Compliance

Singapore first. Then everywhere you operate.

A Singapore CISO should meet their own regulator and a date before they meet a foreign fine. The map below is the order we think in — and the order the evidence is built for.

01The regulatory map

Exact positions, exact citations

Regulatory instruments and how AI Pulse maps to each
InstrumentExact statusHow AI Pulse maps
MAS Guidelines on AI Risk Management (draft)Consulted on 13 Nov 2025 – 31 Jan 2026; final expected 2026; proposed 12-month transition. All FIs; generative AI and autonomous agents in scope. Not yet in force.

Source: MAS, Consultation Paper on Guidelines on Artificial Intelligence Risk Management, 13 November 2025. Consultation closed 31 January 2026; guidelines expected in 2026, with a proposed 12-month transition period. Consulted on — not yet in force.

Evidence packs map to the draft's expectations so you start the transition ready; the enforcement layer governs the agents the draft names.
MAS Information Paper on AI Model Risk ManagementPublished 5 Dec 2024 after a mid-2024 thematic review of banks; spans governance and oversight, risk management systems, and AI development/deployment; generally applicable to other FIs.

Source: MAS, Information Paper on AI Model Risk Management, 5 December 2024.

Evidence structure mirrors the paper's three areas — oversight, risk systems, lifecycle — so supervisory questions land on prepared ground.
PDPC Advisory Guidelines on Personal Data in AI SystemsIssued 1 March 2024. Not legally binding, but PDPC will take enforcement positions consistent with them.

Source: PDPC, Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems, 1 March 2024.

Discovery and tiering identify where personal data meets AI recommendation and decision systems; evidence shows the controls around it.
Singapore PDPA — penalty ceilingIn force since 1 Oct 2022: higher of S$1 million or 10% of annual turnover in Singapore.

Source: Personal Data Protection Act 2012 (as amended), financial penalty provisions in force since 1 October 2022. Source: IBM Security, Cost of a Data Breach Report 2025 (July 2025).

The local ceiling is why discovery comes first: 1 in 5 breached organisations were compromised through shadow AI.
EU AI Act — Article 99Maximum fines: €7.5M or 1% (incorrect information to regulators); €15M or 3% (provider and deployer obligations); €35M or 7% (prohibited practices) — whichever is higher.

Source: Regulation (EU) 2024/1689 (EU AI Act), Article 99.

For European exposure, framework mapping covers AI Act obligations; the evidence model supports regulator-facing transparency.
€7.5M1% of turnoverIncorrect informationto regulators€15M3% of turnoverProvider & deployerobligations€35M7% of turnoverProhibited AIpractices WHICHEVER IS HIGHER · ARTICLE 99
Article 99 maximum fines (exact values) Source: Regulation (EU) 2024/1689 (EU AI Act), Article 99.

02Precedent

The chatbot was you

“While a chatbot has an interactive component, it is still just a part of Air Canada's website.”

Moffatt v. Air Canada, 2024 BCCRT 149

Source: Moffatt v. Air Canada, 2024 BCCRT 149 (Civil Resolution Tribunal, British Columbia).

The tribunal rejected the argument that a chatbot is a separate entity for liability purposes. Organisations are bound by what their AI tells customers. Controls — and evidence of them — are the only preparation that counts.

03Frameworks

Map once, report many

Controls map to 45 frameworks across one shared backbone, so a single evidence set answers many different letters. The depth is deliberately ASEAN-first: Singapore, Malaysia, Indonesia, Thailand and Brunei are covered natively, alongside Europe, the United States, Japan and the international standards. Enable only the regimes that apply to you.

Breadth and depth are separate claims here. Every framework is in scope and evaluated; how deeply each is authored varies — some carry fully written guidance today, others are still being authored — and we never present one as more complete than it is.

SINGAPORE · 8

  • PDPA (Act 26 of 2012, as amended)
  • MAS TRM Guidelines
  • MAS Project MindForge
  • IMDA Model AI Governance Framework 2.0
  • IMDA Model AI Governance Framework for Generative AI
  • IMDA Model AI Governance Framework for Agentic AI
  • AI Verify
  • Cybersecurity Act 2018 + CSA Code of Practice

ASEAN REGIONAL · 2

  • ASEAN Guide on AI Governance and Ethics
  • ASEAN Generative AI Governance Addendum

MALAYSIA · 4

  • BNM RMiT
  • PDPA (Act 709, as amended 2024)
  • Cyber Security Act 2024
  • National Guidelines on AI Governance and Ethics

INDONESIA · 3

  • OJK Risk Management in IT
  • BSSN Cybersecurity
  • UU PDP (Law 27/2022)

THAILAND · 4

  • BOT IT Risk Management Notification
  • PDPA (B.E. 2562)
  • Cybersecurity Act B.E. 2562
  • Thailand AI Governance Guideline

BRUNEI · 1

  • Brunei AI Governance and Ethics

AUSTRALIA · 4

  • APRA CPS 234
  • ISM + Essential Eight
  • Privacy Act 1988 + APPs
  • Voluntary AI Safety Standard

EUROPE · 5

  • EU AI Act (Regulation 2024/1689)
  • GDPR (EU 2016/679)
  • DORA (EU 2022/2554)
  • NIS2 Directive (EU 2022/2555)
  • Cyber Resilience Act (EU 2024/2847)

UNITED STATES · 6

  • HIPAA Security Rule + Breach Notification
  • Sarbanes-Oxley (ITGC focus)
  • Gramm-Leach-Bliley Act
  • FedRAMP Moderate
  • CCPA / CPRA
  • PCI DSS v4.0

INTERNATIONAL · 7

  • ISO/IEC 42001:2023
  • ISO/IEC 27001:2022
  • NIST AI RMF 1.0
  • NIST Cybersecurity Framework 2.0
  • NIST SP 800-53 Rev. 5
  • SOC 2 Type II (AICPA TSC)
  • AI in Healthcare Guidelines (AIHGle 2.0)

JAPAN · 1

  • METI AI Guidelines for Business Ver 1.2
AI Pulse audit and assurance view: audit readiness, high-risk systems, controls awaiting evidence and open violations, above a per-framework readiness breakdown showing ready, partial, gap and pending controls for each regime.
Audit readiness by framework One control set, scored separately against each regime. Gaps and unassessed controls stay visible — a framework with nothing collected yet reads zero rather than being rounded up.

Includes the IMDA Model AI Governance Framework for Agentic AI and MAS Project MindForge — the two Singapore instruments written specifically for agentic and financial-sector AI.