AI governance for Singapore's financial institutions runs across six layers: FEAT (2018), Veritas, the Technology Risk Management Guidelines, Project MindForge, the proposed AI Risk Management Guidelines, and SAFR. Only the Technology Risk Management layer is legally binding today; the proposed AI Risk Management Guidelines are the supervisory spine that makes the stack inspectable, and are being finalised. Together the layers converge on one question: can a firm show what AI it runs and how each use is governed?
| Framework | Year | Role in the stack | Binding today? |
|---|---|---|---|
| FEAT | 2018 | Fairness, ethics, accountability and transparency principles | No |
| Veritas | 2019 onwards | Assessment methodology and open-source toolkit | No |
| TRM | 2021 | Technology risk baseline: Guidelines plus legally binding Notices | Yes, the Notices |
| MindForge | 2023 to 2026 | Generative AI risk practice and toolkit | No |
| Proposed AIRG | 2025 | Supervisory expectations, the inspectable spine | Not yet, being finalised |
| SAFR | 2026 | Voluntary agentic runtime safeguards | No |
FEAT (2018): the principles
The Fairness, Ethics, Accountability and Transparency principles were MAS's first statement on AI in finance, and they remain the foundation the later layers cite. FEAT tells firms what good looks like; it does not tell them what to build.
Veritas (2019 onwards): the methodology
The Veritas consortium turned FEAT into something a firm can run: assessment methodologies and an open-source toolkit for testing AI systems against the principles, developed by MAS with industry. Veritas is how fairness stops being a value and becomes a test.
TRM (2021): the binding baseline
The Technology Risk Management Guidelines, and the legally binding TRM Notices beneath them, are the layer with hard edges. AI does not float free of them: an AI system inside a firm's designated critical systems inherits the Notices' obligations, including one-hour incident notification and four-hour recovery expectations. The TRM layer is in force today.
Project MindForge (2023 to 2026): generative AI, operationalised
MindForge is MAS's consortium work on generative AI risk. Its Phase 2 toolkit, published in January 2026 and developed by MAS with 24 industry firms, includes the AI Risk Management Operationalisation Handbook: the most practical document in the stack, covering roles, use-case ownership, GenAI output controls and vendor deployment patterns.
The proposed AIRG (2025, being finalised): the supervisory spine
The proposed Guidelines on AI Risk Management, consultation paper P017-2025, are where the stack becomes inspectable. They set out MAS's supervisory expectations for every licensed firm: an AI inventory with defined attributes, a risk materiality assessment of every use case on impact, complexity and reliance, controls proportionate to each rating, board accountability, and evidence on demand. The consultation closed on 31 January 2026, and MAS told Parliament on 5 August that the Guidelines apply to all AI use cases, including agentic AI, and will be finalised soon. The consultation paper itself proposes a 12-month transition after finalisation. The AIRG is not yet final. The work it describes is already definable, and the record it expects cannot be backdated.
SAFR (2026): the agentic frontier
Safeguards for Agentic Finance at Runtime, published in July 2026 under MAS's BuildFin.ai initiative with eight industry participants, is a voluntary industry reference model for governing AI agents at the moment they act: agent identity, bounded mandates, deterministic checkpoints, tamper-evident logs. SAFR is not a supervisory expectation. It is the industry's answer to how the AIRG's agentic scope gets implemented, and MAS is supporting it through pilots.
How the layers fit
Read together, the stack has a shape: principles (FEAT), methodology (Veritas), binding baseline (TRM), generative AI practice (MindForge), supervisory expectations (the proposed AIRG), and agentic runtime safeguards (SAFR). A firm does not face six separate compliance projects. It faces one operating question, which the AIRG frames and the others inform: can you show, at any moment, what AI you run and how it is governed?
The distance between Singapore's frameworks and Singapore's practice is the real work. Frameworks published across eight years do not assemble themselves into a single answer inside a firm; the inventory, the per-use assessments and the evidence still have to be built, kept current, and made producible on demand. That is the gap this stack asks every licensed firm to close.
What a licensed firm should take from the map
Three things. First, proportionality is a floor, not an exemption: even firms whose AI use is assistive are expected to hold basic policies, an approved-tools list and clear ownership. Second, the binding layer already applies: TRM obligations do not wait for the AIRG. Third, the work that is identical under the draft and the final text, identification, the inventory, the materiality method, the evidence habit, is the work worth starting now, precisely because it cannot be assembled retroactively.
Governance Row is built for this stack: 68 controls mapped paragraph by paragraph to the AIRG, MindForge, Veritas, SAFR and TRM, from a live AI inventory through to a one-click inspection pack. For the inventory itself, field by field, see our guide to the eleven fields a working inventory needs, with a free template. For the method behind each use case's rating, see how to assess an AI use case's risk.