What MAS Actually Said
The guidelines took effect on 7 October 2027, and they keep the institution accountable for the models it buys.
On 7 October 2026 the Monetary Authority of Singapore issued its Guidelines on Artificial Intelligence Risk Management for Financial Institutions. They apply to all financial institutions and all forms of AI technologies, and they take effect on 7 October 2027, with sections 5 and 6 falling due by 7 October 2028.[1][2]
The sentence that matters to anyone buying AI sits in the third expectation. Financial institutions “remain accountable for AI used in the services they deliver, including AI developed, operated or provided by third parties”.[1][3]
What follows from it is specific. Institutions should obtain sufficient assurance from third-party providers, assess whether third-party AI is suitable for its intended use, and apply compensating controls where assurance gaps or practical constraints arise. Where the risk cannot be brought inside the institution’s risk appetite, MAS expects it to consider limiting, suspending or replacing that service.[1]
Three other expectations complete the framework. First, clear board and senior management accountabilities, with a stated risk appetite. Second, an inventory of AI use, with risk materiality assessed use case by use case. Third, proportionate controls across the life cycle: data governance, testing, human oversight, cybersecurity, monitoring and change management.[1]
The proportionality is not decorative. Institutions may satisfy the expectations with basic policies and procedures where poor performance or unavailability of an AI service is unlikely to materially affect them, their customers or other stakeholders. They need not establish a dedicated AI committee if existing governance already provides adequate oversight.[1]
MAS also indicated what comes next: in 2027 it intends to consult the financial sector on what additional guidance on agentic AI would be useful.[1]