Governance
AI governance for Zimbabwean enterprises
A framework a board risk committee can adopt in one meeting: eight domains, each tied to a section of the Cyber and Data Protection Act, SI 155 of 2024 or a Reserve Bank standard, with the evidence an auditor will ask for.
Zimbabwe does not yet have an AI statute. The National Artificial Intelligence Strategy 2026–2030 launched in March 2026 sets direction but, as a Cabinet-approved strategy, creates no binding obligations on enterprises. What binds you today is older and broader: the Cyber and Data Protection Act (Act 5 of 2021, gazetted as the Data Protection Act [Chapter 11:22] and cited in its regulations as the Cyber and Data Protection Act [Chapter 12:07]), its 2024 licensing regulations (SI 155 of 2024), and for regulated financial institutions the Reserve Bank's Risk Management standard (2024), Model Risk Management standard (2023) and Cybersecurity and Resilience Guideline (August 2025). This page organises those obligations into eight domains you can score with the governance checklist.
01 · The eight domains
- 01
Accountability and policy
A board-approved AI policy; a named executive owner; AI inside the risk appetite statement; AI use cases classified by impact. Evidence: policy, minutes, risk appetite statement. Basis: Act s.24 (accountability); RBZ PS 01-2024 paras 7.2.7–7.2.8 (governance frameworks for transparent, ethical, compliant AI).
- 02
Model inventory and lifecycle
A register of every model, including vendor and embedded models, with owner, purpose, data, materiality and validation status; independent validation before production; change control. Evidence: the register, validation reports. Basis: RBZ PS 02-2023 (model register/inventory, paras 2.4.5, 2.4.17); ISO/IEC 42001 lifecycle controls.
- 03
Data protection under the CDPA and SI 155
Data controller licence in the correct tier; DPO appointed and certified; processing notified to the Authority; lawful basis and written consent for sensitive, biometric, genetic and health data; transfer outside Zimbabwe assessed and notified; processor contracts in writing. Evidence: licence, Forms DP1/DP2, DPIAs, contracts. Basis: Act s.11–13, s.18(7)–(8), s.28–29; SI 155 s.3–6, s.10, s.12–14.
- 04
Security and access control
Identity-bound access to models and data; prompt-injection and data-exfiltration controls; secrets management; logging; encryption in transit and at rest; penetration testing that includes the AI surface. Evidence: architecture, test reports. Basis: Act s.18(4); SI 155 s.16; RBZ Guideline paras 4.7–4.8, 6.4; OWASP Top 10 for LLM Applications 2025.
- 05
Vendors and third parties
Due diligence on every AI provider and its sub-processors; contract clauses for audit, data segregation, portability and exit; jurisdiction and sanctions screening; the Reserve Bank informed early of cloud outsourcing of critical functions. Evidence: due-diligence file, contracts, third-party inventory. Basis: RBZ Guideline paras 5.3–5.14, 6.4(b); Act s.18(7)–(8); SI 155 s.10(4)(f).
- 06
Human oversight and automated decisions
A rule for which decisions may be automated; consent or legal basis where s.25 applies; a human route to contest; documented approval gates for agents that act on systems. Evidence: decision inventory, customer-facing notices. Basis: Act s.25; SI 155 s.10(3), s.10(5)(f) (children).
- 07
Monitoring, audit trail and incidents
Prompt, retrieval and output logs retained with access controls; drift and quality monitoring; a breach path that meets 24 hours to POTRAZ and, for banks, 3 hours to the RBZ; a breach register. Evidence: log samples, incident runbook, register. Basis: Act s.19; SI 155 s.17; RBZ Guideline para 4.30; PS 01-2024 para 7.2.8 (ongoing monitoring and testing of AI models).
- 08
Skills, culture and change
Board and executive AI literacy; a trained DPO; staff guidance on approved and prohibited tools; a route to report concerns. Evidence: training records, acceptable-use standard. Basis: SI 155 s.10(1), s.13(2); RBZ Guideline section 7 (capacity building); Act s.31 (whistleblowing).
02 · Regulatory reference table
| Obligation | Applies to | Instrument | Reference |
|---|---|---|---|
| POTRAZ designated as the Data Protection Authority; regulates the conditions for lawful processing | All | Cyber and Data Protection Act | s.5, s.6(1)(a) |
| Processing must be lawful, fair, transparent, purpose-limited, adequate and not excessive, accurate, and retained no longer than necessary | All controllers and processors | Act | s.13(a)–(f) |
| Sensitive data only with written consent; genetic, biometric and health data prohibited without written consent (exceptions listed) | All | Act | s.11(1), s.12(1) |
| Data subject rights: to be informed, access, object, correction, deletion of false or misleading data | All | Act | s.14 |
| Appropriate technical and organisational security measures; processors must give sufficient guarantees; written contract with processor | All | Act | s.18(4), (7), (8) |
| Breach notification to the Authority within 24 hours | All | Act; SI 155 | s.19; SI 155 s.17(1) |
| Notify the Authority prior to any wholly or partly automated operation serving a purpose | All | Act | s.20(1) |
| Accountability: measures to comply and internal mechanisms to demonstrate compliance | All | Act | s.24 |
| Right not to be subject to a decision based solely on automated processing, including profiling, with legal or similarly significant effects (unless consent or law) | All | Act; SI 155 | s.25; SI 155 s.10(3) |
| Transfer outside Zimbabwe only where adequate protection is ensured; adequacy factors; derogations | All | Act | s.28(1)–(2), s.29 |
| Offences: contravening s.11, 13, 18(4), 24 or 28 — fine up to level 11 or imprisonment up to seven years, or both | Controllers, representatives, agents | Act | s.33(2) |
| Data controller licence required; apply on Form DP1; Authority decides within 14 days; valid 12 months; renew at least 3 months before expiry | Any person determining purposes and means of processing | SI 155 of 2024 | s.3–5 |
| Licence tiers by data subjects: T1 50–1,000; T2 1,001–100,000; T3 100,001–500,000; T4 over 500,000. Fees: T1 USD 50, T2 USD 300, T3 USD 500, T4 USD 2,500 (application USD 30 for T2–T4) | All licensees | SI 155 | s.6; Second Schedule |
| Notify the Authority of all processing activities, intended transfers outside Zimbabwe, and biometric or genetic processing | All licensees | SI 155 | s.10(2)(a)–(d) |
| Appoint a DPO and notify on Form DP2; qualifications and certification course; notify changes within 14 days | All licensees | SI 155 | s.12–14 |
| Security measures: risk assessments, policies, physical and technical measures across all data phases, ability to restore access, testing of effectiveness; zw-CIRT may advise | All | SI 155 | s.16 |
| 72-hour notice to data subjects where breach is high-risk; breach register; 14-day information responses; 21-day concluding report | All | SI 155 | s.17(3)–(5) |
| AI as a component of operational resilience; manage algorithmic bias, data privacy and cyber threats; governance for transparent, ethical, compliant AI; ongoing monitoring and testing of AI models | Banking institutions | RBZ Prudential Standard No. 01-2024/BSD Risk Management (effective 15 May 2024) | paras 7.2.7–7.2.8; section 8 |
| Model risk framework: board oversight of material models, model register, independent validation before production, annual back-testing and validation submissions, vendor and group models in scope | Banks, building societies, microfinance institutions | RBZ Prudential Standard No. 02-2023/BSD Model Risk Management (effective 3 July 2023) | Definitions; 2.1.3–2.1.5; 2.1.15; 2.4.5; 2.4.12; 2.4.17 |
| CISO appointed by the board; cyber incidents reported to the Reserve Bank within 3 hours; annual penetration testing; third-party due diligence, contracts and inventory; inform the RBZ early on cloud outsourcing of critical functions; AI/ML and cloud listed as emerging technologies; prior written approval before new technology platforms or significant ICT changes | Banking institutions, microfinance, payment system participants | RBZ Cybersecurity and Resilience Guideline (August 2025) | 3.8; 4.30; 4.5x (testing); 5.3–5.14; 6.3(e)–(f); 6.4 |
03 · Data protection under the Act: what changes for an AI programme
Three provisions do most of the work. Section 25 gives every person the right not to be subject to a decision based solely on automated processing that has legal or similarly significant effects; a credit decision, a claims rejection or an account closure produced by a model with no human in the loop needs the person's consent or a legal basis. Section 28 stops personal data leaving the country unless the destination ensures adequate protection, judged on the nature of the data, purpose and duration of processing, the recipient country's law and the security measures in place; hosted-model APIs in the United States or Europe are transfers, and SI 155 s.10(2)(c) obliges you to notify the Authority of the intention. Section 18 requires appropriate technical and organisational security measures and a written contract with any processor who offers sufficient guarantees; a model vendor that receives prompts containing personal data is a processor.
SI 155 converts these into administration. Licence tiers are set by the count of data subjects, so a bank, insurer or telco with more than 500,000 customers is a Tier 4 licensee (USD 2,500). The DPO must be certified through an Authority-approved course, and the controller must fund continuing professional development (s.10(1)). Breaches go to the Authority within 24 hours on Form DP3.
Note for the CIOThe Act's offence clause (s.33(2)) attaches criminal liability to contravening s.11, s.13, s.18(4), s.24 and s.28. Four of those five are exactly the sections an AI project touches: sensitive data, processing principles, security measures and cross-border transfer. Treat the data-protection review as a gate, not a sign-off.
04 · Accountability model
| Role | Owns | Evidence produced | Basis |
|---|---|---|---|
| Board / board risk committee | AI policy, risk appetite for AI, oversight of material models | Approved policy; quarterly model risk report | Act s.24; PS 02-2023 2.1.3–2.1.5 |
| Accountable executive (CIO, COO or CRO) | Implementation of the framework; model risk function resourcing | Model register; validation schedule | PS 01-2024 s.8.4; PS 02-2023 2.1.6 |
| Data Protection Officer | Compliance monitoring; DPIAs; contact point for data subjects and the Authority | DPIA register; Forms DP1–DP3 | SI 155 s.14 |
| Chief Information Security Officer | Security controls over the AI surface; incident response; 3-hour RBZ reporting | Test reports; incident log | RBZ Guideline 3.8, 4.30 |
| Model owner (business unit) | Purpose, data, performance, retirement of a specific model | Model file; monitoring results | PS 02-2023 Definitions (model owner) |
| Independent validator | Validation before production and on change; escalation to the board committee | Validation report | PS 02-2023 2.4.5–2.4.9 |
| Internal audit | Review of the validation function and of control effectiveness | Audit report | PS 02-2023 2.4.11; Guideline 3.24 |
05 · Model inventory
The RBZ defines a model as any quantitative methodology, system or approach that turns inputs into an estimate, with three components: input, processor and output. A large language model, a fraud score, a credit scorecard, a vendor's embedded "smart" feature and a spreadsheet macro all qualify. The standard requires a register of all models the institution has and has used, classification of material models, a model log of changes, back-up copies of code and documentation, and validation that is independent from development and use. Non-banks are not bound by the standard, but an insurer or telco that adopts the same register will find the CDPA notifications (SI 155 s.10(2)(a)) and vendor reviews fall out of it for free.
Minimum fields: identifier; name; owner; business purpose; decision it influences; inputs and data sources (with personal-data flag); model type and provider; hosting location; materiality rating; validation date and outcome; monitoring metrics; retirement date.
06 · Human oversight and automated decisions
Write down which decisions may be fully automated, which require a human to confirm, and which may only be recommended. Section 25 sets the outer boundary for decisions with legal or similarly significant effect; the RBZ Guideline's requirement for prior written approval of new technology platforms (para 6.4) sets an inner one for banks. For agents that act on systems, the approval gate belongs in the tool gateway, not in the prompt; see the enterprise agent patterns.
07 · Audit trail and incidents
Log every prompt, retrieved document identifier, tool call and output with the identity that initiated it, retained under access control for as long as the decision could be challenged. This is what lets you answer a data subject's access or objection request (s.14), reconstruct a breach for the 21-day report (SI 155 s.17(5)(c)) and evidence ongoing monitoring of AI models (PS 01-2024 para 7.2.8). Test the 24-hour and 3-hour reporting paths with a drill, not a policy.
08 · Questions boards ask
- Does an AI system need its own licence from POTRAZ?
- No separate AI licence exists. The licence attaches to the data controller: any person who determines the purposes and means of processing personal data must hold a data controller licence under SI 155 of 2024 s.3–4, in a tier set by the number of data subjects (s.6). An AI system that processes customer or employee data falls inside that licence and must be reflected in what you have notified to the Authority (s.10(2)(a)).
- Can we send customer data to a model hosted in South Africa or Europe?
- Only where the Act allows. Section 28(1) prohibits transfer to a foreign country unless an adequate level of protection is ensured there, assessed under s.28(2). Section 29 lists derogations, including unambiguous consent and contractual necessity. SI 155 s.10(2)(c) additionally requires you to notify the Authority of any intention to transfer or share data outside Zimbabwe. Banks must also inform the Reserve Bank early about outsourcing critical functions to cloud providers (Cybersecurity and Resilience Guideline para 5.12).
- Who is accountable when an AI system makes a decision?
- The data controller. Section 24 requires the controller to take all necessary measures to comply and to have internal mechanisms that demonstrate compliance to data subjects and the Authority. For banks, the RBZ Model Risk Management standard places oversight of material models with the board or a board committee (paras 2.1.3–2.1.5) and implementation with senior management. Assign a named model owner for every model in the register.
- Is a chatbot that answers customer questions an "automated decision"?
- Not if it only informs. Section 25 is triggered when a decision based solely on automated processing, including profiling, produces legal effects or similarly significantly affects the person, for example declining a loan, closing an account or rejecting a claim. Where that is the case you need the data subject's consent or a legal basis, and a human route to contest the outcome.
- Do we need a Data Protection Officer, and can the CISO do it?
- A data controller must appoint a DPO and notify the Authority on Form DP2 (SI 155 s.12). The DPO needs qualifications or experience in fields listed in s.13 (data science, information security, audit, law and others) and must complete an Authority-approved certification course. The Act defines the DPO as ensuring compliance "in an independent manner"; combining the role with a line function that the DPO must monitor weakens that independence. Failure to appoint carries a fine up to level 7 or up to two years (s.12(6)).
- What must a breach response plan contain for an AI system?
- A route from detection to the Authority within 24 hours (Act s.19; SI 155 s.17(1)) on Form DP3, a decision rule for the 72-hour notification of affected people where the risk is high (s.17(3)), a breach register (s.17(4)(b)), and the capacity to answer information requests within 14 days and submit a concluding report within 21 days (s.17(5)). Regulated banking institutions must also report cyber incidents to the Reserve Bank within 3 hours (Guideline para 4.30).
Sources
- Data Protection Act [Chapter 11:22], Act 5 of 2021 (gazetted text; cited in regulations as the Cyber and Data Protection Act [Chapter 12:07]) — hosted by Techzim, https://www.techzim.co.zw/zimbabwe-cyber-and-data-protection-act/
- Statutory Instrument 155 of 2024 — Cyber and Data Protection (Licensing of Data Controllers and Appointment of Data Protection Officers) Regulations, 2024 — POTRAZ
- RBZ Prudential Standard No. 01-2024/BSD Risk Management (May 2024)
- RBZ Prudential Standard No. 02-2023/BSD Model Risk Management (July 2023)
- RBZ Cybersecurity and Resilience Guideline (August 2025)
- African Law Matters — Strategy Without Statute: Reading Zimbabwe's National AI Strategy (27 July 2026)
- ISO/IEC 42001:2023 — AI management systems; NIST AI Risk Management Framework 1.0; OWASP Top 10 for LLM Applications 2025