A Hybrid COBIT 2019–RAG Framework to Enhance Consumer Protection Compliance in Digital Finance

Authors

DOI:

https://doi.org/10.26877/asset.v8i4.2088

Keywords:

COBIT 2019, retrieval-augmented generation (RAG), regulatory compliance, consumer protection, digital finance, governance framework, governance automation, compliance technology

Abstract

The rapid growth of digital financial services has increased the need for effective regulatory compliance mechanisms, particularly for consumer protection. This study develops and evaluates a hybrid COBIT 2019–Retrieval-Augmented Generation (RAG) framework for compliance with Indonesia’s OJK Regulation No. 22/2023 in a digital multifinance context. Using a design science research methodology, COBIT 2019 design factors were applied to tailor governance objectives, while a RAG pipeline was evaluated on 100 synthetic compliance queries using RAGAS metrics and expert-validated reference answers. The governance assessment prioritized EDM03, APO12, and MEA03, each assessed at capability Level 2 against a target of Level 4, indicating gaps in risk optimization, risk management, and external compliance. The optimal RAG configuration achieved an overall score of 0.8257, with context recall of 0.9217, faithfulness of 0.8502, and semantic similarity of 0.8629. It also outperformed baseline keyword search in retrieving semantically relevant regulatory passages, although broader benchmarking remains limited. The findings show that integrating structured IT governance with AI-assisted regulatory retrieval can strengthen accountability, regulatory interpretation, and compliance decision support. The framework offers a scalable approach for regulated industries, subject to further validation using real operational data and broader institutional settings.

Author Biographies

  • Edy Salim, Swiss German University

    Data Science Business Informatics, Engineering and Information Technology, Swiss German University, Tangerang, Banten, 15143, Indonesia

  • Mohammad Achmad Amin Soetomo, Swiss German University

    Data Science Business Informatics, Engineering and Information Technology, Swiss German University, Tangerang, Banten, 15143, Indonesia

  • Eka Budiarto, Swiss German University

    Data Science Business Informatics, Engineering and Information Technology, Swiss German University, Tangerang, Banten, 15143, Indonesia

References

[1] Tan D. Demystifying the proliferation of online peer-to-peer lending in Indonesia: Decoding fintech as a regulatory challenge. Asian Journal of Law and Society 2023;10:376–400. https://doi.org/10.1017/als.2022.21.

[2] Amalia C, Poetry EG, Kono MK, Kusuma DA, Kurniawan A. Legal issues of personal data protection and consumer protection in open api payments. Journal of Central Banking Law and Institutions 2022;1:323–52. https://doi.org/10.21098/jcli.v1i2.19.

[3] Makur A, Astutik S. Analisis peran Otoritas Jasa Keuangan (OJK) dalam pengawasan dan regulasi industri perbankan di Indonesia. Gemah Ripah: Jurnal Bisnis 2023;3:42–6.

[4] Agung AA, Erlina E. Perlindungan Hukum Terhadap Konsumen Pengguna Jasa Pinjaman Online. Alauddin Law Development Journal 2020;2:432–44. https://doi.org/10.24252/aldev.v2i3.13190.

[5] Aminullah MZ. Consumer protection in binding sale and purchase agreements of subsidized housing. Journal of Law and Social Politics 2026;4:1–5. https://doi.org/10.59261/jlsp.v4i1.66.

[6] Jeyasingh BBF. Impact of RegTech on compliance risk due to financial misconduct in the United States banking industry. Digital Economy and Sustainable Development 2023;1:24. https://doi.org/10.1007/s44265-023-00024-z.

[7] Kusuma FW. The effect of financial services authority regulatory implementation concerning financial consumer protection on banking financial performance. Eduvest-Journal of Universal Studies 2023;3:1289–302. https://doi.org/10.59188/eduvest.v3i7.845.

[8] Nitha Pricillia. Comparison of Indonesian Banking Regulation for Integrated Governance, Risk Management, Compliance with Its ISO Counterparts. RSF Conference Series: Business, Management and Social Sciences 2021;1:84–96. https://doi.org/10.31098/bmss.v1i5.455.

[9] Indraswari SP, Fathurohman DT. Legal Review of the Administration of Aesthetic Clinics Consumer Protection and Legal Liability in the Administration of Aesthetic Clinics: A Normative Juridical Analysis under Indonesian Health Law. Journal of Law and Social Politics 2026;4:404–12. https://doi.org/10.59261/jlsp.v4i3.151.

[10] Haes S, Grembergen W. COBIT as a Framework for Enterprise Governance of IT. Management for Professionals 2015:103–28. https://doi.org/https://doi.org/10.1007/978-3-030-25918-1_5.

[11] Becker M, Merz K, Buchkremer R. RegTech—the application of modern information technology in regulatory affairs: areas of interest in research and practice. Intelligent Systems in Accounting, Finance and Management 2020;27:161–7. https://doi.org/10.1002/isaf.1479.

[12] Gao Y, Xiong Y, Gao X, Jia K, Pan J, Bi Y, et al. Retrieval-augmented generation for large language models: A survey. ArXiv Preprint ArXiv:231210997 2023. https://doi.org/10.48550/arXiv.2312.10997.

[13] Saad-Falcon J, Khattab O, Potts C, Zaharia M. Ares: An automated evaluation framework for retrieval-augmented generation systems. Proceedings of the 2024 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies (Volume 1: Long Papers), 2024, p. 338–54. https://doi.org/10.18653/v1/2024.naacl-long.20.

[14] Jeong C. A study on the implementation of generative AI services using an enterprise data-based LLM application architecture 2023. https://doi.org/10.54364/AAIML.2023.1191.

[15] Zhao P, Zhang H, Yu Q, Wang Z, Geng Y, Fu F, et al. Retrieval-augmented generation for ai-generated content: A survey. Data Sci Eng 2026;11:1–29. https://doi.org/10.1007/s41019-025-00335-5.

[16] Es S, James J, Anke LE, Schockaert S. Ragas: Automated evaluation of retrieval augmented generation. Proceedings of the 18th conference of the european chapter of the association for computational linguistics: system demonstrations, 2024, p. 150–8. https://doi.org/10.18653/v1/2024.eacl-demo.16.

[17] Yu H, Gan A, Zhang K, Tong S, Liu Q, Liu Z. Evaluation of retrieval-augmented generation: A survey. CCF Conference on Big Data, Springer; 2024, p. 102–20. https://doi.org/10.1007/978-981-96-1024-2_8.

[18] Moudoubah L, El Yamami A, Mansouri K, Qbadou M. From IT service management to IT service governance: An ontological approach for integrated use of ITIL and COBIT frameworks. International Journal of Electrical and Computer Engineering 2021;11:5292–300. https://doi.org/10.11591/IJECE.V11I6.PP5292-5300.

[19] Audia R, Sugiantoro B. Evaluation and Implementation of IT Governance Using the 2019 COBIT Framework at the Department of Food Security, Agriculture and Fisheries of Balangan Regency. IJID (International Journal on Informatics for Development) 2022;11:152–61. https://doi.org/10.14421/ijid.2022.3381.

[20] Jawad MM, AMH, KAA, & HMF. Evaluating the performance of IT management under the implementation of the COBIT 2019 framework. Eximia 2023;12:18–36. https://doi.org/10.47577/eximia.v12i1.331.

[21] Yasin M, Arman AA, Edward IJM, Shalannanda W. Designing information security governance recommendations and roadmap using COBIT 2019 Framework and ISO 27001: 2013 (Case Study Ditreskrimsus Polda XYZ). 2020 14th International Conference on Telecommunication Systems, Services, and Applications (TSSA, IEEE; 2020, p. 1–5. https://doi.org/10.1109/TSSA51342.2020.9310875.

[22] Marchão J, Reis L, Ventura P. Operation management using ITIL and COBIT framework. Conference Proceedings (part of ITEMA conference collection), 2020, p. 201–7.

[23] Meaney C, Stukel TA, Austin PC, Escobar M. Comparing Variation in Tokenizer Outputs Using a Series of Problematic and Challenging Biomedical Sentences. ArXiv Preprint ArXiv:230508787 2023. https://doi.org/10.48550/arXiv.2305.08787.

[24] Juvekar K, Purwar A. Introducing a new hyper-parameter for RAG: Context Window Utilization. ArXiv Preprint ArXiv:240719794 2024. https://doi.org/10.48550/arXiv.2407.19794.

[25] Alavi M, Leidner D, Mousavi R. Knowledge management perspective of generative artificial intelligence (GenAI). Alavi, Maryam 2024:1–12. https://doi.org/10.17705/1jais.00859.

[26] Megasyah Y, Arifnur AA. Academic Information System Security Audits Using COBIT 5 Framework Domains APO12, APO13 and DSS05. Journal of Applied Engineering and Technological Science (JAETS) 2020;1:124–135. https://doi.org/10.37385/jaets.v1i2.79.

[27] Nurbojatmiko N, Aini Q, Wasiqi NC, Alfajri MF, Ulinnuha Z, Purwati YK, Ayu IK, Yasmin NA. Risk Assessment Maturity Level of Academic Information System Using ISO 27001 System Security Engineering-Capability Maturity Model. Journal of Applied Engineering and Technological Science (JAETS) 2024;5:941–954. https://doi.org/10.37385/jaets.v5i2.2971.

[28] Elmobark N. A Comparative Analysis of Python Text Matching Libraries: A Multilingual Evaluation of Capabilities, Performance and Resource Utilization. International Journal of Environment, Engineering and Education 2025;7:48–60. https://doi.org/10.55151/ijeedu.v7i1.188.

Downloads

Published

2026-09-18