Quaintitative

The AIRG is final

Singapore's AI Risk Management Guidelines (AIRG) are final

The MAS AI Risk Management Guidelines (AIRG) are final: issued 7 October 2026, in force 7 October 2027. The overview, and the points that will change what firms do.

Published 7 October 2026.

The Monetary Authority of Singapore issued the final Guidelines on AI Risk Management for Financial Institutions, the MAS AIRG, on 7 October 2026. The AIRG is in force from 7 October 2027. I developed it while leading AI risk supervision at MAS, so take my reading for what it is. Here is the overview, and the points in the final AIRG that will actually change what firms do.

The AIRG applies to every financial institution MAS regulates, and to every kind of AI: traditional AI, generative AI including large language models, and AI agents. They are supervisory expectations, not a rulebook, and they are proportionate. A firm tailors its approach to how much, and how riskily, it uses AI.

The points that matter

  • There is now a clock, and it is phased. Oversight and your core AI risk systems, policies and procedures are expected from 7 October 2027. The lifecycle controls and the capability to run them follow by 7 October 2028. Identify and govern your AI before you are judged on how well you control it.
  • Scope turns on impact, not on how embedded the AI is. The consultation's "integrated part of business processes" test is gone. A firm can keep to basic policies only where its AI, if it failed, is unlikely to have a material adverse impact on the firm, its customers or stakeholders.
  • Third-party AI is where the final tightened most, and where most firms' real exposure sits. The firm retains primary accountability for AI it buys. If it cannot bring the residual risk within appetite, it is expected to limit, suspend, or replace the provider. External assessments must come from independent, competent parties, not self-attestations. Identification now reaches AI embedded in third-party services, and the shadow AI staff use without telling anyone.
  • Generative AI and agents are named directly. The final AIRG names generative AI, large language models, and AI agents including multi-agent systems, and carves out rule-based automation that does not learn. Guardrails have to be tested for effectiveness, not just listed.
  • Some expectations eased. The mandatory cross-functional committee is gone. Model selection and the review cadence for basic policies are lighter. MAS took the consultation feedback seriously.

The idea underneath did not change. AI risk is mostly an extension of risks you already manage, not a new category. Scale the controls to the risk. Go deep where a failure would hurt. Stay light where it would not. A firm with a working model risk, third-party risk and technology risk function is not starting from zero.

Read more

For the detail behind each of these:

Get the detailed analysis

I am publishing a fuller breakdown of what changed from the consultation and what firms should do about it, in the order the runway sets. Subscribe to get it, and future updates on the AIRG.

Subscribe for updates