DORA vs MAS AI Guidelines: what they share and how they differ

DORA and MAS AI Guidelines share 7 of 24 control themes and 6 checks. 45% of MAS AI Guidelines requirements can be proven with checks DORA already uses, 83% the other way round.

EURegulationIn force

DORA

How to cover AI systems in your DORA compliance

6 requirementsNext —
SGSupervisory guidelinesUnder discussion

MAS AI Guidelines

Preparing for the MAS AI risk management guidelines

11 requirementsNext Dec 2026
7/24shared control themes
6shared checks
45%of MAS AI Guidelines requirements covered by DORA evidence
83%of DORA requirements covered by MAS AI Guidelines evidence

At a glance

DORA MAS AI Guidelines
JurisdictionEuropean UnionSingapore
KindRegulationSupervisory guidelines
StatusIn forceUnder discussion
BindingYesNo
Object analysedOrganisationAI system
ScopeFinancial entities and critical ICT third-party providers.All financial institutions supervised by MAS (banks, insurers, asset managers, intermediaries).
Territorial reachEuropean Union.Financial activities in Singapore, including branches of foreign groups.
PenaltiesSet by member states; up to 1% of average daily worldwide turnover as periodic penalty for critical providers.No penalty of their own. Once issued, they are supervisory expectations checked in inspections; shortcomings can lead to supervisory action.
Qualification axesSupports a critical or important functionUse-case risk materiality (impact, complexity, reliance)
RolesFinancial entity, ICT providerFinancial institution
Requirements611
Next milestone—Dec 2026, Expected issuance of the final guidelines

Theme by theme

requirements per theme

What they share: one piece of evidence, two frameworks

6

CodeCheckRequirements DORARequirements MAS AI Guidelines
CHK-POL-RISKAn AI risk-management policy and process are established through transparent, documented controls
CHK-EXEC-ACCOUNTExecutive leadership is accountable for AI risk decisions (board committee, risk appetite)
CHK-INVENTORYA mechanism to inventory AI systems is in place and resourced
VER-009-F-04Resilience to adversarial attacks tested
CHK-THIRDPARTY-POLPolicies address third-party AI/data risks, incl. IP, transparency and testing
VER-AUTO-01Suspension procedure in the event of risk

Differences: requirements specific to each framework

Requirements with no check serving the other framework: the extra work.

Timelines

PastSet in the textPotentialTo verify
Nov 12, 2018MAS AI Guidelines · FEAT principles (fairness, ethics, accountability, transparency)
Jan 16, 2023DORA · Entry into force
Dec 2024MAS AI Guidelines · Information paper on AI model risk management
Jan 17, 2025DORA · Application date
Apr 30, 2025DORA · First register of information submitted
Nov 13, 2025MAS AI Guidelines · Public consultation on the guidelines
Nov 18, 2025DORA · First critical ICT providers designated
Jan 31, 2026MAS AI Guidelines · Consultation closes
Dec 2026MAS AI Guidelines · Expected issuance of the final guidelines
Dec 2027MAS AI Guidelines · End of the 12-month transition (if issued late 2026)

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo