Singapore - AI Model Risk Management
Artificial Intelligence Model Risk Management – Observations from a Thematic Review (MAS information paper)
Singapore
RAI-SG-NA-AIMRMXX-2024The Monetary Authority of Singapore's 2024 information paper guides financial institutions on best practices for managing risks associated with artificial intelligence and generative AI models. In force as of 2024-12-05, it sets supervisory expectations for model governance, lifecycle controls, and third-party risk management.
Summary
The instrument remains In Force as an active supervisory guidance paper issued by the Monetary Authority of Singapore. The most recent dated event occurred on 5 December 2024, when MAS released the information paper following its mid-2024 thematic review of selected banks utilizing artificial intelligence and generative AI.
Because this Information Paper is non-binding supervisory guidance, no regulatory body formally enforces its recommendations as statutory obligations or imposes penalties directly under it. However, the Monetary Authority of Singapore oversees and supervises financial institutions across the jurisdiction, conducting regular supervisory reviews and audits. MAS may also draw upon its general statutory regulatory powers—such as issuing directives, applying licensing conditions, or imposing sanctions under sectoral legislation—if an institution's AI risk management deficiencies jeopardize financial stability or consumer safety.
The paper sets out observed good practices across three key areas: governance and oversight, risk management processes, and model development and deployment. Institutions are advised to establish cross-functional AI oversight forums, articulate governance principles (covering fairness, ethics, accountability, and transparency), and update internal risk policies. MAS highlights maintaining a centralized AI inventory and conducting risk materiality assessments to calibrate lifecycle controls proportionately across financial, operational, compliance, model, reputational, and conduct risk dimensions.
For model lifecycle management, MAS details standards for dataset representativeness, explainability, bias testing, versioning, and pre-deployment independent validation or peer review. The guidance emphasizes post-deployment continuous performance monitoring and change controls, addresses generative AI risks such as hallucinations and data leakage, and recommends contractual safeguards for third-party AI solutions.
Full article
Read full text ↗Overview
The Monetary Authority of Singapore (MAS) published the Information Paper "Artificial Intelligence Model Risk Management: Observations from a Thematic Review" on 5 December 2024 following a thematic review of selected banks in mid-2024. The Paper summarises MAS' supervisory observations and the good practices observed across three primary pillars: governance and oversight, risk management systems and processes (identification, inventorisation, materiality assessment), and model development, validation, deployment and monitoring. While the Paper itself is informational and not legally prescriptive, MAS states that the practices it highlights should be referenced and adopted by financial institutions (FIs) as supervisory expectations evolve. The Paper also signals MAS' intent to develop formal supervisory guidelines on AI risk management in the financial sector, and to work with industry partners to produce supporting materials and handbooks. The full MAS publication is available at MAS – Artificial Intelligence Model Risk Management.
Definitions
In the Information Paper MAS uses practical, risk-focused terms rather than creating a new statutory lexicon. Key definitions and concepts used or implied by the Paper include "AI" and "generative AI" (systems that perform tasks by learning patterns from data and may generate novel content), "model risk management" (MRM) as the lifecycle controls for model development, validation and use, "materiality assessment" (a risk-based determination of the significance of an AI application across risk dimensions), "AI inventory" (a centralised register of AI use-cases and models), and "independent validation/peer review" (objective review of model assumptions, performance and robustness relative to intended use). The Paper reinforces that definitions should be aligned with each FI's risk taxonomy and supervisory expectations.
Governance and Institutional Framework
MAS observed that existing governance frameworks (data governance, technology and cyber risk, third-party risk and legal/compliance) remain relevant but often require augmentation for AI-specific concerns. Good practices highlighted include the establishment of cross-functional oversight forums (e.g., AI steering committees linking business, risk, compliance, technology and legal functions), the articulation of high-level AI principles (fairness, ethics, accountability and transparency), and the updating of risk policies and standard operating procedures to address AI life-cycle risks. MAS also notes the importance of clear role allocation — business accountability for use-cases, risk functions for assessment and monitoring, independent validation for model challenge and compliance for legal/consumer protection matters — and the need to build AI capabilities across the organisation. For further resources on government and supervisory coordination, MAS references related materials and industry engagement efforts such as the MindForge consortium; see Monetary Authority of Singapore for MAS engagement programmes.
Key Focus Areas
MAS sets out several focus areas that were emphasised during the review: (1) Identification and inventorisation — having a complete, up-to-date AI inventory that covers scope, purpose, inputs, outputs, data lineage and third-party dependencies; (2) Materiality assessment — evaluating AI uses across risk dimensions (financial, operational, compliance, model integrity, data protection, reputational and conduct risk) and applying controls proportionately; (3) Data management — ensuring datasets used for training, validation and testing are representative, appropriate and subject to quality checks and lineage controls; (4) Model justification and explainability — documenting why a model was chosen and applying explainability tools to reveal key drivers and reasonableness checks; (5) Fairness and bias assessment — applying techniques to detect distributional biases and disparate impacts and acting on remediation where necessary; (6) Independent validation and pre-deployment checks — conducting challenge and validation activities proportionate to risk materiality; (7) Monitoring and change management — instituting robust performance monitoring, version control, retraining governance and pre-specified rollback/kill-switch procedures; and (8) Third-party risk — ensuring contract terms and oversight address vendor updates, model changes, IP and data provenance. The Paper also highlights practical mitigations for generative AI risks such as output filtering, data access restrictions and enhanced monitoring.
Implementation Framework
Mature implementation practices observed by MAS include: adoption of a risk-based lifecycle framework that maps controls to stages (identify, design, validate, deploy, monitor, retire); the use of AI inventories and registries to enable central oversight and reporting; proportionate control baselines linked to materiality; detailed model development documentation (data lineage, hyper-parameters, training processes, performance metrics); independent validation and sign-off processes; operational safeguards (access management, encryption, staging environments) and pre-deployment checklists. MAS recommends that FIs establish roles, escalation paths and structured approval gates for deployment, and that institutions document assumptions, limitations and permitted operational envelopes for each model. For FIs relying on third-party models, MAS notes the importance of contractual rights to notification of vendor updates and the ability to validate or otherwise assure third-party model behaviour.
Monitoring and Evaluation
The Paper emphasises continuous monitoring to detect model drift, performance degradation and emergent risks (e.g., hallucinations in generative models). MAS observed good practices such as live performance dashboards, threshold-based alerts, scheduled revalidation and backtesting, sampling and audit trails, and periodic governance reviews. Monitoring should cover not only quantitative performance metrics but also qualitative indicators such as shifts in input distributions, changes to vendor-provided models or data sourcing, and operational exceptions. MAS highlights the need for incident response and escalation procedures, and for clear documentation enabling auditability and root-cause analysis. FIs are expected to apply a governance cadence commensurate with materiality and to retain records for supervisory review.
Penalties, Liability, and Appeals
As an information paper, MAS does not itself set out new statutory penalties; however, MAS reminds FIs that failure to manage AI risks effectively may lead to supervisory actions available under existing legislation and MAS powers. This can include directions to remediate, restrictions on activities, licence conditions or revocations, monetary penalties where statutory provisions apply, and reputational consequences. The Paper therefore functions as an advance notice of supervisory expectations: prolonged or material non-compliance with robust AI risk management may attract escalation. Affected firms retain the usual rights of review and appeal under the regulatory framework and administrative procedures governing MAS actions.
Relationship to Other Instruments
The Information Paper complements existing Singapore regulatory instruments and international guidance. MAS references the relevance of data protection under the Personal Data Protection Act (PDPA), technology and cyber risk guidance, third-party risk frameworks, and prior MAS information papers (for example on generative AI cyber risks). The Paper also sits alongside MAS' plan to publish supervisory guidelines on AI risk management and industry materials (e.g., a governance handbook via MindForge). The Paper is intended to be practical and to align with international good practice so that FIs operating across jurisdictions can map MAS expectations to other frameworks, including emerging international standards.
International Alignment
MAS explicitly frames the Information Paper as industry-aligned and internationally aware. The Paper's emphasis on governance, risk-based materiality, explainability, validation and third-party controls resonates with international initiatives (including regulatory thinking in the EU, UK, UK PRA/FCA workstreams, the BIS/FSB financial-sector considerations, and supervisory good practice). MAS intends to keep coordinating with global counterparts and standard-setting bodies to ensure cross-border consistency for financial firms. The Paper therefore positions MAS' expectations in the broader international dialogue on AI governance and financial-sector resilience.
Implementation Timeline
| Milestone | Date / Timing |
|---|---|
| Thematic review of selected banks (field work) | Mid-2024 |
| Publication of Information Paper | 5 December 2024 |
| Mentioned development of supervisory guidelines | 2025 (MAS indicated development during 2025–2026) |
| Planned public consultation on MAS supervisory guidelines | MAS to publish consultation timeline; industry briefings anticipated |
Sources and References
Requirements for a company
What an organisation has to do under Singapore - AI Model Risk Management, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
0Nothing in this category.
Must not do
0Nothing in this category.
Should do
10- Establish cross-functional oversight forums to govern AI adoption across business, risk, compliance, technology, and legal functions.Financial institutions in Singapore using AI models
- Maintain a complete and up-to-date central register of AI use-cases and models detailing inputs, outputs, and third-party dependencies.Financial institutions in Singapore using AI models
- Evaluate AI applications through risk-based materiality assessments across financial, operational, compliance, and reputational dimensions.Financial institutions in Singapore using AI models
- Conduct independent validation and peer review of model assumptions, performance, and robustness proportionate to model materiality.Financial institutions in Singapore deploying AI models
- Apply bias detection techniques to identify distributional biases in AI models and take corrective remediation actions.Financial institutions in Singapore deploying AI models
- Document model choices and implement explainability tools to reveal key drivers and allow reasonableness checks.Financial institutions in Singapore deploying AI models
- +4 more in the table below
Should not do
0Nothing in this category.
Who must do what
The obligations under Singapore - AI Model Risk Management, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Financial institutions in Singapore using AI models | Establish cross-functional oversight forums to govern AI adoption across business, risk, compliance, technology, and legal functions. “establishment of cross-functional oversight forums (e.g., AI steering committees linking business, risk, compliance, technology and legal functions)” | — | Governance and Institutional Framework | Recommended |
| 2 | Financial institutions in Singapore using AI models | Maintain a complete and up-to-date central register of AI use-cases and models detailing inputs, outputs, and third-party dependencies. “having a complete, up-to-date AI inventory that covers scope, purpose, inputs, outputs, data lineage and third-party dependencies” | — | Key Focus Areas | Recommended |
| 3 | Financial institutions in Singapore using AI models | Evaluate AI applications through risk-based materiality assessments across financial, operational, compliance, and reputational dimensions. “evaluating AI uses across risk dimensions (financial, operational, compliance, model integrity, data protection, reputational and conduct risk)” | Before deployment | Key Focus Areas | Recommended |
| 4 | Financial institutions in Singapore deploying AI models | Conduct independent validation and peer review of model assumptions, performance, and robustness proportionate to model materiality. “conducting challenge and validation activities proportionate to risk materiality” | Before deployment | Key Focus Areas | Recommended |
| 5 | Financial institutions in Singapore deploying AI models | Apply bias detection techniques to identify distributional biases in AI models and take corrective remediation actions. “applying techniques to detect distributional biases and disparate impacts and acting on remediation where necessary” | — | Key Focus Areas | Recommended |
| 6 | Financial institutions in Singapore deploying AI models | Document model choices and implement explainability tools to reveal key drivers and allow reasonableness checks. “documenting why a model was chosen and applying explainability tools to reveal key drivers and reasonableness checks” | — | Key Focus Areas | Recommended |
| 7 | Financial institutions in Singapore deploying AI models | Establish pre-specified kill-switch and rollback procedures, version control, and retraining governance for deployed AI models. “instituting robust performance monitoring, version control, retraining governance and pre-specified rollback/kill-switch procedures” | — | Key Focus Areas | Recommended |
| 8 | Financial institutions in Singapore operating AI models | Monitor deployed AI models continuously using live performance dashboards, threshold-based alerts, and drift detection. “live performance dashboards, threshold-based alerts, scheduled revalidation and backtesting, sampling and audit trails” | — | Monitoring and Evaluation | Recommended |
| 9 | Financial institutions using third-party AI models | Include terms in third-party vendor contracts that secure notification rights for updates and validation access for vendor AI models. “contractual rights to notification of vendor updates and the ability to validate or otherwise assure third-party model behaviour” | Before deployment | Implementation Framework | Recommended |
| 10 | Financial institutions using generative AI models | Apply output filtering, data access restrictions, and enhanced monitoring to manage generative AI risks such as hallucinations. “practical mitigations for generative AI risks such as output filtering, data access restrictions and enhanced monitoring” | — | Key Focus Areas | Recommended |
Related Regulations
FINMA Guidance 08/2024: Governance and risk management when using artificial intelligence
Switzerland91% similar
Principles to Promote Fairness, Ethics, Accountability and Transparency (FEAT) in the Use of AI and Data Analytics (MAS)
Singapore90% similar
Bank of Thailand Draft Policy on Risk Management of the Use of Artificial Intelligence Systems (Financial Sector AI Risk Guidelines)
Thailand89% similar
Central Bank AI Guidelines
Qatar88% similar
Interim report on AI regulation in the financial sector (Office of Legal Counsel and Legislative Affairs, Ministry of Justice)
Israel88% similar
© Regulations.AI · reviewed against official sources on 07-Sep-2026 using Gemini 3.6 Flash