Indonesia’s POJK No. 30/2025 and the governance of digital financial intermediation
DICRI Regulatory Watch | Indonesia | Alternative credit scoring | Financial aggregation | Platform finance
Regulation No. 30 of 2025 on governance and risk management for Financial Sector Technology Innovation operators, issued by Indonesia’s Financial Services Authority, Otoritas Jasa Keuangan (OJK), has entered into force on 1 July 2026. The regulation applies to Penyelenggara ITSK, defined as operators of financial-sector technology innovation that hold a business licence from OJK.
In its English press release on POJK No. 30/2025, OJK describes the regulation as part of its effort to strengthen governance and risk management in the financial-sector technology innovation ecosystem. The press release confirms that POJK No. 30/2025 applies to licensed Financial Sector Technology Innovation platforms, including Alternative Credit Scoring providers and Financial Services Aggregators.
Core features of POJK No. 30/2025
POJK No. 30/2025 requires licensed ITSK operators to apply good governance at every level of the organisation. The regulation identifies five governance principles: transparency, accountability, responsibility, independence and fairness. It also links governance to board supervision, risk management, internal audit, external audit, conflict-of-interest controls, information disclosure, business ethics, transparency of financial and non-financial conditions, personal-data protection and information-system security.
The regulation contains specific rules on board composition and competence. Licensed ITSK operators must have at least two directors. Of these, at least one director must have knowledge or experience in financial-sector technology innovation, information technology or financial services, evidenced by certification or at least three years of relevant work experience. The president director must be independent from the controlling shareholder and domiciled in Indonesia, and at least 50% of the board of directors must be domiciled in Indonesia.
Under Article 5, OJK may assess the implementation of good governance and require corrective action. The regulation also allows OJK to evaluate and order corrective action in relation to the appointment, dismissal, replacement or resignation of directors and commissioners where the conditions in the regulation are met.
Risk management is treated as a continuing institutional obligation. Licensed ITSK operators must apply risk management effectively, have an early warning system for risks, and periodically evaluate their risk-management arrangements. The regulation identifies six risk categories: strategic risk, operational risk, cyber risk, legal risk, compliance risk and reputational risk. Cyber risk is defined as risk arising from attacks, failures, vulnerabilities or security gaps in information systems that may cause loss or negative effects for information technology systems, data or operations.
The regulation requires operators to maintain risk-management systems covering board oversight, policies and procedures, risk limits, risk identification, risk measurement, risk control, risk monitoring, risk-management information systems and internal controls. Operators must also establish a risk-management function that is independent from business and operational functions and from internal-control functions.
The reporting framework is both periodic and event-driven. Licensed ITSK operators must conduct semi-annual self-assessments of their risk profile for June and December and submit risk-profile reports to OJK. They must also submit an additional risk-profile report where a condition arises that may cause significant financial loss. That additional report must be submitted no later than one month after the relevant condition becomes known.
The regulation also connects governance with consumer-data accountability. Licensed ITSK operators must disclose and account for their use of consumer data in accordance with personal-data protection law. The explanatory section indicates that this may include disclosure of how data are processed in service provision, from input to output, and the accuracy level of the methods, models or innovations used to process alternative data.
The enforcement structure includes administrative sanctions. These may include written warnings, temporary suspension of some or all activities, administrative fines, inclusion of relevant principal parties in OJK’s list of prohibited parties in the financial sector, and revocation of the business licence. Separate fines apply for late or non-submission of certain governance and risk-profile reports.
Relevance for digital credit markets
The regulation is not limited to credit providers. Its relevance for digital credit lies in the position of alternative credit scoring providers and financial-service aggregators within the credit ecosystem. These actors may influence how consumers are assessed, how financial products are displayed, how offers are compared, and how access to credit is practically structured.
POJK No. 30/2025 therefore illustrates a form of supervision directed not only at financial products, but also at the organisations, systems and controls that support digital financial intermediation. In platform-mediated credit markets, consumer-facing risks may arise before a credit agreement is concluded. They may arise from data processing, scoring methodologies, ranking mechanisms, aggregation design, outsourcing arrangements, conflicts of interest or weak internal controls.
Wider regulatory context
POJK No. 30/2025 can be situated within a wider, albeit uneven movement toward the supervision of digital financial infrastructure. The relevant comparison is not that jurisdictions are adopting the same model, because they are not. The more precise point is that regulators are using different legal tools to address the risks created by digital financial intermediation.
In Southeast Asia, Malaysia’s revised Risk Management in Technology policy, issued by Bank Negara Malaysia on 28 November 2025, sets out policy objectives and minimum requirements for financial institutions’ management of technology and cyber risk. Its focus differs from POJK No. 30/2025, but both instruments treat technology risk as a matter of institutional governance and supervisory concern.
Vietnam provides a different model. Decree No. 94/2025/ND-CP established a regulatory sandbox for fintech solutions in the banking sector, effective from 1 July 2025. The sandbox covers peer-to-peer lending, credit scoring and data sharing through open APIs. This is not equivalent to Indonesia’s governance regime for licensed ITSK operators, but it places digital-credit-related innovation within a supervised regulatory process.
In the European Union, Directive (EU) 2023/2225 revised the consumer-credit framework. The rules had to be transposed by 20 November 2025 and will apply from 20 November 2026. This is a consumer-credit instrument rather than a fintech-governance regulation and many gaps remain as DICRI will show in a future post. Nevertheless, its relevance lies in the broader move to bring newer and smaller-scale forms of consumer credit within a more comprehensive consumer-protection framework.
In the United States, the Consumer Financial Protection Bureau issued a 2024 interpretive rule on the application of Regulation Z to lenders issuing digital user accounts used to access credit, including lenders marketing loans as “Buy Now, Pay Later”. However, the CFPB withdrew the 2024 BNPL Interpretive Rule on 12 May 2025. The U.S. example therefore illustrates both the use of consumer-credit law to address digital-credit products and the instability of that regulatory route.
Brazil offers further contrast. The Central Bank of Brazil recognises credit fintech structures such as Direct Credit Societies and Peer-to-Peer Loan Companies. Brazil’s Open Finance framework also aims to enhance efficiency in credit and payments markets through consumer-authorised data sharing, while preserving financial-system security and consumer protection.
These examples should be read as context, not as evidence of a harmonised global model, for there isn’t one. Indonesia’s POJK No. 30/2025 is distinctive because it applies detailed governance and risk-management obligations to licensed financial-sector technology innovation operators, including alternative credit scoring and financial-service aggregation providers. Its comparative importance lies in the way it treats digital financial intermediaries as supervised organisational actors, not merely as providers of innovative products.
Policy point
For consumer financial protection, the central question is how governance and risk-management duties will be used in practice. They may primarily support institutional resilience, market integrity and supervisory visibility. They may also provide tools for addressing consumer-facing risks generated upstream in digital credit markets.
Those risks include opaque scoring, weak accountability for automated or data-driven assessments, unsuitable product steering, misleading aggregation, conflicts of interest, excessive reliance on alternative data, ineffective complaints handling and inadequate transparency over consumer-data processing.
POJK No. 30/2025 should therefore be monitored as part of a broader shift in digital credit regulation. The regulatory focus is no longer limited to disclosure, financial education or the terms of the credit contract. It increasingly extends to the platforms, data systems, internal controls and governance structures that shape access to credit.