Raymond Cheung
Chartered Actuary · CRO · Board Adviser · Singapore
MAS issued its final AI Risk Management Guidelines on 7 October 2026, effective one year from now. The guidelines apply to every financial institution and every form of AI -- including AI running inside third-party software you never knew was there. Boards have twelve months to get this right.
MAS published its final Guidelines on AI Risk Management on 7 October 2026, effective 7 October 2027. They apply to every financial institution and every form of AI. I have been watching Singapore FIs treat AI as a technology decision for the better part of five years -- something the CTO signs off on, the risk team reviews once a year, and the board receives a quarterly slide about. These guidelines end that model. [CONFIRM with Raymond -- replace with a real episode if possible]
Let me be direct about what has changed and what it means for boards.
What the guidelines actually say about board accountability
MAS's expectation is explicit: boards and senior management are responsible for overseeing AI risk. That means a stated risk appetite for AI, clear governance roles, and approved frameworks and policies. MAS also noted, with unusual specificity, that FIs 'need not establish a dedicated AI committee solely to meet this expectation' -- which tells you something about the kind of box-ticking response MAS anticipated and is pre-empting.
“Boards can no longer treat AI as a technology procurement question. MAS has made it a board accountability question, and the expectation is proportionate, not a get-out.”
The proportionality point is worth reading carefully. FIs with AI that has low impact on customers and stakeholders can meet the guidelines with basic policies and procedures. But proportionality is a function of the risk the AI actually creates, not the function it was sold to perform. An insurer using AI for claims triage, for underwriting pricing decisions, or for customer communication has material AI risk whether or not it has ever classified it as such. The first task for every insurance board over the next twelve months is an honest assessment of where AI is already in the business and what would happen if it failed or behaved badly.
Third-party AI is your problem too
The provision that will catch the most institutions by surprise is the accountability requirement for third-party AI. FIs remain responsible for AI that third parties develop, operate, or supply. Vendor self-attestation will not, in MAS's view, constitute sufficient assurance. If the AI risk cannot be brought within the FI's tolerance through controls and contractual protections, MAS expects the board to be weighing whether to restrict, pause, or replace the external AI service. That is a significant shift from how most procurement conversations about AI-embedded software currently run.
For insurance boards specifically: the phased rollout gives you until October 2027 for Sections 3 to 4 (governance, risk identification, and controls for the AI lifecycle) and until October 2028 for Sections 5 and 6. That timeline is tighter than it looks if you do not yet have an AI inventory -- and most boards do not. Start there.
Common Questions
When do MAS's AI Risk Management Guidelines take effect for Singapore financial institutions?
MAS issued the final Guidelines on 7 October 2026. The phased implementation requires FIs to meet Sections 3 to 4 (covering governance structure, risk identification, and core AI lifecycle controls) by 7 October 2027, and Sections 5 and 6 by 7 October 2028. MAS also noted that high-risk AI use cases should have lifecycle controls applied as soon as possible, rather than waiting for the full transition window. This means FIs that already have material AI deployments should not treat 2027 as a start date -- the expectation is that work begins now.
Do MAS's AI guidelines apply to insurance companies in Singapore?
Yes. The MAS Guidelines on AI Risk Management apply to all financial institutions under MAS's supervision, which includes life and general insurers, reinsurers, and insurance intermediaries licensed in Singapore. The guidelines cover every form of AI, including AI embedded in third-party software, AI used in underwriting, claims management, customer communication, and risk modelling. Proportionality applies -- a small FI with genuinely low-impact AI can meet the guidelines with basic policies -- but the board accountability expectation applies to every FI.
What should a Singapore insurance board do first in response to the MAS AI guidelines?
The most important first step is an AI inventory: a complete picture of where AI is deployed or embedded in the FI's operations, including third-party systems. From that inventory the board can apply MAS's three-dimension materiality framework -- impact, complexity, and reliance on human oversight -- to identify which use cases require the most substantive governance attention. The board should also review whether the current risk appetite statement covers AI risk explicitly, and whether there is a named owner at senior management level for AI risk. These are the governance foundations MAS will be looking for.
Related insights
About the author
Raymond Cheung is a Chartered Actuary, C-suite executive and board adviser with more than 20 years of experience across Asia in risk management, insurance, ESG and corporate governance. He is the CEO of CER Consultancy and an accredited trainer at SMU Academy and the Singapore College of Insurance.