Quaintitative

For regulators and supervisors

AI risk management for regulators and supervisors

You do not assess the model. You assess whether the firm has managed it.

A supervisor does not assess a model; you assess whether a firm has managed it. Under the MAS AI Risk Management Guidelines (AIRG), that means judging the adequacy of the firm's own AI risk management: whether identification works as a net rather than a list, so that embedded and shadow AI are caught; whether materiality is assessed honestly and drives the depth of control; whether the firm retains accountability for the AI it buys, including concentration on a few providers; and whether accountability is real and demonstrable. The firm runs the controls. Your job is to test whether it can show they work.

The practical test is what you find when you ask for evidence: an inventory, a materiality rationale, test results, an escalation record, produced on request, or a set of good intentions. A fuller guide for regulators and supervisors is coming.

Where to start

I developed the AIRG while leading AI risk supervision at MAS, and now advise regulators and supervisors independently. I am building a fuller guide for regulators and supervisors; subscribe to get it, and future updates on the AIRG.

Subscribe for updates