Case study:

GDPR and AI governance for a Middle Eastern bank

Bank of London and The Middle East plc (BLME) is an independent, Sharia’a-compliant UK bank serving UK and Middle Eastern markets.

As part of a wider Data Protection and governance engagement, Pathfinder supported BLME in developing its approach to the responsible use of Artificial Intelligence within a regulated financial services environment.

The work built on Pathfinder’s broader Data Protection support to the bank, including governance, accountability and the practical application of UK GDPR requirements. This gave Pathfinder a strong basis for assessing how AI governance should connect with existing privacy, security and risk controls rather than develop as a separate technology initiative.

The bank was developing its AI governance and policy framework and needed to ensure that proposed commitments were practical, proportionate and capable of being evidenced.

GDPR and AI governance for a Middle Eastern bank featured image

To deliver the AI and Data Protection BLME needed, Pathfinder:

  • Helped ensure AI was treated as a cross-functional risk issue involving Data Protection, IT Security, Legal, Operational Risk, business ownership and executive oversight.
  • Clarified roles and responsibilities across key stakeholders, including Legal, Data Protection, IT Security, Risk and Third-Party Management.
  • Linked AI governance to existing Data Protection controls, including accountability, DPIA considerations, acceptable use, information management and third-party management.
  • Strengthened escalation routes between the AI Working Group and wider IT and risk governance.
  • Highlighted the need for AI use cases to be assessed before deployment and reassessed where their intended use changes or expands.
  • Challenged proposed commitments where defined processes, accountable owners or evidence requirements were not yet in place, including AI risk assessment, transparency, monitoring of misuse and policy deviation.

 

Pathfinder brought a practical implementation perspective to BLME’s Data Protection and AI governance discussions. The work helped move the conversation from high-level responsible-AI principles towards the questions senior stakeholders need answered: who owns the risk, how is the control performed and how can the organisation demonstrate that it is working?

The result was a stronger and more defensible foundation for AI adoption, with Data Protection, security, operational and regulatory considerations embedded into the governance model.

Our work gave dnata visibility of the technical, legal and reputational risks the business faced when managing Personal Data. Pathfinder built both the tools and the confidence they needed to manage those risks. Above all, we made sure our approach was tailored to their specific needs.

Read our client’s testimonials:

“We had the pleasure of working with Pathfinder during its engagement supporting BLME, and I would have no hesitation in recommending them. They brought a strong combination of data protection expertise, sound judgement and a clear focus on what is practical in a regulated banking environment.

Pathfinder approached complex issues professionally and reliably, particularly where legal, technology, IT security and governance considerations needed to come together. They worked well with stakeholders, communicated clearly and brought a pragmatic style that helped move the work forward and get things done.

I particularly valued their contribution on data protection matters requiring close collaboration with the Bank’s IT and Security teams, as well as its constructive input into the Bank’s AI Working Group on governance and policy matters.”

Paul Coomber, Head of IT & Security, BLME

Are you confident your organisation can adopt AI without creating new Data Protection, security or governance risks?

Contact Pathfinder on 020 3143 5558 to discuss your concerns or email info@pathfinderpm.co.uk