AI Risk Assessment: A Step-by-Step Guide to Responsible AI for Singapore Financial Institutions

AI risk assessment framework for responsible AI governance

MAS AI Risk Assessment: Why It’s Becoming Mandatory

MAS AI Risk Assessment is quickly becoming a core expectation for every financial institution in Singapore, not just an internal best practice. The Monetary Authority of Singapore (MAS) signalled this shift for years through its FEAT principles. Then, in November 2025, it moved from principles to practice. MAS proposed formal Guidelines on Artificial Intelligence Risk Management (AIRG) for the whole sector.

Whether you run a bank, insurer, capital markets business, payment service, or advisory firm, the direction is clear. MAS expects your institution to govern, inventory, assess, and monitor AI risk across the full AI lifecycle. Reactive fixes after something breaks are no longer good enough.

This guide explains what MAS expects today and what it plans to formalize next. It also walks you through a practical, seven-step MAS AI Risk Assessment process that can hold up under supervisory scrutiny.

MAS AI Risk Assessment Landscape: FEAT Principles and the AI Risk Management Guidelines

MAS’s approach to AI governance rests on two pillars. Singapore FIs need to understand how these two pillars fit together before they can run an effective MAS AI Risk Assessment.

FEAT Principles (2018)

Since 2018, MAS has expected AI and data analytics in financial services to be Fair, Ethical, Accountable, and Transparent. These principles still apply today. They haven’t been replaced — MAS has built on them instead. You can read the original document here: Principles to Promote Fairness, Ethics, Accountability and Transparency (FEAT) in the Use of Artificial Intelligence and Data Analytics.

MAS also runs the Veritas Initiative, an industry consortium. Veritas has published open-source assessment methodologies and a toolkit to help FIs put FEAT into practice. For a deeper breakdown of how each principle applies to your models, see our guide to FEAT principles for Singapore FIs.

Guidelines on AI Risk Management (AIRG) — Proposed

On 13 November 2025, MAS issued a consultation paper. It proposed new Guidelines on AI Risk Management that would apply to all financial institutions regulated in Singapore. You can read the full paper here: Consultation Paper on Guidelines on Artificial Intelligence Risk Management (see also MAS’s media release).

These Guidelines complement FEAT rather than replace it. In practice, they translate high-level principles into concrete supervisory expectations covering:

  • Board and senior management oversight of AI risk
  • AI risk management systems, policies, and procedures
  • Key controls across the full AI lifecycle
  • The capabilities and capacity FIs need to use AI responsibly

The consultation closed on 31 January 2026. MAS has also proposed a 12-month transition period once the Guidelines are formally issued. As of MAS’s most recent parliamentary update, the Guidelines apply to all AI use cases by FIs — including agentic AI — and MAS will finalise them in due course, though no firm issuance date has been confirmed yet.

Importantly, MAS has been clear that the proposed Guidelines will apply proportionately. Implementation should match an institution’s size, business model, and the materiality of its AI risk exposure. For example, a large bank running AI across core credit and fraud decisioning will face different expectations than a smaller adviser using AI for limited internal tasks. However, every FI is still expected to have foundational AI governance in place.

What this means practically: don’t wait for the final text. MAS-regulated FIs should start building the underlying capability now — an AI inventory, a risk assessment methodology, defined controls, and ongoing monitoring — instead of racing to comply on a shortened runway later.

Why a Strong MAS AI Risk Assessment Matters Beyond Compliance

Treating AI risk assessment as a genuine operational discipline, not a document exercise, protects your institution on several fronts.

  • Supervisory readiness. MAS supervisory reviews increasingly probe AI governance as part of broader technology risk assessments. As a result, institutions without a documented, defensible process risk exposure during inspections — regardless of whether the AIRG is formally in force yet.
  • Customer trust and fair outcomes. FEAT exists because AI-driven decisions, such as credit approvals, claims processing, and fraud flags, affect real customers. Getting this wrong damages trust in ways that are hard to repair.
  • Third-party exposure. MAS’s proposed Guidelines make clear that FIs cannot delegate governance responsibility to vendors. If your AI capability is bought in — a chatbot, a scoring engine, or a model embedded in a SaaS platform — your institution stays accountable for it. Our vendor and third-party AI risk checklist covers this in more detail.
  • Generative AI and agentic AI risk. MAS has flagged generative AI risks such as hallucination, data leakage, and prompt injection by name. It has also signalled that increasingly autonomous AI agents introduce additional operational and security risks that need new safeguards. These aren’t hypothetical categories for Singapore FIs; they are named, current supervisory concerns.

The 7-Step MAS AI Risk Assessment Framework for Singapore FIs

The framework below maps directly onto what MAS expects today under FEAT, and what it plans to formalise under the AI Risk Management Guidelines. Treat it as a continuous cycle rather than a one-off project — step 7 feeds back into step 1.

Step 1: Identify AI Use Cases and Build Your Inventory

MAS’s proposed Guidelines require FIs to identify, inventorise, and assess the risk materiality of every AI use case, system, or model before deployment. This inventory is the foundation the rest of your MAS AI Risk Assessment depends on.

Map every AI system in use across your institution. Include production systems, pilots, and any generative AI tools your business teams have adopted informally. For each system, capture:

  • Purpose and business owner — the decision or process it supports, and who is accountable
  • Data sources — what data trains or feeds the model
  • Deployment scope — customer-facing, internal, or embedded within a vendor product
  • Model origin — built in-house, open-source, or licensed from a third party

MAS is explicit that this inventory must stay current and apply consistently across the organization. One team shouldn’t maintain it while other business units run AI outside its view.

Step 2: Assess Risk Materiality

Once you’ve inventoried every AI use case, apply a structured methodology to assess its risk materiality. This isn’t a generic risk brainstorm. Instead, score each use case consistently against criteria tied to the FEAT principles:

  • Fairness — could the system produce biased or inconsistent outcomes across customer groups?
  • Ethics — does the use case align with your institution’s responsible-AI commitments?
  • Accountability — is there a named owner who can answer for the system’s outputs?
  • Transparency — can you explain how and why the system reached a given output, to a customer or to MAS?

Then layer on the operational categories MAS flags directly: data risk, model risk, cybersecurity risk (including adversarial attacks and data leakage), third-party or vendor risk, and — for generative AI specifically — hallucination and prompt injection risk.

Step 3: Evaluate Impact and Likelihood

For each material use case, evaluate two things: how severe the consequences would be if the risk materializes, and how likely that is to happen. MAS centres this evaluation on real-world consequences for customers and the institution — financial loss, unfair customer outcomes, regulatory exposure, and operational disruption. In fact, MAS specifically notes that AI-driven automation can fail or break down in ways that disrupt core operations.

A generative AI tool used for internal drafting carries a very different risk profile than an AI model embedded in a real-time credit or claims decision. Wherever possible, quantify impact — affected customer volumes, dollar exposure, downtime — rather than relying on vague ratings alone.

Step 4: Prioritise Based on Risk Profile

MAS’s proportionality principle means your controls should scale with the size and nature of your AI risk exposure. In other words, don’t apply one uniform standard to every system in your inventory. Use your materiality and impact scoring to separate use cases into risk tiers. Then apply the deepest scrutiny to systems that are:

  • Customer-facing and influence financial outcomes, such as credit, claims, or pricing decisions
  • Built on generative AI or autonomous agentic capability
  • Sourced from third parties with limited visibility into training data or model behaviour

MAS has also indicated that institutions with material AI risk exposure may need to establish a dedicated cross-functional AI risk committee. This signals that privatization isn’t only about ranking individual systems — it’s also about recognizing when your overall AI footprint needs elevated governance.

Step 5: Define Controls Aligned to FEAT

Translate your MAS AI Risk Assessment into concrete controls, mapped explicitly to the FEAT principles that anchor MAS’s governance approach:

  • Fairness controls — bias testing and fairness audits before and after deployment, especially for models that influence credit, insurance, or employment-adjacent decisions
  • Ethics controls — clear acceptable-use policies for generative AI and defined boundaries on autonomous agent authority
  • Accountability controls — named business and risk owners for every material AI system, with clear escalation paths when something goes wrong
  • Transparency controls — documentation that’s detailed enough to explain model logic and outputs to customers, auditors, and MAS on request

Layer in the lifecycle and technical controls MAS’s proposed Guidelines call out directly: human oversight for high-stakes outputs, robust and resilient technology infrastructure, vendor due diligence and contractual safeguards for third-party AI, and safeguards against generative AI failure modes like data leakage and prompt injection.

Step 6: Monitor Continuously Across the AI Lifecycle

MAS’s proposed Guidelines are explicit: AI risk management must extend across the entire AI lifecycle, not stop at deployment. Build monitoring that tracks:

  • Model performance and accuracy against defined baselines
  • Data and concept drift as production data diverges from training data
  • Fairness metrics, checked on an ongoing basis rather than only at launch
  • Security signals — attempted manipulation, prompt injection attempts, and anomalous query patterns
  • Incidents and near-misses, logged and fed back into your risk register

For institutions using generative AI or agentic AI, pay particular attention here. MAS has flagged these as areas of heightened, less well-understood risk that need active, ongoing oversight rather than a one-time review.

Step 7: Review, Report, and Improve

Close the loop with board and senior management oversight — a requirement MAS places at the centre of its proposed Guidelines. In practice, this means:

  • Regular reporting of your AI risk posture to the board or a designated committee
  • Updating the AI inventory as new use cases launch, models get retrained, or systems retire
  • Reassessing risk materiality whenever regulation evolves, including once the AIRG is formally issued
  • Running post-incident reviews and feeding lessons learned back into your risk methodology and controls

MAS has stated plainly that the board and senior management play a key role in AI risk governance. Therefore, this responsibility can’t sit solely within a technology or model risk team.

 

Practical Readiness Steps for Singapore FIs

MAS could finalise the AIRG without much extra runway. So, Singapore FIs should act now instead of waiting for the final text:

  • Build the AI inventory today. This is the single most concrete, actionable step MAS has flagged, and it underpins every other requirement.
  • Assign clear ownership. Every material AI use case needs a named business owner and risk owner. MAS’s accountability expectations apply whether a system was built internally or bought from a vendor.
  • Revisit vendor contracts. MAS is clear that FIs cannot delegate AI governance to third parties. Review vendor agreements for the audit rights, documentation, and assurances your institution will need.
  • Establish a proportionate governance structure. Decide whether your AI risk exposure warrants a dedicated cross-functional AI committee, based on MAS’s proposed threshold for material exposure.
  • Get ahead of generative AI and agentic AI risk specifically. MAS has called out these risk categories by name as emerging and less well understood. Don’t treat them as a subset of general model risk.

Frequently Asked Questions About MAS AI Risk Assessment

Are MAS’s AI Risk Management Guidelines mandatory yet? Not yet. The Guidelines remain a consultation proposal that MAS is finalizing. The consultation closed on 31 January 2026, and MAS has proposed a 12-month transition period once it formally issues them. Even so, FIs should align their practices now, because MAS supervisory reviews already probe AI governance maturity.

Do the Guidelines apply to smaller financial institutions? Yes, but proportionately. MAS intends the Guidelines to apply to all financial institutions, with implementation scaled to each institution’s size, business model, and AI risk exposure. Smaller FIs won’t face the same depth of governance as large banks, but MAS expects every FI to have foundational AI governance in place.

Does this cover generative AI and AI agents? Yes. MAS’s proposed Guidelines explicitly extend to generative AI and autonomous AI agents, alongside traditional predictive AI and machine learning models.

What’s the difference between FEAT and the new AI Risk Management Guidelines? FEAT (Fairness, Ethics, Accountability, Transparency) sets the high-level principles MAS has expected since 2018. The proposed AI Risk Management Guidelines build on FEAT by translating those principles into concrete supervisory expectations, including inventories, lifecycle controls, governance structures, and reporting requirements.

Key Takeaway

For Singapore FIs, AI risk assessment is shifting. It’s moving from a principles-based expectation under FEAT toward a structured, lifecycle-wide supervisory requirement under MAS’s proposed AI Risk Management Guidelines. The institutions best positioned when MAS finalizes the Guidelines will be the ones that already built the inventory, assigned ownership, embedded FEAT-aligned controls, and set up continuous monitoring. Waiting for the final text before you start puts you behind.


Need help getting ready? Pecuniya helps Singapore financial institutions build and run AI governance and risk management programs aligned with MAS’s FEAT principles and its proposed AI Risk Management Guidelines — from AI inventory design through board-level reporting. Contact us or download our AI Governance & Risk Management Whitepaper to get started.


MAS Reference Links

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.