DORA vs MAS AI Guidelines: what they share and how they differ
DORA and MAS AI Guidelines share 7 of 24 control themes and 6 checks. 45% of MAS AI Guidelines requirements can be proven with checks DORA already uses, 83% the other way round.
In force
DORA
How to cover AI systems in your DORA compliance
6 requirementsNext —
Under discussion
MAS AI Guidelines
Preparing for the MAS AI risk management guidelines
11 requirementsNext Dec 2026
7/24shared control themes
6shared checks
45%of MAS AI Guidelines requirements covered by DORA evidence
83%of DORA requirements covered by MAS AI Guidelines evidence
At a glance
| DORA | MAS AI Guidelines | |
|---|---|---|
| Jurisdiction | European Union | Singapore |
| Kind | Regulation | Supervisory guidelines |
| Status | In force | Under discussion |
| Binding | Yes | No |
| Object analysed | Organisation | AI system |
| Scope | Financial entities and critical ICT third-party providers. | All financial institutions supervised by MAS (banks, insurers, asset managers, intermediaries). |
| Territorial reach | European Union. | Financial activities in Singapore, including branches of foreign groups. |
| Penalties | Set by member states; up to 1% of average daily worldwide turnover as periodic penalty for critical providers. | No penalty of their own. Once issued, they are supervisory expectations checked in inspections; shortcomings can lead to supervisory action. |
| Qualification axes | Supports a critical or important function | Use-case risk materiality (impact, complexity, reliance) |
| Roles | Financial entity, ICT provider | Financial institution |
| Requirements | 6 | 11 |
| Next milestone | — | Dec 2026, Expected issuance of the final guidelines |
Theme by theme
requirements per theme
DORAMAS AI Guidelines
Governance
Assessment
Build
People & use
Lifecycle & third parties
What they share: one piece of evidence, two frameworks
6
| Code | Check | Requirements DORA | Requirements MAS AI Guidelines |
|---|---|---|---|
| CHK-POL-RISK | An AI risk-management policy and process are established through transparent, documented controls | ||
| CHK-EXEC-ACCOUNT | Executive leadership is accountable for AI risk decisions (board committee, risk appetite) | ||
| CHK-INVENTORY | A mechanism to inventory AI systems is in place and resourced | ||
| VER-009-F-04 | Resilience to adversarial attacks tested | ||
| CHK-THIRDPARTY-POL | Policies address third-party AI/data risks, incl. IP, transparency and testing | ||
| VER-AUTO-01 | Suspension procedure in the event of risk |
Differences: requirements specific to each framework
Requirements with no check serving the other framework: the extra work.
DORA
1
DORA-17
MAS AI Guidelines
6
MAS-5.2
MAS-6.1
MAS-6.2
MAS-6.5
Reproducibility and auditability Lifecycle
MAS-7
Skills and capacity suited to the AI uses Capabilities
Timelines
PastSet in the textPotentialTo verify
Nov 12, 2018MAS AI Guidelines · FEAT principles (fairness, ethics, accountability, transparency)
Jan 16, 2023DORA · Entry into force
Dec 2024MAS AI Guidelines · Information paper on AI model risk management
Jan 17, 2025DORA · Application date
Apr 30, 2025DORA · First register of information submitted
Nov 13, 2025MAS AI Guidelines · Public consultation on the guidelines
Nov 18, 2025DORA · First critical ICT providers designated
Jan 31, 2026MAS AI Guidelines · Consultation closes
Dec 2026MAS AI Guidelines · Expected issuance of the final guidelines
Dec 2027MAS AI Guidelines · End of the 12-month transition (if issued late 2026)
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.