AI GOVERNANCEASSESSMENT

How ready is your bank for AI governance?

Assess your institution's readiness against Singapore's complete AI regulatory framework.

193REQUIREMENTS
7DOMAINS
13INSTRUMENTS
6SOURCE CLASSES

Seven Assessment Domains

Model Governance & Validation

115 REQUIREMENTS

Full AI lifecycle from identification through decommissioning. Governance structure, capability, third-party AI, and generative AI controls.

Data Governance & Privacy

15 REQUIREMENTS

Personal data in AI systems: consent, data protection, privacy-by-design, anonymisation, bias assessment, and third-party data processing.

Client-Facing AI & Suitability

14 REQUIREMENTS

AI systems interacting with clients: algorithm governance, suitability of advice, fair dealing, customer transparency, and redress.

Explainability & Fairness

11 REQUIREMENTS

Responsible AI principles: fairness definitions, protected attributes, bias detection, explainability methods, and agentic AI governance.

Outsourcing & Third-Party AI

12 REQUIREMENTS

AI from external providers: governance framework, due diligence, outsourcing agreements, concentration risk, and lifecycle management.

Operational Resilience & Cybersecurity

12 REQUIREMENTS

Technology and security infrastructure: IT governance, access control, audit logging, incident management, and AI-specific security.

Governance Structure & Accountability

14 REQUIREMENTS

Institutional governance architecture: AI management system, risk appetite, AI risk culture, operating model, and skills/knowledge.

13 Source Instruments

InstrumentAuthorityStatusTierReqs
P017 – Proposed Guidelines on AI Risk ManagementMASConsultation (closed Jan 2026)CONSULTATION57
MindForge Ops Handbook & Implementation ExamplesMAS/IndustryPublished Jan 2026METHODOLOGY32
ISO/IEC 42001:2023ISO/IECPublishedASSURANCE19
FEAT Principles (2018)MASPublishedMETHODOLOGY17
MAS Information Paper on AI Model Risk ManagementMASPublished Dec 2024OBSERVED PRACTICE16
TRM Guidelines 2021MASIn forceSUPERVISORY13
PDPA Advisory Guidelines (Mar 2024)PDPCPublished Mar 2024METHODOLOGY11
Outsourcing Guidelines (Banks, Dec 2023)MASIn forceSUPERVISORY8
CMG-G02 Digital Advisory GuidelinesMASIn forceSUPERVISORY7
Veritas Assessment MethodologyMAS/IndustryPublishedMETHODOLOGY6
Fair Dealing Guidelines (May 2024)MASIn forceSUPERVISORY3
IMDA Model AI Governance Framework for Agentic AIIMDAPublishedMETHODOLOGY2
P004 – Proposed Guidelines on Third-Party Risk ManagementMASConsultation (open until Apr 2026)CONSULTATION2

This assessment classifies every requirement into one of six regulatory source classes. The classification determines the compliance expectation: statutory requirements impose binding obligations; supervisory guidelines set expectations; consultation papers signal regulatory direction; and industry methodologies offer recommended practice. Each class carries a different weight in the assessment's gap analysis.

Read the full methodology →