If your firm holds a Singapore licence, you have until October 7, 2027 to find the AI you use, including AI your material SaaS vendors switched on quietly, and risk-rate each use case. A designated control function has to sign off each rating. The Monetary Authority of Singapore issued its final Guidelines on Artificial Intelligence Risk Management on October 7, 2026. They cover every financial institution and every form of AI. They also make the institution accountable for AI it bought and cannot inspect, and they say a vendor's own statement that the risks are handled will generally not count as assurance.
The lifecycle controls (testing, human oversight, third-party onboarding) get until October 7, 2028. The inventory comes first, and it is the larger job for most firms because the hardest AI to find is the AI nobody bought as AI.
What MAS Actually Finalised on October 7
MAS finalised a two-stage deadline, a scope that reaches into vendor software, and a lighter regime for firms whose AI use is genuinely low risk. Per the MAS media release, the guidelines take effect on October 7, 2027. Paragraph 1.8 of the guidelines PDF splits the work:
- Sections 3 and 4, covering board and senior management oversight, AI identification, the AI inventory and risk materiality assessment, apply from October 7, 2027.
- Sections 5 and 6, covering lifecycle controls (including third-party AI management) and AI capability and capacity, must be met by October 7, 2028.
The phasing was a concession. MAS's response to consultation feedback says the November 2025 draft proposed a single 12-month transition, and that "many respondents" asked for 18 to 24 months, citing talent shortages and the work of applying the rules retrospectively to third-party AI already in production. MAS gave 24 months for full implementation, with a catch in paragraph 13.5: a firm "should apply appropriate lifecycle controls for its high risk use cases as soon as possible, and not delay application until the end of the 24-month transition period." If you have a credit or underwriting model on the list, 2028 is not your deadline for it.
The consultation page records the paper as P017-2025, open from November 13, 2025 to January 31, 2026.
Why the Inventory Is Harder Than It Sounds
The inventory is harder than it sounds because MAS's definition of AI pulls in models your firm has run for a decade and features your vendors added last quarter. The guidelines define AI as machine-based systems that "derive outputs through learned premises," and the response paper's examples place logistic regression and gradient boosting inside scope, alongside generative AI and multi-agent systems. Rule-based RPA, if-then expert systems and Monte Carlo simulations not derived from training data fall outside. Hybrid systems, pilots and proofs of concept are in.
So the credit scorecard your model risk team already validates now belongs in the AI inventory too. Paragraph 4.6 lets you extend an existing model inventory rather than build a new one, as long as the two link up.
The harder part is embedded AI. Paragraph 4.2 says identification "should minimally cover such AI in services provided by material third-party service providers," and footnote 21 names the target: "software-as-a-service which may not be explicitly sold as AI, but contains AI features." Respondents asked MAS to limit third-party scope to AI they procured as AI. MAS declined. Its response says the challenges of finding embedded or shadow AI "do not by themselves justify excluding" it, because assessing those risks "can only be made by first identifying the sources and nature" of that AI.
MAS did soften two things. It accepts that complete identification may not be practical, and asks instead for mitigations where you have gaps: permitted-use policies, technical controls on public AI tools, monitoring for unauthorised use. And it leaves the inventory's granularity and update frequency to you. Respondents asked for a single "category-level" entry for tools like Microsoft Copilot; MAS answered that granularity should vary with the use case's risk, and that a firm running multi-agent systems in material use cases may need agent-level entries listing the tools each agent can reach.
Paragraph 4.7 lists the attributes MAS expects you to consider: purpose, approved scope (including jurisdiction), model type, data used, dependencies, lifecycle status, risk materiality rating, model review status, owners and links to documentation. If you already run a governance platform such as Credo AI or ServiceNow AI Control Tower, map its fields against that list before you buy anything else. We made the same argument about EU AI Act tooling: the inventory is where the money should go first.
How MAS Wants Each Use Case Rated
MAS wants every use case rated on three dimensions, impact, complexity and reliance, with a designated control function as the final approver. Paragraph 4.12 defines them: impact on the firm and its customers, including the sensitivity of the data; complexity, which for third-party AI explicitly includes "the level of visibility into the nature of the AI technology or the data used"; and reliance, meaning how much autonomy the AI has and how much a human is involved.
That complexity clause has a consequence buyers should see coming. A vendor that tells you less about its model makes your use case score as more complex, which pushes it toward a higher materiality rating and heavier controls. Opacity carries a compliance cost, and you will pay it unless the vendor gives you something better than marketing copy.
The assessment covers inherent and residual risk, and paragraph 4.11 requires residual risk to sit inside your risk appetite before deployment. Footnote 18 suggests quantitative appetite measures, including "number of material AI use cases with dependencies on a single provider." That is a concentration metric your board can watch, and it is the same exposure the UK chose to regulate at the cloud layer and not at the model layer.
There is a lighter path. Under paragraph 2.3 a firm may apply only basic AI governance policies if the poor performance or unavailability of its AI "is unlikely to have a material adverse impact." The examples in paragraph 2.4 are drafting emails, summarising internal documents and internal chatbots that find policies, with humans checking outputs. MAS moved to this test after respondents worried the draft's workflow-dependence criterion would catch firms whose only AI was productivity tools like Microsoft Copilot. Most banks will not qualify, but a small asset manager or payment firm might.
What Third-Party AI Accountability Means at Renewal
Third-party AI accountability means you answer to MAS for your vendor's model, and you need contract terms that let you meet that duty. Paragraph 5.11 says "the FI retains primary accountability for its use of third-party AI." Respondents argued that providers should own model safety, training data quality and platform security. MAS's response: the choice to onboard rests with the firm, so the firm stays accountable "even where an FI may not be in a position to influence or compel third-party AI providers."
On evidence, respondents proposed accepting ISO 42001 or SOC 2 Type 2 reports, and a few asked for a "safe harbour" for reputable providers. MAS granted no safe harbour. It accepts certifications or external assessments only where the assessor is independent and competent and the report covers the risks you cannot see yourself. Self-attestations or "statements" by the provider, "particularly where unsupported by evidence, would generally not be considered as effective." Where transparency is thin, the guidelines expect compensating testing on your own data and use cases, or more human oversight of outputs. If neither gets residual risk inside appetite, MAS expects you to consider "limiting or suspending the third-party AI service, or replacing the relevant third-party provider."
Paragraph 5.11(f) lists the contract terms MAS has in mind: performance guarantees, data protection, the right to audit, notification when AI is introduced and updated, or seeking your agreement before the vendor incorporates AI. MAS stopped short of requiring you to track every vendor model update. It accepts you may not be able to compel notification, but expects contracts to give "a risk-proportionate degree of visibility," and where significant changes can land without your review, compensating controls such as enhanced monitoring.
None of this replaces outsourcing rules. MAS says the AI guidelines are read alongside existing requirements, including the Guidelines on Outsourcing (Banks) in force since December 11, 2024. Expect your vendor management team to ask whether one assessment can serve both; one respondent raised the risk of a parallel, duplicative framework, and MAS answered by cross-referencing the outsourcing rules in paragraph 1.2 without listing every overlap.
Most standard AI vendor terms give you little of this. Our review of AI vendor exit clauses found standard terms give zero to 90 days to leave, and the six security review questions we published in September cover subprocessor disclosure and ISO 42001, two of the places MAS's assurance test will land.
Where Agents and Committees Land
On agents, MAS has deferred the detailed rules, and on committees, it has dropped a requirement. The media release says MAS will consult the industry in 2027 on what additional agentic AI guidance would help. Until then, the response paper names the IMDA Model AI Governance Framework for Agentic AI (version 1.5, published May 20, 2026) as the practical reference, and says monitoring should extend to "reasoning processes, actions taken, and tools used" across chains of agents. If your agent logs only capture the final output, they will not meet that line; our guide to agent audit logging covers the event set you would need.
The draft expected firms with material AI exposure to stand up a dedicated cross-functional AI committee. Respondents called that duplicative, and MAS amended paragraph 3.3: you can manage AI risk through existing model risk or technology risk structures, provided you can show a consolidated view. Global groups can run the committee at regional or global level. The cost of that flexibility is paragraph 3.6: local senior management "remains accountable" for whether group frameworks meet Singapore's requirements and must be able to show MAS how they discharge oversight.
How This Compares to Other Regulators
Singapore's version is more prescriptive than the global baseline and less prescriptive than a statute. The Financial Stability Board's June 2026 consultation set out twelve nonbinding sound practices for AI adoption, with Practice 12 covering vendor due diligence, contracts and exit planning, and naming the same "information gaps" and "accountability gaps" MAS addresses. US insurance regulators are heading the same way: the NAIC's draft exam supplement asks insurers for a model inventory but, as we reported, lets each insurer set its own materiality bar. MAS fixes the dimensions and names a control function as approver.
Commentary on the draft, such as Simmons & Simmons' February 2026 note, read it as a lifecycle regime with board oversight on top. The final text keeps that shape. What changed is proportionality and timing, and the third-party scope held. Banks already deploying agents at scale, like DBS with its credit-memo rollout, now have a dated deadline to show the inventory behind them.
What to Do Before October 2027
This Month:
- Name the control function that will own AI identification, the inventory and materiality sign-off. MAS asks for a designated owner in paragraphs 4.3, 4.9 and 4.13; one function for all three is simplest.
- Pull your model inventory and tag every logistic regression and gradient-boosted model as AI. Those are in scope, and they already have validation records you can reuse.
- List your material third-party service providers from the outsourcing register and send each a written question: which AI features are in the service you deliver to us, and which are on by default?
This Quarter:
- Write the materiality methodology on impact, complexity and reliance, and score your five highest-risk use cases first, since paragraph 13.5 of MAS's response paper expects controls on those before 2028.
- Add the paragraph 5.11(f) terms (AI introduction notice, audit right, performance guarantees) to your AI vendor contract template, and ask each renewing vendor for an independent third-party assessment of its AI.
- Add a board risk appetite measure for single-provider concentration across material AI use cases.
Before Renewal:
- For any vendor that will not disclose enough to rate its AI, budget the compensating testing on your own data now, or plan the replacement. Under paragraph 5.11, keeping an opaque provider means doing that testing yourself.
The Bottom Line
Most bank model risk programmes start from models the bank built and can validate. MAS's guidelines assume a bank's AI arrives in other people's software, and they hold the bank accountable anyway. That makes vendor disclosure a procurement term with a deadline: identification of embedded AI in material providers is due October 7, 2027, and lifecycle controls on third-party AI by October 7, 2028.
Send the AI-feature question to your material providers this month; their answers are the start of your inventory.
Continue Reading
- NAIC's Draft AI Exam Lets Insurers Set Their Own Materiality Bar
- AI Vendor Security Review: 6 Questions That Change the Answer
- AI Vendor Exit Clauses: Standard Terms Give 0 to 90 Days to Get Out
- Britain Regulated Four Clouds. Not the Models Inside.
- EU AI Act Governance Tools: Buy Inventory, Not Policy Packs
- DBS Put 1,500 Bankers on Agents. The 30% Is a Goal.
