In This Guide
Disclaimer
This article summarises publicly available documents from IMDA and the AI Verify Foundation as of 28 September 2026. It is not legal advice. Frameworks and tools are updated regularly; check the current versions on the AI Verify Foundation resource library before relying on them.
Singapore’s approach to AI governance leans heavily on practical frameworks and testing tools rather than a single AI statute. For enterprises rolling out generative AI inside business workflows — drafting, summarisation, customer replies, document review, internal agents — two resources come up again and again in procurement and risk discussions: IMDA’s Model AI Governance Framework for Generative AI and the AI Verify testing framework and tools maintained by the AI Verify Foundation.
This guide explains what each one actually contains and how a deploying organisation can use them to structure its own controls. It sits alongside our guides to PDPC’s generative AI guidelines for system deployers and MAS’s proposed AI risk management guidelines, which cover the data protection and financial-sector angles.
What the Framework Is, and Is Not
The Model AI Governance Framework for Generative AI (often shortened to MGF for GenAI) was developed by IMDA and the AI Verify Foundation. According to the Foundation, a proposed version was released for international views on 16 January 2024 and the final framework was released on 30 May 2024 (AI Verify Foundation: MGF for GenAI). It expands on the earlier Model AI Governance Framework for traditional AI, first released by IMDA and PDPC on 23 January 2019, with a second edition on 21 January 2020.
It is a governance framework, not a licensing regime. It sets out practical suggestions across nine dimensions and describes itself as a first step toward more detailed guidelines under each. For an enterprise, its value is as a shared vocabulary: it gives risk, legal, IT and business teams one structure to check a GenAI deployment against, and it is the structure many Singapore stakeholders will expect you to recognise.
The Nine Dimensions, Read as a Deployer
The framework covers the whole ecosystem, including model developers, policymakers and researchers. Several dimensions are mainly for those groups. The ones below are where an organisation deploying GenAI in its own workflows has direct work to do.
1. Accountability
The framework notes that GenAI involves multiple layers in the tech stack, with model developers, application deployers and cloud service providers each playing a part. It points to the cloud industry’s shared responsibility models as a reference for allocating responsibility. For deployers: write down which party is responsible for what — model behaviour, prompt and retrieval design, access control, output review — and reflect it in vendor contracts.
2. Data
Ensuring data quality and dealing with potentially contentious training data. For deployers: the most relevant data is usually your own — the documents and records your workflows feed into models. Control what goes in, and apply your PDPA obligations to it.
3. Trusted Development and Deployment
Baseline safety and hygiene measures, with “food label”-type transparency about how models were developed and evaluated. The framework notes that techniques such as input and output filters and retrieval-augmented generation are commonly used to reduce harmful output and hallucinations. For deployers: ask vendors for their disclosures, and document the safeguards in your own application layer.
4. Incident Reporting
The framework’s starting point is that no AI system is foolproof. It recommends vulnerability reporting before incidents, borrowing software practice (including a patch window that is typically 90 days by industry practice), and internal processes to report incidents for timely notification and remediation afterwards, supported by ongoing monitoring. For deployers: add AI-specific categories to your existing incident process and define who is notified.
5. Testing and Assurance
Third-party testing and assurance play a complementary role, as they do in finance and healthcare. The framework describes the two main evaluation approaches today: benchmarking against datasets of questions and answers, and red teaming, where testers act as adversarial users. For deployers: test the application you actually run, not just the underlying model.
6. Security
GenAI introduces new threat vectors. The framework recommends adapting security-by-design and developing new safeguards such as input filters that detect unsafe prompts, and digital forensics tools for generative AI. For deployers: treat prompts, retrieved documents and connected tools as part of the attack surface.
7. Content Provenance
Transparency about where content comes from, with governments looking at technical solutions such as digital watermarking and cryptographic provenance. For deployers: decide when AI-generated output must be labelled, particularly in customer-facing content.
The remaining two dimensions, Safety and Alignment R&D and AI for Public Good, are aimed mainly at research bodies, governments and the wider ecosystem, although the latter includes upskilling workers, which matters for any enterprise rollout.
AI Verify: Turning Principles Into Evidence
A framework tells you what good looks like. The AI Verify Testing Framework helps you show that you have done it. According to the AI Verify Foundation, it helps organisations assess the responsible implementation of an AI system against 11 internationally recognised AI governance principles, covers both traditional and generative AI, and is mapped to other frameworks including the US NIST AI Risk Management Framework and its Generative AI Profile, the Hiroshima Process International Code of Conduct, and ISO/IEC 42001 (AI Verify Foundation: AI Verify Testing Framework).
The 11 principles are transparency; explainability; reproducibility; safety; security; robustness; fairness; data governance; accountability; human agency and oversight; and inclusive growth, societal and environmental well-being. Each principle is broken into four elements:
- Principles — the overarching considerations.
- Outcomes — what each principle should achieve in practice.
- Processes — actionable steps (process checks) to reach those outcomes.
- Evidence — the documentary evidence that validates each process.
The process checks are available as a PDF overview, an Excel checklist for tracking progress, and a software tool (for GenAI) that documents practices and generates a summary report. For an enterprise, the Excel or software version is a practical backbone for an internal AI assurance file: each check is marked implemented, not implemented or not applicable, with an explanation and a pointer to where the evidence lives. Because the framework is mapped to ISO/IEC 42001 and NIST, the same evidence can often support conversations with overseas customers and auditors.
Testing GenAI Apps: Starter Kit and Moonshot
Process checks cover governance. Technical testing of the application itself is handled by two further resources.
IMDA’s Starter Kit for Testing LLM-based Applications for Safety and Reliability is described by the Foundation as a set of voluntary guidelines for pre-deployment testing (AI Verify Foundation: Starter Kit). It addresses five risks — hallucination and inaccuracy, bias in decision-making, undesirable content, data leakage, and vulnerability to adversarial prompts — through three steps: identify the relevant risks and thresholds, test in a structured way from the app’s outputs to its components, and assess whether thresholds are met.
Project Moonshot is the open-source toolkit that puts this into practice. It assesses LLM applications through benchmark testing and red teaming, and implements the benchmarks recommended in the Starter Kit (AI Verify Foundation: Project Moonshot).
The Foundation’s Global AI Assurance Pilot, which ran from February to May 2025, paired organisations deploying GenAI applications with testing providers, focusing on the real-life application rather than the underlying foundation model. The Foundation says the showcase featured 17 such pairs. Its published case studies are useful reading for anyone scoping tests for a similar use case.
Where Agentic AI Fits
Workflows increasingly use AI agents that take actions — updating records, sending messages, calling other systems — not just generating text. IMDA has published a separate Model Governance Framework for Agentic AI. The AI Verify Foundation describes it as guidance on deploying AI agents responsibly that emphasises that humans are ultimately accountable, gives a structured overview of agentic risks and emerging practices, and was updated in May 2026 with real-world case studies. If your workflows include agents, read it alongside the GenAI framework: permissions, approval steps and audit trails matter more once a system can act. Our governed AI workflows page describes how we think about those controls.
Applying It to an Enterprise Workflow
A practical sequence for a team deploying GenAI in, say, contract review or customer-service drafting:
- Inventory and scope. List each GenAI use case, the model and vendors behind it, the data it touches and who relies on its output.
- Allocate responsibility. Using the accountability dimension, record what the model provider, platform vendor and your own team each own.
- Pick the risks that matter. Use the Starter Kit’s five risks to decide what to test for this use case, and set thresholds before testing.
- Test the application. Run benchmarks and red teaming against the deployed app, including your prompts, retrieval sources and integrations.
- Document with process checks. Work through the AI Verify checks relevant to the use case and file the evidence.
- Set up incident handling and monitoring. Add AI incident categories, reporting lines and review of flagged outputs.
- Review on change. Re-test when the model, prompts, data sources or permissions change.
Questions to put to a GenAI workflow vendor
- How is responsibility split between you, your model providers and us? Is it in the contract?
- What transparency disclosures can you share about model evaluation and safeguards?
- Can we run our own benchmark and red-team tests against the configured application?
- Have you mapped your controls to the AI Verify process checks, ISO/IEC 42001 or NIST AI RMF? Can we see the evidence?
- How do you detect and report incidents and vulnerabilities, and how quickly will we be told?
- For agents: what actions can the system take, and where are human approvals enforced?
For how these questions fit into a broader governance programme, see our AI governance overview.
Frequently Asked Questions
Is the Model AI Governance Framework for Generative AI legally binding?
It is a governance framework offering practical suggestions, not legislation. Sector regulators and laws such as the PDPA still apply to how you deploy GenAI, and the framework is a useful structure for meeting those expectations.
What is the difference between AI Verify and the governance framework?
The framework sets out what trustworthy GenAI involves across nine dimensions. The AI Verify Testing Framework turns 11 governance principles into outcomes, process checks and evidence that an organisation can document and assess.
Do we need to test the model or the application?
For a deploying organisation, the application. IMDA’s Starter Kit and the Global AI Assurance Pilot both focus on testing the LLM-based application as deployed, including its components, rather than only the foundation model.
Does AI Verify help outside Singapore?
The testing framework is mapped to the NIST AI RMF, its Generative AI Profile, the Hiroshima Process Code of Conduct and ISO/IEC 42001, so evidence gathered with it can support discussions in other jurisdictions.
Build GenAI Workflows You Can Evidence
Talk to BoostenX about approval workflows, audit trails and governance documentation for enterprise AI deployments.
Contact Our Team