News confirmed medium confidence

Singapore MAS Issues Phased AI Risk Guidelines for Financial Institutions

The supervisory framework covers every form of AI used by regulated firms, with governance expectations starting in 2027 and later requirements following in 2028.

Edited by Tyronne Panaino

The Monetary Authority of Singapore issued AI Risk Management Guidelines on October 7, 2026, setting supervisory expectations for financial institutions that use artificial intelligence. The framework applies across Singapore's financial sector and begins taking effect in phases from October 7, 2027, giving boards, risk teams, technology leaders and third-party managers a dated preparation horizon.

The immediate change is not a ban on particular models or a certification of existing systems. MAS has instead defined a principles-based structure that applies to all financial institutions and all forms of AI, while allowing controls to vary with the nature, scale and materiality of each use. That distinction matters for firms ranging from limited internal-tool users to institutions deploying more autonomous systems in customer or operational workflows.

Oversight can use existing structures

MAS expects boards and senior management to provide effective oversight through clear accountability, risk appetite, frameworks, policies and procedures. The guidelines do not require every institution to create a dedicated AI committee. Existing governance can remain in place when it delivers adequate oversight and cross-functional coordination.

That makes the operational test more substantive than an org-chart exercise. A firm must be able to show who owns an AI risk, how the use fits within risk appetite and how legal, security, data, model and business functions coordinate. The source does not prescribe one universal committee design, leaving institutions to demonstrate that their chosen structure is proportionate and effective.

Lifecycle controls start with knowing what is used

Institutions are expected to identify their AI use, maintain inventories at an appropriate level of detail and assess the materiality of individual use cases. MAS lists data governance, testing, human oversight, cybersecurity, monitoring and change management among the controls that should follow an AI system through its lifecycle.

The inventory requirement is practically important because governance cannot be applied consistently to systems that an institution has not identified. The proportional approach also means a low-impact internal tool may justify simpler procedures than an AI service whose poor performance or unavailability could materially affect customers, counterparties or other financial institutions.

MAS explicitly extends accountability to third-party AI used in services a financial institution delivers. Firms should seek sufficient assurance from providers, assess whether a service suits its intended use and apply compensating controls when assurance gaps remain. If a third-party system cannot be brought within risk appetite, the regulator says the institution should consider limiting, suspending or replacing it.

Agentic AI gets a later checkpoint

The guidelines address controls for systems with growing autonomy, but MAS also says it intends to consult the sector in 2027 on what additional agentic-AI guidance would be useful. That future consultation is a separate checkpoint: this release establishes the broad framework, not a final detailed rulebook for every tool-using or autonomous workflow.

Implementation is phased. Expectations in Sections 3 and 4 begin on October 7, 2027, while Sections 5 and 6 are due by October 7, 2028. Institutions therefore need to read the section-level requirements rather than treat the two dates as interchangeable.

Evidence quality and what remains open

The source is MAS's official release and is authoritative for what the regulator issued, its stated scope and the implementation dates. Internal confidence is medium because this is first-party policy evidence: it does not independently show how firms will interpret the guidance, how consistently supervisory expectations will be assessed or whether the controls will reduce real incidents.

The next verifiable checkpoints are the institutions' phased implementation, any section-specific supervisory clarification and the promised 2027 consultation on agentic AI. Evidence of inventories, oversight decisions, third-party assurance and corrective action will matter more than policy language alone.

Status

Confirmed. MAS has issued the guidelines and published the phased dates. Their implementation, supervisory consistency and practical effectiveness remain to be demonstrated.

Sources

Update note: Last reviewed 2026-10-07. We will revise this post when MAS publishes material implementation or agentic-AI guidance.

Sources

Drafted with AI assistance from source briefs; reviewed for citation completeness and label accuracy.

More News coverage