Bangladesh banks and large financial institutions operate under layered policy frameworks: Bangladesh Bank guidance awareness, internal acceptable-use and data-classification rules, vendor and outsourcing standards, and increasingly explicit AI-use policies. Control owners publish PDFs; behaviour drifts in core banking adjacent systems, collaboration tools, and exception queues. Spot checks by compliance analysts do not scale across branches, shared services, and digital channels.
High-risk workflows — merchant onboarding file exports, credit document sharing, privileged access changes, model deployment requests — proceed without checking whether the activity matches the policy that supposedly governs it. Exceptions are granted in email and forgotten. When internal audit or Bangladesh Bank examination asks for continuous assurance, the answer is often sampling theatre rather than evidence chains.
Tool sprawl amplifies the gap. The same data-handling rule must be interpreted across SaaS logs, ERP events, ticketing systems, and document trails. Shadow IT and consumer AI tools create new gaps faster than legal can rewrite binders. Hiring more compliance headcount to manually review tickets linearly does not close the gap — it creates backlog without improving coverage reporting.
Banking anti-patterns are specific: punitive surveillance without due process, auto-blocking business-critical flows without named owners, monitoring against draft policies never approved by the board risk committee, and treating every minor deviation as equal severity. Proportionate response design is as important as detection. Alert fatigue causes control owners to ignore the queue; auto-blocks without Approvals paths create outages worse than the original breach.
Compliance owns frameworks; business lines own remediation; legal owns policy text; IT and security own telemetry. Programmes fail when monitoring starts before ratified policy text exists, or when telemetry cannot reach the systems where breaches actually occur. AI policy compliance monitoring for banking should map approved rules to observable events, flag likely breaches with evidence, route waivers through dual-control paths, and report coverage honestly — what is monitored and what remains blind.