A complete guide
AI risk management in finance in Singapore
One place for all of it: what AI risk management is, what the MAS AIRG requires and how it changed, the wider Singapore framework, and how to apply it.
AI risk management in finance in Singapore now has a clear centre: the Monetary Authority of Singapore's AI Risk Management Guidelines (AIRG), issued in final form on 7 October 2026 and in force from 7 October 2027. This guide pulls together everything on this site into one map: what AI risk management is, what the AIRG requires and how it changed, how it sits within Singapore's wider framework, and how a firm or a supervisor applies it. I developed the AIRG while leading AI risk supervision at MAS, and now work independently through Quaintitative, so take this as an informed but independent reading.
The idea underneath all of it is simple. AI risk is mostly an extension of risks a firm already manages, model risk, third-party risk and technology risk, scaled to how much harm a failure would do. Each link below goes to a focused page; start wherever your question sits.
Start here: what AI risk management is
- AI risk management, explained - what it is, the questions at its core, and the areas a programme covers.
The AIRG itself
The AIRG is the core of AI risk management in Singapore's financial sector. These pages cover it from every angle.
- The AIRG explained - a guide to the guidelines.
- The AIRG is final - the 7 October 2026 final, and the points that change what firms do.
- What changed - from the November 2025 consultation to the final.
- Consultation draft vs final, clause by clause - the full blackline comparison.
- MAS's response to feedback - what the industry raised, and why MAS changed what it did.
- The AIRG in practice - identification, inventory, risk materiality and lifecycle controls as a working system.
- The transition timeline - what is due by 7 October 2027 and by 2028.
- The AIRG and third-party AI - where the final tightened most, and where most firms' real exposure sits.
The wider Singapore framework
The AIRG sits within a set of Singapore frameworks built up over years, and alongside the main international ones.
- AI risk management in Singapore - the timeline from FEAT and Veritas to the AIRG, the MindForge Toolkit and SAFR.
- The MindForge Toolkit guides - a guide per area of the MAS MindForge AI Risk Management Toolkit, each tied to the AIRG.
- AIRG, MindForge and the CRI framework - how expectations, risks and controls line up across the three.
- The AIRG compared to the EU AI Act, NIST and ISO 42001 - side by side, area by area.
In practice, by role
The same framework reads differently from each seat.
- For boards - the oversight the AIRG expects, and the questions to ask.
- For leadership and senior management - running the framework the board approves.
- For business lines, the first line - identifying and running AI within appetite.
- For risk and compliance, the second line - independent oversight and challenge of the firm's AI.
- For validators, reviewers and assurance - independent validation that the AI does what the firm says.
- For internal audit, the third line - independent assurance over the AI risk framework.
- For regulators and supervisors - judging whether a firm's AI risk management is adequate.
- For finance professionals - the basics of using AI responsibly in your work.
By sector
The AIRG applies to every financial institution. How it lands depends on what the firm does.
- For banks - credit, fraud and AML, trading, operations.
- For insurers - underwriting, pricing, claims and distribution.
- For Capital Markets Services (CMS) licence holders - fund management, dealing, research and advice.
- For financial advisers - advice, suitability and client-facing tools.
By topic
Doing a specific thing with AI, with the risks in mind.
- AI investing - the risks and the mental models to manage them. To build it, see AI for investing.
- AI forecasting - the risks and the mental models to manage them. To build it, see AI forecasting.
Going deeper
- Governing AI at scale - keeping control as the number of AI systems grows.
- Agentic AI risk management and runtime governance - governing AI that acts, not only AI that produces an output.
- AI testing, evaluation and assurance - where the controls stop being paper.
The reference list
The primary sources worth knowing, in one place.
- AI risk management in finance: the resource list - supervisory guidance, standards, model risk management, tooling and research, focused on financial services.
- Also on GitHub as awesome-ai-risk-finance, where it is kept the most up to date.
Work with me
I train and advise financial institutions, regulators and boards on the AIRG and AI risk management. See the courses and workshops, or get in touch. I am also publishing more on AI risk management in the coming weeks. Subscribe to get it.