Industries · Banking
AI inside a Zimbabwean bank
Banks are the one sector where the regulator has already written AI into its standards. The Risk Management standard names AI as a component of operational resilience; the Model Risk standard defines what must be in the register; the Cybersecurity Guideline requires prior approval and early notice on cloud. Start from those.
Sector figures
What the RBZ already requires of an AI system
| Instrument | What it says about AI and models | What it means for a project |
|---|---|---|
| Prudential Standard No. 01-2024/BSD Risk Management (effective 15 May 2024) | Para 7.2.7: AI is "a critical component of operational resilience management" presenting "both transformative opportunities and unique risks"; institutions should manage algorithmic bias, data privacy and cyber threats. Para 7.2.8: governance frameworks so AI systems are "transparent, ethical, and compliant", with ongoing monitoring and testing of AI models. Section 8 points model risk to PS 02-2023. | An AI policy, a monitoring regime and a place in the operational risk framework are expected, not optional. |
| Prudential Standard No. 02-2023/BSD Model Risk Management (effective 3 July 2023) | Defines a model as any quantitative methodology, system or approach that processes inputs into an estimate; requires a model register, materiality classification, board oversight of material models, independent validation before production, annual back-testing and validation submissions; external and group models are in scope. | Every LLM, scorecard and vendor-embedded model goes in the register with an owner and a validation record. Hosted-model version changes trigger re-validation. |
| Cybersecurity and Resilience Guideline (August 2025) | Lists AI/ML and cloud computing among emerging technologies (6.3); requires a risk-based framework, cyber risk impact assessment before deployment, and prior written approval from the Reserve Bank before new technology platforms or significant ICT changes (6.4); third-party due diligence, contracts, inventory (5.3–5.14); inform the RBZ early about cloud outsourcing of critical functions (5.12); report cyber incidents within 3 hours (4.30). | Sequence the regulator into the plan: early notice on cloud, written approval before go-live, vendor file complete, incident path tested. |
| AML/CFT/CPF Guideline No. 01-2025/BSSFS (June 2025) | Sets the compliance expectations that AI-assisted monitoring and KYC must serve. | AI may assemble evidence and prioritise alerts; the compliance officer's decisions and records remain the control. |
Three use cases with risk notes
- 01
KYC refresh and AML alert triage
A read-and-propose agent assembles a customer's existing records, adverse-media results and transaction patterns, drafts the periodic review, and ranks monitoring alerts by evidence for an analyst. No customer outcome is decided by the system.
Risk notes. Personal and often sensitive data: in-country hosting or a documented s.28 assessment; retrieval must respect analyst entitlements; the model goes in the register as material if alert ranking affects escalation; keep the analyst's decision as the recorded control for the AML guideline.
- 02
Credit decision support inside the s.25 boundary
Scoring and document extraction accelerate the application; a credit officer takes the decision. Where the bank wants a fully automated decision for a product, it obtains the applicant's consent to an automated decision at application and provides a human review route.
Risk notes. Act s.25 and SI 155 s.10(3) on solely automated decisions; PS 02-2023 independent validation and outcome analysis; bias monitoring under PS 01-2024 7.2.7; explainability sufficient for a customer complaint and for the 21-day breach report if data were mishandled.
- 03
In-country knowledge assistant for branches and the contact centre
Retrieval over policies, product manuals, fee schedules and procedure documents, with citations, hosted on the bank's own servers or in Zimbabwean colocation. Customer records are excluded from the index in the first phase.
Risk notes. Lowest data-protection exposure of the three; still a new technology platform requiring prior written approval (Guideline 6.4); index is a copy of documents with their own classification; log retention for staff queries.
SequenceMost banks that get this right run use case 03 first, because it builds the gateway, the index and the register with the least regulatory friction, then reuse those for 01 and 02. The full argument is in the banking briefing.
Sources
- RBZ Bank Supervision, Surveillance and Financial Stability Division — Banking Sector Report for the period ended 30 September 2025
- RBZ Prudential Standard No. 01-2024/BSD Risk Management (May 2024)
- RBZ Prudential Standard No. 02-2023/BSD Model Risk Management (July 2023)
- RBZ Cybersecurity and Resilience Guideline (August 2025)
- RBZ Guidelines, circulars and public notices (index page listing AML/CFT/CPF Guideline No. 01-2025/BSSFS, June 2025)
- Data Protection Act, Act 5 of 2021 (Cyber and Data Protection Act [Chapter 12:07]) — s.25, s.28; SI 155 of 2024 — s.10(3)