
Following MAS’ consultation on the Guidelines in November 2025, the Guidelines sets out clear supervisory expectations for financial institutions (FIs) to manage risks arising from AI use. FIs are expected to manage AI risks at both the enterprise and individual use case levels, and build the capabilities needed for responsible AI use as adoption grows. The key expectations are for FIs to:
- Apply the Guidelines in a risk-proportionate manner
- Establish frameworks, policies and procedures including identification of AI use cases, perform materiality assessment and maintain AI inventory. Apply life cycle controls and establish capabilities and technology infrastructure.
- Apply basic policies and procedures to govern AI use, if poor performance or unavailability of their AI services or tools is unlikely to have a material impact on the FI, its customers or other stakeholders, including other FIs.
- Strengthen oversight of AI risks with clear accountabilities
- Board and senior management provide effective oversight of AI risks, including setting and regularly review roles and responsibilities, risk appetite, and risk management frameworks, policies and procedures.
- Existing governance structures may be used where they provide adequate oversight and cross functional coordination.
- Identify, assess and manage AI risks
- Identify AI use, maintain AI inventories at an appropriate level of granularity containing key attributes, assess the risk materiality of AI use cases, and apply proportionate controls.
- Risk materiality assessment should account for inherent risk and residual risk by considering impact of poor/failed consequences, complexity of technology and level of reliance on AI.
- AI life cycle controls
- Plan and implement robust controls covering the entire life cycle in a proportionate manner appropriate to the risk materiality. High risk cases should have contingency plans.
- Areas in life cycle controls include data governance, disclosures, human oversight, third party management, testing, technology, cybersecurity, monitoring and change management. Review controls regularly as AI use expands and the technologies evolve, such as the greater use of agentic AI systems that can operate autonomously and access tools.
- Capability and capacity
- Personnel have the necessary competence and proper conduct through recruitment, appropriate training and adequate resource allocation. These should be reviewed regularly.
- Technology infrastructure is adequate and risks are addressed appropriately to ensure the underlying hardware and software resources are sufficient to meet the need of the AI use case.
- Effective date
- Expectations on section 3 and 4 of the Guidelines (“AI Oversight” and “Key AI Risk Management Systems, Policies and Procedures”) effective from 07 October 2027.
- Expectations on section 5 and 6 of the Guidelines (“AI Life Cycle Controls” and “AI Capability & Capacity”) by 07 October 2028.
For the full details, please refer to https://www.mas.gov.sg/regulation/guidelines/guidelines-on-artificial-intelligence-risk-management-for-financial-institutions
Disclaimer: The information, views or opinions expressed are provided for general information and should not be relied upon as legal or professional advice.