For the second line
AI risk management for risk and compliance
You do not build the AI. You make sure the first line's AI is identified, rated and controlled.
Under the MAS AI Risk Management Guidelines (AIRG), the second line gives the firm independent oversight of its AI. You hold independent oversight of how the first line identifies, inventories and rates its AI, and you are the final arbiter of what counts as AI and how material a use is. You provide independent validation and effective challenge of the models and systems in use, run the ongoing monitoring that catches drift and degradation, and own the vendor checkpoint so that bought AI is held to the same standard as built AI. This is your existing model risk, third-party risk and technology risk discipline, extended to AI rather than replaced.
The practical test is whether your challenge has teeth: whether you can see the whole AI estate, whether a weak materiality rating gets corrected, and whether a vendor's assurance is tested rather than accepted. A fuller guide for risk and compliance is coming.
Where to start
- The complete guide to AI risk management in finance in Singapore - the whole picture in one place.
- The AIRG in practice - identification, inventory, materiality and lifecycle controls as a working system.
- The AIRG and third-party AI - the vendor checkpoint you own.
- The AIRG explained - the guidelines your firm is supervised against.
I developed the AIRG while leading AI risk supervision at MAS, and now advise second-line functions independently. I am building a fuller guide for risk and compliance; subscribe to get it, and future updates on the AIRG.