Skip to content
Assess  /  Methodology

Methodology

A free research diagnostic using 193 assessment criteria from 13 selected source instruments across 7 domains. This page explains its corpus, 6 source classes, scoring and limits.

Updated

Research register 99bd55b3e4118451

01 — Framework

Scope and authorship

Adrien Pesa developed this free research diagnostic within Governed Autonomy, his independent, self-funded and non-commercial research programme. It supports structured reflection on AI governance practices in private banks in Singapore.

The register is an authored interpretation of the selected corpus, not a complete inventory of Singapore law or a regulator-approved assessment. No criterion in the current register is classified as statutory.

The short diagnostic covers 35 selected priority criteria and takes approximately 25–30 minutes; the extended diagnostic covers all 193 and takes approximately 90–120 minutes. Both are free and use the same scoring rules. A short diagnostic leaves most of the corpus unassessed, so its results describe that limited scope.

Results are calculated in your browser. If you request a PDF, your answers and optional institution label are sent to the report server. Reports use authored analysis by default. An optional AI summary sends selected findings to Anthropic only if you choose it. Anthropic normally retains API inputs and outputs for 30 days, with legal and policy enforcement exceptions. The privacy policy explains processing and retention.

02 — Authority

Source classes and corpus

The programme distinguishes five normative tiers—statutory, supervisory, consultation, methodology and assurance—and a separate observed-practice class. These 6 source classes describe different kinds of authority and evidence; they are not six levels of legal obligation. Expand a class to see the selected instruments, editions and criterion counts. Source class matters for interpretation and the specific maturity override below; it does not weight the readiness percentage.

STATUTORYBinding obligation — "shall" / "must"
0 criteria

Binding legal obligations use “shall” or “must”. This category remains part of the programme framework. Its absence from the selected register does not imply that institutions have no statutory obligations.

No criterion in the current diagnostic is classified as statutory. The corpus is not a complete inventory of applicable law.—
SUPERVISORYSupervisory expectation — "should" / "is expected to"
31 criteria

MAS guidelines set supervisory expectations, expressed as “should” or “is expected to”. The selected corpus includes technology risk, outsourcing, digital advisory and fair dealing guidelines. Supervisory expectations retain their distinct status from statutory obligations.

13 criteria
7 criteria
Fair Dealing Guidelines (May 2024)

MAS · May 2024

The link opens the MAS guidelines directory.

3 criteria
OBSERVED PRACTICEObserved good practice — "MAS has observed that…"
16 criteria

The December 2024 MAS Information Paper reports practices observed in banks. Observations provide evidence for research; they are distinct from statutory obligations, supervisory expectations and proposed guidance.

CONSULTATIONProposed guidance — "has proposed" / "would expect"
60 criteria

Proposals describe what MAS has proposed, not settled obligations. The corpus assesses the P017 and P004 consultation texts. Their consultation periods have closed; users should verify subsequent publications and finalisation status with MAS.

P017 – Proposed Guidelines on AI Risk Management

MAS · November 2025 proposal; consultation closed 31 January 2026

58 criteria
P004 – Proposed Guidelines on Third-Party Risk Management

MAS · March 2026 proposal; consultation closed 20 April 2026

2 criteria
METHODOLOGYRecommended practice — "recommends" / "suggests"
67 criteria

Industry and public-sector frameworks recommend implementation approaches. Sources include FEAT, Veritas, MindForge, the IMDA agentic AI framework and PDPC advisory guidance. Inclusion in this class does not convert a recommendation into a binding obligation or change the status of underlying law.

32 criteria
FEAT Principles (2018)

MAS · 2018 corpus edition

17 criteria
Veritas Assessment Methodology

MAS / Industry · Edition not specified in the register

The link opens the initiative page; edition-level mapping remains to be confirmed.

5 criteria
IMDA Model AI Governance Framework for Agentic AI

IMDA · January 2026 corpus edition (v1.0)

January launch page. The publisher has since issued a revised framework.

2 criteria
ASSURANCEVoluntary standard — "shall" (within standard scope)
19 criteria

ISO/IEC 42001 provides an AI management system standard. Its requirements apply within the scope of adopting or seeking certification to that standard. Inclusion here does not establish certification, independent verification or a MAS requirement to adopt the standard.

ISO/IEC 42001:2023 – AI Management System

ISO / IEC · Edition 1, December 2023

Publisher overview; the full standard requires licensed access.

19 criteria

Counts sum to 193 across the source classes. Each criterion is counted once under its primary source; some also cite supporting instruments. Edition labels describe the selected research corpus. Publisher links may open an initiative page or directory. Check the publishers for later revisions; the corpus is not an exhaustive or continuously updated regulatory inventory.

03 — Coverage

The seven domains

Every criterion is assigned to one of 7 thematic domains. Results report the fully implemented percentage and findings within each domain. The overall maturity label uses all applicable answered criteria; domain percentages are not averaged to produce it.

D1 · Model Governance & Validation

115

Full AI model lifecycle — identification, risk classification, development, validation, deployment, monitoring, change, and decommissioning. Governance structure and committee oversight, validation independence, third-party model controls, and generative-AI safeguards. Drawn primarily from P017, the MAS AI MRM Information Paper, MindForge, and ISO/IEC 42001.

D2 · Data Governance & Privacy

15

Personal data in AI systems — consent and notification, data protection impact assessments, privacy-by-design, anonymisation, training-data bias, and third-party data processing. Selected PDPC advisory guidance is combined with proposed AI-specific governance in P017 and implementation methods from MindForge.

D3 · Client-Facing AI & Suitability

14

AI systems that interact with clients or influence client outcomes — robo-advisory, recommendation engines, chatbots, and automated suitability. Algorithm governance, fair dealing, customer transparency, and redress mechanisms. CMG-G02 Digital Advisory Guidelines and Fair Dealing Guidelines, supplemented by P017’s client-facing provisions.

D4 · Explainability & Fairness

11

Responsible-AI principles — fairness definitions and metrics, protected-attribute handling, bias detection and mitigation, explainability proportionate to the use case, and agentic-AI governance. FEAT Principles operationalised through Veritas, with the IMDA Agentic AI Framework extending coverage to autonomous systems.

D5 · Outsourcing & Third-Party AI

12

AI from external providers — cloud AI platforms, vendor model APIs, and outsourced AI development. Governance framework, due diligence, outsourcing agreements, concentration risk, and lifecycle management. The selected Outsourcing Guidelines for Banks plus proposed third-party provisions in the P017 and P004 consultation texts.

D6 · Operational Resilience & Cybersecurity

12

Technology and security infrastructure for AI — IT governance and change management, access control, audit logging, incident response, and AI-specific cybersecurity threats (adversarial attacks, data poisoning, model extraction). Selected TRM supervisory expectations are supplemented by proposed AI-specific operational resilience provisions in P017.

D7 · Governance Structure & Accountability

14

Institutional governance architecture for AI — management system, risk appetite and tolerance, AI risk culture, operating model, and skills and capability across board, senior management, and operational layers. ISO/IEC 42001 provides a management-system structure, with P017 supplying proposed governance provisions that intersect other domains.

Domain 1 carries 60% of the register, reflecting the depth of P017 and the MAS AI MRM Information Paper around the model lifecycle. The remaining 40% is distributed across the other 6 domains. Because each applicable answered criterion has equal weight, domains with more criteria contribute more to the overall percentage. This distribution reflects the selected corpus, not an independently established ranking of institutional risks.

04 — Logic

Response model & scoring

Select the response that best matches the evidence available to you. The diagnostic does not inspect that evidence or independently verify your answers. Not applicable is available only where the criterion offers option D.

If none of the available answers accurately describes your institution, leave the criterion unanswered. You can review partial results in the browser; a PDF requires an answer to every criterion in the selected scope.

A
Fully implemented
The stated practice is fully in place and supported by evidence available to you. The diagnostic does not inspect or verify that evidence.
Implemented
B
Partially implemented
Some elements are in place, but gaps remain in coverage, documentation or review cadence.
Partial
C
Not implemented
The stated practice is absent or materially incomplete. This response identifies a gap against the selected criterion.
Gap
D
Not applicable (where offered)
This option is offered only where the register provides it. The criterion does not apply to the scope being assessed. Retain a defensible reason; the diagnostic does not verify this judgement.
Excluded

Implementation percentage and severity

The implementation percentage is A ÷ (A + B + C) × 100, rounded to one decimal place for display. A counts in the numerator and denominator; B and C count in the denominator, with no partial credit for B. D and unanswered criteria are excluded. Domain percentages use the same calculation. Every applicable answered criterion has equal weight; neither source class nor severity weights the percentage.

HIGH, MEDIUM and LOW are authored severity classifications for the findings. Severity determines their presentation order and the HIGH-gap overrides described below. Only C answers count as gaps for those overrides; partial answers remain separate findings. These are research conventions, not regulator-issued severity scores.

05 — Output

Maturity rating

Zero applicable answers produce “Insufficient Data”. Otherwise, any STATUTORY HIGH-severity C answer, or three or more HIGH-severity C answers across any source class, produces “Critical Gaps”. If neither override applies, the unrounded overall percentage determines the band below. These labels and thresholds are research conventions; they are not regulatory grades or validated benchmarks of institutional performance.

1
Critical Gaps
The lowest percentage band, or a HIGH-gap override. The label identifies a research result within the answered scope; it does not itself establish a statutory breach.
< 40%
2
Developing
The proportion reported as fully implemented falls within this band. Read partial implementation, gaps and source classes alongside the percentage.
40% to <65%
3
Defined
A higher proportion of applicable answered criteria is reported as fully implemented. The label does not establish coverage of every domain or independently verified control effectiveness.
65% to <85%
4
Established
The highest percentage band without a HIGH-gap override. Up to two HIGH-severity gaps can still be present. Read the underlying findings and coverage; this is not a finding of compliance.
≥ 85%

The statutory override remains part of the scoring framework, although the current register contains no statutory criteria. Fewer than half of the register’s criteria answered A, B or C adds a coverage warning; it does not otherwise change the label. The short diagnostic will therefore normally carry that warning. Rule-based consistency checks flag specified answer combinations for review without changing answers. Scoring, labels and gap identification are deterministic; AI does not calculate them.

06 — Caveats

Limitations

The assessment provides an indicative view of AI governance readiness. The following limitations should be considered when interpreting results.

Self-assessment bias
Self-assessments are subject to optimism bias, knowledge gaps, and inconsistent interpretation. Results should be validated through independent review or internal audit where material decisions depend on the outcome.
Point-in-time snapshot
Results describe the self-reported practices in the answered scope at a single moment. A high percentage can conceal unassessed areas, different gaps or unjustified non-applicability choices. Review findings and coverage alongside the label.
Not legal advice
Results are not an audit, certification, legal opinion, regulatory approval or prediction of supervisory outcomes. They support research and internal reflection; they do not replace qualified professional judgement.
Scope
The corpus focuses on Singapore private banking and wealth management. It is not an exhaustive or continuously updated statement of applicable obligations. Statutory duties, institution-specific applicability, other jurisdictions and later revisions require separate review.
Consultation texts and editions
A material portion of the register (60 of 193) derives from the P017 and P004 consultation texts. Their consultation periods have closed. The selected texts remain research inputs here; current finalisation status and subsequent publications should be checked with MAS.
Validation
The methodology has not been validated against supervisory outcomes or a representative sample of institutions. The register includes historical editions and voluntary frameworks; source inclusion does not turn them into current legal obligations.
Optional AI narrative
When available and explicitly selected for a PDF, AI-assisted prose can contain errors. It does not change deterministic scores or findings. Reports otherwise use authored research analysis; processing is explained before submission and in the privacy policy.