Back to News
RSS feedwww.theregister.com

Singapore Regulator Calls for Independent Review of All FinTech AI Use Cases

Summary

Singapore’s Monetary Authority (MAS), which is both the country’s central bank and financial regulator, has issued its first Guidelines on Artificial Intelligence Risk Management for Financial Institutions. The guidance says AI’s complexity and probabilistic behavior can create uncertainty, bias, and failures that are harder to detect than problems in simpler systems. MAS considers generative AI riskier because training-data noise, unrepresentative data, and unfamiliar scenarios can produce unexpected behavior, while agentic AI may amplify those risks. Financial institutions are expected to expand their risk frameworks, with boards and senior management responsible for implementation. Before deployment, every AI use case and its underlying systems or models should be independently reviewed by people not involved in development, and technology and cybersecurity checks should confirm that production deployment is controlled and secure. After deployment, institutions must monitor their own systems and third-party AI for model staleness, data or model drift, performance degradation, and security problems. MAS says institutions remain accountable even when an AI service comes from a supplier; they must assess suitability, obtain sufficient assurance, apply compensating controls where needed, and limit, suspend, or replace services whose risks exceed their tolerance. Firms should maintain inventories of all AI used in their operations, including attempts to manage undisclosed AI contributions from suppliers. For high-risk uses, they should also prepare alternative systems or manual processes to preserve business continuity. The guidelines take effect on October 7, 2027.