Singapore - AI Governance Framework
AI Verify (AI governance testing framework and toolkit)
Singapore
RAI-SG-NA-AVAGTXX-2022AI Verify is a voluntary AI governance testing framework and open-source toolkit launched by Singapore (IMDA and PDPC) in May 2022 as a Minimum Viable Product to help organisations objectively demonstrate the responsible implementation of AI systems through technical tests and process checks. It has evolved under the stewardship of the AI Verify Foundation to include testing guidance for generative AI and international pilots and sandbox initiatives.
Summary
Read full text ↗Plain English
Overview
AI Verify is a voluntary AI governance testing framework and toolbox originally launched by the Infocomm Media Development Authority (IMDA) together with the Personal Data Protection Commission (PDPC) in May 2022 as a Minimum Viable Product (MVP). The initiative was announced at the World Economic Forum in Davos and set out to provide an objective, repeatable means for organisations to test and demonstrate the claimed performance and governance of AI systems through a combination of technical tests and process checks. The core aim is to increase transparency between companies and their stakeholders by producing standardised reports about fairness, robustness, explainability and operational governance. The framework was subsequently stewarded by the AI Verify Foundation which expanded the toolkit to address Generative AI testing, international pilots and a global assurance sandbox. For official background, see the IMDA press release and the Foundation website (IMDA – press release) and the Foundation's overview (AI Verify Foundation – What is AI Verify).
Definitions
For AI Verify, key terms are defined operationally: "testing framework" refers to the set of governance principles, desired outcomes and mapping to tests/process checks; "toolkit" denotes the collection of open-source testing modules, scripts, datasets, templates and reporting formats that can be executed inside an organisation’s environment; "self-test" describes a developer/owner-conducted execution of the toolkit to verify claims about system behaviour; "third-party test" indicates an independent technical testing provider performing analogous tests under agreed scopes and non-disclosure arrangements. The framework distinguishes Traditional AI (supervised and predictive models) from Generative AI (models that produce content) in its test design and guidance, and emphasises process evidence as much as technical output documentation.
Governance and Institutional Framework
AI Verify was developed under IMDA/PDPC guidance and the advisory inputs from Singapore’s Advisory Council on the Ethical Use of AI and Data. From its MVP launch, governance responsibilities transitioned to the AI Verify Foundation — a not-for-profit steward established to coordinate an open-source community of model and tool providers, enterprise adopters, third-party testers and standards bodies. The Foundation operates as a neutral convenor and maintains the codebase, pilots and outreach; IMDA remains an industry sponsor and collaborator on standards alignment. The institutional design encourages multi-stakeholder membership (including industry premier members, technical testing providers and end-user organisations), transparent release cycles, and partnerships with international benchmarking consortia (for example MLCommons). See the AI Verify Foundation site for details on membership, pilots and events (AI Verify Foundation – Foundation).
Key Focus Areas
AI Verify organises testing and process checks around several interlocking governance dimensions: transparency and explainability (tests to confirm that claims about capabilities, data use and decision logic are accurate and disclosed); fairness and bias (statistical assessments and subgroup performance tests); safety and resilience (robustness checks, adversarial or perturbation tests, and stability under distributional shifts); accountability and oversight (process audits, role and responsibility evidence, incident response readiness); data governance and privacy (data provenance, minimisation and PDPA compliance checks); and model/cybersecurity (basic model integrity and supply-chain checks). For Generative AI, the toolkit adds red-teaming, content-safety benchmarks and contextual safety evaluations, reflecting particular risks such as hallucination, privacy leakage and harmful outputs. The framework emphasises mapping each test to a governance principle and producing traceable documentary evidence to support declared outcomes.
Implementation Framework
Implementation is modular and practical. Organisations select the AI Verify modules aligned to their use case and risk profile, run technical tests (which include open-source benchmarks and scripts) in their enterprise environment, and collate process evidence (policies, design decisions, model cards, dataset summaries). The toolkit generates a structured report describing tests executed, input datasets and metrics, deviations observed, and recommended mitigation steps. Implementation guidance includes: scoping the system under test (model boundary, data inputs, outputs), choosing appropriate metrics and test datasets, documenting governance processes and assigning accountable owners, and determining whether to publish result summaries to customers or procurement partners. The Foundation provides starter kits for both Traditional AI and Generative AI testing and offers pathways to pair deployers with accredited testing partners in pilot sandboxes (AI Assurance Sandbox).
Monitoring and Evaluation
Monitoring under AI Verify focuses on continuous testing and change control: tests should be repeated on model updates, dataset shifts, and operational retraining cycles. The toolkit supports periodic re-run automation, test result dashboards and baseline comparisons so organisations can track risk metrics over time. The Foundation and pilots gather anonymised insights from participating organisations to evaluate tool effectiveness, identify gaps in test coverage, and iterate the toolkit. The Global AI Assurance Pilot and subsequent Sandbox initiative have been used to harvest lessons on what to test for real deployments and how third-party testers can be integrated into an assurance market.
Penalties, Liability, and Appeals
AI Verify is explicitly voluntary and does not itself create statutory penalties. There are no prescribed sanctions in the AI Verify materials for non-participation or for failing tests. However, documented failed tests or governance weaknesses identified by AI Verify could be material in other regulatory or contractual contexts: e.g., PDPA compliance matters (personal data misuse), sectoral supervision (Monetary Authority of Singapore for financial institutions), or procurement and commercial liability in vendor relationships. Organisations should therefore treat AI Verify outputs as part of their internal risk management and external evidence in legal or regulatory reviews. The framework encourages remediation, re-testing and transparent reporting but does not provide an administrative appeals mechanism; any legal appeals would follow jurisdictional statutory routes under relevant Singapore laws.
Relationship to Other Instruments
AI Verify complements Sri ngapore’s existing Model AI Governance Framework and PDPC guidance on AI and data protection rather than replacing them. It maps testable outcomes to internationally-recognised principles (OECD, G7, EU) and seeks interoperability with standardisation work such as ISO/IEC JTC 1/SC 42. The AI Verify Foundation has collaborated with MLCommons and other benchmarking bodies to harmonise safety benchmarks for Generative AI and to feed pilot learnings into standards development. As such, AI Verify functions as an operational assurance layer that sits alongside policy guidance (Model AI Framework), data protection law (PDPA), and sectoral supervisory expectations (e.g., MAS FEAT guidance for finance).
International Alignment
From its inception, AI Verify was designed to be internationally interoperable: the initial IMDA/PDPC announcement invited global pilot partners, the Foundation runs international pilots, and AI Verify mapping documents explicitly reference EU, OECD and G7 principles and ISO work. Collaborations with MLCommons seek to align safety benchmarks and provide benchmarks that can be used by multinational companies and standards bodies. The cross-border intention is to enable common technical testing methods so purchasers and regulators in different jurisdictions can compare and interpret test results in a consistent way.
Implementation Timeline
| Event | Date | Notes |
|---|---|---|
| IMDA/PDPC AI Verify launch (MVP announced at Davos) | 2022-05-25 | IMDA press release announces MVP toolkit and pilot invitations (IMDA). |
| AI Verify Foundation launched (stewardship) | 2023-06-07 | Foundation formed to expand and steward the toolkit (AI Verify Foundation). |
| Project Moonshot (LLM/GenAI toolkit) public/beta | 2024-05-31 | Toolkit for Generative AI testing (Project Moonshot) introduced to address LLM safety & security. |
| Global AI Assurance Pilot | 2025-02-xx | Pilot pairing deployers with technical testers to codify testing norms (AI Verify Foundation report). |
| Global AI Assurance Sandbox launch | 2025-07-07 | Sandbox to scale pilot learnings and connect deployers with testers globally. |
Compliance Checklist
| Checklist Item | How to Demonstrate |
|---|---|
| Scope & system boundary defined | System description, data flow diagrams, intended use statement and model cards |
| Run appropriate technical tests | Test scripts, datasets used, metrics and raw results exported from toolkit |
| Process evidence collected | Governance policies, roles and responsibilities, change control logs |
| Data governance & privacy checks | Data lineage, PDPA impact assessment, anonymisation arguments |
| Remediation & re-testing | Action logs, updated tests and comparative results |
| Stakeholder reporting | Standardised report generated by toolkit and any redacted public summary |
Sources and References
| Source | Type |
|---|---|
| Singapore launches A.I. Verify (IMDA press release, 25 May 2022) | Primary Source |
| Launch of AI Verify (PDPC announcement) | Primary Source |
| AI Verify Foundation – What is AI Verify | Primary Source |
Singapore's AI Verify is a voluntary framework and toolkit designed to help organisations objectively test and demonstrate that their artificial intelligence (AI) systems are implemented responsibly. Launched in May 2022 by the Infocomm Media Development Authority (IMDA) and the Personal Data Protection Commission (PDPC), it applies to any organisation developing or deploying AI systems, offering a way to build trust and transparency with stakeholders.
While participation is voluntary, organisations choosing to use AI Verify gain a structured approach to assessing their AI. Key actions involve: - Running technical tests and process checks on their AI systems using the open-source toolkit. - Focusing on core governance areas such as fairness, robustness, explainability, accountability, data privacy, and cybersecurity. - Documenting their AI governance processes, design decisions, and system boundaries. - Generating standardised reports that detail test results, input data, and any observed deviations. - Regularly re-testing AI systems, especially after updates or changes to data.
The framework, now stewarded by the AI Verify Foundation, has expanded to include specific guidance and tools for generative AI, addressing unique risks like hallucination and harmful outputs. It became operational in May 2022 with its Minimum Viable Product launch.
Crucially, AI Verify itself carries no statutory penalties for non-participation or for failing tests. However, a significant practical pitfall is that any weaknesses or failed tests identified through AI Verify could become relevant evidence in other legal or contractual situations. For example, issues might surface during Personal Data Protection Act (PDPA) compliance reviews, sectoral supervision by authorities like the Monetary Authority of Singapore, or in commercial liability disputes. Therefore, organisations should view AI Verify outputs as a critical component of their internal risk management and as potential external evidence.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 11 marked completePlain-English obligations under Singapore - AI Governance Framework. Not legal advice — verify against the official text before relying on it.
- #1ImportantImplementation Framework⏰ Before commencing testing
Applies to: Organizations choosing to use AI Verify.
“scoping the system under test (model boundary, data inputs, outputs)”
- #2ImportantImplementation Framework⏰ Before commencing testing
Applies to: Organizations choosing to use AI Verify.
“Organisations select the AI Verify modules aligned to their use case and risk profile”
- #3ImportantImplementation Framework⏰ Before demonstrating AI system performance
Applies to: Organizations choosing to use AI Verify.
“run technical tests (which include open-source benchmarks and scripts) in their enterprise environment”
- #4ImportantImplementation Framework⏰ Before demonstrating AI system governance
Applies to: Organizations choosing to use AI Verify.
“collate process evidence (policies, design decisions, model cards, dataset summaries)”
- #5ImportantKey Focus Areas⏰ Before demonstrating AI system performance
Applies to: Organizations choosing to use AI Verify.
“fairness and bias (statistical assessments and subgroup performance tests)”
- #6ImportantKey Focus Areas⏰ Before demonstrating AI system performance
Applies to: Organizations choosing to use AI Verify.
“safety and resilience (robustness checks, adversarial or perturbation tests, and stability under distributional shifts)”
- #7ImportantKey Focus Areas⏰ Before demonstrating AI system governance
Applies to: Organizations choosing to use AI Verify.
“data governance and privacy (data provenance, minimisation and PDPA compliance checks)”
- #8ImportantImplementation Framework⏰ After completing tests and checks
Applies to: Organizations choosing to use AI Verify.
“The toolkit generates a structured report describing tests executed, input datasets and metrics, deviations observed, and recommended mitigation steps.”
- #9ImportantMonitoring and Evaluation⏰ Continuously
Applies to: Organizations choosing to use AI Verify.
“tests should be repeated on model updates, dataset shifts, and operational retraining cycles.”
- #10ImportantPenalties, Liability, and Appeals⏰ Continuously
Applies to: Organizations choosing to use AI Verify.
“Organisations should therefore treat AI Verify outputs as part of their internal risk management and external evidence in legal or regulatory reviews.”
- #11RecommendedImplementation Framework⏰ After generating the report
Applies to: Organizations choosing to use AI Verify.
“determining whether to publish result summaries to customers or procurement partners.”
Related Regulations
National Artificial Intelligence Strategy 2.0 (NAIS 2.0)
Singapore90% similar
Advisory Council on the Ethical Use of AI and Data
Singapore90% similar
Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems (PDPC)
Singapore90% similar
AI Singapore (national AI research and translation programme)
Singapore89% similar
India AI Governance Guidelines: Enabling Safe and Trusted AI Innovation
India89% similar
© Regulations.AI — created on 13-Jun-2026