Central Bank of Jordan Artificial Intelligence Framework for the Banking Sector, Version 1.0
Guidance, not a law: the Central Bank of Jordan's reading of Personal Data Protection Law, comprehensive regime and lawful basis. It binds nobody by itself; the law it reads does.
Guidance on an AI sector rules rule, addressed to private bodies.
- Enforcement body
- Central Bank of Jordan
- Instrument type
- guidance published by a regulator
- Obligation class
- Governance, Disclosure, Security, Reporting
- Audit expectation
- continuous
- Who audits it
- Self
- Where the report goes
- Filed with regulator
As of .
What the regulator expects
- It reaches you if you are a banking institution regulated by the Central Bank of Jordan (CBJ): the CBJ says the framework applies to your use of AI whether you develop and implement AI internally, procure AI systems or outsource processes and functions that directly depend on AI (Scope and Definitions).
- The CBJ expects you to establish an AI oversight committee or clearly delegate AI governance responsibilities to an existing governance body, to have the use of AI in decision-making approved by an appropriate internal authority, to stay accountable for internally developed and externally sourced AI-driven decisions, and to designate an AI System Owner for each AI system (sections 1.1 and 2.4).
- The CBJ says you must adopt a risk-based approach and establish a framework that classifies AI applications by potential impact as low, medium or high risk and tailors oversight to each classification (section 1.3).
- The CBJ expects human-in-the-loop and human-on-the-loop mechanisms in proportion to the criticality and risk of each AI system, direct human oversight and intervention for critical systems, fallback procedures or human review, and contingency strategies including a kill switch (sections 5.2 and 5.4).
- The CBJ expects AI systems with material impact on customers, such as credit scoring or anti-fraud measures, to produce explainable outputs, and expects you to notify customers clearly and prominently, at the point of interaction, that they are interacting with AI-driven systems (section 2.2).
- The CBJ expects you to offer opt-out or alternative service options to customers who prefer not to interact with AI-driven systems, without compromising their access to essential banking services, to let customers access, correct and request deletion of their personal data where applicable, and to keep open channels for customers to question and appeal AI decisions that affect them (sections 2.3 and 2.4).
- The CBJ expects you to review and validate AI data, models and decisions to detect and mitigate bias, to conduct periodic AI Impact Assessments proportional to risk, to validate and robustness-test models, and to monitor AI performance continuously at a level matched to the use case and risk (sections 2.5, 2.6, 5.2 and 5.3).
- The CBJ expects you to log and keep auditable all data, models, decisions, user prompts and authorized overrides, to store logs in a secure, tamper-evident manner, and to provide regulatory authorities with comprehensive audit reports on AI decision-making processes (sections 2.2 and 4.2).
- The CBJ expects you to maintain a central AI Incident Registry and to notify FinCERT or the CBJ promptly of AI-related incidents in accordance with any CBJ instructions (section 6.1).
- The CBJ expects you to evaluate external AI solutions rigorously according to the criticality of the model, to put explicit clauses on responsibilities and liability, data privacy, intellectual property, bias mitigation, explainability and standards, and audit rights into vendor contracts, and to require an AI Bill of Materials from third-party vendors when applicable (section 7.1).
- The CBJ says that along with the framework you should adhere to the regulations, guidelines, frameworks and circulars it issues and to national cybersecurity and data privacy laws, including Personal Data Protection Law 24 of 2023 (section 3.1).
What this law does
The Central Bank of Jordan's framework is Version 1.0 of the Artificial Intelligence Framework for Banking Sector in Jordan, dated July 2025. The Central Bank of Jordan announced the issuance of a regulatory framework for using artificial intelligence in the Jordanian banking sector on .
The framework applies to the use of AI by banking institutions regulated by the Central Bank of Jordan, whether an entity develops and implements AI internally, procures AI systems or outsources processes and functions that directly depend on AI. The framework defines an entity as a banking institution regulated by the Central Bank of Jordan.
The framework says it is published and owned by the Central Bank of Jordan, which is responsible for evaluating and ensuring its effective implementation across entities, while the entities themselves are accountable for adopting, integrating and maintaining it within their operations. The framework describes itself as designed to guide institutions in governing, deploying and scaling AI capabilities securely and resiliently.
The framework says an entity should establish an AI oversight committee or clearly delegate AI governance responsibilities to an existing governance body within the entity. The framework says each entity must adopt a risk-based approach to manage AI applications, including a risk-based framework that classifies AI applications by potential impact as low, medium or high risk and tailors oversight to each classification.
The framework says an entity should ensure that the use of AI systems in decision-making is approved by an appropriate internal authority and should be accountable for both internally developed and externally sourced AI-driven decisions. The framework says an entity should designate an AI System Owner for each AI system, who is accountable for the system's governance, performance, compliance and ethical alignment throughout its lifecycle.
The framework says an entity should incorporate human-in-the-loop and human-on-the-loop mechanisms in proportion to the criticality and risk level of its AI systems, with direct human oversight and intervention for critical systems and continuous human monitoring for higher-risk systems.
The framework says an entity should design AI systems with fallback procedures or human review, and should develop contingency strategies, including a kill switch, for immediate human intervention in case of system malfunctions, particularly for critical applications. The framework says an entity should ensure that AI systems with material impact on customers, such as credit scoring or anti-fraud measures, can produce explainable outputs.
The framework says an entity should give customers clear and prominent notifications at the point of interaction that they are interacting with AI-driven systems. The framework says regulatory authorities should be provided with comprehensive audit reports on AI decision-making processes to ensure transparency and compliance.
The framework says an entity should implement clear opt-out or alternative service options for customers who prefer not to interact with AI-driven systems, and ensure customers can opt out of AI-driven processes without compromising their access to essential banking services.
The framework says an entity should ensure that customers can access, correct and request the deletion of their personal data, where applicable and subject to legal and regulatory obligations, particularly for Generative AI systems. The framework says an entity should maintain open channels for consumers to question and submit appeals to review AI decisions that affect them.
The framework says an entity should regularly review and validate AI data, models and the AI-driven decisions they produce to detect and mitigate biases, ensuring fairness in outcomes. The framework says an entity should conduct periodic AI Impact Assessments proportional to the risk level of the application, with higher-risk AI requiring more frequent and in-depth reviews.
The framework says that, along with the framework, an entity should ensure adherence to all applicable regulations, guidelines, frameworks, circulars and sector-specific security regulations issued by the Central Bank of Jordan, and to all national cybersecurity and data privacy laws and guidelines, including Personal Data Protection Law 24 of 2023. The framework says an entity should ensure that all data, models, decisions, user prompts and authorized overrides are logged and auditable.
The framework says an entity should store logs in a secure, tamper-evident manner to preserve integrity for regulatory audits or investigations. The framework says an entity should validate AI models against structured test scenarios and real-world conditions, measuring performance metrics such as accuracy, precision and recall. The framework says an entity should continuously monitor AI performance, adjusting the level of monitoring based on the use case and risk level.
The framework says an entity should establish and maintain a central AI Incident Registry and notify FinCERT or the Central Bank of Jordan promptly of any AI-related incidents in accordance with any instructions issued by the Central Bank. The framework says an entity should perform rigorous evaluations of external AI solutions, ensuring that vendors comply with Central Bank of Jordan and other relevant domestic regulations, based on the criticality of the AI model.
The framework says an entity should include in vendor contracts explicit clauses on responsibilities and liability, data privacy, intellectual property rights, bias mitigation, explainability and compliance with relevant standards, and provisions for audit rights. The framework says an entity should require third-party vendors, when applicable, to provide an AI Bill of Materials for all AI systems or solutions supplied.