The Monetary Authority of Singapore (MAS) issued Guidelines on Artificial Intelligence Risk Management on 7 October 2026. They apply to all financial institutions and all forms of AI, including generative AI and AI agents, and take effect on 7 October 2027.
Firms remain accountable for AI developed, operated or provided by third parties, MAS says. If the risks of a third-party AI service cannot be brought within a firm’s risk appetite, it should consider limiting, suspending or replacing it.
Business Pill · WHAT IS INSIDE WHAT YOU BUY
A short explainer of embedded dependency: something you rely on that is hidden inside something else you use. It teaches the general idea only and says nothing about any company or regulator in this story.
The key insight: As we read it, the guidelines make buying AI part of supervised risk management. Third-party AI is to be identified, tested with the firm’s own data and kept within risk appetite, and where it cannot be, a firm should consider limiting, suspending or replacing it.
What Firms Must Do
MAS says boards and senior management should oversee AI risks with clear roles, risk appetite and frameworks. Existing governance structures may be used, and firms need not set up a dedicated AI committee solely to meet this expectation.
Firms should identify their AI use, keep an inventory and assess the risk materiality of each use case. The guidelines name three dimensions to cover at minimum: impact, complexity and reliance, including how much autonomy the AI is given.
Controls then follow the AI life cycle: data management, transparency and explainability, fairness, human oversight, evaluation and testing, cybersecurity, pre-deployment reviews, monitoring and change management. Use cases assessed as high risk materiality should undergo formal independent validation before deployment.

The Third-Party Clause
The guidelines say the decision to use third-party AI is ultimately the firm’s, and that it retains primary accountability for that use. Contracts should give firms visibility over the introduction of AI and later updates, and firms should test third-party AI in the context of their own use cases, including with their own data.
Where provider transparency is limited, firms may review certifications or external assessments by independent parties, which the guidelines specify are “not self-attestations”. They also list concentration risk from over-reliance on key third-party AI providers among the areas to assess.
At a minimum, identification should cover AI embedded in services from material third-party providers. The guidelines give the example of software-as-a-service that may not be explicitly sold as AI but contains AI features.

Agents and Kill Switches
For AI agents, the guidelines suggest inventory attributes such as the tools and systems an agent can access and the guardrails imposed. Monitoring may cover reasoning processes, actions taken and tools used.
For high risk materiality AI, firms should consider “kill switches” or override mechanisms to deactivate a system rapidly, with contingency plans that are tested regularly. MAS intends to consult the industry in 2027 on what additional guidance on agentic AI would be useful.
When Basic Rules Are Enough
Firms may apply basic AI governance policies where poor performance or unavailability of the AI is unlikely to have a material adverse impact. MAS’s examples include AI that helps draft customer emails or summarise documents for internal reference.
Basic policies should at least set clear accountability for AI oversight, for example by designating a senior manager, along with permitted and prohibited uses, an approved list of AI tools and regular compliance checks.
“With greater regulatory clarity on financial institutions’ AI usage, FIs can innovate with confidence, while maintaining the trust of customers and the resilience of Singapore’s financial system,” said Ho Hern Shin, Deputy Managing Director at MAS.
The Structural Read
The heaviest part comes second. On our count from the contents page, Section 5 on life-cycle controls runs to 13 of the 30 pages, and MAS gives firms until 7 October 2028 to meet it.
Agents get their own attributes. The guidelines suggest recording the tools and systems an agent can access, and monitoring reasoning processes, actions taken and tools used.
Concentration becomes something to measure. Among example risk appetite measures, the guidelines list the number of material AI use cases with dependencies on a single provider.
MAS, Guidelines on AI Risk Management, 7 October 2026
“The decision to onboard and use third-party AI is ultimately a decision of the FI, and the FI retains primary accountability for its use of third-party AI”
Three Implications
VENDORS IN THE INVENTORY The guidelines say identification should minimally cover AI in services from material third-party providers.
INDEPENDENT ASSURANCE Where provider transparency is limited, firms may review independent certifications or external assessments rather than self-attestations.
A PHASED START Oversight and inventory expectations apply from 7 October 2027, and life-cycle controls by 7 October 2028, MAS says.
The Business Engineer Lens
This story maps onto the Business Engineer framework Enterprise AI: From Software to Substrate.
The framework’s starting point: “Enterprise vendors don’t sell software anymore—they sell irreversibility. The product is the interconnection.”
As we read it, MAS’s third-party clause asks financial firms to keep the opposite option open: to be able to limit, suspend or replace an AI service whose risks cannot be brought within their appetite, including AI that arrives embedded inside software they already use.
What Is Not Established
We read MAS’s release and the full guidelines; we did not read the accompanying response to feedback paper. The guidelines set supervisory expectations and do not specify penalties, and they do not name any AI provider. We did not contact MAS.
The Bottom Line
MAS’s AI risk guidelines take effect on 7 October 2027, with oversight and inventory expectations from that date and life-cycle controls by 7 October 2028. Firms keep primary accountability for third-party AI, should test it with their own data, and should consider limiting, suspending or replacing it if its risks exceed their appetite.
94,000+ executives read Business Engineer for the AI strategy frameworks cited by ChatGPT, Claude, and Perplexity.
A note on sourcing. We read MAS’s media release and the full 30-page guidelines of 7 October 2026; we did not read the response to feedback paper. Page counts per section are our arithmetic. We did not contact MAS. Nothing here is a forecast, and nothing here is financial or investment advice.
Sources: MAS media release: supervisory expectations on responsible AI adoption by financial institutions (7 Oct 2026) · MAS: Guidelines on Artificial Intelligence Risk Management (7 Oct 2026)









