Search the Atlas

Search risks, controls, and glossary terms

Non-AgenticLegal Compliance

Cross-Border Transfers

Explanation

Cross-Border Transfers checks whether personal or sensitive data moved out of its home jurisdiction during AI processing is going to acceptable destinations under privacy and data-localisation rules — a frequent concern for international banking operations that route customer data or model calls to overseas providers. It matters because transferring sensitive financial data to a high-risk country can violate RBI data-privacy expectations and expose the bank to legal and security risk. It is measured by the Transfer Risk Level, computed as Transfer Risk = Σ(Country_Risk_i × Data_Sensitivity_i × Transfer_Volume_i), so each transfer accumulates risk proportional to how risky the destination country is, how sensitive the data is, and how much of it moves. To implement, inventory every cross-border data flow in the AI pipeline, tag each with a country-risk rating, a data-sensitivity classification and a measured volume, compute the weighted sum continuously, and log source, destination, data category and volume as evidence aligned to NIST GOVERN 1.1/2.1 and ISO Clause 5.2/5.3. The threshold is a Transfer Risk Level below 50 on a 0–100 scale; crossing it is an immediate-priority breach that should halt or reroute the transfer, restrict it to approved jurisdictions, and escalate for legal review.

Metric calculation

Transfer Risk = Σ(Country_Risk_i × Data_Sensitivity_i × Transfer_Volume_i) For international banking operations.

Risks mitigated

2