Summary

  • MAS says a financial institution remains primarily accountable for AI it relies on from outside providers, including AI embedded in services.
  • Board oversight and use inventories are due first; lifecycle controls follow, with risk-based measures for high-impact uses expected sooner.

Accountability follows the use case

A bank cannot move supervisory responsibility across the table by signing a cloud or software contract. Singapore’s Monetary Authority (MAS) says the choice to onboard and use a third-party AI remains the financial institution’s decision, and primary accountability stays there. The final Guidelines therefore focus on where AI enters a business process, what it can affect and how much the institution depends on it—not simply on which company owns the model.

Issued on 7 October, the Guidelines apply to all financial institutions and all forms of AI. MAS defines the perimeter broadly enough to include externally supplied models, tools and services, as well as AI embedded in another provider’s product or used by that provider to deliver it. A procurement team may never see the words “AI” on an invoice and still need to find the dependency. MAS’s announcement says the framework complements existing laws and guidance; it does not announce a new ban on a class of systems.

That boundary turns visibility into an institutional control. Firms should identify where AI is used, maintain an inventory at a useful level and assess each use case by potential impact, technical and application complexity, and reliance. Reliance includes how autonomous the system is and how much human oversight remains. A register can connect to existing data and supplier records; MAS is not prescribing a separate AI bureaucracy for its own sake.

The governance chain begins with the board approving and reviewing risk appetite, roles and direction. Senior management is expected to put the framework into operation, assign owners, escalate material risks and report back. Existing committees may do the work if oversight is coordinated and effective; MAS says a dedicated AI committee is not required solely because the Guidelines exist.

The supplier boundary becomes a test

For a material external system, the institution should test suitability in the context where it will actually be used, including with its own data where appropriate. The Guidelines point firms toward risk-appropriate contractual visibility into the introduction of AI and subsequent changes. They also call for attention to supply-chain dependencies, concentration, change management, contingency arrangements, legal terms, staff capability and system complexity.

This is not a demand for every provider to disclose every technical detail. MAS acknowledges that disclosure can be limited. The institution then has to recognize the blind spot and compensate—for example with additional testing or human review. If the remaining risk cannot be brought within its appetite, the listed choices are operational: limit, suspend or replace the service. The risk is not made manageable simply because it sits behind a vendor’s interface.

The transition is phased. The Guidelines take effect on 7 October 2027, with governance and identification, inventory and materiality work under sections 3 and 4 due then. Sections 5 and 6, covering fuller lifecycle controls and capability, follow by 7 October 2028. That sequence is not a two-year grace period for every use: MAS’s feedback response says high-risk cases should receive appropriate lifecycle controls as soon as possible. For genuinely low-impact uses, basic policies can be proportionate, but still include permitted-use boundaries, named oversight, human review, approved tools, staff education and checks.

MAS also treats agentic AI as an evolving risk area. General expectations apply now; the regulator says it intends to consult the sector in 2027 on any additional agent-specific guidance. That is a future consultation, not a present prohibition or evidence that a particular institution has lost control.

The institutional question is whether the party that chooses the use can see enough, test enough and retain a practical stop option. Heng Lu’s Note 32 offers an editorial analogy about delegated authority and visibility in internet governance; it is not evidence about Singapore’s financial rules. The MAS documents themselves provide the case: responsibility remains where the use is authorized, even when execution depends on an external chain.

Sources