Singapore MAS AI Risk Guidelines

Guidelines on Artificial Intelligence Risk Management

Singapore

RAI-SG-NA-SINGAPO-2026
Awaiting Entry(Awaiting Entry)As published at mas.gov.sg

Singapore MAS AI Risk Guidelines is Awaiting Entry in Singapore, according to mas.gov.sg. We have not yet been able to confirm the status.

GuidelineGovernance and OversightRisk ManagementAccountability and Documentation
Export PDF

MAS sets supervisory expectations for responsible AI use by Singapore financial institutions.

Summary

MAS issued AI risk management guidelines for financial institutions, covering governance, inventories, testing, monitoring, and proportional controls across the AI life cycle. The framework applies to all AI types, including generative AI and AI agents, and phases in between 2027 and 2028.

Full article

Read full text ↗

Overview

The Monetary Authority of Singapore (MAS) issued the Guidelines on Artificial Intelligence Risk Management on 7 October 2026 to set out supervisory expectations for financial institutions (FIs) using AI. The Guidelines are explicitly designed to support responsible AI adoption across Singapore’s financial sector, while allowing firms to tailor controls to their own size, activities, and risk profiles. MAS states that the Guidelines apply to all FIs and all forms of AI technologies, including Generative AI and newer developments such as AI agents. The instrument is non-binding in form, but it is supervisory guidance that MAS expects institutions to follow in a proportionate manner.

The Guidelines are structured around six substantive areas: application and proportionality; AI oversight; key AI risk management systems, policies and procedures; AI life cycle controls; and AI capability and capacity. MAS emphasizes that AI risks are usually extensions of existing business, operational, conduct, financial crime, reputational, legal, and technology risks, but that newer systems can increase uncertainty, opacity, and susceptibility to harmful outcomes. The instrument also notes that local and group frameworks may be used where they satisfy MAS’ expectations, and that existing FEAT principles remain relevant. The Guidelines take effect on 7 October 2027, with Sections 3 and 4 applicable from that date and Sections 5 and 6 by 7 October 2028.

Official source: MAS Guidelines on Artificial Intelligence Risk Management for Financial Institutions. A related MAS media release dated 7 October 2026 explains that the Guidelines follow a November 2025 consultation and refine the expectations in response to stakeholder feedback, especially on proportionality, existing governance structures, embedded AI, and when basic policies may suffice.

Definitions

MAS defines AI for purposes of the Guidelines as machine-based systems or models that derive outputs through learned premises such as the data or inputs they receive. The outputs may include estimates, predictions, content, summaries, recommendations, or decisions that influence physical or virtual environments. The definition is broad enough to cover machine learning, deep learning, natural language processing, computer vision, Generative AI, large language models, and AI agents, while excluding calculators, purely rule-based systems, explicit formula tools, and robotic process automation that does not learn or adapt. MAS also makes clear that the list of examples is non-exhaustive and that newer techniques should be assessed against the functional definition rather than their label.

The Guidelines also define three core operational terms. A model is a method or approach that converts assumptions and input data into outputs such as estimates, decisions, or recommendations. A system comprises one or more models and other machine-based components. A use case is the specific real-world context in which a model or system is applied. MAS further introduces the idea of third-party AI, meaning systems, models, services, or tools developed, owned, operated, or provided by an external party and relied upon by an FI. These definitions matter because the scope of governance, inventorisation, testing, and monitoring obligations varies depending on whether an FI is using AI internally, deploying it in customer-facing settings, or relying on externally supplied tools.

The document also uses several risk and control concepts throughout, including AI incidents, kill switches, risk materiality, and residual risk materiality. In the MAS framework, these terms function as compliance anchors: institutions must identify AI, place it into inventories, assess whether it is materially risky, and ensure that the remaining risk after controls fits within the FI’s risk appetite. The definitions are therefore operational rather than academic, and they drive how institutions structure oversight, testing, documentation, and ongoing review.

Governance and Institutional Framework

MAS places AI governance squarely at board and senior management level. The board of directors, or a delegated board committee, is responsible for approving and regularly reviewing the overall governance approach, setting the strategic direction for AI use, embedding AI risks into the risk appetite framework, and ensuring clear roles and responsibilities for oversight. The board must also understand AI sufficiently to challenge management effectively and must keep the governance model under regular review as AI technologies and the institution’s business profile evolve. MAS is explicit that existing governance structures may be used if they provide adequate oversight and coordination; a dedicated AI committee is not mandatory.

Senior management carries the responsibility for implementation. It must ensure that AI-related risk management frameworks, structures, policies, and procedures are actually embedded across the institution and remain consistent with the approved risk appetite. Management must establish internal escalation processes for material risks, exceptions, and incidents, update the board on significant issues, and ensure that personnel have the necessary competence and resources. MAS also emphasizes local accountability where an FI is part of a global group: Singapore senior management remains accountable for ensuring group frameworks address Singapore-specific considerations and regulatory requirements, and must be able to demonstrate this to MAS even when relying on group-level governance. This reflects a clear supervisory expectation that governance cannot be outsourced to global policy alone.

The Guidelines are therefore built around accountable, cross-functional governance rather than formalistic structures. MAS expects AI risk to be coordinated across business lines and control functions, with clear reporting lines and escalation paths. That approach mirrors the broader MAS supervisory style in financial regulation: institutions are allowed flexibility in design, but they must prove that oversight is effective, coordinated, and proportionate to risk. The focus is not only on preventing harm, but on ensuring that AI use remains compatible with regulatory compliance, consumer protection, and broader risk management obligations.

Key Focus Areas

The Guidelines identify six major control domains. First, an FI must establish systems, policies, and procedures to identify AI across business and functional areas, including AI embedded in third-party services. Second, it must maintain an AI inventory that is accurate, up to date, and linked to other relevant inventories. Third, it must assess the risk materiality of each AI use case using a consistent methodology that considers impact, complexity, and reliance. Fourth, it must implement life cycle controls covering data management, transparency, fairness, human oversight, third-party AI, selection, evaluation and testing, security, documentation, pre-deployment review, monitoring, change management, and retirement. Fifth, it must ensure adequate capabilities and capacity, including training and sufficient technical infrastructure.

A central theme across these focus areas is proportionality. MAS distinguishes between AI use cases that are low materiality and those that pose higher risks to the FI, its customers, or other stakeholders. For low-impact uses, such as drafting emails or summarising internal notes, basic AI governance policies may suffice if poor performance or unavailability is unlikely to have a material adverse impact. Even then, basic policies must include accountability, permitted and prohibited uses, approved tool lists, staff education, compliance checks, and periodic reviews. By contrast, AI used in high-impact activities such as credit decisioning, insurance underwriting, financial advisory, fund management, or mission-critical internal processes requires stronger controls, deeper testing, more robust documentation, and more active oversight.

MAS also highlights particular technology trends and their associated risks, especially Generative AI and AI agents. These systems can introduce new forms of uncertainty, hallucination, prompt injection, data poisoning, confidentiality leakage, automation bias, and tool misuse. The Guidelines therefore treat newer AI not as an exception to the framework, but as a reason to revisit the adequacy of existing controls. Institutions are expected to review their arrangements regularly and upgrade them as AI capabilities, deployment patterns, and operational dependencies evolve.

Implementation Framework

MAS requires each FI to build practical systems for AI identification, inventory management, and risk assessment. Identification is the entry point: institutions must establish clear AI definitions, criteria, and processes so that relevant business and functional units can consistently spot AI use, including AI hidden inside software-as-a-service or other third-party offerings. A designated control function must oversee the process, remain the final arbiter of whether a use counts as AI, and ensure that documentation is maintained and updated as technologies and third-party services change. Where identification is difficult because of shadow AI or poor disclosure by vendors, the FI must identify the residual risks and deploy mitigating measures.

The AI inventory is the backbone of implementation. It must track use cases, systems, or models to the extent practicable, and should include attributes such as purpose, scope of use, model type, data used, dependencies, lifecycle status, assigned risk materiality, review status, key owners, and links to essential documentation. The inventory may be dedicated or integrated into existing registers, but it should be linked to related data or third-party inventories. MAS also expects a formal risk materiality methodology that evaluates impact, complexity, and reliance both before and after controls are applied. The residual risk must fit the FI’s risk appetite before deployment, and the assessment framework must be documented, assigned to a control function, and reviewed regularly.

Implementation also requires controls through the full AI life cycle. These controls are not one-size-fits-all; they must be calibrated to relevance and risk. For example, high-risk systems may need contingency plans, kill switches, more intensive testing, formal independent validation, and stronger post-deployment monitoring. The Guidelines also recognize that deployment may occur in pilots or phased rollouts, and that controls may need to be adapted for partial deployment, subject to clear policies, user limits, success criteria, and monitoring. This is a practical framework rather than a purely theoretical one, designed to integrate AI into existing compliance and technology risk management operations.

Monitoring and Evaluation

Monitoring and evaluation are recurring obligations under the Guidelines. MAS expects FIs to define evaluation measures, thresholds, testing approaches, and review processes that are proportionate to the risk materiality of the AI use case. Before deployment, systems or models should be tested against real-world scenarios and edge cases, with particular attention to reliability and safety. Testing methods may include out-of-sample and out-of-time testing, sensitivity analysis, stability analysis, sub-population analysis, stress testing, error analysis, benchmarking, and adversarial testing. For Generative AI, the Guidelines highlight failure modes such as hallucinations, toxic or biased outputs, data leakage, and vulnerabilities to attack.

Post-deployment monitoring must be continuous and robust. MAS expects institutions to track metrics such as robustness, stability, data quality, and fairness, and to include tiered thresholds that provide early warning of deterioration. The FI must also watch for data drift, concept drift, and model drift. If issues arise, there must be formal processes for reporting, escalating, tracking, and resolving them, including retraining, redevelopment, or decommissioning where necessary. Users should have a way to provide feedback and report issues, and monitoring personnel should be trained to recognize unintended behaviour. High-risk use cases should be subject to regular re-validations by independent parties.

The monitoring framework extends beyond outputs to include operational and governance records. FIs should maintain logs and documentation of monitoring activities, issues, incidents, remediation actions, and, where relevant, prompts, responses, and reasoning traces for Generative AI or agentic systems. Re-validations may also be triggered by broader changes, such as changes in the operating environment, incidents in connected systems, or new external regulatory or technological developments. MAS’ approach is clearly life-cycle oriented: AI governance is not complete at approval; it must be sustained and refreshed throughout deployment and use.

Penalties, Liability, and Appeals

The Guidelines themselves do not create a standalone penalties regime, civil liability framework, or formal appeal process. They are supervisory expectations issued by MAS, not a statute or regulation with its own sanctions code. That said, MAS frames the Guidelines as part of the regulatory expectations that financial institutions must consider in meeting their broader obligations. Failure to follow the Guidelines could therefore become relevant in supervisory reviews, thematic assessments, enforcement decisions, or evaluations of whether an FI has managed operational, conduct, technology, or outsourcing risks adequately under the MAS framework.

MAS also states that the Guidelines complement existing legislation, guidelines, information papers, and circulars. This means that any enforcement or liability consequences will generally arise through the underlying sectoral regimes rather than through the Guidelines as a self-contained instrument. For example, where AI use intersects with technology risk, data protection, financial advice, fair dealing, or outsourcing, the relevant legal and supervisory instruments continue to apply. Institutions are expected to implement AI risk management in a manner consistent with those existing requirements, and to use controls that are proportionate to the potential impact on customers, the FI, and other stakeholders.

Because the instrument is non-binding guidance, there is no dedicated statutory appeal channel described in the text. However, institutions interacting with MAS can generally respond through ordinary supervisory engagement, remediation discussions, or other procedural avenues that arise under the applicable financial regulatory framework. In practical terms, the strongest compliance strategy is not to rely on post hoc contestation, but to build documented evidence that the FI’s AI controls, approvals, testing, and monitoring satisfy MAS’ supervisory expectations.

Relationship to Other Instruments

The Guidelines explicitly complement existing MAS legislation and guidance. They are to be read together with relevant guidelines, information papers, and circulars issued by MAS from time to time. MAS specifically notes that the FEAT principles—Fairness, Ethics, Accountability and Transparency—continue to guide the use of AI in the financial sector. The Guidelines also interact with MAS’ technology risk management framework, third-party risk management expectations, and broader conduct and compliance obligations. They are not intended to displace those instruments but to provide an AI-specific supervisory overlay.

MAS also references a number of external and related frameworks that firms may use for reference where appropriate. These include the Cyber Security Agency of Singapore’s guidance on securing AI systems, IMDA’s AI Governance Framework, the AI Verify Foundation initiatives, PDPC advisory guidelines on the use of personal data in AI recommendation and decision systems and in Generative AI, and the NIST AI Risk Management Framework. The document likewise cross-references MAS’ Guidelines on Risk Management Practices for Technology Risk and notes that existing principles on fair dealing remain relevant. This ecosystem approach means that AI governance is embedded within a wider multi-agency and multi-framework compliance landscape in Singapore.

The relationship to other instruments is especially important for third-party AI and data-related controls. MAS says that its expectations on outsourcing and third-party services continue to apply where third-party AI is used. Similarly, privacy and consent requirements remain relevant where AI processes personal or sensitive personal data. The Guidelines therefore function as a sector-specific harmonization document, aligning AI governance with Singapore’s established regulatory architecture rather than creating a separate isolated regime.

International Alignment

MAS positions the Guidelines within an international trend toward risk-based AI governance. The document references the Financial Stability Board’s consultations on sound practices for responsible AI adoption and notes that regulators and international bodies are emphasizing the need to manage AI risks while allowing firms to realize the benefits of adoption. The structure of the Guidelines, with its focus on proportionality, enterprise-wide oversight, life-cycle controls, and ongoing review, is consistent with international supervisory practice in financial regulation.

There is also technical and conceptual alignment with well-known global frameworks. MAS refers to the NIST AI Risk Management Framework for transparency, explainability, and infrastructure considerations, and draws on ISO/IEC 22989 for the AI life-cycle concept. In addition, the Guidelines encourage FIs to consider industry standards and broader national initiatives when appropriate. This signals openness to internationally recognized approaches while keeping the compliance baseline anchored in Singapore’s supervisory expectations. The Guidelines thus support cross-border firms that already operate with global AI governance structures, so long as local controls remain sufficiently tailored to Singapore.

On a policy level, the Guidelines reflect a broader international move toward accountable AI rather than prescriptive technology bans. They are compatible with innovation, including generative and agentic systems, but insist that institutions understand, test, monitor, and govern those systems in proportion to their risk. That balance between innovation and control is one of the clearest markers of convergence with leading international regulatory approaches.

Implementation Timeline

MilestoneDateNotes
Consultation paper issued2025-11-13MAS launched consultation on proposed AI risk management guidelines for financial institutions.
Public consultation closes2026-01-31Deadline for comments announced in the MAS media release.
Guidelines issued2026-10-07MAS published the final Guidelines on Artificial Intelligence Risk Management for Financial Institutions.
Guidelines take effect2027-10-07General effective date stated in paragraph 1.8.
Sections 3 and 4 applicable2027-10-07AI Oversight and Key AI Risk Management Systems, Policies and Procedures become applicable from this date.
Sections 5 and 6 applicable2028-10-07AI Life Cycle Controls and AI Capability & Capacity become applicable by this date.

Compliance Checklist

CheckRequired Action
Board oversightConfirm board or delegated committee approval of AI governance approach, risk appetite, and accountability.
Senior management ownershipAssign senior management responsibility for implementing AI controls and escalation.
AI identificationEstablish consistent processes to identify AI use across business lines and third-party services.
AI inventoryMaintain an accurate inventory with required attributes, linkages, and regular updates.
Risk materiality assessmentAssess impact, complexity, and reliance for each AI use case and document residual risk.
Data governanceEnsure AI data is fit for purpose, representative, secure, auditable, and privacy-compliant.
Testing and validationConduct proportionate evaluation, testing, and independent pre-deployment review.
Monitoring and incident responseImplement post-deployment monitoring, escalation, remediation, and re-validation procedures.
Third-party AI controlsObtain adequate contractual rights, visibility, testing assurance, and contingency planning.
Capability and infrastructureEnsure personnel competence, training, and sufficient technology infrastructure for AI use.

Sources and References

SourceType
Guidelines on Artificial Intelligence Risk Management — Monetary Authority of Singaporeofficial
Guidelines on Artificial Intelligence Risk Management (PDF, 7 October 2026)official
MAS media release, 7 October 2026official
Consultation Paper P017-2025 on the proposed Guidelinesofficial

© Regulations.AI — created on 9 Oct 2026 using Gemini 3.6 Flash