MAS finalises AI risk rules for Singapore banks, requiring independent checks and third-party accountability

Fintech News

MAS finalises AI risk rules for Singapore banks, requiring independent checks and third-party accountability #

The Monetary Authority of Singapore (MAS) has issued finalised Guidelines on Artificial Intelligence Risk Management for financial institutions, setting out binding supervisory expectations for how banks, insurers, payment firms and other regulated entities must govern their use of AI.

Published on 7 October 2026, the framework follows a public consultation launched in November 2025 and closed in January 2026. According to the regulator’s announcement, firms had broadly supported a principles-based, risk-proportionate approach but sought greater clarity on governance structures, the treatment of AI embedded in third-party software, and what a lighter-touch compliance path would look like for firms with lower-risk AI deployments.

A core requirement is that institutions retain full accountability for AI used in delivering their services, regardless of whether it is built in-house or sourced from an outside provider. MAS has specified that firms must obtain independent assessments from third-party AI vendors rather than rely on self-attestations, a standard expected to affect procurement and contracting processes across the sector. Where the risks from an external AI system cannot be brought within a firm’s stated risk appetite, MAS expects the institution to consider limiting, suspending or replacing the service.

The guidelines place boards and senior management directly in the governance chain, making them responsible for setting AI risk appetite, defining roles and accountability, and overseeing risk management frameworks. MAS noted that firms are not required to establish a dedicated AI committee, provided that existing cross-functional governance structures deliver adequate oversight and coordination.

Other requirements include maintaining detailed inventories of all AI in use, including AI embedded in material third-party services and “shadow AI” not formally procured as AI, and implementing controls across the full AI lifecycle. These cover data governance, cybersecurity, testing, human oversight, monitoring and change management, with contingency plans and kill-switch protocols for high-risk applications required to be regularly tested.

MAS identified agentic AI, systems capable of acting autonomously and calling upon external tools, as an area of elevated risk and incomplete guidance. The regulator said it intends to consult the industry in 2027 on further agentic AI requirements.

Implementation is phased. Governance and risk identification expectations in Sections 3 and 4 take effect on 7 October 2027, with lifecycle controls and capability requirements in Sections 5 and 6 applying from 7 October 2028. Firms whose AI use is unlikely to have a material impact on themselves, customers or other institutions may satisfy the guidelines through basic policies and procedures.

Source: Monetary Authority of Singapore