE Monetary Authority of Singapore (MAS) is seeking intel from the financial industry on potential ethical pitfalls in the use of artificial intelligence (AI) and data analytics - with such consultation likely to lead to regulatory guidelines in this nascent space, The Business Times has learnt.
This comes amid an increasing use of AI and machine learning by financial institutions that promises stronger compliance standards as well as more efficient sales targeting, but also carries a danger that the use of predictive analytics can be predatory, or create financial exclusion.
David Hardoon, chief data officer, MAS, told BT that the regulator is working with the industry to explore the implications of the growing use of AI and data analytics in the financial sector by financial institutions and fintech companies.
"Our objective is to foster innovative uses of AI and data analytics that take into account fairness, ethics, accountability and transparency in delivering services to customers," Dr Hardoon told BT.
"The nascent use of AI and data analytics in the financial sector gives us an opportunity to move ahead of the curve and set the right conditions for its ethical and proper use. We look forward to working with the industry and the public to understand the opportunities and challenges ahead."
MAS itself has set aside S$27 million for a grant to promote the adoption and integration of AI and data analytics in financial institutions.
Banks in Singapore have already found benefits from using better forms of data analytics. About a decade ago, OCBC was using hypothesis testing for its marketing campaigns, and the successful sales conversion rate was a mere 1.5 per cent. For some of the bank's real-time campaigns today, conversion rates have gone to as high as 60 per cent, with the average at about 20 per cent.
OCBC is now using more AI and machine learning in the area of compliance, extending its testing with a fintech firm to boost the bank's efficiency and accuracy in the detection of suspicious transactions. Its earlier test with the fintech's technology, using a year's worth of OCBC corporate banking data, found that it was able to reduce the number of alerts that did not require further review, by 35 per cent. The accuracy rate of identifying suspicious transactions also increased by more than four times.
DBS has launched several Big Data projects, and one significant test that has helped to rein in its ATM network.
It runs the world's busiest ATM network, with some 20,000 monthly transactions done per machine. It has sharply reduced the number of cases of ATMs running out of cash, by monitoring cash withdrawals at near real-time pace to deploy cash-refill trucks at the best possible time. It has also investigated rare cash withdrawals at certain spots - one ATM was suddenly neglected because the escalator next to it changed direction.
UOB uses Big Data to go through thousands of dining transactions per day paid with UOB cards, and customises dining recommendations based on customers' preferences and location. Insurance companies are also tying up with fintechs looking at Big Data. Prudential and Great Eastern are working with data analytics startup Sqreem to pilot projects. Sqreem, a Singapore-based fintech, claims to have built the world's largest AI platform.
But Mark Jansen, data and analytics leader, PwC Singapore, pointed out that of "paramount concern" for regulators is the protection of societies' broader interests.
"The data revolution within which we are experiencing is enabling a massive breakthrough in many fields from autonomous vehicles, to healthcare and safety. On the flip side, individuals feel - and rightly so - more exposed, as big companies now know and have more data than ever before," said Mr Jansen.
"This has societal ramifications through potential inclusion or exclusion of people based on their characteristics or even DNA. In considering this, care is required. Understanding the profile of people is important as it brings more precision and efficiency in servicing the needs of the community. (But) the exclusion of some, for example in not providing medical insurance for certain people, is not necessarily a desired outcome."
The European financial regulators put out a discussion paper late last year to discuss the ethics of Big Data used by financial institutions, noting not just the risks of aggressive marketing practices, but also of discriminatory practices. One example cited was in flood insurance, where the use of zip codes to see if a home owner qualifies for insurance, may be replaced by predictive satellite images or heat maps. Homeowners living in areas that are less prone to flooding could then qualify for insurance coverage. But in general, data analytics could also lead to higher premiums for certain customers with high risks.
"The increasing individualisation of risk profiles could have, to a certain extent, implications for the principle of solidarity and risk pooling in the insurance sector."
Both DBS and OCBC have told BT they are wary of overreaching in their use of data. DBS has said it thinks of the use of data as a form of "stewardship" of the relationship with its customer. OCBC, meanwhile, has scaled back from rapid location-based marketing. It used to send location-based marketing to customers the second it sees where they have swiped an OCBC credit card, but has eased up on the "creep" factor.
On the issue of data security, KPMG Singapore's head of cybersecurity Daryl Pereira said regulators can set up a Big Data management policy to define how much data should be stored, and to establish processes to deal with breaches.
That being said, there are already key principles of data management that are covered within the existing MAS technology risk management guideline requirements, said Mr Pereira. They include ensuring confidentiality and authorisation, such that data is only available to the people intended to use or see it.
MAS has already specified timely reporting on security breaches and root-cause analysis by financial institutions here. The existing guidelines state financial institutions should notify MAS of all relevant incidents, including data breaches, within one hour upon discovery of the incident.
Given the existing regulatory requirements on financial institutions in the area of cybersecurity, what may attract even more scrutiny in time are non-financial firms working with copious amounts of data as well.
"Data is seen now as the 'new oil' and a critical asset. When and if this is stolen, it is as serious as any other theft and should be reported to the authorities," said PwC's Mr Jansen. "What we have seen less of is this (regulation) broadening to other large data owners, whose data is perhaps even more valuable and could have a greater impact if lost."
TRENDING NOW
Could stablecoins be the future of money?
Once staunchly pro-China, Malaysian Chinese businesses are now distancing themselves from Beijing
Vietnam’s data-centre investment rush faces reality check on power and site constraints
‘My grandfather’s legacy’: Sherman Kwek lays out three-year plan for CDL to drive returns