Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Business

MAS mandates banks to own AI risk even when sourced from third parties

The Monetary Authority of Singapore issued new rules requiring financial firms to assess and manage AI risks, including those from external providers, and remain accountable for any AI used in their services.

On Oct 7, the Monetary Authority of Singapore released a set of AI governance guidelines that place full liability on financial institutions for any artificial-intelligence tools used in their offerings, regardless of whether the software is developed in-house or by external vendors. Institutions must secure sufficient assurance from providers, judge the appropriateness of the AI for their purposes, and implement compensating measures when assurance gaps exist, potentially suspending or substituting the service if risks cannot be contained.

The rules, which come into force on Oct 7 2027 with full compliance required by Oct 7 2028, require firms to maintain AI inventories, assess risks at both enterprise and use-case levels, and enforce controls such as data governance, testing, human oversight, cybersecurity, monitoring and change management. Boards and senior executives must oversee AI risk, though a dedicated AI committee is not mandatory if existing governance structures suffice. The MAS will consult the sector in 2027 on further guidance for autonomous, agentic AI systems.

Why it matters

Banks must now ensure AI from any source is safe, affecting how financial services innovate and protect customers.

In this story

AI risk managementthird-party AIfinancial institutionsregulatory guidelinesboard oversightagentic AIrisk appetite
Get the beta ↗