Imagine your company has used a SaaS CRM or accounting system for years. This year the vendor added an AI feature that summarises customer data and suggests credit limits. Sales likes it because work moves faster. Nobody in the company has written down which model it uses, where the data goes, or who answers for it when a suggestion is wrong.
Singapore's central bank has just answered that question for the financial institutions it supervises. The short answer: the company using the AI is still responsible.
What happened
On 7 October 2026 the Monetary Authority of Singapore (MAS) issued its Guidelines on Artificial Intelligence Risk Management for financial institutions. The consultation ran from 13 November 2025 to 31 January 2026, and MAS published a response paper explaining what it changed.
The guidelines apply to all financial institutions and all forms of AI, but each firm can scale its approach to the size and risk of its own AI use. They take effect on 7 October 2027 and come in two phases.
- By 7 October 2027, firms should have a framework for overseeing AI risk, a process to identify and inventory AI, and risk materiality assessments for each use.
- By 7 October 2028, firms should apply lifecycle controls across all AI use cases and have enough people and skills to run them.
MAS also says high-risk use cases should get proper controls as soon as possible, not at the end of the 24 months.
The parts that matter more than the dates
Vendor AI counts
Third-party AI is in scope, including AI built into a vendor's service even when it is not sold as "AI". One example MAS gives itself is an AI feature inside SaaS software that extracts information used for key business decisions.
MAS accepts that finding every piece of embedded AI is hard. So the minimum is to identify embedded AI in services from material third-party providers, and the difficulty is not a reason to leave shadow AI, the tools staff adopt on their own, out of the search.
Using someone else's AI does not move the accountability
When an institution chooses a third-party AI service, it remains accountable for the outcome for its customers. If the vendor will not share enough detail, the firm may rely on certifications or independent external assessments. MAS is clear that the vendor's own self-attestation is not enough. If risk exceeds the firm's appetite, it should consider limiting, suspending or replacing the service.
Contracts should also give the firm a risk-proportionate view of model updates or AI changes that could affect how the use case performs.