Financial institutions must remain accountable for use of third-party AI tools: MAS新加坡金融管理局:金融机构必须对第三方人工智能工具的使用承担责任
Financial institutions are expected to adhere to the new guidelines in phases starting from Oct 2027. Read more at straitstimes.com.
The guideline published by the Monetary Authority of Singapore on Oct 7 also highlights rules regarding the need for human oversight, inventories that track various AI use cases, and how safeguards on AI can be applied in a risk-proportionate manner.
Published Oct 07, 2026, 08:22 PM
Updated Oct 07, 2026, 08:22 PM
SINGAPORE - Financial institutions here relying on artificial intelligence tools such as chatbots must remain accountable for any unintended consequences such as data leaks or inaccurate information, even if a third-party had built the software.
New guidelines for AI use in the financial sector were published by the Monetary Authority of Singapore (MAS) on Oct 7, which sets regulatory expectations on how institutions such as banks and insurers should manage risks from AI use.
The new guidelines, which will be effective in phases starting from Oct 2027 , come amid intense debates over the safety and regulation of advanced frontier AI models that have autonomous abilities.
“Financial institutions remain accountable for AI used in the services they deliver, including AI developed, operated, or provided by third parties,” MAS said in a statement on Oct 7.
It added that institutions should assess factors such as model transparency, explainability and contingency plans in case of unexpected behaviour, before deciding to use third-party AI tools.
The guideline also highlights rules regarding the need for human oversight, inventories that track various AI use cases, and how safeguards can be applied in a risk-proportionate manner.
This follows a period of public consultation in November 2025, during which respondents had sought clarity on whether institutions could tap on existing governance structures to manage AI risks, how they should manage risks from embedded AI, and whether basic AI governance policies would suffice.
The newly-issued guidelines clarified that basic AI governance policies - such as restricting the input of confidential or client information - are sufficient when the poor performance of AI services are unlikely to have an material adverse impact on the company, its customers, or stakeholders.
This includes AI use for drafting and proofreading e-mails, summarising internal meeting notes, and designing marketing materials.
The board and senior management must be responsible for regularly reviewing the policies and risks regarding AI use, and establishing clear internal reporting processes for managing incidents that occur from AI use.
“Existing governance structures may be used where they provide adequate oversight and cross-functional coordination, and financial institutions need not establish a dedicated AI committee solely to meet this expectation,” said MAS in its media statement.
Other top-line rules include the need for an “inventory” of the various ways that AI is used by the institution. The inventory should have details of the systems and models in use such as the approved modes of use, training data involved and the humans accountable.
Risks assessments also need to be conducted, considering factors such as the potential consequences of poor AI performance and the extent of autonomy granted to the AI system.
Proportionate controls can then be applied according to the risk level, said MAS. For instance, AI that is used for credit decisioning, insurance underwriting, or other activities with high impact on customers will require more stringent scrutiny and robust controls .
Appropriate controls must also be implemented to mitigate harmful biases and discriminatory outcomes that might result from AI use, said MAS.
“For example, greater attention should be paid to AI used in areas such as credit decisioning and insurance underwriting that may lead to unfair access or denial of financial services or products offered to individuals,” it added.
Financial institutions are expected to adhere to rules spelled out in the guidelines in two phases.
From Oct 7, 2027, institutions must have their foundational governance systems ready, with an inventory of AI tools used and the ability to conduct risk assessments. From Oct 8, 2028, institutions must be able to rigorously test, monitor, and maintain strict human control over their AI systems, while securing the necessary skilled staff and technology infrastructure to operate them safely.
In 2027, MAS intends to further consult the financial sector on what additional guidance is needed for agentic AI use.
AI has significant potential to improve financial services by enhancing customer experiences, strengthening risk management, and creating new products, said MAS’ deputy managing director Ho Hern Shin.
“Realising these benefits sustainably requires financial institutions to understand and manage the risks that come with increasingly capable AI systems,” said Ho.
“With greater regulatory clarity on financial institutions’ AI usage, financial institutions can innovate with confidence, while maintaining the trust of customers and the resilience of Singapore’s financial system.”
AI/artificial intelligence
Monetary Authority of Singapore
新加坡金融管理局于 10 月 7 日发布的指导方针还重点强调了有关人工监督的必要性、跟踪各种人工智能使用案例的清单以及如何以风险相称的方式应用人工智能安全保障的规则。
发布于 2026 年 10 月 7 日晚上 8:22
更新于2026年10月7日晚上8:22
新加坡——即使软件是由第三方开发的,依赖人工智能工具(例如聊天机器人)的金融机构也必须对任何意外后果(例如数据泄露或信息不准确)负责。
新加坡金融管理局 (MAS) 于 10 月 7 日发布了金融领域人工智能使用的新指南,其中规定了银行和保险公司等机构应如何管理人工智能使用带来的风险的监管预期。
新的指导方针将于 2027 年 10 月起分阶段生效,此时正值人们对具有自主能力的先进前沿人工智能模型的安全性和监管展开激烈辩论之际。
新加坡金融管理局 (MAS) 在 10 月 7 日的一份声明中表示:“金融机构仍需对其提供的服务中使用的 AI 负责,包括由第三方开发、运营或提供的 AI。”
报告还指出,机构在决定使用第三方人工智能工具之前,应评估模型透明度、可解释性以及在出现意外行为时的应急计划等因素。
该指南还重点强调了有关人工监督的必要性、跟踪各种人工智能使用案例的清单以及如何以风险相称的方式应用保障措施的规则。
此前,在 2025 年 11 月进行了一段时间的公众咨询,期间受访者希望明确机构是否可以利用现有的治理结构来管理人工智能风险,它们应该如何管理嵌入式人工智能带来的风险,以及基本的人工智能治理政策是否足够。
新发布的指导方针明确指出,当人工智能服务的性能不佳不太可能对公司、其客户或利益相关者产生重大不利影响时,基本的人工智能治理政策(例如限制输入机密信息或客户信息)就足够了。
这包括利用人工智能撰写和校对电子邮件、总结内部会议记录以及设计营销材料。
董事会和高级管理层必须负责定期审查有关人工智能使用的政策和风险,并建立清晰的内部报告流程,以管理因人工智能使用而发生的事件。
新加坡金融管理局在媒体声明中表示:“现有的治理结构如果能够提供足够的监督和跨职能协调,就可以继续使用,金融机构无需专门设立人工智能委员会来满足这一期望。”
其他主要规则包括需要建立一份机构使用人工智能各种方式的“清单”。该清单应详细列出正在使用的系统和模型,例如已批准的使用模式、涉及的训练数据以及负责人员。
还需要进行风险评估,考虑诸如人工智能性能不佳的潜在后果以及赋予人工智能系统的自主程度等因素。
新加坡金融管理局表示,之后可以根据风险等级采取相应的管控措施。例如,用于信贷决策、保险承保或其他对客户影响较大的活动的AI,需要接受更严格的审查和更强有力的管控。
金管局表示,还必须实施适当的控制措施,以减轻人工智能使用可能导致的有害偏见和歧视性结果。
报告还补充道:“例如,应该更加关注人工智能在信贷决策和保险承保等领域的应用,因为这可能会导致个人无法公平地获得或被拒绝获得金融服务或产品。”
金融机构应分两个阶段遵守指南中规定的规则。
自2027年10月7日起,各机构必须建立完善的基础治理体系,包括已使用的AI工具清单以及开展风险评估的能力。自2028年10月8日起,各机构必须能够对其AI系统进行严格的测试、监控和人工控制,同时确保配备必要的专业人员和技术基础设施,以安全运行这些系统。
2027 年,新加坡金融管理局 (MAS) 计划进一步咨询金融界,了解在智能人工智能 (AI) 的应用方面还需要哪些额外指导。
新加坡金融管理局副局长何赫新表示,人工智能具有巨大的潜力,可以通过提升客户体验、加强风险管理和创造新产品来改善金融服务。
“要可持续地实现这些好处,金融机构需要了解和管理日益强大的人工智能系统带来的风险,”何先生说。
“随着金融机构人工智能使用方面的监管更加明朗,金融机构可以更有信心地进行创新,同时保持客户的信任和新加坡金融体系的韧性。”
人工智能
新加坡金融管理局