As AI adoption accelerates across financial services, regulators are increasingly focused not only on how firms govern AI, but also on how they demonstrate that governance is working in practice. In Singapore, MAS's proposed AI Risk Management Guidelines signal an important evolution in regulatory expectations, with greater emphasis on accountability, risk-based controls and evidence that appropriate governance and oversight are in place.
We spoke with Steven Nunez, Capco Executive Director and AI Lead about what this evolving landscape means for financial institutions and what firms should be doing now to prepare. He discusses how MAS initiatives and emerging approaches to Agentic AI fit together, the practical challenges of establishing effective AI governance and where ISO/IEC 42001 can provide a common management-system foundation as organizations navigate regulatory expectations in Singapore and across jurisdictions.
What do MAS’s proposed AI Risk Management Guidelines mean in practice, and what should financial institutions do before the final guidelines are issued?
It's first worth properly framing the overall shift that's taking place. We're moving from a principles-based Responsible AI framework and voluntary compliance to an evidence-based regulatory assurance one. It's still principles-based, so there are numerous ways to satisfy the requirements, but entities may now be asked to prove adherence.
The final guidelines are expected to be issued before the end of 2026, and the best thing institutions can do now is understand the scope of the problem. Now is the time to establish inventories, governance structures, perform a materiality assessment and begin thinking about remediation plans.
While taking stock of their AI inventory, it's also a great time to conduct a maturity assessment across each business function. This is often overlooked because AI operating models tend to grow organically rather than being planned. The bottom line at this stage is to figure out what you have, and what value it brings to the business.
How do MAS initiatives such as FEAT, Veritas and Project MindForge fit together with the ISO/IEC 42001 framework and MAS SAFR when it comes to demonstrating regulatory compliance in the modern AI era?
This is one of the questions many people struggle to understand. The best way to think about it is as a hierarchy. At the highest level, you have governing principles, such as FEAT (Fairness, Ethics, Accountability and Transparency). Below are assessment methodologies, such as Veritas, which give you a means of measuring how well your AI system aligns with those principles. Then we have operational resources, such as MindForge, which provide a playbook for keeping your AI systems aligned with these principles over time.
Alongside these, MAS recently released a white paper on managing agents: Safeguards for Agentic Finance at Runtime (SAFR), which provides a technical framework describing safeguards that can be implemented to reduce the risk of deploying agents that make financial decisions or transactions on behalf of customers.1 Deploying these types of agents is probably the most common 'north star' project we see at Capco at the moment.
ISO/IEC 42001 provides another important piece of the picture. It is a certifiable Artificial Intelligence Management System (AIMS) standard that provides a structured foundation for managing AI governance across an organization. It forms the basis for compliance in the EU under the EU AI Act and is referenced by other AI regulatory bodies, such as the IMDA in Singapore, which provides a mapping, and NIST in the US. It's not compulsory to implement ISO/IEC 42001 outside the EU, but it provides an excellent foundation for achieving cross-jurisdictional compliance.
What challenges do financial institutions face in determining whether an AI use case is material and requires enhanced governance, validation and human oversight?
The truth is that most organizations fail before they even get to the materiality determination. That’s because they don’t have a proper inventory. The reasons, we think, are historical and stem from the rise of ‘citizen data scientists’, who were so popular a few years ago.
Do you know where all your models are now? One bank I know of has more than 300 models, on just one of their platforms, and there are undoubtedly many more running across the organization that they don’t know about.
Back to materiality, in Singapore, and to a large extent across the ASEAN region, a consensus is emerging on how institutions can determine materiality. MAS, in guidance papers released over the last couple of years, defines materiality across three risk dimensions: impact, complexity and reliance.
Impact captures the potential consequences of an AI failure, both for the institution and for external stakeholders. Institutional impacts can include reputational, regulatory or financial effects on the business, while stakeholder impacts need to consider fairness, ethics and reputation (FEAT, as we mentioned above).
Then there’s complexity which considers the complexity of AI technology itself, the novelty of its application and the data it uses. Deterministic symbolic AI is generally easier to govern here, and most of the current challenges come from LLM-based applications, which are inherently non-deterministic by nature.
Finally, reliance considers both the degree of autonomy given to an AI system and the degree to which the institution relies on it. We're seeing a lot of challenges here with the rise of agentic workflows, which combine two risks: high autonomy and non-deterministic outcomes. These are both easily addressed by having agents follow only pre-defined workflows and by ensuring decisions are made by deterministic systems, such as rules engines informed by statistically backed predictions.
This kind of risk-based materiality assessment also fits naturally within an ISO/IEC 42001-based management system, where the level of governance and oversight should be proportionate to the risks involved.
Unfortunately, in the headlong rush into LLM-based workflows, many organizations are going to have some rework to do. Ultimately, effective materiality assessment starts with knowing what AI you have and applying a consistent, risk-based approach to determine where enhanced governance is genuinely needed.
How can financial institutions turn high-level AI principles into governance frameworks, policies and procedures that work in day-to-day operations?
That's really the challenge financial institutions now face. MAS sets out principles and expectations around areas such as accountability, risk management and oversight, but organizations still need to translate those expectations into governance that works consistently in day-to-day operations. This is where ISO/IEC 42001 can provide a useful management system structure.
ISO/IEC 42001 uses a Plan-Do-Check-Act (PDCA) cycle as the basis for continuous improvement of an AIMS. In practical terms, it gives organizations a way to move from principles and regulatory expectations to defined responsibilities, operational controls, monitoring and corrective action.
In the ‘Plan’ phase of PDCA, you establish what you're governing. That means understanding your AI inventory, assessing the associated risks and setting objectives for the system, including the business outcomes you're trying to achieve. This is where the inventory and materiality assessments we've already discussed become particularly important, because they help determine what level of governance is appropriate.
The ‘Do’ phase is where that governance becomes operational. You implement the relevant controls, establish accountability – for example, through a RACI matrix – and manage areas across the AI lifecycle such as data quality, system design and testing. Annex A of ISO/IEC 42001 provides 38 controls that can help organizations get started, although most will need to supplement these based on their specific risks and regulatory requirements. Singapore's IMDA also provides AI Verify, a testing framework that maps to ISO/IEC 42001 controls and now includes GenAI capabilities.
The ‘Check’ phase is about determining whether the management system and its controls are operating as intended. Organizations measure performance, conduct audits and review whether governance and leadership controls remain appropriate.
Finally, ‘Act’ means addressing nonconformities, applying corrective actions and adjusting the AIMS where necessary to prevent issues from recurring.
That's ultimately how you move from principles on paper to governance that works in practice. MAS provides regulatory direction, while a management-system approach such as ISO/IEC 42001 can provide the structure for embedding those expectations into day-to-day operations and continually adapting as technology, risks and regulatory expectations evolve.
How can an organization prove that its AI controls operate effectively, rather than merely documenting policies and control descriptions?
There’s a nuance in this question that’s worth exploring. First, you can’t prove that AI controls are operating effectively. You can only prove that they are operating as designed. This is one of the reasons for the principles-based approach. Each organization has to determine and continuously adjust its AIMS to ensure that it is effective for that particular use case. You need an AIMS for each use case or system, including those provided by third parties.
ISO/IEC 42001 is a certifiable standard, meaning you can have a third party audit your AIMS and certify that it meets the standard (similar to ISO 27000), but that doesn’t mean it’s effective for your organization. Ultimately, organizations still need to assess whether their controls are appropriate for the risks, technologies and use cases they are managing.
Responsibility for these systems ultimately comes down to proper organizational management, and that’s one of the key points that’s often missing from these discussions. We've seen this first-hand through our AI for Executives half-day workshop. It's become one of our most popular AI governance training courses because many executives are still trying to understand where their responsibilities lie. AI is still so new that most executives don't know where their responsibilities begin and end, yet they are ultimately the ones accountable for compliance.
What additional controls are needed when AI agents can initiate actions autonomously and at a speed that makes traditional human approval impractical?
This is a topical area of research, and there isn’t yet any solid guidance. Conventional AIMSs aren’t designed for real-time operation. They focus on managing inputs, outputs and FEAT, but agentic systems add further dimension: should this agent be allowed to take a specific action, in a specific context, at a specific moment? In short, traditional AIMSs manage AI that recommends actions to a human, whereas this type of management is aimed at agents that actually perform those actions themselves, in real time.
At its core, this kind of AIMS sits between the execution environment and the agent. This runtime governance is different from guardrails – it’s not about prompt defenses; it’s about authorization and authority.
The newly published SAFR architecture describes four core components: agent identity, controls repository, disposition engine and an audit log. Before an agent takes any action, a decision is made: deny, escalate, auto-execute or observe. The disposition engine can be implemented as a rules-engine because its outputs are deterministic; it is a special case of an expert system.
Fuzzy logic, an established form of symbolic reasoning, is seeing a resurgence because it can be deterministic within statistical boundaries (think p-factors). It's exciting to see this technology from years ago finally have its day in the sun.
How should a regional financial institution set about building one AI control framework that meets Singapore’s expectations while also accommodating Hong Kong, Malaysia and Thailand? What areas of overlap exist, and what are the key obstacles?
The key is to establish a robust base level of governance and then layer jurisdictional or application-specific requirements on top of it. ISO/IEC 42001 provides a useful foundation for an AIMS because it gives organizations a common management-system structure that can then be adapted to different regulatory expectations.
We've already seen how this can work in practice in areas such as auditability and logging. ISO/IEC 42001 has no such requirement, but the EU AI Act does, so an organization can start with ISO/IEC 42001 and layer additional logging requirements on top. We're now seeing similar requirements emerge through SAFR. Many regulatory regimes also provide mappings, or 'crosswalks', to ISO/IEC 42001, which can help organizations identify where their existing governance foundation aligns and where additional jurisdiction-specific controls may be needed.
The challenge for regional financial institutions is therefore not necessarily to build a different AI governance framework for every market, but to understand where regulatory expectations overlap, where they diverge and what additional controls need to be applied locally. A common foundation can make that much more manageable while still allowing institutions to respond to the specific expectations of regulators in Singapore and across the region.
And that adaptability is going to become increasingly important. The pace of AI innovation isn't going to slow down, and neither are regulatory expectations. My advice to organizations is not to wait for perfect clarity before taking action. Start by understanding your AI landscape, establish the right governance foundations and build the capability to adapt over time. If you get those fundamentals right, you'll be in a much stronger position to respond to whatever comes next.
Preparing for MAS’s evolving AI expectations?
Complete the form below to speak with our experts about your AI governance readiness.
References
Get in touch
To find out more about working with Capco and how we can help you overcome any potential challenges, contact our experts or subscribe for the latest insights below.