Back to Insights
Technology Risk8 min readSeptember 2026

AI governance in Singapore insurance: what MAS expects, what boards miss

RC

Raymond Cheung

Chartered Actuary · CRO · Board Adviser · Singapore

MAS has set clear supervisory expectations for how insurers govern, test and monitor AI. In the boardrooms I sit in, the effort goes into mapping the guidelines clause by clause — when the harder and more useful work is building an inventory of where the insurer already uses AI, and owning the third-party models, drift and human oversight that inventory exposes.

A board I advise asked me last quarter whether the insurer was ready for MAS's incoming AI risk management guidelines. The honest place to start, I said, was that we could not yet produce a reliable list of where the company already used AI. Underwriting had two models. Claims had a triage tool bought from a vendor. Marketing had licensed a platform with a generative feature that nobody had mentioned to the risk function. The guidelines were not the problem. The inventory was.

MAS consulted on its Guidelines on AI Risk Management from November 2025 to January 2026, and followed in March 2026 with an industry toolkit built alongside two dozen banks and insurers. This is not a new regime bolted onto insurance regulation. It sets out how a financial institution is expected to govern, test, monitor and manage AI across its whole life cycle — from board and senior management oversight through data management, fairness, transparency and human oversight — scaled to the size and nature of what the institution actually does. MAS has proposed a twelve-month runway from issuance to implementation.

“The AI guidelines are not a new regime bolted onto insurance regulation. They are model risk governance, extended to tools your actuaries did not build.”

What MAS expects, in plain terms

Strip out the terminology and the expectations are familiar to anyone who has run model governance for pricing or reserving. Know which models you have. Know what they do and which decisions they drive. Assess them before deployment, in proportion to how material they are. Monitor them after deployment, because performance drifts. Keep a human genuinely accountable for outcomes, not merely present in the workflow. Be able to explain, to a customer or a regulator, why a model produced the decision it did. The genuinely new surface area is generative AI, autonomous agents that can take actions on their own, and the rising share of models that arrive through vendors rather than internal teams.

Where boards think the work is

In most of the boardrooms I have sat in, the instinct is to treat the guidelines as a mapping exercise: line up each clause against an existing policy, note the gaps, ask management for a remediation plan, move on. That produces a tidy paper. It does not produce governance. The mapping approach assumes the hard part is knowing what the regulator wants. The hard part is knowing what your own business is already doing — and a clause-by-clause review will not tell you that, because it starts from the regulation rather than from the company.

The five things I see boards miss

  • The AI inventory. Almost no insurer I have worked with can produce a current, complete list of AI and machine-learning models in use, who owns each one, and what decision it influences. Without that list, every other control is theoretical.
  • The third-party blind spot. A claims model licensed from a vendor is still your model for governance purposes. Boards routinely accept 'the vendor handles that' for the testing, bias assessment and monitoring the guidelines expect the insurer itself to own.
  • Explainability as a document, not a capability. Being able to explain a model's decision is treated as a one-time write-up for the file. It should be a standing ability to reconstruct, on request, why a specific customer was declined, priced or flagged.
  • Post-deployment drift with no owner. Models are scrutinised hardest just before go-live and least afterwards, which is backwards. Pricing and underwriting models degrade as portfolios and customer behaviour shift, and few insurers have named the person accountable for noticing.
  • Nominal human oversight. 'Human in the loop' often means someone who approves model output under time pressure with no real ability to override it. The guidelines expect meaningful human accountability, which is a question of resourcing and authority, not a box on a workflow diagram.

What I would have in place before the transition period ends

If I were chairing the risk committee of a Singapore insurer today, I would want four things settled before the guidelines take effect. A complete AI inventory, refreshed quarterly, with a named owner for each model. A materiality tiering, so that the heaviest governance falls on the models that price risk, accept risk or pay claims. A monitoring regime for the high-tier models, with defined performance thresholds and an escalation path when they are breached. And a clear line between the MAS supervisory expectations that apply to the institution and the older, voluntary Model AI Governance Framework, which some management teams still cite as though it discharges the obligation. It does not.

Singapore is ahead of most jurisdictions in writing down what it expects of AI in finance, and insurers here will be judged against a standard that is clearer than the one their peers face elsewhere. The institutions that struggle will not be the ones that misread a clause. They will be the ones that spent the transition period mapping the guidelines instead of mapping their own use of AI. The board's first question should not be 'are we compliant?' It should be 'can someone show me the list?'

Common Questions

What does MAS expect from insurers on AI governance?

MAS's Guidelines on AI Risk Management set supervisory expectations for how insurers and other financial institutions govern, test, monitor and manage AI across its full life cycle — including board and senior management oversight, data management, fairness, explainability and human oversight — scaled to the size and nature of the institution. MAS consulted on the guidelines between November 2025 and January 2026 and has proposed a twelve-month implementation period after they are issued.

How is AI governance different from existing model risk management for a Singapore insurer?

For pricing and reserving models built in-house, the expectations are largely an extension of the model risk governance actuaries already know: inventory, pre-deployment assessment, post-deployment monitoring and accountable human ownership. The genuinely new elements are generative AI, autonomous AI agents, and the rising share of models supplied by third-party vendors — where the insurer still carries governance responsibility even though it did not build the model.

What is the difference between MAS's AI Risk Management Guidelines and Singapore's Model AI Governance Framework?

The Model AI Governance Framework, issued through IMDA and the PDPC, is a voluntary, cross-sector guide to responsible AI practices. MAS's AI Risk Management Guidelines are financial-sector supervisory expectations that MAS will assess regulated institutions against. Citing the voluntary framework does not discharge a MAS-regulated insurer's obligations under the guidelines.

About the author

Raymond Cheung is a Chartered Actuary, C-suite executive and board adviser with more than 20 years of experience across Asia in risk management, insurance, ESG and corporate governance. He is the CEO of CER Consultancy and an accredited trainer at SMU Academy and the Singapore College of Insurance.

All insights