What will Singapore require banks to do before using AI?
Singapore's financial regulator has set staged, risk-proportionate expectations for every financial institution: know where AI is used, assess materiality, assign accountable leaders and control the full lifecycle. The rules begin in 2027, and publication is not evidence that firms already comply.
Editorial responsibility: The Impact of AI Editorial Desk · Report a factual concern
At a glance
- 1The guidelines apply to all Singapore financial institutions in a proportionate way and cover generative AI and AI agents as well as established machine-learning systems.
- 2Boards and senior management must oversee AI risk; firms must identify AI use, keep an inventory, assess materiality and apply relevant lifecycle controls, including to material third-party services.
- 3The first governance and risk-management expectations begin on 7 October 2027, while lifecycle controls and capability requirements follow by 7 October 2028. The document is a supervisory standard, not evidence of compliance or improved customer outcomes.
Research topic
How Singapore's financial regulator expects institutions to identify, govern and control AI use

The direct answer: inventory, accountability and controls before scale
Singapore will expect every financial institution to know where it uses AI, decide how much harm each use could cause, put a named control structure around it and apply lifecycle safeguards proportionate to the risk. The Monetary Authority of Singapore, or MAS, published the 30-page guideline on 7 October 2026. It covers machine learning, natural-language processing, computer vision, generative AI and AI agents; fixed formulas and conventional rule-based automation are outside its AI definition.
The requirement is deliberately broader than a model-validation exercise. An institution must connect AI to board oversight, risk appetite, internal escalation, an inventory, materiality assessment, data governance, testing, human oversight, monitoring, cybersecurity, third-party management and staff capability. A globally managed bank may reuse a group framework, but local senior management remains accountable for showing that Singapore-specific risks and regulatory duties are met.
The timetable is staged. MAS says the oversight and core risk-management sections can be met from 7 October 2027, while lifecycle controls and capability requirements should be met by 7 October 2028. That runway is important: publication begins an implementation period. It does not mean every covered firm already has a complete inventory, independent validation or reliable monitoring in place.[1][2]
Who and what the guideline covers
The guideline applies to all financial institutions regulated in Singapore, proportionate to their size, activities and risk profile. Locally incorporated firms subject to consolidated MAS supervision, and owners of critical information infrastructure, must apply it on a group basis. The high-level expectations extend to newer systems including generative and agentic AI, even when the technology is embedded inside a service bought from a supplier.
The unit of governance is the use case, not only the model. MAS distinguishes a model, a wider system and the real-world context in which it is used. That matters because one general-purpose model could draft internal notes, advise a customer, screen a transaction or execute actions through tools. Those uses create very different consequences even if the underlying model is identical.
Materiality therefore drives the intensity of controls. Firms must consider potential financial, operational, regulatory, legal and reputational effects, alongside fairness, ethical conduct and consumer protection. They should assess risk before controls and the residual risk after controls. Higher-materiality use cases receive more scrutiny; low-impact assistance may use a simpler governance route, but it is not exempt from accountability.[1]
Even low-risk copilots need a basic governance floor
MAS gives examples of uses that may normally qualify for basic controls: drafting or proofreading customer emails, summarising internal notes, initially reviewing internal documents, generating internal charts, creating marketing material and helping staff locate policies. The condition is that poor performance or unavailability is unlikely to cause material harm and that a human checks the output before it is used.
The minimum floor is still concrete. A member of senior management should be accountable. The institution should define permitted and prohibited uses, specify when human review is mandatory, maintain an approved-tools list, educate staff, run compliance checks and revisit the classification periodically or when a trigger occurs. MAS specifically gives the example of prohibiting confidential, proprietary or client information from being entered into public AI tools.
This prevents proportionality from becoming a blanket low-risk label. A drafting assistant can change function, gain access to sensitive records or become embedded in a customer process. Periodic and trigger-based reviews are meant to catch that drift. Firms also need controls for shadow AI and undisclosed AI features in software services, because an inventory limited to systems purchased under an ‘AI’ label will be incomplete.[1]
Boards cannot delegate away the accountability
The board, or an appropriately delegated committee, is expected to approve and regularly review the overall approach, place AI risk inside the risk-appetite framework, understand the technology well enough to challenge management and keep the approach current. MAS suggests that quantitative appetite measures could include incident impact, concentration in one provider or material systems breaching performance thresholds.
Senior management must turn that direction into operating controls. Its responsibilities include implementing the framework, assigning roles, managing the lifecycle, escalating incidents and exceptions, updating the board and providing adequate people, technology, finance and training. MAS notes that firms can use a three-lines-of-defence model: business and developers in the first line, independent challenge and compliance in the second, and internal audit in the third.
This is particularly consequential for multinational institutions. A regional or global committee may provide governance, but local leaders need visibility, input and escalation paths for Singapore. They must be able to demonstrate to MAS how they discharged their duties. A vendor contract or group policy can support the work; neither transfers the institution's responsibility for customer outcomes or regulatory compliance.[1]
An AI inventory becomes the backbone of supervision
Firms should establish a consistent process to identify AI across business and control functions, including AI inside material third-party services. A designated control function should retain independent oversight and be the final arbiter of whether something counts as AI. Documentation must be updated as techniques change, which is essential when suppliers add generative features to existing products without presenting them as a separate model.
The inventory should link a use case to its purpose, approved scope, model type, data, dependencies, lifecycle status, materiality rating, review status, owners and essential documents. MAS also encourages links to data inventories and vendor registers. That turns an abstract model list into an operational map: supervisors and risk teams can see which customer processes depend on which data, providers and controls.
Completeness will be difficult. Shadow tools, open-source components, application programming interfaces and rapidly changing software can evade central procurement. MAS acknowledges those practical constraints but expects residual risk to remain within appetite. Staff rules, network monitoring and data-loss prevention are examples of mitigations; none removes the need to keep improving discovery.[1]
Why generative and agentic AI raise the stakes
MAS treats many AI risks as extensions of familiar financial risks: poor assessments can create losses, automation failures can disrupt operations, biased outputs can cause unfair treatment and uncertain monitoring can miss suspicious transactions. Generative systems add harder-to-structure inputs and outputs, opaque training data, privacy and intellectual-property questions, prompt-injection exposure and dependence on a small group of providers.
Agents add autonomy and access to tools. A system that can send instructions, move information or invoke internal services could execute an erroneous or unauthorised action at scale. A compromised agent could also exfiltrate data or issue malicious commands. The guideline includes agents in its scope, while MAS says it plans further consultation in 2027 on the specific risks and controls associated with agentic AI.
For customers, the practical test is not whether a product contains fashionable technology. It is whether the institution can explain who is accountable, test the system in the intended context, preserve meaningful human intervention and respond when behaviour changes. A well-written policy is useful only if incident data, audits and customer outcomes show that those controls operate in practice.[1]
What would show that the policy is working
The guideline itself contains no sample of institutions, compliance audit, incident comparison or customer-outcome evaluation. It is a supervisory standard, not an empirical study. The central uncertainty is implementation: how consistently firms identify embedded AI, how they calibrate materiality, whether independent challenge is genuinely independent and whether controls can keep pace with provider updates.
Evidence of progress would include supervisory reviews showing inventory coverage, timely closure of gaps and reliable escalation of incidents. Firms could publish aggregate information on material use cases, overridden outputs, performance drift, customer complaints and subgroup testing without exposing security-sensitive details. Comparative evidence before and after the effective dates would help distinguish paperwork from risk reduction.
Singapore's approach may influence other financial centres because it joins model governance, conduct, cyber, operational resilience and third-party dependency in one risk-proportionate framework. But it remains one jurisdiction's supervisory approach. Confidence should rise only when implementation survives real incidents, independent assurance and cross-border operations—and when customers receive demonstrably fairer and safer services rather than more extensive documentation alone.[1][2]
What this means for people
- Customers could gain stronger protection from biased, inaccurate or insecure financial AI, but the guideline does not yet demonstrate improved outcomes.
- Bank and insurance staff will need training, clear approval paths and authority to challenge AI rather than functioning as an informal safety layer.
- Boards and senior managers acquire explicit oversight duties; vendors remain part of the risk chain without absorbing the institution's accountability.
Global context
Singapore is a major international financial centre, so its supervisory approach will be watched beyond the domestic market. The framework aligns AI with established model, conduct, operational, cyber and third-party risk disciplines, while retaining local accountability. It is not a global standard and should be compared with binding law and supervisory practice in every jurisdiction where a financial group operates.
What the evidence does not yet show
- The guideline is a supervisory standard, not a study of compliance, incident reduction, model performance or customer outcomes.
- It is principles-based and proportionate, leaving institutions substantial judgement in identifying AI, rating materiality and selecting controls.
- Implementation is staged to October 2027 and October 2028, so publication does not show that required systems are operating now.
- The text covers agentic AI at a high level; MAS plans a further consultation on agent-specific risks and controls in 2027.
- The guideline applies within Singapore's regulatory framework and cannot be assumed to satisfy requirements in other jurisdictions.
What to watch next
- MAS supervisory reviews and enforcement or remediation findings after the effective dates.
- The planned 2027 consultation on agentic AI risks, autonomy, tool access and control expectations.
- Evidence that firms can detect embedded and shadow AI and maintain accurate inventories as products change.
- Published data on incidents, provider concentration, drift, fairness, complaints and human overrides.
- How multinational institutions reconcile Singapore requirements with group frameworks and other regulators.
Living evidence record
Impact record IAI-00UG6Z0
Evidence stage
Announced
Confidence
Supported
Reporting basis
Source analysis
Independent or research support
Not yet
Record status
Monitoring
Last checked
7 October 2026
Source trail
2 direct sources across 2 source types.
People impact
Documented in this record.
Uncertainty
Limits and next checks are explicit.
Stages describe the evidence available—not whether a technology is good or bad. See the public method.
Related-source reporting disclosure
This record analyses 2 linked source records around the same underlying development. The extra records add method, date or context, but they do not by themselves constitute independent replication of every performance claim or predicted outcome.
Evidence trail
Sources used for this report
Links checked 7 October 2026
This report is labelled source analysis. We summarise and analyse source material in our own words; company statements remain attributed claims until independently supported. Translated summaries preserve the meaning of the original source and link back to it. Read our editorial standards.
Continue the story
Related reporting
Finance & Business
Are CFOs ready to govern AI investment? IBM finds a wide execution gap
A survey of 1,500 finance leaders across 33 geographies finds broader authority over AI strategy, but only 6% describe finance as transformation-ready. The results map perceptions and associations—not audited returns or proof that AI caused better performance.
5 min · 2 sources
Finance & Business
Should an AI agent be allowed to move a company's money?
Airwallex says its revamped business accounts let approved agents manage liquidity and transfers within rules and approvals. The 30 September release identifies important controls, but provides no independent test, loss data or deployment denominator.
6 min · 2 sources
Finance & Business
Who receives AI productivity gains may matter for inflation, central banker argues
ECB Governing Council member Fabio Panetta said central banks need to understand how AI-driven gains are distributed because the split between wages, profits and prices will shape demand and inflation.
2 min · 1 source
The Impact Brief
Keep the evidence trail, not the noise.
Get the most consequential AI developments with direct sources and clear limits.
Reader commentary
Add evidence, experience or a question
No account is required. Reader notes are published after a brief civility, relevance and safety check; disagreement is welcome.
Explore commentary across the portal →Published reader notes
0No published reader notes yet. You can start the evidence-led discussion above.
Prefer a private correction or response? Contact the newsroom.