Abstract
The rapid growth of digital financial services has increased the need for effective regulatory compliance mechanisms, particularly for consumer protection. This study develops and evaluates a hybrid COBIT 2019–Retrieval-Augmented Generation (RAG) framework for compliance with Indonesia’s OJK Regulation No. 22/2023 in a digital multifinance context. Using a design science research methodology, COBIT 2019 design factors were applied to tailor governance objectives, while a RAG pipeline was evaluated on 100 synthetic compliance queries using RAGAS metrics and expert-validated reference answers. The governance assessment prioritized EDM03, APO12, and MEA03, each assessed at capability Level 2 against a target of Level 4, indicating gaps in risk optimization, risk management, and external compliance. The optimal RAG configuration achieved an overall score of 0.8257, with context recall of 0.9217, faithfulness of 0.8502, and semantic similarity of 0.8629. It also outperformed baseline keyword search in retrieving semantically relevant regulatory passages, although broader benchmarking remains limited. The findings show that integrating structured IT governance with AI-assisted regulatory retrieval can strengthen accountability, regulatory interpretation, and compliance decision support. The framework offers a scalable approach for regulated industries, subject to further validation using real operational data and broader institutional settings.