UK bank HSBC is strengthening its model-risk, data and technology controls as the financial institution prepares to deploy artificial intelligence more widely, acknowledging that generative and agentic AI introduce new operational, cybersecurity and governance risks.
In its latest interim report, covering the first half of 2026, the global banking giant said artificial intelligence will play an increasingly important role in personalising customer services, improving decision-making and simplifying internal operations.
However, the bank directly linked that expansion to the need for more robust assurance foundations, stating that it is strengthening “the data, technology and controls needed to deploy these capabilities safely and at scale”.
The disclosure comes as banks move beyond isolated AI experiments and begin embedding the technology into operational processes, customer journeys and decision-making systems.
For quality assurance teams, that shift increases the need to evaluate AI throughout its lifecycle rather than treating validation as a one-off exercise conducted immediately before deployment.
HSBC said it is enhancing its group-wide AI oversight, governance, lifecycle management and risk framework to address both internally developed technology and AI supplied or facilitated by third parties.
“HSBC is committed to using AI responsibly,” the bank stated. “We are working to balance the opportunity AI presents to accelerate delivery of our strategy with the need for appropriate controls to help mitigate the associated risks.”

The report does not set out a dedicated AI testing methodology or disclose the tools, benchmarks or evaluation techniques used by the bank.
Nevertheless, its emphasis on lifecycle management and model-risk controls points towards a broader continuous-assurance approach covering development, deployment and ongoing use.
In response to the report, Hemant Julka, group head of digital innovation and partnerships at Emirates NBD Bank, said the significance of HSBC’s approach lies in the decision to connect AI governance with its existing control environment.
“That is the part I find important,” the Dubai-based banking executive wrote in a LinkedIn post discussing HSBC’s report.
“HSBC is not describing AI governance as a separate Responsible AI programme sitting alongside the bank’s existing control environment. It is explicitly connecting AI to the wider risk framework, lifecycle management, third-party oversight and monitoring,” he stated.
For banks seeking to scale the technology, Julka argued that the central question is whether established risk structures can accommodate AI while preserving an enterprise-wide view of control.
“For banks scaling AI, perhaps this is the more useful maturity question: Can the existing risk architecture absorb AI and still provide one coherent view of whether the institution remains in control?”
“That is where AI Assurance ultimately needs to sit. Not beside the bank’s risk framework. Inside it.”
Agentic AI raises control demands
HSBC identified digitalisation and technological change as one of its principal risks, warning that emerging technology can introduce disruption alongside new commercial opportunities.
“Along with opportunities, new technology, including generative and agentic AI, can introduce risks and disruption,” the bank said. “We seek to manage technology developments with appropriate controls and oversight.”
The specific reference to agentic AI is significant for testing teams. Systems capable of planning, invoking tools or taking actions with greater autonomy require assurance beyond conventional deterministic applications.
Testing may need to address variable outputs, unexpected execution paths, access permissions, system interactions and whether agents remain within their intended operational boundaries.
HSBC also identified model risk as an important area of control. The bank uses models across financial and non-financial processes and said evolving regulatory expectations are changing the way that risk must be managed.
“New technologies, including generative AI, are driving a need for enhanced model risk controls,” it said.

During the first half of the year, HSBC made further enhancements to its risk management framework and monitoring processes to support the responsible adoption and oversight of models using AI and generative AI techniques.
The bank said human accountability will remain central as adoption grows. Julka highlighted that commitment as another indication that HSBC is incorporating AI into its wider model-risk and governance structures rather than handling it as a standalone programme.
“In the Risk section, HSBC reinforces the point: ‘As the Group expands its use of AI, we will maintain human judgement, human decision-making and human accountability at the core’,” he quoted the report.
“It also says it is enhancing its Risk Management Framework and monitoring processes for models using AI and generative AI techniques,” Julka pointed out.
HSBC has progressed the development of an integrated AI capability model and is seeking to give employees the skills required to understand, develop and use the technology responsibly.
For QA and risk teams, retaining human accountability does not remove the need to test automated decisions. Instead, it places additional importance on validating escalation paths, human-review mechanisms and whether employees receive sufficient information to identify and challenge an erroneous AI output.
Cyber threat scales with AI
HSBC’s AI expansion is taking place against what the bank described as a heightened external threat environment.
The bank warned of an increased risk of service disruption or data loss caused by technology failures or malicious activity. AI, it said, is enabling cyber activity to become faster and more scalable through both direct and third-party channels.
HSBC operates a continuous-improvement programme intended to support the resilience and stability of its technology operations. This includes responding to the changing threat environment created by frontier AI models.
The bank said it had enhanced its technology and cybersecurity controls during the first half of 2026 to improve the security and resilience of its technology services.
It is also investing in the reliability of critical services and its capacity to withstand and respond to cyberattacks. HSBC described an approach built around business and technical controls intended to “detect, prevent, respond to, recover and learn from issues in a timely manner within our risk appetite”.
That formulation places testing and assurance across the complete incident lifecycle. Beyond preventive security checks, financial institutions need to demonstrate that detection systems work, response procedures can be activated and critical services can be recovered within established tolerances.
The requirement to learn from issues also points towards the use of production evidence, incident data and post-event analysis to update test scenarios and strengthen controls continuously.
The interim report does not disclose the results of resilience exercises, recovery-time performance or material technology incidents. It nevertheless makes clear that technology resilience is being treated as a continuous programme rather than a periodic compliance exercise.
Third-party scrutiny
HSBC is also strengthening assurance over external technology and service providers. The bank said it assesses third parties to help ensure they deliver the service standards required to maintain operational resilience, protect customers and counterparties and minimise the risk of disruption.
This scrutiny extends beyond a bank’s immediate provider. HSBC said it is improving controls, oversight and risk-management processes covering third parties’ own supply chains, particularly where external services support activities that could affect operational resilience.
“We have strengthened our due diligence and monitoring capabilities with respect to our third parties to better manage our supply chain, and we continued to assess and manage our operational resilience,” the bank stated.
HSBC warned that supply-chain cyber threats are increasing and that the risk of disruption remains elevated.
“We have strengthened our due diligence and monitoring capabilities with respect to our third parties to better.”
– HSBC interim report
The disclosure reflects a wider challenge for quality engineering teams across financial services: demonstrating the resilience of an end-to-end service when individual components, infrastructure or AI capabilities are controlled by different providers.
Assurance may therefore need to include contractual service requirements, integration testing, supplier monitoring, exit planning and scenario exercises involving both the bank and its external partners.
The issue becomes more complex when a third-party AI system can change over time without a conventional software release by the bank itself. That increases the importance of ongoing evaluation, version monitoring and controls capable of detecting changes in system behaviour.
Julka said this integration of AI with existing third-party oversight is a defining element of HSBC’s position.
“To help meet the Group’s needs and regulatory expectations for AI, whether developed internally or facilitated through third parties, we continue to enhance our Group-wide AI oversight, governance, lifecycle management and risk framework.”
Regulatory reporting overhaul
Separate from its AI work, HSBC is advancing a programme to strengthen its global regulatory-reporting processes and make them more sustainable.
The bank said the programme includes enhancements to data, consistency and controls across the reporting process. It also acknowledged that changes introduced through the programme could affect some of its regulatory ratios.
“While this programme continues, there may be further impacts on some of our regulatory ratios as we implement recommended changes and continue to enhance our controls across the process,” HSBC said.
The report does not explain what prompted the programme or identify specific weaknesses. However, the acknowledgement of potential effects on regulatory ratios underlines the relationship between data quality, calculation logic and the figures ultimately submitted to supervisors.
Testing regulatory reporting requires more than validating the final output. Banks must establish whether source data is complete and accurate, whether transformations and calculations consistently implement regulatory requirements and whether reconciliations can identify problems before submission.
Changes to upstream platforms, data definitions or regulatory interpretations can affect multiple reports and ratios simultaneously, increasing the importance of automated regression testing and end-to-end traceability.
Data quality underpins resilience
HSBC’s wider data strategy provides another connection between quality assurance and operational resilience.
The bank said it uses data to operate its business and serve customers, often in real time through digital experiences and processes. Inaccurate or delayed information could consequently affect customer service, resilience and regulatory compliance.
“If our data is not accurate and timely, our ability to serve customers, operate with resilience or meet regulatory requirements could be impacted,” HSBC warned.

During the first half of the year, the bank monitored delivery across its group-wide data strategy and sought to enhance controls supporting the resilience and sustainability of its data-risk environment.
The disclosure illustrates why resilience testing cannot focus solely on whether infrastructure remains available. A critical banking service can remain online while producing unreliable outcomes if its underlying information is incomplete, stale or corrupted.
End-to-end resilience assurance therefore needs to test both service continuity and data integrity, including whether accurate information continues to move between systems during disruption, recovery and failover.
This will be particularly important as AI is integrated into more banking processes. Model performance depends on the availability, suitability and quality of the information used to train models and generate decisions. Deficient data controls can therefore undermine both conventional digital services and AI-enabled operations.
Models put to the test
HSBC’s conventional financial-model controls provide one of the report’s clearest examples of measurable testing.
The bank said it routinely validates the accuracy of its value-at-risk models by back-testing them against both actual and hypothetical profit and loss. The results, alongside other indicators, are used to assess model performance and determine whether enhanced internal monitoring is required.

During the first half of 2026, HSBC recorded two back-testing exceptions against hypothetical losses and one exception against actual losses.
The hypothetical exceptions were attributed to interest-rate volatility resulting from conflict in the Middle East. The actual-loss exception arose from periodic fair-value adjustments, particularly widening bid-offer spreads.
HSBC is also redeveloping its internal ratings-based models to meet Basel 3.1 requirements and said its implementation of the Prudential Regulation Authority’s SS1/23 model-risk management principles remains on track.
The PRA framework requires banks to apply model-risk controls throughout the model lifecycle, supported by effective governance, independent validation and continuing performance monitoring.
While traditional risk models and generative AI systems behave differently, HSBC’s disclosures show that both are increasingly being brought within an enterprise-wide control environment based on oversight, monitoring and lifecycle management.
That supports Julka’s argument that AI assurance should be absorbed into the institution’s established risk architecture, giving senior management and risk functions a coherent view across conventional models, generative systems and third-party AI.
Digital infrastructure expands
The assurance demands facing the bank are likely to increase as HSBC develops new forms of financial infrastructure.
The UK government has selected HSBC to provide technology for its first digital government bond. The bank has also expanded its tokenised deposit services into the US and the UAE, bringing the capability to six markets.
HSBC is expanding its stablecoin and digital-asset offering and developing treasury-risk frameworks and policies intended to support consistent management of liquidity, capital and interest-rate risk.
Such systems introduce additional testing requirements around transaction integrity, security, interoperability, settlement, performance and regulatory compliance. Failure can affect not only an individual customer journey but the underlying movement and ownership of financial assets.
HSBC does not disclose how the digital bond or tokenised deposit services are being tested. However, their expansion reinforces the bank’s wider message that innovation at scale depends on the strength of the controls, data and technology supporting it.
The report’s central implication is that AI assurance, cybersecurity, data quality, third-party oversight and operational resilience can no longer be treated as separate disciplines.
As AI becomes embedded in critical financial services, banks will need to test not only whether individual systems work as designed, but whether the combined ecosystem continues to produce reliable, explainable and compliant outcomes under changing conditions.
NEXT MONTH



REGISTER TODAY – SIMPLY CLICK HERE
Why not become a QA Financial subscriber?
It’s entirely FREE
* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *
REGULATION & COMPLIANCE
Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.
READ MORE
- Goldman puts AI coding to the test
- How to test AI models that banks do not control
- OpenAI, Filigran and SunTec: the latest vendor and product news
- Sygnum: Testing AI is ‘a measurement problem’
- Banks’ ‘code for all’ push raises testing risks
WATCH NOW


QA FINANCIAL PODCASTS

CLICK HERE TO LISTEN TO OUR EXCLUSIVE CONVERSATIONS



