Industries · Banking

AI inside a Zimbabwean bank

Banks are the one sector where the regulator has already written AI into its standards. The Risk Management standard names AI as a component of operational resilience; the Model Risk standard defines what must be in the register; the Cybersecurity Guideline requires prior approval and early notice on cloud. Start from those.

Sector figures

19
Banking institutions as at 30 September 2025: 14 commercial banks, 4 building societies and the POSB. With 8 deposit-taking and 312 credit-only microfinance institutions and 4 development finance institutions, the Reserve Bank supervised 343 institutions.
RBZ Banking Sector Report, 30 Sept 2025, Table 1
65.73%
Share of total deposits held by the five domestic systemically important banks (CBZ, CABS, Stanbic, Ecobank, FCB), which also held 65.51% of loans and 63.50% of assets.
RBZ Banking Sector Report, 30 Sept 2025, para 1.3
46.70%
Share of banking-sector liabilities that were foreign currency deposits. Total assets ZiG200.66 billion; deposits ZiG116.95 billion; loans ZiG71.05 billion; capital adequacy 31.71% against a 12% minimum; NPL ratio 3.07%.
RBZ Banking Sector Report, 30 Sept 2025, Table 2 and Figure 3

What the RBZ already requires of an AI system

RBZ instruments with direct bearing on AI in banking institutions, with the paragraphs that matter.
InstrumentWhat it says about AI and modelsWhat it means for a project
Prudential Standard No. 01-2024/BSD Risk Management (effective 15 May 2024)Para 7.2.7: AI is "a critical component of operational resilience management" presenting "both transformative opportunities and unique risks"; institutions should manage algorithmic bias, data privacy and cyber threats. Para 7.2.8: governance frameworks so AI systems are "transparent, ethical, and compliant", with ongoing monitoring and testing of AI models. Section 8 points model risk to PS 02-2023.An AI policy, a monitoring regime and a place in the operational risk framework are expected, not optional.
Prudential Standard No. 02-2023/BSD Model Risk Management (effective 3 July 2023)Defines a model as any quantitative methodology, system or approach that processes inputs into an estimate; requires a model register, materiality classification, board oversight of material models, independent validation before production, annual back-testing and validation submissions; external and group models are in scope.Every LLM, scorecard and vendor-embedded model goes in the register with an owner and a validation record. Hosted-model version changes trigger re-validation.
Cybersecurity and Resilience Guideline (August 2025)Lists AI/ML and cloud computing among emerging technologies (6.3); requires a risk-based framework, cyber risk impact assessment before deployment, and prior written approval from the Reserve Bank before new technology platforms or significant ICT changes (6.4); third-party due diligence, contracts, inventory (5.3–5.14); inform the RBZ early about cloud outsourcing of critical functions (5.12); report cyber incidents within 3 hours (4.30).Sequence the regulator into the plan: early notice on cloud, written approval before go-live, vendor file complete, incident path tested.
AML/CFT/CPF Guideline No. 01-2025/BSSFS (June 2025)Sets the compliance expectations that AI-assisted monitoring and KYC must serve.AI may assemble evidence and prioritise alerts; the compliance officer's decisions and records remain the control.

Three use cases with risk notes

  1. 01

    KYC refresh and AML alert triage

    A read-and-propose agent assembles a customer's existing records, adverse-media results and transaction patterns, drafts the periodic review, and ranks monitoring alerts by evidence for an analyst. No customer outcome is decided by the system.

    Risk notes. Personal and often sensitive data: in-country hosting or a documented s.28 assessment; retrieval must respect analyst entitlements; the model goes in the register as material if alert ranking affects escalation; keep the analyst's decision as the recorded control for the AML guideline.

  2. 02

    Credit decision support inside the s.25 boundary

    Scoring and document extraction accelerate the application; a credit officer takes the decision. Where the bank wants a fully automated decision for a product, it obtains the applicant's consent to an automated decision at application and provides a human review route.

    Risk notes. Act s.25 and SI 155 s.10(3) on solely automated decisions; PS 02-2023 independent validation and outcome analysis; bias monitoring under PS 01-2024 7.2.7; explainability sufficient for a customer complaint and for the 21-day breach report if data were mishandled.

  3. 03

    In-country knowledge assistant for branches and the contact centre

    Retrieval over policies, product manuals, fee schedules and procedure documents, with citations, hosted on the bank's own servers or in Zimbabwean colocation. Customer records are excluded from the index in the first phase.

    Risk notes. Lowest data-protection exposure of the three; still a new technology platform requiring prior written approval (Guideline 6.4); index is a copy of documents with their own classification; log retention for staff queries.

SequenceMost banks that get this right run use case 03 first, because it builds the gateway, the index and the register with the least regulatory friction, then reuse those for 01 and 02. The full argument is in the banking briefing.

Sources

  1. RBZ Bank Supervision, Surveillance and Financial Stability Division — Banking Sector Report for the period ended 30 September 2025
  2. RBZ Prudential Standard No. 01-2024/BSD Risk Management (May 2024)
  3. RBZ Prudential Standard No. 02-2023/BSD Model Risk Management (July 2023)
  4. RBZ Cybersecurity and Resilience Guideline (August 2025)
  5. RBZ Guidelines, circulars and public notices (index page listing AML/CFT/CPF Guideline No. 01-2025/BSSFS, June 2025)
  6. Data Protection Act, Act 5 of 2021 (Cyber and Data Protection Act [Chapter 12:07]) — s.25, s.28; SI 155 of 2024 — s.10(3)