For the first line
AI risk management for business lines
If you build or use AI to do your job, you own the first line of its risk.
Under the MAS AI Risk Management Guidelines (AIRG), the business line that builds or uses AI owns the first line of its risk. You identify the AI you use or build, including AI embedded in the tools you buy and the shadow AI people reach for without telling anyone; you assess how material each use is; you apply lifecycle controls in proportion to that materiality; and you escalate when the residual risk sits outside the firm's appetite. The control functions oversee and challenge, but the first act, finding and rating the AI, is yours.
The practical test is simple: can you produce a complete list of the AI your unit uses, a materiality rating for each, and the controls that follow, on request? If AI is in use that nobody logged, it is not lightly governed; it is ungoverned. A fuller first-line guide is coming.
Where to start
- The complete guide to AI risk management in finance in Singapore - the whole picture in one place.
- The AIRG in practice - identification, inventory, materiality and lifecycle controls as a working system.
- The AIRG and third-party AI - the AI you bought rather than built, and the AI hidden inside it.
- The AIRG explained - the guidelines your firm is supervised against.
I developed the AIRG while leading AI risk supervision at MAS, and now advise first-line teams independently. I am building a fuller guide for the business line; subscribe to get it, and future updates on the AIRG.