Home/ Compliance/ Indonesia AI Governance for Financial Services
Indonesia

Join data, banking, and payment governance around one runtime.

Separate UU PDP, OJK banking supervision, and Bank Indonesia payment-system obligations while preserving one traceable control and evidence path.

Applies to: Indonesian banks, fintechs, payment providers, data controllers, and supporting platforms Status: Binding laws and regulations plus OJK supervisory AI guidance Reviewed: 31 July 2026

Three workstreams, one governed execution path

Indonesia starts as one substantive page because the same financial-services workflow may simultaneously process personal data, sit inside an OJK-supervised bank, and interact with a Bank Indonesia-regulated payment service. The legal sources remain distinct even when the runtime evidence overlaps.

Law 27 of 2022

UU PDP

Personal-data rights, controller responsibilities, security, breach notification, and cross-border transfer governance apply across sectors.

UU PDP technical guide
Financial Services Authority

OJK banking AI governance

Binding IT and consumer-protection rules combine with OJK's 2025 AI governance guidance for banking supervision.

OJK technical guide
Central bank and payment regulator

Bank Indonesia

Payment service providers and payment-system infrastructure firms operate under PBI governance, security, risk, audit, and reporting expectations.

Bank Indonesia technical guide

Where the control evidence overlaps

Control areaUU PDP lensOJK / BI lensAxonFlow contribution
Personal dataPurpose, rights, safeguards, breach response, and transfers.Customer protection, banking secrecy, security, and operational risk.Configured NIK, NPWP, phone, and bank-account detection with policy and audit records.
System accountabilityController and processor responsibilities.Responsible owner, governance, reliability, and supervised operation.Tenant, system, actor, policy, and execution context linked to framework workflows.
Human interventionOrganizational safeguard for material processing decisions.Human oversight and accountable action in banking and payments.HITL approval records and licensed emergency controls.
Incident evidenceDiscovery, affected data, notification content, timing, and remediation.Operational incident reporting, containment, recovery, and audit evidence.Incident-oriented records and Enterprise breach-notification workflow support.
Cross-border processingTransfer basis and destination governance.Outsourcing, infrastructure, data, and operational risk controls.Enterprise transfer-basis and data-residency evidence fields; legal basis remains yours.
AuditabilityDemonstrate processing and safeguards.IS audit, readiness, retention, and regulator-facing evidence.Governed request records and OJK / BI / UU PDP-oriented exports.

An Indonesia-focused pilot

1. Trace data

Map NIK, NPWP, account, and customer data

Identify where data enters, which model or tool receives it, the transfer location, and the downstream system of record.

2. Place controls

Enforce policy before external access

Test allow, redact, block, and approval behavior before information reaches a model, connector, or payment action.

3. Join evidence

Correlate governance and business events

Connect AxonFlow decisions with banking, payment, customer-case, and infrastructure logs.

4. Exercise an incident

Test notification inputs and containment

Capture discovery time, data categories, affected subjects, remediation, approvals, and downstream correction.

5. Test transfers

Record destination and transfer basis

Verify that routing and evidence match the organization's approved cross-border processing decision.

6. Review gaps

Run readiness before assurance

Confirm retention, ownership, reviewer authority, missing metadata, and export completeness before audit or supervisory engagement.

Why these frameworks are not separate landing pages yet

Separate technical pages already preserve the implementation detail. On the landing site, one country page gives a buyer or platform team a coherent map without repeating the same policy, PII, approval, and audit story three times.

Split later when

  • Search data shows clearly distinct demand
  • Each framework supports substantial unique buyer guidance
  • Customer workflows require different architecture or control decisions
  • Independent pages can stay current without contradictory duplication

Keep together while

  • The same banking or payment workflow crosses all three
  • Most runtime controls and evidence paths are shared
  • The technical docs already provide framework-level depth
  • A country overview is the clearest entry point for procurement and platform teams

Test the control path against a real workflow.

Use the Evaluation license to assess policy enforcement, human review, evidence records, and deployment boundaries before a regulated rollout.