Governance Row
Insights
MAS AI Governance

MAS AI Risk Management Guidelines: What Financial Institutions Actually Need to Do

/8 min read

By now, most financial institutions in Singapore have quietly folded AI into how they work. A research team uses a large language model to summarise filings. A portfolio desk runs a model to flag anomalies. Client-facing staff draft correspondence with a chatbot and tidy it up before it goes out. None of this felt like a governance decision at the time. It felt like using a better tool.

Under MAS's proposed AI Risk Management Guidelines, a financial institution is expected to identify every use of AI, assess each use's risk materiality on impact, complexity and reliance, apply controls proportionate to that rating, hold the board and senior management accountable, and produce evidence of all of it on demand. The Guidelines are proportionate: a firm using AI lightly does less than one running AI in customer-facing decisions, but both are expected to have looked at the question. They are supervisory expectations, issued as consultation paper P017-2025, and not yet final.

The Monetary Authority of Singapore has noticed the same shift, and its posture is changing with it. For years the message was about encouraging responsible innovation. The message now is closer to: you are using AI, so show us how you govern it. The proposed AI Risk Management guidelines are the clearest signal yet of where supervisory expectations are heading.

A fair question before you read further: are these guidelines actually binding? Not yet. They are at consultation stage, which means the detail can still move. But treating "not final" as "not my problem" is a mistake. The direction of travel is unmistakable, it is consistent with what MAS has already done through MindForge and the Veritas work, and the firms that get their house in order now will not be the ones scrambling when a supervisor asks a pointed question. This piece is about what the guidelines expect in practice, and what a firm can reasonably start doing about it.

What the MAS AI Risk Management Guidelines propose

The proposed MAS Guidelines on AI Risk Management (AIRG), issued as consultation paper P017-2025 and still being finalised, set out how MAS expects financial institutions to identify, assess, and manage the risks that come with using AI. They sit alongside the broader body of work MAS has built up: the MindForge framework for generative AI risk, and the Veritas initiative with its FEAT principles (fairness, ethics, accountability, and transparency) for the use of AI and data analytics in finance. These are layers in the full Singapore AI governance stack, six frameworks in all.

The important word is expectations. These are supervisory expectations, not black-letter law. That distinction matters for how you frame the work internally: you are getting ahead of where the regulator is clearly going, not responding to a rule that already carries a penalty. But do not let the softness of "guidelines" lull the firm. When a supervisor engages, "it was only guidance" is not a position anyone wants to be defending.

Who this applies to, and why "we don't really use AI" is the wrong answer

There is a comforting assumption doing the rounds: this is for the big players with data-science teams and AI in the core of what they do. It is not.

If your staff use an off-the-shelf tool to draft, summarise, or analyse, your firm is using AI, and it is in scope. The threshold for "AI governance for financial institutions" is not whether you built something clever. It is whether AI touches your work at all. That catches a great many licensed firms that would not describe themselves as AI-driven: the boutique fund manager, the family office, the firm with no dedicated compliance function where the risk lands on a fund manager, a risk officer, or the tech-risk lead.

This is exactly why the guidelines are built around proportionality rather than a single fixed standard. MAS is not asking a three-person fund using a chatbot to do what a bank running AI-driven credit decisions must do. But it is asking both to have looked at the question honestly.

Proportionality in the MAS AI Guidelines

If there is one idea to take from the guidelines, it is that the response is expected to be proportionate to the risk. This is the part that should reassure a smaller firm and sharpen a larger one.

Proportionality runs on what MAS frames as risk materiality, an assessment of how much the AI actually matters, weighed on impact, complexity, and reliance. A firm using a general-purpose tool for internal drafting, with a person reviewing everything before it is used, sits at one end. A firm embedding AI into a workflow that shapes a customer-affecting decision sits further along. A firm letting AI make those decisions at scale, or act on its own without a human reviewing each case, sits at the far end and carries the heaviest expectations.

The practical upshot: you do not govern all AI the same way. You assess each use, you place it on that spectrum, and you apply controls that fit. A light-touch use earns a light-touch response. That is not a loophole. It is the design.

What the guidelines actually expect you to have

Strip away the framing and a consistent set of expectations emerges. In plain terms, a financial institution is expected to be able to show:

  • An AI inventory: a maintained record of where AI is used across the firm, whether it is a vendor tool, something built in-house, or a public model staff have adopted. You cannot govern what you have not written down.
  • A named owner for each use, so accountability is not diffuse. Someone is answerable for each AI use, and for a small firm that someone is often a founder or the head of risk.
  • A risk assessment per use: the materiality judgement above, recorded, so the tier of controls follows from something, not from a guess.
  • Controls that fit the risk, covering the AI lifecycle: how it is used, what data goes into it, how its output is checked, and what happens when it drifts or fails.
  • Board and senior oversight appropriate to the firm. For a large institution that means real board-level visibility of AI risk. For a two-partner fund it means the partners are demonstrably aware and signing off, proportionate but present.
  • Third-party AI risk management, because using a vendor's model does not transfer the responsibility. Governance of that AI still sits with you.

And running through all of it, the expectation that you can produce evidence of the above when asked. Not a description of your intentions. The record.

The part most firms miss: it is not the framework, it is living it

Here is where most governance efforts quietly fall short, and it is worth being blunt about.

Writing a policy is the easy part. A firm can commission a governance framework, receive a well-crafted document, and file it. On paper the firm now "has AI governance." But a policy that sits in a folder is not what a supervisor inspects. What gets inspected is whether the firm is actually doing the thing: is the AI inventory current, or was it accurate for one afternoon a year ago? Is there evidence that controls were applied, captured as the work happened? Can the firm produce, on demand, the record that proves it?

There is a line going around the AI governance world that gets this exactly right: if you cannot evidence it, it is not governance yet. The framework is the starting line, not the finish. The hard, unglamorous work is in the maintaining, keeping the inventory live, capturing evidence as controls are applied, and being able to hand a regulator a clean, current record rather than a promise.

This is the gap between a consultant's report and a governed firm. The report tells you what good looks like. It does not keep your evidence current, and it is not there the day the question comes.

How to prepare for the MAS AI Guidelines

None of this requires a transformation programme. For most firms, being ready is a matter of doing the basics deliberately, sized to the firm:

Start an AI inventory this week: list every place AI touches the work, even the informal ones. Assign an owner to each. Assess each use for materiality (impact, complexity, reliance) and let that set how much governance it needs. Write a baseline AI use policy that says, in plain terms, what staff may and may not do, that a person reviews AI output before it is relied on, and that confidential or client material does not go into public tools. Make sure the people who run the firm are aware of, and have signed off on, how AI is being used. And from the start, keep the evidence trail, because the record is the thing you will be asked for.

For what that inventory must actually contain, we break it down attribute by attribute in the AI inventory, field by field. For how to weigh each use's materiality, see how to assess an AI use case's risk.

Done proportionately, a smaller firm can stand up a credible baseline in days, not months. The point is to have looked at the question honestly and to be able to show your working.

The bottom line

The regulatory direction is set, even if the final text is not. AI has moved from a technology choice to a governance obligation for financial institutions, and MAS's proposed guidelines are a clear signal of the supervisory expectations to come. Proportionality makes the obligation manageable: you are not being asked to over-engineer. What you are being asked to do is know where AI lives in your firm, govern it in proportion to its risk, and be able to evidence that you did.

That last part, the evidencing, is where governance is won or lost. It is also the reason we built Governance Row: a single platform that maps to MAS's frameworks, lets a firm inventory its AI, work through the controls that apply at its tier, and produce an inspection-ready evidence pack when a regulator asks. The framework matters. Being able to prove you live it matters more.

Frequently asked questions

What do the MAS AI Risk Management Guidelines require a financial institution to do?
In substance, six things: identify where AI is used, keep an AI inventory, assess each use's risk materiality on impact, complexity and reliance, apply controls proportionate to that rating, give the board and senior management clear accountability, and be able to produce evidence on demand. Sections 2 and 3 of the proposed Guidelines set out the governance and assessment expectations, and Section 4 the AI life cycle controls.
Are the MAS AI Risk Management Guidelines mandatory?
Not yet, and not as black-letter law. They are supervisory expectations issued for consultation as paper P017-2025; the consultation closed on 31 January 2026, and MAS told Parliament on 5 August 2026 that they would be finalised soon, with a proposed 12-month transition. Guidelines of this kind set what a supervisor expects to see, so "it was only guidance" is a weak position to defend at inspection.
Who is in scope of the MAS AI Guidelines?
All financial institutions that use AI, sized proportionately. Paragraph 1.5 sets a floor of basic policies for every firm, while firms that use AI as an integrated part of their business are expected to add frameworks, identification, materiality assessment and an inventory; the threshold is whether AI touches the work, not whether the firm built anything. A boutique fund using a chatbot is in scope, at a lighter level than a bank running AI-driven credit decisions.
What is proportionality under the MAS AI Guidelines?
The principle that the response should match the risk. Paragraphs 1.4 to 1.6 ask firms to implement the Guidelines commensurate with the size and nature of their activities and the materiality of each AI use, so a copilot used to assist writing carries lighter expectations than AI making customer-affecting decisions. Proportionality is a floor, not an exemption: even assistive use carries the Annex's basic policies.
Who is accountable for AI risk under the Guidelines?
The board and senior management of the licensed entity. Section 2 of the proposed Guidelines places accountability with them, with the board or a delegated committee responsible for standards and oversight and senior management for implementation (paragraphs 2.4 to 2.6). A parent group's framework may be leveraged to meet the expectations (paragraph 1.3), but the accountability stays with the Singapore entity.
When do the MAS AI Risk Management Guidelines take effect?
After finalisation, which MAS has said is coming. The consultation closed on 31 January 2026, MAS confirmed to Parliament on 5 August 2026 that the Guidelines apply to all AI use cases including agentic AI, and the consultation paper proposes a 12-month transition once they are issued. The identification, inventory and assessment work is already definable, and the record it produces cannot be backdated.

Governance Row helps MAS-regulated financial institutions govern and evidence their use of AI. See how it works.