Singapore - AI Governance Framework

AI Verify (AI governance testing framework and toolkit)

Singapore

RAI-SG-NA-AVAGTXX-2022
Effective: May 25, 2022
In Force(In Force)
GuidelineSafety, Testing, and EvaluationTransparency and DisclosureAccountability and Documentation
Export PDF

AI Verify is a voluntary AI governance testing framework and open-source toolkit launched by Singapore (IMDA and PDPC) in May 2022 as a Minimum Viable Product to help organisations objectively demonstrate the responsible implementation of AI systems through technical tests and process checks. It has evolved under the stewardship of the AI Verify Foundation to include testing guidance for generative AI and international pilots and sandbox initiatives.

Overview

AI Verify is a voluntary AI governance testing framework and toolbox originally launched by the Infocomm Media Development Authority (IMDA) together with the Personal Data Protection Commission (PDPC) in May 2022 as a Minimum Viable Product (MVP). The initiative was announced at the World Economic Forum in Davos and set out to provide an objective, repeatable means for organisations to test and demonstrate the claimed performance and governance of AI systems through a combination of technical tests and process checks. The core aim is to increase transparency between companies and their stakeholders by producing standardised reports about fairness, robustness, explainability and operational governance. The framework was subsequently stewarded by the AI Verify Foundation which expanded the toolkit to address Generative AI testing, international pilots and a global assurance sandbox. For official background, see the IMDA press release and the Foundation website (IMDA – press release) and the Foundation's overview (AI Verify Foundation – What is AI Verify).

Definitions

For AI Verify, key terms are defined operationally: "testing framework" refers to the set of governance principles, desired outcomes and mapping to tests/process checks; "toolkit" denotes the collection of open-source testing modules, scripts, datasets, templates and reporting formats that can be executed inside an organisation’s environment; "self-test" describes a developer/owner-conducted execution of the toolkit to verify claims about system behaviour; "third-party test" indicates an independent technical testing provider performing analogous tests under agreed scopes and non-disclosure arrangements. The framework distinguishes Traditional AI (supervised and predictive models) from Generative AI (models that produce content) in its test design and guidance, and emphasises process evidence as much as technical output documentation.

Governance and Institutional Framework

AI Verify was developed under IMDA/PDPC guidance and the advisory inputs from Singapore’s Advisory Council on the Ethical Use of AI and Data. From its MVP launch, governance responsibilities transitioned to the AI Verify Foundation — a not-for-profit steward established to coordinate an open-source community of model and tool providers, enterprise adopters, third-party testers and standards bodies. The Foundation operates as a neutral convenor and maintains the codebase, pilots and outreach; IMDA remains an industry sponsor and collaborator on standards alignment. The institutional design encourages multi-stakeholder membership (including industry premier members, technical testing providers and end-user organisations), transparent release cycles, and partnerships with international benchmarking consortia (for example MLCommons). See the AI Verify Foundation site for details on membership, pilots and events (AI Verify Foundation – Foundation).

Key Focus Areas

AI Verify organises testing and process checks around several interlocking governance dimensions: transparency and explainability (tests to confirm that claims about capabilities, data use and decision logic are accurate and disclosed); fairness and bias (statistical assessments and subgroup performance tests); safety and resilience (robustness checks, adversarial or perturbation tests, and stability under distributional shifts); accountability and oversight (process audits, role and responsibility evidence, incident response readiness); data governance and privacy (data provenance, minimisation and PDPA compliance checks); and model/cybersecurity (basic model integrity and supply-chain checks). For Generative AI, the toolkit adds red-teaming, content-safety benchmarks and contextual safety evaluations, reflecting particular risks such as hallucination, privacy leakage and harmful outputs. The framework emphasises mapping each test to a governance principle and producing traceable documentary evidence to support declared outcomes.

Implementation Framework

Implementation is modular and practical. Organisations select the AI Verify modules aligned to their use case and risk profile, run technical tests (which include open-source benchmarks and scripts) in their enterprise environment, and collate process evidence (policies, design decisions, model cards, dataset summaries). The toolkit generates a structured report describing tests executed, input datasets and metrics, deviations observed, and recommended mitigation steps. Implementation guidance includes: scoping the system under test (model boundary, data inputs, outputs), choosing appropriate metrics and test datasets, documenting governance processes and assigning accountable owners, and determining whether to publish result summaries to customers or procurement partners. The Foundation provides starter kits for both Traditional AI and Generative AI testing and offers pathways to pair deployers with accredited testing partners in pilot sandboxes (AI Assurance Sandbox).

Monitoring and Evaluation

Monitoring under AI Verify focuses on continuous testing and change control: tests should be repeated on model updates, dataset shifts, and operational retraining cycles. The toolkit supports periodic re-run automation, test result dashboards and baseline comparisons so organisations can track risk metrics over time. The Foundation and pilots gather anonymised insights from participating organisations to evaluate tool effectiveness, identify gaps in test coverage, and iterate the toolkit. The Global AI Assurance Pilot and subsequent Sandbox initiative have been used to harvest lessons on what to test for real deployments and how third-party testers can be integrated into an assurance market.

Penalties, Liability, and Appeals

AI Verify is explicitly voluntary and does not itself create statutory penalties. There are no prescribed sanctions in the AI Verify materials for non-participation or for failing tests. However, documented failed tests or governance weaknesses identified by AI Verify could be material in other regulatory or contractual contexts: e.g., PDPA compliance matters (personal data misuse), sectoral supervision (Monetary Authority of Singapore for financial institutions), or procurement and commercial liability in vendor relationships. Organisations should therefore treat AI Verify outputs as part of their internal risk management and external evidence in legal or regulatory reviews. The framework encourages remediation, re-testing and transparent reporting but does not provide an administrative appeals mechanism; any legal appeals would follow jurisdictional statutory routes under relevant Singapore laws.

Relationship to Other Instruments

AI Verify complements Sri ngapore’s existing Model AI Governance Framework and PDPC guidance on AI and data protection rather than replacing them. It maps testable outcomes to internationally-recognised principles (OECD, G7, EU) and seeks interoperability with standardisation work such as ISO/IEC JTC 1/SC 42. The AI Verify Foundation has collaborated with MLCommons and other benchmarking bodies to harmonise safety benchmarks for Generative AI and to feed pilot learnings into standards development. As such, AI Verify functions as an operational assurance layer that sits alongside policy guidance (Model AI Framework), data protection law (PDPA), and sectoral supervisory expectations (e.g., MAS FEAT guidance for finance).

International Alignment

From its inception, AI Verify was designed to be internationally interoperable: the initial IMDA/PDPC announcement invited global pilot partners, the Foundation runs international pilots, and AI Verify mapping documents explicitly reference EU, OECD and G7 principles and ISO work. Collaborations with MLCommons seek to align safety benchmarks and provide benchmarks that can be used by multinational companies and standards bodies. The cross-border intention is to enable common technical testing methods so purchasers and regulators in different jurisdictions can compare and interpret test results in a consistent way.

Implementation Timeline

EventDateNotes
IMDA/PDPC AI Verify launch (MVP announced at Davos)2022-05-25IMDA press release announces MVP toolkit and pilot invitations (IMDA).
AI Verify Foundation launched (stewardship)2023-06-07Foundation formed to expand and steward the toolkit (AI Verify Foundation).
Project Moonshot (LLM/GenAI toolkit) public/beta2024-05-31Toolkit for Generative AI testing (Project Moonshot) introduced to address LLM safety & security.
Global AI Assurance Pilot2025-02-xxPilot pairing deployers with technical testers to codify testing norms (AI Verify Foundation report).
Global AI Assurance Sandbox launch2025-07-07Sandbox to scale pilot learnings and connect deployers with testers globally.

Compliance Checklist

Checklist ItemHow to Demonstrate
Scope & system boundary definedSystem description, data flow diagrams, intended use statement and model cards
Run appropriate technical testsTest scripts, datasets used, metrics and raw results exported from toolkit
Process evidence collectedGovernance policies, roles and responsibilities, change control logs
Data governance & privacy checksData lineage, PDPA impact assessment, anonymisation arguments
Remediation & re-testingAction logs, updated tests and comparative results
Stakeholder reportingStandardised report generated by toolkit and any redacted public summary

Sources and References

SourceType
Singapore launches A.I. Verify (IMDA press release, 25 May 2022)Primary Source
Launch of AI Verify (PDPC announcement)Primary Source
AI Verify Foundation – What is AI VerifyPrimary Source
Plain English

Singapore's AI Verify is a voluntary framework and toolkit designed to help organisations objectively test and demonstrate that their artificial intelligence (AI) systems are implemented responsibly. Launched in May 2022 by the Infocomm Media Development Authority (IMDA) and the Personal Data Protection Commission (PDPC), it applies to any organisation developing or deploying AI systems, offering a way to build trust and transparency with stakeholders.

While participation is voluntary, organisations choosing to use AI Verify gain a structured approach to assessing their AI. Key actions involve: - Running technical tests and process checks on their AI systems using the open-source toolkit. - Focusing on core governance areas such as fairness, robustness, explainability, accountability, data privacy, and cybersecurity. - Documenting their AI governance processes, design decisions, and system boundaries. - Generating standardised reports that detail test results, input data, and any observed deviations. - Regularly re-testing AI systems, especially after updates or changes to data.

The framework, now stewarded by the AI Verify Foundation, has expanded to include specific guidance and tools for generative AI, addressing unique risks like hallucination and harmful outputs. It became operational in May 2022 with its Minimum Viable Product launch.

Crucially, AI Verify itself carries no statutory penalties for non-participation or for failing tests. However, a significant practical pitfall is that any weaknesses or failed tests identified through AI Verify could become relevant evidence in other legal or contractual situations. For example, issues might surface during Personal Data Protection Act (PDPA) compliance reviews, sectoral supervision by authorities like the Monetary Authority of Singapore, or in commercial liability disputes. Therefore, organisations should view AI Verify outputs as a critical component of their internal risk management and as potential external evidence.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 11 marked complete

Plain-English obligations under Singapore - AI Governance Framework. Not legal advice — verify against the official text before relying on it.

  1. #1ImportantImplementation FrameworkBefore commencing testing

    Applies to: Organizations choosing to use AI Verify.

    scoping the system under test (model boundary, data inputs, outputs)
  2. #2ImportantImplementation FrameworkBefore commencing testing

    Applies to: Organizations choosing to use AI Verify.

    Organisations select the AI Verify modules aligned to their use case and risk profile
  3. #3ImportantImplementation FrameworkBefore demonstrating AI system performance

    Applies to: Organizations choosing to use AI Verify.

    run technical tests (which include open-source benchmarks and scripts) in their enterprise environment
  4. #4ImportantImplementation FrameworkBefore demonstrating AI system governance

    Applies to: Organizations choosing to use AI Verify.

    collate process evidence (policies, design decisions, model cards, dataset summaries)
  5. #5ImportantKey Focus AreasBefore demonstrating AI system performance

    Applies to: Organizations choosing to use AI Verify.

    fairness and bias (statistical assessments and subgroup performance tests)
  6. #6ImportantKey Focus AreasBefore demonstrating AI system performance

    Applies to: Organizations choosing to use AI Verify.

    safety and resilience (robustness checks, adversarial or perturbation tests, and stability under distributional shifts)
  7. #7ImportantKey Focus AreasBefore demonstrating AI system governance

    Applies to: Organizations choosing to use AI Verify.

    data governance and privacy (data provenance, minimisation and PDPA compliance checks)
  8. #8ImportantImplementation FrameworkAfter completing tests and checks

    Applies to: Organizations choosing to use AI Verify.

    The toolkit generates a structured report describing tests executed, input datasets and metrics, deviations observed, and recommended mitigation steps.
  9. #9ImportantMonitoring and EvaluationContinuously

    Applies to: Organizations choosing to use AI Verify.

    tests should be repeated on model updates, dataset shifts, and operational retraining cycles.
  10. #10ImportantPenalties, Liability, and AppealsContinuously

    Applies to: Organizations choosing to use AI Verify.

    Organisations should therefore treat AI Verify outputs as part of their internal risk management and external evidence in legal or regulatory reviews.
  11. #11RecommendedImplementation FrameworkAfter generating the report

    Applies to: Organizations choosing to use AI Verify.

    determining whether to publish result summaries to customers or procurement partners.

© Regulations.AI — created on 13-Jun-2026