01 — Framework
Scope and authorship
Adrien Pesa developed this free research diagnostic within Governed Autonomy, his independent, self-funded and non-commercial research programme. It supports structured reflection on AI governance practices in private banks in Singapore.
The register is an authored interpretation of the selected corpus, not a complete inventory of Singapore law or a regulator-approved assessment. No criterion in the current register is classified as statutory.
The short diagnostic covers 35 selected priority criteria and takes approximately 25–30 minutes; the extended diagnostic covers all 193 and takes approximately 90–120 minutes. Both are free and use the same scoring rules. A short diagnostic leaves most of the corpus unassessed, so its results describe that limited scope.
Results are calculated in your browser. If you request a PDF, your answers and optional institution label are sent to the report server. Reports use authored analysis by default. An optional AI summary sends selected findings to Anthropic only if you choose it. Anthropic normally retains API inputs and outputs for 30 days, with legal and policy enforcement exceptions. The privacy policy explains processing and retention.
02 — Authority
Source classes and corpus
The programme distinguishes five normative tiers—statutory, supervisory, consultation, methodology and assurance—and a separate observed-practice class. These 6 source classes describe different kinds of authority and evidence; they are not six levels of legal obligation. Expand a class to see the selected instruments, editions and criterion counts. Source class matters for interpretation and the specific maturity override below; it does not weight the readiness percentage.
STATUTORYBinding obligation — "shall" / "must"0 criteria
Binding legal obligations use “shall” or “must”. This category remains part of the programme framework. Its absence from the selected register does not imply that institutions have no statutory obligations.
SUPERVISORYSupervisory expectation — "should" / "is expected to"31 criteria
MAS guidelines set supervisory expectations, expressed as “should” or “is expected to”. The selected corpus includes technology risk, outsourcing, digital advisory and fair dealing guidelines. Supervisory expectations retain their distinct status from statutory obligations.
MAS · January 2021
MAS · December 2023
MAS · October 2018
OBSERVED PRACTICEObserved good practice — "MAS has observed that…"16 criteria
The December 2024 MAS Information Paper reports practices observed in banks. Observations provide evidence for research; they are distinct from statutory obligations, supervisory expectations and proposed guidance.
MAS · December 2024
CONSULTATIONProposed guidance — "has proposed" / "would expect"60 criteria
Proposals describe what MAS has proposed, not settled obligations. The corpus assesses the P017 and P004 consultation texts. Their consultation periods have closed; users should verify subsequent publications and finalisation status with MAS.
MAS · November 2025 proposal; consultation closed 31 January 2026
MAS · March 2026 proposal; consultation closed 20 April 2026
METHODOLOGYRecommended practice — "recommends" / "suggests"67 criteria
Industry and public-sector frameworks recommend implementation approaches. Sources include FEAT, Veritas, MindForge, the IMDA agentic AI framework and PDPC advisory guidance. Inclusion in this class does not convert a recommendation into a binding obligation or change the status of underlying law.
MAS / Industry · January 2026
MAS · 2018 corpus edition
PDPC · March 2024
MAS / Industry · Edition not specified in the register
The link opens the initiative page; edition-level mapping remains to be confirmed.
IMDA · January 2026 corpus edition (v1.0)
January launch page. The publisher has since issued a revised framework.
ASSURANCEVoluntary standard — "shall" (within standard scope)19 criteria
ISO/IEC 42001 provides an AI management system standard. Its requirements apply within the scope of adopting or seeking certification to that standard. Inclusion here does not establish certification, independent verification or a MAS requirement to adopt the standard.
ISO / IEC · Edition 1, December 2023
Publisher overview; the full standard requires licensed access.
Counts sum to 193 across the source classes. Each criterion is counted once under its primary source; some also cite supporting instruments. Edition labels describe the selected research corpus. Publisher links may open an initiative page or directory. Check the publishers for later revisions; the corpus is not an exhaustive or continuously updated regulatory inventory.
03 — Coverage
The seven domains
Every criterion is assigned to one of 7 thematic domains. Results report the fully implemented percentage and findings within each domain. The overall maturity label uses all applicable answered criteria; domain percentages are not averaged to produce it.
D1 · Model Governance & Validation
115Full AI model lifecycle — identification, risk classification, development, validation, deployment, monitoring, change, and decommissioning. Governance structure and committee oversight, validation independence, third-party model controls, and generative-AI safeguards. Drawn primarily from P017, the MAS AI MRM Information Paper, MindForge, and ISO/IEC 42001.
D2 · Data Governance & Privacy
15Personal data in AI systems — consent and notification, data protection impact assessments, privacy-by-design, anonymisation, training-data bias, and third-party data processing. Selected PDPC advisory guidance is combined with proposed AI-specific governance in P017 and implementation methods from MindForge.
D3 · Client-Facing AI & Suitability
14AI systems that interact with clients or influence client outcomes — robo-advisory, recommendation engines, chatbots, and automated suitability. Algorithm governance, fair dealing, customer transparency, and redress mechanisms. CMG-G02 Digital Advisory Guidelines and Fair Dealing Guidelines, supplemented by P017’s client-facing provisions.
D4 · Explainability & Fairness
11Responsible-AI principles — fairness definitions and metrics, protected-attribute handling, bias detection and mitigation, explainability proportionate to the use case, and agentic-AI governance. FEAT Principles operationalised through Veritas, with the IMDA Agentic AI Framework extending coverage to autonomous systems.
D5 · Outsourcing & Third-Party AI
12AI from external providers — cloud AI platforms, vendor model APIs, and outsourced AI development. Governance framework, due diligence, outsourcing agreements, concentration risk, and lifecycle management. The selected Outsourcing Guidelines for Banks plus proposed third-party provisions in the P017 and P004 consultation texts.
D6 · Operational Resilience & Cybersecurity
12Technology and security infrastructure for AI — IT governance and change management, access control, audit logging, incident response, and AI-specific cybersecurity threats (adversarial attacks, data poisoning, model extraction). Selected TRM supervisory expectations are supplemented by proposed AI-specific operational resilience provisions in P017.
D7 · Governance Structure & Accountability
14Institutional governance architecture for AI — management system, risk appetite and tolerance, AI risk culture, operating model, and skills and capability across board, senior management, and operational layers. ISO/IEC 42001 provides a management-system structure, with P017 supplying proposed governance provisions that intersect other domains.
Domain 1 carries 60% of the register, reflecting the depth of P017 and the MAS AI MRM Information Paper around the model lifecycle. The remaining 40% is distributed across the other 6 domains. Because each applicable answered criterion has equal weight, domains with more criteria contribute more to the overall percentage. This distribution reflects the selected corpus, not an independently established ranking of institutional risks.
04 — Logic
Response model & scoring
Select the response that best matches the evidence available to you. The diagnostic does not inspect that evidence or independently verify your answers. Not applicable is available only where the criterion offers option D.
If none of the available answers accurately describes your institution, leave the criterion unanswered. You can review partial results in the browser; a PDF requires an answer to every criterion in the selected scope.
Implementation percentage and severity
The implementation percentage is A ÷ (A + B + C) × 100, rounded to one decimal place for display. A counts in the numerator and denominator; B and C count in the denominator, with no partial credit for B. D and unanswered criteria are excluded. Domain percentages use the same calculation. Every applicable answered criterion has equal weight; neither source class nor severity weights the percentage.
HIGH, MEDIUM and LOW are authored severity classifications for the findings. Severity determines their presentation order and the HIGH-gap overrides described below. Only C answers count as gaps for those overrides; partial answers remain separate findings. These are research conventions, not regulator-issued severity scores.
05 — Output
Maturity rating
Zero applicable answers produce “Insufficient Data”. Otherwise, any STATUTORY HIGH-severity C answer, or three or more HIGH-severity C answers across any source class, produces “Critical Gaps”. If neither override applies, the unrounded overall percentage determines the band below. These labels and thresholds are research conventions; they are not regulatory grades or validated benchmarks of institutional performance.
The statutory override remains part of the scoring framework, although the current register contains no statutory criteria. Fewer than half of the register’s criteria answered A, B or C adds a coverage warning; it does not otherwise change the label. The short diagnostic will therefore normally carry that warning. Rule-based consistency checks flag specified answer combinations for review without changing answers. Scoring, labels and gap identification are deterministic; AI does not calculate them.
06 — Caveats
Limitations
The assessment provides an indicative view of AI governance readiness. The following limitations should be considered when interpreting results.