Posted on — Leave a comment

MAS gives Singapore’s financial firms one year to prepare for AI risk rules

Singapore’s financial regulator has set out how banks, insurers, payment companies and other financial institutions should govern artificial intelligence, as AI moves from back-office experiments into systems that can influence customer outcomes, risk decisions and even execution.

The Monetary Authority of Singapore (MAS) has issued its Guidelines on Artificial Intelligence Risk Management, a principles-based framework that will take effect on 7 October 2027. Financial institutions will be allowed to implement the rules in phases, with core expectations around governance and risk management due in 2027, and additional requirements to be met by 7 October 2028.

Also Read: AI governance is moving from promises to proof

The guidelines apply to all financial institutions and all forms of AI technology. MAS is not prescribing a single compliance model. Instead, it is asking firms to calibrate their controls based on how extensively they use AI, the complexity of those systems, and the potential harm if something goes wrong.

That distinction matters. A bank using AI to summarise internal documents does not carry the same risk as one deploying AI to approve loans, detect fraud, price insurance or interact with customers. MAS’s message is that financial firms can innovate, but they must know where AI sits in their operations, who is accountable for it, how it is tested, and what happens when it fails.

“AI has significant potential to improve financial services, from enhancing customer outcomes and strengthening risk management to improving productivity and enabling new products and services,” said Ho Hern Shin, Deputy Managing Director at MAS. “Realising these benefits sustainably requires financial institutions to understand and manage the risks that come with increasingly capable AI systems.”

A risk-based rulebook, not a blanket ban

The MAS guidelines follow a public consultation held in November 2025, during which respondents supported a principles-based and risk-proportionate approach. In plain terms, this means the regulator is not trying to stop financial institutions from using AI, nor is it asking every firm to build the same governance machinery regardless of size or risk.

Financial institutions may use their existing governance structures if those structures provide adequate oversight and cross-functional coordination. They do not need to create a dedicated AI committee simply to satisfy MAS. This will be welcomed by smaller firms and fintechs, which often lack the resources of large banks but still use AI in customer support, compliance, data analysis or product personalisation.

At the same time, MAS is making clear that AI cannot be treated as a side project controlled only by technology teams. Boards and senior management are expected to provide effective oversight, set clear roles and responsibilities, define risk appetite, and ensure policies and procedures are in place.

Also Read: The compliance paradox: More checks, more fraud

This reflects a broader shift in how regulators view AI. Early AI governance discussions often focused on ethical principles such as fairness, explainability and accountability. Those still matter, but the rise of generative AI and agentic AI systems (tools that can generate outputs, make decisions or take actions with greater autonomy) has made operational resilience, cyber risk, third-party dependency and model failure much more urgent.

What financial institutions must do

The MAS framework expects firms to manage AI risks at two levels: across the enterprise and at the level of individual use cases.

At the enterprise level, financial institutions will need to understand their overall AI exposure. This means identifying where AI is being used, maintaining inventories with an appropriate level of detail, and assessing which applications are material from a risk perspective.

At the use case level, firms must apply controls across the AI life cycle. These include data governance, testing, human oversight, cybersecurity, monitoring and change management. The life-cycle approach is important because AI risk does not end once a model is launched. Models can degrade over time, behave differently as data changes, or produce unexpected results when integrated into new workflows.

The guidelines also cover third-party AI, one of the most difficult issues facing financial institutions. Many firms do not build their own AI systems from scratch. They rely on cloud providers, software vendors, embedded AI features in enterprise tools, and external model providers. MAS says financial institutions remain accountable for AI used in the services they deliver, even when that AI is developed, operated or supplied by third parties.

Firms must therefore obtain sufficient assurance from providers, assess whether third-party AI is suitable for their intended use, and apply compensating controls where there are gaps. If risks cannot be brought within the institution’s risk appetite, MAS says the firm should consider limiting, suspending or replacing the third-party AI service.

That is a notable signal to the market. As banks and fintechs race to integrate AI copilots, fraud detection tools and automated customer engagement systems, vendor due diligence will become more demanding. AI procurement will no longer be only a technology or commercial decision; it will become a regulatory and risk management issue.

Why this matters for Southeast Asia’s fintech sector

Although the guidelines apply to Singapore-regulated financial institutions, they are likely to influence AI governance beyond the city-state. Singapore remains a regional base for many banks, insurers, payment firms, digital asset companies and fintech startups operating across Southeast Asia. When MAS raises supervisory expectations, regional compliance teams often take notice.

Also Read: The EU called ChatGPT a search engine. SEA’s AI startups should worry about what comes next

This is especially relevant because Southeast Asia’s financial services market is highly digital but unevenly regulated. Digital banks, e-wallets, buy-now-pay-later providers, remittance platforms and lending startups serve large underbanked populations, often using alternative data and automated decisioning to manage cost and scale. AI can improve fraud detection, credit scoring and customer service, but it can also create risks around bias, opaque decisions, data misuse and over-automation.

For startups, the immediate challenge will be documentation and discipline. Many young companies use AI tools informally across product, engineering, compliance and support functions. The MAS guidelines point towards a future in which financial startups will need a clearer inventory of AI use, stronger vendor controls, and evidence that higher-risk systems have been tested and monitored.

This could raise compliance costs, particularly for smaller fintechs. But it may also give serious players a clearer path to enterprise partnerships and regulatory trust. In financial services, the ability to demonstrate responsible AI governance could become a competitive advantage, especially when selling to banks or expanding into regulated markets.

The next frontier: agentic AI

MAS also flagged agentic AI as an area for further attention. Agentic systems can operate with more autonomy, access tools and execute tasks across software environments. In finance, that could eventually mean AI agents that help with portfolio management, compliance investigations, customer servicing, treasury operations or claims processing.

The upside is productivity. The risk is that autonomous systems may take actions that are hard to predict, explain or reverse. In regulated financial markets, small failures can cascade quickly if they affect transactions, customer decisions or market behaviour.

MAS plans to consult the financial sector in 2027 on what additional guidance on agentic AI would be useful. This suggests the current guidelines are not the final word, but a foundation on which more specific expectations may be built.

Also Read: SEA’s insurers face a new question: what happens when customers have agents?

The phased timeline gives financial institutions room to prepare. But the direction is clear: AI adoption in finance is moving from experimentation to supervision. Singapore wants firms to use the technology, but not at the expense of customer trust or financial stability.

For Southeast Asia’s financial sector, that may become the defining balance of the next few years: how to capture AI’s productivity gains while proving that automated systems can be governed as carefully as any other part of the financial infrastructure.

The post MAS gives Singapore’s financial firms one year to prepare for AI risk rules appeared first on e27.

Leave a Reply

Your email address will not be published. Required fields are marked *