SGSingaporeUnder discussionMAS AI Guidelines

Preparing for the MAS AI risk management guidelines

Singapore MAS Guidelines on Artificial Intelligence Risk Management

Status
Under discussion
Binding
No
Object analysed
AI system
Requirements
11
Next milestone
Dec 2026

In short

Monetary Authority of Singapore expectations for all financial institutions: board and senior management oversight, AI use inventory, risk materiality assessment, lifecycle controls, capabilities. Covers generative AI and agents, proportionately. Extends the FEAT principles (2018).

Steps to compliance

  1. Qualify each AI systemAxes to decide: Use-case risk materiality (impact, complexity, reliance).
  2. Determine your roleDuties vary by role: Financial institution.
  3. Apply the 11 requirementsThey focus on: Risk management, Governance & accountability, Inventory & categorisation and Data governance.
  4. Prove it with checks25 checks to document, 24 of which also serve NIST AI RMF, AI Act and ISO 42001.
  5. Track the deadlinesNext milestone: Dec 2026, Expected issuance of the final guidelines (potential).

Scope and penalties

Kind
Supervisory guidelines
Scope
All financial institutions supervised by MAS (banks, insurers, asset managers, intermediaries).
Territorial reach
Financial activities in Singapore, including branches of foreign groups.
Penalties
No penalty of their own. Once issued, they are supervisory expectations checked in inspections; shortcomings can lead to supervisory action.
Jurisdiction
Singapore

Timeline

Nov 12, 2018FEAT principles (fairness, ethics, accountability, transparency)
Dec 2024Information paper on AI model risk management
Nov 13, 2025Public consultation on the guidelines
Jan 31, 2026Consultation closes
Release
Dec 2026Expected issuance of the final guidelinesPotential
Dec 2027End of the 12-month transition (if issued late 2026)Potential
PastSet in the textPotentialTo verify

Qualifying a system

Classification axes and possible verdicts

Use-case risk materiality (impact, complexity, reliance)

High materialityMedium materialityLow materiality

Requirements

11 requirements

CodeArticleRequirementApplies toChecks
MAS-4OversightBoard and senior management oversight of AI risk management; framework, policies and roles
Financial institution
MAS-5.1IdentificationIdentify and inventory AI uses, including generative AI and third-party solutions
Financial institution
MAS-5.2MaterialityAssess each use's risk materiality to size the controls
Financial institution
MAS-6.1LifecycleData, fairness, transparency and explainability
Financial institution
MAS-6.2LifecycleHuman oversight proportionate to materiality
Financial institutionHigh materialityMedium materiality
MAS-6.3LifecyclePre-deployment evaluation and testing, independent review of material uses
Financial institutionHigh materiality
MAS-6.4LifecycleTechnology and cybersecurity, including risks specific to generative AI and agents
Financial institution
MAS-6.5LifecycleReproducibility and auditability
Financial institution
MAS-6.6LifecyclePost-deployment monitoring, change management and contingency
Financial institution
MAS-6.7LifecycleThird-party risk: vendors and foundation models
Financial institution
MAS-7CapabilitiesSkills and capacity suited to the AI uses
Financial institution

Checks to document

Evidence collected for a check counts for every regulation that uses it.

CodeCheckScopeThemesAlso used by
CHK-EXEC-ACCOUNTExecutive leadership is accountable for AI risk decisions (board committee, risk appetite)Organisation
CHK-POL-RISKAn AI risk-management policy and process are established through transparent, documented controlsOrganisation
CHK-ROLES-CLARIFIEDRoles, responsibilities and delegated authorities are documented and clear to relevant stakeholdersOrganisation
CHK-INVENTORYA mechanism to inventory AI systems is in place and resourcedOrganisation
CHK-CATEGORIZATIONAI system tasks and methods are categorized (classifier, generative, recommender)System
CHK-RISK-TOLERANCERisk tolerances are defined and AI systems are assigned to risk levelsOrganisation
VER-003-01Documented and up-to-date risk registerSystem
NEW-SG-MAS-01Risk materiality assessed and reviewed for each AI use proposedSystem
—
VER-004-01Documented data governance (collection process, bias, quality)System
CHK-BIASFairness and bias are evaluated and results documentedSystem
VER-033-D-02System explanation capability verifiedSystem
VER-008-02System designed to allow human oversight (stop button, override)System
VER-008-03Competent overseers assigned to the systemSystem
CHK-TEVVTEVV plan, test sets, metrics and data considerations are documentedSystem
CHK-INDEP-ASSESSIndependent or internal-expert assessment involves domain experts and affected communitiesSystem
VER-009-03Cybersecurity of the AI system verifiedSystem
VER-009-F-04Resilience to adversarial attacks testedModel
VER-006-01Documented log retention policyOrganisation
VER-005-01Complete technical documentation compliant with Annex IVSystem
VER-021-D-03Operation monitoringSystem
VER-AUTO-01Suspension procedure in the event of riskOrganisation
CHK-THIRDPARTY-POLPolicies address third-party AI/data risks, incl. IP, transparency and testingOrganisation
CHK-MODEL-MONITORINGPre-trained models used in development are monitored and maintainedModel
CHK-COMPETENCEOperator/practitioner proficiency processes and relevant standards are definedSystem
CHK-TRAININGPersonnel and partners receive AI risk-management trainingOrganisation

Themes covered

Frequently asked questions

Who is in scope of MAS AI Guidelines?

All financial institutions supervised by MAS (banks, insurers, asset managers, intermediaries). Financial activities in Singapore, including branches of foreign groups.

What penalties does MAS AI Guidelines carry?

No penalty of their own. Once issued, they are supervisory expectations checked in inspections; shortcomings can lead to supervisory action.

When do the MAS AI Guidelines obligations apply?

Nov 13, 2025: Public consultation on the guidelines; Jan 31, 2026: Consultation closes; Dec 2026: Expected issuance of the final guidelines; Dec 2027: End of the 12-month transition (if issued late 2026).

Is MAS AI Guidelines binding?

No. Kind: supervisory guidelines. Status: under discussion.

How does MAS AI Guidelines relate to other regulations?

The same checks serve several texts. Shared checks: NIST AI RMF (16), AI Act (11) and ISO 42001 (10).

Related regulations

Official sources

Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo