AI Regulation Tracker · MAS · Circular

What does MAS Circular MAS/TCRS/2025/06 say about AI in banking?

Published Sep 18, 2025 · Last reviewed Oct 5, 2026

MAS circular MAS/TCRS/2025/06, an information paper dated September 2025 and issued on 18 September 2025, examines how deepfakes threaten financial institutions and what mitigating measures they can take. It covers three areas: defeating biometric authentication, social engineering and impersonation scams, and misinformation and disinformation, and it lists five risk types (market, cyber, fraud, regulatory and reputational). It applies to FIs including banks as awareness guidance, and extends the deepfake section of MAS's July 2024 generative AI cyber paper. A bank should check that its biometric authentication has liveness detection and that high-risk transactions need additional verification.

OFFICIAL TEXT: mas.gov.sg ↗ · IN FORCE · MAS

DocumentMAS Circular MAS/TCRS/2025/06 — Cyber Risks Associated with Deepfakes (Information Paper)
Issued byMonetary Authority of Singapore
TypeCircular
StatusIn force
PublishedSep 18, 2025
Applies toFinancial institutions in Singapore (the circular is addressed to FIs), which includes banks; an awareness paper describing threats and mitigating measures, not a binding rule
Official sourcemas.gov.sg ↗
Use casesFraud detection · Cybersecurity · AML / KYC · Generative & agentic AI

What are the key points of MAS Circular MAS/TCRS/2025/06?

  • Section 2 lists five risk types from deepfakes: market, cyber, fraud, regulatory (for example falsified identities in recruitment by actors from sanctioned countries) and reputational.
  • Section 2.1 addresses defeating biometric authentication, with recent incidents and possible mitigating measures.
  • Section 2.2 addresses social engineering and impersonation scams, with incidents and mitigation.
  • Section 2.3 addresses misinformation and disinformation, including fabricated executive statements and market-moving content.
  • Section 3 concludes that FIs should assess deepfake risks to their own operations and customer interactions and keep monitoring both generation and detection technologies.
  • The conclusion names liveness detection, additional verification for high-risk transactions, industry information sharing, awareness campaigns, real-time deepfake detection in communication channels and endpoint devices, and regularly updated and tested incident response plans.
  • Appendix A summarises threats, impact and mitigating measures; the paper credits the Association of Banks in Singapore Standing Committee on Cyber Security and MAS's Cyber and Technology Resilience Experts panel for input.

What did MAS Circular MAS/TCRS/2025/06 change for banks?

It expands the deepfake material in MAS's July 2024 paper into a standalone treatment aimed at the threats most relevant to banks: biometric onboarding and authentication, impersonation of executives and customers, and disinformation affecting markets and reputation.

What does MAS/TCRS/2025/06 expect banks to do about deepfake risks?

MAS information paper MAS/TCRS/2025/06, 'Cyber Risks Associated with Deepfakes', of September 2025 says financial institutions should assess the risks deepfakes pose to their own operations and customer interactions and implement appropriate defences. It identifies three areas of impact (defeating biometric authentication, social engineering and impersonation scams, and misinformation and disinformation) across five risk types (market, cyber, fraud, regulatory and reputational). Its conclusion names liveness detection, additional verification for high-risk transactions, information sharing, awareness campaigns, real-time deepfake detection integrated into communication channels and endpoint devices, and incident response plans that are regularly updated and tested. It is guidance rather than a binding rule.

RuleAuthorityWhat it requiresApplies
Section 2 — Five risk typesMASAssess market, cyber, fraud, regulatory and reputational risks from deepfakes against the institution's own operations and customer interactions.Awareness guidance, 18 September 2025
Section 2.1 — Biometric authenticationMASCheck identification documents and digital content for tampering during onboarding and verification, and harden biometric authentication against deepfakes, including liveness detection.Awareness guidance, 18 September 2025
Section 2.2 — Social engineering and impersonationMASRun staff deepfake simulations and customer awareness campaigns, and train staff to challenge suspected impersonation by verifying through a separate, trusted communication channel.Awareness guidance, 18 September 2025
Section 2.3 — Misinformation and disinformationMASMonitor digital channels for deepfake-based brand abuse and executive impersonation, with escalation and takedown procedures and authenticated channels for public clarifications.Awareness guidance, 18 September 2025
Section 3 — Detection and responseMASMonitor advances in deepfake generation and detection, deploy detection tools in communication channels and endpoints where suitable, share information with the industry and keep incident response plans updated and tested.Awareness guidance, 18 September 2025

The paper complements MAS's July 2024 generative AI cyber paper and is cited in MAS's November 2025 consultation paper as the paper covering AI used against FIs by third parties, which the proposed AI risk management Guidelines exclude from their scope.

For banks the practical overlap is with onboarding and know-your-customer controls, payment authorisation and fraud operations, since the same deepfake techniques are used to defeat biometric checks and to impersonate customers or executives.

WHAT THIS MEANS IN PRACTICE

  • Test onboarding and authentication flows against deepfake and injection attacks.
  • Verify unusual or urgent payment and information requests through a separate, trusted channel (the paper gives the example of confirming a video call by another medium).
  • Include deepfake impersonation of executives in tabletop exercises.
  • Join industry information-sharing channels on deepfake incidents.
  • Review the Appendix A threat and mitigation table against current controls.

Does MAS/TCRS/2025/06 apply to banks?

Yes. It is addressed to financial institutions and its examples and measures, such as biometric authentication and high-risk transaction verification, are directed at banks and other FIs. It is an information paper and not a binding notice.

What does MAS recommend against deepfakes?

The conclusion lists liveness detection, additional verification for high-risk transactions, industry information sharing, awareness campaigns, real-time deepfake detection tools and regularly updated and tested incident response plans.

Is MAS/TCRS/2025/06 binding?

No. It is an information paper that provides an overview of threats and possible mitigating measures, and FIs should assess the risks to their own operations and implement appropriate defensive measures.

DateDocumentStatus
Mar 20, 2026MAS MindForge AI Risk Management Toolkit — AI Risk Management: Operationalisation Handbook (Project MindForge AI Risk Management Toolkit)Final
Nov 13, 2025MAS Consultation Paper P017-2025 (AI Risk Management Guidelines) — Consultation Paper on Guidelines on Artificial Intelligence Risk ManagementProposed
Dec 5, 2024MAS AI Model Risk Management information paper — Artificial Intelligence Model Risk Management: Observations from a Thematic Review (Information Paper)Final
Jul 30, 2024MAS Circular MAS/TCRS/2024/05 — Cyber Risks Associated with Generative Artificial Intelligence (Information Paper)In force
Nov 12, 2018MAS FEAT Principles — Principles to Promote Fairness, Ethics, Accountability and Transparency (FEAT) in the Use of Artificial Intelligence and Data Analytics in Singapore's Financial SectorIn force
Sep 3, 2026FIN-2026-Alert005 (Digital Asset Investment Scam Centers) — FinCEN Alert on Money Laundering Activity Associated with Digital Asset Investment Scam CentersIn force

Follow every document these regulators publish

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning