On a recent engagement, we found staff using several different AI tools to do their daily work: drafting, summarizing, answering customers. None had been approved by the IT department, and some of the work involved customers’ personal information.
Nobody meant any harm. People were trying to work faster. But each tool was a place customer data could go that the institution could not see, control or recover.
What good governance looks like
Approved tools only. IT and security assess every AI tool before it touches company information: where it stores data, whether it trains on what is entered, who can access it, and how it is secured. Staff use the business or enterprise version, under a signed agreement, never free or trial versions on the network or with customer data.
The Data Protection Act, 2020, as the baseline. Collect only what is needed, keep it secure, and send personal data outside Jamaica only where it will be protected to the standard the Act requires. The Office of the Information Commissioner oversees compliance.
Contracts read before they are signed. Review every service level agreement and non-disclosure agreement, particularly with partners outside Jamaica: where data is stored and processed, who can reach it, breach notification times, subcontractors, and what happens to the data when the contract ends.
Data residency as a deliberate choice. Our recommendation is not to contract with a vendor that stores or processes customer data outside the Americas and the Caribbean.
Vendors held to Jamaican standards. Local or international, a vendor must meet the Act and the Office of the Information Commissioner’s requirements, and, for institutions regulated by the Financial Services Commission, the Commission’s requirements too, before any contract is signed.
Questions a board should be able to answer
- Which AI tools are our staff using today, and which did we approve?
- Where is our customers’ data stored, and in which countries?
- Which of our vendors can reach customer data, and under what contract?
- How quickly would a vendor tell us about a breach?
- If a regulator asked tomorrow, could we show our controls?
How we help
We assess where AI and vendors touch your customer data, build an approved-tools policy with your IT and compliance teams, and review vendor contracts against the Data Protection Act and your regulator’s expectations, before a headline makes the case for you.
Is AI already in use across your institution?
An independent review now costs far less than a breach, a regulator’s inquiry or a legal claim later. We can help you get it right the first time.
Begin a conversation →