NIST AI RMF vs MAS AI Guidelines: what they share and how they differ

NIST AI RMF and MAS AI Guidelines share 13 of 24 control themes and 16 checks. 73% of MAS AI Guidelines requirements can be proven with checks NIST AI RMF already uses, 39% the other way round.

USVoluntary frameworkVoluntary

NIST AI RMF

How to apply the NIST AI RMF to your AI systems

72 requirementsNext Dec 2026
SGSupervisory guidelinesUnder discussion

MAS AI Guidelines

Preparing for the MAS AI risk management guidelines

11 requirementsNext Dec 2026
13/24shared control themes
16shared checks
73%of MAS AI Guidelines requirements covered by NIST AI RMF evidence
39%of NIST AI RMF requirements covered by MAS AI Guidelines evidence

At a glance

NIST AI RMF MAS AI Guidelines
JurisdictionUnited States (federal)Singapore
KindVoluntary frameworkSupervisory guidelines
StatusVoluntaryUnder discussion
BindingNo sameNo same
Object analysedAI system sameAI system same
ScopeAny organisation designing, deploying or using AI.All financial institutions supervised by MAS (banks, insurers, asset managers, intermediaries).
Territorial reachNo territorial scope; de facto reference for US public buyers.Financial activities in Singapore, including branches of foreign groups.
PenaltiesNone (voluntary). Leverage: safe harbour in state laws.No penalty of their own. Once issued, they are supervisory expectations checked in inspections; shortcomings can lead to supervisory action.
Qualification axesInternal risk tier (organisation-defined)Use-case risk materiality (impact, complexity, reliance)
RolesAI actorFinancial institution
Requirements7211
Next milestoneDec 2026, Expected RMF revisionDec 2026, Expected issuance of the final guidelines

Theme by theme

requirements per theme

What they share: one piece of evidence, two frameworks

16

CodeCheckRequirements NIST AI RMFRequirements MAS AI Guidelines
CHK-POL-RISKAn AI risk-management policy and process are established through transparent, documented controls
CHK-RISK-TOLERANCERisk tolerances are defined and AI systems are assigned to risk levels
CHK-ROLES-CLARIFIEDRoles, responsibilities and delegated authorities are documented and clear to relevant stakeholders
CHK-INVENTORYA mechanism to inventory AI systems is in place and resourced
CHK-TRAININGPersonnel and partners receive AI risk-management training
CHK-EXEC-ACCOUNTExecutive leadership is accountable for AI risk decisions (board committee, risk appetite)
VER-008-03Competent overseers assigned to the system
CHK-THIRDPARTY-POLPolicies address third-party AI/data risks, incl. IP, transparency and testing
CHK-CATEGORIZATIONAI system tasks and methods are categorized (classifier, generative, recommender)
CHK-TEVVTEVV plan, test sets, metrics and data considerations are documented
CHK-COMPETENCEOperator/practitioner proficiency processes and relevant standards are defined
CHK-INDEP-ASSESSIndependent or internal-expert assessment involves domain experts and affected communities
CHK-BIASFairness and bias are evaluated and results documented
VER-003-01Documented and up-to-date risk register
VER-008-02System designed to allow human oversight (stop button, override)
CHK-MODEL-MONITORINGPre-trained models used in development are monitored and maintained

Differences: requirements specific to each framework

Requirements with no check serving the other framework: the extra work.

NIST AI RMF

44

Timelines

PastSet in the textPotentialTo verify
Nov 12, 2018MAS AI Guidelines · FEAT principles (fairness, ethics, accountability, transparency)
Jan 26, 2023NIST AI RMF · AI RMF 1.0
Jul 26, 2024NIST AI RMF · Generative AI Profile (NIST AI 600-1)
Dec 2024MAS AI Guidelines · Information paper on AI model risk management
Jul 23, 2025NIST AI RMF · AI Action Plan asks for a revision of the framework
Nov 13, 2025MAS AI Guidelines · Public consultation on the guidelines
Jan 31, 2026MAS AI Guidelines · Consultation closes
Dec 2026NIST AI RMF · Expected RMF revision
Dec 2026MAS AI Guidelines · Expected issuance of the final guidelines
Dec 2027MAS AI Guidelines · End of the 12-month transition (if issued late 2026)

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo