Skip to content
Questa e una traduzione di cortesia. La versione inglese e la versione ufficiale e giuridicamente vincolante. Visualizza versione inglese
SGDEEP coverage

Singapore MAS AI Model Risk Management (Information Paper 2024 + Proposed AI Risk Management Guidelines, in consultation) + Model AI Governance Framework: AI Compliance Requirements

The Monetary Authority of Singapore (MAS) has two NON-MANDATORY AI workstreams for financial institutions, not a binding AI rule in force. (1) On 5 December 2024 MAS published an Information Paper, "Artificial Intelligence Model Risk Management," sharing NON-BINDING good practices observed in a 2024 thematic review of selected banks — covering board/senior-management oversight, AI risk-management systems, and model development/validation/deployment. MAS encourages FIs to reference these good practices; the paper is not an enforceable rule. (2) MAS issued a Consultation Paper on PROPOSED Guidelines on AI Risk Management (AIRG) for all MAS-regulated FIs (banks, insurers, capital markets firms, payment service providers, expressly reaching generative AI and AI agents) on 13 November 2025; the consultation closed 31 January 2026, and — per MAS Chairman/DPM Gan Kim Yong's written Parliamentary reply of 5 August 2026 — the Guidelines are STILL not finalised as of this cycle, though he stated they "will be finalised soon" with no date given. Once finalised they would be supervisory expectations, with a proposed ~12-month transition period. Separately, MAS and industry released the Project MindForge AI Risk Management Toolkit on 20 March 2026 (an executive handbook, an operationalisation handbook, and implementation examples spanning traditional, generative, and agentic AI) — a voluntary practical resource, not a binding rule. On general AI governance (not MAS-specific), IMDA/PDPC's cross-sector Model AI Governance Framework (2nd ed., Jan 2020) remains voluntary for all sectors, with two later SEPARATE IMDA companion documents — the Model AI Governance Framework for Generative AI (30 May 2024) and the Model AI Governance Framework for Agentic AI (22 Jan 2026) — Cycle 22 (2026-08-22) correction: this entry previously conflated these into a single "Model AI Governance Framework (2024, updated 2025)," a framing not corroborated by any source found this cycle; see the twin entry `singapore_pdpa_aig`, corrected in the same cycle for the same conflation. (Status as of August 2026; web-verified 2026-08-22.)

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

December 5, 2024

Maximum Penalty

No AI-specific penalty regime in force yet. MAS supervises FIs under existing financial-services legislation; the proposed AI Risk Management Guidelines, once finalised, would be supervisory expectations assessed in inspections (not a standalone fining statute).

What Your Business Must Do

5 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Board-Level AI Governance (MAS-Regulated FIs)

Critical

Note on legal force (as of 2026-08-22, per MAS Chairman/DPM Gan Kim Yong's 5 Aug 2026 Parliamentary reply that the Guidelines are still pending): these MAS-FI items are currently NON-BINDING good practice (MAS Information Paper, Dec 2024) and would become supervisory expectations only if/when MAS finalises its proposed AI Risk Management Guidelines (in consultation Nov 2025–Jan 2026), after a proposed ~12-month transition. Recommended good practice: establish board-level oversight and accountability for AI systems — board approves the AI governance framework and risk appetite and receives regular reporting on AI performance and risk.

AI Risk Management Systems (MAS-Regulated FIs)

Critical

Implement enterprise-wide AI risk management processes: risk identification, assessment, monitoring, and control. Document risk taxonomy covering model risk, data risk, operational risk, and ethical risk from AI systems.

AI Model Development, Validation & Deployment

High Priority

Follow structured model lifecycle management: document model purpose and data sources, conduct independent model validation before deployment, maintain model performance monitoring, and establish model retirement procedures.

PDPA Automated Decision-Making Transparency

High Priority

Singapore's Personal Data Protection Act (PDPA) 2021 amendments require organizations to notify individuals when decisions with significant impact are made based solely on automated processing of personal data. For AI systems making significant decisions (credit, employment, insurance), provide: notification of automated processing, explanation of how the decision was made, and avenue for human review.

PDPA 2012 (as amended 2021), s. 48J; PDPC Advisory Guidelines on AI

Model AI Governance Framework (MAIGF) — All Sectors

Medium Priority

For non-financial-sector organizations: Align with the IMDA/PDPC Model AI Governance Framework (2nd ed., Jan 2020) and, where relevant, its two later separate companion documents — the Model AI Governance Framework for Generative AI (30 May 2024) and the Model AI Governance Framework for Agentic AI (22 Jan 2026). Implement governance roles, data governance, explainability practices, fairness assessments, and human oversight. Use AI Verify toolkit for self-assessment.

IMDA/PDPC Model AI Governance Framework (2nd ed., Jan 2020); Model AI Governance Framework for Generative AI (30 May 2024); Model AI Governance Framework for Agentic AI (22 Jan 2026)

Who Does This Apply To?

Three layers, none currently a mandatory AI-specific rule in force: (1) NON-BINDING GOOD PRACTICE — the MAS Information Paper on AI Model Risk Management (5 Dec 2024) sets out observed good practices MAS encourages MAS-regulated FIs (banks, insurers, capital markets firms, payment service providers, including foreign FIs operating Singapore branches) to reference for AI used in regulated activities: credit decisioning, fraud detection, AML, customer-service AI, algorithmic trading. (2) PROPOSED / PENDING — MAS's proposed Guidelines on AI Risk Management (consultation Nov 2025, closed 31 Jan 2026) would, once finalised, set supervisory expectations for the same FIs, with a proposed ~12-month transition; STILL not yet in force as of this cycle (2026-08-22) — MAS Chairman/DPM Gan Kim Yong's written Parliamentary reply of 5 August 2026 confirmed the Guidelines "will be finalised soon" with no date given. Separately, MAS and industry released the voluntary Project MindForge AI Risk Management Toolkit on 20 March 2026 (executive + operationalisation handbooks, implementation examples). (3) VOLUNTARY (all sectors) — the IMDA/PDPC Model AI Governance Framework (MAIGF, 2nd ed. Jan 2020) applies to all organizations across all sectors and is strongly encouraged for any Singapore-incorporated company using AI; two later, SEPARATE IMDA companion documents extend this to newer paradigms — the Model AI Governance Framework for Generative AI (30 May 2024) and the Model AI Governance Framework for Agentic AI (22 Jan 2026). The AI Verify toolkit provides a voluntary self-assessment testing report (not a government certification) useful for enterprise procurement and government tender responses.

Recent Regulatory Guidance

guidance2024-12-05

MAS Information Paper — Artificial Intelligence Model Risk Management (non-binding good practices)

On 5 December 2024 MAS published an Information Paper sharing NON-BINDING good practices for AI (including generative AI) model risk management, observed in a 2024 thematic review of selected banks. MAS encourages FIs to reference these practices; they are not enforceable requirements. Themes: (1) board and senior-management oversight and accountability for AI; (2) AI risk-management systems and processes (risk identification, assessment, monitoring, controls); (3) model development, validation, monitoring and deployment standards, including third-party / cloud-based AI subject to comparable model-risk discipline. No annual-review mandate or deadline is imposed by this paper.

Source
consultation2025-11-13

MAS Consultation Paper — Proposed Guidelines on AI Risk Management for Financial Institutions (not yet in force)

In November 2025 MAS issued a Consultation Paper proposing Guidelines on AI Risk Management (AIRG) for all MAS-regulated FIs, setting out supervisory expectations for AI oversight, risk-management systems, AI life-cycle controls, and capability/capacity. Consultation closed 31 January 2026. As of 2026-08-22 the Guidelines are STILL NOT finalised or in force — MAS Chairman/DPM Gan Kim Yong's written Parliamentary reply of 5 August 2026 confirmed they "will be finalised soon" with no date given; once finalised (expected 2026) they would be supervisory expectations assessed in MAS inspections, with a proposed ~12-month transition period. Separately, MAS released the voluntary Project MindForge AI Risk Management Toolkit on 20 March 2026. (Web-verified 2026-08-22.)

Source
guidance2026-03-20

MAS launches AI Risk Management Toolkit + Operationalisation Handbook

On 20 March 2026 MAS published an AI Risk Management Toolkit for the financial-services sector, developed with a consortium of financial institutions and industry partners, covering traditional AI, generative AI, and emerging agentic AI. It includes an AI Risk Management Operationalisation Handbook giving practical implementation guidance. This is separate from — and does not itself confirm finalisation of — the proposed AI Risk Management Guidelines (AIRG) still in the consultation-to-final pipeline as of this cycle.

Source
guidance2025-05-29

Singapore IMDA / AI Verify Foundation — updated AI Verify Testing Framework (traditional + generative AI)

On 29 May 2025 IMDA and the AI Verify Foundation released an updated AI Verify testing framework (~118 pages) extending the voluntary toolkit to generative AI — adding process checks for hallucination testing, red-teaming, model versioning, auditability and impact assessment across 11 governance domains (transparency, safety, fairness, accountability, etc.). AI Verify is a voluntary self-assessment that produces a testing report, not a government certification or licence; it maps to OECD AI Principles and the NIST AI RMF and is widely used by Singapore enterprises for vendor due diligence.

Source

Quarterly Enforcement Digest

Q2 2026 (web-verified 2026-06-09): Singapore still has NO mandatory AI-specific rule in force for financial institutions. The 5-Dec-2024 MAS Information Paper on AI Model Risk Management remains non-binding good practice. MAS's proposed Guidelines on AI Risk Management went out for consultation in Nov 2025 (closed 31 Jan 2026); they are not yet finalised or in force, with finalisation expected in 2026 and a proposed ~12-month transition before FIs are expected to meet them. No public MAS AI-credit enforcement action or remediation order against a financial institution exists. AI Verify's testing framework was updated (29 May 2025) and extended to generative AI; it is a voluntary self-assessment, increasingly used for vendor due diligence and government tenders. Singapore keeps its "trusted AI hub" stance — no prohibitionist approach. Practical step for vendors: FIs referencing the MAS good practices increasingly ask third-party / cloud AI providers for model-documentation packages, and this expectation would harden once the proposed Guidelines take effect — but it is good practice today, not an enforced mandate.

Digest covers enforcement actions, guidance, and regulatory developments. Last verified: 2026-08-22.

Industry Playbooks covering Singapore MAS AI Model Risk Management (Information Paper 2024 + Proposed AI Risk Management Guidelines, in consultation) + Model AI Governance Framework

These industry playbooks include jurisdiction-specific checklist items and guidance for Singapore MAS AI Model Risk Management (Information Paper 2024 + Proposed AI Risk Management Guidelines, in consultation) + Model AI Governance Framework.

Frequently Asked Questions

Does Singapore MAS AI Model Risk Management (Information Paper 2024 + Proposed AI Risk Management Guidelines, in consultation) + Model AI Governance Framework apply to my business?

The Monetary Authority of Singapore (MAS) has two NON-MANDATORY AI workstreams for financial institutions, not a binding AI rule in force. (1) On 5 December 2024 MAS published an Information Paper, "Artificial Intelligence Model Risk Management,"… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Singapore MAS AI Model Risk Management (Information Paper 2024 + Proposed AI Risk Management Guidelines, in consultation) + Model AI Governance Framework is: No AI-specific penalty regime in force yet. MAS supervises FIs under existing financial-services legislation; the proposed AI Risk Management Guidelines, once finalised, would be supervisory expectations assessed in inspections (not a standalone fining statute).. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Singapore MAS AI Model Risk Management (Information Paper 2024 + Proposed AI Risk Management Guidelines, in consultation) + Model AI Governance Framework?

The 5 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.mas.gov.sg/publications/monographs-or-information-paper/2024/artificial-intelligence-model-risk-management

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan