MAS circular MAS/TCRS/2025/06, an information paper dated September 2025 and issued on 18 September 2025, examines how deepfakes threaten financial institutions and what mitigating measures they can take. It covers three areas: defeating biometric authentication, social engineering and impersonation scams, and misinformation and disinformation, and it lists five risk types (market, cyber, fraud, regulatory and reputational). It applies to FIs including banks as awareness guidance, and extends the deepfake section of MAS's July 2024 generative AI cyber paper. A bank should check that its biometric authentication has liveness detection and that high-risk transactions need additional verification.
OFFICIAL TEXT: mas.gov.sg ↗ · IN FORCE · MAS
| Document | MAS Circular MAS/TCRS/2025/06 — Cyber Risks Associated with Deepfakes (Information Paper) |
| Issued by | Monetary Authority of Singapore |
| Type | Circular |
| Status | In force |
| Published | Sep 18, 2025 |
| Applies to | Financial institutions in Singapore (the circular is addressed to FIs), which includes banks; an awareness paper describing threats and mitigating measures, not a binding rule |
| Official source | mas.gov.sg ↗ |
| Use cases | Fraud detection · Cybersecurity · AML / KYC · Generative & agentic AI |
What are the key points of MAS Circular MAS/TCRS/2025/06?
- Section 2 lists five risk types from deepfakes: market, cyber, fraud, regulatory (for example falsified identities in recruitment by actors from sanctioned countries) and reputational.
- Section 2.1 addresses defeating biometric authentication, with recent incidents and possible mitigating measures.
- Section 2.2 addresses social engineering and impersonation scams, with incidents and mitigation.
- Section 2.3 addresses misinformation and disinformation, including fabricated executive statements and market-moving content.
- Section 3 concludes that FIs should assess deepfake risks to their own operations and customer interactions and keep monitoring both generation and detection technologies.
- The conclusion names liveness detection, additional verification for high-risk transactions, industry information sharing, awareness campaigns, real-time deepfake detection in communication channels and endpoint devices, and regularly updated and tested incident response plans.
- Appendix A summarises threats, impact and mitigating measures; the paper credits the Association of Banks in Singapore Standing Committee on Cyber Security and MAS's Cyber and Technology Resilience Experts panel for input.
What did MAS Circular MAS/TCRS/2025/06 change for banks?
It expands the deepfake material in MAS's July 2024 paper into a standalone treatment aimed at the threats most relevant to banks: biometric onboarding and authentication, impersonation of executives and customers, and disinformation affecting markets and reputation.
What does MAS/TCRS/2025/06 expect banks to do about deepfake risks?
MAS information paper MAS/TCRS/2025/06, 'Cyber Risks Associated with Deepfakes', of September 2025 says financial institutions should assess the risks deepfakes pose to their own operations and customer interactions and implement appropriate defences. It identifies three areas of impact (defeating biometric authentication, social engineering and impersonation scams, and misinformation and disinformation) across five risk types (market, cyber, fraud, regulatory and reputational). Its conclusion names liveness detection, additional verification for high-risk transactions, information sharing, awareness campaigns, real-time deepfake detection integrated into communication channels and endpoint devices, and incident response plans that are regularly updated and tested. It is guidance rather than a binding rule.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| Section 2 — Five risk types | MAS | Assess market, cyber, fraud, regulatory and reputational risks from deepfakes against the institution's own operations and customer interactions. | Awareness guidance, 18 September 2025 |
| Section 2.1 — Biometric authentication | MAS | Check identification documents and digital content for tampering during onboarding and verification, and harden biometric authentication against deepfakes, including liveness detection. | Awareness guidance, 18 September 2025 |
| Section 2.2 — Social engineering and impersonation | MAS | Run staff deepfake simulations and customer awareness campaigns, and train staff to challenge suspected impersonation by verifying through a separate, trusted communication channel. | Awareness guidance, 18 September 2025 |
| Section 2.3 — Misinformation and disinformation | MAS | Monitor digital channels for deepfake-based brand abuse and executive impersonation, with escalation and takedown procedures and authenticated channels for public clarifications. | Awareness guidance, 18 September 2025 |
| Section 3 — Detection and response | MAS | Monitor advances in deepfake generation and detection, deploy detection tools in communication channels and endpoints where suitable, share information with the industry and keep incident response plans updated and tested. | Awareness guidance, 18 September 2025 |
The paper complements MAS's July 2024 generative AI cyber paper and is cited in MAS's November 2025 consultation paper as the paper covering AI used against FIs by third parties, which the proposed AI risk management Guidelines exclude from their scope.
For banks the practical overlap is with onboarding and know-your-customer controls, payment authorisation and fraud operations, since the same deepfake techniques are used to defeat biometric checks and to impersonate customers or executives.
WHAT THIS MEANS IN PRACTICE
- Test onboarding and authentication flows against deepfake and injection attacks.
- Verify unusual or urgent payment and information requests through a separate, trusted channel (the paper gives the example of confirming a video call by another medium).
- Include deepfake impersonation of executives in tabletop exercises.
- Join industry information-sharing channels on deepfake incidents.
- Review the Appendix A threat and mitigation table against current controls.
Does MAS/TCRS/2025/06 apply to banks?
Yes. It is addressed to financial institutions and its examples and measures, such as biometric authentication and high-risk transaction verification, are directed at banks and other FIs. It is an information paper and not a binding notice.
What does MAS recommend against deepfakes?
The conclusion lists liveness detection, additional verification for high-risk transactions, industry information sharing, awareness campaigns, real-time deepfake detection tools and regularly updated and tested incident response plans.
Is MAS/TCRS/2025/06 binding?
No. It is an information paper that provides an overview of threats and possible mitigating measures, and FIs should assess the risks to their own operations and implement appropriate defensive measures.
| Date | Document | Status |
|---|---|---|
| Mar 20, 2026 | MAS MindForge AI Risk Management Toolkit — AI Risk Management: Operationalisation Handbook (Project MindForge AI Risk Management Toolkit) | Final |
| Nov 13, 2025 | MAS Consultation Paper P017-2025 (AI Risk Management Guidelines) — Consultation Paper on Guidelines on Artificial Intelligence Risk Management | Proposed |
| Dec 5, 2024 | MAS AI Model Risk Management information paper — Artificial Intelligence Model Risk Management: Observations from a Thematic Review (Information Paper) | Final |
| Jul 30, 2024 | MAS Circular MAS/TCRS/2024/05 — Cyber Risks Associated with Generative Artificial Intelligence (Information Paper) | In force |
| Nov 12, 2018 | MAS FEAT Principles — Principles to Promote Fairness, Ethics, Accountability and Transparency (FEAT) in the Use of Artificial Intelligence and Data Analytics in Singapore's Financial Sector | In force |
| Sep 3, 2026 | FIN-2026-Alert005 (Digital Asset Investment Scam Centers) — FinCEN Alert on Money Laundering Activity Associated with Digital Asset Investment Scam Centers | In force |
Follow every document these regulators publish
when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning