The Monetary Authority of Singapore (MAS) has issued new Guidelines on Artificial Intelligence (AI) Risk Management, setting clear supervisory expectations for financial institutions (FIs) to govern and manage the risks associated with AI adoption.
“AI has significant potential to improve financial services, from enhancing customer outcomes and strengthening risk management to improving productivity and enabling new products and services,” said Ho Hern Shin, Deputy Managing Director for Financial Supervision at MAS. “Realising these benefits sustainably requires financial institutions to understand and manage the risks that come with increasingly capable AI systems. With greater regulatory clarity on financial institutions’ AI usage, FIs can innovate with confidence, while maintaining the trust of customers and the resilience of Singapore's financial system.”
The Guidelines emphasize that FIs should secure the skilled staff and technology infrastructure needed to operate AI safely while maintaining appropriate human oversight. Boards and senior management are expected to provide effective oversight of AI risks, including setting a clear risk appetite, establishing management frameworks, and defining clear roles and responsibilities. FIs may leverage existing governance structures without a dedicated AI committee, provided that these structures offer adequate oversight and cross-functional coordination, and that senior management remains explicitly responsible for establishing internal escalation processes for material risks and AI incidents.
The Guidelines establish that FIs retain primary accountability for any AI used in the services they deliver, including systems developed, operated, or provided by third parties. FIs are expected to obtain sufficient assurance from third-party providers and assess whether the AI is suitable for its intended use. If transparency or assurance gaps arise, FIs are expected to put in place appropriate mitigants, which may include additional testing or greater human oversight. Ultimately, if the risks of a third-party AI service cannot be brought within the FI’s risk appetite, the institution should consider limiting or suspending the service, or replacing the provider.
MAS expects FIs to maintain an accurate inventory of their AI use cases and conduct risk materiality assessments based on factors such as potential impact, complexity, and the FI’s level of reliance on the AI. The Guidelines expect controls to be applied in a risk-proportionate manner. For low-risk administrative tasks, basic AI governance policies like restricting the input of confidential client information may suffice. For high-risk areas with potential high impact on customer outcomes such as credit decisioning or insurance underwriting, FIs should implement more robust controls to identify and mitigate harmful biases, discriminatory outcomes, and unfair access to financial services.
FIs may implement the Guidelines in two phases. By October 7, 2027, they should meet expectations for board and senior management oversight and establish AI risk management systems, policies, and procedures, including AI identification and inventory management. By October 7, 2028, FIs should establish adequate AI capabilities and capacity and meet expectations for AI life cycle controls, including data management, testing, and human oversight.
Join The Discussion
Sign in and be the first to comment.