Singapore issues AI risk guidelines for financial institutions
The monetary authority sets risk-based expectations for AI oversight, third-party systems and life-cycle controls, with phased implementation from October 2027.
A framework for banks and other financial firms
The Monetary Authority of Singapore issued AI risk management guidelines for all financial institutions on October 7. The regulator says firms should oversee AI risks at both enterprise and individual use-case levels, identify their AI systems, assess material risks and apply controls throughout each system’s life cycle. Its examples include data governance, testing, human oversight, cybersecurity, monitoring and change management. Boards and senior managers should have clear responsibilities, but MAS says firms can use existing governance structures when those provide adequate oversight; a dedicated AI committee is not automatically required.
Third parties and phased deadlines
MAS says institutions remain accountable for AI used in services they deliver, including systems built or operated by third parties. They should obtain assurance from providers and consider limiting or replacing a service when its risks cannot be managed within the firm’s risk appetite. The approach is proportionate: basic policies may suffice for low-impact uses. The guidelines take effect on October 7, 2027. MAS allows sections 5 and 6 until October 7, 2028, and says it intends to consult further on agentic AI guidance in 2027. The October 7 announcement issued supervisory guidelines; it did not say every firm must already comply or that new agent-specific rules have been finalized.