Quaintitative

AIRG in context

AIRG, Project MindForge, and the CRI Financial Services AI Risk Management Framework

Three bodies of work come up again and again for AI risk in financial services: Singapore's AI Risk Management Guidelines (AIRG), Project MindForge, and the Cyber Risk Institute Financial Services AI Risk Management Framework. They look like different things, and in shape they are. But they are answers to the same problem, and they line up on the same spine. I wrote the AIRG, and this is how I place them against each other.

The shorthand I use is the simplest way in: the AIRG is the expectations and standards, Project MindForge is the risks and the practices, and the CRI Financial Services AI Risk Management Framework is the control framework. Each answers a different question - what is expected, what can go wrong and how firms actually handle it, and which controls to put in place.

What each one is

  • The AIRG is the expectations and standards. MAS guidelines setting out what a financial institution is expected to do across five areas: oversight, the systems that find and rate AI, lifecycle controls, and capability. It covers all AI, and it sets the depth of controls by a materiality assessment on impact, complexity and reliance. It is the standard a firm is held to.
  • Project MindForge is the risks and the practices. MindForge is the MAS-convened consortium of financial institutions, and it has produced two distinct bodies of work - the risks, then the practices:
    • The MindForge risk paper (the risks) - Emerging Risks and Opportunities of Generative AI for Banks - maps the risks of generative AI across seven dimensions, extending the earlier FEAT principles. It tells you what can go wrong with GenAI.
    • The MindForge AI Risk Management Toolkit (the practices) - the consortium's operationalisation of the AIRG, published as a trilogy: an Executive Handbook (November 2025), and an Operationalisation Handbook and Implementation Examples (January 2026). It answers "how do 24 financial institutions actually do what the AIRG requires?", with templates, metrics, guardrails and bank case studies.
  • The CRI Financial Services AI Risk Management Framework is the control framework. Published by the Cyber Risk Institute (CRI) in February 2026 with regulatory and NIST input, it operationalises the US NIST AI Risk Management Framework for finance: it keeps NIST's four functions and adds 200+ financial-sector control objectives, staged by a four-stage adoption model.

So MindForge's risk paper is the map of the risks, the AIRG is the expectations and standards set against them, and the practices - the MindForge Toolkit for Singapore, and the CRI control framework globally - are what turn the standard into concrete controls.

At a glance

DocumentWhat it isOriginShape
MAS AIRGThe expectations and standardsMAS (Singapore)Five-area control architecture
MindForge risk paperThe risks (GenAI risk taxonomy)MAS-convened consortiumSeven risk dimensions, extending FEAT
MindForge AI Risk Management ToolkitThe practices (operationalising the AIRG)MAS-convened consortium (24 FIs)Four pillars, 17 Considerations, with templates and case studies
CRI Financial Services AI Risk Management FrameworkThe control frameworkCyber Risk Institute (industry)Four NIST functions, 200+ control objectives

The MindForge Toolkit in brief

The Toolkit organises its guidance under four pillars and seventeen Considerations, and maps each one back to the AIRG:

  • Scope and Oversight - the AI governance operating model (C1).
  • AI Risk Management - governance documents, the organisation-wide risk framework, third-party AI risk, use-case risk management and materiality, and the AI inventory (C2 to C6).
  • AI Lifecycle Management - use-case design, data ethics and management, third-party onboarding, guardrails and metrics, testing and review, deployment, monitoring, and change management (C7 to C15).
  • Enablers - skills, knowledge and culture, and infrastructure (C16 to C17).

The architecture: AIRG, the MindForge Toolkit, and the CRI functions

Because the CRI Financial Services AI Risk Management Framework is a profile of the NIST AI RMF, it inherits NIST's four functions, and those line up with the AIRG's architecture. The MindForge Toolkit maps to the AIRG explicitly, so all three sit side by side.

AIRG areaMindForge ToolkitCRI framework function
Oversight (s.2)Scope and Oversight (C1); governance documents and org risk framework (C2, C3)Govern (GV)
Key systems: find, inventory, rate (s.3)Use-case risk management and materiality (C5); AI inventory (C6)Map (MP)
Lifecycle controls (s.4)AI Lifecycle Management (C7 to C15)Measure (MS) and Manage (MG)
Third-party AI (s.4)Third-party AI risk (C4) and onboarding (C10)Govern and Manage
Capability (s.5)Enablers: skills and infrastructure (C16, C17)Assumed, not tiered

Two other things align without sitting in a function. The AIRG's materiality assessment, the MindForge Toolkit's use-case risk rating, and the CRI framework's four-stage adoption model are the same idea in three forms: all make the weight of controls follow the risk.

The risk lens: MindForge's seven dimensions

The MindForge risk paper is the one that tells you what to worry about with generative AI specifically, and its seven dimensions carry through into the Toolkit's own risk taxonomy. They map onto the AIRG's controls and the CRI framework's functions.

MindForge risk dimensionAIRG controlCRI framework function
Fairness and BiasFairnessMeasure (fairness)
Ethics and ImpactOversight, responsible-use cultureGovern
Accountability and GovernanceOversight, three lines (s.2)Govern
Transparency and ExplainabilityTransparency and explainabilityMeasure
Legal and RegulatoryIntegration with existing risk and compliance frameworksGovern
Monitoring and StabilityMonitoring, evaluation and testingMeasure, Manage
Cyber and Data SecuritySecurity, data managementGovern, Manage

Read the columns across and the point is clear: the same concerns recur, named differently. What MindForge calls a risk dimension, the AIRG states as a control to apply in proportion to risk, and the CRI framework breaks into specific control objectives under a function.

How they fit together

They are complementary, not competing, and the shorthand holds: expectations, risks and practices, control framework. The AIRG sets the expectations and standards with supervisory force in Singapore - what a financial institution must do, across all AI, in proportion to risk. Project MindForge supplies the risks (the risk paper's GenAI dimensions, from the same FEAT lineage as the AIRG) and the practices (the Toolkit's how-to for the AIRG, with templates, metrics, guardrails and worked examples from banks). The CRI Financial Services AI Risk Management Framework is the control framework: a library of control objectives mapped to a widely used standard, with a staged way to adopt it. A Singapore financial institution that builds to the AIRG, uses MindForge for the risks and the practices, and borrows CRI control objectives where useful is not running four programmes. It is running one, described four ways.

My take

Build to the AIRG, because it is the expectations and standards with supervisory weight behind them, it covers all AI rather than only GenAI, and its materiality assessment already does the proportionality work. Reach for the MindForge risk paper when the question is specifically about generative AI, because its seven dimensions are the clearest local statement of the risks. Reach for the MindForge Toolkit first when you need to actually implement, because it is the practices, written for the AIRG, showing how two dozen local institutions did it. Reach for the CRI Financial Services AI Risk Management Framework when you want the control framework: a ready-made library of control objectives and a staged way to adopt them. The mistake is to treat them as separate regimes to comply with. They converge, which means the real work, done once to the AIRG, carries across.

Help mapping across frameworks

I wrote the AIRG and led the 2024 thematic review it builds on. I train and advise financial institutions on the AIRG and on placing it against the other frameworks, including the EU AI Act, NIST and ISO 42001. For the fuller Singapore picture, see the timeline of AI risk management in Singapore, or read more on AI risk management. See the courses and workshops, or get in touch.