external-popup-close

You are being redirected to

https://www.ttbbank.com/

Proceed

Risk Governance

As part of the overall corporate governance framework, the Board of Directors is responsible for overseeing a strong risk governance framework. The Bank has established a solid risk governance framework, which serves as the foundation for consistent and effective risk management. The risk governance framework mainly consists of a clear risk governance structure, risk appetite, risk management policies, consistent risk management processes, and an embedded risk culture. The Board of Directors holds ultimate responsibility of bank-wide risk management and ensure that all risk governance framework is well communicated through the whole organization. For effective risk oversights, the Risk Oversight Committee (ROC) has been delegated by the Board of Directors to review and oversee the management of all risks across the Bank and is authorized to approve certain parts of Bank’s risk management strategies, policies, frameworks and standards, as well as aggregate risk tolerance and risk concentration levels.


Risk Management Processes

Risk Management in the Bank consists of 5 key risk management processes:

  1. Risk Appetite Setting: The Bank annually sets risk appetites for various risk types (Credit, Market and Non-Financial Risk). These appetites are input for and aligned with the business planning process, are discussed in and endorsed by the relevant Sub-Committees, and ultimately approved by the Board of Directors. Actual performance is regularly measured against and reported on the basis of these risk appetites.
  2. Risk Identification: The Bank classifies risks that are arising in daily business activities into 6 key risk areas: Credit Risk, Market Risk (including but not limited to Foreign Exchange Risk and Interest Rate Risk), Liquidity Risk, Non-Financial Risk (comprising Operational Risk, IT Risk, Compliance Risk including Market Conduct Risk, and Legal Risk), Strategic Risk and Reputational Risk.
  3. Risk Assessment & Measurement: The Bank uses different methods and tools to measure various risk types in both quantitative and qualitative aspects. In addition, the Bank also conducts Stress Testing for material risks to measure the quality and resilience of the Bank’s portfolio and the Bank’s capacity to absorb the impact resulting from various stress event scenarios.
  4. Risk Monitoring and Control: The Bank regularly monitors, controls, and mitigates risks by setting key risk indicators, risk limits, as well as risk appetite at bank-wide, portfolio, product and other levels as deemed appropriate.
  5. Risk Reporting & Communication: The Bank regularly reports the status of various risk types covering both financial risk and non-financial risk as well as actions taken/to be taken are reported to relevant parties/committees and top management on a regular basis. The risk reports cover product level, portfolio level, functional level, and the bank-wide level.


Three Lines of Defense:
Over the last years, the Bank has invested significantly in strengthening its risk management culture by establishing three lines of defense. In this structure the employees in the business units (the 1st line of defense) identify risks, consider the impact, report if necessary and apply appropriate risk mitigation strategies. Investments include training, tooling, processes, and policies. Risk Management units under the Chief Risk Officer perform the 2nd line of defense duties of formulating risk strategy and appetite, policies, guidelines, standards, and appropriate risk structures, provide oversight and monitor the 1st line of defense and actively challenge the risk – return trade-off in the Business units. Internal audit as the 3rd line of defense provides independent and objective assurance on the effectiveness of controls and recommends improvements to the governance, risk & control framework.


Risk Culture

Fostering a solid risk culture throughout the Bank is a fundamental component of effective risk management. Several measures have been implemented to ensure that risk awareness is instilled from the highest level of the organization. Examples include:

  • Regular provision of risk management knowledge to the Board of Directors.
  • Incorporation of risk management metrics into a corporate KPI, which is cascaded down to senior management and relevant employees. Risk modifier metrics are used to ensure that the senior management are accountable for the implementation of risk and control measures. The risk modifier metrics include, but are not limited to, the completion of risk and control self-assessment activities, compliance with AML/KYC/CDD, and other related regulatory requirements. Any delays/mis-target/overdue deliverables in relations to the significant risk and controls are monitored in the risk oversight dashboard and shall be considered a disincentive to the senior executives.
  • Mandatory E-learning around risk topics is provided to employees on an annual basis to ensure that all employees develop risk awareness in their day-to-day responsibilities. For example, non-financial risk management, PDPA (Personal Data Protection Act), cybersecurity risk awareness, fraud risk management, anti-corruption, market conduct, anti-money laundering and Counter-Terrorism and Proliferation of Weapon of Mass Destruction Financing.
  • ttb awards – an annual innovation competition aiming to motivate employees to propose initiatives that promote customers’ financial well-being and/or improve the Bank’s performance in six key areas, including a specific focus on data and risk management.
  • Incorporation of proper risk assessment for all products and services which the bank would like to offer to the customers into the Products and Services Approval Process (PSAP). The process ensures that adequate risk assessments are performed, and effective mitigation controls are put in place to manage the inherent risks within the Bank’s appetite.


Artificial Intelligence

At ttb, artificial intelligence (AI) is applied with a strong commitment to responsibility, transparency, security, and trust. The Bank's Responsible AI framework is anchored by the AI Minimum Standard (AIMS), which establishes an enterprise-wide governance and control framework covering the design, development, deployment, monitoring, and oversight of AI systems across their entire lifecycle.

AIMS is positioned under the Bank's Cyber & Digital Risk Management Policy and forms part of the Non-Financial Risk Framework, serving as a key control framework for managing AI-related technology and digital risks. It applies to all employees and contractors involved in AI technologies and helps ensure that AI is used in a secure, ethical, transparent, and risk-controlled manner.

The framework encompasses:

  • Enterprise-wide governance structure, roles, responsibilities, and accountability
  • End-to-end AI lifecycle management
  • AI risk management aligned with the Bank's risk appetite
  • Responsible AI principles based on Fairness, Ethics, Accountability, and Transparency (FEAT)
  • Compliance with applicable laws, regulations, and internal policies
  • Oversight and control mechanisms, including monitoring, explainability, and human oversight (Human-in-the-Loop and Human-over-the-Loop)
  • Business enablement to support efficiency, innovation, and digital transformation

These principles are embedded throughout the AI lifecycle, from design and development to deployment, monitoring, evaluation, and continuous improvement. Customer data is handled with strict privacy safeguards and supported by robust cybersecurity controls to protect systems, data, and users. The Bank actively works to identify, assess, and mitigate potential bias in AI models and outcomes, promoting fairness, inclusiveness, and equitable treatment.

Human oversight remains a fundamental safeguard. For AI use cases with material customer, operational, or risk implications, the Bank applies risk-based human oversight mechanisms to help ensure that decisions remain subject to appropriate review, intervention, and accountability. Clear governance structures define responsibilities and accountability throughout the AI lifecycle, while establishing boundaries for the appropriate use of AI, including requirements for human oversight, approved use cases, prohibited practices, and compliance with the Bank's policies and standards.

Transparency and explainability are key pillars of ttb's approach. The Bank seeks to ensure that the role of AI is appropriately communicated and that AI-generated or AI-supported outputs and decisions can be understood, interpreted, and explained. Where applicable, users are clearly informed when they are interacting with AI-powered services or when content, recommendations, or decisions are generated or materially supported by AI technologies.

To operationalize these principles, ttb implements a range of controls across the AI lifecycle. Access to sensitive AI capabilities is carefully managed through appropriate authorization and security measures. AI models are continuously monitored to maintain performance, reliability, and effectiveness, with established mechanisms to detect model drift or degradation, retrain models when necessary, and improve outcomes over time. Regular reviews help ensure that AI systems continue to operate in line with business objectives, ethical principles, and applicable regulatory requirements.

The Bank conducts regular assessments of deployed AI models to identify and mitigate potential bias and fairness concerns. Structured AI risk management processes evaluate operational, legal, regulatory, ethical, reputational, and technology-related risks associated with AI use cases and support appropriate controls throughout deployment and ongoing operation.

Customers and affected stakeholders are provided with channels to provide feedback, raise concerns, submit complaints, seek clarification, or request human assistance through established service and escalation channels, where appropriate. Users may also be provided with options to opt out of certain AI-enabled services when applicable, reinforcing a human-centered approach to technology adoption.

Recognizing the importance of responsible AI culture, ttb provides ongoing employee training and awareness programs covering the ethical, secure, and compliant use of AI technologies. The Bank also evaluates AI initiatives against defined business objectives, customer outcomes, and risk management requirements to support responsible innovation and long-term value creation.

Consistent with the Bank's ethical standards, Responsible AI principles, and applicable regulations, AI must not be used for discriminatory, manipulative, deceptive, or otherwise harmful purposes, including unauthorized uses that may undermine individual rights, freedoms, privacy, or human dignity. The Bank also prohibits the circumvention of governance, security, and compliance controls established for the responsible use of AI.

The effectiveness of the Bank's AI governance framework is supported by ongoing oversight, monitoring, and independent assurance activities, including periodic reviews and audits where appropriate.

Through this integrated approach, ttb seeks to ensure that AI not only enhances efficiency, innovation, and digital transformation, but also upholds the highest standards of responsibility, protecting customers, strengthening trust, and supporting sustainable long-term value creation.

Risk Governance

As part of the overall corporate governance framework, the Board of Directors is responsible for overseeing a strong risk governance framework. The Bank has established a solid risk governance framework, which serves as the foundation for consistent and effective risk management. The risk governance framework mainly consists of a clear risk governance structure, risk appetite, risk management policies, consistent risk management processes, and an embedded risk culture. The Board of Directors holds ultimate responsibility of bank-wide risk management and ensure that all risk governance framework is well communicated through the whole organization. For effective risk oversights, the Risk Oversight Committee (ROC) has been delegated by the Board of Directors to review and oversee the management of all risks across the Bank and is authorized to approve certain parts of Bank’s risk management strategies, policies, frameworks and standards, as well as aggregate risk tolerance and risk concentration levels.


Risk Management Processes

Risk Management in the Bank consists of 5 key risk management processes:

  1. Risk Appetite Setting: The Bank annually sets risk appetites for various risk types (Credit, Market and Non-Financial Risk). These appetites are input for and aligned with the business planning process, are discussed in and endorsed by the relevant Sub-Committees, and ultimately approved by the Board of Directors. Actual performance is regularly measured against and reported on the basis of these risk appetites.
  2. Risk Identification: The Bank classifies risks that are arising in daily business activities into 6 key risk areas: Credit Risk, Market Risk (including but not limited to Foreign Exchange Risk and Interest Rate Risk), Liquidity Risk, Non-Financial Risk (comprising Operational Risk, IT Risk, Compliance Risk including Market Conduct Risk, and Legal Risk), Strategic Risk and Reputational Risk.
  3. Risk Assessment & Measurement: The Bank uses different methods and tools to measure various risk types in both quantitative and qualitative aspects. In addition, the Bank also conducts Stress Testing for material risks to measure the quality and resilience of the Bank’s portfolio and the Bank’s capacity to absorb the impact resulting from various stress event scenarios.
  4. Risk Monitoring and Control: The Bank regularly monitors, controls, and mitigates risks by setting key risk indicators, risk limits, as well as risk appetite at bank-wide, portfolio, product and other levels as deemed appropriate.
  5. Risk Reporting & Communication: The Bank regularly reports the status of various risk types covering both financial risk and non-financial risk as well as actions taken/to be taken are reported to relevant parties/committees and top management on a regular basis. The risk reports cover product level, portfolio level, functional level, and the bank-wide level.


Three Lines of Defense:
Over the last years, the Bank has invested significantly in strengthening its risk management culture by establishing three lines of defense. In this structure the employees in the business units (the 1st line of defense) identify risks, consider the impact, report if necessary and apply appropriate risk mitigation strategies. Investments include training, tooling, processes, and policies. Risk Management units under the Chief Risk Officer perform the 2nd line of defense duties of formulating risk strategy and appetite, policies, guidelines, standards, and appropriate risk structures, provide oversight and monitor the 1st line of defense and actively challenge the risk – return trade-off in the Business units. Internal audit as the 3rd line of defense provides independent and objective assurance on the effectiveness of controls and recommends improvements to the governance, risk & control framework.


Risk Culture

Fostering a solid risk culture throughout the Bank is a fundamental component of effective risk management. Several measures have been implemented to ensure that risk awareness is instilled from the highest level of the organization. Examples include:

  • Regular provision of risk management knowledge to the Board of Directors.
  • Incorporation of risk management metrics into a corporate KPI, which is cascaded down to senior management and relevant employees. Risk modifier metrics are used to ensure that the senior management are accountable for the implementation of risk and control measures. The risk modifier metrics include, but are not limited to, the completion of risk and control self-assessment activities, compliance with AML/KYC/CDD, and other related regulatory requirements. Any delays/mis-target/overdue deliverables in relations to the significant risk and controls are monitored in the risk oversight dashboard and shall be considered a disincentive to the senior executives.
  • Mandatory E-learning around risk topics is provided to employees on an annual basis to ensure that all employees develop risk awareness in their day-to-day responsibilities. For example, non-financial risk management, PDPA (Personal Data Protection Act), cybersecurity risk awareness, fraud risk management, anti-corruption, market conduct, anti-money laundering and Counter-Terrorism and Proliferation of Weapon of Mass Destruction Financing.
  • ttb awards – an annual innovation competition aiming to motivate employees to propose initiatives that promote customers’ financial well-being and/or improve the Bank’s performance in six key areas, including a specific focus on data and risk management.
  • Incorporation of proper risk assessment for all products and services which the bank would like to offer to the customers into the Products and Services Approval Process (PSAP). The process ensures that adequate risk assessments are performed, and effective mitigation controls are put in place to manage the inherent risks within the Bank’s appetite.


Artificial Intelligence

At ttb, artificial intelligence (AI) is applied with a strong commitment to responsibility, transparency, security, and trust. The Bank's Responsible AI framework is anchored by the AI Minimum Standard (AIMS), which establishes an enterprise-wide governance and control framework covering the design, development, deployment, monitoring, and oversight of AI systems across their entire lifecycle.

AIMS is positioned under the Bank's Cyber & Digital Risk Management Policy and forms part of the Non-Financial Risk Framework, serving as a key control framework for managing AI-related technology and digital risks. It applies to all employees and contractors involved in AI technologies and helps ensure that AI is used in a secure, ethical, transparent, and risk-controlled manner.

The framework encompasses:

  • Enterprise-wide governance structure, roles, responsibilities, and accountability
  • End-to-end AI lifecycle management
  • AI risk management aligned with the Bank's risk appetite
  • Responsible AI principles based on Fairness, Ethics, Accountability, and Transparency (FEAT)
  • Compliance with applicable laws, regulations, and internal policies
  • Oversight and control mechanisms, including monitoring, explainability, and human oversight (Human-in-the-Loop and Human-over-the-Loop)
  • Business enablement to support efficiency, innovation, and digital transformation

These principles are embedded throughout the AI lifecycle, from design and development to deployment, monitoring, evaluation, and continuous improvement. Customer data is handled with strict privacy safeguards and supported by robust cybersecurity controls to protect systems, data, and users. The Bank actively works to identify, assess, and mitigate potential bias in AI models and outcomes, promoting fairness, inclusiveness, and equitable treatment.

Human oversight remains a fundamental safeguard. For AI use cases with material customer, operational, or risk implications, the Bank applies risk-based human oversight mechanisms to help ensure that decisions remain subject to appropriate review, intervention, and accountability. Clear governance structures define responsibilities and accountability throughout the AI lifecycle, while establishing boundaries for the appropriate use of AI, including requirements for human oversight, approved use cases, prohibited practices, and compliance with the Bank's policies and standards.

Transparency and explainability are key pillars of ttb's approach. The Bank seeks to ensure that the role of AI is appropriately communicated and that AI-generated or AI-supported outputs and decisions can be understood, interpreted, and explained. Where applicable, users are clearly informed when they are interacting with AI-powered services or when content, recommendations, or decisions are generated or materially supported by AI technologies.

To operationalize these principles, ttb implements a range of controls across the AI lifecycle. Access to sensitive AI capabilities is carefully managed through appropriate authorization and security measures. AI models are continuously monitored to maintain performance, reliability, and effectiveness, with established mechanisms to detect model drift or degradation, retrain models when necessary, and improve outcomes over time. Regular reviews help ensure that AI systems continue to operate in line with business objectives, ethical principles, and applicable regulatory requirements.

The Bank conducts regular assessments of deployed AI models to identify and mitigate potential bias and fairness concerns. Structured AI risk management processes evaluate operational, legal, regulatory, ethical, reputational, and technology-related risks associated with AI use cases and support appropriate controls throughout deployment and ongoing operation.

Customers and affected stakeholders are provided with channels to provide feedback, raise concerns, submit complaints, seek clarification, or request human assistance through established service and escalation channels, where appropriate. Users may also be provided with options to opt out of certain AI-enabled services when applicable, reinforcing a human-centered approach to technology adoption.

Recognizing the importance of responsible AI culture, ttb provides ongoing employee training and awareness programs covering the ethical, secure, and compliant use of AI technologies. The Bank also evaluates AI initiatives against defined business objectives, customer outcomes, and risk management requirements to support responsible innovation and long-term value creation.

Consistent with the Bank's ethical standards, Responsible AI principles, and applicable regulations, AI must not be used for discriminatory, manipulative, deceptive, or otherwise harmful purposes, including unauthorized uses that may undermine individual rights, freedoms, privacy, or human dignity. The Bank also prohibits the circumvention of governance, security, and compliance controls established for the responsible use of AI.

The effectiveness of the Bank's AI governance framework is supported by ongoing oversight, monitoring, and independent assurance activities, including periodic reviews and audits where appropriate.

Through this integrated approach, ttb seeks to ensure that AI not only enhances efficiency, innovation, and digital transformation, but also upholds the highest standards of responsibility, protecting customers, strengthening trust, and supporting sustainable long-term value creation.

Risk Governance

As part of the overall corporate governance framework, the Board of Directors is responsible for overseeing a strong risk governance framework. The Bank has established a solid risk governance framework, which serves as the foundation for consistent and effective risk management. The risk governance framework mainly consists of a clear risk governance structure, risk appetite, risk management policies, consistent risk management processes, and an embedded risk culture. The Board of Directors holds ultimate responsibility of bank-wide risk management and ensure that all risk governance framework is well communicated through the whole organization. For effective risk oversights, the Risk Oversight Committee (ROC) has been delegated by the Board of Directors to review and oversee the management of all risks across the Bank and is authorized to approve certain parts of Bank’s risk management strategies, policies, frameworks and standards, as well as aggregate risk tolerance and risk concentration levels.


Risk Management Processes

Risk Management in the Bank consists of 5 key risk management processes:

  1. Risk Appetite Setting: The Bank annually sets risk appetites for various risk types (Credit, Market and Non-Financial Risk). These appetites are input for and aligned with the business planning process, are discussed in and endorsed by the relevant Sub-Committees, and ultimately approved by the Board of Directors. Actual performance is regularly measured against and reported on the basis of these risk appetites.
  2. Risk Identification: The Bank classifies risks that are arising in daily business activities into 6 key risk areas: Credit Risk, Market Risk (including but not limited to Foreign Exchange Risk and Interest Rate Risk), Liquidity Risk, Non-Financial Risk (comprising Operational Risk, IT Risk, Compliance Risk including Market Conduct Risk, and Legal Risk), Strategic Risk and Reputational Risk.
  3. Risk Assessment & Measurement: The Bank uses different methods and tools to measure various risk types in both quantitative and qualitative aspects. In addition, the Bank also conducts Stress Testing for material risks to measure the quality and resilience of the Bank’s portfolio and the Bank’s capacity to absorb the impact resulting from various stress event scenarios.
  4. Risk Monitoring and Control: The Bank regularly monitors, controls, and mitigates risks by setting key risk indicators, risk limits, as well as risk appetite at bank-wide, portfolio, product and other levels as deemed appropriate.
  5. Risk Reporting & Communication: The Bank regularly reports the status of various risk types covering both financial risk and non-financial risk as well as actions taken/to be taken are reported to relevant parties/committees and top management on a regular basis. The risk reports cover product level, portfolio level, functional level, and the bank-wide level.


Three Lines of Defense:
Over the last years, the Bank has invested significantly in strengthening its risk management culture by establishing three lines of defense. In this structure the employees in the business units (the 1st line of defense) identify risks, consider the impact, report if necessary and apply appropriate risk mitigation strategies. Investments include training, tooling, processes, and policies. Risk Management units under the Chief Risk Officer perform the 2nd line of defense duties of formulating risk strategy and appetite, policies, guidelines, standards, and appropriate risk structures, provide oversight and monitor the 1st line of defense and actively challenge the risk – return trade-off in the Business units. Internal audit as the 3rd line of defense provides independent and objective assurance on the effectiveness of controls and recommends improvements to the governance, risk & control framework.


Risk Culture

Fostering a solid risk culture throughout the Bank is a fundamental component of effective risk management. Several measures have been implemented to ensure that risk awareness is instilled from the highest level of the organization. Examples include:

  • Regular provision of risk management knowledge to the Board of Directors.
  • Incorporation of risk management metrics into a corporate KPI, which is cascaded down to senior management and relevant employees. Risk modifier metrics are used to ensure that the senior management are accountable for the implementation of risk and control measures. The risk modifier metrics include, but are not limited to, the completion of risk and control self-assessment activities, compliance with AML/KYC/CDD, and other related regulatory requirements. Any delays/mis-target/overdue deliverables in relations to the significant risk and controls are monitored in the risk oversight dashboard and shall be considered a disincentive to the senior executives.
  • Mandatory E-learning around risk topics is provided to employees on an annual basis to ensure that all employees develop risk awareness in their day-to-day responsibilities. For example, non-financial risk management, PDPA (Personal Data Protection Act), cybersecurity risk awareness, fraud risk management, anti-corruption, market conduct, anti-money laundering and Counter-Terrorism and Proliferation of Weapon of Mass Destruction Financing.
  • ttb awards – an annual innovation competition aiming to motivate employees to propose initiatives that promote customers’ financial well-being and/or improve the Bank’s performance in six key areas, including a specific focus on data and risk management.
  • Incorporation of proper risk assessment for all products and services which the bank would like to offer to the customers into the Products and Services Approval Process (PSAP). The process ensures that adequate risk assessments are performed, and effective mitigation controls are put in place to manage the inherent risks within the Bank’s appetite.


Artificial Intelligence

At ttb, artificial intelligence (AI) is applied with a strong commitment to responsibility, transparency, security, and trust. The Bank's Responsible AI framework is anchored by the AI Minimum Standard (AIMS), which establishes an enterprise-wide governance and control framework covering the design, development, deployment, monitoring, and oversight of AI systems across their entire lifecycle.

AIMS is positioned under the Bank's Cyber & Digital Risk Management Policy and forms part of the Non-Financial Risk Framework, serving as a key control framework for managing AI-related technology and digital risks. It applies to all employees and contractors involved in AI technologies and helps ensure that AI is used in a secure, ethical, transparent, and risk-controlled manner.

The framework encompasses:

  • Enterprise-wide governance structure, roles, responsibilities, and accountability
  • End-to-end AI lifecycle management
  • AI risk management aligned with the Bank's risk appetite
  • Responsible AI principles based on Fairness, Ethics, Accountability, and Transparency (FEAT)
  • Compliance with applicable laws, regulations, and internal policies
  • Oversight and control mechanisms, including monitoring, explainability, and human oversight (Human-in-the-Loop and Human-over-the-Loop)
  • Business enablement to support efficiency, innovation, and digital transformation

These principles are embedded throughout the AI lifecycle, from design and development to deployment, monitoring, evaluation, and continuous improvement. Customer data is handled with strict privacy safeguards and supported by robust cybersecurity controls to protect systems, data, and users. The Bank actively works to identify, assess, and mitigate potential bias in AI models and outcomes, promoting fairness, inclusiveness, and equitable treatment.

Human oversight remains a fundamental safeguard. For AI use cases with material customer, operational, or risk implications, the Bank applies risk-based human oversight mechanisms to help ensure that decisions remain subject to appropriate review, intervention, and accountability. Clear governance structures define responsibilities and accountability throughout the AI lifecycle, while establishing boundaries for the appropriate use of AI, including requirements for human oversight, approved use cases, prohibited practices, and compliance with the Bank's policies and standards.

Transparency and explainability are key pillars of ttb's approach. The Bank seeks to ensure that the role of AI is appropriately communicated and that AI-generated or AI-supported outputs and decisions can be understood, interpreted, and explained. Where applicable, users are clearly informed when they are interacting with AI-powered services or when content, recommendations, or decisions are generated or materially supported by AI technologies.

To operationalize these principles, ttb implements a range of controls across the AI lifecycle. Access to sensitive AI capabilities is carefully managed through appropriate authorization and security measures. AI models are continuously monitored to maintain performance, reliability, and effectiveness, with established mechanisms to detect model drift or degradation, retrain models when necessary, and improve outcomes over time. Regular reviews help ensure that AI systems continue to operate in line with business objectives, ethical principles, and applicable regulatory requirements.

The Bank conducts regular assessments of deployed AI models to identify and mitigate potential bias and fairness concerns. Structured AI risk management processes evaluate operational, legal, regulatory, ethical, reputational, and technology-related risks associated with AI use cases and support appropriate controls throughout deployment and ongoing operation.

Customers and affected stakeholders are provided with channels to provide feedback, raise concerns, submit complaints, seek clarification, or request human assistance through established service and escalation channels, where appropriate. Users may also be provided with options to opt out of certain AI-enabled services when applicable, reinforcing a human-centered approach to technology adoption.

Recognizing the importance of responsible AI culture, ttb provides ongoing employee training and awareness programs covering the ethical, secure, and compliant use of AI technologies. The Bank also evaluates AI initiatives against defined business objectives, customer outcomes, and risk management requirements to support responsible innovation and long-term value creation.

Consistent with the Bank's ethical standards, Responsible AI principles, and applicable regulations, AI must not be used for discriminatory, manipulative, deceptive, or otherwise harmful purposes, including unauthorized uses that may undermine individual rights, freedoms, privacy, or human dignity. The Bank also prohibits the circumvention of governance, security, and compliance controls established for the responsible use of AI.

The effectiveness of the Bank's AI governance framework is supported by ongoing oversight, monitoring, and independent assurance activities, including periodic reviews and audits where appropriate.

Through this integrated approach, ttb seeks to ensure that AI not only enhances efficiency, innovation, and digital transformation, but also upholds the highest standards of responsibility, protecting customers, strengthening trust, and supporting sustainable long-term value creation.

Risk Governance

As part of the overall corporate governance framework, the Board of Directors is responsible for overseeing a strong risk governance framework. The Bank has established a solid risk governance framework, which serves as the foundation for consistent and effective risk management. The risk governance framework mainly consists of a clear risk governance structure, risk appetite, risk management policies, consistent risk management processes, and an embedded risk culture. The Board of Directors holds ultimate responsibility of bank-wide risk management and ensure that all risk governance framework is well communicated through the whole organization. For effective risk oversights, the Risk Oversight Committee (ROC) has been delegated by the Board of Directors to review and oversee the management of all risks across the Bank and is authorized to approve certain parts of Bank’s risk management strategies, policies, frameworks and standards, as well as aggregate risk tolerance and risk concentration levels.


Risk Management Processes

Risk Management in the Bank consists of 5 key risk management processes:

  1. Risk Appetite Setting: The Bank annually sets risk appetites for various risk types (Credit, Market and Non-Financial Risk). These appetites are input for and aligned with the business planning process, are discussed in and endorsed by the relevant Sub-Committees, and ultimately approved by the Board of Directors. Actual performance is regularly measured against and reported on the basis of these risk appetites.
  2. Risk Identification: The Bank classifies risks that are arising in daily business activities into 6 key risk areas: Credit Risk, Market Risk (including but not limited to Foreign Exchange Risk and Interest Rate Risk), Liquidity Risk, Non-Financial Risk (comprising Operational Risk, IT Risk, Compliance Risk including Market Conduct Risk, and Legal Risk), Strategic Risk and Reputational Risk.
  3. Risk Assessment & Measurement: The Bank uses different methods and tools to measure various risk types in both quantitative and qualitative aspects. In addition, the Bank also conducts Stress Testing for material risks to measure the quality and resilience of the Bank’s portfolio and the Bank’s capacity to absorb the impact resulting from various stress event scenarios.
  4. Risk Monitoring and Control: The Bank regularly monitors, controls, and mitigates risks by setting key risk indicators, risk limits, as well as risk appetite at bank-wide, portfolio, product and other levels as deemed appropriate.
  5. Risk Reporting & Communication: The Bank regularly reports the status of various risk types covering both financial risk and non-financial risk as well as actions taken/to be taken are reported to relevant parties/committees and top management on a regular basis. The risk reports cover product level, portfolio level, functional level, and the bank-wide level.


Three Lines of Defense:
Over the last years, the Bank has invested significantly in strengthening its risk management culture by establishing three lines of defense. In this structure the employees in the business units (the 1st line of defense) identify risks, consider the impact, report if necessary and apply appropriate risk mitigation strategies. Investments include training, tooling, processes, and policies. Risk Management units under the Chief Risk Officer perform the 2nd line of defense duties of formulating risk strategy and appetite, policies, guidelines, standards, and appropriate risk structures, provide oversight and monitor the 1st line of defense and actively challenge the risk – return trade-off in the Business units. Internal audit as the 3rd line of defense provides independent and objective assurance on the effectiveness of controls and recommends improvements to the governance, risk & control framework.


Risk Culture

Fostering a solid risk culture throughout the Bank is a fundamental component of effective risk management. Several measures have been implemented to ensure that risk awareness is instilled from the highest level of the organization. Examples include:

  • Regular provision of risk management knowledge to the Board of Directors.
  • Incorporation of risk management metrics into a corporate KPI, which is cascaded down to senior management and relevant employees. Risk modifier metrics are used to ensure that the senior management are accountable for the implementation of risk and control measures. The risk modifier metrics include, but are not limited to, the completion of risk and control self-assessment activities, compliance with AML/KYC/CDD, and other related regulatory requirements. Any delays/mis-target/overdue deliverables in relations to the significant risk and controls are monitored in the risk oversight dashboard and shall be considered a disincentive to the senior executives.
  • Mandatory E-learning around risk topics is provided to employees on an annual basis to ensure that all employees develop risk awareness in their day-to-day responsibilities. For example, non-financial risk management, PDPA (Personal Data Protection Act), cybersecurity risk awareness, fraud risk management, anti-corruption, market conduct, anti-money laundering and Counter-Terrorism and Proliferation of Weapon of Mass Destruction Financing.
  • ttb awards – an annual innovation competition aiming to motivate employees to propose initiatives that promote customers’ financial well-being and/or improve the Bank’s performance in six key areas, including a specific focus on data and risk management.
  • Incorporation of proper risk assessment for all products and services which the bank would like to offer to the customers into the Products and Services Approval Process (PSAP). The process ensures that adequate risk assessments are performed, and effective mitigation controls are put in place to manage the inherent risks within the Bank’s appetite.


Artificial Intelligence

At ttb, artificial intelligence (AI) is applied with a strong commitment to responsibility, transparency, security, and trust. The Bank's Responsible AI framework is anchored by the AI Minimum Standard (AIMS), which establishes an enterprise-wide governance and control framework covering the design, development, deployment, monitoring, and oversight of AI systems across their entire lifecycle.

AIMS is positioned under the Bank's Cyber & Digital Risk Management Policy and forms part of the Non-Financial Risk Framework, serving as a key control framework for managing AI-related technology and digital risks. It applies to all employees and contractors involved in AI technologies and helps ensure that AI is used in a secure, ethical, transparent, and risk-controlled manner.

The framework encompasses:

  • Enterprise-wide governance structure, roles, responsibilities, and accountability
  • End-to-end AI lifecycle management
  • AI risk management aligned with the Bank's risk appetite
  • Responsible AI principles based on Fairness, Ethics, Accountability, and Transparency (FEAT)
  • Compliance with applicable laws, regulations, and internal policies
  • Oversight and control mechanisms, including monitoring, explainability, and human oversight (Human-in-the-Loop and Human-over-the-Loop)
  • Business enablement to support efficiency, innovation, and digital transformation

These principles are embedded throughout the AI lifecycle, from design and development to deployment, monitoring, evaluation, and continuous improvement. Customer data is handled with strict privacy safeguards and supported by robust cybersecurity controls to protect systems, data, and users. The Bank actively works to identify, assess, and mitigate potential bias in AI models and outcomes, promoting fairness, inclusiveness, and equitable treatment.

Human oversight remains a fundamental safeguard. For AI use cases with material customer, operational, or risk implications, the Bank applies risk-based human oversight mechanisms to help ensure that decisions remain subject to appropriate review, intervention, and accountability. Clear governance structures define responsibilities and accountability throughout the AI lifecycle, while establishing boundaries for the appropriate use of AI, including requirements for human oversight, approved use cases, prohibited practices, and compliance with the Bank's policies and standards.

Transparency and explainability are key pillars of ttb's approach. The Bank seeks to ensure that the role of AI is appropriately communicated and that AI-generated or AI-supported outputs and decisions can be understood, interpreted, and explained. Where applicable, users are clearly informed when they are interacting with AI-powered services or when content, recommendations, or decisions are generated or materially supported by AI technologies.

To operationalize these principles, ttb implements a range of controls across the AI lifecycle. Access to sensitive AI capabilities is carefully managed through appropriate authorization and security measures. AI models are continuously monitored to maintain performance, reliability, and effectiveness, with established mechanisms to detect model drift or degradation, retrain models when necessary, and improve outcomes over time. Regular reviews help ensure that AI systems continue to operate in line with business objectives, ethical principles, and applicable regulatory requirements.

The Bank conducts regular assessments of deployed AI models to identify and mitigate potential bias and fairness concerns. Structured AI risk management processes evaluate operational, legal, regulatory, ethical, reputational, and technology-related risks associated with AI use cases and support appropriate controls throughout deployment and ongoing operation.

Customers and affected stakeholders are provided with channels to provide feedback, raise concerns, submit complaints, seek clarification, or request human assistance through established service and escalation channels, where appropriate. Users may also be provided with options to opt out of certain AI-enabled services when applicable, reinforcing a human-centered approach to technology adoption.

Recognizing the importance of responsible AI culture, ttb provides ongoing employee training and awareness programs covering the ethical, secure, and compliant use of AI technologies. The Bank also evaluates AI initiatives against defined business objectives, customer outcomes, and risk management requirements to support responsible innovation and long-term value creation.

Consistent with the Bank's ethical standards, Responsible AI principles, and applicable regulations, AI must not be used for discriminatory, manipulative, deceptive, or otherwise harmful purposes, including unauthorized uses that may undermine individual rights, freedoms, privacy, or human dignity. The Bank also prohibits the circumvention of governance, security, and compliance controls established for the responsible use of AI.

The effectiveness of the Bank's AI governance framework is supported by ongoing oversight, monitoring, and independent assurance activities, including periodic reviews and audits where appropriate.

Through this integrated approach, ttb seeks to ensure that AI not only enhances efficiency, innovation, and digital transformation, but also upholds the highest standards of responsibility, protecting customers, strengthening trust, and supporting sustainable long-term value creation.