Skip to main content

Singapore finalises AI risk guidelines for financial institutions

The framework will take effect in phases in 2027 and 2028, with institutions remaining accountable for AI supplied by external providers.

By Arif Rahman

Illustration of an AI network alongside financial data on a computer screen
Photo: Fintech News Network

The Monetary Authority of Singapore (MAS) has finalised guidelines setting expectations for how financial institutions manage AI risks throughout a system’s lifecycle, including those arising from external providers. The framework follows a November 2025 public consultation.

The implementation timetable sets 7 October 2027 as the effective date for Sections 3 and 4. Sections 5 and 6 take effect on 7 October 2028. Institutions can adapt their approach to the scale of their AI use and its risk profile, and may rely on existing governance arrangements rather than creating separate AI committees.

MAS expects firms to keep an inventory of how they use AI. Controls should address data governance and cybersecurity, alongside testing, human oversight, monitoring and the management of changes.

Accountability remains with institutions when AI forms part of their services, even if an outside provider develops, operates or supplies the system. Firms should seek adequate assurance from providers, check suitability for the intended purpose and introduce compensating controls where assurance is insufficient or practical constraints arise.

MAS said institutions should consider restricting, suspending or replacing an external AI service if its risks cannot be reduced to fit their risk appetite.

The regulator also noted increasing use of agentic AI, which can act autonomously and access tools. It plans to consult the financial sector in 2027 about useful additional guidance. MAS Deputy Managing Director Ho Hern Shin said managing risks from increasingly capable systems was necessary to realise AI’s benefits sustainably.

Latest in Technology

All latest