Explainability is no longer a Saudi-specific expectation, or even a banking-specific one. It is where global financial regulation is converging. Canada’s OSFI finalized Guideline E-23, taking full effect in May 2027, which redefines what counts as a model to explicitly include AI and black-box systems, and requires institutions to manage explainability, fairness, and bias for every one of them, regardless of complexity (OSFI, via Moody’s 2025). The Bank for International Settlements’ Financial Stability Institute has published its own paper on the explainability trade-off in AI, arguing that regulators need “human-in-control” frameworks specifically because limited explainability makes it nearly impossible to catch bias or model drift before it causes harm (BIS FSI, via Moody’s 2025).
Not every regulator demands the same explanation, but all of them demand proof
The detail matters here, because the requirement is not identical everywhere. In the United States, the 2026 interagency guidance that replaced the long-standing SR 11-7 model risk framework does not impose a single, universal explainability rule. What it does require is risk-based governance: documented validation, monitoring, stated limitations and assumptions, and what regulators call effective challenge, meaning someone independent of the model’s builders has to be able to question it (Moody’s 2025, citing the 2026 interagency guidance). Canada’s approach is more explicit. The UK’s Prudential Regulation Authority and India’s Reserve Bank have each issued their own principles covering the same ground (Moody’s 2025). Different regulators, different wording, but the same practical demand: a bank has to be able to produce, on request, a specific account of why a model did what it did, whether the word used is explainability or something else.
Saudi Arabia has already taken a clear position on this
SDAIA’s Generative AI Guidelines call for exactly this standard inside the Kingdom. Systems have to be built to be appropriately explainable, with enough information available about how an automated decision was reached that a human can intervene if something looks wrong, and every output has to be checkable against an independent source before it is relied on. That puts Saudi Arabia ahead of the ambiguity still playing out in some other markets, not behind it. The guidance is advisory rather than legally binding today, which makes it a preview of where enforcement is heading rather than a reason to treat it as optional.
The trade-off regulators keep warning about is real
The BIS paper is candid about a genuine tension: the most accurate AI models are often the least interpretable ones, and forcing every system into a simple, fully transparent form can mean giving up real performance. That tension is why explainability cannot be solved by picking a different model. It has to be engineered into how the system operates, specifically into whether the reasoning behind a decision was captured at the moment it was made. A system that never recorded why an exception was granted cannot explain that exception later, no matter how interpretable its underlying model is. That is also why this question could not be answered on its own in an earlier stage of this argument. Explainability depends on memory existing in the first place.
What makes a decision explainable is built, not bolted on afterward
An explainable system is one where every action can be traced to the specific policy, data point, and prior exception that produced it, in language a compliance officer or a regulator can actually follow, not a confidence score or a plausible-sounding summary generated after the fact. Building that trace requires the same operating model this series has described from the start: policies modeled before an agent acts, a governed layer instead of a core replacement, and decisions retained rather than logged. Explainability is the payoff of getting the first three right, engineered inside the bank, on its own data, under its own policies, rather than purchased as a separate feature.
A bank that can produce that account, on demand, for any decision an agent made, owns something a regulator can trust and a competitor cannot easily copy. A bank that cannot produce it owns a liability it has not yet been asked to explain.
Saudi Arabia will not become the fintech capital other markets study by being the fastest to deploy AI. It will earn that position by being the first to prove, in full view of its own regulator, that it can be trusted with the decisions it made.
Sources
OSFI (Office of the Superintendent of Financial Institutions, Canada). Guideline E-23: Model Risk Management, effective May 2027. Cited via Moody’s, “From Compliance to Resilience: Regulators Drive New Standards for AI Model Risk Management,” 26 September 2025.
Bank for International Settlements, Financial Stability Institute. FSI Papers on AI and model risk. Cited via Moody’s, 26 September 2025.
Federal Reserve and US banking agencies. 2026 interagency model risk management guidance (successor to SR 11-7). Cited via Moody’s, 26 September 2025.
SDAIA (Saudi Data and AI Authority). Generative AI Guidelines. sdaia.gov.sa.