Singapore Is Making Banks Prove Someone Checked Their AI — and Vendors’ Failures Don’t Count
Singapore — October 8, 2026.
Singapore’s central bank has issued formal AI risk management guidelines for the financial sector: every AI use case must pass an independent review before it goes live, banks stay on the hook for their AI vendors’ failures, and full compliance is due by October 2028. Why it matters: this is one of the first national frameworks to explicitly say “our vendor messed up” is not an acceptable excuse for an AI failure at a bank.
Key takeaway: Banks, insurers, and payment firms regulated by the Monetary Authority of Singapore (MAS) must now subject AI systems to pre-deployment review by people not involved in building them, monitor them continuously, and maintain inventories of every AI in use — including AI buried inside third-party services.
What happened
On October 7, 2026, MAS published its AI risk management guidelines for financial institutions, following a public consultation launched in November 2025. The guidelines cover banks, insurers, payment providers, and other MAS-regulated entities. They set out four core expectations: strengthen board-level oversight of AI risks, manage AI risks across the full life cycle, manage the risks of third-party AI use, and apply everything in a risk-proportionate way.
The rollout is phased. Sections covering board and senior management oversight and AI risk management systems must be met by October 7, 2027; the sections on AI use case life cycles, data management, transparency, fairness, third-party management, and testing follow a year later, by October 7, 2028. MAS also says it plans to consult the sector in 2027 on whether further guidance is needed for agentic AI.
What the rules actually require
Three requirements stand out:
- Independent pre-deployment review. Before an AI use case ships, it — including its underlying systems or models — must be reviewed by parties not involved in its development, to confirm evaluation and testing controls were actually followed.
- No outsourcing of accountability. Financial institutions remain accountable for AI used in the services they deliver, including AI developed or operated by third parties. If risks from a vendor’s AI can’t be brought within the firm’s risk appetite, the firm should limit, suspend, or replace the service.
- Ongoing monitoring and full inventories. Firms must continuously monitor deployed AI for drift and degradation, and keep up-to-date inventories of all AI in use — even accounting for cases where third-party services use AI without saying so.
The guidelines are principles-based: smaller or lower-risk AI applications can be governed with simpler policies, and firms aren’t required to create dedicated AI committees as long as existing governance structures coordinate properly.
Why it matters
Most AI governance talk has been voluntary frameworks and best practices. Singapore is converting the talk into supervisory expectations with teeth and a calendar — and the third-party accountability clause is the sharpest part. Banks have been quietly bolting AI onto credit decisions, fraud detection, and customer service, often via vendors, with the implicit assumption that the vendor carries the risk. MAS just said the bank carries it. For anyone shopping for financial AI tools: if your bank or payment provider can’t show you its independent AI review paperwork, that’s a vendor-selection red flag, not just a compliance gap.
Frequently asked questions
When do the rules take effect?
The guidelines were published October 7, 2026. Board oversight and risk management system requirements apply from October 7, 2027; full life cycle, data, fairness, and third-party controls from October 7, 2028.
Do the rules cover AI from third-party vendors?
Yes — explicitly. Financial institutions remain accountable for AI in the services they deliver, even when developed or operated by third parties.
What happens if a vendor’s AI misbehaves?
The guidelines say the firm should apply compensating controls, and if the risk can’t be managed within its appetite, limit, suspend, or replace the service.
Do small AI tools get the same treatment?
No. The framework is risk-proportionate: lower-risk applications can use simpler controls, provided the risks stay limited.
What about AI agents?
MAS flagged agentic AI as needing possible additional safeguards and plans to consult the sector on dedicated guidance in 2027.
Sources: The Register, TechRepublic, Singapore Business Review.

