AI Risk Assessment: A Step-by-Step Guide to Responsible AI for Singapore Financial Institutions
For Singapore’s financial institutions, AI risk management is no longer a matter of internal best practice — it’s fast becoming a defined supervisory expectation.
The Monetary Authority of Singapore (MAS) has been signalling this shift for years through its FEAT principles, and in November 2025 it moved decisively from principles to practice with a consultation paper proposing formal Guidelines on Artificial Intelligence Risk Management (AIRG).
Whether you’re a bank, insurer, capital markets intermediary, payment service provider, or financial adviser, the direction of travel is clear: MAS expects AI risk to be governed, inventoried, assessed, and monitored across the full AI lifecycle — not managed reactively after something goes wrong.
This guide walks through what MAS currently expects (and is proposing to formalize) and gives you a practical AI Risk Assessment, seven-step process for running an AI risk assessment that stands up to supervisory scrutiny.
Where MAS Stands Today: FEAT Principles and the AI Risk Management Guidelines
MAS’s approach to AI governance rests on two pillars, and Singapore FIs need to understand how they fit together.
FEAT Principles (2018)
 Since 2018, MAS has set out expectations that AI and data analytics used in financial services should be Fair, Ethical, Accountable, and Transparent. These principles remain in force today and continue to guide how FIs should think about AI use — they haven’t been replaced, they’ve been built upon. The original document is available on MAS’s website: Principles to Promote Fairness, Ethics, Accountability and Transparency (FEAT) in the Use of Artificial Intelligence and Data Analytics. MAS also runs the Veritas Initiative, an industry consortium that has published open-source assessment methodologies and a toolkit to help FIs operationalize FEAT in practice.
Guidelines on AI Risk Management (AIRG) — proposed On 13 November 2025
MAS issued a consultation paper proposing new Guidelines on AI Risk Assessment that would apply to all financial institutions regulated in Singapore: Consultation Paper on Guidelines on Artificial Intelligence Risk Management (see also MAS’s media release). These Guidelines are designed to complement FEAT, not replace it, by translating high-level principles into concrete supervisory expectations covering:
- Board and senior management oversight of AI risk assessment
- AI risk management systems, policies, and procedures
- Key controls across the full AI lifecycle
- The capabilities and capacity FIs need to use AI responsibly
The consultation closed on 31 January 2026, and MAS has proposed a 12-month transition period once the Guidelines are formally issued. As of MAS’s most recent parliamentary update, the Guidelines apply to all AI use cases by FIs — including agentic AI — and will be finalized in due course, though no firm issuance date has been confirmed. Importantly, MAS has been clear that the proposed Guidelines will apply proportionately: implementation is expected to be commensurate with an institution’s size, business model, and the materiality of its AI risk exposure. A large bank running AI across core credit and fraud decisioning will face different expectations than a smaller adviser using AI for limited internal support functions — but every FI is expected to have foundational AI governance in place.
What this means practically: even before the Guidelines are formally issued, MAS-regulated FIs should be building the underlying capability now — an AI inventory, a risk assessment methodology, defined controls, and monitoring — rather than waiting for a final text and a shortened runway to comply.
Why This Matters Beyond Compliance
Treating AI risk assessment as a genuine operational discipline — not a document exercise — protects the institution on several fronts:
- Supervisory readiness. MAS supervisory reviews increasingly probe AI governance as part of broader technology risk assessments. Institutions without a documented, defensible process will be exposed during inspections, regardless of whether the AIRG is formally in force yet.
- Customer trust and fair outcomes. FEAT exists because AI-driven decisions — credit approvals, claims processing, fraud flags — affect real customers. Getting this wrong damages trust in ways that are hard to repair.
- Third-party exposure. MAS’s proposed Guidelines make clear that FIs cannot delegate governance responsibility to vendors. If your AI capability is bought in — a chatbot, a scoring engine, an embedded model in a SaaS platform — your institution remains accountable for it.
- Generative AI and agentic AI risk. MAS has explicitly flagged generative AI risks such as hallucination, data leakage, and prompt injection, and has signaled that increasingly autonomous AI agents introduce additional operational and security risks requiring new safeguards. These are not hypothetical categories for Singapore FIs — they are named, current supervisory concerns.
The 7-Step AI Risk Assessment Framework for MAS-Regulated FIs
The following AI Risk Assessment framework maps directly onto what MAS expects today under FEAT and what it is proposing to formalize under the AI Risk Management Guidelines. Run it as a continuous cycle, not a one-off project — step 7 feeds back into step 1.
1. Identify AI Use Cases and Maintain an AI Inventory
MAS’s proposed Guidelines require FIs to establish systems and procedures to identify, inventorize, and assess the risk materiality of all AI use cases, systems, or models before deployment. This inventory is the foundation the rest of the AI Risk Assessment framework depends on.
Map every AI system in use across the institution — production systems, pilots, and generative AI tools adopted informally by business teams — and capture, for each one:
- Purpose and business owner — the decision or process it supports, and who is accountable
- Data sources — what data trains or feeds the model
- Deployment scope — customer-facing, internal, or embedded within a vendor product
- Model origin — built in-house, open-source, or licensed from a third party
MAS is explicit that this inventory must be kept up to date and applied consistently across the organization — not maintained by one team while other business units run AI outside its view.
2. Assess Risk Materiality
Once every AI use case is inventoried, MAS’s proposed approach calls for FIs to apply a structured methodology to assess risk materiality for each one. This isn’t the same as a generic risk brainstorm — it means consistently scoring each use case against defined criteria tied to the FEAT principles:
- Fairness — could the system produce biased or inconsistent outcomes across customer groups?
- Ethics — is the use case consistent with the institution’s responsible-AI commitments?
- Accountability — is there a named owner who can answer for the system’s outputs?
- Transparency — can the institution explain how and why the system reached a given output, to a customer or to MAS?
Layer on the operational categories MAS flags directly: data risk, model risk, cybersecurity risk (including adversarial attacks and data leakage), third-party/vendor risk, and — for generative AI specifically — hallucination and prompt injection risk.
3. Evaluate Impact and Likelihood
For each use case assessed as material, evaluate the potential severity if the risk materialities and the likelihood of it occurring. MAS’s framing here centers on the real-world consequences to customers and to the institution: financial loss, unfair customer outcomes, regulatory exposure, and operational disruption — MAS specifically notes that AI-driven automation can fail or break down in ways that disrupt core operations.
A generative AI tool used for internal drafting carries a very different risk profile from an AI model embedded in a real-time credit or claims decision. Quantify impact where you can — affected customer volumes, dollar exposure, downtime — rather than relying on vague ratings alone.
4. Prioritize Based on Risk Profile
MAS’s proportionality principle means your controls should scale with the size and nature of your AI risk exposure — not apply a single uniform standard to every system in the inventory. Use your materiality and impact scoring to separate use cases into risk tiers, and apply the deepest scrutiny to systems that are:
- Customer-facing and influence financial outcomes (credit, claims, pricing)
- Built on generative AI or autonomous agentic capability
- Sourced from third parties with limited visibility into training data or model behaviour
MAS has also indicated that institutions with material AI risk exposure may be expected to establish a dedicated cross-functional AI risk committee — a signal that prioritization isn’t just about ranking individual systems, but about recognizing when your overall AI footprint warrants elevated governance structures.
5. Define Controls Aligned to FEAT
Translate your AI risk assessment into concrete controls, mapped explicitly to the FEAT principles MAS uses as its governance lens:
- Fairness controls — bias testing and fairness audits before and after deployment, especially for models influencing credit, insurance, or employment-adjacent decisions
- Ethics controls — defined acceptable-use policies for generative AI and clear boundaries on autonomous agent authority
- Accountability controls — named business and risk owners for every material AI system, with escalation paths when something goes wrong
- Transparency controls — documentation sufficient to explain model logic and outputs to customers, auditors, and MAS on request
Layer in the lifecycle and technical controls MAS’s proposed Guidelines call out specifically: human oversight for high-stakes outputs, robust and resilient technology infrastructure, vendor due diligence and contractual safeguards for third-party AI, and safeguards against generative AI failure modes such as data leakage and prompt injection.
6. Monitor Continuously Across the AI Lifecycle
MAS’s proposed Guidelines are explicit that AI risk management must extend across the entire AI lifecycle, not stop at deployment. Build monitoring that tracks:
- Model performance and accuracy against defined baselines
- Data and concept drift as production data diverges from training data
- Fairness metrics, checked on an ongoing basis rather than only at launch
- Security signals — attempted manipulation, prompt injection attempts, anomalous query patterns
- Incidents and near-misses, logged and fed back into the risk register
For institutions using generative AI or agentic AI, this step deserves particular attention — MAS has flagged these as areas of heightened and less well-understood risk requiring active, ongoing oversight rather than a one-time review.
7. Review, Report, and Improve
Close the loop with board and senior management oversight — a requirement MAS places at the centre of its proposed Guidelines. This means:
- Regular reporting of AI risk posture to the board or a designated committee
- Updating the AI inventory as new use cases launch, models are retrained, or systems are retired
- Reassessing risk materiality when regulation evolves — including once the AIRG is formally issued
- Conducting post-incident reviews and feeding lessons learned back into your risk methodology and controls
MAS has stated plainly that the board and senior management play a key role in AI risk governance — this isn’t a responsibility that can sit solely within a technology or model risk team.
Practical Readiness Steps for Singapore FIs
With the AIRG expected to be finalized without an extended runway, Singapore FIs should act now rather than wait for the final text:
- Build the AI inventory today. This is the single most concrete, actionable step MAS has flagged, and it underpins every other requirement.
- Assign clear ownership. Every material AI use case needs a named business owner and risk owner — MAS’s accountability expectations apply regardless of whether a system was built internally or bought from a vendor.
- Revisit vendor contracts. MAS is clear that FIs cannot delegate AI governance to third parties. Review vendor agreements for the audit rights, documentation, and assurances your institution will need.
- Establish a proportionate governance structure. Determine whether your AI risk exposure warrants a dedicated cross-functional AI committee, per MAS’s proposed threshold for institutions with material exposure.
- Get ahead of generative AI and agentic AI risk specifically. These are the risk categories MAS has called out by name as emerging and less well understood — don’t treat them as a subset of general model risk.
Frequently Asked Questions
Are MAS’s AI Risk Management Guidelines mandatory yet?
Not yet. As of MAS’s most recent update, the Guidelines remain a consultation proposal being finalized; the consultation closed on 31 January 2026 and a 12-month transition period has been proposed once they are formally issued. FIs should still align practices now, as MAS supervisory reviews already probe AI governance maturity.
Do the Guidelines apply to smaller financial institutions?
Yes, but proportionately. MAS has stated the Guidelines are intended to apply to all financial institutions, with implementation commensurate with each institution’s size, business model, and AI risk exposure — smaller FIs are not held to the same depth of governance as large banks, but all are expected to have foundational AI governance in place.
Does this cover generative AI and AI agents?
Yes. MAS’s proposed Guidelines explicitly extend to generative AI and autonomous AI agents, alongside traditional predictive AI and machine learning models.
What’s the difference between FEAT and the new AI Risk Management Guidelines?
FEAT (Fairness, Ethics, Accountability, Transparency) sets the high-level principles MAS has expected since 2018. The proposed AI Risk Management Guidelines complement FEAT by translating those principles into concrete supervisory expectations — inventories, lifecycle controls, governance structures, and reporting requirements.
Key Takeaway
For Singapore FIs, AI risk assessment is moving from a principles-based expectation under FEAT to a structured, lifecycle-wide supervisory requirement under MAS’s proposed AI Risk Management Guidelines. The institutions best positioned when the Guidelines are finalized will be the ones that have already built the inventory, assigned ownership, embedded FEAT-aligned controls, and established continuous monitoring — not the ones waiting for the final text before they start.
Need help getting ready? Pecuniya helps Singapore financial institutions build and operationalize AI governance and risk management programs aligned with MAS’s FEAT principles and its proposed AI Risk Management Guidelines — from AI inventory design through board-level reporting. Contact us or download our AI Governance & Risk Management Whitepaper to get started.
MAS Reference Links
- Consultation Paper on Guidelines on Artificial Intelligence Risk Management (2025)
- MAS Media Release: Guidelines for Artificial Intelligence (AI) Risk Management
- Principles to Promote Fairness, Ethics, Accountability and Transparency (FEAT) in the Use of AI and Data Analytics (2018)
- MAS Media Release: MAS Introduces New FEAT Principles (2018)
- MAS Veritas Initiative (FEAT assessment methodologies and open-source toolkit)


Leave a Reply