Our Expert in Pakistan
No results available
The deployment of AI in financial services in Pakistan has moved from boardroom aspiration to urgent compliance challenge. The National AI Policy 2025, the Digital Nation Pakistan Act 2025, the State Bank of Pakistan’s evolving supervisory signals, and the Securities and Exchange Commission of Pakistan’s proposed algorithmic-trading framework have collectively created a new regulatory environment that every fintech founder, bank risk committee and investor must navigate before putting an AI model into production. This guide delivers the regulator-mapped, step-by-step checklists that compliance teams need right now, answering the primary compliance decision every regulated entity faces: can you deploy without prior approval, or do you need SBP or SECP clearance first?
Pakistan’s financial-services sector sits at the intersection of two fast-moving policy streams. On one side, the federal government has endorsed artificial intelligence as a national priority through the National AI Policy 2025 and the establishment of the Pakistan Digital Authority (PDA) under the Digital Nation Pakistan Act 2025. On the other, the SBP and SECP continue to exercise sector-specific prudential and market-conduct oversight that any AI deployment must satisfy.
The result is a layered compliance landscape. A fintech building AI-powered credit scoring, a bank deploying fraud-detection algorithms, or a broker-dealer automating order routing cannot simply follow one rulebook. Each must map its obligations across the national policy framework and its sectoral regulator. This guide provides the checklists, decision trees and contract-clause templates required to do that mapping efficiently and defensibly.
Primary compliance decision: Whether you need prior regulatory approval or can proceed with internal governance alone depends on your entity type, the risk tier of your AI model, and the specific regulator that oversees your licence. The sections below break this decision into actionable steps for SBP-regulated entities, SECP-regulated entities, and cross-cutting obligations under the Digital Nation Act and data-protection rules.
Understanding how the various policy instruments interact is the first step toward fintech AI compliance in Pakistan. There is no single “AI Act” that governs the entire financial sector. Instead, obligations arise from a combination of national policy, primary legislation and sectoral guidance.
The National AI Policy 2025, announced by the Ministry of Information Technology and Telecommunication (MoITT), sets out overarching principles for the responsible development and deployment of AI across all sectors. It emphasises transparency, accountability, data protection, and the alignment of Pakistan’s AI governance with international norms. Importantly, it directs sectoral regulators, including the SBP and SECP, to develop domain-specific rules consistent with these principles.
The Digital Nation Pakistan Act 2025 provides the statutory backbone. It establishes the Pakistan Digital Authority (PDA) with a mandate to coordinate digital governance across ministries and regulators. For financial-services entities, the Act’s significance lies in its provisions on data governance, digital infrastructure standards, and the legal recognition of digital processes, all of which underpin AI deployment.
Enforcement responsibility is distributed. The SBP retains primary authority over scheduled banks, microfinance banks, electronic money institutions (EMIs), and payment service providers. The SECP oversees broker-dealers, asset management companies, collective investment schemes, and trading platforms. The PDA, meanwhile, acts as a cross-sector policy coordinator rather than a direct enforcement body for financial services. In practice, this means that a fintech deploying AI must satisfy its primary sectoral regulator and remain consistent with the national policy overlay.
Pakistan’s National AI Policy explicitly draws on internationally recognised frameworks. The OECD Recommendation on Artificial Intelligence, first adopted in 2019 and updated in 2024, remains the de facto international benchmark for trustworthy AI. The table below maps the core OECD principles against their Pakistani regulatory equivalents, giving compliance teams a quick reference for gap analysis.
| OECD AI Principle | Pakistani Regulatory Equivalent | Primary Source |
|---|---|---|
| Transparency and explainability | National AI Policy transparency pillar; SBP customer-disclosure expectations | MoITT National AI Policy 2025; SBP guidance |
| Accountability | Board-level oversight requirements; PDA coordination mandate | Digital Nation Pakistan Act 2025; SBP prudential standards |
| Robustness, security and safety | Model validation, testing and kill-switch controls | SBP Financial Stability Review signals; SECP concept paper |
| Fairness and non-discrimination | Bias-testing obligations; consumer-protection standards | National AI Policy 2025; SBP consumer-protection framework |
| Human oversight | Human-in-the-loop requirements for high-risk decisions | National AI Policy 2025; SBP model-risk signals |
| Event | Date / Period | Significance for Financial Services |
|---|---|---|
| National AI Policy 2025 approved by MoITT | 2025 | Establishes national principles and directs sectoral regulators to issue domain-specific guidance |
| Digital Nation Pakistan Act 2025 enacted; PDA established | 2025 | Creates statutory framework for digital governance; PDA coordinates cross-sector implementation |
| SBP Financial Stability Review 2024 published (includes AI adoption survey findings) | 2024 | Provides baseline data on AI adoption among regulated financial institutions and signals supervisory expectations |
| SECP concept paper on algorithmic trading proposed | Published (see SECP press releases) | Signals pre-approval, surveillance and risk-management requirements for automated trading systems |
The State Bank of Pakistan has not yet issued a standalone, binding circular dedicated exclusively to AI model risk management. However, the SBP has communicated its supervisory expectations through multiple channels, including the Financial Stability Review 2024, NIBAF training programmes, and its existing prudential framework on technology risk and outsourcing. For compliance teams, the practical effect is clear: the SBP expects banks and regulated FIs to treat AI models with the same governance rigour applied to any material risk, and to be prepared to demonstrate that governance to supervisors on request.
The SBP AI guidance that emerges from these signals can be distilled into the following compliance checklist for any institution deploying AI in a production environment:
The decision tree for SBP-regulated entities turns on two factors: the risk tier of the AI model and the nature of the activity. Industry observers expect that high-risk AI applications, those making autonomous credit decisions, driving AML/CFT screening, or managing systemic payment flows, will attract the highest level of supervisory scrutiny. For these models, the likely practical effect of SBP’s current posture is that prior notification, and in some cases supervisor review of governance evidence, will be expected before production deployment. Lower-risk applications (internal process automation, chatbot routing for non-financial queries) are more likely to proceed under internal governance alone, provided the institution can evidence compliance on demand.
When engaging with the SBP on an AI deployment, whether proactively or in response to a supervisory request, institutions should prepare the following evidence pack:
The Securities and Exchange Commission of Pakistan has taken a more targeted approach, focusing its initial AI-related guidance on algorithmic and automated trading. The SECP’s proposed regulatory framework for algorithmic trading in Pakistan, published as a concept paper, signals that the Commission views automated trading systems as a priority area requiring pre-clearance and ongoing surveillance obligations.
Under the SECP’s proposed framework, entities seeking to deploy algorithmic trading systems will need to satisfy requirements that go well beyond simple technology approvals. The SECP AI regulation framework, as signalled in the concept paper, is expected to include the following obligations:
For SECP-regulated entities beyond the trading floor, asset management companies, collective investment schemes, insurance companies, the integration of AI into investment processes, customer onboarding or claims assessment raises governance and outsourcing questions. Early indications suggest the SECP will expect these entities to apply their existing outsourcing and corporate governance frameworks to AI deployments, with additional emphasis on model transparency, data security and the ability to demonstrate human oversight of material decisions affecting investors or policyholders.
| Regulator | Entity Type | Approval / Notification Required & Key Expectations |
|---|---|---|
| SBP | Scheduled banks, microfinance banks, EMIs, payment service providers | High-risk AI (credit, fraud, AML): prior notification expected; SBP may require governance evidence and supervisor review. Medium/low-risk: internal governance with evidence-on-demand readiness. |
| SECP | Broker-dealers, trading platforms, CIS managers, asset management companies | Algorithmic trading: pre-approval/registration with exchange and SECP + ongoing surveillance obligations. Other AI uses: existing outsourcing and governance frameworks apply, enhanced by transparency and auditability requirements. |
| PDA / MoITT | All entities (cross-sector policy overlay) | National AI Policy sets overarching transparency, accountability and data-protection obligations. Digital Nation Act establishes PDA for cross-sector coordination. No separate PDA approval process for financial services, obligations flow through sectoral regulators. |
One of the most frequently asked compliance questions concerns cross-border data transfers in Pakistan, specifically, whether customer data used to train or run AI models can be processed offshore. The answer requires navigating an evolving legal landscape where no single, comprehensive data-protection statute yet applies uniformly.
The Digital Nation Pakistan Act 2025 includes data-governance provisions and empowers the PDA to coordinate standards, but it is not a substitute for a standalone personal data protection act. The draft Personal Data Protection Act (PDPA) has been under consideration for several years. Until it is enacted, institutions must rely on a patchwork of sectoral rules (SBP data-residency expectations, SECP outsourcing requirements) and the general principles set out in the National AI Policy 2025, which emphasises data sovereignty, informed consent and purpose limitation.
In the absence of a comprehensive PDPA, the practical position for SBP-regulated entities is that customer financial data should, as a default, be processed and stored within Pakistan unless the institution can demonstrate adequate safeguards for offshore processing. The National AI Policy’s emphasis on data sovereignty reinforces this position. Where offshore processing is necessary, for example, because an AI vendor’s infrastructure is hosted outside Pakistan, institutions should implement the following controls:
| Control Mechanism | Description | Applicability |
|---|---|---|
| Standard contractual clauses (SCCs) | Binding contractual commitments between data exporter and importer covering security, purpose limitation and data-subject rights | All cross-border transfers |
| Encryption in transit and at rest | End-to-end encryption using industry-standard protocols for all customer data leaving the jurisdiction | All cross-border transfers |
| Anonymisation / pseudonymisation | Removing or masking personally identifiable information before data leaves Pakistan | Training data; analytics; model tuning |
| Onshore processing with offshore model | Running inference locally using a model trained offshore, so raw customer data never leaves the jurisdiction | High-sensitivity use cases (credit, AML) |
| Federated learning | Training models on distributed local datasets without centralising raw data offshore | Multi-jurisdiction deployments; collaborative AI projects |
Regardless of whether the PDPA is enacted, compliance teams deploying AI in financial services in Pakistan should conduct a Data Protection Impact Assessment (DPIA) for every AI model that processes personal data. The DPIA should document the lawful basis for processing (consent, contractual necessity or legitimate interest), the categories and volumes of data used, the risks to data subjects, and the mitigation measures in place. For consumer-facing AI, credit scoring, customer segmentation, marketing personalisation, informed consent will typically be the most defensible basis, supported by clear and accessible privacy notices.
Robust model governance is the single most important compliance investment for any institution deploying AI. Regulators across the SBP and SECP frameworks, and the overarching principles of the National AI Policy, converge on the expectation that institutions must be able to demonstrate end-to-end governance over every AI model in production. The following model governance checklist provides the minimum controls that compliance teams should implement:
The National AI Policy’s transparency pillar and international best practice both demand that AI-driven decisions be explainable to the people they affect. For consumer-facing models in financial services, loan approvals, insurance underwriting, fraud blocks, this means the institution must be able to provide a clear, non-technical reason for the decision when a customer asks. Compliance teams should establish tiered explainability standards: high-level plain-language explanations for customers, detailed technical explanations for internal risk committees, and full methodology disclosure for supervisors.
| Evidence Item | Purpose | Recommended Retention Period |
|---|---|---|
| Model design document | Demonstrates methodology, assumptions and intended use | Life of model + 5 years |
| Training data catalogue / metadata | Proves data provenance, legality and representativeness | Life of model + 5 years |
| Validation report (initial + periodic) | Evidences independent testing of accuracy, fairness and robustness | Life of model + 5 years |
| Performance monitoring logs | Demonstrates ongoing tracking of model drift and output quality | Rolling 3 years minimum |
| Bias-testing results | Proves testing for disparate impact across protected characteristics | Life of model + 5 years |
| Change-management log | Records all version changes, retraining events and rationale | Life of model + 5 years |
| Incident and override log | Captures model failures, human overrides and remediation actions | Rolling 5 years minimum |
| Board / committee approval minutes | Demonstrates governance oversight and risk-appetite alignment | Permanent |
Many fintechs and banks in Pakistan rely on third-party vendors for AI capabilities, from cloud-hosted machine-learning platforms to specialist credit-scoring or fraud-detection models. AI vendor due diligence is therefore a critical compliance step, not merely a procurement exercise. The following checklist should be completed before engaging any AI vendor:
The contractual framework for AI vendor engagements must go beyond standard IT outsourcing terms. The following clause categories address the specific risks of algorithmic risk management and AI deployment:
| Clause Category | Key Provisions | Risk Addressed |
|---|---|---|
| Warranties on model performance | Vendor warrants that the model meets agreed accuracy, fairness and robustness benchmarks at deployment and throughout the contract term | Model underperformance; regulatory non-compliance |
| Indemnities | Vendor indemnifies the institution against losses arising from defective model outputs, data breaches or IP infringement in training data | Financial loss; third-party claims; regulatory fines |
| Liability caps and carve-outs | Negotiated cap on vendor liability with explicit carve-outs for wilful misconduct, data breaches and IP infringement (uncapped or higher-cap items) | Inadequate recovery in the event of material failure |
| Audit rights | Institution retains the right to audit the vendor’s model, data-handling practices and security controls, directly or through an independent third party, with reasonable notice | Inability to evidence compliance to SBP/SECP supervisors |
| Model retraining / change notice | Vendor must provide advance written notice (e.g. 30 days) of any model retraining, methodology change or infrastructure migration, with right of institution to test and approve | Uncontrolled model changes affecting production outputs |
| IP and output ownership | Clear allocation of intellectual property rights in the model, training data, inference outputs and any derivatives created using the institution’s data | Disputes over data ownership; regulatory data-sovereignty concerns |
| Escrow and continuity | Source code and model weights held in escrow; defined transition-assistance obligations in the event of vendor insolvency or contract termination | Vendor lock-in; business continuity risk |
Investors evaluating AI-powered fintechs or approving internal AI production deployments need a focused due-diligence framework. The following checklist captures the minimum verification steps before funding or production sign-off:
Investment committees should treat the following as material risk indicators: absence of a model inventory; no independent validation of AI models; customer-facing AI decisions with no explainability mechanism; data processed offshore without documented safeguards; no board-level accountability for AI risk; and vendor contracts that lack audit rights or change-notification clauses. Any of these gaps signals a compliance deficit that could result in supervisory action, customer harm or reputational damage.
Moving from compliance planning to production deployment requires a structured timeline. The following phased roadmap covers a typical six-to-twelve-week implementation cycle for a regulated financial institution deploying AI in Pakistan:
When engaging a supervisor, whether proactively or in response to a request, prepare: an executive summary of the AI use case and its business rationale; the full model documentation and validation report; the governance framework and board approval evidence; the data-handling and residency confirmation; the vendor due diligence file; and the incident-response and rollback plan. Having this pack ready before a supervisor meeting demonstrates maturity and reduces the risk of protracted supervisory exchanges.
Deploying AI in financial services in Pakistan in 2026 is no longer a question of whether regulators will scrutinise your models, it is a question of whether your governance, documentation and vendor contracts can withstand that scrutiny when it arrives. The National AI Policy 2025, the Digital Nation Pakistan Act 2025 and the supervisory signals from both the SBP and SECP have created a compliance environment that rewards preparation and penalises ambiguity. Institutions that invest now in robust model governance, defensible data-handling practices and well-structured vendor agreements will be best positioned to deploy AI at scale, with regulatory confidence rather than regulatory risk.
Those seeking tailored guidance on fintech AI compliance in Pakistan should engage qualified legal experts with deep experience across banking regulation, capital markets and technology law.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Shazil Ibrahim at Chima & Ibrahim, a member of the Global Law Experts network.
posted 30 minutes ago
posted 54 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 4 hours ago
posted 4 hours ago
posted 5 hours ago
No results available
Find the right Advisory Expert for your business
Sign up for the latest advisor briefings and news within Global Advisory Experts’ community, as well as a whole host of features, editorial and conference updates direct to your email inbox.
Naturally you can unsubscribe at any time.
Global Law Experts is dedicated to providing exceptional legal services to clients around the world. With a vast network of highly skilled and experienced lawyers, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Global Advisory Experts is dedicated to providing exceptional advisory services to clients around the world. With a vast network of highly skilled and experienced advisors, we are committed to delivering innovative and tailored solutions to meet the diverse needs of our clients in various jurisdictions.
Send welcome message