MAS AI Risk Management Guidelines: What Financial Institutions Should Ask AI Workflow Vendors

MAS's proposed Guidelines bring vendor AI and AI added to existing software inside the risk perimeter. Here is what the consultation paper says about third-party AI, and the questions to put to any AI workflow provider.

Published September 28, 2026  |  By BoostenX Editorial  |  10 min read

In This Guide

  1. Where the Guidelines Stand
  2. Why Vendor AI Is in Scope
  3. The AI Inventory
  4. Risk Materiality: Impact, Complexity, Reliance
  5. Third-Party AI Controls
  6. Human Oversight and Agentic AI
  7. Vendor Due-Diligence Questions
  8. FAQ

Disclaimer

This article summarises publicly available MAS documents as of 28 September 2026. It is not legal or regulatory advice. The Guidelines discussed here were still at the proposed stage when this was written; always check the latest version on the MAS website and consult your compliance team.

Most financial institutions in Singapore no longer build every AI capability in-house. They buy workflow platforms, copilots, document-processing tools, and increasingly AI agents from third parties, and existing software vendors are adding AI features to products the institution already uses. The Monetary Authority of Singapore's proposed Guidelines on Artificial Intelligence Risk Management make clear that all of this falls inside the institution's risk management perimeter. This guide explains what the proposal says about third-party AI and turns it into practical questions procurement, risk, and technology teams can put to any AI workflow vendor.

Where the Guidelines Stand

MAS published its consultation paper on the proposed Guidelines on 13 November 2025 (consultation number P017-2025), and the consultation closed on 31 January 2026. According to the MAS media release, the Guidelines will apply to all financial institutions and set out supervisory expectations in three broad areas: oversight of AI risk management by the board and senior management; key AI risk management systems, policies and procedures; and AI life cycle controls, capabilities and capacity. MAS said the Guidelines are intended to be applied proportionately, commensurate with each institution's size, activities, use of AI and risk profile, and that they cover generative AI and AI agents as well as traditional models.

In a written parliamentary reply on 5 August 2026, MAS stated that the Guidelines apply to all AI use cases by FIs, including agentic AI, and "will be finalised soon". The consultation paper proposed a 12-month transition period after the Guidelines are issued (paragraph 4.7), so institutions have a window, but not an indefinite one, to bring vendor arrangements into line.

Two industry resources sit alongside the proposal. In March 2026 MAS announced the Project MindForge AI Risk Management Toolkit, including an Operationalisation Handbook organised around the proposed Guidelines, developed by a consortium of 24 financial institutions and industry partners. In July 2026 MAS published Safeguards for Agentic Finance at Runtime (SAFR), an industry-developed framework on how agent actions are authorised, how human oversight is activated, and what is recorded at each consequential decision.

Why Vendor AI Is Squarely in Scope

The proposed Guidelines expect FIs to identify AI use cases, systems or models that are both internally developed and third-party. The consultation paper defines third-party AI broadly: it includes providers of third-party AI products and services, covering systems, models and data used for AI, and it explicitly includes existing third-party products and services where AI has been introduced. It also notes that MAS's existing expectations on outsourcing and third-party services continue to apply.

That last point matters for day-to-day procurement. A CRM, ticketing system or document tool that was approved years ago as conventional software may now contain AI features switched on by a routine update. Under the proposal, that becomes third-party AI that needs to be identified, assessed and governed.

The AI Inventory: What You Will Need From Vendors

The proposal expects an FI to establish and maintain an accurate, up-to-date inventory of AI use cases, systems or models (paragraph 3.4 of the proposed Guidelines). Suggested attributes include purpose and description, approved scope of use, model type, data used, dependencies, lifecycle status, assigned risk materiality rating, validation status, key roles and responsibilities, and links to essential documentation (paragraph 3.5).

Several of those fields can only be completed with vendor input. For each AI workflow platform, expect to need from the provider:

A vendor that cannot answer these questions creates an inventory gap that your control function will have to document and mitigate.

Risk Materiality: Impact, Complexity and Reliance

The proposal asks FIs to assess the risk materiality of each AI use case, system or model, looking at both inherent risk (before controls) and residual risk (after controls), and to ensure residual risk is within risk appetite before deployment (paragraph 3.9). The assessment should minimally cover three dimensions (paragraph 3.10):

Impact

The potential consequences of failure, malfunction or poor performance for the FI and its customers or other stakeholders, including the nature and sensitivity of the data processed.

Complexity

Arising from the AI technology used, the novelty of its application, or the data it uses.

Reliance

The level of autonomy granted to the AI, the degree of human involvement or oversight, and the availability of alternatives.

In practice, the same platform can land in different tiers depending on the workflow. An AI assistant that drafts internal meeting summaries is not the same risk as an agent that triages customer complaints or pre-screens credit applications. Evaluate vendors per use case, not per product. Our overview of operational risk boundaries describes how we think about separating low-risk assistance from higher-risk automated actions.

Third-Party AI Controls in the Proposal

Paragraph 4.11 of the proposed Guidelines expects FIs to ensure onboarding, development and deployment controls for third-party AI are adequate for the risk materiality of the use case. It calls for testing third-party AI in the context of the FI's own use cases, including with the FI's own data, and for compensatory testing where vendor disclosures are inadequate. It also expects processes to receive notification of updates or changes to third-party AI and to assess their impact. Key areas listed include:

Where vendor disclosure is limited, paragraph 4.3 says the FI should identify the resulting risks and put mitigants in place, such as limiting the usage of the AI, and confirm residual risk stays within appetite. For high-risk AI, paragraph 4.4 expects contingency plans with fallback options such as alternative systems or manual processes, and tested activation protocols for any "kill switch".

Human Oversight and Agentic Workflows

Paragraph 4.10 asks FIs to ensure human oversight proportionate to risk materiality, and to take account of automation bias and decision fatigue as AI use scales. It highlights clear roles and escalation paths, giving overseers the authority and ability to intervene, designing systems from the outset to enable oversight, and documenting and reviewing oversight decisions and interventions, including near misses.

For AI agents that take actions rather than just produce text, this is where platform design matters most. Ask whether the product lets you define which actions need approval, whether approvals and overrides are logged, and whether an agent can be paused without breaking the surrounding process. SAFR's focus on authorisation, oversight activation and decision records is a useful lens for these conversations. We describe our own approach to approval workflows and audit trails on the AI governance and human oversight page.

Vendor Due-Diligence Questions Mapped to the Proposal

Questions to ask any AI workflow vendor

These questions work best when they sit inside your existing outsourcing and technology risk process rather than in a separate AI track. Our procurement and vendor onboarding page outlines the documentation we provide to enterprise buyers.

Frequently Asked Questions

Are the MAS AI Risk Management Guidelines final?

Not as of this article's date. MAS consulted from November 2025 to January 2026 and said in August 2026 that the Guidelines "will be finalised soon". The consultation proposed a 12-month transition period after issuance.

Do the Guidelines cover AI inside software we already use?

The consultation paper's definition of third-party AI includes existing third-party products and services where AI has been introduced, so AI features added to existing tools are in scope.

Are the proposed Guidelines the same for every financial institution?

They apply to all FIs, but MAS proposes proportionate application based on the size and nature of the FI's activities, its use of AI and its risk profile, with controls scaled to each use case's risk materiality.

Where can we find practical implementation guidance?

The Project MindForge AI Risk Management Operationalisation Handbook, published with MAS in March 2026, is organised around the proposed Guidelines and is a practical starting point.

Evaluate AI Workflows With Governance in Mind

Talk to BoostenX about our approach to approval workflows, audit trails and procurement documentation for regulated enterprises.

Contact Our Team