Preparing for the MAS AI risk management guidelines
Singapore MAS Guidelines on Artificial Intelligence Risk Management
- Status
- Under discussion
- Binding
- No
- Object analysed
- AI system
- Requirements
- 11
- Next milestone
- Dec 2026
In short
Monetary Authority of Singapore expectations for all financial institutions: board and senior management oversight, AI use inventory, risk materiality assessment, lifecycle controls, capabilities. Covers generative AI and agents, proportionately. Extends the FEAT principles (2018).
Steps to compliance
- Qualify each AI systemAxes to decide: Use-case risk materiality (impact, complexity, reliance).
- Determine your roleDuties vary by role: Financial institution.
- Apply the 11 requirementsThey focus on: Risk management, Governance & accountability, Inventory & categorisation and Data governance.
- Prove it with checks25 checks to document, 24 of which also serve NIST AI RMF, AI Act and ISO 42001.
- Track the deadlinesNext milestone: Dec 2026, Expected issuance of the final guidelines (potential).
Scope and penalties
- Kind
- Supervisory guidelines
- Scope
- All financial institutions supervised by MAS (banks, insurers, asset managers, intermediaries).
- Territorial reach
- Financial activities in Singapore, including branches of foreign groups.
- Penalties
- No penalty of their own. Once issued, they are supervisory expectations checked in inspections; shortcomings can lead to supervisory action.
- Jurisdiction
- Singapore
Timeline
Qualifying a system
Classification axes and possible verdicts
Use-case risk materiality (impact, complexity, reliance)
Requirements
11 requirements
| Code | Article | Requirement | Applies to | Checks |
|---|---|---|---|---|
| MAS-4 | Oversight | Board and senior management oversight of AI risk management; framework, policies and roles | ||
| MAS-5.1 | Identification | Identify and inventory AI uses, including generative AI and third-party solutions | ||
| MAS-5.2 | Materiality | Assess each use's risk materiality to size the controls | ||
| MAS-6.1 | Lifecycle | Data, fairness, transparency and explainability | ||
| MAS-6.2 | Lifecycle | Human oversight proportionate to materiality | ||
| MAS-6.3 | Lifecycle | Pre-deployment evaluation and testing, independent review of material uses | ||
| MAS-6.4 | Lifecycle | Technology and cybersecurity, including risks specific to generative AI and agents | ||
| MAS-6.5 | Lifecycle | Reproducibility and auditability | ||
| MAS-6.6 | Lifecycle | Post-deployment monitoring, change management and contingency | ||
| MAS-6.7 | Lifecycle | Third-party risk: vendors and foundation models | ||
| MAS-7 | Capabilities | Skills and capacity suited to the AI uses |
Checks to document
Evidence collected for a check counts for every regulation that uses it.
| Code | Check | Scope | Themes | Also used by |
|---|---|---|---|---|
| CHK-EXEC-ACCOUNT | Executive leadership is accountable for AI risk decisions (board committee, risk appetite) | Organisation | ||
| CHK-POL-RISK | An AI risk-management policy and process are established through transparent, documented controls | Organisation | ||
| CHK-ROLES-CLARIFIED | Roles, responsibilities and delegated authorities are documented and clear to relevant stakeholders | Organisation | ||
| CHK-INVENTORY | A mechanism to inventory AI systems is in place and resourced | Organisation | ||
| CHK-CATEGORIZATION | AI system tasks and methods are categorized (classifier, generative, recommender) | System | ||
| CHK-RISK-TOLERANCE | Risk tolerances are defined and AI systems are assigned to risk levels | Organisation | ||
| VER-003-01 | Documented and up-to-date risk register | System | ||
| NEW-SG-MAS-01 | Risk materiality assessed and reviewed for each AI use proposed | System | ||
| VER-004-01 | Documented data governance (collection process, bias, quality) | System | ||
| CHK-BIAS | Fairness and bias are evaluated and results documented | System | ||
| VER-033-D-02 | System explanation capability verified | System | ||
| VER-008-02 | System designed to allow human oversight (stop button, override) | System | ||
| VER-008-03 | Competent overseers assigned to the system | System | ||
| CHK-TEVV | TEVV plan, test sets, metrics and data considerations are documented | System | ||
| CHK-INDEP-ASSESS | Independent or internal-expert assessment involves domain experts and affected communities | System | ||
| VER-009-03 | Cybersecurity of the AI system verified | System | ||
| VER-009-F-04 | Resilience to adversarial attacks tested | Model | ||
| VER-006-01 | Documented log retention policy | Organisation | ||
| VER-005-01 | Complete technical documentation compliant with Annex IV | System | ||
| VER-021-D-03 | Operation monitoring | System | ||
| VER-AUTO-01 | Suspension procedure in the event of risk | Organisation | ||
| CHK-THIRDPARTY-POL | Policies address third-party AI/data risks, incl. IP, transparency and testing | Organisation | ||
| CHK-MODEL-MONITORING | Pre-trained models used in development are monitored and maintained | Model | ||
| CHK-COMPETENCE | Operator/practitioner proficiency processes and relevant standards are defined | System | ||
| CHK-TRAINING | Personnel and partners receive AI risk-management training | Organisation |
Themes covered
Frequently asked questions
Who is in scope of MAS AI Guidelines?
All financial institutions supervised by MAS (banks, insurers, asset managers, intermediaries). Financial activities in Singapore, including branches of foreign groups.
What penalties does MAS AI Guidelines carry?
No penalty of their own. Once issued, they are supervisory expectations checked in inspections; shortcomings can lead to supervisory action.
When do the MAS AI Guidelines obligations apply?
Nov 13, 2025: Public consultation on the guidelines; Jan 31, 2026: Consultation closes; Dec 2026: Expected issuance of the final guidelines; Dec 2027: End of the 12-month transition (if issued late 2026).
Is MAS AI Guidelines binding?
No. Kind: supervisory guidelines. Status: under discussion.
How does MAS AI Guidelines relate to other regulations?
The same checks serve several texts. Shared checks: NIST AI RMF (16), AI Act (11) and ISO 42001 (10).
Related regulations
Official sources
Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.