The Monetary Authority of Singapore has issued final Guidelines on Artificial Intelligence Risk Management, establishing principles based and risk proportionate supervisory expectations for all financial institutions and all forms of AI. Institutions must manage risks at both enterprise and individual use case levels, tailoring governance and controls to the nature, scale and materiality of their AI use. The Guidelines finalize the framework that underpinned the AI Risk Management Toolkit released through Project MindForge in March 2026. Boards and senior management must oversee AI risks through clear accountability, risk appetite and management frameworks, although institutions may use adequate existing governance structures rather than create dedicated AI committees. Firms should identify and inventory AI use, assess each use case’s materiality and apply proportionate controls across the AI life cycle, including data governance, testing, human oversight, cybersecurity, monitoring and change management. They remain accountable for third-party AI used in their services and should obtain sufficient assurance, address gaps with compensating controls, or limit, suspend or replace services whose risks cannot be brought within appetite. Basic policies and procedures may be sufficient where poor performance or unavailability is unlikely to have a material impact. The Guidelines take effect on Oct. 7, 2027. Institutions may implement them in phases, meeting Sections 3 and 4 from that date and Sections 5 and 6 by Oct. 7, 2028. MAS also intends to consult the financial sector in 2027 on whether additional guidance is needed for agentic AI systems that can operate autonomously and access tools.