Governance Row
Insights
MAS AI Governance

AI Governance in Singapore: Six Frameworks, One Map

Last updated: /7 min read

Singapore has been building AI governance for finance longer than almost any jurisdiction. What began as four principles in 2018 is now a six-layer stack, and the layers are converging into a single supervisory reality: a licensed firm will be expected to show which AI it uses, how each use is assessed, which controls apply, and the evidence behind all of it. Anyone trying to answer "what governs AI in Singapore's financial sector" today faces six documents published across eight years. This is the map.

AI governance for Singapore's financial institutions runs across six layers: FEAT (2018), Veritas, the Technology Risk Management Guidelines, Project MindForge, the proposed AI Risk Management Guidelines, and SAFR. Only the Technology Risk Management layer is legally binding today; the proposed AI Risk Management Guidelines are the supervisory spine that makes the stack inspectable, and are being finalised. Together the layers converge on one question: can a firm show what AI it runs and how each use is governed?

The six layers of Singapore's AI governance stack for financial institutions.
FrameworkYearRole in the stackBinding today?
FEAT2018Fairness, ethics, accountability and transparency principlesNo
Veritas2019 onwardsAssessment methodology and open-source toolkitNo
TRM2021Technology risk baseline: Guidelines plus legally binding NoticesYes, the Notices
MindForge2023 to 2026Generative AI risk practice and toolkitNo
Proposed AIRG2025Supervisory expectations, the inspectable spineNot yet, being finalised
SAFR2026Voluntary agentic runtime safeguardsNo

FEAT (2018): the principles

The Fairness, Ethics, Accountability and Transparency principles were MAS's first statement on AI in finance, and they remain the foundation the later layers cite. FEAT tells firms what good looks like; it does not tell them what to build.

Veritas (2019 onwards): the methodology

The Veritas consortium turned FEAT into something a firm can run: assessment methodologies and an open-source toolkit for testing AI systems against the principles, developed by MAS with industry. Veritas is how fairness stops being a value and becomes a test.

TRM (2021): the binding baseline

The Technology Risk Management Guidelines, and the legally binding TRM Notices beneath them, are the layer with hard edges. AI does not float free of them: an AI system inside a firm's designated critical systems inherits the Notices' obligations, including one-hour incident notification and four-hour recovery expectations. The TRM layer is in force today.

Project MindForge (2023 to 2026): generative AI, operationalised

MindForge is MAS's consortium work on generative AI risk. Its Phase 2 toolkit, published in January 2026 and developed by MAS with 24 industry firms, includes the AI Risk Management Operationalisation Handbook: the most practical document in the stack, covering roles, use-case ownership, GenAI output controls and vendor deployment patterns.

The proposed AIRG (2025, being finalised): the supervisory spine

The proposed Guidelines on AI Risk Management, consultation paper P017-2025, are where the stack becomes inspectable. They set out MAS's supervisory expectations for every licensed firm: an AI inventory with defined attributes, a risk materiality assessment of every use case on impact, complexity and reliance, controls proportionate to each rating, board accountability, and evidence on demand. The consultation closed on 31 January 2026, and MAS told Parliament on 5 August that the Guidelines apply to all AI use cases, including agentic AI, and will be finalised soon. The consultation paper itself proposes a 12-month transition after finalisation. The AIRG is not yet final. The work it describes is already definable, and the record it expects cannot be backdated.

SAFR (2026): the agentic frontier

Safeguards for Agentic Finance at Runtime, published in July 2026 under MAS's BuildFin.ai initiative with eight industry participants, is a voluntary industry reference model for governing AI agents at the moment they act: agent identity, bounded mandates, deterministic checkpoints, tamper-evident logs. SAFR is not a supervisory expectation. It is the industry's answer to how the AIRG's agentic scope gets implemented, and MAS is supporting it through pilots.

How the layers fit

Read together, the stack has a shape: principles (FEAT), methodology (Veritas), binding baseline (TRM), generative AI practice (MindForge), supervisory expectations (the proposed AIRG), and agentic runtime safeguards (SAFR). A firm does not face six separate compliance projects. It faces one operating question, which the AIRG frames and the others inform: can you show, at any moment, what AI you run and how it is governed?

The distance between Singapore's frameworks and Singapore's practice is the real work. Frameworks published across eight years do not assemble themselves into a single answer inside a firm; the inventory, the per-use assessments and the evidence still have to be built, kept current, and made producible on demand. That is the gap this stack asks every licensed firm to close.

What a licensed firm should take from the map

Three things. First, proportionality is a floor, not an exemption: even firms whose AI use is assistive are expected to hold basic policies, an approved-tools list and clear ownership. Second, the binding layer already applies: TRM obligations do not wait for the AIRG. Third, the work that is identical under the draft and the final text, identification, the inventory, the materiality method, the evidence habit, is the work worth starting now, precisely because it cannot be assembled retroactively.

Governance Row is built for this stack: 68 controls mapped paragraph by paragraph to the AIRG, MindForge, Veritas, SAFR and TRM, from a live AI inventory through to a one-click inspection pack. For the inventory itself, field by field, see our guide to the eleven fields a working inventory needs, with a free template. For the method behind each use case's rating, see how to assess an AI use case's risk.

Frequently asked questions

What frameworks govern AI in Singapore's financial sector?
Six, published across eight years: the FEAT principles (2018), the Veritas assessment methodology and toolkit, the Technology Risk Management Guidelines and Notices, Project MindForge for generative AI, the proposed AI Risk Management Guidelines, and SAFR for agentic runtime safeguards. They range from principles to a binding baseline to supervisory expectations, and increasingly converge rather than compete.
Which of these frameworks are legally binding?
The Technology Risk Management layer is the one with hard edges: the TRM Guidelines sit above legally binding TRM Notices, and AI inside a firm's critical systems inherits those obligations today. FEAT, Veritas, MindForge and SAFR are principles, methodologies or voluntary reference models, and the proposed AI Risk Management Guidelines are supervisory expectations that are not yet final.
Are the proposed MAS AI Risk Management Guidelines in force yet?
Not yet. The consultation closed on 31 January 2026, and MAS told Parliament on 5 August 2026 that the Guidelines apply to all AI use cases, including agentic AI, and would be finalised soon; the consultation paper proposes a 12-month transition after they are issued. Until then they are the clearest signal of supervisory direction rather than a rule that already carries a penalty.
Does MAS AI governance apply to firms that only use third-party or generative AI tools?
Yes. The proposed Guidelines' scope covers AI a firm buys or adopts, not only what it builds, and the definition reaches generative AI and AI agents, so a firm answers for the governance of the vendor and public tools its staff use. Project MindForge specifically addresses generative AI risk, and the proposed Guidelines make third-party AI the firm's responsibility (paragraph 4.11).
What is the difference between the AI Risk Management Guidelines and MindForge?
MindForge is MAS's industry consortium work on generative AI risk, and its Phase 2 Operationalisation Handbook is the most practical, how-to layer in the stack. The proposed AI Risk Management Guidelines are the supervisory expectations that sit above it: an AI inventory, per-use-case materiality assessment, proportionate controls, board accountability and evidence on demand. One shows a firm how to operate generative AI; the other sets what a supervisor will expect to see.