Quaintitative

AIRG: response to feedback

The MAS AIRG: what the consultation feedback changed, and why

On 7 October 2026 MAS published its Response to Feedback alongside the final AIRG. What the industry raised, and how MAS answered, theme by theme.

Published 8 October 2026.

I developed the AIRG while leading AI risk supervision at MAS, but I am no longer there, so this is an independent view. On 7 October 2026 MAS issued the final AIRG and, alongside it, its Response to Feedback on the November 2025 consultation (P017-2025). The clause-by-clause comparison shows what changed in the text. This page is the other half: what the industry asked for, and how MAS answered. For shorter reads, see what changed and the overview, or the clear guide to the AIRG.

The short version: MAS moved on the asks that were burdensome or unworkable, and held firm on the ones that were principled. Proportionality and outcomes won over prescription. Here it is, in the order MAS set out.

Who counts, and what counts as AI

Respondents asked whether the Guidelines reach firms incorporated outside Singapore, and what exactly counts as AI: hybrid rule-based-plus-AI systems, embedded AI inside vendor tools, conventional models like logistic regression, and AI in pilot. Some asked to narrow third-party AI to procured solutions only.

MAS held the line on breadth. The expectations apply to every financial institution deploying AI, wherever incorporated, and on a group basis where the firm is under consolidated supervision or owns critical information infrastructure. It rewrote the definition of AI to "machine-based systems or models that derive outputs through learned premises," and gave an illustrative in-and-out list: machine learning including logistic regression and gradient boosting, deep learning, natural language processing, computer vision, generative AI and agents are in; hand-specified formulae, expert if-then systems, traditional rule-based RPA, and Monte Carlo simulations not derived from data are out. Third-party AI stays broad, covering AI embedded in, or used to deliver, a vendor's services, with identification handled proportionately. The net effect: you cannot put a model out of scope by calling it "just regression" or by not noticing the AI inside a tool you bought.

Proportionality, and the scope test that was rewritten

This drew the most consequential change. MAS had keyed the full expectations to whether AI was an "integrated part of business processes." Respondents objected that operational dependence is the wrong test, that it could sweep in low-risk productivity tools such as a copilot, and that scoping should turn on impact.

MAS agreed and replaced the test. A firm may keep to basic AI governance policies only where poor performance or unavailability of its AI is unlikely to have a material adverse impact on the firm, its customers or other stakeholders; otherwise the full Sections 3 to 6 apply. It added worked examples of assistive use that can stay on the basic track, such as drafting or proofreading emails, summarising documents for internal reference, and generating charts for internal use. It also clarified that even a firm not yet using AI needs basic policies, mainly to manage shadow AI; renamed those basic "guidelines" to "policies" to avoid confusion with the Guidelines themselves; and made the review cadence flexible and trigger-based rather than a fixed annual cycle, while encouraging an annual review as good practice.

Board and senior management

Respondents wanted the board and senior-management roles delineated, flexibility for global groups to use regional structures, and guidance on board competence and risk appetite. MAS streamlined the split: the board approves the overall governance approach, the strategic direction for AI use, and the risk appetite; senior management implements the framework, institutes controls, and assigns roles across the firm. The board is not expected to hold hands-on technical expertise, but it must understand the risks well enough to challenge, and it cannot substitute an expert's advice for its own judgement. All risks from AI use, not only the material ones, must be addressed in the risk appetite framework, with illustrative qualitative and quantitative measures given. Group frameworks may be leveraged, but local senior management stays accountable and must be able to demonstrate its oversight to MAS. The three-lines-of-defence model, including internal audit, was added as an illustrative reference in a footnote rather than mandated.

The mandatory committee, dropped

MAS had proposed a dedicated cross-functional committee where overall AI exposure is material. Views were mixed, and respondents warned it would duplicate existing structures. MAS removed the requirement. A firm may manage AI risk through a new centralised function or through existing risk functions, and the coordinating body may sit at group or regional level, as long as there is a consolidated, consistent and coordinated view of AI risk across the firm and the firm can show how its chosen structure achieves that. An easing, in exchange for having to demonstrate effective coordination.

Identification and inventory

Respondents said full identification of embedded AI and shadow AI is hard, and that inventorying every AI use would be burdensome once AI is everywhere. MAS kept the intent but made it workable. Identification must still reach, at a minimum, embedded AI in the services of material third-party providers, and the shadow AI staff use; where complete identification is not possible, the firm assesses the risk of the gap and puts mitigations in place, such as clear use policies, technical controls on public tools, monitoring, and staff awareness. The inventory need only be accurate "to the extent possible or practicable" and can be risk-proportionate. Granularity varies with the use case, with agent-specific attributes for agents. There is no fixed update frequency; periodic plus trigger-based updates suffice. Linkages to other registers are expected only where useful, for example consistent vendor identifiers that support a concentration view. The earlier call for "robust systems" was softened: a firm with few use cases can rely on manual processes, and automated discovery of shadow AI is left to the firm's judgement.

Risk materiality, anchored on the use case

Respondents argued that materiality should turn on how AI is used, not on the model in isolation, and proposed many extra dimensions. MAS agreed to anchor the assessment on the AI use case: the same model can carry different ratings in different use cases, depending on autonomy and human involvement. It kept Impact, Complexity and Reliance as the minimum three, folded explainability and third-party visibility into Complexity, and folded third-party dependence into Reliance while removing "availability of alternatives" from it (fallbacks now sit under contingency planning). It retained Complexity despite objections, with the clarification that a firm less familiar with a technology, or with less visibility into a third-party model, may reasonably rate Complexity higher and test harder. It declined to prescribe a formula for combining the three or a universal threshold for "high," leaving the weighting to the firm, and confirmed that the controls reserved for high-materiality AI are triggered on inherent, not residual, risk.

Who runs it: control functions and the business

Respondents wanted to use existing or group-level control functions and federated approaches. MAS allowed it: a firm may designate an existing function, including one with group-level oversight, provided it can show adequate oversight of AI used in Singapore. The business and functional units may carry out identification, inventory and materiality assessment, with the designated control function keeping sufficient and independent oversight. Notably, MAS dropped the named requirement for "attestation processes" and refocused on the outcomes those were meant to achieve, namely that AI is identified in time, the inventory stays accurate and complete, and risks are assessed and kept under review. The firm chooses the mechanism.

Third-party AI, where it tightened most

This is where the final firmed up. Respondents asked how far a firm is responsible for what the vendor controls, how to deal with proprietary vendors that will not share training data, whether certifications such as ISO 42001 or SOC 2 could stand in, and whether they must track every vendor update. MAS was clear that the choice to use third-party AI is the firm's, so the firm retains primary accountability for how that AI is used, whatever the vendor does or does not disclose. Where it cannot bring the residual risk within appetite, it is expected to limit, suspend, or replace the provider. Where transparency is insufficient, a firm may rely on external certifications or assessments only if they are by independent, competent parties and cover the relevant risks; self-attestations by the vendor do not count, and there is no safe harbour for "reputable" providers. Compensatory testing on the firm's own data, and greater human oversight, remain the fallback. A firm need not track every update, but its contracts must give it a risk-proportionate view of changes that could affect performance or risk, with compensating controls such as enhanced monitoring where a vendor can change a model without prior review. MAS also confirmed that AIRG materiality is assessed per use case and is not the same as outsourcing materiality, so third-party AI is not automatically a material outsourcing arrangement; the two frameworks are read together.

The lifecycle controls, refined

Most of the lifecycle changes are refinements in one direction: calibrate to the risk materiality of the use case, and prescribe less. On data management, representativeness is now assessed across "a range" of real-world conditions rather than "the full range," consent stays governed by the existing data-protection regime, and generative AI picks up data-security points such as leakage through prompt injection. Transparency and explainability are explicitly contextual and driven by the audience; customer disclosures need not be technical, and if a firm cannot reach adequate explainability for a given use case with a given model, it should reconsider the model. Fairness is proportionate in rigour rather than optional, with FEAT as a reference and group-level principles assessed at the use-case level. Model selection must be documented in proportion to materiality and may draw on research or industry practice rather than being required to. Evaluation and testing are not prescribed by method or threshold, are done at the use-case level, must cover the effectiveness of guardrails for generative AI and agents, and for third-party AI should use the firm's own data.

Three lifecycle points are worth singling out. Reproducibility was reworked: for non-deterministic generative AI, a firm documents enough to replicate the evaluation and testing process, not the exact outputs, and may keep enhanced logs of prompts, responses, model versions and reasoning steps. Independent validation stays a firm expectation for high-materiality use cases: it can be done by external or group-level reviewers if they meet the bar and cover the local context, and a vendor-commissioned review counts only if it was genuinely independent and competent. And the periodic portfolio-wide review of aggregate AI risk was removed, replaced by re-validation whose frequency and rigour follow the use case's materiality. Change management now rests on a change-assessment framework keyed to the nature of the change and the materiality of the use case, applied to vendor-driven updates as well, with compensating controls where those updates can land without prior review.

Capability and capacity

Respondents wanted the competence expectation widened beyond builders, minimum qualifications clarified, and training treated as good practice rather than a requirement. MAS widened it to cover personnel who use AI, not only those who develop and deploy it; set competence in proportion to the firm's risk profile; and held that AI training and capacity building are supervisory expectations, not merely good practice. The form and frequency of capability reviews are left to the firm, and the infrastructure expectations are principle-based and technology-neutral, with specific hardware named only as illustration.

Generative AI and agents

Some respondents worried the risk discussion might discourage adoption, and asked MAS to state that there are no restrictions. MAS clarified that the discussion is meant to raise awareness, not to restrict: it does not limit any AI technology or use case provided the risks are addressed within the firm's appetite, and a firm should decide how to deploy AI in a safe and responsible manner. Agentic AI is singled out for dedicated attention given its autonomy, tool use, and chaining of actions, and monitoring is expected to extend, where relevant, to the reasoning processes, actions taken and tools used across a chain of agents. MAS is taking an iterative approach here: it points firms to IMDA's Model AI Governance Framework for Agentic AI as a reference and intends to consult the sector separately on further agent-specific guidance.

The timeline, now phased

Respondents found twelve months too short and asked for eighteen to twenty-four, or a phased approach. MAS granted the phasing. Oversight, identification, inventory and materiality assessment (Sections 3 and 4) are due twelve months after issuance, by 7 October 2027. The lifecycle controls and the capability to run them (Sections 5 and 6) follow by 7 October 2028. The one caveat worth heeding: a firm should apply controls to its high-risk use cases as soon as it can, rather than waiting for the 2028 date.

Who responded

Annex A lists 95 named respondents, plus 40 who asked to remain confidential: banks, insurers, asset managers, industry associations, professional bodies, consultancies, technology vendors, and individuals. It was a broad and serious response, and MAS moved on the biggest asks, the scope test, the timeline, the committee, and third-party AI, while holding its ground where the principle mattered.

Read more

For the text itself, see the clause-by-clause comparison of the consultation and the final. For the overview, see the AIRG is final and what changed. I am publishing more details on AI risk management in the coming weeks. Subscribe to get them, and future updates on the AIRG.

Subscribe for updates