The law library · Singapore · Financial supervision
Singapore: the MAS Guidelines on AI Risk Management
Monetary Authority of Singapore · Guidelines on Artificial Intelligence Risk Management · issued 7 October 2026 · for all financial institutions, banks and insurers included
Guidelines and media release read in full; the quotation is from the release. Source: the Monetary Authority of Singapore.
On 7 October 2026 the Monetary Authority of Singapore issued its final Guidelines on Artificial Intelligence Risk Management. They apply to all financial institutions, insurers included, and to all forms of AI technology. A firm remains accountable for the AI in the services it delivers, and in MAS’s words that includes “AI developed, operated or provided by third parties.” The Guidelines take effect on 7 October 2027: Sections 3 to 4 apply from 7 October 2027, and Sections 5 and 6 by 7 October 2028.
Status
- Issued7 October 2026, after a public consultation in November 2025, with a response to feedback paper published alongside.
- 7 Oct 2027The Guidelines take effect. Section 3 (AI Oversight) and Section 4 (Key AI Risk Management Systems, Policies and Procedures) apply from this date (paragraph 1.8).
- 7 Oct 2028Section 5 (AI Life Cycle Controls) and Section 6 (AI Capability and Capacity) apply by this date (paragraph 1.8).
- 2027MAS intends to consult the financial sector further on what additional guidance on agentic AI would be useful.
- ScopeAll financial institutions, in a manner proportionate to their size and risk profile (paragraph 2.1), and all forms of AI, including generative AI and AI agents (paragraph 1.5). Where poor performance or unavailability of an AI tool is unlikely to have a material adverse impact, a firm may apply basic policies and procedures, which include a member of senior management designated as responsible for AI oversight (paragraphs 2.3 and 2.5).
What the Guidelines ask of a firm
- The boardThe board, or a committee it delegates, approves the approach to AI risk management and addresses AI risk in the risk appetite framework. Senior management sets clear roles and responsibilities across business lines and an internal escalation process for AI incidents and breaches of risk thresholds (paragraphs 3.4 and 3.5).
- InventoryThe firm identifies its AI use, keeps an accurate inventory of AI use cases, systems or models, and assesses the risk materiality of each use case. For AI agents, the inventory may record agent identifiers, the tools and systems the agent can access, and the guardrails imposed (paragraphs 4.5 to 4.12 and footnote 25).
- AI agentsMAS describes the risk that an AI agent with access to tools carries out unauthorised or erroneous actions, where its actions diverge from the goals it was set (paragraph 1.11).
- PeopleClear roles for human oversight, including escalation and decision making; competent people with the authority and ability to intervene; AI designed from the outset to allow oversight; and logs and records of human oversight decisions and interventions, including incidents and near misses, reviewed regularly (paragraph 5.9).
- VendorsThe decision to use third-party AI is the firm’s, and the firm keeps primary accountability for it. It obtains sufficient assurance from providers, tests third-party AI in the context of its own use cases, keeps documentation of that testing, and limits, suspends or replaces a service whose risk it cannot bring within its risk appetite (paragraphs 5.10 and 5.11).
- MonitoringOngoing monitoring of all deployed AI, third-party AI included, covering, where relevant, the reasoning processes, actions taken and tools used. For high risk materiality AI, kill switches or override mechanisms to deactivate it rapidly. Clear records of monitoring, issues, incidents and remediation for auditability, with enhanced documentation for generative AI and AI agents, such as logs of prompts and responses with model versions (paragraph 5.23).
Why it is on this site
When an AI agent drifts from what was authorised, Regulayer™ supplies the evidence of who held the authority and whether it held at the moment of action. The firm and MAS make the determination.
Sources
- MAS Sets Out Supervisory Expectations on Responsible AI Adoption by Financial Institutions, media release, 7 October 2026
- Guidelines on Artificial Intelligence Risk Management, 7 October 2026, read in full for this page
- The Guidelines and the response to feedback, on MAS’s website
Related
- The law library
- NAIC · AI Model Bulletin, insurers’ AI Systems Program in the United States
- Singapore · PDPA, data breach assessment and notification
- SR 26-2 / OCC Bulletin 2026-13, model risk management
- ISO/IEC 42001:2023, AI management system
Read against the Guidelines and the media release, in full. Information, not legal advice.
Information, not legal advice. Every entry is verified against the issuing body’s own document; where a source is reporting rather than the document, we say so.
