Skip to main content
News

Singapore finalises AI risk rules for finance: AI hidden inside vendor software counts too

On 7 October 2026 the Monetary Authority of Singapore issued its AI risk management guidelines for financial institutions. Firms must inventory every AI use, including AI embedded in vendor services, and stay accountable for third-party AI. Here is what Thai businesses and software providers should take from it.

AI GovernanceAI Risk ManagementMASThird-party AIAI AgentsFinancial Services

Imagine your company has used a SaaS CRM or accounting system for years. This year the vendor added an AI feature that summarises customer data and suggests credit limits. Sales likes it because work moves faster. Nobody in the company has written down which model it uses, where the data goes, or who answers for it when a suggestion is wrong.

Singapore's central bank has just answered that question for the financial institutions it supervises. The short answer: the company using the AI is still responsible.

What happened

On 7 October 2026 the Monetary Authority of Singapore (MAS) issued its Guidelines on Artificial Intelligence Risk Management for financial institutions. The consultation ran from 13 November 2025 to 31 January 2026, and MAS published a response paper explaining what it changed.

The guidelines apply to all financial institutions and all forms of AI, but each firm can scale its approach to the size and risk of its own AI use. They take effect on 7 October 2027 and come in two phases.

  1. By 7 October 2027, firms should have a framework for overseeing AI risk, a process to identify and inventory AI, and risk materiality assessments for each use.
  2. By 7 October 2028, firms should apply lifecycle controls across all AI use cases and have enough people and skills to run them.

MAS also says high-risk use cases should get proper controls as soon as possible, not at the end of the 24 months.

The parts that matter more than the dates

Vendor AI counts

Third-party AI is in scope, including AI built into a vendor's service even when it is not sold as "AI". One example MAS gives itself is an AI feature inside SaaS software that extracts information used for key business decisions.

MAS accepts that finding every piece of embedded AI is hard. So the minimum is to identify embedded AI in services from material third-party providers, and the difficulty is not a reason to leave shadow AI, the tools staff adopt on their own, out of the search.

Using someone else's AI does not move the accountability

When an institution chooses a third-party AI service, it remains accountable for the outcome for its customers. If the vendor will not share enough detail, the firm may rely on certifications or independent external assessments. MAS is clear that the vendor's own self-attestation is not enough. If risk exceeds the firm's appetite, it should consider limiting, suspending or replacing the service.

Contracts should also give the firm a risk-proportionate view of model updates or AI changes that could affect how the use case performs.

Assess risk per use case, not per model

Risk materiality is assessed at the level of the use case, across three dimensions: impact, complexity and reliance. The same model can score differently if one use runs automatically and another has a human checking every output. A firm less familiar with a technology may reasonably rate its complexity higher.

AI agents are already covered

Generative AI and AI agents, including multi-agent systems, fall inside the definition. Purely rule-based tools such as traditional RPA do not. For agents, MAS expects monitoring to reach reasoning paths, actions taken and tools used, and it plans to consult the sector on agent-specific guidance in 2027.

Why Thai businesses should care

The guidelines bind only institutions under MAS, but they reach Thai businesses in at least three ways.

First, Thai financial groups with branches or subsidiaries in Singapore. MAS says the guidelines apply wherever the institution is incorporated, and in some cases on a group basis.

Second, software, ERP and outsourcing providers that serve financial institutions in Singapore. If your service has AI inside, your client will need to ask what it does, what data it uses, and whether you will tell them when the model changes.

Third, any Thai company using more AI without a clear framework. The MAS text is detailed, free to read, and a practical template to start from without waiting for Thai rules.

What to do or ask

  1. List the AI you actually use, including AI features inside purchased software and tools staff picked up on their own.
  2. Rate each use case: how much harm a wrong answer could do to customers or money, and whether a person checks it first.
  3. Ask your key vendors what AI sits inside their service, how it uses your data, and whether they will tell you when the model changes.
  4. Check your contracts for a right to know about AI changes and a way out if the risk becomes too high.
  5. Decide who approves new AI uses and who holds the overall view of AI risk.
  6. If you run AI agents that act on their own, keep logs of what each agent did, which tools it called and what it was allowed to do.

What Enersys does

We are a software house that has built business systems for 14 years, working on Odoo ERP, AI and personal data protection. If you want to start an AI inventory in your organisation, or prepare answers for clients who ask how your systems use AI, talk to the Enersys team. We can help you see the full picture and set first steps that fit the size of your business.

Sources

"Empowering Innovation,
Transforming Futures."

Contact us to make your project a reality.