WEGRY

17.1000.06%

Singapore’s central bank wants all FinTech AI use cases subject to independent review

LongbridgeAII'm LongbridgeAI, I can summarize articles.

Singapore’s Monetary Authority (MAS) has issued new guidelines requiring financial institutions to subject all AI use cases, including generative and agentic AI, to independent review before deployment. The regulator emphasizes that AI's complexity increases risk and uncertainty. FIs must expand risk management frameworks, conduct technology and cybersecurity reviews, maintain AI inventories, and establish contingency plans for high-risk applications. MAS holds firms accountable for third-party AI services, with the guidelines taking effect on October 7, 2027.

Singapore’s Monetary Authority, which acts as both central bank and finance industry regulator, wants all local industry players to seek independent review of AI use cases before deployment.

The island nation’s combination of strict regulation and low taxes have made it one of the world’s premier finance hubs.

One of the roles of Singapore’s Monetary Authority (MAS) is ensuring the nation retains that status, but in its first Guidelines on Artificial Intelligence Risk Management for Financial Institutions, published on Wednesday, warns that AI increases risk.

“The use of AI can improve performance across business and functional areas but its complexity and probabilistic nature can lead to greater uncertainty, as well as unexpected or more biased behaviour that is harder to identify compared to the use of simpler methods,” the guidelines state.

And that’s MAS’s view of old-school AI: it rates generative AI as even riskier.

“The greater complexity of Generative AI gives rise to even greater uncertainty and unexpected behaviour compared to AI,” MAS warns, citing “noise that is inherent in training data, training data that may not be representative, or when the model encounters scenarios that are not present in its training data” as sources of risk.

The regulator fears agentic AI “could further amplify these risks.”

MAS therefore calls for financial institutions (FIs) to expand their risk management frameworks to cover AI and expects board and senior management to make that happen.

The regulator also wants all AI use cases to undergo independent review before going into production.

“Prior to deployment, an FI should subject the AI use case, including its underlying systems or models, to reviews by parties not involved in its development to ensure that the relevant controls, such as evaluation and testing, have been adhered to,” the guidelines state. MAS also wants regulated entities to run technology and cybersecurity reviews “to ensure that AI can be deployed into the production environment in a controlled and secure manner.”

If an AI project survives those reviews, MAS wants ongoing monitoring of both the FI’s own systems and any third-party AI powering an application.

“Given the uncertainties associated with AI, their dynamic nature and the potential for model staleness and performance degradation due to data or model drifts over time, ongoing monitoring is critical to ensure that deployed AI operates as intended and remains fit for purpose over time,” the guidelines state.

MAS does not see failings by third-party AI suppliers as an acceptable excuse for AI problems at entities it regulates, and it wants FIs to monitor their suppliers’ products and services to ensure they remain stable and secure.

“FIs remain accountable for AI used in the services they deliver, including AI developed, operated or provided by third parties,” the regulator explained. “FIs should obtain sufficient assurance from third-party providers, assess whether third-party AI is suitable for their intended use, and apply compensating controls where practical constraints or assurance gaps arise. If the risks cannot be brought within the FI’s risk appetite, it should consider limiting, suspending or replacing the use of the third-party AI service.”

The regulator also wants Singaporean FIs to maintain up-to-date inventories of all AI used in their business. If that’s not possible due to third-party services using AI without revealing it, financial institutions need to find ways to manage the risk of unknowable AI contributions.

Another of the guidelines calls for FIs to develop contingency plans and fallback options for AI used in high-risk applications. Those plans should include “alternative systems or manual processes, to ensure business continuity in case of AI failure or unexpected behavior.”

The guidelines come into force on October 7, 2027. ®

Login to unlock3,373characters for free

Due to copyright restrictions, please log in to your Longbridge account to view this content.
Thank you for your understanding and support of licensed content.