The Monetary Authority of Singapore has issued final Guidelines on Artificial Intelligence Risk Management, establishing principles based and risk proportionate supervisory expectations for all financial institutions and all forms of AI. Institutions must manage risks at both enterprise and individual use case levels, tailoring governance and controls to the nature, scale and materiality of their AI use. The Guidelines finalize the framework that underpinned the AI Risk Management Toolkit released through Project MindForge in March 2026. Boards and senior management must oversee AI risks through clear accountability, risk appetite and management frameworks, although institutions may use adequate existing governance structures rather than create dedicated AI committees. Firms should identify and inventory AI use, assess each use case’s materiality and apply proportionate controls across the AI life cycle, including data governance, testing, human oversight, cybersecurity, monitoring and change management. They remain accountable for third-party AI used in their services and should obtain sufficient assurance, address gaps with compensating controls, or limit, suspend or replace services whose risks cannot be brought within appetite. Basic policies and procedures may be sufficient where poor performance or unavailability is unlikely to have a material impact. The Guidelines take effect on Oct. 7, 2027. Institutions may implement them in phases, meeting Sections 3 and 4 from that date and Sections 5 and 6 by Oct. 7, 2028. MAS also intends to consult the financial sector in 2027 on whether additional guidance is needed for agentic AI systems that can operate autonomously and access tools.
Monetary Authority of Singapore issues final AI risk management guidelines for all financial institutions, with phased implementation from October 2027
The Monetary Authority of Singapore has finalized risk proportionate AI risk management guidelines covering all financial institutions and forms of AI. Firms must strengthen oversight, apply life cycle controls and remain accountable for third-party AI, with simpler arrangements permitted for immaterial uses. The Guidelines take effect in phases from Oct. 7, 2027, while MAS plans a 2027 consultation on possible agentic AI guidance.