Urgent.News

What's breaking now, across thousands of outlets.

AI

Singapore central bank issues risk rules on banks' AI use

Banks in Singapore must seek an independent review of any forthcoming AI projects before implementation, according to new rules.

Singapore's financial regulator, the Monetary Authority of Singapore (MAS), has issued guidelines for artificial intelligence (AI) risk management in the country's financial institutions. These guidelines aim to ensure that banks, insurers, and payment companies appropriately govern AI systems that can influence customer outcomes, risk decisions, and execution.

The guidelines will take effect on October 7, 2027, with core expectations to be implemented by the same date in 2027 and additional requirements by October 7, 2028. Financial institutions can implement the rules in phases, with the level of detail required based on their extent of AI use, system complexity, and potential harm.

The guidelines apply to all financial institutions and all forms of AI technology, without prescribing a single compliance model. Instead, MAS asks firms to tailor their controls according to the specifics of their AI usage. This approach acknowledges the diverse needs of financial institutions, from smaller firms and fintechs to large banks.

However, MAS is clear that AI governance cannot be limited to technology teams. Boards and senior management must provide effective oversight, set clear roles and responsibilities, define risk appetite, and ensure policies and procedures are in place.

The MAS guidelines focus on managing AI risks at two levels: enterprise-wide and at the individual use case level. At the enterprise level, firms must understand their overall AI exposure by identifying AI usage, maintaining inventories, and assessing the risk relevance of various applications. At the use case level, firms need to apply controls throughout the AI life cycle, including data governance, testing, human oversight, cybersecurity, monitoring, and change management.

This life-cycle approach is crucial as AI risks can persist even after a model is launched, as models can degrade over time, behave unexpectedly with changing data, or produce unintended results in new workflows.

Furthermore, MAS emphasizes the importance of third-party AI, as many financial institutions rely on external providers for AI development, operation, or supply. Even when third-party AI is used, financial institutions remain accountable for the services they deliver, and must obtain sufficient assurance from providers, assess suitability for intended use, and apply compensating controls where necessary.

If risks cannot be brought within the institution's risk appetite, MAS suggests limiting, suspending, or replacing the third-party AI service. This signals that vendor due diligence will become a regulatory and risk management issue, reflecting the growing significance of AI in financial operations.

Written by urgent.news from e27's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at finextra.com →

More in AI

More from Thursday 8 October →