Get the hottest Fintech Hong Kong News once a month in your Inbox
AI has outgrown the role of an assistant, now moving money, approving transactions, and carrying out multi-step tasks with little to no human input in every loop. These agents now behave more like participants in the business.
Now, when a person makes a decision, accountability is obvious. But when an AI agent makes thousands of decisions a day on your behalf, your organisation has to answer three things.
What did the AI do, why did it do it, and who is answerable for the outcome?
Today, especially for compliance, risk, and fraud leaders who ultimately answer to a regulator when deploying AI, the question of AI governance in APAC has shifted to what AI is doing on their behalf and whether they can prove it.
The instinct to pin every action to a human is already near-universal. Sumsub’s latest APAC State of Digital Trust: AI Governance Benchmark report finds that 98.6% of organisations say they are very or somewhat likely to adopt software that traces AI actions back to a responsible human identity.
But wanting that traceability is not the same as being ready for it.
The report also measures just how prepared organisations across Asia Pacific really are. A quantitative survey reached 720 senior professionals in technology, product, risk, compliance, and operations across nine Asia-Pacific markets and four sectors.
It scored each organisation from 0 to 100 across three pillars: Autonomy, Responsibility, and Traceability, where a higher score signals more advanced governance.
When AI is Questioned, Proof Matters More Than Performance
Businesses worry most about incorrect and unreliable decisions when AI acts on their behalf, topping the list of concerns at 52% in the report.
Regulatory and compliance risk follow at 44%, data quality or input issues at 43%, and lack of transparency at 33%.
Those top four concerns have the one underlying fear, which is that the AI can produce an output that no human can yet trust nor defend.
Businesses are, in other words, worried about undetectable failure. This is where an AI decision looks fine and only reveals itself as a problem once a third-party, like a regulator, looks into it.
The irony is that organisations have correctly identified their concerns, yet built less around precisely that danger.
The Sumsub report indicates that Traceability lags behind Autonomy and Responsibility in every market and sector surveyed. Autonomy and Responsibility both sit close to 70, while Traceability drops to 61.0.
Sumsub calls it the Accountability Asymmetry: the distance between how fully organisations own their AI’s decisions and how well they can prove what those decisions actually were.
The gap is seemingly all about proof. While 95% of respondents are confident they can explain an AI decision, only 50% can reconstruct the pathway that led to it. Worse still, only 38% hold a tamper-proof audit trail.
For Mick Amelishko, Senior Engineering Manager at Sumsub, explainability is the defining factor:
Mick Amelishko
“Every action an AI takes without a traceable record is a cost deferred, not avoided. Explainability is what lets you see the bill before it comes due,” said Amelishko.
The real challenge is whether those decisions hold up when a regulator, a shareholder, or a customer probes further.
The Financial Sector Doesn’t Guess Its Way With AI
Out of the four sectors surveyed, financial services hits Traceability and Responsibility best at ratings of 63.3 and 72.4, respectively. Financial services firms also posted the highest overall governance score at 69.6.
Financial firms are also the fastest movers. 72% already run multi-step AI systems in production, deeper into real autonomy than the other sectors.
In a sector where strict regulatory standards leave little choice, regulatory or compliance risk (54%) is the biggest perceived risk when AI acts on behalf of the firms.
Critically, if an automated system triggers an unintended payment, the lack of an immutable audit trail turns right into the alley of liability. The sector builds accordingly due to this: 68% keep audit trails of AI decisions, ahead of IT (59%), mobility (55%), and e-commerce (50%).
That same discipline extends to the upside of AI. Edmund Phuang, the Digital Data & AI Adoption Lead at CIMB Singapore, explained:
Edmund Phuang
“One of the key values of large language models is their ability to institutionalise knowledge. For example, a bank may process hundreds of credit memos, but any individual typically gains exposure to only a fraction of them. By capturing that collective expertise, new joiners can start from the bank’s accumulated best practices rather than from scratch.”
Proof is the New Foundation of AI Governance
Everything in this report points to one conclusion: the organisations that pull ahead will be the ones that can prove what their autonomy actually did.
Penny Chai, the Vice President for APAC at Sumsub, shared,
Penny Chai
“Prudence, rather than a lack of strategic intent, defines how enterprises are scaling AI agents. Establishing robust tracking architectures and guardrails is the vital prerequisite to safely deploying high-stakes AI at scale.”
That single capability of reconstructable, verifiable proof will be the defining factor for forward-looking organisations.
Accountability as the Architecture
Business leaders should decide who owns each AI-driven outcome before deployment, and make traceability a release requirement. The logic behind this is clear; an agent you cannot reconstruct is ultimately a liability you can’t price.
Treat Traceability as an Audit Requirement
Compliance and risk teams should treat traceability as an audit requirement. The benchmark here lies in whether a reviewer can reconstruct an AI decision independently, without leaning on the model to explain itself after the fact.
Proof Over Paperwork, Always
For regulators and policymakers, the problem lies in evidence. As for the intent, it is already there. Standards that reward demonstrable traceability, reconstructable decisions, and tamper-proof trails will pull the market forward faster than rules requiring written policies.
Verified Accountability Will Become a Competitive Edge
For the rest of the market, verified accountability is turning into a competitive edge. As agents act and transact at scale, the firms that can show which agent acted and on whose authority become the firms others are actually willing to transact with.
The same proof that satisfies a regulator doubles as a commercial signal: a counterparty is far more willing to let your agent into its systems when that agent arrives with a verifiable identity and a spotless record.
A trust infrastructure: one system that brings verification, monitoring, and governance together, is key to ensuring trust and transparency get into every digital interaction.