Blog

What Decision 33/2026 means for banks

Vietnam's high-risk AI list has two entries for banking, and both apply only when no human approves. That changes what banks must do before September 2027.

Tan TranLeads Sancire, the data and AI practice of Titan Technology

Since the start of the year, many compliance teams at banks have been planning on the assumption that every AI model in production needs a conformity assessment before 1 September 2027. That was a reasonable assumption while there was no list. Now there is one. Decision 33/2026/QD-TTg was signed on 30 June 2026 and has been in force since 15 August 2026. It is shorter than most people expected, and it says something quite different.

For most of what banks run today, the required work is not a conformity assessment. It is a documented classification, and proof that a human approves.

The list is closed

Decree 142/2026/ND-CP, Article 6.3, sorts AI systems into three tiers. High-risk systems are those on the list issued by the Prime Minister. Medium-risk systems are those not on the list but caught by Article 9. Everything else is low-risk.

In other words, a model does not become high-risk because it feels sensitive. It is high-risk only if it matches a specific entry in the annex of Decision 33, including that entry’s condition of application.

The annex has 46 systems in 6 sectors:

Sector Entries
Education 3
Ethnic and religious affairs 7
Healthcare 2
Banking 2
Judicial proceedings 1
Transport 31

Of the 31 transport entries, 28 are aviation. Insurance has no entry. Securities has no entry. Healthcare covers only surgical robots and robots that execute medical orders on a patient.

The two banking entries

In summary, from the digitally signed copy:

  1. AI systems that automatically execute high-value electronic banking transactions without human control.
  2. AI systems that automatically decide to grant credit without independent approval by a credit officer.

Both share one condition: the system acts on its own, and no human controls or independently approves. That condition is not a footnote. It is what decides whether a system is on the list or off it.

So a credit scoring model where every application still goes to a credit officer for approval does not match entry 2. A fraud model that only flags transactions for a person to decide does not match entry 1. What does match is straight-through processing of high-value transactions that nobody looks at, and automatic credit approval that no officer signs.

The list can be amended, and Decree 142, Article 11.1(c), requires re-classification when that happens. So a conclusion of “not on the list” should record the date of the check and the version of the text used.

Three things you still have to do

Being off the list does not mean there is nothing to do. There are three things, and all three apply now, not in 2027.

Classify each system, and stand behind the result

Article 6.1 of Decree 142: the provider classifies a system before putting it into use, and is legally accountable for the accuracy of the result. A bank using a third party’s system must, under Article 6.4, work with the provider to re-classify when integration or changes create new risk.

For high-risk and medium-risk systems, Article 12 requires a classification file with four parts: identification of the system, a description of the system and its context of use, the main input data, and a summary of risk management measures. The file does not have to contain source code or model parameters, and it must be kept for as long as the system operates. If the system uses personal data, the impact assessment already required by personal data law can replace or be merged into it.

Low-risk systems are not subject to Article 12. But when someone asks why a system is low-risk, the answer needs to exist. One page stating what the system is, which entries were checked, why none matched, and when the check was done, is enough and cheap.

Prove that a human approves

This is where many banks will stumble. The written procedure says an officer approves. But an inspector does not ask for the procedure. They ask for evidence.

Decree 142, Article 8.2(b), describes what substantive human oversight means: an authorised person can independently review, intervene in, reject or change the system’s decision before it takes effect. Those four verbs have to leave a trace. Who approved, when, what they saw at the time (model version, inputs, score), whether they could reject, and how often they did.

If the logs show that one hundred percent of applications were approved within two seconds, that is not independent approval, whatever the procedure says. Article 11.5 states the regulator’s expectation plainly: the person overseeing the system must have enough information and authority to assess independently, and operating logs together with every intervention must be retained for inspection.

This is exactly where a data platform earns its keep. The approval trail is a table, linked to the model version and the input data that were used, with lineage, access control and retention. It comes from logs, not from testimony.

Re-classify when the system changes

Article 11.1 lists the events that trigger re-classification. The one that matters most is 11.1(a): a significant change in function, purpose or deployment context that affects the original classification criteria. Raising the auto-approval threshold, removing the officer step for small loans, or connecting the model to a new product are all changes of that kind. Performance upgrades, bug fixes and routine data refreshes are not, under Article 11.4.

If re-classification results in a higher tier, Article 11.3(a) requires notifying the competent authority within 15 working days and applying the measures of the new tier immediately. The simplest way not to miss this is to add one classification question to the change control process the bank already has.

Who the 1 September 2027 deadline applies to

The Law on Artificial Intelligence 134/2025/QH15 came into force on 1 March 2026. Article 35 gives systems already in operation before that date a transition period of 18 months in the financial sector, which ends on 1 September 2027. That date matters only for systems on the list: it is the deadline for completing the conformity assessment under Article 13.

Systems not on the list have no conformity assessment deadline. But the classification obligation applies now, before a system is put into use. A new system that is on the list must be assessed before it is used, with no transition period.

Two things on the side

A customer-facing chatbot is not on the list. But under Article 9.1, it becomes medium-risk if users cannot tell they are talking to an AI. That brings transparency obligations and a classification file under Article 12. Labelling the assistant as such at the start of every conversation is the cheapest way to stay in the low tier.

And the largest financial exposure is still not in the AI law. The Personal Data Protection Law 91/2025/QH15, Article 8.4, sets fines of up to 5% of the previous year’s revenue for breaches of the rules on transferring personal data abroad. Keeping data in the bank’s own cloud account and region is the simplest answer, and it is also what keeps the approval trail described above under the bank’s own control.

What we do

Sancire prepares a documented classification for each system, checked entry by entry against Decision 33 and against the exclusions in Decree 142, with the date and the version of the text recorded. And we build the approval trail on the bank’s own data platform, so that the answer to an inspector comes from logs. The Vietnam page sets out the scope, and the Govern stage is where this sits in our services.


Sources: Decision 33/2026/QD-TTg, digitally signed copy, checked on 15 September 2026. Decree 142/2026/ND-CP, in force 1 May 2026, Articles 6, 8, 9, 11, 12 and 13. Law on Artificial Intelligence 134/2025/QH15, Articles 13 and 35. Personal Data Protection Law 91/2025/QH15, Article 8. This article is an introduction and does not replace legal advice for a specific case.

Talk to us

Tell us what you are working on. A named person replies within one business day.

We use these details only to reply to you. No mailing list. Privacy.