AI Governance Institute

MAS Guidelines on Artificial Intelligence Risk Management

Issued by

Monetary Authority of Singapore

liveEffective 2025-11-13MAS AIRMUpdated October 2026 · Last verified October 1, 2026
Official document →

The Monetary Authority of Singapore proposed Guidelines on AI Risk Management for all financial institutions in a consultation paper published on 13 November 2025. They set expectations on board oversight, AI inventories, risk materiality assessment, and life cycle controls. The consultation closed on 31 January 2026.

Applies To

Large enterpriseSMBAI developerAI deployer

Overview

The Monetary Authority of Singapore (MAS) Guidelines on Artificial Intelligence Risk Management will establish supervisory expectations for all MAS-regulated financial institutions that develop, deploy, or procure AI systems. MAS published the proposed guidelines for consultation on 13 November 2025, and the consultation closed on 31 January 2026. A written parliamentary reply on 5 August 2026 confirmed that agentic AI (systems that act on their own) is covered. Key provisions are expected to cover board and senior management accountability, structured risk management frameworks, AI lifecycle controls from development through decommissioning, and robust audit trail requirements. MAS indicated that model governance and human-in-the-loop approval workflows (a person approves AI actions) will face heightened scrutiny, reflecting growing concern about autonomous AI decision-making in financial services. The reply said the Guidelines will be finalised soon. MAS proposed giving firms 12 months from issue to implement them. Regulated firms should treat the proposed framework as an early indicator of enforceable supervisory expectations, given MAS's track record of converting guidelines into binding notice requirements.

Key Requirements

  • •Board and senior management must maintain documented oversight of all AI systems in use, including agentic AI deployments
  • •Institutions must establish a formal AI risk management framework aligned with supervisory expectations, covering identification, assessment, and mitigation of AI-specific risks
  • •AI lifecycle controls must be implemented at each stage: development, validation, deployment, monitoring, and decommissioning
  • •Model governance processes must include defined approval workflows, particularly for high-risk or autonomous AI use cases
  • •Ongoing monitoring and audit trail requirements apply to all AI systems, with records available for MAS examination
  • •Agentic AI systems carrying out multi-step or autonomous actions in financial services are explicitly in scope and subject to the same obligations as conventional AI

What Your Organization Must Do

  • →Map every AI system your firm develops, deploys or buys, including agentic AI that acts alone.
  • →Prepare board level accountability for AI oversight, as MAS proposes documented board and senior management oversight.
  • →Review third party AI vendor contracts for audit rights, model documentation and risk management obligations.
  • →Build logging and audit trails covering development, validation, deployment, monitoring and decommissioning of AI models.
  • →Plan against the proposed 12 month implementation window that would start when MAS issues final Guidelines.
  • →Use the existing FEAT principles as a baseline while the broader AIRM expectations remain proposed.

Playbook Guidance

Step-by-step implementation guidance for compliance teams.

Frequently Asked Questions

Does MAS AIRM apply to third-party AI vendors used by Singapore financial institutions?
Yes. Financial institutions that procure AI from third-party vendors remain responsible for compliance under the guidelines. Firms should review vendor contracts now to ensure audit rights, model documentation, and risk management obligations are contractually enforceable before the guidelines are finalized.
Are agentic AI systems explicitly covered under the MAS AI risk management guidelines?
Yes: MAS said in a written parliamentary reply on 5 August 2026 that the Guidelines apply to all AI use cases, including agentic AI. Agentic systems face the same oversight, lifecycle controls, and records as other AI.
What is the current status of the MAS AIRM guidelines and when do they take effect?
The Guidelines are still proposed, and MAS said in August 2026 they will be finalised soon. MAS proposed a 12-month transition from issue for firms to implement them.
How do MAS AIRM expectations compare to the existing FEAT principles for financial institutions?
The FEAT principles address fairness, ethics, accountability, and transparency in AI use, while MAS AIRM introduces broader supervisory requirements covering lifecycle controls, model governance workflows, and audit trail obligations. FEAT serves as a useful baseline for board accountability structures, but AIRM is expected to impose more operationally detailed compliance requirements.
What level of board involvement is required under the MAS AI risk management framework?
Board and senior management must maintain documented oversight of all AI systems in use, including agentic AI deployments. This means assigning named accountability at the board level and ensuring that AI governance is embedded into existing senior management responsibility structures before the guidelines are finalized.
What model governance documentation will MAS expect financial institutions to produce under AIRM?
MAS expects defined approval workflows for AI models, particularly for high-risk or autonomous use cases, along with audit trails covering development, validation, deployment, monitoring, and decommissioning. Records must be available for MAS examination, meaning logging and documentation infrastructure should be in place well before any supervisory review.