For validators, reviewers and assurance
AI risk management for validators and assurance
Your job is to check, independently, that the AI does what the firm says it does.
Independent validation and review are where AI risk management is tested for real. You test an AI or generative-AI model on the firm's own data and population, against its own definition of good enough; you perform compensatory testing where a third-party provider will not disclose enough to judge it from the outside; you challenge the first line's own testing rather than accept it; and you give the second line, the board and the supervisor assurance that the controls actually work. Under the MAS AIRG, independent validation is a firm expectation for high-materiality AI. It can be carried out by external or group-level reviewers where they are independent and competent, and a vendor-commissioned review counts only if it was genuinely independent.
The practical test is whether a reviewer could pick up a material AI use case and reach an independent view of whether it is fit for use, from the evidence the firm holds, and have the standing to say no. A fuller guide for validators and assurance is coming.
Where to start
- The complete guide to AI risk management in finance in Singapore - the whole picture in one place.
- The AIRG in practice - inventory, risk materiality and lifecycle controls as a working system.
- The AIRG and third-party AI - compensatory testing and what to do when the vendor will not show its work.
- The AIRG explained - the guidelines your validation is measured against.
I developed the AIRG while leading AI risk supervision at MAS, and now advise firms on validation and assurance independently. I am building a fuller guide for validators and assurance; subscribe to get it, and future updates on the AIRG.