Proposed under MAS consultation paper P017-2025, still being finalised. Governance, systems and processes, life-cycle controls, capability and capacity.
Governance Row
AI risk governance for financial institutions regulated by MAS. Every AI use inventoried, risk-assessed, controlled, and inspection-ready, mapped clause by clause to supervisory expectations.

The AI your firm uses is not on any list.
Most firms cannot answer three questions their supervisor will ask: which AI systems are in use, who owns them, and what controls are in place. The answer sits in spreadsheets, emails, and heads. Governance Row replaces all three.
From AI use to inspection-ready: five steps, one motion.
One record. Every step timestamped. Nothing lives in spreadsheets.
Inventory
Log every AI use with owner, source, and description
Assess
Score risk materiality on impact, complexity, and reliance
Control
Apply the controls MAS expects for that risk tier
Evidence
Attach the proof each control requires
Produce
Generate the inspection pack in one motion
Every screen has one job.
Not a spreadsheet with a login. A workspace for the compliance officer, built for the way MAS asks.
Every AI use, on one screen.
A live register of every AI system in the firm: internal builds, vendor AI, staff use of tools like ChatGPT. Owner, source, risk tier, and evidence status visible at a glance.
- Third-party AI detection across vendor tools
- Owner assignment per entry
- Evidence completion tracked live

Risk scoring the way MAS defines it.
Every AI use scored on impact, complexity, and reliance: inherent risk before controls, residual after. Same method every time. Auditable.
- MAS-defined risk dimensions
- Inherent and residual scoring
- Consistent scoring across all AI uses

Every control cites the MAS clause it satisfies.
Each control tied to the exact supervisory expectation. Attach the evidence, and the record is defensible.
- Clause-by-clause mapping to MAS AIRG
- Evidence library per control
- Missing evidence flagged visibly
Senior person accountable for AI risk
A named senior individual is formally accountable for the firm's AI risk.
The document your supervisor asks for. In one motion.
A complete, timestamped record of your AI governance, ready to hand over. Board-ready. Regulator-ready. Every entry backed by the append-only ledger.
- Board-ready summary and detail
- Complete, timestamped output
- Every change tied to the append-only ledger
AI Governance Record: Northpoint Capital Partners
Append-only. Timestamped. Auditable.
Every action in Governance Row (every AI added, every risk score changed, every control attested, every piece of evidence attached) is written to an append-only ledger on the server, timestamped as it happens. No part of the application can edit or remove an entry once written, not even our own admin tools. A supervisor gets a complete record of every governance action, not a summary compiled after the fact.
- 2026-08-03 16:04:22DSEvidence added: AI Governance Policy v2.1
- 2026-07-31 10:12:47DSEvidence added: Q2 2026 Board Minutes
- 2026-07-28 15:38:09WLEvidence added: Model Card, Credit Scoring
- 2026-07-24 11:22:19ROControl mapped: MAS AIRG 4.2 (draft clause, subject to change on finalisation)
- 2026-07-22 09:19:03MLAI use added: Aladdin Copilot
MAS's clauses, mapped to our controls.
Governance Row's control library is grounded in the supervisor's own materials, not a translation of a US or EU framework. Where MAS is thinner than global practice, we strengthen quietly with EU AI Act and NIST conventions.
Published under Project MindForge by MAS and 24 industry partners. Working templates for identification, inventory, GenAI, and life-cycle controls.
MAS's toolkit for assessing fairness, ethics, accountability, and transparency in FS AI/ML systems.
A voluntary industry reference model for real-time safeguards on agentic AI, developed through MAS's BuildFin.ai collaboration (2026). Not a supervisory expectation.
Technology and cyber risk management principles, applied to AI systems and third-party deployments.
Built for the practitioner. Read by the board.
Compliance officers, heads of risk, general counsel. The people who will answer the supervisor's questions. Governance Row gives them:
- A live view of AI risk, not a spreadsheet
- Every control tied to the clause it satisfies
- Evidence attached, not chased
- One-click inspection pack
Chief compliance officers, chief risk officers, boards. The people accountable for what the firm attests. Governance Row gives them:
- A defensible record on demand
- Clear ownership per AI use
- A ledger nothing can rewrite
- Board-ready reporting, always current
Everything the platform covers, in one view.
Mapped clause by clause to MAS supervisory expectations. Inventory, controls, evidence, and a record that stands up on inspection.
Explore the platformThe compliance clock is already running.
Access is opening to a small number of institutions ahead of enforcement. Talk to us about your AI governance before your supervisor asks to see it.