The Monetary Authority of Singapore (MAS) has published new guidelines that make financial institutions answerable for the risks of every AI system they deploy, including tools built, run or provided by outside vendors.
According to CNA, under the framework released on 7 October, responsibility stays with the institution even when another firm developed or operates the technology.
MAS expects firms to secure adequate assurances from vendors, judge whether external AI fits its intended purpose, and add compensating safeguards where assurance falls short or practical limits get in the way. Where risks still exceed what a firm is willing to tolerate, it should think about restricting, pausing or swapping out the service.
The rules come into force on 7 October 2027. Firms may adopt them gradually, with full compliance due by 7 October 2028.
Institutions will need to oversee AI risk across the organisation as a whole and for each specific application, and to strengthen their capabilities as adoption grows. In practice, this means cataloguing where AI is used, keeping records of those deployments, rating the risk of each application and applying controls in proportion to that risk at every stage of the AI life cycle.
These controls span data governance, testing, human oversight, cybersecurity, monitoring and change management.
MAS wants these safeguards revisited on a regular basis as adoption widens and the technology matures. It flagged the rise of agentic AI, meaning systems that act independently and can use tools, and intends to ask the financial sector in 2027 what further guidance on agentic AI would help.
The regulator observed that AI is advancing quickly and spreading through financial services at greater scale and with more sophistication. This includes systems with more autonomy over producing outputs, making decisions and carrying out actions.
Boards and senior managers must exercise effective oversight of AI risk by defining roles and responsibilities, risk appetite and risk management frameworks. A standalone AI committee is not mandatory where current governance arrangements already deliver adequate oversight and coordination across functions.
The final guidelines follow a public consultation that MAS ran in November 2025. They arrive as scrutiny grows over the dangers of increasingly powerful and autonomous AI models. Singapore is also examining whether additional safeguards are required for high-risk AI applications. Last week, Minister for Digital Development and Information Josephine Teo said protections introduced by frontier AI developers fall short of the risks that more capable systems present.
MAS deputy managing director Ho Hern Shin recognised that AI holds “significant potential” to enhance financial services. However, she stressed that firms must understand and control the risks of more capable systems if they are to capture those gains sustainably.
In its media release, MAS said, “Financial institutions should obtain sufficient assurance from third-party providers, assess whether third-party AI is suitable for their intended use, and apply compensating controls where practical constraints or assurance gaps arise.”
MAS deputy managing director Ho Hern Shin said, “With greater regulatory clarity on financial institutions’ AI usage, financial institutions can innovate with confidence, while maintaining the trust of customers and the resilience of Singapore’s financial system. MAS will continue to work with the industry to advance sound AI risk management practices in a practical and industry-grounded manner.”
Copyright © 2026 RegTech Analyst
Copyright © 2026 RegTech Analyst





