# MAS Circular MAS/TCRS/2025/06: Cyber Risks Associated with Deepfakes (Information Paper)

Source: https://www.bankingnewsai.com/ai-regulation/documents/mas-circular-cyber-risks-deepfakes-2025
Last updated: Oct 5, 2026

MAS circular MAS/TCRS/2025/06, an information paper dated September 2025 and issued on 18 September 2025, examines how deepfakes threaten financial institutions and what mitigating measures they can take. It covers three areas: defeating biometric authentication, social engineering and impersonation scams, and misinformation and disinformation, and it lists five risk types (market, cyber, fraud, regulatory and reputational). It applies to FIs including banks as awareness guidance, and extends the deepfake section of MAS's July 2024 generative AI cyber paper. A bank should check that its biometric authentication has liveness detection and that high-risk transactions need additional verification.

## At a glance

| Field | Value |
| --- | --- |
| Authority | [MAS](https://www.bankingnewsai.com/ai-regulation/mas) |
| Type | Circular |
| Status | In force |
| Published | Sep 18, 2025 |
| Applies to | Financial institutions in Singapore (the circular is addressed to FIs), which includes banks; an awareness paper describing threats and mitigating measures, not a binding rule |
| Official text | https://www.mas.gov.sg/regulation/circulars/cyber-risks-associated-with-deepfakes |

## Key points

- Section 2 lists five risk types from deepfakes: market, cyber, fraud, regulatory (for example falsified identities in recruitment by actors from sanctioned countries) and reputational.
- Section 2.1 addresses defeating biometric authentication, with recent incidents and possible mitigating measures.
- Section 2.2 addresses social engineering and impersonation scams, with incidents and mitigation.
- Section 2.3 addresses misinformation and disinformation, including fabricated executive statements and market-moving content.
- Section 3 concludes that FIs should assess deepfake risks to their own operations and customer interactions and keep monitoring both generation and detection technologies.
- The conclusion names liveness detection, additional verification for high-risk transactions, industry information sharing, awareness campaigns, real-time deepfake detection in communication channels and endpoint devices, and regularly updated and tested incident response plans.
- Appendix A summarises threats, impact and mitigating measures; the paper credits the Association of Banks in Singapore Standing Committee on Cyber Security and MAS's Cyber and Technology Resilience Experts panel for input.

## What changed for banks

It expands the deepfake material in MAS's July 2024 paper into a standalone treatment aimed at the threats most relevant to banks: biometric onboarding and authentication, impersonation of executives and customers, and disinformation affecting markets and reputation.

## Use cases it governs

- [Fraud detection](https://www.bankingnewsai.com/ai-regulation/by-use-case#fraud)
- [Cybersecurity](https://www.bankingnewsai.com/ai-regulation/by-use-case#cybersecurity)
- [AML / KYC](https://www.bankingnewsai.com/ai-regulation/by-use-case#aml-kyc)
- [Generative & agentic AI](https://www.bankingnewsai.com/ai-regulation/by-use-case#generative-agentic-ai)

## What does MAS/TCRS/2025/06 expect banks to do about deepfake risks?

MAS information paper MAS/TCRS/2025/06, 'Cyber Risks Associated with Deepfakes', of September 2025 says financial institutions should assess the risks deepfakes pose to their own operations and customer interactions and implement appropriate defences. It identifies three areas of impact (defeating biometric authentication, social engineering and impersonation scams, and misinformation and disinformation) across five risk types (market, cyber, fraud, regulatory and reputational). Its conclusion names liveness detection, additional verification for high-risk transactions, information sharing, awareness campaigns, real-time deepfake detection integrated into communication channels and endpoint devices, and incident response plans that are regularly updated and tested. It is guidance rather than a binding rule.

| Rule | Authority | What it requires | Status | Source |
| --- | --- | --- | --- | --- |
| Section 2 — Five risk types | [MAS](https://www.bankingnewsai.com/ai-regulation/mas) | Assess market, cyber, fraud, regulatory and reputational risks from deepfakes against the institution's own operations and customer interactions. | Awareness guidance, 18 September 2025 | [MAS Circular MAS/TCRS/2025/06](https://www.bankingnewsai.com/ai-regulation/documents/mas-circular-cyber-risks-deepfakes-2025) |
| Section 2.1 — Biometric authentication | [MAS](https://www.bankingnewsai.com/ai-regulation/mas) | Check identification documents and digital content for tampering during onboarding and verification, and harden biometric authentication against deepfakes, including liveness detection. | Awareness guidance, 18 September 2025 | [MAS Circular MAS/TCRS/2025/06](https://www.bankingnewsai.com/ai-regulation/documents/mas-circular-cyber-risks-deepfakes-2025) |
| Section 2.2 — Social engineering and impersonation | [MAS](https://www.bankingnewsai.com/ai-regulation/mas) | Run staff deepfake simulations and customer awareness campaigns, and train staff to challenge suspected impersonation by verifying through a separate, trusted communication channel. | Awareness guidance, 18 September 2025 | [MAS Circular MAS/TCRS/2025/06](https://www.bankingnewsai.com/ai-regulation/documents/mas-circular-cyber-risks-deepfakes-2025) |
| Section 2.3 — Misinformation and disinformation | [MAS](https://www.bankingnewsai.com/ai-regulation/mas) | Monitor digital channels for deepfake-based brand abuse and executive impersonation, with escalation and takedown procedures and authenticated channels for public clarifications. | Awareness guidance, 18 September 2025 | [MAS Circular MAS/TCRS/2025/06](https://www.bankingnewsai.com/ai-regulation/documents/mas-circular-cyber-risks-deepfakes-2025) |
| Section 3 — Detection and response | [MAS](https://www.bankingnewsai.com/ai-regulation/mas) | Monitor advances in deepfake generation and detection, deploy detection tools in communication channels and endpoints where suitable, share information with the industry and keep incident response plans updated and tested. | Awareness guidance, 18 September 2025 | [MAS Circular MAS/TCRS/2025/06](https://www.bankingnewsai.com/ai-regulation/documents/mas-circular-cyber-risks-deepfakes-2025) |

The paper complements MAS's July 2024 generative AI cyber paper and is cited in MAS's November 2025 consultation paper as the paper covering AI used against FIs by third parties, which the proposed AI risk management Guidelines exclude from their scope.

For banks the practical overlap is with onboarding and know-your-customer controls, payment authorisation and fraud operations, since the same deepfake techniques are used to defeat biometric checks and to impersonate customers or executives.

### What this means in practice

- Test onboarding and authentication flows against deepfake and injection attacks.
- Verify unusual or urgent payment and information requests through a separate, trusted channel (the paper gives the example of confirming a video call by another medium).
- Include deepfake impersonation of executives in tabletop exercises.
- Join industry information-sharing channels on deepfake incidents.
- Review the Appendix A threat and mitigation table against current controls.

## FAQ

### Does MAS/TCRS/2025/06 apply to banks?

Yes. It is addressed to financial institutions and its examples and measures, such as biometric authentication and high-risk transaction verification, are directed at banks and other FIs. It is an information paper and not a binding notice.

### What does MAS recommend against deepfakes?

The conclusion lists liveness detection, additional verification for high-risk transactions, industry information sharing, awareness campaigns, real-time deepfake detection tools and regularly updated and tested incident response plans.

### Is MAS/TCRS/2025/06 binding?

No. It is an information paper that provides an overview of threats and possible mitigating measures, and FIs should assess the risks to their own operations and implement appropriate defensive measures.

## Related documents

- [MAS MindForge AI Risk Management Toolkit](https://www.bankingnewsai.com/ai-regulation/documents/mas-mindforge-ai-risk-management-toolkit-2026) — AI Risk Management: Operationalisation Handbook (Project MindForge AI Risk Management Toolkit) (Mar 20, 2026)
- [MAS Consultation Paper P017-2025 (AI Risk Management Guidelines)](https://www.bankingnewsai.com/ai-regulation/documents/mas-consultation-ai-risk-management-guidelines-2025) — Consultation Paper on Guidelines on Artificial Intelligence Risk Management (Nov 13, 2025)
- [MAS AI Model Risk Management information paper](https://www.bankingnewsai.com/ai-regulation/documents/mas-info-paper-ai-model-risk-management-2024) — Artificial Intelligence Model Risk Management: Observations from a Thematic Review (Information Paper) (Dec 5, 2024)
- [MAS Circular MAS/TCRS/2024/05](https://www.bankingnewsai.com/ai-regulation/documents/mas-circular-cyber-risks-generative-ai-2024) — Cyber Risks Associated with Generative Artificial Intelligence (Information Paper) (Jul 30, 2024)
- [MAS FEAT Principles](https://www.bankingnewsai.com/ai-regulation/documents/mas-feat-principles-2018) — Principles to Promote Fairness, Ethics, Accountability and Transparency (FEAT) in the Use of Artificial Intelligence and Data Analytics in Singapore's Financial Sector (Nov 12, 2018)
- [FIN-2026-Alert005 (Digital Asset Investment Scam Centers)](https://www.bankingnewsai.com/ai-regulation/documents/fincen-alert-2026-scam-centers) — FinCEN Alert on Money Laundering Activity Associated with Digital Asset Investment Scam Centers (Sep 3, 2026)
- [FIN-2026-Alert004 (Federal Student Aid Fraud)](https://www.bankingnewsai.com/ai-regulation/documents/fincen-alert-2026-federal-student-aid-fraud) — FinCEN Alert on Fraud Schemes Targeting Federal Student Aid (Jul 24, 2026)
- [Commission guidelines on AI Act Article 50 transparency](https://www.bankingnewsai.com/ai-regulation/documents/eu-commission-guidelines-ai-act-article-50-transparency-2026) — Commission Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of Regulation (EU) 2024/1689 (AI Act) (Jul 20, 2026)

Last reviewed Oct 5, 2026. Cite the official text (https://www.mas.gov.sg/regulation/circulars/cyber-risks-associated-with-deepfakes) for the rule and this page for the summary and dates.

---

Canonical page: https://www.bankingnewsai.com/ai-regulation/documents/mas-circular-cyber-risks-deepfakes-2025
Part of [BankingNewsAI](https://www.bankingnewsai.com/) — a free daily brief on AI in banking, an AI regulation tracker (41 authorities, 237 documents) and AI-strategy profiles of the 120 largest US banks. Markdown versions of every reference page: append `.md` to the page URL; index at https://www.bankingnewsai.com/llms.txt.
