For Regulators
AI governance and supervision for regulators
Supervising AI is not the same as running it. A supervisor's job is to judge whether a firm's AI risk management is adequate for what the firm is actually doing, not to validate its models or write its policies. I supervised AI at the Monetary Authority of Singapore and wrote the AIRG, and I now teach regulators and supervisors. This is how I think about it from the supervisor's seat.
What a supervisor actually assesses
You are not grading the maths. You are checking whether a firm can answer, honestly, a short set of questions: does it know where it uses AI, has it judged how risky each use is, is someone accountable, are the controls matched to the risk, and does it have the capability to run all of that. The same five areas every serious framework uses, read as a test of adequacy rather than a checklist to tick.
Where firms hide risk
Three places, in my experience inspecting them.
- The low-materiality rating. The cheapest way to make a lot of risk disappear is to rate it low. So go to the systems rated low risk, not high. The low rating is the one field that quietly tells every other control to try less.
- The inventory gap. The AI the firm did not write down does not get governed. A vendor "smart feature", an old model, a quiet retrain. If it is not in the inventory, assume it is ungoverned.
- Human oversight on paper. An override rate near zero is not oversight working. It is automation bias wearing a job title.
Proportionality is your tool, not a loophole
You cannot supervise every AI use to the same depth, and you should not try. Match your scrutiny to materiality, the same way you expect firms to match controls to materiality. That is what keeps supervision sustainable as the number of AI systems grows. It also means the burden you place on a firm should track the risk it is carrying, not the noise around the technology.
You do not need to invent a framework
Strip the packaging off the main frameworks and they converge on the same areas: inventory, materiality, oversight, lifecycle controls. Singapore's AIRG, the EU AI Act, the US NIST AI RMF, ISO/IEC 42001. Take a current one, structure from it, and adapt to your mandate. For a supervisor in an emerging market, build on the risk-based supervision you already run, adopt a recognised standard rather than reinventing it, upskill your teams, and pay particular attention to how firms manage third-party AI, because most of the AI they use they did not build.
Work with me
I train regulators, supervisors, and public authorities on AI governance and risk management, including as a module lead for the Cambridge Centre for Alternative Finance's programme for financial authorities. See the courses and workshops, read more on AI risk management, or get in touch.