Quaintitative

AIRG

Singapore's AI Risk Management Guidelines (AIRG)

The AI Risk Management Guidelines, known as the AIRG, are the Monetary Authority of Singapore's guidelines on how financial institutions should manage the risks of using AI. MAS issued them for consultation in November 2025. They apply to all financial institutions, and cover AI use cases, systems and models. I developed the AIRG while leading AI risk supervision at the MAS.

What the AIRG covers

The guidelines are risk-proportionate and technology-neutral, so they are meant to hold across machine learning, generative AI and agents. They are best read as one system rather than a checklist, and are organised in five parts.

  • Scope. AI use cases, systems and models, across all financial institutions.
  • Oversight. Board and senior management roles and responsibilities, and making sure AI risk management across the organisation is adequate.
  • Key systems, policies and procedures. Identifying where AI is used, assessing the risk materiality of each use, and maintaining an AI inventory.
  • AI lifecycle controls. Controls applied across the AI lifecycle: data management, transparency and explainability, fairness, human oversight, third-party AI, AI selection, evaluation and testing, technology and cybersecurity, reproducibility and auditability, reviews and monitoring, and change management.
  • AI capability and capacity. The AI capabilities and technology infrastructure a firm needs to manage AI risk.

Whether the AIRG applies to you, and how much

How much of the AIRG applies depends on how a firm uses AI. A firm first asks whether it has AI use cases, systems or models. If it does, it asks whether AI is an integrated part of its business processes. Where AI is integrated, the firm is expected to establish oversight, identify and inventory its AI, assess risk materiality, and apply the lifecycle controls in proportion to that materiality, with adequate capability and capacity behind them. Where AI use is limited, the firm institutes basic policies commensurate with its level of AI adoption.

How materiality is assessed

Not every AI use warrants the same controls. Materiality is assessed on impact, complexity and reliance, and the depth of the lifecycle controls follows that assessment. This is why the guidelines stay proportionate rather than applying a fixed set of controls equally to everything.

How the AIRG relates to FEAT and the 2024 model risk paper

Singapore already had the FEAT principles on fairness, ethics, accountability and transparency, and the industry-developed Veritas methodology for assessing FEAT. These set principles but were not a full AI risk management framework, and they predate generative AI. In December 2024, MAS published an Information Paper on AI Model Risk Management, setting out observations from a thematic review of banks. I led that thematic review. The AIRG builds on both, and turns them into operational expectations across machine learning, generative AI and agents.

How it compares to the EU AI Act, NIST and ISO 42001

The AIRG sits alongside other frameworks that address the same risks in different forms. The EU AI Act is a binding, tiered law. The US NIST AI Risk Management Framework is voluntary. ISO/IEC 42001 is a certifiable standard for an AI management system. The AIRG is a financial-sector regulator's risk-proportionate guidance. The underlying areas, such as inventory, materiality, oversight and lifecycle controls, are largely common across these, so work done for one maps substantially onto the others.

Where the AIRG stands now

MAS issued the guidelines for consultation in November 2025. A final version is expected in 2026, with a transition period for firms after issuance. This page reflects the consultation version. For the current text and timelines, check the MAS site.

Help implementing the AIRG

I train and advise financial institutions on the AIRG, as well as AI governance and risk management in general. See the courses and workshops, or get in touch.