# What Should an Indonesia AI Governance Checklist Cover in 2026?

infonesia.fyi · September 30, 2026

> The Short Answer An Indonesia AI governance checklist should cover more than a written AI policy, a model inventory, and approval from management. For...

## The Short Answer

An Indonesia AI governance checklist should cover more than a written AI policy, a model inventory, and approval from management. For an organization operating in Indonesia, the working control set should connect the National AI Ethics Principles with applicable sector rules, personal-data obligations, cybersecurity duties, competition rules, intellectual-property requirements, and documented board oversight. As of 30 September 2026, businesses should verify the status of new rules rather than assume that every widely discussed “AI rulebook” is already in force. In particular, financial institutions need to distinguish binding OJK requirements from drafts, consultations, and industry guidance.

**Also worth reading:** [How Should Organizations Implement AI Governance in Indonesia?](https://infonesia.fyi/knowledge/how_should_organizations_implement_ai_governance_in_indonesia.php) · [How Do Enterprise Teams Navigate Indonesia AI Data Governance in 2026?](https://infonesia.fyi/knowledge/how_do_enterprise_teams_navigate_indonesia_ai_data_governance_in_2026.php) · [How Does AI Governance in Indonesia Compare with China and the United States?](https://infonesia.fyi/knowledge/how_does_ai_governance_in_indonesia_compare_with_china_and_the_united_states.php)

A practical checklist has six decision layers: identify what the organization uses; classify systems according to legal and business risk; assign accountable owners; test data, safety, security, and vendor controls; establish incident and human-review procedures; and retain evidence. The threshold is not simply whether software contains an AI model. Generative AI embedded in customer service, credit decisions, employee monitoring, fraud detection, or clinical or educational assessment usually deserves stronger review than an internal autocomplete tool with no material operational effect. The goal is proportionate governance, not paperwork created after deployment.

No single universal “Indonesia AI governance checklist” replaces professional legal advice. The applicable controls depend on the company’s sector, the people affected, the data processed, whether the service is offered in Java or outside it, and whether the organization is a regulated financial institution. For most teams, however, the checklist below provides a defensible minimum for 2026.

## Applicable Indonesian Laws and Policy Foundations

Indonesia does not yet have the same structure as the EU AI Act, with one horizontal risk-tiered statute governing most commercial AI systems. Governance is instead distributed across existing laws, sectoral supervision, national strategy, and the National AI Ethics Principles adopted through Government Regulation No. 71 of 2019. Those principles include beneficial use, human rights, non-discrimination, transparency, accountability, privacy, and responsible design. Companies can use them as the policy backbone even when no general AI-specific law directly applies to a particular tool.

Personal-data processing remains governed principally by Law No. 27 of 2022 on Personal Data Protection, alongside sector rules such as Indonesia’s financial-sector cybersecurity and risk-management requirements. A controller or processor should establish a lawful processing basis, data-minimization measures, purpose limitations, security controls, retention periods, and mechanisms for data-subject requests. The checklist should also address the distinction between data supplied by a customer and information inferred by an AI system. An inference used to score a person can still create a serious governance issue even if it is not written in the customer’s source file.

Companies should separately review intellectual-property, consumer-protection, e-commerce, labor, sectoral, and competition concerns. Copyright issues may arise where AI systems ingest protected text, images, code, or music. Consumer-facing claims such as “AI verified,” “fraud free,” or “100% accurate” can create misleading-advertising exposure if testing does not support them. The review should record which conclusion is legal, which is regulatory, and which is merely prudent risk management; this prevents uncertain items from being presented as settled statutory duties.

## The Core Indonesia AI Governance Checklist

The first control is an inventory containing, at minimum, the system name, business owner, technical owner, vendor, purpose, users, affected groups, countries of operation, training or input-data category, hosting location, automated-decision role, monitoring method, and last review date. AI should not remain a hidden feature inside another product. A reasonable inventory target is to account for 100% of known production AI and machine-learning systems, including vendor-provided models, internal decision models, and low-code automation.

The second control is a risk-based classification. Organizations can use a simple three-tier model: low risk for tools with limited effects, such as internal drafting assistance; medium risk for operational or customer-facing tools whose errors may cause inconvenience or limited loss; and high risk for uses involving financial access, employment, essential services, health, education, children, biometrics, or legally significant decisions. High-risk systems should receive independent testing, documented human escalation, stronger access controls, and periodic recertification. Numeric acceptance thresholds should come from the use case: for example, false-negative rates for fraud, false-positive rates for identity checks, and subgroup performance tests should be set before deployment.

The remaining controls concern data rights, model performance, security, explainability, human oversight, incident handling, and retirement. The checklist is not complete until it identifies who can stop a system, how errors are reported, what happens when an upstream model changes, and when data or a model must be deleted. Evidence should include approval records, test results, data documentation, vendor contracts, training records, monitoring reports, and incident tickets. Merely signing a code of conduct without assigning operational responsibility does not demonstrate control.

## Financial Services and the 2026 Rulebook Question

Financial institutions need a more specific checklist than ordinary enterprises. They should verify every requirement against the current version of Financial Services Authority regulations, Bank Indonesia rules, and, where relevant, the Indonesian Financial Crime Prevention Institute. Banking, insurance, payment, capital-markets, fintech, and credit-support organizations may face different obligations even when they use similar models. A marketing recommendation tool and a model used to determine loan eligibility should not receive the same level of scrutiny simply because both are developed by the same bank.

The “Indonesia 2026 AI Rulebook for Fintech and Financial Services” should be treated as a compliance guide or secondary explanation unless its provisions can be traced to a binding regulation. Practitioners should ask whether the rule is effective, transitional, proposed, or voluntary, and which entity it applies to. This distinction is especially important for model-governance, cloud-computing, third-party risk, explainability, and customer-data requirements. A bank should preserve the official publication, effective date, amendment history, and supervisory interpretation behind any implementation decision.

A sound financial-sector review covers model-development governance, data quality, explainability, fairness, robustness, cyber controls, vendor concentration, model validation, and business-continuity planning. The institution should compare production performance with approved use cases and investigate material drift. It should also identify whether the model creates a customer explanation that is meaningful to a non-specialist rather than merely revealing technical feature importance. For credit, insurance, or fraud decisions, adverse-action reasons and human reconsideration procedures are especially important. As of 30 September 2026, legal and compliance teams should recheck the status of every pending 2026 measure before claiming full compliance in customer or investor materials.

## Governance Models and Alternatives

Organizations can choose a centralized, decentralized, or hybrid model, but the label matters less than the allocation of responsibility. In a centralized model, a central AI or risk committee defines standards and approves high-risk systems while business units own their deployments. This can create consistency but may become a bottleneck. A decentralized model lets teams deploy quickly, yet it risks inconsistent documentation and unreported third-party tools. A hybrid approach generally suits medium and large companies: central standards apply globally, while nominated business owners make use-case decisions.

| Feature | Centralized model | Decentralized or hybrid model |
| --- | --- | --- |
| Standard setting | Central committee defines company-wide controls | Central team sets minimum controls; business units refine them |
| Decision speed | Potentially slower for approvals | Often faster, especially for low-risk tools |
| Consistency | Stronger documentation and escalation | Depends on maturity and control enforcement |
| Best fit | Banks, insurers, and tightly regulated groups | Multi-unit companies and fast-moving technology teams |
| Main weakness | Committee capacity and “approval theater” | Inconsistent risk treatment or ownership |
| Required evidence | Committee minutes, risk tiers, approval logs, testing | Business ownership, local attestations, platform logs, escalations |

External assessment is another alternative to internal review. An independent assessor can improve confidence in high-risk or customer-facing systems, but it does not transfer accountability to the assessor. A consultant’s generic checklist can support maturity assessments, while legal advice is necessary for contested regulatory interpretation. Automated governance platforms can collect inventories, approvals, and monitoring evidence, but they cannot decide whether a business purpose is ethical, lawful, or appropriate. The strongest option combines internal accountability with targeted external review.

## A Practical 90-Day Implementation Process

The first 30 days should focus on discovery and ownership. The compliance, legal, security, data, technology, risk, internal-audit, and business teams should identify production systems, experimental tools, vendor products, and shadow AI. They can search procurement records, cloud accounts, software licenses, data-science repositories, and vendor contracts. Each use case should have a named business owner and a technical owner; systems without an owner should be reviewed for shutdown. The organization should also establish a threshold for reporting an incident, even if the threshold will be refined later.

Days 31–60 are for classification and control design. Teams should document purpose, affected people, data sources, automated decisions, external dependencies, and plausible misuse. They should identify existing laws and supervisory expectations, then record uncertainty rather than inventing legal certainty. High-risk systems should receive measurable tests for accuracy, robustness, privacy, security, bias where relevant, and explainability. The review should include failure modes, not only average performance, because a 95% overall accuracy result can conceal unacceptable performance for a smaller or historically underrepresented group.

Days 61–90 should cover approval, monitoring, and evidence. Management should approve a risk-tiering standard, decision rights, review frequency, and incident process. A pilot should operate under defined limits, such as a maximum customer population, a restricted set of decisions, or a requirement for human confirmation. At day 90, teams should run a tabletop exercise, inspect the inventory for omissions, and measure control completion. A defensible early target is 100% ownership of material production systems, at least 95% completion of privacy and vendor reviews for high-risk deployments, and all open high-severity findings assigned with a dated remediation plan. The board or risk committee should receive exceptions and overdue actions rather than only a green dashboard.

## Common Mistakes and Cost Considerations

A common mistake is treating ethics principles as a substitute for regulation. The National AI Ethics Principles are useful, but they do not by themselves answer every question under Indonesian data, consumer, financial, labor, or intellectual-property law. Another error is assuming that a vendor’s “responsible AI” statement transfers risk. Contracts should allocate obligations for data use, security notifications, model changes, audit evidence, intellectual-property claims, service continuity, and deletion. Organizations also fail when they test only aggregate performance or describe a model as explainable without evaluating the explanation’s usefulness to the person affected.

Over-governance is also a problem. A four-week legal review for every password reset or internal writing assistant can waste scarce legal and technical capacity, while under-governance exposes customers and the company. Classification should therefore use documented criteria. Privacy, security, customer, safety, employment, financial, and reputational effects should carry more weight than whether a marketing brochure calls a feature “AI.”

There is no official fixed price for an Indonesia AI governance checklist. Internal programs may begin with roughly Rp25 million–Rp150 million for policy design, inventory tooling, workshops, and basic testing, while independent high-risk assessments can cost Rp150 million–Rp1 billion or more depending on the model, regulated status, data volume, and assurance depth. Software subscriptions might range from several million rupiah per month for small organizations to hundreds of millions for enterprise platforms, but the actual price depends on users, integrations, hosting, and support. Ongoing operating cost usually exceeds the first policy document because monitoring, retesting, audits, and staff time are recurring obligations. Organizations should compare total annual cost with the loss exposure from a faulty decision, sensitive-data breach, regulatory finding, or prolonged service interruption.

## When to Act and How the Board Should Oversee AI

An organization should act before deployment when the system affects customers, employees, credit, payments, safety, health, education, identity, or legally meaningful opportunities. A pilot involving only synthetic data and no human impact may justify a lighter review, but it should still be registered. Organizations should also reassess the checklist after a major model or vendor change, a merger, entry into a new regulated line, a material incident, or evidence of performance drift. For many companies, the first realistic schedule is a 90-day initial program followed by annual recertification of high-risk systems and event-driven review for significant changes.

Board oversight should ask whether management can explain the AI portfolio, the largest risks, control failures, spending, and accountability. Directors do not need to review model parameters; they do need assurance that material systems have owners, validated purposes, functioning escalation paths, and resources for remediation. Reports should include the number of production systems, high-risk deployments, unresolved incidents, overdue reviews, vendor concentration, and performance against approved limits. They should distinguish leading warnings, such as rising review delays, from lagging results, such as customer complaints or control breaches.

The board should not rely solely on an external assurance report. Assurance has scope limits and may be stale by the time it reaches the board. Management should preserve the underlying metrics, challenge management’s assumptions, and escalate overdue high-severity findings. For smaller companies without a formal board committee, the directors or designated risk committee can perform the same function. The decisive point is documented ownership: a governance framework succeeds when senior leaders understand what the organization’s AI can do, what it must not do, and who has the authority to stop it.

## Quick answers

### Is there one mandatory AI governance checklist for all Indonesian companies?

No single checklist currently governs every organization and use case. Companies must combine the National AI Ethics Principles with applicable personal-data, consumer, intellectual-property, cybersecurity, labor, competition, and sector-specific requirements.

### Do Indonesian financial institutions have to follow a 2026 AI rulebook?

Financial institutions should verify the legal status of every provision described as a 2026 AI rulebook. Binding duties should be traced to current OJK, Bank Indonesia, PSSI, or other applicable official rules, with drafts and industry guides kept clearly identified.

### How often should AI systems be reviewed?

The review schedule should reflect risk rather than a universal statutory interval. High-risk systems may need annual recertification or event-driven review after a major model, data, vendor, or business-purpose change, while low-risk tools can receive lighter periodic checks.

### Can a vendor certify that a company’s AI system is compliant?

A vendor can provide contractual, technical, and audit evidence, but its certificate usually does not remove the deploying organization’s responsibility. The buyer should independently confirm that the product matches the approved use case and applicable Indonesian legal obligations.

### What is the first step for a company with no formal AI policy?

The first step is to create an inventory and assign business and technical owners to known AI systems. Companies should also identify shadow and vendor-provided tools before deciding which policies, tests, and approvals are necessary.

Canonical: https://infonesia.fyi/knowledge/what_should_an_indonesia_ai_governance_checklist_cover_in_2026-2.php
Markdown: https://infonesia.fyi/knowledge/what_should_an_indonesia_ai_governance_checklist_cover_in_2026-2.php/index.md
