Insights · Analysis
MAS’s Guidelines on AI Risk Management
What the Monetary Authority of Singapore now expects of every financial institution that uses AI, what its 51 footnotes add, where the text is open to more than one reading, and what to do first.
This analysis explains published guidance. It is not legal advice, and MAS’s text is the authority. Paragraph numbers refer to the Guidelines; “FN” is a footnote in the Guidelines; “Response” is MAS’s Response to Feedback Received. MAS had published no FAQs on the Guidelines when we checked its site on 9 October 2026, so the Response is the closest thing to them.
In brief
- Every financial institution, every kind of AI. The Guidelines apply to all financial institutions (FIs), in proportion to their size and risk profile (para 2.1), and to machine learning as well as generative AI and AI agents (para 1.5, FN6).
- A light tier for low-impact use. A firm whose AI could not cause material harm if it failed may run six basic policies instead of the full framework (paras 2.3–2.5). A firm with no AI at all still needs basic policies, to deal with staff using AI tools unofficially (Response, para 3.14).
- The board owns AI risk. AI must be “explicitly addressed” in the risk appetite framework (para 3.4(b)). A dedicated AI committee is not required (para 3.3).
- Find, list and rate. Each firm identifies its AI, including AI built into the software it buys from material providers (para 4.2), keeps an inventory (paras 4.5–4.9) and rates each use case on impact, complexity and reliance (para 4.12).
- Inherent risk decides the heavy controls. A use case that is high risk before controls gets the high-risk controls, including independent validation before deployment, even as a pilot (Response, paras 7.21 and 10.79).
- The firm stays accountable for vendors’ AI. Independent certifications and assessments of a provider can help; a provider’s own assurances generally do not (para 5.11(a); Response, para 9.9).
- No new reporting duty. MAS is not adding AI-specific incident reporting; existing technology risk and business continuity reporting applies (Response, para 10.69).
- The footnotes matter. Several definitions and boundaries live only in footnotes, and two of the cited sources have moved on since they were written (see section 12).
1. Who the Guidelines apply to
The Guidelines set out MAS’s supervisory expectations for financial institutions as defined in section 2 of the Financial Services and Markets Act 2022 (para 1.1, FN1). That definition is wide. MAS’s own page for the Guidelines tags 52 types of institution, from banks and insurers to fund managers, financial advisers, insurance brokers, credit bureaus, money-changers and both major and standard payment institutions. Small firms get relief through proportionality (paras 1.6 and 2.1), not through scope.
For locally incorporated FIs, the Guidelines apply on a group basis where the FI is subject to consolidated supervision by MAS (FN4 names banks and insurers) or owns critical information infrastructure (para 1.2). An FI in a global group may use its group’s AI framework if that framework meets the Guidelines (para 1.5), but local senior management stays accountable and must be able to show MAS how it discharges its oversight (para 3.6).
These are guidelines, not a notice or a statute. MAS describes them as supervisory expectations. They are read together with existing rules, such as the technology risk management guidelines, the outsourcing guidelines and the Guidelines on Fair Dealing (paras 1.2, 3.2, 5.16; FN15, FN39, FN47).
2. What counts as AI
AI means machine-based systems or models that “derive outputs through learned premises” such as the data they receive (para 1.3). Tools whose outputs come only from predefined logic or rules are out. FN6 lists what is in: machine learning of every kind, deep learning, natural language processing, computer vision, generative AI and AI agents, including multi-agent systems. It also lists what would “not ordinarily” be in: rule-based systems, hand-specified formulae and robotic process automation that does not learn.
The Response makes the boundary sharper. Logistic regression and gradient boosting are in. Standard rule-based investment formulas, if-then expert systems, rule-based RPA and Monte Carlo simulations not derived from training data are out (Response, para 2.8).
Why this matters. Many credit scorecards and fraud models built with logistic regression now count as AI. They come into the inventory and the risk rating, even where the firm has always treated them as ordinary statistical models.
Three terms are used precisely: a model turns assumptions and input data into outputs; a system is one or more models plus other components; a use case is a real-world context in which a model or system is applied (para 1.4). Risk is rated per use case (para 4.10), so the same model can be low risk in one use and high in another.
3. The basic tier for low-impact use
A firm may apply basic AI governance policies instead of the full framework if poor performance or unavailability of its AI tools is unlikely to have a material adverse impact on it, its customers or other stakeholders (para 2.3). It weighs financial, operational, regulatory, legal and reputational impact on itself, and fairness, ethics and consumer protection for customers.
MAS gives six examples that would generally qualify, all assistive and all subject to human review of the output before use (para 2.4, FN13): drafting or rephrasing customer emails; summarising documents or meeting notes for internal reference; initial review of documents for internal reference; generating formulas, charts or visualisations for internal reference; image generation for marketing or internal materials; and an internal chatbot that helps staff find policies.
The basic policies are (para 2.5):
- clear accountability, for example a named member of senior management;
- permitted and prohibited uses, such as no confidential or client information in public AI tools, with rules on when human review is mandatory;
- an approved list of AI tools and a way to request new ones;
- staff education on the policies;
- regular compliance checks; and
- periodic and trigger-based review of whether the firm still qualifies.
MAS encourages at least an annual review and expects basic-tier firms to finish within 12 months, by October 2027 (Response, paras 3.16 and 13.6).
Three things to watch
- To qualify, you first have to look. The test is about “the AI services or tools used by the FI”, including AI that arrives inside software the firm already uses (FN21). A firm cannot honestly say it qualifies without a light identification exercise: a staff survey, a check of its main software vendors, and what its network or data loss controls show (FN22). Keep that as the evidence for the decision.
- The test looks at failure, not misuse. It asks about poor performance or unavailability. The biggest risk of copilots in a small firm is often confidentiality: client data pasted into a tool. Policy item 2 covers this, but the eligibility test does not.
- One material use case changes the picture. In our view the test applies to the firm’s AI use as a whole. A single customer-facing chatbot, or AI in credit, anti-money-laundering or investment decisions, takes the firm into the full framework, where proportionality then does the calibrating (para 2.2, FN12).
4. The board and senior management
The board, or a committee it delegates to, approves the overall approach to AI risk, including the strategic direction for AI use; makes sure AI risk is explicitly addressed in the risk appetite framework; sets roles; keeps enough understanding of AI to challenge; and reviews all of this as AI and the business change (para 3.4). For a firm in a global group, the committee can be a regional or global body (FN17).
FN18 shows what risk appetite measures could look like: a qualitative statement of the AI risks the firm accepts or prohibits, and quantitative measures such as the number or financial impact of AI-related incidents, the number of material use cases that depend on a single provider, and the number of material use cases breaching performance thresholds.
Senior management implements the framework, reviews it, sets controls across the life cycle, assigns roles (including the control functions for identification, inventory and risk rating), runs an escalation process for AI incidents and breaches of thresholds, keeps the board informed and resources the work (para 3.5). FN19 suggests the three lines of defence: developers and users first, independent challenge and validation second, internal audit third.
A firm may set up a central AI function or manage AI risk through its existing functions, as long as management is consistent and coordinated (para 3.3, FN16). MAS’s media release confirms that a dedicated AI committee is not needed just to meet this expectation.
5. Find, list and rate your AI
Identification
A firm needs a consistent way to identify AI use across the business, with clear definitions and criteria (para 4.2). A designated control function oversees it and is the final arbiter of whether something counts as AI (para 4.3). Where AI is embedded in third-party services, identification must at least cover services from material third-party providers (para 4.2), including software “not explicitly sold as AI” (FN21).
Paragraph 4.4 is new since the consultation and unusual: the firm must keep the residual risk from AI it has not identified, such as shadow AI or undisclosed vendor features, within its risk appetite. FN22 suggests clear staff guidance on allowed and disallowed AI and technical controls such as network monitoring and data loss prevention.
Inventory
The inventory should be accurate “to the extent possible or practicable” and updated at a frequency the firm sets (para 4.5). It can extend an existing inventory or stand alone, linked to data inventories and outsourcing registers (para 4.6, FN23). Typical attributes include purpose, approved scope, model type, data used, dependencies, life cycle status, risk rating, review status, owners and links to documentation (para 4.7). For AI agents, add agent identifiers, the tools and systems the agent can reach, its components and its guardrails (FN25).
Risk materiality
Each use case gets a risk materiality rating, before controls (inherent) and after them (residual). The residual rating must be within appetite before deployment (paras 4.10–4.11). The rating covers at least three dimensions (para 4.12):
| Dimension | What it asks | Notes |
|---|---|---|
| Impact | What happens to the firm and to customers if the AI fails, malfunctions or performs poorly, including the sensitivity of the data it uses. | Financial, operational, regulatory and reputational impact; fairness and consumer protection. |
| Complexity | How new and opaque the technology and its application are, the data it uses and how explainable its outputs are. | For third-party AI, how much the firm can see. Kept despite industry objections (Response, paras 7.9–7.11). |
| Reliance | How much the decision or output rests on the AI, how autonomous it is and how much people oversee it. | “Availability of alternatives”, in the draft, was dropped. |
MAS will not prescribe a formula or a universal threshold for “high” (Response, para 7.19). It does say that the controls for high-risk use cases apply on the basis of inherent risk materiality (Response, para 7.21). A use case cannot be rated down by its controls to avoid the controls meant for it. A control function sets the method and arbitrates or approves the ratings (para 4.13).
6. Life cycle controls
Section 5 covers the whole life of an AI use case, “from inception to retirement”, adapted from ISO/IEC 22989 (FN27). Controls are applied in proportion to risk materiality (para 5.2). The table summarises each area and what the footnotes and the Response add.
| Area | What MAS expects | What the footnotes and Response add |
|---|---|---|
| Contingency 5.3 | Fallback plans for high-risk use cases, tested regularly; tested activation protocols where AI has kill switches. | Contingency plans are expected only for high risk materiality; whether to use kill switches is the firm’s choice (Response, para 10.70; FN29). |
| Data 5.4 | Data fit for purpose, representative, of good quality, classified, secure, lawful to use and documented with lineage. | Points to the PDPC’s two advisory guidelines on personal data in AI (FN30). See section 9. |
| Transparency and explainability 5.5–5.6 | More for AI relied on in credit, underwriting, advice or fund management; less for internal low-risk assistance. | Transparency means disclosure to people affected; explainability means methods for understanding outputs (FN32). Customer disclosures need not be technical (FN34). |
| Fairness 5.7–5.8 | Define fair outcomes; test for systematic disadvantage using protected attributes and fairness metrics; document. | Proxies for protected attributes count too (FN36). FEAT is the reference (FN35). Proportionality changes how rigorous the test is, not whether it is done (Response, para 10.19). |
| Human oversight 5.9 | Roles, competence and authority to intervene, design for escalation, logs and review of interventions; watch for automation bias. | Covers human in the loop and over the loop (FN37). MAS did not ban fully automated decisions for high-risk use cases; the firm sets the level of oversight and must be able to show MAS it is adequate. Human review of all credit or underwriting decisions is one example it gives (Response, paras 10.48–10.49). |
| Third-party AI 5.10–5.11 | Controls fitted to risk; contracts that give visibility of AI and its changes; testing on the firm’s own data. | See section 7. |
| Selection 5.12–5.13 | Document why a more complex model or feature was chosen over a simpler one. | “Features” here means data attributes (FN42). |
| Evaluation and testing 5.14–5.15 | Clear, measurable thresholds agreed in advance; testing across real-world and edge conditions; guardrails tested for generative AI and agents. | Testing focuses on the use case, not the model alone (Response, para 10.30). IMDA’s Starter Kit is the named reference for generative AI (FN43, FN46). |
| Technology and cyber 5.16, 5.22 | Secure environments, access control, third-party components governed; pre-go-live reviews with penetration testing and red teaming. | MAS’s technology risk guidelines apply (FN47). No red-team method is prescribed. |
| Reproducibility 5.17 | Documentation good enough for an independent reviewer to understand and potentially replicate the build and its testing. | Exact output replication is not expected for non-deterministic generative AI (Response, para 10.44). |
| Pre-deployment review 5.18–5.21 | Review by people not involved in development; formal independent validation for high risk materiality. | Applies to pilots of high-risk use cases too (Response, para 10.79). External validators are allowed. If no qualified, independent validator can be found, reduce the risk by redesign or reconsider deploying (Response, para 10.57). |
| Monitoring 5.23–5.24 | Metrics with early-warning thresholds, drift checks, incident handling, feedback channels; re-validation by independent parties for high risk. | “AI incident” means failure, malfunction or poor performance of the AI (FN20). For generative AI and agents, logging prompts, responses, model versions and reasoning “could also be considered” (5.23(d)). |
| Change and retirement 5.25–5.26 | A framework for what makes a change significant; version control and roll-back; stricter controls for self-updating AI; controlled decommissioning. | Significant changes include changes to training data, architecture, assumptions or scope (FN49), and vendor updates that happen without prior review need compensating controls such as closer monitoring. |
Pilots. FN28 allows pilots and phased rollouts to deviate from standard life cycle controls under clear policies: time and user limits, success criteria and close monitoring. The Response is firm that a pilot of a high-risk use case still needs formal independent validation first (para 10.79).
7. Third-party AI
Third-party AI covers AI systems, models and AI-enabled services developed, owned, operated or provided by an outside party that the firm procures, subscribes to or relies on (FN10). The decision to use it is the firm’s, and the firm keeps primary accountability (para 5.11). Before onboarding, the firm considers eight areas (para 5.11(a)–(h)): the provider’s transparency, supply chain checks on models and datasets, concentration on a few providers, notice of changes, contingency plans, legal terms, staff capability and complexity.
Where a provider says too little, the firm can rely on certifications or external assessments by parties that are competent and independent of the provider and that cover the key risks. A provider’s own statements that risks are addressed generally do not count (Response, paras 9.9–9.10). Respondents asked for a safe harbour for recognised certifications; MAS did not give one. If residual risk cannot be brought within appetite, the firm should consider limiting or suspending the service, or replacing the provider (para 5.11).
The outsourcing rules still apply (FN39), but MAS does not treat the AI rating as a duplicate of the outsourcing materiality assessment, and an AI provider is not automatically a material outsourcing arrangement (Response, paras 9.19–9.21). MAS consulted in March 2026 on third-party risk management guidelines that would replace the outsourcing guidelines. A firm re-papering its AI contracts for paragraph 5.11(f) (performance, data protection, audit rights, notice when AI is introduced or updated) should do it once, with both in view.
8. Generative AI and AI agents
Paragraph 1.10 lists the extra risks of generative AI: security (prompt injection, data poisoning), privacy, intellectual property, reliance on a few providers, outages and human factors such as shadow AI, automation bias and loss of skills. Paragraph 1.11 adds agents: an agent with tools could take unauthorised or erroneous actions when it turns a goal into steps that do not match the firm’s objectives or a customer’s interests, and a compromised agent could exfiltrate data or run malicious commands at scale.
The agent-specific expectations are few and mostly permissive: agent attributes in the inventory (FN25), testing of key failure modes and guardrails (para 5.15), monitoring of reasoning, actions and tool use (para 5.23(a)), and the option of fuller logging (para 5.23(d)). For the rest, MAS points to IMDA’s Model AI Governance Framework for Agentic AI (FN11; version 1.5, May 2026). MAS will not set minimum controls or tests for now (Response, para 12.7) and intends to consult the sector separately on agent guidance (Response, para 12.9); its media release names 2027 for that consultation.
A firm deploying an agent that can act in its systems should not wait. The Guidelines leave out several controls that the IMDA framework and the Cyber Security Agency’s June 2026 addendum on securing agentic AI cover. We would treat these as the minimum:
- a separate identity and credentials for each agent, so its actions are attributable and can be revoked;
- a tool allow-list with read and write scopes, value and rate limits;
- human approval tied to the impact of an action (payments, customer messages, changes to records), not only to confidence;
- testing for instructions hidden in content the agent reads, through every tool and data source;
- a sandbox and limits on where the agent can send data;
- action and reasoning logs kept as the audit trail; and
- a tested way to stop the agent that also halts actions in progress and revokes its credentials.
9. Data and privacy
Paragraph 5.4 applies general data governance to AI and lifts it where AI needs more: fitness for purpose, representativeness including stressed conditions, quality and drift checks, classification, security across the data life cycle including destruction of training data and model artefacts, privacy and lineage. On privacy, FN30 points to the PDPC’s Advisory Guidelines on use of Personal Data in AI Recommendation and Decision Systems (March 2024) and its Advisory Guidelines on use of Personal Data in Generative AI (July 2026).
Paragraph 5.4(f) gives, as an example, “the need to obtain consent” when sensitive personal data is used to train or is processed by AI. Read it as an illustration, not a new rule. The PDPA has exceptions that can apply instead of consent, such as business improvement and research, and the PDPC’s guidance explains when they cover AI development. Where consent is relied on to train generative AI, the PDPC’s guidance expects the notice to say specifically that the data trains AI, a point the Guidelines do not make. Banks must also respect banking secrecy under the Banking Act when customer information goes to an outside AI provider.
Logging prompts and responses (para 5.23(d)) creates new stores of personal data. They need the same protection, retention limits and access controls as any other.
10. How AI Verify fits
MAS tells firms they may refer to “the various initiatives under the AI Verify Foundation” (FN3). AI Verify is Singapore’s voluntary AI governance testing framework. Its Testing Framework sets out 11 principles with process checks, and the Foundation publishes mappings of it to the NIST AI Risk Management Framework and to ISO/IEC 42001. Its Project Moonshot toolkit runs the tests in IMDA’s Starter Kit for LLM-based applications, the reference MAS names for testing generative AI (FN43, FN46). Using them is good evidence of practice; it does not by itself meet MAS’s expectations, and AI Verify is not a certification.
The table maps each AI Verify principle to the paragraphs of the Guidelines it supports. It is our mapping, using the principle names only.
| AI Verify principle | Where the Guidelines deal with it |
|---|---|
| Transparency | 5.5–5.6 (disclosure to people affected, FN32, FN34) |
| Explainability | 5.5–5.6; explainability analysis in documentation and validation (5.17(e), 5.19(e)) |
| Reproducibility | 5.17 (reproducibility and auditability); version control in 5.25(b) |
| Safety | 5.14–5.15 (reliability and safety testing); contingency plans in 5.3 |
| Security | 5.16 and 5.22 (technology and cyber controls, red teaming) |
| Robustness | 5.14(b) (stress, edge-case and adversarial testing); monitoring for drift in 5.23 |
| Fairness | 5.7–5.8, with FEAT as the reference (FN35) |
| Data governance | 5.4 (fitness, representativeness, quality, classification, security, privacy, lineage) |
| Accountability | 3.4–3.6 (board and senior management); control functions in 4.3, 4.9 and 4.13 |
| Human agency and oversight | 5.9 (roles, capability, design for escalation, review of interventions) |
| Inclusive growth, societal and environmental well-being | No section of its own. Impact on customers and other stakeholders is part of the basic-tier test and the impact rating (2.3(b), 4.12(a)), and FN14 lists environmental risk among the areas AI touches. |
For a worked example of the principles applied to a small business, see our framework sketch for AI-assisted coding, which includes our three-minute video AI Verify, Explained.
11. The footnotes as a reading list
Eighteen of the 51 footnotes cite an outside document. We checked each link and the document’s current status on 9 October 2026. All the URLs given in the footnotes work. Some MAS files refuse automated link checkers, so a broken-link report from a tool is not proof.
| FN | Document | What it is for |
|---|---|---|
| 1 | Financial Services and Markets Act 2022, s 2 | Who is a financial institution. |
| 2, 35 | MAS, FEAT principles (2018) | Fairness, ethics, accountability and transparency; the reference for “fair” outcomes. |
| 3 | CSA, Guidelines and Companion Guide on Securing AI Systems (2024); IMDA Model AI Governance Framework; AI Verify Foundation initiatives | National references. No links or dates are given (see section 12). |
| 5 | Cybersecurity Act 2018 | Critical information infrastructure (see section 12). |
| 9 | MAS, Cyber Risks Associated with Generative AI (July 2024) | Prompt injection, data poisoning and other cyber risks of generative AI. |
| 11 | IMDA, Model AI Governance Framework for Agentic AI (v1.5, May 2026) | Agent risks and controls. The link has no version number, so record which version you relied on. |
| 15 | MAS, Guidelines on Fair Dealing | Fair treatment of customers continues when AI delivers the product. |
| 27 | ISO/IEC 22989 | The AI life cycle, from inception to retirement. |
| 30 | PDPC advisory guidelines on personal data in AI recommendation and decision systems (2024) and in generative AI (2026) | Consent, exceptions, notices and provider responsibilities under the PDPA. |
| 31, 51 | NIST, AI Risk Management Framework 1.0 (2023) | Transparency and explainability; cited for technology infrastructure too. |
| 34 | IMDA, Transparency Guidelines for Generative AI Chatbots (2026) | What to tell customers who talk to a chatbot. Customer-facing chatbots only. |
| 39 | MAS outsourcing and third-party expectations | No instrument is named; today the outsourcing guidelines and notices. |
| 43, 46 | IMDA, Starter Kit for Testing LLM-Based Applications (v1.0, January 2026) | Tests for hallucination, bias, undesirable content, data leakage and adversarial prompts: the same five risks FN46 lists. It does not yet cover agents. |
| 47, 50 | MAS, Technology Risk Management Guidelines (2021) | Security, resilience and infrastructure for AI systems. |
Two sources shape the Guidelines without being cited. MAS’s December 2024 information paper on AI model risk management, from its review of banks, uses the same impact, complexity and reliance dimensions and is the best guide to what MAS means by many expectations. The industry handbooks from MAS’s Project MindForge were written against the November 2025 draft, so read them alongside the final text, not instead of it.
12. Where the text is open to more than one reading
None of these changes what a firm should do in principle. Each is a place where a firm should write down its own reading, so that its staff, its auditors and its supervisor work from the same one.
- Footnote 5 points to a definition that has changed. Since amendments in force on 31 October 2025, the Cybersecurity Act no longer defines “critical information infrastructure” on its own; it defines provider-owned and third-party-owned critical information infrastructure. Whether an FI that is responsible for, but does not own, third-party-owned infrastructure falls within paragraph 1.2 is not clear.
- “High risk” is never defined. The text uses “high risk”, “high risk materiality”, “high materiality” and “material”. Independent validation, re-validation and contingency plans all switch on at “high”, so each firm must define its own top tier and map these phrases to it.
- Timing. Paragraph 4.11 (due from October 2027) asks that residual risk be within appetite before deployment, but the review and validation controls that show it are in Section 5 (due by October 2028). High-risk use cases should get them “as soon as possible” anyway (Response, para 13.5). Section 2, with the basic tier, has no date in paragraph 1.8; the Response fills the gap (para 13.6).
- “AI incident” is about failure. FN20 covers failure, malfunction or poor performance of the AI. Misuse by staff, or an agent faithfully carrying out a malicious instruction, may not fit. FN18 says “AI-related incidents”, which may count something different.
- Key definitions sit in footnotes. The scope of AI (FN6) and the meaning of third-party AI (FN10) are easy to miss. Put them in your policy’s definitions.
- “Material third-party service providers” is undefined in the Guidelines (para 4.2). The outsourcing framework is the natural reference, though MAS says the two assessments differ.
- Up to three control functions. Identification, inventory and risk rating each need a designated control function (paras 4.3, 4.9, 4.13). One function can hold all three, but in a small firm it may be the same people who run the tools, which strains “independent oversight”.
- The consent example in paragraph 5.4(f) reads stricter than the PDPA on consent and looser than the PDPC on notices (section 9).
- Citations that need care. FN3 names “the” IMDA Model AI Governance Framework when there are now three (2020, generative AI in 2024 and agentic AI in 2026), and its wording misplaces the abbreviation. FN51 cites the NIST framework for technology infrastructure, which it barely covers; MAS’s own technology risk guidelines (FN50) do. FN27 gives no edition year for ISO/IEC 22989.
- The media release and the text differ slightly. The release adds “including other FIs” to the basic-tier test; paragraph 2.3 does not say this. The Guidelines govern.
- Spelling of “life cycle”. The text uses both “life cycle” and “lifecycle”. Nothing turns on it, but search for both when mapping your controls.
13. How it compares with other regimes
- United States. The 2026 interagency model risk guidance that replaced SR 11-7 (SR 26-2) leaves generative and agentic AI out of its scope. MAS covers both.
- European Union. The AI Act imposes binding duties, including conformity assessment, but only on listed high-risk uses, such as credit scoring of individuals and life and health insurance pricing. MAS is not a statute, but it reaches every AI use in every FI, including AI embedded in vendor software.
- Hong Kong. The HKMA’s 2024 circular on generative AI and consumer protection asks for a human in the loop in early customer-facing use and, as far as practicable, a way for customers to opt out. MAS asks for neither, and goes further on inventory, risk rating and independent validation.
- ISO/IEC 42001. A 42001 management system gives a firm structure: policy, roles, risk assessment, internal audit and management review. The Guidelines expect more that is specific to finance: impact, complexity and reliance ratings per use case, board risk appetite measures, independent validation of high-risk use cases, third-party checks and agent monitoring. 42001 helps a firm meet the Guidelines; it does not by itself show that it does. MAS does not cite 42001, and a vendor’s 42001 certificate is one input to third-party assurance, not a safe harbour (Response, paras 9.9–9.10).
- NIST AI RMF. Cited for transparency and explainability (FN31). Its govern, map, measure and manage functions line up well with Sections 3 to 5.
14. What to do first
A small FI using copilots and SaaS tools
- List the AI tools staff use and ask your main software vendors which AI features are on.
- Test yourself against paragraph 2.3 and write the decision down, with the evidence.
- If you qualify, put the six basic policies in place, starting with the rule on what may go into AI tools.
- Name the accountable senior manager and brief staff.
- Set the triggers that send you back to step 2: a new tool, a vendor switching on AI, AI output reaching customers or decisions, an incident.
- Have it done by October 2027.
A bank or insurer with models, chatbots and agents
- Agree the board’s AI risk appetite statement and measures (FN18).
- Settle what counts as AI at the margins, such as scorecards and vendor analytics, and designate the control functions.
- Build the inventory, link it to data and outsourcing registers, and add agent attributes.
- Write the risk rating method and define “high”; rate on inherent risk first.
- Bring high-risk use cases under life cycle controls now, including independent validation and contingency plans; do not wait for 2028.
- Review AI vendor contracts once, against paragraph 5.11(f) and the coming third-party guidelines.
- Set an agent control baseline (section 8) before agents act in production.
Sources
All accessed 9 October 2026.
- Monetary Authority of Singapore, Guidelines on Artificial Intelligence Risk Management, 7 October 2026.
- Monetary Authority of Singapore, Response to Feedback Received on Guidelines on Artificial Intelligence Risk Management, 7 October 2026.
- Monetary Authority of Singapore, media release, 7 October 2026.
- Monetary Authority of Singapore, Consultation Paper on Proposed Guidelines on Artificial Intelligence Risk Management, 13 November 2025.
- Monetary Authority of Singapore, Artificial Intelligence Model Risk Management, information paper, December 2024.
- Cybersecurity Act 2018, section 2, as amended by Act 19 of 2024, Singapore Statutes Online.
- Financial Services and Markets Act 2022, section 2, Singapore Statutes Online.
- Personal Data Protection Commission, the two advisory guidelines linked in section 9.
- Infocomm Media Development Authority and Cyber Security Agency of Singapore, the documents linked in sections 8 and 11.
- AI Verify Foundation, AI Verify Testing Framework and Project Moonshot.
- National Institute of Standards and Technology, AI Risk Management Framework 1.0, January 2023.
- Board of Governors of the Federal Reserve System, SR 26-2, 17 April 2026.