MAS AI Guidelines vs ISO 42001: what they share and how they differ

MAS AI Guidelines and ISO 42001 share 12 of 24 control themes and 10 checks. 54% of ISO 42001 requirements can be proven with checks MAS AI Guidelines already uses, 73% the other way round.

SGSupervisory guidelinesUnder discussion

MAS AI Guidelines

Preparing for the MAS AI risk management guidelines

11 requirementsNext Dec 2026
INTLCertifiable standardVoluntary

ISO 42001

How to prepare for ISO/IEC 42001 certification

13 requirementsNext Dec 2026
12/24shared control themes
10shared checks
54%of ISO 42001 requirements covered by MAS AI Guidelines evidence
73%of MAS AI Guidelines requirements covered by ISO 42001 evidence

At a glance

MAS AI Guidelines ISO 42001
JurisdictionSingaporeInternational
KindSupervisory guidelinesCertifiable standard
StatusUnder discussionVoluntary
BindingNo sameNo same
Object analysedAI systemOrganisation
ScopeAll financial institutions supervised by MAS (banks, insurers, asset managers, intermediaries).Organisations providing or using AI systems.
Territorial reachFinancial activities in Singapore, including branches of foreign groups.International.
PenaltiesNo penalty of their own. Once issued, they are supervisory expectations checked in inspections; shortcomings can lead to supervisory action.None; certification lost or refused.
Qualification axesUse-case risk materiality (impact, complexity, reliance)System impact level (Cl. 6.1.4)
RolesFinancial institutionProvider, User, Producer
Requirements1113
Next milestoneDec 2026, Expected issuance of the final guidelinesDec 2026, CEN-CENELEC JTC 21 harmonised standards for the AI Act (prEN 18286 QMS)

Theme by theme

requirements per theme

What they share: one piece of evidence, two frameworks

10

CodeCheckRequirements MAS AI GuidelinesRequirements ISO 42001
CHK-EXEC-ACCOUNTExecutive leadership is accountable for AI risk decisions (board committee, risk appetite)
CHK-POL-RISKAn AI risk-management policy and process are established through transparent, documented controls
CHK-ROLES-CLARIFIEDRoles, responsibilities and delegated authorities are documented and clear to relevant stakeholders
VER-003-01Documented and up-to-date risk register
VER-004-01Documented data governance (collection process, bias, quality)
VER-008-03Competent overseers assigned to the system
CHK-TEVVTEVV plan, test sets, metrics and data considerations are documented
VER-005-01Complete technical documentation compliant with Annex IV
CHK-THIRDPARTY-POLPolicies address third-party AI/data risks, incl. IP, transparency and testing
CHK-TRAININGPersonnel and partners receive AI risk-management training

Differences: requirements specific to each framework

Requirements with no check serving the other framework: the extra work.

Timelines

PastSet in the textPotentialTo verify
Nov 12, 2018MAS AI Guidelines · FEAT principles (fairness, ethics, accountability, transparency)
Dec 18, 2023ISO 42001 · ISO/IEC 42001 published
Dec 2024MAS AI Guidelines · Information paper on AI model risk management
May 2025ISO 42001 · ISO/IEC 42005 (impact assessment)
Jul 2025ISO 42001 · ISO/IEC 42006 (certification bodies)
Nov 13, 2025MAS AI Guidelines · Public consultation on the guidelines
Jan 31, 2026MAS AI Guidelines · Consultation closes
Dec 2026MAS AI Guidelines · Expected issuance of the final guidelines
Dec 2026ISO 42001 · CEN-CENELEC JTC 21 harmonised standards for the AI Act (prEN 18286 QMS)
Dec 2027MAS AI Guidelines · End of the 12-month transition (if issued late 2026)

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo