Singapore gave banks 12 months to get each AI tool checked first. Vendors' too.
The Monetary Authority of Singapore (MAS), the city-state's central bank and financial regulator, published its first guidelines for managing AI risk at banks, insurers and other financial firms on 8 October, The Register…
The Monetary Authority of Singapore (MAS), the city-state's central bank and financial regulator, published its first guidelines for managing AI risk at banks, insurers and other financial firms on 8 October, The Register reported. They apply from 7 October 2027, a year away.
Before AI is put to work on a task, MAS says the firm should have that use reviewed "by parties not involved in its development". After that, MAS expects the firm to keep watching it, including AI services bought from outside.
MAS says firms "remain accountable for AI used in the services they deliver, including AI developed, operated or provided by third parties". It expects a list of all the AI a firm uses, including AI a supplier did not disclose where that can be found, and a fallback for high-risk AI, "alternative systems or manual processes".
The vendor clause reaches past a bank's own code. A bank can test the AI it builds itself. For AI that suppliers add to software it rents, MAS expects assurance from the supplier, or the bank's own controls where none is given.
If you run finance systems at a bank, does your AI list include what your suppliers switched on inside their software?
Sources
For your next steering committee
- 1Ask which AI tools already touch your ERP or finance data, including the ones nobody approved.
- 2Ask what each tool is allowed to change, and who reviews what it changed.
- 3Ask how the result is measured, and who decides to switch a tool off.
Issue 01 of the ERP LEADERS brief puts a timeline, the three-number review and six questions on one page. Read issue 01
Welcome back. · Issue 01


