Podcast
AI risk supervision in central banking
I went on the Talking Central Banks podcast, with Karan Bhasin, to talk through how a financial supervisor actually approaches AI risk: the AIRG, where accountability sits, and what changes with generative and agentic AI. I wrote the AIRG while leading AI risk supervision at the Monetary Authority of Singapore, and the short version of my argument is that most of this is old risk in a new coat - the discipline that governs a credit model governs an AI one, applied harder. You can watch the full conversation below; here are the points I made.
The 2008 parallel
I joined the MAS in 2007, just before the financial crisis, working on Basel capital rules. One model, the Gaussian copula, played a large part in the crisis - a fairly simple model whose risk no one fully understood. If a single model we thought was too complex could do that then, consider today: financial institutions now run far more than one model, and AI is becoming pervasive across use cases. The lesson from 2008 is the one to carry into how we govern and risk-manage models now.
Three questions, old models or new
After enough model-risk audits - credit, market pricing, liquidity - it comes down to three questions, and they are the same for AI. What is at risk: find where your models are, judge how material each one is, and record them in an inventory, because not all models are built equal. How do you manage it: the controls, above all evaluation and testing, and fairness where it is an essential service like credit. And can you actually run it: if the board and senior management cannot put the systems and controls in place, everything you say about oversight stays empty. I put that one last on purpose, because without it nothing else works.
Singapore's seven-year path to the AIRG
The journey ran from voluntary principles to guidelines. You start high-level when a field is unsettled, so the FEAT principles - fairness, ethics, accountability, transparency - set outcomes rather than telling banks exactly what to do. Then Veritas, where the MAS worked closely with industry on practices and toolkits. ChatGPT was the inflection point: the MAS set up Project MindForge, which in its first year mapped the risks. In 2024 I led a thematic review of how the major banks actually managed AI model risk - a fact-finding exercise, not a hunt for fault - which became the Information Paper. The AIRG came last, once we understood enough to set expectations. The guidelines are not law; they are what the MAS looks for when it inspects.
How a supervisor assesses a bank
A thematic review is not an audit looking for something that went wrong. It is a journey to understand how banks manage AI risk front to end - the first line, the developers and business; the second line, the risk, technology-risk and model-risk functions. A supervisor has a bird's-eye view: we may not be the practitioners or the technologists, but by looking across a range of banks we can distil what works, what fails, and what good practice looks like. If I had to name the first things I check, it is what is at risk - how well a firm does identification, risk-materiality assessment, and inventory. Without those three systems interlocking, the oversight and the controls do not hold.
Proportionality: a five-person fintech is not a big bank
One set of guidelines has to fit a global bank and a tiny fintech, and the answer is proportionality. Start from first-principles expectations that both need, then be explicit that relevance and proportionality decide how much applies. A useful test is how integrated the AI is: if a provider going down tomorrow would stop you functioning, you rely on it heavily and need a higher level of control. If humans, processes and backups can carry the load, a lighter bar is fine - identify who is responsible, set basic policies on what can and cannot be done, review them, communicate them.
Transparency theatre versus explainability you can act on
Transparency is becoming less useful on its own. AI is now used everywhere, often invisibly, so "we disclose that AI is involved" starts to look like greenwashing: responsibility declared, and then it is someone else's problem. Explainability is different and more useful. It does not mean pinpointing which neurons fired; it means building a system you understand - so that when it breaks, you know why. That connects to the other controls: evaluation and testing to see how it behaves across conditions, and human oversight that is actually designed for a person to act on, not a human dropped in the loop as theatre. Agentic AI makes this harder, because it moves faster than the machine-learning systems we are used to.
Validating generative and agentic AI
Traditional validation assumed bounded inputs and outputs - tables, numbers, time series. Large language models break that, because the permutations across text and images are effectively endless. It does not mean there is no solution; it means ordinary testing is not enough. You still build a test set, contextualised to the firm's use case. You red-team it, thinking like an attacker. And you put deterministic guardrails around it, not just a language model judging another language model. I think of it as a hamburger: language models are the buns, good at parsing intent and synthesising; the meat is your rules, functions and tools, which are deterministic and can be trusted more. Let the model use those, rather than throwing everything at it and hoping.
Agentic AI adds two problems: errors compound as one step's mistake feeds the next, and the system can act on the world, not just answer. But it is also more tractable in one respect - you can make an agent log and trace its actions, step by step, which is more reliable than a reasoning trace that can itself be fabricated. In a recent paper on agentic model-risk management, the approach is to treat an agent as a collection of granular capabilities - retrieval, computation, answering - and govern each like a Lego brick, with guards and tests around it, rather than piecing the whole thing together and hoping it holds.
The thread: first principles
Basel, model risk management, and AI are connected by first principles. In all three, you cannot work off the surface of the rules. Below the Basel formulas is a motivation; below the validation documents are a model's real limitations and advantages; and much of what applies to Basel and model risk applies to AI now. That is also why I prefer "AI risk management" to "AI governance" - the job is to operationalise, close to the ground, not to stay one level too high.
Watch the full conversation on Talking Central Banks with Karan Bhasin. For more, see AI governance for regulators, the AIRG, and the timeline of AI risk management in Singapore.
Work with me
I train and advise regulators, supervisors, and financial institutions on AI risk management and the AIRG. See the courses and workshops, or get in touch.