The Monetary Authority of Singapore issued its first Guidelines on Artificial Intelligence Risk Management for Financial Institutions, requiring independent review of AI projects before deployment. The regulator warns that generative and agentic AI pose heightened risks due to complexity and uncertainty. Financial institutions must maintain AI inventories, monitor third-party AI suppliers, and develop contingency plans for high-risk applications.

The Monetary Authority of Singapore has introduced comprehensive regulations requiring financial institutions to subject all AI use cases to independent review before deployment, marking a significant shift in how the city-state's finance sector approaches AI risk management.

New regulatory framework targets AI complexity

The Monetary Authority of Singapore issued its inaugural Guidelines on Artificial Intelligence Risk Management for Financial Institutions

1

, warning that AI's complexity and probabilistic nature can lead to greater uncertainty and more biased behavior that is harder to identify compared to simpler methods. The regulator, which serves as both Singapore's central bank and main financial regulator, acknowledges that while AI can improve performance across business and functional areas, its inherent risks demand stricter oversight.

Source: The Register

Source: The Register

The guidelines specifically highlight concerns about generative and agentic AI. "The greater complexity of Generative AI gives rise to even greater uncertainty and unexpected behaviour compared to AI," the MAS warns, citing data noise inherent in training data, training data that may not be representative, or scenarios not present in training data as sources of risk

2

. The regulator fears agentic AI could further amplify these risks, pushing financial institutions toward more rigorous evaluation processes.

Independent review of AI projects becomes mandatory

Prior to deployment, financial institutions must subject AI use cases, including underlying systems or models, to reviews by parties not involved in their development to ensure relevant controls have been adhered to

1

. The MAS also requires technology and cybersecurity reviews to ensure AI can be deployed into production environments in a controlled and secure manner. This independent review of AI projects represents a critical checkpoint designed to catch potential issues before they affect customers or market stability.

The regulatory framework expects board and senior management to expand their risk management frameworks to cover AI comprehensively. Given the uncertainties associated with AI, their dynamic nature, and the potential for model staleness and performance degradation due to data or model drifts over time, ongoing monitoring is critical to ensure deployed AI operates as intended and remains fit for purpose

1

.

Accountability for AI-related risks extends to third parties

Financial institutions remain accountable for AI used in the services they deliver, including AI developed, operated or provided by third-party AI suppliers

2

. The MAS requires FIs to obtain sufficient assurance from third-party providers, assess whether third-party AI is suitable for their intended use, and apply compensating controls where practical constraints or assurance gaps arise. If risks cannot be brought within the institution's risk appetite, it should consider limiting, suspending or replacing the use of the third-party AI service.

The regulator does not see failings by third-party AI suppliers as an acceptable excuse for AI problems at entities it regulates. Financial institutions must monitor their suppliers' products and services to ensure they remain stable and secure, maintaining ongoing vigilance even after initial deployment approval.

Contingency plans for high-risk AI applications required

The MAS mandates that financial institutions maintain up-to-date inventories of all AI used in their business. Where third-party services use AI without revealing it, institutions need to find ways to manage the risk of unknowable AI contributions. Banks should also develop contingency plans for high-risk AI applications, including alternative systems or manual processes, to ensure business continuity in case of AI failure or unexpected behavior

2

.

These requirements reflect the regulator's concern about bias, performance degradation, and the potential for AI systems to encounter scenarios outside their training parameters. The guidelines come into force on October 7, 2027

1

, giving FinTech players and traditional financial institutions time to build robust AI risk management capabilities and establish the necessary governance structures to comply with the new regulatory framework.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved