Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →MAS Guidelines on Artificial Intelligence Risk Management
Issued by
Monetary Authority of Singapore
The Monetary Authority of Singapore is finalizing supervisory guidelines that will set binding expectations for how financial institutions govern, deploy, and monitor artificial intelligence systems. The guidelines apply to all AI use cases, including agentic AI, and cover board-level oversight, risk frameworks, and lifecycle controls. Financial institutions regulated by MAS should anticipate formal requirements around model governance, approval workflows, ongoing monitoring, and audit trails.
Applies To
Overview
The MAS Guidelines on Artificial Intelligence Risk Management will establish supervisory expectations for all MAS-regulated financial institutions that develop, deploy, or procure AI systems. The guidelines were signaled through a written parliamentary reply dated 12 August 2026, which confirmed that agentic AI use cases fall within scope alongside conventional AI applications. Key provisions are expected to cover board and senior management accountability, structured risk management frameworks, AI lifecycle controls from development through decommissioning, and robust audit trail requirements. MAS indicated that model governance and human-in-the-loop approval workflows will be subject to heightened scrutiny, reflecting growing concern about autonomous AI decision-making in financial services. Finalization timelines have not been formally published, though the parliamentary reply signals that guidance is at an advanced stage of development. Regulated firms should treat the proposed framework as an early indicator of enforceable supervisory expectations, given MAS's track record of converting guidelines into binding notice requirements.
Key Requirements
- •Board and senior management must maintain documented oversight of all AI systems in use, including agentic AI deployments
- •Institutions must establish a formal AI risk management framework aligned with supervisory expectations, covering identification, assessment, and mitigation of AI-specific risks
- •AI lifecycle controls must be implemented at each stage: development, validation, deployment, monitoring, and decommissioning
- •Model governance processes must include defined approval workflows, particularly for high-risk or autonomous AI use cases
- •Ongoing monitoring and audit trail requirements apply to all AI systems, with records available for MAS examination
- •Agentic AI systems carrying out multi-step or autonomous actions in financial services are explicitly in scope and subject to the same obligations as conventional AI
What Your Organization Must Do
- →Audit all AI systems currently in use across the institution and classify each by risk level and degree of autonomy, including any agentic AI pilots or production deployments
- →Assign board-level and senior management accountability for AI governance before the guidelines are finalized, using existing MAS accountability frameworks such as FEAT as a baseline
- →Develop or update an enterprise AI risk management policy that maps to the anticipated MAS lifecycle control requirements, covering development through decommissioning
- →Establish documented model approval workflows that include defined escalation paths and human review gates, particularly for autonomous or high-stakes AI decisions
- →Implement monitoring and logging infrastructure capable of generating audit trails for all AI-driven decisions or recommendations that affect customers or financial risk
- →Review vendor and third-party AI contracts to ensure audit rights, model documentation, and risk management obligations are contractually enforceable before MAS finalizes the guidelines
Playbook Guidance
Step-by-step implementation guidance for compliance teams.
Frequently Asked Questions
- Does MAS AIRM apply to third-party AI vendors used by Singapore financial institutions?
- Yes. Financial institutions that procure AI from third-party vendors remain responsible for compliance under the guidelines. Firms should review vendor contracts now to ensure audit rights, model documentation, and risk management obligations are contractually enforceable before the guidelines are finalized.
- Are agentic AI systems explicitly covered under the MAS AI risk management guidelines?
- Yes. MAS confirmed in a parliamentary reply dated 12 August 2026 that agentic AI use cases fall within scope alongside conventional AI applications. Autonomous multi-step AI systems are subject to the same board oversight, lifecycle controls, and audit trail requirements as other AI deployments.
- What is the current status of the MAS AIRM guidelines and when do they take effect?
- The guidelines are currently in draft review, and MAS has not published a formal finalization or effective date. However, given MAS's track record of converting supervisory guidelines into binding notice requirements, regulated firms should treat the framework as an early indicator of enforceable expectations.
- How do MAS AIRM expectations compare to the existing FEAT principles for financial institutions?
- The FEAT principles address fairness, ethics, accountability, and transparency in AI use, while MAS AIRM introduces broader supervisory requirements covering lifecycle controls, model governance workflows, and audit trail obligations. FEAT serves as a useful baseline for board accountability structures, but AIRM is expected to impose more operationally detailed compliance requirements.
- What level of board involvement is required under the MAS AI risk management framework?
- Board and senior management must maintain documented oversight of all AI systems in use, including agentic AI deployments. This means assigning named accountability at the board level and ensuring that AI governance is embedded into existing senior management responsibility structures before the guidelines are finalized.
- What model governance documentation will MAS expect financial institutions to produce under AIRM?
- MAS expects defined approval workflows for AI models, particularly for high-risk or autonomous use cases, along with audit trails covering development, validation, deployment, monitoring, and decommissioning. Records must be available for MAS examination, meaning logging and documentation infrastructure should be in place well before any supervisory review.
