MAS Consultation Paper P017-2025, issued on 13 November 2025, proposes Guidelines on Artificial Intelligence Risk Management that would apply to all financial institutions in Singapore, including banks, in a proportionate manner. The comment period closed on 31 January 2026; as of 5 October 2026 the MAS pages checked show no final Guidelines, and on 5 August 2026 MAS's Chairman said in a written Parliamentary reply that the Guidelines would be finalised soon. The proposal has four focus areas: oversight by the Board and senior management, AI risk management systems (identification, inventory and risk-materiality assessment), AI life cycle controls, and capabilities and capacity. MAS proposes a 12-month transition after issue, so a bank should assess its AI inventory and governance against the draft now.
OFFICIAL TEXT: mas.gov.sg ↗ · PROPOSED · COMMENT PERIOD CLOSED · MAS
| Document | MAS Consultation Paper P017-2025 (AI Risk Management Guidelines) — Consultation Paper on Guidelines on Artificial Intelligence Risk Management |
| Issued by | Monetary Authority of Singapore |
| Type | Consultation |
| Status | Proposed · comment period closed |
| Published | Nov 13, 2025 |
| Comment deadline | Jan 31, 2026 |
| Applies to | Proposed to apply to all financial institutions as defined in section 2 of the Financial Services and Markets Act 2022, including banks, in a proportionate manner; branches and subsidiaries of foreign parents may leverage the parent's AI risk management framework if it meets the expectations. Covers AI based on machine learning, deep learning and reinforcement learning, generative AI, AI agents and newer AI technologies |
| Official source | mas.gov.sg ↗ |
| Use cases | AI governance (general) · Model risk management · Generative & agentic AI · Third-party & vendor AI · Fair lending & discrimination |
What are the key points of MAS Consultation Paper P017-2025 (AI Risk Management Guidelines)?
- Paragraph 3.1 proposes applying the Guidelines to all FIs, with paragraph 3.2 allowing proportionate implementation by size, nature of activities, use of AI and risk profile; footnote 13 says all FIs should have basic AI policies, while the oversight and risk-management-systems expectations apply only to FIs using AI as an integrated part of business processes.
- Paragraph 3.3 defines AI as use cases involving models or systems that learn and/or infer from inputs to generate outputs such as estimates, predictions, content, summaries, recommendations or decisions, and excludes calculators or tools whose outputs rest solely on predefined rules.
- Paragraph 4.1: Board and senior management should govern and oversee AI risk and foster an appropriate risk culture; where overall AI risk exposure is material, MAS proposes a dedicated cross-functional committee.
- Paragraphs 4.2-4.4: FIs should identify AI use consistently, keep an accurate and up-to-date AI inventory (which can build on existing inventories), and assess risk materiality across at least the dimensions of impact, complexity and reliance.
- Paragraph 4.5: lifecycle controls, applied by relevance and proportionate to risk materiality, covering data management, fairness, transparency and explainability, human oversight, third-party AI risks, selection of AI, evaluation and testing, technology and cybersecurity, reproducibility and auditability, reviews, monitoring and change management.
- Paragraph 4.7: a 12-month transition period after the Guidelines are issued (Question 10 asks for comment on it).
- Paragraph 1.5: submissions were due by 31 January 2026; MAS publishes submissions unless respondents request confidentiality.
- The paper builds on the FEAT principles, collaboration with industry (Veritas and Project MindForge) and MAS's information papers on AI model risk management and cyber risks; risks from external actors' AI use, such as AI-powered cyber-attacks and scams, are outside scope (footnote 11).
What did MAS Consultation Paper P017-2025 (AI Risk Management Guidelines) change for banks?
It converts the good practices in MAS's December 2024 AI model risk management information paper into proposed supervisory expectations for every financial institution, and explicitly covers generative AI and AI agents. Once final, it would be MAS's first AI-specific supervisory guideline, with a proposed 12-month runway. The MindForge AI Risk Management Operationalisation Handbook (March 2026) was released as the industry companion guide for implementing it.
What would the MAS Guidelines on AI Risk Management require of banks?
The proposed MAS Guidelines on Artificial Intelligence Risk Management, set out in Consultation Paper P017-2025 of 13 November 2025, would require financial institutions, including banks, to put in place oversight by the Board and senior management, systems to identify AI use, keep an AI inventory and assess each use case's risk materiality (impact, complexity and reliance), controls across the AI life cycle, and adequate capabilities and capacity. They would apply proportionately, with a proposed 12-month transition after issue, and cover generative AI and AI agents. The comment period closed on 31 January 2026 and, as of 5 October 2026, MAS has not published final Guidelines. Banks should treat the draft as the direction of travel and align inventories, materiality assessments and lifecycle controls now.
| Rule | Authority | What it requires | Applies |
|---|---|---|---|
| Paragraph 3.1-3.2 — Scope and proportionality | MAS | Apply the Guidelines to all FIs in a manner commensurate with size, activities, AI use and risk profile; foreign-parented FIs may leverage parent frameworks that meet the expectations. | Proposed; comment period closed 31 January 2026 |
| Paragraph 4.1 — AI oversight | MAS | Board and senior management oversee AI risk, foster risk culture, and establish a dedicated cross-functional committee where overall AI risk exposure is material. | Proposed; comment period closed 31 January 2026 |
| Paragraph 4.2 — AI identification | MAS | Establish clear definitions, criteria and processes, supported by robust systems, to identify AI use consistently across business and functional areas. | Proposed; comment period closed 31 January 2026 |
| Paragraph 4.3 — AI inventory | MAS | Maintain an accurate, up-to-date inventory of AI use cases, systems or models, linked to other inventories, to prevent unapproved use. | Proposed; comment period closed 31 January 2026 |
| Paragraph 4.4 — Risk materiality assessment | MAS | Assess the risk materiality of each AI use case, system or model, covering at least impact, complexity and reliance. | Proposed; comment period closed 31 January 2026 |
| Paragraph 4.5 — AI life cycle controls | MAS | Implement controls proportionate to materiality across data management, fairness, transparency and explainability, human oversight, third-party AI, selection, evaluation and testing, technology and cybersecurity, reproducibility and auditability, reviews, monitoring and change management. | Proposed; comment period closed 31 January 2026 |
| Paragraph 4.7 — Transition | MAS | Allow 12 months after the Guidelines are issued for FIs to assess and implement them as appropriate. | Proposed; runs from issue of the final Guidelines |
| Paragraph 1.1 — Capabilities and capacity ↗ | MAS | Ensure the FI has capabilities and capacity commensurate with its use of AI (one of the four focus areas listed in the MAS media release and paragraph 1.1). | Proposed; comment period closed 31 January 2026 |
The draft is the supervisory sequel to MAS's December 2024 thematic review. The same architecture (oversight, identification, inventory, risk materiality, development and deployment controls) now appears as expectations, and MAS ties the draft to FEAT, Veritas and Project MindForge. The MindForge AI Risk Management Operationalisation Handbook, released in March 2026, is the industry-led companion guide.
Status as of 5 October 2026: the consultation page shows the consultation closed; MAS's March 2026 MindForge release said it was reviewing consultation responses; and in a written Parliamentary reply for the 5 August 2026 sitting MAS said the Guidelines apply to all AI use cases by FIs, including agentic AI, and will be finalised soon. No final Guidelines or response to feedback was visible on the MAS pages reviewed. If MAS issues them, this page will be superseded by the final Guidelines.
WHAT THIS MEANS IN PRACTICE
- Build or extend a model inventory so every AI use case, system and model is recorded with purpose, scope, owner and risk rating.
- Define an AI identification test that model risk, procurement and business teams apply consistently, including AI embedded in vendor products.
- Adopt an impact, complexity and reliance materiality scale and map control depth to it.
- Decide whether your overall AI exposure warrants a cross-functional AI committee and document the reasoning.
- Plan against a 12-month runway from issue, and track MAS's announcements for the final text.
- Use the MindForge Operationalisation Handbook as implementation reference.
Does the MAS Guidelines on AI Risk Management apply to banks?
The proposed Guidelines would apply to all financial institutions, which includes banks, in a proportionate manner (paragraphs 3.1-3.2). Banks that are branches or subsidiaries of foreign parents may use the parent's AI risk management framework if it meets the expectations.
When do the MAS AI Risk Management Guidelines take effect?
They have not been finalised as of 5 October 2026 on the MAS pages checked. The consultation ran from 13 November 2025 to 31 January 2026, MAS proposed a 12-month transition after issue, and a written Parliamentary reply on 5 August 2026 said the Guidelines would be finalised soon without giving a date.
Are the MAS AI Risk Management Guidelines binding?
They are proposed supervisory expectations in the form of guidelines, not a notice, and the consultation describes them as expectations that may be applied proportionately. The final text and any enforcement approach will be known only when MAS issues them.
Do the Guidelines cover generative AI and AI agents?
Yes. Paragraphs 1.2 and 2.9 say the Guidelines should be generally applicable to different AI applications and technologies, including generative AI and newer developments such as AI agents.
How do the MAS Guidelines compare with the EU AI Act or SS1/23?
Unlike the EU AI Act, a binding regulation with defined risk categories, the MAS proposal is a principles-based supervisory guideline applied by materiality. It is closer to PRA SS1/23 in that it builds on model risk management, but it is AI-specific and requires an AI inventory and materiality assessment.
| Date | Document | Status |
|---|---|---|
| Mar 20, 2026 | MAS MindForge AI Risk Management Toolkit — AI Risk Management: Operationalisation Handbook (Project MindForge AI Risk Management Toolkit) | Final |
| Sep 18, 2025 | MAS Circular MAS/TCRS/2025/06 — Cyber Risks Associated with Deepfakes (Information Paper) | In force |
| Dec 5, 2024 | MAS AI Model Risk Management information paper — Artificial Intelligence Model Risk Management: Observations from a Thematic Review (Information Paper) | Final |
| Jul 30, 2024 | MAS Circular MAS/TCRS/2024/05 — Cyber Risks Associated with Generative Artificial Intelligence (Information Paper) | In force |
| Nov 12, 2018 | MAS FEAT Principles — Principles to Promote Fairness, Ethics, Accountability and Transparency (FEAT) in the Use of Artificial Intelligence and Data Analytics in Singapore's Financial Sector | In force |
| Sep 30, 2026 | SB 947 — Employment: Automated Decision Systems (No Robo Bosses Act) | Final |
Follow every document these regulators publish
when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free
plus every tracker, bank and agent page update, the morning after · leave any morning