Ask any banking leader in the region whether AI is on the roadmap, and the answer is yes. Ask them where it actually sits today, and the tone changes.
The Research
That gap was the subject of a study conducted by Sabio World across 14 Malaysian banking institutions earlier this year.
The finding: 76% of respondents said they were still running pilots or scaling AI unevenly across enterprise divisions (“scaling in pockets” — some divisions ahead, most not).
Only 24% described themselves as actively scaling with a genuine cross-divisional programme.
The same study asked where AI breaks down inside an institution. Three constraints came up, in this order:
- Legacy infrastructure (43%): AI can only reach core systems through workarounds.
- Data (36%): silos across the estate, with governance frameworks that don’t align.
- Ownership (21%): sponsorship exists, but no single leader is accountable for pushing AI through.
When asked about the cost of failing to scale AI, respondents pointed to the same three layers: 43% to duplicated effort across divisions solving the same problem separately, 36% to revenue opportunities they can see but can’t act on, and 21% to risk accumulating in decisions made without proper model support.
Taken on its own, that’s already a clear diagnosis: the constraint on enterprise AI in ASEAN banking isn’t ambition, or even the technology — it’s the foundation underneath it.
The Discussion
That research formed the backdrop for a closed-door roundtable in Kuala Lumpur, hosted by Sabio World and sponsored by Cognizant, bringing together senior banking and financial services leaders from across Malaysia to discuss what the findings meant on the ground.
On Infrastructure, the conversation surfaced a candid admission: almost every institution present had a legacy workaround running somewhere, rather than a resolved fix.
The blocker, participants said, isn’t cost. It’s courage and sequencing: the courage to touch a core system that currently works and to absorb the outage risk and disruption that may follow, and the sequencing to decide which component goes first, what waits, and what depends on what.
With little documentation of how these systems actually work, that is not an easy call to make.
A workaround lets AI sit on top of infrastructure it was never designed to talk to, which is fine inside a pilot but starts to fail exactly when that pilot tries to go enterprise-wide.
On Data, the discussion centred less on quality and more on ownership.
Every institution wants AI to use its data. Far fewer people want to be the ones accountable for it — and when no one has been explicitly told the data is theirs to certify, no one steps forward to certify it.
AI initiatives quietly wait at the door.
On “scaling in pockets”, several leaders noted that this is the most deceptive place to be in, because it looks like progress.
A pocket of success can mask the fact that the operating model that made one division work was never extended anywhere else.
Infrastructure and data fractures feed each other.
The institutions that haven’t modernised their core connectivity are, predictably, also struggling with siloed data.
They aren’t two independent problems competing for budget. They’re one problem showing up twice.
What Can Help You Get Unstuck?
Diagnosis is the easy part; most leaders in the room already knew where their own fractures sat. The harder, more useful conversation was what to do next.
Two paths came up, neither of them novel: one on modernising the foundations, another one on governing AI once it’s running on top of them. Both are well established in the industry.
What the room debated was not whether they were right, but what it’d take to execute them.
1) Modernisation: Treat It As a Structured Decision, Not a Single Heavy Lift
- Map the estate first. Understand what each legacy component is costing you, and why, before committing to a path.
- Match the treatment to the component. Some systems can be lifted and shifted at low risk and low cost; others need re-architecting; some should simply be retired because the function already exists elsewhere. Not every component deserves the same response.
- Fund it from what it saves. Optimising and stabilising what’s running today — trimming licensing and infrastructure spend on the legacy estate — can fund the modernisation that follows, turning it into a self-reinforcing cycle rather than a one-off ask to the board.
- Build governance in, from day one. Human checkpoints on what changes, audit trails on what moved — engineered into the modernisation itself, not bolted on afterwards.
While there was agreement on the approach, leaders pointed out that there are specific reasons organisations still can’t move fast.
Some said the capability and bandwidth simply weren’t there: the people who designed and built these legacy applications have long since left, and the teams that would have to map the estate and re-architect it are the same teams already running the bank day to day.
The good news is that now we have modern AI-powered solutions help address this challenge, from discovery, code and dependency analysis to operation.
Others said the challenge was a business case.
Building a programme that genuinely funds itself from what it saves and then getting the board to back it on that basis has proved harder than agreeing it is the right thing to do.
2) Governance: Extend What Already Exists, Rather Than Build New
The approach the room kept returning to was not to build new governance structures for AI, but to extend the three-lines-of-defence model most institutions already run for traditional risk:
- The business (Layer 1) owns the AI workflow day to day and sets the thresholds and approval gates.
- Risk and compliance (Layer 2) independently audits that design and can pause or restrict the system.
- Internal audit (Layer 3) checks after the fact whether the controls held.
Most institutions already have all three lines in place.
The gap isn’t structure, it’s scope: those same lines haven’t yet been told to look at what the AI is doing.
As one leader in the room put it, everyone owns a piece of AI, but no one owns all of it — a fracture the room agreed is worth closing by pointing existing committees at the problem, rather than adding a new one.
Put together, the research and the conversation it prompted told a consistent story: technology is not what’s missing.
What’s missing is usually a self-funded business case that the board will back, the courage to accept the disruption that modernising may cause and press ahead anyway, the sequencing, clear ownership, and the will to extend structures that already exist rather than wait for perfect new ones.
For COOs, CIOs and CDOs across ASEAN banking: if your institution is still scaling in pockets, which of these constraints is holding you back?
And if you are already scaling evenly across the enterprise, I would be keen to hear what got you there.
Featured image: Edited by Fintech News Singapore based on an image by Cognizant.
