Live Updates

MAS Sets Out Supervisory Expectations on Responsible AI Adoption by Financial Institutions

AI Analysis

MAS issued Guidelines on Artificial Intelligence Risk Management on 7 October 2026, establishing supervisory expectations for every Singapore financial institution and all forms of AI, including generative and increasingly autonomous or agentic systems. The framework is principles-based and risk-proportionate, but creates broad expectations for board and senior-management accountability, AI inventories, lifecycle controls, third-party assurance and risk-based remediation, with initial implementation required from 7 October 2027 and later sections by 7 October 2028.

Key dates

2026-10-07
MAS issued the Guidelines on Artificial Intelligence Risk Management following its November 2025 consultation.
2027-10-07 Deadline
The Guidelines take effect. FIs should meet the expectations in Sections 3 and 4 from this date.
2027-10-07
MAS intends to consult the financial sector during 2027 on what additional guidance on agentic AI would be useful.
2028-10-07 Deadline
FIs should meet the expectations in Sections 5 and 6 by this date under the phased implementation timetable.

Suggested considerations

  • FIs should establish or update an enterprise inventory of AI systems, models, embedded AI functionality and third-party AI services, using a level of granularity appropriate to their risk profile.
  • Compliance and risk teams may wish to classify individual AI use cases by materiality, including potential effects on customers, prudential soundness, operational resilience, other financial institutions and the wider financial system.
  • Boards and senior management should consider documenting AI risk appetite, ownership, escalation routes and the allocation of responsibilities across business, risk, compliance, technology, cybersecurity, data and model-governance functions.
  • FIs should map existing AI controls across the lifecycle, including data governance, development and validation, testing, human oversight, cybersecurity, monitoring, incident management and change management, and identify gaps against the Guidelines.
  • Procurement, outsourcing and third-party-risk functions should consider adding AI-specific due diligence, assurance, contractual rights, performance monitoring, incident notification and exit or substitution arrangements for external AI providers.
  • FIs should assess whether existing governance committees and risk frameworks provide sufficient cross-functional oversight, rather than assuming that a new dedicated AI committee is necessary.
  • FIs may wish to define evidence that supports proportionality decisions, including why basic policies and procedures are adequate for lower-materiality AI use cases.
  • Implementation planning should distinguish the expectations in Sections 3 and 4, which should be met from 7 October 2027, from Sections 5 and 6, which should be met by 7 October 2028.

What changed

The Guidelines introduce an enterprise- and use-case-level framework for managing AI risk. Boards and senior management are expected to oversee AI risk, define accountabilities, set risk appetite, and maintain suitable risk-management frameworks, policies and procedures; existing governance structures may be used and a dedicated AI committee is not required solely for compliance. FIs are expected to identify their AI use, maintain inventories at an appropriate level of granularity, assess use-case materiality, and apply proportionate lifecycle controls covering data governance, testing, human oversight, cybersecurity, monitoring and change management. FIs remain accountable for AI used in services they deliver even where the AI is developed, operated or supplied by a third party; they shou

Compliance impact

The Guidelines are supervisory guidance rather than a stated new statute or prescriptive rule, but they apply across the regulated financial sector and create concrete expectations that MAS may use in supervisory assessments of governance, operational resilience, outsourcing, cybersecurity and model risk. Failure to identify material AI use, maintain effective oversight or control third-party AI c

Who is affected

  • All Singapore-regulated financial institutions
  • Singapore-incorporated and Singapore-licensed banks
  • Insurers and reinsurers regulated by MAS
  • Capital markets intermediaries and payment service providers regulated by MAS
  • MAS Guidelines on Technology Risk Management
  • MAS Guidelines on Outsourcing
  • MAS Guidelines on Business Continuity Management
  • MAS Guidelines on Individual Accountability and Conduct
  • MAS Information Paper on Artificial Intelligence Model Risk Management
  • FEAT Principles for Fairness, Ethics, Accountability and Transparency in the Use of Artificial Intelligence and Data Analytics in Singapore's Financial Sector

AI-generated analysis. May contain errors or omissions — verify with the original MAS source before acting. Full disclaimer.

What the MAS said

The Monetary Authority of Singapore today issued a set of Guidelines on Artificial Intelligence Risk Management to support responsible AI adoption in Singapore’s financial sector.

Published by MAS . Read the full notice at the source for the authoritative text.

Relevant Firm Types

BankInsuranceBroker DealerAll Firms
View Original on MAS Back to Feed

Share this update