Singapore To Make Financial Institutions Accountable For AI Even If From Third-Party

Financial institutions will be expected to assess and manage risks from their use of artificial intelligence, including AI by third-party providers, under new guidelines issued by the Monetary Authority of Singapore (MAS) on Wednesday (Oct 7).

They also remain accountable for AI used in the services they provide even when the technology is developed, operated or supplied by a third party, MAS said.“Financial institutions should obtain sufficient assurance from third-party providers, assess whether third-party AI is suitable for their intended use, and apply compensating controls where practical constraints or assurance gaps arise,” the central bank said in a media release.

If the risks still cannot be brought within the firm’s risk appetite, it should consider limiting, suspending or replacing the third-party AI service.

The guidelines will take effect on Oct 7, 2027, with financial institutions allowed to implement them in phases and meet the full requirements by Oct 7, 2028 Under the guidelines, financial institutions are expected to manage AI risks at both the enterprise level and for individual use cases, while building up their capabilities as their use of the technology expands.

They should identify their AI use, maintain inventories, assess the risk posed by individual use cases and put in place proportionate controls throughout the AI life cycle.

These include data governance, testing, human oversight, cybersecurity, monitoring and change management.

MAS said such controls should be reviewed regularly as AI use expands and the technology evolves, pointing to the growing use of agentic AI systems that can operate autonomously and access tools.

The authority plans to consult the financial sector in 2027 on what additional guidance on agentic AI would be useful.

CNA

Latest News

Must read