Insights
The definitive guide

AI Governance and MAS: what every financial institution now has to prove

The Monetary Authority of Singapore (MAS) is finalising how financial institutions must govern their use of AI. It applies to firms of every size, to agentic AI, and to uses as ordinary as a chatbot or a summary. Here is what it asks, and what being ready actually means.

By Governance Row//10 min read
01 / The rules are being finalised now

The rules are being finalised now

Singapore is finalising its supervisory expectations for how financial institutions govern artificial intelligence. This is not a distant consultation. The regulator has told Parliament the guidelines will be finalised soon, and that they will cover agentic AI, the systems that act on their own.

A transition period follows. But the clock starts on publication, and for any firm with real AI in production it is a build window, not a grace period. The firms that treat this as a problem for 2027 will find the transition is not long enough to start from scratch.

  1. Consultation closed
    The proposal is set. The shape is known.
  2. Finalisation
    Imminent. This is where the clock starts.
  3. Transition period
    Time to build, not time to wait.
  4. Expectation in force
    The record is expected to already exist.

The clock starts on publication, not at the end of the transition

02 / What governance means

What governance actually means here

Most firms believe they already govern their AI. They have a policy. They have a list of the tools they use. Measured against these expectations, that is not governance. A policy and a spreadsheet describe an intention. Governance is the ongoing, evidenced record that the intention is being carried out.

The regulator’s question is never “do you have a policy.” It is “show me how you govern this, and prove it has been operating.” The distinction that catches firms out is between having controls and being able to evidence them, over time, with a name and a date attached.

What firms think governance is
A policy, written and filed.
A list of the tools the firm uses.

A statement of intention. It describes what the firm means to do.

What the regulator expects
A living record, kept current.
Each control shown to have operated.
Every entry with a name and a date.

Not “do you have a policy,” but “show me how you govern this, and prove it has been operating.”

03 / It applies to you, and to each use

The scope trap: it applies to you, and to each use

Two assumptions leave firms exposed. The first is that this is only for the big AI users. It is not. There is a baseline expectation for every firm that uses AI at all, including a firm whose only use is staff running a general AI tool to summarise a document. There is no size exemption.

The second assumption is subtler: that a firm sets one overall AI risk level. It does not work that way. The expectations apply per use case. A single firm can run a low-risk internal tool and a high-risk customer-facing system at the same time, and each is governed on its own terms. The depth of what is required follows each individual use, not the firm as a whole.

One licensed firm
Summarising a document
Staff run a general AI tool to condense or draft.
Light obligation
Flagging for review
A model surfaces items for a person to check.
Moderate obligation
Customer-facing decisions
AI shapes an outcome with little human hand.
Heavy obligation

One firm. Several uses. Each governed on its own terms, not by a single firm-wide setting

04 / What a firm must do

What a firm is actually expected to do

Strip away the language and the expectations describe a single, continuous lifecycle. It is the same loop whether a firm has one AI use or a hundred, and it is what a supervisor expects to see running.

  1. 01Identify
  2. 02Inventory
  3. 03Assess
  4. 04Control
  5. 05Evidence
  6. 06Oversee
  7. Re-assess

A cycle, not a project. It returns to assessment as the AI and its risks change

01

Identify every place AI is used, including inside vendor products and staff use of general tools.

02

Inventory those uses in a living record: what each is, the data it uses, who owns its risk, its status, and more, kept current as things change.

03

Assess how material each use is, its potential impact, its complexity, and how far the firm relies on it, both before and after controls.

04

Control in proportion to that materiality: light where the risk is low, rigorous where it is high.

05

Evidence every control, so the record shows not just that a control exists but that it has operated.

06

Oversee it at board and senior-management level, as a standing responsibility.

07

Re-assess on a cycle, because AI and the risks it carries do not stand still.

What a living inventory captures, for each AI use
Purpose
Data it uses
Risk owner
Lifecycle status
Materiality
Model or vendor
Human oversight
Controls applied
Last reviewed
Dependencies

Illustrative of the kinds of things recorded, not a fixed list

05 / The obligation scales

The obligation scales with the use

This is where proportionality matters, and where firms can take some relief. A firm using AI only for internal, low-stakes work carries a genuinely light set of obligations, the baseline every firm meets. A firm running customer-facing, autonomous, or decision-making AI carries a substantially heavier set, because the potential for harm is greater.

The same firm may sit at both ends at once, use by use. The system is demanding where the risk is real and light where it is not, which is precisely what makes it achievable even for a firm without a large compliance function.

A light use
Internal, low-stakes work.

A genuinely light set of obligations. The baseline every firm meets.

A heavy use
Customer-facing, autonomous, decision-affecting.

A substantially heavier set, because the potential for harm is greater.

The same firm may sit at both ends at once, use by use. Demanding where the risk is real, light where it is not

06 / Managers and directors

Two seats at the table: managers and directors

Accountability and oversight are different duties, and both matter. Accountability sits with the manager, the licensed entity that runs the AI. It answers, in its own name, for how that AI is governed, and it cannot delegate that answer to a vendor or a technology team.

Oversight sits with the board and its directors, whose duty is to ensure the manager can demonstrate it governs its AI, in the same way a board already relies on management to evidence other regulatory obligations.

The manager
Accountability

The licensed entity that runs the AI answers, in its own name, for how it is governed. That answer cannot be delegated to a vendor or a technology team.

The shared record
One governance record
ProducedReviewed
The board
Oversight

Directors ensure the manager can demonstrate it governs its AI, the same way a board relies on management to evidence any other regulatory obligation.

For a fund, where the vehicle itself is not the licensed entity, the director’s lever is precisely this: asking the manager to show the record. The two are the same governance, seen from two seats.

07 / Why global frameworks fall short

Why “we already follow US or EU frameworks” is not enough

A common and dangerous assumption is that following a global AI framework covers a Singapore-licensed firm. It does not. Voluntary frameworks are, by definition, not mandatory, and adoption is uneven. Risk-tiered regimes elsewhere ask a different question from a use-based regime.

What matters for a Singapore-regulated entity is the expectation it actually answers to, applied to the licensed entity itself. When the regulator inspects, it asks the firm here, not its parent or its overseas framework.

How AI governance around MAS compares with voluntary global frameworks and risk-tiered regimes elsewhere.
Singapore's approachVoluntary global frameworksRisk-tiered regimes elsewhere
Does it apply to you?Directly, to your Singapore-licensed entity, and it is what your supervisor asks about.Only if you choose to adopt it. Adoption is optional and uneven.To entities in that jurisdiction, not to your licensed entity here.
Who is in scopeEvery licensed firm that uses AI at all.Whoever opts in, to the extent they opt in.Entities that fall inside that jurisdiction's categories.
How it scopesPer use case, proportionate to each use.By broad principle, self-directed.By fixed risk categories set in advance.
Covers agentic AI?Yes, explicitly, including AI that acts on its own.Varies, and often lagging.Only where the fixed categories happen to reach it.
08 / When the regulator asks

The moment the regulator asks

Everything comes to one moment: the regulator asks a firm to show how it governs its AI. A firm that has built the record continuously produces it in minutes, dated, attributable, complete. A firm that assembles it the week it is asked produces something that reads as exactly that: a record with no history, which invites deeper scrutiny.

The record cannot be backdated. This is the single reason the work starts now rather than when the expectation is in force. Not because the deadline is close, but because a credible record takes time to accumulate.

The continuous record
Feb
Apr
Jun
Aug
Oct
Dec

Built over time. Dated, attributable, complete. Produced in minutes.

The scramble
All dated the same week

Assembled the week it is asked for. A record with no history reads as exactly that, and invites deeper scrutiny.

09 / What being ready looks like

What being ready looks like

A firm is ready when every AI use is identified and inventoried, each is assessed for its materiality, controls proportionate to each are in place and evidenced, the board can see the position, and the whole record is current and produceable on request.

Ready firms enter the transition already holding this. Everyone else spends the transition catching up.

Every AI use is identified and inventoried.
Each use is assessed for how material it is.
Controls proportionate to each are in place and evidenced.
The board can see the position at any time.
The whole record is current and produceable on request.
10 / Common questions

Frequently asked questions

Does MAS's AI governance apply to smaller financial institutions?
Yes. There is a baseline expectation for every financial institution that uses AI at all, including a firm whose only use is staff running a general AI tool to summarise a document. There is no size exemption. What changes with a firm's size and sophistication is the depth of what is required, not whether the expectation applies.
Does it cover generative and agentic AI?
Yes. The expectations are intended to cover the use of AI broadly, including generative AI and agentic AI, the systems that can act on their own. MAS has been explicit that agentic AI is in scope, which is one reason a firm cannot treat an older, narrower definition of AI as the boundary of its obligations.
Is following a US or EU AI framework enough for a Singapore-licensed firm?
No. Voluntary global frameworks are not mandatory and adoption is uneven, and a risk-tiered regime abroad answers a different question from a use-based one. What matters for a Singapore-regulated entity is the expectation applied to the licensed entity itself. When the regulator inspects, it asks the firm here, not its parent or its overseas framework.
Who is accountable for AI governance, the board or management?
Both, in different ways. Accountability sits with the manager, the licensed entity that runs the AI, which answers in its own name and cannot delegate that answer to a vendor or a technology team. Oversight sits with the board, whose duty is to ensure the manager can demonstrate it governs its AI, in the same way it relies on management to evidence any other regulatory obligation.
When do the expectations take effect, and how long is the transition?
MAS has said the guidelines will be finalised soon, and a transition period is expected to follow publication. The practical point is that the clock starts on publication rather than at the end of the transition, because a credible governance record accumulates over time and cannot be assembled retroactively. A firm with real AI in production is best treating the period as a build window.
What does a firm actually need to be able to show?
Every AI use identified and inventoried, each use assessed for how material it is, controls proportionate to that materiality that are not only in place but evidenced as having operated, oversight at board and senior-management level, and a record that is current and can be produced on request. In short, not just that controls exist, but that they have been working, with a name and a date attached.

The firms that start now enter the transition ready.

If you are working out what these expectations mean for your firm, we are glad to help you think it through.