This study aims to examine how digital policy and regulatory governance should respond to vendor-mediated generative artificial intelligence (AI) in regulated financial services. It argues that the central problem concerns not only model assurance but also the evidentiary pipeline through which customer data, vendor processing, generated outputs and human review become auditable.
The article uses a conceptual and design-orientated documentary comparison of Singapore and Vietnam. It analyses AI governance, data protection, financial supervision and third-party risk instruments through four functional axes, derives operational indicators from the documentary corpus and examines their internal coherence through a structured illustrative case in financial services.
Singapore’s interoperability-orientated model and Vietnam’s dossier-based model of legal visibility provide different regulatory entry points. Both remain incomplete unless institutions preserve workflow-level evidence across procurement, configuration, deployment, output verification and supervisory review.
The framework links risk triggers to pipeline maps, vendor due diligence, transfer records, output-verification protocols and audit trails.
The article develops a conceptually grounded pipeline accountability framework that connects vendor obligations, data movement, generated outputs and human verification. It is operationally specified but remains a design proposition requiring empirical testing and refinement.
