MAS AI Risk Management Guidelines: Inventory First, Controls by 2028

RegReportingDesk card: MAS, Monetary Authority of Singapore, Singapore

On 7 October 2026 the Monetary Authority of Singapore (MAS) issued its Guidelines on Artificial Intelligence Risk Management, together with a response to the feedback it received on consultation paper P017-2025 of November 2025. The MAS AI risk management guidelines take effect on 7 October 2027 and reach every financial institution (FI) as defined in Section 2 of the Financial Services and Markets Act 2022, across all forms of AI, from a logistic regression credit model to an AI agent with tool access. Implementation is phased. The oversight, identification, inventory and risk materiality expectations in Sections 3 and 4 apply from 7 October 2027; the lifecycle controls and capability expectations in Sections 5 and 6 are to be met by 7 October 2028.

The first deliverables are records a supervisor can ask to see: a board-approved governance approach and AI risk appetite, a defined process for finding AI use, an AI inventory, and a methodology that rates each AI use case on impact, complexity and reliance. An FI whose AI tools are unlikely to cause a material adverse impact if they perform poorly or go offline can stay on a shorter set of basic policies, and MAS expects that set completed within the same first 12 months.

The response paper also answers a question reporting teams will ask first. MAS does not intend to introduce AI-specific incident reporting to MAS at this juncture; existing incident reporting duties keep applying whatever the root cause.

Related reading: FSB AI Sound Practices: Consultation Responses Published

MAS AI risk management guidelines: the dates that matter

Two dates carry the obligations. The response paper adds a qualifier that cuts into the second one.

Date What happens Source
13 November 2025 MAS issues consultation paper P017-2025 Response paper, para 1.1
31 January 2026 Consultation closes Response paper, para 1.2
7 October 2026 Final Guidelines and response to feedback published MAS media release
7 October 2027 Guidelines take effect; Sections 3 and 4 apply; FIs on the basic-policies route complete implementation Guidelines para 1.8; response paper paras 13.5 and 13.6
2027 (no date given) MAS intends to consult the sector on additional guidance for agentic AI MAS media release
7 October 2028 Sections 5 and 6 (lifecycle controls, capability and capacity) to be met Guidelines para 1.8

The qualifier sits in paragraph 13.5 of the response paper. An FI should apply appropriate lifecycle controls to its high risk use cases as soon as possible and should not hold them back until the end of the 24-month transition. October 2028 stays the outer limit for full implementation across the portfolio, but for a use case the FI has rated high risk the paragraph expects the controls as soon as possible, so that date should not be planned as the delivery date for those use cases.

Paragraph 1.8 of the Guidelines frames the phasing permissively (“FIs may meet the expectations set out in Sections 3 to 4 from 7 October 2027”), while the media release and the response paper describe the same dates as expectations FIs should meet. Both texts carry the same two dates; the response paper is the clearer statement of what MAS expects by when.

MAS describes guidelines as principles or best practice standards. Contravening them is not a criminal offence and does not attract civil penalties, but specified institutions should observe their spirit, and how well an institution observes them may affect MAS’s overall risk assessment of it.

Paragraph 1.2 places the Guidelines on top of what already exists. The FEAT principles on fairness, ethics, accountability and transparency, issued in 2018, continue to guide AI use. Footnote 15 adds that an FI should continue to adhere to the Guidelines on Fair Dealing when it uses AI to deliver products and services. Footnote 39 applies MAS’s outsourcing and third-party expectations to third-party AI, and footnote 47 points to the Guidelines on Risk Management Practices for Technology Risk.

The layering runs one way. Response paragraph 10.37 states that an AI system meeting the “critical system” criteria under the MAS Notice on Technology Risk Management stays subject to that Notice’s availability and recoverability requirements, and that controls already built for the Notices on Cyber Hygiene and Technology Risk Management may be applied to AI components. The same paragraph says the AI expectations complement MAS’s existing Technology Risk Management Guidelines and should be read in conjunction with those Notices, so the AI-specific expectations sit alongside the Notice requirements.

For groups that also run EU entities, the two regimes classify differently. The EU AI Act compliance obligations for financial institutions attach to categories the Act itself defines, including its high-risk classification rules. MAS sets no list of prohibited or high-risk uses and states in response paragraph 12.3 that it does not intend to restrict any specific AI technology or limit use cases, provided the risks are adequately addressed. A Singapore “high” rating comes from the FI’s own methodology.

Who the Guidelines reach, and the group-basis rule

The Guidelines apply to all FIs in a proportionate manner (paragraph 2.1), and response paragraph 2.3 confirms they apply regardless of where an FI is incorporated. A Singapore branch of a foreign bank and a locally incorporated insurer sit under the same expectations.

The group-basis rule is narrower. Paragraph 1.2 applies the Guidelines on a group basis for locally incorporated FIs that are either subject to consolidated supervision by MAS, which footnote 4 says includes locally incorporated FIs from the banking and insurance sectors, or an owner of critical information infrastructure as defined in the Cybersecurity Act 2018. For those groups, the expectations extend across their branches and subsidiaries, including those abroad (response paragraphs 2.2 and 2.3).

FIs inside a global group get room to reuse group work. Paragraph 1.5 lets an FI that is part of a global group take guidance from, or use, its group’s AI risk management framework, as long as that framework meets the Guidelines. The board-level oversight role can sit with a regional or global committee that oversees the AI risks relevant to the Singapore FI (footnote 17).

Accountability for the Singapore view still stays local. Paragraph 3.6 expects local senior management to have adequate visibility into and input on matters affecting Singapore operations, timely access to the reports and data behind AI risk decisions, clear escalation paths for Singapore-specific issues, and the ability to demonstrate to MAS how they discharge oversight when relying on group frameworks. A group policy document on its own does not meet that paragraph.

What counts as AI, including hybrid and embedded systems

Paragraph 1.3 defines AI as machine-based systems or models that derive outputs through learned premises, such as the data or inputs they receive. Outputs include estimates, predictions, content, summaries, recommendations or decisions. Calculators or tools whose outputs rest solely on predefined programming logic or rules fall outside. The response paper turned the definition into examples:

Generally within the AI definition Generally outside the AI definition
Machine learning (supervised, unsupervised, reinforcement), including logistic regression and gradient boosting Standard rule-based investment formulas and portfolio construction methods
Deep learning, natural language processing, computer vision Expert systems based on explicit if-then rules
Generative AI, including large language models Traditional robotic process automation following rule-based decision trees
AI agents, including multi-agent systems Stochastic simulations such as Monte Carlo that are not derived from training data

Source: response paper paragraph 2.8 and Guidelines footnote 6. MAS calls the lists illustrative and non-exhaustive.

A scoping exercise that reads “AI” as generative AI would leave out a logistic regression application scorecard or a gradient-boosted fraud model, and MAS names both techniques as in scope. Response paragraph 2.9 extends coverage to hybrid systems with both rule-based and AI components, and to AI that is only partially deployed in a pilot or proof of concept.

Embedded AI is in scope too. Response paragraphs 2.10 and 2.11 bring in AI incorporated within third-party services and AI that a provider uses to deliver services to the FI, even when the service is not marketed as AI. Footnote 21 gives the typical case: software-as-a-service with AI features an FI uses as part of consuming the service.

My reading of the Monte Carlo exclusion is that it turns on the words “not derived from training data”. A simulation engine whose parameters come out of a learned model would be assessed as a hybrid, and hybrids are in.

The paragraph 2.3 test: when basic AI policies are enough

Paragraph 2.3 is the switch that decides how much of the Guidelines an FI has to build. An FI may apply basic AI governance policies and procedures if the poor performance or unavailability of the AI services or tools it uses is unlikely to have a material adverse impact on the FI, its customers or other stakeholders. The assessment has to consider two things: the potential financial, operational, regulatory, legal or reputational impact on the FI, and the potential impact on customers or other stakeholders, including fairness, ethical conduct and consumer protection.

Paragraph 2.4 lists uses that would generally meet the test, provided humans review and check the outputs before using them (footnote 13): drafting, proofreading or rephrasing emails to customers; summarising documents or meeting notes for internal reference; initial review or analysis of documents for internal reference; generating formulas, charts or visualisations for internal reference; image generation for marketing or internal materials; and chatbots that help staff locate internal resources such as policies or procedures.

The basic set in paragraph 2.5 should minimally include:

  • clear accountability for AI oversight, for example a designated member of senior management;
  • permitted and prohibited uses of AI, such as a ban on inputting confidential, proprietary or client information into public AI tools, with the circumstances in which human review of outputs is mandatory;
  • an approved list of AI tools and a process for requesting approval of new ones;
  • staff education on the FI’s AI policies;
  • regular compliance checks; and
  • periodic and trigger-based review of whether the FI’s AI use still meets the paragraph 2.3 criteria.

This test replaced the consultation approach. The November 2025 paper applied the full expectations where AI was an “integrated” part of business processes, meaning its unavailability would disrupt workflows the FI materially depends on, or it was integrated with systems the FI materially depends on. A few respondents objected that this would capture firms using only low-risk productivity tools, and some disputed the consultation annex treating an internal IT helpdesk chatbot as integrated use (response paragraphs 3.3 and 3.4). MAS agreed and moved to the material adverse impact test (response paragraphs 3.6 and 3.7).

Review frequency for the basic set is the FI’s call. MAS encourages at least an annual review as good practice and expects a review that finds nothing to change to be documented (response paragraph 3.16(c)).

My reading is that the test applies to the AI services or tools the FI uses taken together. One use case that could cause a material adverse impact moves the FI to the full Sections 3 to 6 framework (response paragraph 3.7), which is then scaled by proportionality within it (paragraph 3.9). FIs unsure where they fall may engage MAS bilaterally on the application of Section 2 (response paragraph 3.8).

A documentation map for the full framework

For an FI outside the basic route, each core record can be tied to a paragraph, to an owner where the text names one, and to the date its section applies. Where the Guidelines name no owning function, the table says so.

Artifact Paragraph Owner named in the text Expected by
Overall AI governance approach, strategic direction, key frameworks and policies 3.4(a) Board or a committee it delegates 7 Oct 2027
AI risks in the risk appetite framework (qualitative and quantitative) 3.4(b) Board or delegated committee 7 Oct 2027
Escalation process for AI incidents and risk threshold breaches 3.5(e) Senior management 7 Oct 2027
AI identification process and record of its outcomes 4.2, 4.3 Designated control function, final arbiter on what is AI 7 Oct 2027
AI inventory and its maintenance policy 4.5 to 4.9 Designated control function sets policy; business units may maintain 7 Oct 2027
Risk materiality methodology and assessment per use case 4.10 to 4.13 Designated control function, arbiter or approver of ratings 7 Oct 2027
Contingency plan with fallback options (high risk use cases only) 5.3 No function named As soon as possible, and by 7 Oct 2028
Development documentation for reproducibility and audit 5.17 No function named; depth scales with materiality 7 Oct 2028
Pre-deployment review findings 5.21 Reviewers report to the relevant approval body 7 Oct 2028
Monitoring records, incidents and remediation 5.23(c), (d) Appropriate accountable person designated by the FI 7 Oct 2028

The split between board and management approvals matters for the governance calendar. Response paragraph 4.8 limits the board’s approval duty to the documents that set the overall governance approach, which could cover areas such as the definition and scope of AI, the oversight structures, and the overarching tone and guiding principles. Operational or technical documents, such as the risk materiality methodology or how lifecycle controls are applied, may be approved by senior management or relevant committees.

Board and senior management: oversight without a dedicated AI committee

Paragraph 3.4 gives the board, or a committee it delegates, five responsibilities: approving and reviewing the overall governance approach and strategic direction for AI use; addressing AI risks explicitly in the risk appetite framework; setting board and senior management roles; having an adequate understanding of AI to provide effective challenge; and keeping the approach under review as AI and the FI’s business change. Strategic direction was added after consultation (response paragraph 4.10(c)).

Footnote 18 gives the risk appetite examples. A qualitative statement can set the types and level of AI risk the FI accepts, or prohibited use categories. Quantitative measures could cover the number or financial impact of AI-related incidents, the number of material AI use cases dependent on a single provider, or the number of material use cases in breach of performance thresholds. Each of those measures needs a data source, which is the reporting team’s part of the build.

Response paragraph 4.10(a) sets the board’s bar at enough understanding of the FI’s AI risks to challenge senior management’s assessments, the adequacy of the control environment and the fit with risk appetite. Hands-on technical expertise at a granular level is not expected, and advice from internal or external experts does not replace the board’s own judgement.

Senior management’s list in paragraph 3.5 runs to seven items. It includes implementing the framework consistently with risk appetite, setting roles across business lines and control functions, establishing an internal escalation process for material AI risks and exceptions such as AI incidents or threshold breaches, updating the board on material AI risk issues in a timely manner, and resourcing competent staff.

The headline clarification is structural. FIs need not establish a dedicated AI committee solely to meet the oversight expectation; existing governance structures may be used where they give adequate oversight and cross-functional coordination (media release; paragraph 3.3). The consultation had proposed a dedicated cross-functional committee where an FI’s overall AI risk exposure was material (response paragraph 5.1). What survives is the outcome: response paragraph 5.3 still expects a consolidated view of AI risks across the organisation, managed consistently, and an FI able to demonstrate how its chosen structure achieves that.

Who approves individual high materiality use cases is left to the FI, board or senior management, given the operational nature of those decisions (response paragraph 4.10(c)). Footnote 19 offers the three lines of defence as an optional reference, with internal audit as the third line giving independent assurance on the framework.

Identification and inventory: the records MAS expects to exist

Paragraph 4.2 expects systems, policies and procedures that identify AI use consistently across all relevant business and functional areas. Where AI is incorporated within or used to deliver third-party services, identification should minimally cover AI in services from material third-party service providers. Response paragraph 6.6 explains the floor: an FI should endeavour to identify all embedded AI, MAS recognises it may face challenges in doing so, and the minimum is set at material providers.

A designated control function is responsible for the identification systems and processes (paragraph 4.3). Business units may do the identifying, but the control function keeps independent oversight, acts as final arbiter on whether a given use is AI, and maintains documentation of the process and its outcomes.

The tooling scales with the estate. An FI with few AI use cases may rely on manual processes in which staff identify and attest to their AI use, and an FI with many may need more sophisticated systems (response paragraph 6.10). Automated surveillance for shadow AI is the FI’s decision (paragraph 6.11). The consultation had asked control functions to set up attestation processes; the final text sets the outcomes and leaves the mechanism open (response paragraph 8.8).

What cannot be identified still has to be managed. Paragraph 4.4 expects residual risk from unidentified AI to stay within risk appetite, with mitigating measures where constraints exist. Footnote 22 gives examples: staff guidance on allowed and disallowed uses, including embedded features and public AI tools, and technical controls such as network monitoring and data loss prevention.

The inventory itself (paragraphs 4.5 to 4.9) should be accurate “to the extent possible or practicable”, with policies setting how often it is updated for new, changed or decommissioned AI. An FI can extend an existing inventory or build a dedicated one. Paragraph 4.7 lists attributes it may include:

  • purpose and description, and approved scope of use (for example jurisdiction);
  • model type, data used and dependencies;
  • lifecycle status, assigned risk materiality rating and model review status;
  • key roles such as owners and developers; and
  • links to essential documentation.

For AI agents, footnote 25 adds agent-specific identifiers, the tools and systems the agent can access, its components and its guardrails. Response paragraph 6.15 ties granularity to the nature and materiality of the use: an FI using AI mainly for assistive, low-risk tasks may not need agent-level attributes at all.

The linkage requirement is the operational detail that pays back. Paragraph 4.6 expects clear links between the AI inventory and other relevant inventories, and footnote 23 suggests consistent data asset identifiers and consistent vendor or service identifiers linking to third-party or outsourcing registers. Response paragraph 6.21 confirms MAS does not expect links to every inventory. A shared vendor identifier is also what lets an FI count material AI use cases that depend on a single provider, one of the footnote 18 risk appetite measures, and response paragraph 6.22 includes aggregate reliance for concentration risk assessment in the consolidated vendor view that such a link can support.

Scoring risk materiality per use case

Paragraphs 4.10 to 4.13 expect one methodology, applied consistently to every AI use case, rating both inherent risk materiality before controls and residual risk materiality after them. Residual risk materiality should meet the FI’s risk appetite before deployment. The assessment covers at least three dimensions:

  • Impact: consequences of failure, malfunction or poor performance for the FI and its customers or other stakeholders, including the nature and sensitivity of the data processed.
  • Complexity: the AI technology, the novelty of its application, its data and the explainability of its outputs, plus, for third-party AI, the FI’s visibility into the technology and data.
  • Reliance: how far the decision or output depends on AI, including autonomy, the degree of human involvement and dependence on third-party AI.

MAS published relative illustrations for each dimension in response paragraph 7.18:

Dimension Could be assessed higher Could be assessed lower
Impact AI for credit scoring, affecting customers’ access to and pricing of credit, possibly processing sensitive personal data Personal productivity, such as internal document summarisation
Complexity Third-party generative AI, where testing and explanation methods are still evolving and visibility into design or training data may be limited Regression-based models developed in-house with full visibility into design, training and data
Reliance Automated trade execution with limited human review, hard to reverse once executed AI recommending responses to consumer queries, with staff reviewing each recommendation

MAS states that these are comparisons and imply no absolute rating. It sets no formula for combining the dimensions and no universal threshold for “high” (response paragraph 7.19), and an FI may weight them, including approaches where one dimension dominates and others only matter under certain conditions.

The assessment is anchored to the use case, so the same model can carry two ratings. Response paragraph 7.6 gives the example of one model deployed in an automated way in one use case and with full human-in-the-loop oversight in another.

The trap is which rating drives the heavy controls. Response paragraph 7.21 states that requirements specific to high risk materiality use cases, including the more rigorous lifecycle controls, apply on inherent risk materiality. A methodology that rates a use case “medium” after controls has not taken it out of independent validation or contingency planning if its inherent rating was high.

Complexity is judged against the FI’s own understanding. An FI less familiar with a technology may reasonably assess it as more complex and apply more testing and review, then revise as familiarity grows (response paragraph 7.11). MAS removed the “availability of alternatives” from the Reliance dimension (paragraph 7.13) but kept contingency planning for high risk use cases (paragraph 7.14), and it suggested access to tools and systems as an extra dimension for agentic AI (paragraph 7.7).

Third-party and embedded AI: accountability stays with the FI

Paragraph 5.11 states the principle directly: the decision to onboard third-party AI is the FI’s, and the FI retains primary accountability for its use, including the impact on stakeholders and on its ability to comply with regulatory requirements. Where residual risk materiality cannot be brought within risk appetite, the FI should consider limiting or suspending the service or replacing the provider.

Paragraph 5.10 sets the controls. Contracts should give a risk-appropriate degree of visibility over the introduction of AI and later updates. Third-party AI should be tested in the context of the FI’s own use cases, using its own data where practicable, with compensatory testing where the provider discloses too little, and the FI should keep documentation of how it tested the AI and found it suitable.

The onboarding assessment in paragraph 5.11 covers eight areas: provider transparency, supply chain assessments, concentration risk, change management, contingency plans, legal agreements, staff capabilities and complexity. The legal agreements item asks how far the contract sets out clear expectations and responsibilities for the AI provider, and gives example clauses: performance guarantees, data protection, the right to audit, notification when AI is introduced or updated, and seeking the FI’s agreement before AI is incorporated.

Where a provider will not disclose enough, paragraph 5.11(a) allows the FI to review certifications or external assessments performed by independent and competent parties, and excludes self-attestations. Response paragraph 9.9 adds that provider statements that risks have been addressed, particularly without evidence, would generally not be an effective answer. Additional testing and closer human oversight remain available as compensating controls.

Vendor updates are handled proportionately. Response paragraph 9.14 asks for contractual visibility into changes that could reasonably be expected to affect the use case’s performance, behaviour or risk profile, and paragraph 9.13 accepts that an FI cannot always compel a provider to notify every update. For high materiality use cases where significant changes may happen without the FI’s prior review, paragraph 5.25(a) calls for compensating controls such as enhanced monitoring.

The outsourcing frame is moving at the same time. Response footnote 3 notes that MAS consulted on proposed Guidelines on Third-Party Risk Management on 6 March 2026, intended to supersede the Guidelines on Outsourcing once finalised. For the international reference point, see our note on the BCBS third-party risk principles.

Lifecycle controls and capability for October 2028

Section 5 covers data management, transparency and explainability, fairness, human oversight, third-party AI, selection, evaluation and testing, technology and cybersecurity, reproducibility and auditability, pre-deployment reviews, post-deployment monitoring, change management and decommissioning. Each is calibrated to risk materiality (paragraph 5.2). A handful of controls switch on at a defined trigger:

Control Paragraph Trigger
Contingency plan with fallback options, reviewed and tested 5.3 High risk use case
Contingency activation protocols, tested regularly 5.3 AI with a “kill switch”
Formal independent validation before deployment 5.19 High risk materiality
Other documented review, such as peer review by qualified people not involved in development or deployment (may be used) 5.20 Not high risk materiality
Consider kill switches or override mechanisms 5.23(b) High risk materiality
Regular re-validation by independent parties 5.24 High risk materiality

Paragraph 5.17 sets the documentation standard that validation and audit depend on (response paragraph 10.56 makes the link). It expects the development process to be documented, with extent and rigour commensurate with the use case’s risk materiality, in enough detail for a reviewer or auditor to understand and potentially replicate the implementation and its testing. That documentation may include information such as data sources, processing and quality checks; the selection rationale; training procedures including code versions, environments and hyperparameters; evaluation measures, thresholds and results; explainability and fairness analysis; and assumptions, limitations and mitigants.

For generative AI that bar was adjusted. Response paragraph 10.44 accepts that exact outputs of non-deterministic AI cannot be replicated, so documentation should enable replication of the evaluation and testing process. For third-party AI, that means the testing the FI ran on its own data and use cases.

Global groups can rely on group-level pre-deployment reviews where those reviews meet the Guidelines, with two conditions in response paragraph 10.59: high risk use cases still get formal independent validation, and the review and testing approach should address the Singapore context of use, including whether test datasets are representative locally. Where they are not, local review or testing fills the gap before deployment.

Section 6 extends the competence expectation to staff who use AI, beyond those who build and deploy it (response paragraph 11.4), and response paragraph 11.6 states that FIs should treat AI training and capacity building as supervisory expectations. Paragraph 6.3 asks for technology infrastructure adequate to the AI the FI runs, which MAS reads as principle-based and technology-neutral (response paragraph 11.11).

Agentic and generative AI: in scope of the Guidelines, agentic consultation planned for 2027

The Guidelines cover generative AI and AI agents from the effective date (paragraph 1.5). Paragraph 1.11 describes the agentic risk: an agent with tool access could execute unauthorised or erroneous actions when its interpretation of pre-defined goals diverges from the FI’s business objectives or a customer’s interests, and a compromised agent could exfiltrate data or execute malicious commands at scale.

Several lifecycle controls carry agent-specific detail. Monitoring under paragraph 5.23(a) should cover, where relevant, information flows and decision-making paths across AI workflows, including reasoning processes, actions taken and tools used. Paragraph 5.23(d) says enhanced documentation could be considered for generative AI or agents, such as logging prompts and model responses with model versions and reasoning processes. Testing of generative AI and agents should cover key failure modes and the effectiveness of guardrails (paragraph 5.15).

MAS chose not to set minimum controls or mandated testing techniques for generative or agentic AI at this time (response paragraph 12.7). For now it points to the Infocomm Media Development Authority’s Model AI Governance Framework for Agentic AI as a practical reference (footnote 11; response paragraph 12.9), and the media release says MAS intends to consult the sector in 2027 on what further agentic guidance would help.

AI incidents: internal escalation, no new report to MAS

Footnote 20 defines AI incidents as incidents that involve a failure, malfunction or poor performance of the underlying AI systems or models. The Guidelines then build an internal chain: senior management establishes an escalation process for AI incidents and risk threshold breaches (paragraph 3.5(e)), and post-deployment monitoring needs processes for reporting, tracking, escalating and resolving issues, plus user feedback channels (paragraph 5.23(b)).

The external side does not change. Response paragraph 10.69 asks each FI to establish its own processes to identify, manage and escalate AI incidents, including severity thresholds or classification frameworks where relevant, states that MAS does not intend to introduce AI-specific incident reporting requirements at this juncture, and says FIs should continue to comply with existing requirements on incident reporting to MAS, for example under technology risk management or business continuity management, irrespective of whether the root cause is AI-related. An AI-caused outage of a critical system therefore travels down the reporting route the FI already runs.

My working assumption for incident and reporting teams is that the AI tag becomes an internal classification field. It is what turns the incident log into the source for the footnote 18 risk appetite measure on the number or financial impact of AI-related incidents. MAS’s separate work with industry on AI-driven cyber risk is covered in our note on the MAS AI cyber taskforce.

What changed between the November 2025 consultation and the final text

Teams that started building against the consultation paper can check these seven points, each taken from the response paper. Paragraph references are to the response paper unless marked as Guidelines.

Topic Consultation (P017-2025) Final Guidelines (October 2026)
Proportionality trigger Full set where AI is an “integrated” part of business processes (paras 3.1, 3.2) Basic policies where poor performance or unavailability is unlikely to have a material adverse impact (Guidelines 2.3; response 3.7)
Oversight structure Dedicated cross-functional committee where overall AI risk exposure is material (para 5.1) Existing structures allowed; consolidated, coordinated view to be demonstrated (Guidelines 3.3; response 5.3)
Reliance dimension Included availability of alternatives (para 7.12) Removed; dependence on AI outputs, autonomy, human oversight, third-party reliance (response 7.13)
Control-function attestations Designated functions to set up attestation processes (para 8.1) Outcomes set; attestation is one option (response 8.8)
Data representativeness “The full range” of real-world conditions (para 10.7) “A range” of real-world conditions, risk-proportionate (Guidelines 5.4(b); response 10.7)
Reproducibility Documentation detailed enough for potential replication of the system and its results (para 10.42) Replication of the evaluation and testing process; exact outputs of non-deterministic AI excluded (response 10.44)
Transition 12 months after issue (para 13.1) 12 months for Sections 3 and 4; 24 months for Sections 5 and 6 (response 13.5)

Two additions point the other way. Board responsibility for strategic direction was added (response paragraph 4.10(c)), and the competence expectation now reaches staff who use AI (response paragraph 11.4).

Frequently Asked Questions

We are a Singapore branch and our AI inventory is held at group level. Can the group inventory serve as ours?

It can, with conditions. Response paragraph 8.4 lets an FI designate an existing function with group-level responsibilities for identification and inventory, provided the FI can demonstrate adequate oversight of AI used in Singapore, including that the inventory appropriately captures attributes of that AI. The test is whether the Singapore AI and its attributes can be shown from that inventory.

Our FI does not use AI today. Does anything apply on 7 October 2027?

Yes. Response paragraph 3.14 expects an FI that has not adopted AI to have basic AI-related policies that set out whether and how staff may use AI, to manage unauthorised “shadow AI” and to allow governance to scale up if adoption follows.

A vendor sent us an independent review of its model. Does that satisfy formal independent validation for a high risk use case?

Only if the FI can establish that the reviewer had the necessary expertise and was independent of the vendor’s development and deployment teams (response paragraph 10.58). Otherwise the review may count as a documented review under paragraph 5.20, the standard for use cases below high risk materiality. Either way the FI still tests the AI on its own data and documents that testing under paragraph 5.10, and where an existing review falls short of the validation expectations, the FI should commission or conduct its own.

Is every third-party AI provider now a material outsourcing arrangement?

No. Response paragraphs 9.19 to 9.21 separate the two: outsourcing materiality looks at the service provider relationship, while AI risk materiality is assessed per use case and also covers in-house AI. MAS does not treat the two assessments as duplicative, and providers of third-party AI are not automatically material outsourcing arrangements.

How often does the AI inventory have to be updated?

MAS will not prescribe a frequency, and a real-time inventory may not be necessary in all cases (response paragraph 6.18). The FI should consider more frequent updates for AI in material use cases or AI that changes often, and event triggers such as material changes to a use case or its systems, or a change in how many use cases rely on the same system or provider (paragraph 6.19).

Can a high risk use case run as a pilot before independent validation is finished?

No. Response paragraph 10.79 states that formal independent validation before deployment applies to high risk materiality use cases irrespective of whether they are pilots or partial deployments. Footnote 28 and response paragraph 10.78 cover the guardrails any pilot needs, such as time and user limits, success criteria and close monitoring of usage and outputs.

Do we have to file the inventory or an attestation with MAS by the effective date?

The Guidelines contain no submission or notification step. The recurring formula is that the FI “should be able to demonstrate” its approach to MAS, for example on local oversight (paragraph 3.6) and on the outcomes of identification and inventory processes (response paragraph 8.8). No filing date for any of these records appears in the Guidelines or the response paper.

Key Takeaways

  • Write down the paragraph 2.3 assessment before anything else; it decides whether the FI builds the paragraph 2.5 minimum set of basic policies or the full Sections 3 to 6 framework, and an FI on the basic route should review it periodically and on a trigger basis (paragraph 2.5(f)).
  • Book the board approval for the governance approach, AI scope definition and risk appetite before 7 October 2027, and route the materiality methodology through senior management or a committee.
  • Rate every use case on inherent risk materiality first; that rating, whatever the residual result, sets the validation and contingency workload.
  • Give the AI inventory and the third-party register a common vendor identifier so single-provider dependence can be counted.
  • When reviewing material technology contracts, compare them with the example clauses in paragraph 5.11(f): notice when AI is introduced or updated, audit rights, and the FI’s agreement before AI is incorporated.
  • Keep incident reporting to MAS on its existing channels and add an AI root-cause field to the internal log.
  • If agents are in the build plan, diary the consultation on agentic AI guidance that MAS intends to hold in 2027.

Sources and References

  • MAS media release, “MAS Sets Out Supervisory Expectations on Responsible AI Adoption by Financial Institutions” (7 October 2026): mas.gov.sg
  • MAS, Guidelines on Artificial Intelligence Risk Management for Financial Institutions, landing page: mas.gov.sg
  • MAS, Guidelines on Artificial Intelligence Risk Management (7 October 2026, PDF): mas.gov.sg
  • MAS, Response to Feedback Received on Guidelines on Artificial Intelligence Risk Management, P017-2025 (7 October 2026, PDF): mas.gov.sg
  • MAS, Consultation Paper on Proposed Guidelines on Artificial Intelligence Risk Management for Financial Institutions, P017-2025 (13 November 2025), consultation page: mas.gov.sg
  • MAS, Consultation Paper P017-2025 (PDF): mas.gov.sg
  • MAS, Supervisory Approach and Regulatory Instruments (legal effect of guidelines): mas.gov.sg
  • MAS, Principles to Promote Fairness, Ethics, Accountability and Transparency (FEAT) in the Use of Artificial Intelligence and Data Analytics in Singapore’s Financial Sector (12 November 2018): mas.gov.sg
  • MAS, Guidelines on Risk Management Practices for Technology Risk (18 January 2021): mas.gov.sg
  • Infocomm Media Development Authority, Model AI Governance Framework for Agentic AI (PDF): imda.gov.sg
  • Regulation (EU) 2024/1689 (Artificial Intelligence Act): EUR-Lex

The October 2027 file for MAS AI oversight

The next operative date is 7 October 2027, when Sections 3 and 4 apply. The record the rest of the framework hangs from is the AI inventory with an inherent and a residual materiality rating on every use case, including the embedded AI found in services from material providers. The lifecycle controls due by 7 October 2028 are scoped from that inventory, and for use cases rated high risk the response paper expects them applied as soon as possible.

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts

  • Standing Liquidity Facility: OSFI and BoC Call Overnight Draws Routine

    On 29 September 2026 the Bank of Canada and the Office of the Superintendent of Financial Institutions (OSFI) issued a joint statement on the Bank’s Standing Liquidity Facility (SLF), the facility that gives participants in Lynx, Canada’s high-value payment system, secured liquidity both intraday and overnight. Its operative sentence is short: overnight SLF draws “are…

  • MAS Corporate Governance Consultation: Tiered Boards and Approvals

    On 30 September 2026 the Monetary Authority of Singapore (MAS) published consultation paper P016-2026, which proposes amendments to the corporate governance regulations for banks, insurers and designated financial holding companies (DFHCs). The MAS corporate governance consultation runs until 11:59 pm on 9 December 2026, and comments go in through a FormSG link. Five instruments are…

  • Japan FSA Deposit-Taking Monitoring Report 2026: Supervisory Signals

    Japan’s Financial Services Agency published its Report on the Monitoring and Analysis of Deposit-Taking Financial Institutions on 31 July 2026. It sets out where the FSA spent its prudential supervision effort across Business Year (BY) 2025, the window from July 2025 to June 2026, and it identifies seven areas covered in the report without ranking…

  • Hong Kong Taxonomy Phase 2A: Transition and Adaptation Added

    Hong Kong Taxonomy Phase 2A, published by the Hong Kong Monetary Authority on 22 January 2026, expanded the HKMA’s voluntary framework for classifying economic activities as green, transition-aligned or adaptation-aligned. The classification that Phase 1 introduced in May 2024 covered 12 economic activities across four sectors and dealt only with climate change mitigation. Phase 2A…

  • FCA Asset Management Reform: The £128m Rulebook Package

    On 14 July 2026 the Financial Conduct Authority opened three linked consultations that together make up its asset management reform package, a set of proposals the regulator estimates would save UK asset managers around £128m a year. The three papers cover fund reporting, the alternative investment fund manager regime, and the remuneration rules that apply…

  • CSSF Incident Handling Guidance: NIS2 Rulebooks and the DORA Clock

    On 28 September 2026 the CSSF published press release 26/19 announcing operational guidance for incident handling: nine rulebooks written jointly by cybersecurity experts from the High Commission for National Protection (HCPN, acting as ANSSI and as GOVCERT.LU), CIRCL, the CSSF and the ILR. The practical question for Luxembourg DORA entities is whether the CSSF incident…