MAS turns proportionality into an evidence problem
On October 7, 2026, the Monetary Authority of Singapore issued final Guidelines on Artificial Intelligence Risk Management for Financial Institutions. They apply to all financial institutions and all forms of AI, while allowing implementation to reflect the institution's size, risk profile, and the scale and nature of its AI use. The Guidelines take effect on October 7, 2027; the lifecycle and third-party sections may be met by October 7, 2028.
The phased dates should not be read as permission to wait. Population discovery, ownership, data lineage, vendor rights, baseline tests, and monitoring history take time. An institution cannot apply proportionality if it does not know which AI systems exist, what decisions they influence, which providers and data they depend on, and which controls actually operate.
MAS also gives smaller or lower-risk populations a practical path: a basic policy can name an accountable senior person, define permitted and prohibited uses, require human oversight and approved tools, educate users, check compliance, and review periodically or on trigger. That is not an exemption. It is a proportionate baseline whose adequacy depends on the use case and evidence.
The core operating decision is materiality. A drafting assistant used by two analysts should not automatically receive the same validation burden as a model that ranks customers, approves limits, executes transactions, or communicates binding outcomes. Conversely, calling a system “assistive” does not make it low-risk if staff routinely follow its output or cannot detect errors.
This guide is an implementation pattern, not legal advice. Qualified legal and compliance owners must decide scope, interpretation, and how MAS expectations interact with sector rules, technology-risk, outsourcing, privacy, conduct, and internal model-risk frameworks.