Singapore Raises The Bar For AI Risk Management In Finance

Blog
Corporate Risk Leaders
Third-Party Risk Management
AI Platforms & Applications
30 Sep, 2026

In December 2025, Verdantix examined Singapore’s proposed approach to AI risk management in financial services following the Monetary Authority of Singapore's (MAS) launch of a consultation on new AI risk management guidelines. The proposals called for board and senior management oversight, AI inventories, risk materiality assessments and controls across the AI life cycle. With the consultation now closed, MAS has moved the conversation towards implementation, even as the rapid emergence of agentic AI creates new governance challenges. For financial institutions, the challenge is no longer whether to govern AI, but how to build risk management capabilities that can keep pace with its rapid adoption and growing autonomy.

The proposed guidelines built on MAS’s existing principles of fairness, ethics, accountability and transparency (FEAT) and sought to apply AI risk management proportionately across financial institutions. They also broadened the scope of AI risk beyond traditional financial and operational risks to include conduct, financial crime, reputational, security, legal, intellectual property, privacy and third-party risks

A key development since our previous blog is MAS’s March 2026 publication of its AI Risk Management Toolkit, developed with 24 banks, insurers, capital market firms and other industry participants. The Operationalisation Handbook that accompanies this provides practical guidance for implementing AI risk management frameworks, supported by case studies from financial institutions. The toolkit covers traditional AI, generative AI and emerging agentic AI. This shifts the focus from what AI risk governance should look like in theory to how financial institutions can operationalize it in reality.

The emergence of AI agents makes this shift particularly important. Unlike conventional AI systems that primarily generate outputs, agents can take actions across financial workflows and enterprise systems, potentially at a speed that limits practical human intervention. In July 2026, MAS and industry partners published Safeguards for Agentic Finance at Runtime (SAFR), an industry-developed framework focused on how AI agent actions are authorized, assessed and recorded at the point of execution. It proposes real-time safeguards to keep agents within predefined mandates, policies and risk boundaries. SAFR is an industry framework, rather than regulatory guidance or a new supervisory requirement.

For risk leaders, this reinforces a key message from the original consultation: AI governance cannot stop at model oversight. As AI becomes more autonomous, controls must increasingly address what AI can do, when it can act and how its actions are monitored; a task that is not easily achievable.

Third-party AI remains a critical risk

Third-party risk was a key element of MAS’s original proposals and is increasingly relevant as firms expand their use of external AI technologies. Survey data from the Singapore Infocomm Media Development Authority (IMDA)show that among Singapore firms already adopting AI, 84% use off-the-shelf generative AI tools, while 52% use domain-specific AI solutions and 44% use customized or proprietary AI. These figures are not mutually exclusive; organizations can use several types of AI solution at the same time, creating a more complex risk landscape where critical AI capabilities may sit across internal systems, embedded software and external providers. Risk teams therefore need visibility across both internal and third-party AI, supported by ongoing monitoring of material changes to providers, controls, data use and model behaviour.

The next priority is moving from collection of AI inventories and policies to continuous oversight. Financial institutions should:

  • Maintain visibility across the AI estate. This should include internally developed, procured and embedded AI, including relevant third-party applications.
  • Apply risk-based governance. Materiality must be used to determine appropriate testing, human oversight, monitoring and assurance.
  • Prepare for autonomous AI by establishing clear mandates, approval boundaries, monitoring and audit trails for material agentic AI use cases.

Singapore’s approach demonstrates how AI risk management is moving beyond high-level principles towards operationalization. For financial institutions, the priority is to build an AI risk management capability that can adapt as AI moves from experimentation into increasingly autonomous business processes.

To learn more about best practices, explore our AI Applied module and Third-Party Risk Management module, and to find out about the technology that can help organizations strengthen their TPRM programmes, look out for the upcoming Green Quadrant on TPRM early next year. 

Discover more Corporate Risk Leaders content
See More