Financial firms answer for vendor AI from October 2027
Singapore's financial institutions stay accountable for the AI they rely on, including AI built into a vendor's software. The Monetary Authority of Singapore (MAS) set that out in its final Guidelines on Artificial Intelligence Risk Management, issued on 7 October 2026.
The guidelines apply to all financial institutions and all forms of AI, MAS says in its media release. They take effect on 7 October 2027. MAS published them with a 57-page response to feedback on its November 2025 consultation.
The change that matters most for AI vendors sits in the third-party section. When a provider will not say how its model was built and tested, a firm may consider certifications or external assessments. The guidelines say these should be by "independent and competent parties", which excludes self-attestations.
The rules reach AI services that Singapore firms already buy. AWS added in-region Claude inference on Amazon Bedrock in Singapore on 30 September. See Amazon Bedrock adds in-region Claude inference in Seoul and Singapore and an India-only cross-Region profile.
What changed after 135 consultation responses
Annex A of the response paper lists 95 named respondents. It adds 11 who withheld their identity and 29 who withheld both identity and submission, so 135 responses in all.
The November 2025 consultation paper proposed a 12-month transition. Many respondents found that challenging, and 18 to 24 months was the most common request, MAS says. The final text splits the deadline in two:
- Oversight frameworks, AI identification, inventories and risk materiality assessments (Sections 3 and 4) apply from 7 October 2027.
- Life cycle controls and AI capability and capacity (Sections 5 and 6) apply by 7 October 2028.
- MAS says firms should apply life cycle controls to high risk use cases "as soon as possible" and not wait for the 24 months.
For life cycle controls, the deadline moves from the proposed 12 months to 24.
The test for who faces the full rulebook also changed. The consultation applied it to firms that use AI as an "integrated" part of their business processes. A few respondents said that could capture firms whose only AI was a productivity tool such as Microsoft Copilot.
The final test asks whether poor performance or unavailability of the AI would materially harm the firm, its customers or other stakeholders. If it would not, basic AI governance policies and procedures are enough.
MAS lists examples that would generally meet that test. They include AI that helps draft or proofread customer emails, summarise documents or meeting notes, or produce charts for internal use. Humans should still check the outputs, MAS adds.
The consultation proposed a dedicated cross-functional committee where a firm's AI risk exposure is material. The final text also allows "other appropriate structures" if the firm keeps a consolidated view of AI risk, the response says.
Embedded AI, pilots and agents are in scope
- The guidelines cover AI built into, or used in delivering, a vendor's service, even when nobody sells it as AI. MAS gives the example of AI features in software as a service that extract information for key business decisions.
- Hybrid systems and AI still in pilot or proof of concept count as well.
- MAS's illustrative table leaves out rule-based investment formulas, if-then expert systems, traditional robotic process automation and Monte Carlo simulations not derived from training data.
- For AI workflows, monitoring should cover "reasoning processes, actions taken, tools used" where relevant. MAS points firms to IMDA's Model AI Governance Framework for Agentic AI. Over time, it intends to consult the financial sector separately on agentic AI guidance.
- Contracts should give firms a risk-appropriate degree of visibility over the introduction of AI and later updates or changes, the guidelines say. MAS says it does not expect firms to receive and assess every vendor change in all circumstances.
OpenAI already offers a ChatGPT Work product aimed at investment banking and equity research. See OpenAI launches ChatGPT for Financial Services with built-in market data hosts.
MAS names no certification scheme or assessor
Some respondents proposed that firms rely on certifications such as ISO 42001 or SOC Type 2. A few asked for a "safe harbour" for reputable providers. MAS agrees firms may consider certifications or external assessments, if the assessor is independent of the provider, has the expertise and covers the key risks. The firm still remains responsible for the risks, MAS says.
Neither the guidelines nor the response paper names an accepted scheme or assessor. MAS also says it "will not mandate specific testing techniques or minimum controls at this time" for generative AI or agentic AI.
The guidelines add a fallback. When a vendor's residual risk sits outside a firm's risk appetite, it should consider limiting or suspending the service, or replacing the provider.
IMDA's latest report puts AI adoption among Singapore enterprises at 23.5% in 2025. See IMDA Singapore Digital Economy Report 2026: 85.7% of workers use AI, but 23.5% of firms have adopted it.
What financial firms and AI vendors can do now
- Financial institutions in Singapore can start an AI inventory that covers AI inside vendor products and pilots. Inventories and materiality assessments are due from 7 October 2027.
- Firms whose AI use is limited to assistive drafting and summarising tools can record why they meet the basic tier test. MAS says firms may engage it bilaterally where that test is unclear.
- A firm that is part of a global group may use the group's AI risk framework if it meets MAS's expectations. MAS says a dedicated committee can sit at global or regional level if it covers AI risk for Singapore operations.
- AI vendors selling to Singapore financial institutions should expect requests for independent assessments and for contract terms on update notices. MAS says vendor self-attestations, especially without evidence, would generally not be considered effective.
