AI Regulation Tracker · MAS · Report

What does MAS AI Model Risk Management information paper say about AI in banking?

Published Dec 5, 2024 · Last reviewed Oct 5, 2026

MAS published this information paper on 5 December 2024 after a thematic review, conducted in mid-2024, of selected banks' AI and generative AI model risk management. It records good practices in three areas: governance and oversight of AI; identification, inventorisation and risk-materiality assessment of AI; and development, validation, deployment, monitoring and change management of AI. MAS says the practices should generally apply to other financial institutions and treats generative AI and third-party AI in separate sections (7.1 and 7.2). The paper is not a rule, but in section 8.2 MAS said it was considering supervisory guidance for all FIs the following year, which became the November 2025 consultation on Guidelines on AI Risk Management.

OFFICIAL TEXT: mas.gov.sg ↗ · FINAL · MAS

DocumentMAS AI Model Risk Management information paper — Artificial Intelligence Model Risk Management: Observations from a Thematic Review (Information Paper)
Issued byMonetary Authority of Singapore
TypeReport
StatusFinal
PublishedDec 5, 2024
Applies toWritten from a mid-2024 thematic review of selected banks in Singapore; MAS says the good practices should generally apply to other financial institutions, which should take reference from them when developing and deploying AI. It is an information paper of observed good practices, not a binding rule
Official sourcemas.gov.sg ↗
Use casesModel risk management · Generative & agentic AI · Third-party & vendor AI · AI governance (general) · Customer-facing chatbots

What are the key points of MAS AI Model Risk Management information paper?

  • Section 4 (governance and oversight): cross-functional AI oversight forums, updated policies and procedures, central statements on fair, ethical, accountable and transparent AI use, and capability building.
  • Section 5.1 (identification): banks extend existing model definitions to identify AI, with model risk management functions typically the key control function for AI identification.
  • Section 5.2 (inventory): a formal AI inventory showing the approved scope of use (purpose, jurisdiction, use case), so AI approved for one jurisdiction is not automatically treated as approved for another; typical attributes are listed in paragraph 5.2.4.
  • Section 5.3.1 (risk materiality): most banks assess impact, complexity and reliance (autonomy granted to the AI and human-in-the-loop mitigants) and review ratings over time.
  • Section 6 (development and deployment): standards for data management, robustness and stability, explainability and fairness, reproducibility and auditability; independent validation or peer review by risk materiality (6.4.4); pre-deployment checks and post-deployment monitoring and change management (6.5).
  • Section 7.1 (generative AI): hallucination and unexpected behaviour were a key concern; most banks limited generative AI to assisting humans or non-customer-facing efficiency uses, with human oversight, input and output filters and data-security controls.
  • Section 7.2 (third-party AI): banks use compensatory testing, contingency planning, updated contracts (performance guarantees, data protection, audit rights, notice of AI being introduced) and awareness efforts, within existing third-party risk standards.
  • Paragraph 3.5 puts data governance, technology and cyber risk and third-party risk management outside the paper, noting existing MAS notices, guidelines and information papers continue to apply.

What did MAS AI Model Risk Management information paper change for banks?

This was MAS's first supervisory paper dedicated to AI model risk management. It showed what Singapore banks were already doing and so set the practical benchmark that supervisors compare against, and it signposted the move from FEAT principles to risk-management expectations that culminated in the November 2025 draft AI risk management Guidelines. MAS published a companion circular (ID 18/24) to insurers on the same date.

What good practices does the MAS information paper on AI model risk management set out for banks?

The MAS information paper on artificial intelligence model risk management, published on 5 December 2024, describes good practices observed at selected banks across three areas: oversight and governance of AI, key risk management systems (AI identification, inventories and risk materiality assessment using impact, complexity and reliance), and development, validation and deployment (data management, robustness, explainability, fairness, reproducibility, independent validation or peer review, pre-deployment checks, monitoring and change management). It adds sections on generative AI and third-party AI. The practices are not binding, but MAS says they should generally apply to other financial institutions, and the paper foreshadowed the 2025 consultation on Guidelines on AI Risk Management. For banks, it is the clearest statement of what MAS saw as sound practice before the Guidelines are finalised.

RuleAuthorityWhat it requiresApplies
Section 4 — Governance and oversightMASSet up cross-functional AI oversight forums, update control policies and procedures, publish central statements on fair, ethical, accountable and transparent AI use, and build AI capabilities.Good practice, published 5 December 2024
Section 5.1 — AI identificationMASEstablish definitions and processes, typically led by the model risk management function, to identify where AI is used so that commensurate controls apply.Good practice, published 5 December 2024
Section 5.2 — AI inventoryMASMaintain a complete AI inventory recording purpose, scope of use, jurisdiction, model type, dependencies, risk rating, approvals and owners, so AI is used only within its approved scope.Good practice, published 5 December 2024
Section 5.3 — Risk materiality assessmentMASRate each AI model or use case on impact, complexity and reliance, and review the ratings over time, so controls are proportionate.Good practice, published 5 December 2024
Section 6.1-6.3 — Standards, data and developmentMASSet standards for data management, robustness and stability, explainability and fairness, and reproducibility and auditability in AI development.Good practice, published 5 December 2024
Section 6.4 — ValidationMASSubject AI to independent validation, or at least peer review for lower-materiality AI, before deployment, with validators who have relevant AI expertise.Good practice, published 5 December 2024
Section 6.5 — Deployment, monitoring and change managementMASRun pre-deployment checks, monitor deployed AI to confirm it behaves as intended, and apply change management to updates.Good practice, published 5 December 2024
Sections 7.1-7.2 — Generative AI and third-party AIMASApply additional controls for generative AI (human oversight, guardrails, testing) and for third-party AI (compensatory testing, contingency plans, contract terms, awareness).Good practice, published 5 December 2024

The paper is deliberately observational. MAS gathered practices from selected banks in mid-2024 and framed them as good practice that other FIs should take reference from, while excluding general data governance, technology and cyber, and third-party risk management, where existing MAS notices, guidelines and information papers apply (paragraph 3.5). It also cites supervisory statements from other jurisdictions, for example the Federal Reserve and OCC's SR 11-7 on independent validation.

In paragraph 8.2 MAS said it was considering supervisory guidance for all FIs the following year, building on these focus areas; the November 2025 consultation paper on Guidelines on AI Risk Management repeats the same structure (oversight, identification, inventory, risk materiality, lifecycle controls) and proposes a 12-month transition once finalised.

WHAT THIS MEANS IN PRACTICE

  • Check that your model inventory tags AI models and records approved scope of use, including jurisdiction.
  • Adopt a documented materiality methodology based on impact, complexity and reliance and tie validation depth to the rating.
  • Ensure independent validators or peer reviewers have AI technical expertise.
  • For generative AI, document why a use case is or is not customer-facing and what human review and guardrails apply.
  • For vendor AI, build compensatory testing, contingency plans and contract clauses (audit rights, notice of new AI features) into third-party risk processes.
  • Use the paper as a gap-assessment baseline now, ahead of the final Guidelines.

Does the MAS AI model risk management information paper apply to banks?

It was written from a thematic review of selected banks, and MAS says the good practices it describes should generally apply to other financial institutions as well. It is an information paper rather than a binding notice, so it sets expectations by example rather than by rule.

Is the MAS AI model risk management paper binding?

No. It sets out good practices observed during the review, and MAS encourages financial institutions to refer to them when developing and deploying AI. The paper says MAS was considering supervisory guidance for all FIs the following year, which became the November 2025 consultation on AI risk management Guidelines.

What does the MAS paper say about generative AI?

Section 7.1 notes that generative AI use in banks was at an early stage, mainly assisting staff rather than customer-facing, and that hallucination and unpredictable behaviour were key concerns. Observed controls included human oversight, cross-functional checks, guardrail filters on inputs and outputs, and limits on access to sensitive information.

How does the MAS paper compare with SR 11-7 and PRA SS1/23?

SR 11-7 and SS1/23 are supervisory statements on model risk generally; the MAS paper is narrower and observational, focused on AI-specific practices such as AI identification, inventories, materiality assessment and generative AI. It cites SR 11-7 on independent validation, and it is not itself a binding standard.

DateDocumentStatus
Mar 20, 2026MAS MindForge AI Risk Management Toolkit — AI Risk Management: Operationalisation Handbook (Project MindForge AI Risk Management Toolkit)Final
Nov 13, 2025MAS Consultation Paper P017-2025 (AI Risk Management Guidelines) — Consultation Paper on Guidelines on Artificial Intelligence Risk ManagementProposed
Sep 18, 2025MAS Circular MAS/TCRS/2025/06 — Cyber Risks Associated with Deepfakes (Information Paper)In force
Jul 30, 2024MAS Circular MAS/TCRS/2024/05 — Cyber Risks Associated with Generative Artificial Intelligence (Information Paper)In force
Nov 12, 2018MAS FEAT Principles — Principles to Promote Fairness, Ethics, Accountability and Transparency (FEAT) in the Use of Artificial Intelligence and Data Analytics in Singapore's Financial SectorIn force
Jul 24, 2026Regulation (EU) 2026/1744 (Digital Omnibus on AI) — Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI)In force

Follow every document these regulators publish

when one of these regulators moves, the next morning's brief says so · six sourced stories · 7 am ET · free

plus every tracker, bank and agent page update, the morning after · leave any morning