Expectations include accountability for managing risks from third-party artificial intelligence use
[SINGAPORE] The Monetary Authority of Singapore (MAS) has issued new guidelines spelling out supervisory expectations for financial institutions to manage risks arising from artificial intelligence use.
The Guidelines on Artificial Intelligence Risk Management will take effect on Oct 7, 2027, and apply to all financial institutions and all forms of AI technologies.
The central bank noted in a media statement on Wednesday (Oct 7) that financial regulators and international bodies are “highlighting the need to manage AI risks effectively while enabling firms to realise the benefits of adoption”.
The guidelines follow a public consultation, where respondents expressed “strong support” for a principles-based and risk-proportionate approach, said MAS.
Meanwhile, financial institutions should assess how to best meet these expectations based on the nature and scale of their AI use, it added.
They may implement the guidelines in phases, and should meet the expectations set out in Sections 3 to 4 from Oct 7, 2027, and Sections 5 and 6 by Oct 7, 2028.
The release of the guidelines follows the formation of the AI-Driven Cyber and Technology Risk Taskforce in July by MAS and the Association of Banks in Singapore to strengthen collective cyber and technology resilience in response to the emerging risks posed by frontier AI models.
Key expectations #
The guidelines laid out four key expectations for financial institutions to manage risks arising from AI use.
First, the board and senior management of financial institutions should provide effective oversight of AI risks with clear accountabilities. This includes setting clear risk appetite, management frameworks, policies and procedures.
MAS noted that existing governance structures may be used where they provide adequate oversight and cross-functional coordination, and financial institutions need not establish a dedicated AI committee solely to meet this expectation.
Second, financial institutions should identify, assess and manage AI risks across the AI life cycle and apply proportionate controls.
These controls, which should be reviewed regularly, include data governance, testing, human oversight, cybersecurity, monitoring and change management.
MAS said it intends to further consult the financial sector in 2027 on what additional guidance on agentic AI would be useful.
Third, financial institutions should manage the risks from third-party AI use. This includes remaining accountable for AI used in the services they deliver, including AI developed, operated or provided by third parties.
If the risks cannot be brought within the institution’s risk appetite, it should consider limiting, suspending or replacing the use of the third-party AI service, noted MAS. Lastly, financial institutions should apply the guidelines in a risk-proportionate manner, meaning that the extent and sophistication of controls should depend on its risk exposure.
Ho Hern Shin, deputy managing director at MAS, noted that AI has “significant potential” to improve financial services.
“Realising these benefits sustainably requires financial institutions to understand and manage the risks that come with increasingly capable AI systems,” she said.
“With greater regulatory clarity on financial institutions’ AI usage, financial institutions can innovate with confidence, while maintaining the trust of customers and the resilience of Singapore’s financial system,” she added.
Decoding Asia newsletter: your guide to navigating Asia in a new global order. Sign up here to get Decoding Asia newsletter. Delivered to your inbox. Free.
Copyright SPH Media. All rights reserved.