The Monetary Authority of Singapore (MAS) is finalising its Guidelines on Artificial Intelligence Risk Management (AIRG), and it has now confirmed on the record that autonomous AI agents sit inside them. In a written parliamentary reply dated 5 August 2026, MAS stated that the Guidelines "apply to all AI use cases by FIs, including agentic AI, and will be finalised soon." The November 2025 consultation paper proposes a 12-month transition period after issuance for financial institutions to assess and implement the Guidelines. That window is the planning horizon for every risk, compliance, and AI platform team at a MAS-regulated institution running or piloting AI agents. This article lays out what AIRG expects, how it connects to SAFR, and a month-by-month plan from today through the end of the transition period.
What AIRG is, and where it stands
AIRG is the short name for the proposed Guidelines on Artificial Intelligence Risk Management, published for consultation by MAS on 13 November 2025 as consultation paper P017-2025. The Guidelines set out MAS' supervisory expectations for AI risk management in financial institutions across four areas: oversight by the Board and senior management, key AI risk management systems, policies and procedures (identification, inventory, risk materiality assessment), AI life cycle controls, and the capabilities and capacity needed for the use of AI.
The consultation closed on 31 January 2026. The 5 August 2026 parliamentary reply, given by Deputy Prime Minister Gan Kim Yong as Chairman of MAS, confirmed the Guidelines "will be finalised soon" and that they apply to all AI use cases by FIs, including agentic AI. MAS has not published a finalisation date. The consultation paper proposes a transition period of 12 months from issuance, and the reply positions SAFR and the Project MindForge AI Risk Management Toolkit as the industry implementation resources that sit under the Guidelines.
The scope of AI is broad by design. It covers AI models, systems, and use cases based on machine learning, deep learning, and reinforcement learning, as well as Generative AI, AI agents, and newer AI technologies. Calculators and tools whose outputs follow predefined programming logic fall outside it. The definition turns on whether the system learns or infers from inputs to generate outputs that may influence physical or virtual environments, with varying levels of autonomy and adaptiveness after deployment.
Who is in scope, and how proportionality works
MAS proposes to apply the Guidelines to all FIs as defined in Section 2 of the Financial Services and Markets Act 2022. Singapore branches and subsidiaries of foreign groups may leverage their parent entity's AI risk management framework, provided that framework meets the AIRG expectations.
Application is proportionate along two axes. The first is the institution: expectations scale with the size and nature of activities, the use of AI, and the risk profile. The second is the AI itself: life cycle controls are calibrated to the assessed risk materiality of each use case, system, or model.
The consultation paper's Annex draws a practical line. Every FI, whatever its AI adoption level, should have basic AI policies: a designated senior management owner for AI oversight, allowed and disallowed uses, human review requirements, an approved-tools list, and an annual review. FIs that use AI as an integrated part of their business processes carry the fuller expectations: oversight frameworks, identification, inventory, and risk materiality assessment. The Annex's test is material dependence: would losing access to the AI disrupt workflows the FI materially depends on, or is the AI integrated with systems it materially depends on. An agent that triages AML alerts, screens payments, or drafts credit assessments inside a production workflow answers yes.
For agentic deployments the proportionality analysis rarely lands on the light end. The paper singles out AI agents as amplifying risk because they are "granted greater autonomy and access to tools," can "autonomously execute actions that are not aligned with an FI's business objectives or a customer's best interests," and, if compromised, can "exfiltrate sensitive data or execute malicious commands at scale."
How AIRG relates to SAFR
AIRG and SAFR occupy two distinct layers, and the parliamentary reply states the division cleanly. AIRG sets MAS' supervisory expectations. SAFR (Safeguards for Agentic Finance at Runtime), the July 2026 white paper from MAS' BuildFin.ai program, "sets out a potential approach to how agent actions are authorised, how human oversight is activated, and what is recorded at the point of every consequential decision." The reply also names the Project MindForge AI Risk Management Toolkit as an industry resource to help FIs implement the Guidelines.
Read together: AIRG tells an FI what its Board, risk function, and AI owners must be able to demonstrate. SAFR describes runtime machinery an FI can implement to produce that demonstration for agents: verified agent identity, explicit mandates, a disposition for every proposed action, and an append-only audit log. This article assumes familiarity with the SAFR specification; the full walkthrough is in SAFR, Explained and the build guidance is in How to Implement SAFR.
SAFR remains an industry reference without supervisory force. AIRG is the document MAS will supervise against once issued. The practical consequence for planning: an FI that implements SAFR-style runtime controls during the transition period is building the operational evidence base that AIRG's oversight, human oversight, monitoring, and auditability expectations ask for.
The AIRG expectations that decide your agent program
Five clusters of expectations in the proposed Guidelines carry most of the weight for agentic AI.
Board and senior management accountability. The Board and senior management own the frameworks, structures, policies, and processes to identify AI use, assess risk materiality, maintain the inventory, manage AI across its lifecycle, and build the needed capability. The Board approves the overall governance approach and ensures material AI risks appear in the risk appetite framework with qualitative statements and quantitative limits. Senior management implements the policies, establishes an internal escalation process for material AI risks and incidents, and updates the Board on material AI risk issues in a timely manner. Where the overall AI risk exposure of the FI is deemed material, MAS proposes a dedicated cross-functional committee.
Identification, inventory, and risk materiality. FIs should consistently identify AI usage across all business and functional areas, with a designated control function acting as final arbiter on whether something is AI. The inventory should stay accurate and current, capturing purpose, approved scope of use, model type, data used, dependencies, lifecycle status, risk materiality rating, validation status, and owners. Risk materiality assessments minimally cover three dimensions: impact, complexity, and reliance. Reliance explicitly considers "the level of autonomy granted to the AI system or model" and "the degree of human involvement or oversight," which places agents at the sharp end of the methodology.
Life cycle controls, development through retirement. The AI life cycle in AIRG runs from inception to retirement or decommissioning, adapted from ISO/IEC 22989. Controls span data management, fairness, transparency and explainability, human oversight, third-party AI management, selection, evaluation and testing, technology and cybersecurity, reproducibility and auditability, pre-deployment reviews, post-deployment monitoring, change management, and controlled retirement. High-materiality AI needs formal independent validation before deployment, contingency plans with fallback options, and, where kill switches exist, tested activation protocols. Retirement controls cover dependencies, data retention policies, secure removal from production, and stakeholder notifications.
Human oversight. Controls should ensure appropriate human oversight across the life cycle, proportionate to risk materiality, with clear roles, escalation and decision-making processes, personnel who hold "the necessary authority and ability to intervene," systems designed from the outset to enable oversight, and documented reviews of oversight decisions and interventions, including near misses. The Guidelines also flag automation bias and decision fatigue as oversight risks as AI increases in speed and scale.
Third-party parity. Third-party AI carries the same governance weight as internally built AI. The definition is wide: all providers of third-party AI products and services, including systems, models, data used for AI, and existing third-party products where AI has been introduced. FIs should test third-party AI in the context of their own use cases using their own data, perform compensatory testing where vendor disclosure falls short, secure notification of updates or changes, assess supply chain and concentration risks, and update legal agreements, including audit rights and notification when AI is introduced. Ongoing monitoring expectations explicitly include third-party AI used in the FI. A vendor agent embedded in your workflow is your AIRG problem.
| AIRG expectation | What it means for agents | Evidence to retain |
|---|---|---|
| Board and senior management oversight | Agent risk in the risk appetite framework; escalation path for agent incidents; committee where exposure is material | Approved governance framework, risk appetite statements and limits, Board reporting packs, escalation records |
| AI identification and inventory | Every agent registered with owner, approved scope, tools, dependencies, lifecycle status | Current inventory extract with attestation trail |
| Risk materiality assessment (impact, complexity, reliance) | Autonomy and tool access scored under reliance; inherent and residual ratings within risk appetite | Assessment methodology, per-agent ratings, control-function sign-off |
| Human oversight | Named reviewers with authority to intervene; oversight designed into the agent path | Oversight decisions and interventions, incidents and near misses, periodic effectiveness reviews |
| Monitoring and auditability | Reasoning processes, actions taken, and tools used monitored; records support independent review | Append-only action records, monitoring metrics against thresholds, drift and anomaly checks |
| Third-party AI management | Vendor agents inventoried, tested on FI data, contracts updated, changes notified and assessed | Due-diligence files, compensatory test results, updated agreements, change notifications |
The transition plan: from today to finalisation
MAS has committed to finalising the Guidelines soon, without a published date. Work done before issuance counts double: it removes the discovery phase from the 12-month clock and it surfaces the decisions that need Board time. Two workstreams belong in this window.
Agent and AI inventory. Stand up the identification process and inventory now, against the attribute list in the consultation paper. For agents, extend the standard attributes with the agent-specific ones the inventory design review is meant to catch: tools the agent can call, systems it can reach, the mandate or approved scope of autonomous action, and the guardrails in place. Include third-party and vendor-embedded agents from day one.
Materiality classification. Draft the risk materiality methodology on the three proposed dimensions of impact, complexity, and reliance, and run it across the inventory. The output that matters is a ranked list: which agents are high materiality, and would therefore need formal independent validation, contingency plans, and the fullest life cycle controls once the Guidelines apply. Expect agents in credit, AML, payments, and regulated advisory workflows to rank high on both impact and reliance.
Both workstreams are also the first two sections of a SAFR gap assessment, so a single pass covers both. The SAFR Readiness Checklist structures that pass as assessor-style questions with per-section scoring.
The transition plan: the 12 months after issuance
The consultation paper proposes 12 months from issuance "for FIs to assess and implement the Guidelines as appropriate." The plan below sequences that window for an FI running agents in production or bringing them there. Months are counted from the issuance date. The sequencing logic: governance decisions first because everything downstream needs an approved framework; runtime controls for high-materiality agents in the middle because they take the longest to build and produce the evidence everything else consumes; assurance and reporting last because they audit what the earlier months built.
Two standing disciplines run across all twelve months. Evidence retention: from the first month, keep the records the Guidelines expect an independent party to be able to review, covering development documentation, validation reports, oversight decisions and interventions, monitoring results, incidents, and change records, with retention rules settled once in policy. Board reporting: senior management updates the Board on material AI risk issues in a timely manner throughout, with the formal cadence fixed in month 2 and exercised every quarter after.
| Months | Workstream | Done means |
|---|---|---|
| 1–2 | Governance baseline | Board approves the AI risk governance approach and risk appetite statements with quantitative limits. Roles assigned: control functions for identification, inventory, and materiality assessment; accountable owners per agent. Cross-functional AI risk committee established if overall exposure is material. Board reporting cadence fixed. |
| 1–3 | Inventory and materiality closure | Pre-issuance inventory reconciled against the final Guidelines text. Materiality methodology approved by the control function and applied to every AI use case, system, and model, third-party included. High-materiality agent list signed off. Residual-risk positions checked against risk appetite. |
| 3–6 | Runtime authorization checkpoints | High-materiality agents run behind a runtime checkpoint: every proposed action is evaluated against approved policy before execution, with allow, warn, require-approval, and block outcomes enforced and recorded. Human oversight wired in: named reviewers with authority to approve, modify, or decline, escalation timeouts, and documented decisions. Kill-switch and contingency protocols defined and tested for high-materiality agents. |
| 4–7 | Third-party AI parity | Vendor and embedded agents tested in the FI's own use-case context on the FI's own data, with compensatory testing where disclosure is thin. Legal agreements updated: audit rights, performance terms, notification when AI is introduced or changed. Concentration and supply chain risks assessed. Update-notification and impact-assessment process operating. |
| 6–9 | Validation and pre-deployment control | Formal independent validation completed for high-materiality agents; documented peer review for the rest. Evaluation and testing cover key failure modes for Generative AI and agents, including adversarial testing. Technology and cybersecurity reviews closed. Reproducibility documentation sufficient for an independent party to understand and replicate the implementation. |
| 8–11 | Monitoring, change, and retirement controls | Post-deployment monitoring live with metrics, tiered thresholds, and drift checks; for agents, monitoring covers reasoning processes, actions taken, and tools used. Incident and issue management process exercised at least once. Change management distinguishes material from minor changes and gates material ones on re-approval. Retirement and decommissioning controls documented, including data retention and secure removal. |
| 10–12 | Assurance and steady state | Aggregate AI risk reviewed across the portfolio; re-validation triggers defined. Internal audit or an equivalent independent function walks the evidence chain end to end: inventory entry, materiality rating, validation, runtime decisions, oversight records, monitoring results. Gaps remediated. Board receives the transition closure report and the recurring AI risk report takes over. |
Runtime controls and the authorization of each agent action
The hardest AIRG expectations to satisfy for agents are the ones that assume you can account for what the AI actually did. Monitoring should cover, where relevant, "information flow and decision-making paths across workflows that use AI, such as reasoning processes, actions taken, tools used." Human oversight requires personnel with the authority and ability to intervene, and documented oversight decisions. Reproducibility and auditability require records an independent reviewer can work from. For a static model these are achievable with logging and periodic review. For an agent that chooses its own next action at runtime, they require a control point in the execution path.
A runtime authorization checkpoint is that control point. Each proposed agent action is intercepted before execution and resolved against approved policy into one of four outcomes: allow, warn, require approval, or block. The SAFR specification formalises the same pattern as its four dispositions and adds the property that matters for multi-step agents: authorization at one step carries no authority into the next, so step three of a workflow is evaluated as independently as step one. The parliamentary reply describes SAFR in exactly these terms: how agent actions are authorised, how human oversight is activated, and what is recorded at the point of every consequential decision.
This structure answers the AIRG expectations directly. The require-approval path gives human oversight its intervention point, with a named reviewer, a decision, and a record, before the action executes. The decision log gives monitoring its per-action trail of what was proposed, which policy applied, and what happened. The block outcome plus a kill switch gives the contingency expectation its enforcement mechanism. The same checkpoint in front of a vendor agent delivers third-party parity without changes to vendor code. KLA Control Plane ships this pattern, with the four dispositions mapped one-to-one to allow, warn, require_approval, and block; the component mapping is on the SAFR implementation page.
The retention half matters as much as the enforcement half. A checkpoint that decides but does not durably record fails the auditability expectation; retention that captures logs without a decision structure fails the oversight one. The record for each consequential action should hold the proposed action, the policy version evaluated, the outcome, the human decision where one was required, and the execution result, kept for the period your record-keeping policy sets and retrievable when a validator or supervisor asks.
What to do this quarter
The pre-issuance window is measured in MAS' word "soon." Three moves fit inside a quarter. First, run the gap assessment: score your current state across inventory, mandates, controls, dispositions, escalation, and evidence with the SAFR Readiness Checklist. Second, brief the Board: the accountability expectations land on them, and the SAFR Executive Briefing is written for that audience. Third, pick the first high-materiality agent and put a runtime authorization checkpoint in front of it, so the 12-month plan starts from a working reference implementation.
Frequently Asked Questions
What is the MAS AIRG?
AIRG stands for the Guidelines on Artificial Intelligence Risk Management, proposed by the Monetary Authority of Singapore in consultation paper P017-2025 (13 November 2025). The Guidelines set out MAS' supervisory expectations for AI risk management in financial institutions, covering Board and senior management oversight, AI identification, inventory and risk materiality assessment, AI life cycle controls, and capability and capacity for the use of AI.
Does AIRG cover agentic AI?
Yes. In a written parliamentary reply dated 5 August 2026, MAS confirmed the Guidelines "apply to all AI use cases by FIs, including agentic AI, and will be finalised soon." The consultation paper also names AI agents throughout its scope definition and risk discussion.
When does AIRG take effect?
The Guidelines have not been issued yet. MAS stated on 5 August 2026 that they will be finalised soon, without publishing a date. The consultation paper proposes a transition period of 12 months after issuance for FIs to assess and implement the Guidelines.
Which institutions are in scope?
MAS proposes to apply the Guidelines to all financial institutions as defined in Section 2 of the Financial Services and Markets Act 2022, implemented proportionately to the size and nature of activities, use of AI, and risk profile. Singapore branches and subsidiaries of foreign groups may leverage their parent entity's AI risk management framework where it meets the AIRG expectations.
How does AIRG treat third-party AI?
Third-party AI carries the same governance expectations as internally developed AI. The consultation paper defines third-party AI to include all providers of third-party AI products and services, including systems, models, data used for AI, and existing third-party products where AI has been introduced. FIs should test third-party AI in their own use-case context with their own data, perform compensatory testing where vendor disclosure is inadequate, manage concentration and supply chain risks, and update legal agreements. MAS' expectations on outsourcing and third-party services also apply.
How do AIRG and SAFR fit together?
AIRG sets MAS' supervisory expectations; SAFR is an industry implementation reference from MAS' BuildFin.ai program. The parliamentary reply describes SAFR as a potential approach to how agent actions are authorised, how human oversight is activated, and what is recorded at the point of every consequential decision. Implementing SAFR-style runtime controls is one way to produce the operational evidence AIRG's oversight, monitoring, and auditability expectations call for. See the full explainer at /blog/safr-mas-framework-explained.
Key Takeaways
MAS has settled the scope question: agents are inside the AIRG supervisory expectations, and the Guidelines are close to final. The proposed 12-month transition is enough time for an FI that starts now on the two pre-issuance workstreams, agent inventory and materiality classification, and then works the transition plan in sequence: governance first, runtime authorization checkpoints and third-party parity in the middle, validation, monitoring, and assurance to close. Score your starting point with the SAFR Readiness Checklist, and put the SAFR Executive Briefing in front of the people the accountability expectations name.
Sources: MAS Consultation Paper P017-2025, Guidelines on Artificial Intelligence Risk Management, 13 November 2025; MAS written reply to Parliamentary Question on agentic AI in financial services, 5 August 2026. The AIRG remains a consultation draft until issued; details cited here reflect the proposed text and may change in the final Guidelines. KLA is independent of and not affiliated with, endorsed by, or certified by MAS.
