The Korea Financial Security Institute has built a new system to identify potential risks in financial firms when deploying artificial intelligence (AI), including AI hallucinations and bias, system malfunctions, and security breaches.
According to reports, the institute confirmed that it has completed Korea’s first dedicated evaluation framework for AI reliability and safety in financial services. This initiative is spearheaded as the use of AI in core banking functions continues to grow following the easing of strict network separation rules.
As more financial institutions expand their use of AI across critical operations, the need for specific evaluation standards is also increasing to manage risks from model errors, unreliable outputs and cyber incidents.
The institute built the framework by combining domestic and international standards. These include the Financial Services Commission’s AI guidelines for the financial industry, the Financial Supervisory Service’s AI risk management framework and South Korea’s AI Basic Act. It also uses international standards such as ISO/IEC 42001, the international standard for AI management systems, and inspect, an evaluation tool developed by the UK’s AI Safety Institute.
What the AI Evaluation Framework Covers
The framework was built around ten criteria divided into two pillars: reliability and safety.
Under the reliability pillar, assessors will evaluate model performance management, data quality, fairness, bias, and explainability.
This pillar includes checking whether performance thresholds are properly calibrated, whether hallucinations and performance decline are continuously monitored, and whether the data supporting the models are accurate, complete and consistent.
It also covers how bias is managed during live operations, whether customers receive clear explanations of AI-driven decisions, and whether channels are available for customers to challenge or appeal those outcomes.
On the other hand, the safety pillar covers six areas: AI-specific threats, detection and response to targeted attacks, protection of AI assets, vetting of external models and data, scalability of security governance, and ongoing security verification.
In practice, this includes testing defenses against adversarial inputs, managing risks related to AI models, assets and open-source components, and ensuring that external models and data are properly vetted. It also includes supply chain security, safeguards against internal data leakage, and compliance with cross-border data transfer rules.
Testing and Future Implementation
The Financial Security Institute is planning to hold an online briefing for financial firms on August 14, followed by a demand survey in September. Pilot testing is expected to begin in the second half of the year to further refine the evaluation criteria, with full evaluations scheduled to start in 2027.
The initial evaluations will focus on companies that are members of the institute, with possible expansion to other financial institutions. The institute is also considering using the framework as a formal certification system for AI safety and reliability under the AI Basic Act.




