GMAsia
    🇸🇬Singapore·Policy·7 Oct 2026·via Straitstimes

    Financial institutions must remain accountable for use of third-party AI tools: MAS

    The Monetary Authority of Singapore (MAS) has issued new guidelines requiring financial institutions to remain accountable for risks associated with third-party AI tools, such as data leaks or inaccurate information. These rules, published on October 7, set regulatory expectations for managing AI risks and will be implemented in phases starting October 2027.

    Nexa's Summary

    MAS's new guidelines clarify that financial institutions are responsible for AI used in their services, even if a third party developed or operates the tool. This means institutions must assess factors like model transparency, explainability, and contingency plans before deploying external AI. The focus is on the institution's ultimate responsibility for outcomes, not just the origin of the software.

    The phased rollout, with foundational governance systems required by October 7, 2027, provides time for institutions to prepare. This includes establishing AI inventories and risk assessment capabilities. For AI use cases with low potential impact, such as drafting emails or summarizing notes, basic governance policies like restricting confidential data input are considered sufficient.

    A key element of the guidelines is the risk-proportionate application of controls. AI used in critical areas like credit decisioning or insurance underwriting, which can significantly affect customers, will require more stringent scrutiny and robust controls. This approach tailors regulatory oversight to the potential consequences of AI, distinguishing between high-impact and low-impact applications rather than applying a universal standard.

    Share this article

    Original reporting by StraitstimesWe don't republish, read the full story â†’

    Related reading

    6 stories