Asiacom Group AI Governance & Responsible Use Framework cover
DOCUMENT STRUCTURE

Table of Contents

SectionTitle
1Purpose and Basic Philosophy
2Asiacom Core Governance Model
3Company Rules Before AI
4Human Decision Principle
5Approved AI Use
6Restricted AI Use
7Company Memory
8Information Governance
9External AI & Third-Party Services
10Traceability
11System Doctor
12AI Incident Management
13Transparency & External Communication
14Document Status, Review & Updates
Document TitleAsiacom Group AI Governance & Responsible Use Framework
PurposeGovernance Principles for Human-Controlled AI Use Across Asiacom Group
Review StatusDraft for Final Content Review
Publication StatusDraft / Not Yet Published
Core governance sequence: Company Rules → Authority → Business Context → AI Support → Human Decision
ASIACOM GROUP | AI GOVERNANCE & RESPONSIBLE USE
SECTION 01

1. Purpose and Basic Philosophy

1.1Purpose of this Framework

Asiacom Group uses artificial intelligence and AI-supported business systems to assist employees, management and business operations.

This AI Governance & Responsible Use Framework establishes the general principles used by Asiacom Group to govern the use of AI in a practical, controlled and responsible manner while maintaining clear human responsibility for important business decisions.

The Framework is intended to support employee productivity, document preparation, translation, operational assistance, business analysis, organisational knowledge and responsible use of external AI services.

1.2Basic Philosophy

Asiacom Group does not position AI as a replacement for employees, management responsibility or human judgment.

The Group’s basic principle is: AI supports the work. People remain responsible for the decision.

1.3Human and AI Division of Responsibility

AI may be used for classification, translation, summarisation, draft preparation, information retrieval, document analysis, operational assistance and identification of possible issues or alternatives.

Human members remain responsible for judgment, approval, negotiation, external commitments, risk acceptance, exception handling and final accountability.

1.4Practical and Proportionate Governance

Asiacom Group seeks to maintain AI governance that is proportionate to its actual business operations.

The priority is clear responsibility, controlled access, appropriate information handling, human approval for material actions, traceability where important, practical security and continuous improvement based on operational experience.

1.5External Reference Position

This Framework provides an external reference to Asiacom Group’s general approach to AI governance and responsible AI-supported operations.

Detailed internal controls, security information and technical implementation are maintained separately.

ASIACOM GROUP | AI GOVERNANCE & RESPONSIBLE USE
SECTION 02

2. Asiacom Core Governance Model

2.1Position of Asiacom Core

Asiacom Group uses Asiacom Core as the central operating and governance layer for AI-supported business activities.

Its role is not merely to function as a chatbot, but to connect company rules, permissions, workflow requirements, business context, organisational knowledge, AI-supported functions and human decision-making.

2.2Company Governance Before AI Output

AI-generated recommendations or outputs do not override Asiacom Group rules.

Where company rules, permission requirements, approval conditions or business restrictions apply, those controls take priority over an AI-generated suggestion.

2.3Basic Governance Order

The basic governance order is: Company Rules → Authority and Permissions → Business Context → AI Support → Human Decision where required.

2.4Supporting Business Systems

Asiacom Core may work with other internal systems used for employee assistance, document processing, translation, communication, transaction support, information analysis, organisational memory and system diagnostics.

The existence of multiple supporting systems does not create independent management authority for those systems.

2.5Separation of Support and Authority

Asiacom Group distinguishes between AI capability and company authority.

Technical capability alone does not constitute business authority.

2.6Internal Architecture and Public Disclosure

The public version of this Framework describes governance principles rather than detailed technical architecture.

Internal information such as system credentials, API endpoints, database structures, permission implementation and security mechanisms is maintained separately as non-public information.

ASIACOM GROUP | AI GOVERNANCE & RESPONSIBLE USE
SECTION 03

3. Company Rules Before AI

3.1Basic Principle

Asiacom Group maintains the principle that company rules come before AI-generated recommendations.

AI may assist in interpreting information or suggesting possible actions, but it should operate within established company rules, authority boundaries and workflow requirements.

3.2Types of Company Rules

Relevant company rules may include employee permissions, department responsibilities, required information, approval requirements, transaction status, access restrictions, information handling rules, storage requirements, communication requirements and escalation requirements.

3.3Permission Control

Access to AI-supported functions should reflect the responsibilities of the employee or management member using the system.

Not every employee requires access to every category of information or every AI-supported capability.

3.4Required Information

Where a business process requires specific information before execution, AI should not be used to bypass that requirement.

3.5Approval Conditions

Where company policy requires human approval, the AI-supported workflow should recognise that requirement.

AI may prepare information, identify missing information, summarise a case, recommend an option or prepare a draft, but it does not convert a required human approval into an automatic approval.

3.6No Autonomous Change of Company Rules

AI systems should not independently modify company rules, authority boundaries, approval requirements or material governance conditions.

Changes to such controls require appropriate human authority.

ASIACOM GROUP | AI GOVERNANCE & RESPONSIBLE USE
SECTION 04

4. Human Decision Principle

4.1Basic Principle

Asiacom Group maintains human responsibility for material business decisions.

AI may support analysis, preparation and operational work, but decisions creating material financial, contractual, compliance, legal, external or system responsibility remain subject to appropriate human confirmation or approval.

4.2Matters Requiring Human Decision

Human decision or approval may be required for payment approval, contract approval, material transaction approval, accounting judgment, compliance exceptions, official external commitments, personal-data matters, permission changes, production deployment and other matters involving significant responsibility.

4.3AI Recommendations

AI may provide recommendations, alternative options, risk indicators, summaries, draft responses, classifications and possible next actions.

Such outputs should be treated as decision support rather than automatic company decisions where human authority is required.

4.4External Communication

Important communication with banks, government offices, public authorities, financial institutions, customers, suppliers or other external parties may require responsible human review before final transmission.

4.5Incomplete or Uncertain AI Output

Where an AI output is incomplete, uncertain, contradictory or inconsistent with available information, the matter should not be treated as resolved merely because an AI system produced an answer.

Responsible users should verify the relevant facts, escalate where the matter exceeds their responsibility, or hold the action where material uncertainty remains.

4.6No Automatic Transfer of Responsibility

Use of AI does not transfer responsibility away from the responsible employee, manager or director.

The person or function authorised to make the decision remains responsible for the final action.

ASIACOM GROUP | AI GOVERNANCE & RESPONSIBLE USE
SECTION 05

5. Approved AI Use

5.1Basic Principle

Asiacom Group permits the use of AI where it supports legitimate business operations, improves employee productivity and remains within applicable company rules, permissions and human-responsibility boundaries.

5.2Information Organisation

AI may assist in classification, categorisation, extraction of key information, document sorting, identification of missing information, comparison of records and preparation of structured summaries.

5.3Translation and Language Support

AI may be used to support multilingual business operations, including translation, terminology support, multilingual drafting, communication assistance and document comprehension.

Where the communication is commercially, legally or institutionally important, responsible human review may be required before external use.

5.4Summarisation and Draft Preparation

AI may summarise emails, documents, meeting notes, transaction information, operational reports and internal reference material.

AI may also assist with draft emails, business correspondence, internal notes, reports, presentations and operational instructions.

5.5Document and Image Analysis

AI may assist in analysing documents, images and structured business information, including identifying key fields, comparing information, recognising apparent discrepancies and supporting document-review workflows.

AI analysis should not be treated as proof that a document is legally valid, authentic or complete unless appropriate verification has occurred.

5.6Business and Operational Analysis

AI may support internal analysis by identifying patterns, comparing alternatives, highlighting possible risks, suggesting questions, generating hypotheses and supporting management review.

5.7Employee Assistance

AI may support employees with ordinary tasks such as finding internal information, explaining company procedures, preparing routine drafts, summarising information, translation, organising work and directing the employee to an appropriate internal function where necessary.

5.8Appropriate Human Review

The level of human review should reflect the significance of the output.

Routine internal assistance may require limited review, while material external, financial, contractual, compliance or management matters may require formal human confirmation.

ASIACOM GROUP | AI GOVERNANCE & RESPONSIBLE USE
SECTION 06

6. Restricted AI Use

6.1Basic Principle

AI capability does not automatically create permission to perform an action.

Asiacom Group restricts AI from independently making or executing decisions where material company authority, financial responsibility, legal responsibility, compliance responsibility or sensitive system authority is involved.

6.2Financial Decisions

AI must not independently provide final approval for trade settlement, supplier payments, customer refunds, significant expenditure, banking instructions, transfers between accounts or other material movement of company funds.

AI may prepare information or recommendations for authorised human review.

6.3Contractual Decisions

AI must not independently approve a contract, accept binding contractual terms, commit a Group entity to a material obligation or make a final legal commitment on behalf of Asiacom Group.

6.4Accounting and Compliance Decisions

AI may assist with classification, checking, explanation and preparation, but it must not independently make final determinations concerning accounting treatment where human judgment is required, compliance clearance, acceptance of a material compliance exception or approval of a high-risk transaction.

6.5Employment and Personnel Decisions

AI should not independently make final decisions concerning significant employment matters such as hiring, termination, disciplinary action, material compensation decisions or employee sanctions.

6.6External Commitments

AI must not independently confirm a transaction, commit to a price or contractual term, make a formal representation to a bank or government authority, admit liability, provide official compliance confirmation or accept material obligations.

6.7System and Permission Changes

AI must not independently make material changes to production systems, user permissions, authority levels, security controls, company rules, approval requirements, system configurations or permanent operational data.

6.8Permanent Deletion and Circumvention

AI should not independently perform permanent deletion of important company records, transaction evidence, customer information, accounting information, governance records or other material business information.

AI must not be used to bypass required approvals, access controls, information restrictions, compliance review, retention requirements, security controls or other established company rules.

ASIACOM GROUP | AI GOVERNANCE & RESPONSIBLE USE
SECTION 07

7. Company Memory

7.1Purpose of Company Memory

Asiacom Group recognises that important business knowledge is created through the daily experience of employees, management and field operations.

Company Memory is intended to preserve and organise useful organisational knowledge so that experience is not lost when individual employees change roles, locations or responsibilities.

7.2Structured Organisational Knowledge

Company Memory may retain structured organisational knowledge derived from business experience, including decisions, reasons, lessons learned, operational methods and reusable business knowledge.

It is not intended to operate as an unrestricted archive of raw emails, personal information, banking records, customer records or other confidential source material.

7.3Practical Knowledge

Examples of practical knowledge may include how a transaction problem was resolved, how a logistics delay was handled, what information a bank previously requested, how a document discrepancy was corrected, which operational steps caused problems and what should be checked before similar work begins.

7.4Use and Retrieval

Where appropriate, information may be organised so that employees and authorised systems can retrieve relevant knowledge for future work.

Company Memory may support internal search, employee assistance, operational guidance, transaction preparation, incident prevention, management review and training.

7.5Current Judgment Still Required

Past decisions may have depended on circumstances that no longer apply.

Employees and responsible management should still consider current facts, current company rules, current transaction conditions, current authority and current external requirements.

7.6Relationship with Information Governance

Company Memory remains subject to Asiacom Group’s information governance, access-control and retention requirements.

7.7Retention and Relevance

Not all information needs to be retained indefinitely.

The Group may review, update, archive or remove information that is outdated, duplicated, no longer useful, inaccurate, no longer permitted to be retained or inconsistent with current company rules.

ASIACOM GROUP | AI GOVERNANCE & RESPONSIBLE USE
SECTION 08

8. Information Governance

8.1Basic Principle

AI-supported operations must be conducted with appropriate control of company information.

Asiacom Group seeks to use only the information reasonably necessary for the intended business purpose and to limit access according to responsibility and need.

8.2Categories of Information

Information used in AI-supported operations may include public information, internal business information, confidential business information, customer information, supplier information, transaction information, financial information, personal information, banking information and restricted internal information.

8.3Minimum Necessary Information

AI-supported processes should use the minimum amount of information reasonably necessary to perform the intended task.

8.4Purpose Limitation and Access Control

Information should be used for a legitimate and identifiable business purpose.

Access should reflect employee role, department, business responsibility, information sensitivity, authorised purpose and operational need.

8.5Sensitive Information

Personal, customer, supplier, financial and banking information should be handled with appropriate care.

Employees should consider whether the information is necessary before providing it to an AI-supported process.

8.6Confidential Business Information

Confidential company information should not be disclosed to an AI service merely for convenience.

Before using external processing, the Group should consider necessity, approval, access control, purpose and whether a less sensitive method is available.

8.7Accuracy, Data Minimisation and Retention

AI processing does not guarantee that the underlying information is accurate.

Where important decisions depend on the information, users should distinguish between source information and AI-generated interpretation, and retention should reflect business value, legal or operational requirements, information sensitivity, traceability needs and practical necessity.

ASIACOM GROUP | AI GOVERNANCE & RESPONSIBLE USE
SECTION 09

9. External AI & Third-Party Services

9.1Basic Principle

Asiacom Group may use external AI services, APIs and other third-party technology services where they provide legitimate business value.

External AI provides capability. Asiacom Group retains authority.

9.2Relationship with Asiacom Core

Where external AI services are connected to Asiacom Group systems, they may provide language processing, document analysis, summarisation, classification, information extraction, image analysis, business analysis and draft preparation.

Where appropriate, Asiacom Core or other authorised internal systems may provide the business context, rules and permissions surrounding such use.

9.3Approved Services and Minimum Necessary Data

Employees should use external AI services for company work only where their use is authorised or reasonably permitted under Asiacom Group rules.

When an external service is used, only information reasonably necessary for the intended task should be provided.

9.4No Company Authority for External AI

An external AI provider, model or service does not independently receive authority to approve transactions, approve payments, modify permissions, change company rules, make contracts, commit Asiacom Group externally, approve compliance exceptions, permanently delete important information or make material production-system changes.

9.5Controlled Connection and Service Change

Connections between internal systems and external AI services should be established for identifiable purposes and supported by appropriate controls.

As external services may change over time, Asiacom Group may review or change the use of a service where those changes materially affect company operations, security or governance.

9.6Service Failure and Non-Public Technical Information

Company operations should not assume that an external AI service will always be available or correct.

Detailed API credentials, security keys, internal endpoints and other sensitive technical configuration are maintained separately as non-public information.

ASIACOM GROUP | AI GOVERNANCE & RESPONSIBLE USE
SECTION 10

10. Traceability

10.1Basic Principle

Asiacom Group recognises that important AI-supported business activity should be reasonably traceable.

Traceability helps the Group understand what task was being performed, what information was used, how AI assisted, who reviewed the result, what final decision was made and what action followed.

10.2Risk-Based Traceability

The level of traceability should reflect the significance of the activity.

Routine internal assistance may require little or no formal record beyond normal business documentation, while more significant activities may require additional evidence.

10.3Possible Traceability Information

Where appropriate, a record may include business purpose, user or responsible function, relevant source information, AI-assisted output, identified issue or recommendation, human reviewer, approval or decision, final action and date or version information.

10.4Source and AI Output Separation

Where material accuracy is important, the Group should distinguish between original source information and AI-generated summaries, interpretations, classifications, recommendations or drafts.

10.5Human Decision Evidence

Where a material action requires Human Decision, the record should make it reasonably possible to distinguish AI recommendation, system status, human review and final authorised decision.

10.6Corrections and Retention

If an AI-supported output is found to be materially incorrect, relevant records may be corrected or supplemented.

Asiacom Group does not require every conversation with an AI system to become a permanent company record; retention should remain proportionate.

ASIACOM GROUP | AI GOVERNANCE & RESPONSIBLE USE
SECTION 11

11. System Doctor

11.1Purpose of System Doctor

Asiacom Group may use System Doctor as an internal monitoring and diagnostic function supporting AI-supported business systems.

Its purpose is to identify technical issues and support responsible review and corrective action.

11.2Monitoring and Diagnostic Role

System Doctor may help identify service errors, failed processes, abnormal conditions, integration problems or other technical issues requiring review.

It may collect relevant status information, compare expected and actual conditions, classify an incident and propose possible corrective actions.

11.3Recommendation, Not Automatic Authority

System Doctor may recommend corrective action, but a recommendation does not automatically authorise a material system change.

Asiacom Group distinguishes between diagnosis, recommendation, authority and execution.

11.4Material System Changes

System Doctor should not independently make material production changes where human approval is required, such as production deployment, permission changes, security-control changes, deletion of important data or material database changes.

11.5No Self-Approval

A system that identifies a problem should not automatically create its own authority to bypass established controls in order to correct that problem.

11.6Limited Automated Recovery

Limited automated recovery may be permitted only for pre-authorised, predefined and low-risk technical actions operating within established company rules.

Such recovery does not create authority to modify company rules, permissions, security boundaries, production logic or material business data.

11.7Records and Security

Material findings or corrective actions may be recorded where appropriate.

Diagnostic information may reveal sensitive technical details and access to such information should therefore be limited according to legitimate operational need.

ASIACOM GROUP | AI GOVERNANCE & RESPONSIBLE USE
SECTION 12

12. AI Incident Management

12.1Basic Principle

AI-supported systems may produce errors, incorrect outputs or unexpected behaviour.

Asiacom Group therefore uses a practical response model: Stop / Contain → Review → Human Decision → Corrective Action → Learn.

12.2Types of AI Incidents

AI-related incidents may include materially incorrect output, translation errors, inappropriate disclosure, excessive data exposure, action attempted outside authorised permission, failed AI service, integration error, suspicious access or other abnormal technical activity.

12.3Initial Containment

Where a material AI-related problem is identified, the immediate objective is to prevent unnecessary continuation of the problem.

Depending on the circumstances, this may include stopping the affected process, holding an external response, preventing execution, suspending a function, restricting access, preserving relevant records or notifying responsible management or technical personnel.

12.4Review and Human Decision

Relevant information should be reviewed to understand what occurred, what information was involved, whether an external party was affected, whether a company rule was bypassed and whether the issue remains active.

Responsible human members determine the next action, which may include resume, correct, restrict, disable, escalate or external response.

12.5Corrective Action

Corrective action may include correcting an AI output, replacing incorrect information, updating instructions, changing a workflow, changing permissions, improving validation, revising company guidance, modifying an AI connection, changing service provider or model or disabling an unsuitable function.

12.6Incident Records and Lessons Learned

Material incidents may be recorded where appropriate.

Where an incident reveals a recurring weakness, Asiacom Group may improve company rules, AI instructions, access controls, Human Decision requirements, information handling, system monitoring, employee guidance, validation processes or technical implementation.

ASIACOM GROUP | AI GOVERNANCE & RESPONSIBLE USE
SECTION 13

13. Transparency & External Communication

13.1Basic Principle

Asiacom Group seeks to communicate the use of AI in a clear, practical and responsible manner.

The Group is a trading group that uses AI and AI-supported systems to assist employees, management and business operations.

13.2Responsible Description of AI Use

Asiacom Group should avoid representations that suggest AI independently manages the company, approves transactions, controls company funds, makes contractual commitments, provides final compliance clearance, replaces management responsibility or operates without human governance.

13.3Asiacom Core in External Communication

Asiacom Group may publicly describe Asiacom Core as the central operating and governance layer supporting its AI-enabled business environment, including company rules, workflow support, permission-based operations, Company Memory, Human Decision and system monitoring.

13.4Public and Non-Public Information

Transparency does not require publication of confidential technical or operational information such as credentials, API keys, internal endpoints, database structures, security configurations, detailed permission logic, internal authority thresholds, confidential prompts or sensitive audit records.

13.5AI-Assisted External Content

AI may assist with the preparation of website content, business correspondence, company documents, translations, reports, presentations, images, summaries and other external materials.

Where the content is material, official or sensitive, responsible human review may be required before publication or transmission.

13.6Official External Responses and Disclosure

AI-generated or AI-assisted material does not automatically become an official Asiacom Group response.

Not every routine use of AI requires a specific public disclosure, but where disclosure is appropriate because of the nature of the interaction, the significance of the output or applicable requirements, Asiacom Group may identify that AI or AI-supported processing was involved.

13.7External Enquiries Concerning AI Governance

Banks, business partners, government offices, public authorities or other qualified counterparties may request information concerning Asiacom Group’s use of AI.

Where appropriate, the Group may provide information regarding AI governance principles, Human Decision, information handling, approval controls, use of external AI services, incident management, system monitoring and other relevant governance arrangements.

ASIACOM GROUP | AI GOVERNANCE & RESPONSIBLE USE
SECTION 14

14. Document Status, Review & Updates

14.1Status of this Framework

The Asiacom Group AI Governance & Responsible Use Framework is an external reference document explaining the Group’s basic principles for responsible AI-supported business operations.

14.2Purpose of Publication

The purpose of publication is to provide customers, business partners, financial institutions, public authorities and other interested parties with a clear explanation of how Asiacom Group approaches AI governance, Human Decision, Asiacom Core, Company Rules, approved and restricted AI use, Company Memory, information governance, external AI services, traceability, System Doctor and AI incident management.

14.3Scope and Limitation

This Framework describes general Asiacom Group principles.

It does not constitute legal advice, regulatory advice, technical certification, cybersecurity certification, contractual commitment, service-level guarantee or assurance that AI output will always be accurate.

14.4Relationship with Internal Controls

This public Framework does not contain every internal operating rule.

Asiacom Group may maintain additional non-public controls concerning authority, permissions, approval thresholds, system configuration, technical security, data access, deployment, incident response, internal audit evidence and other detailed implementation requirements.

14.5Relationship with Trade Governance

AI-supported operations used in trade activities should also operate within the relevant principles of the Asiacom Group Trade Governance & Compliance Framework.

AI Governance determines how AI may assist the work. Trade Governance determines how the underlying transaction is governed.

Where both Frameworks apply, the underlying trade transaction remains subject to the Trade Governance & Compliance Framework, and AI use remains subject to this AI Governance & Responsible Use Framework. Where controls overlap, the more restrictive applicable control should be followed until responsible human review is completed.

14.6Version Control and Periodic Review

This Framework should maintain identifiable version information and should be reviewed where there is a material change in AI-supported business operations, Asiacom Core, Company Memory, external AI services, information-handling practices, internal authority arrangements, system monitoring, incident experience, company structure or relevant external requirements.

14.7Technology-Neutral Governance and Closing Principle

The principles of this Framework are intended to remain applicable even when individual AI models, providers or technologies change.

Asiacom Group does not base its governance solely on a particular AI model or service provider.

The Group’s governance remains centred on Company Rules, Authority, Information Control, Human Decision, Traceability and Responsible Operations.

ASIACOM GROUP | AI GOVERNANCE & RESPONSIBLE USE
Asiacom Group AI Governance & Responsible Use Framework back cover