| MAS Guidelines on AI Risk Management (draft) | Consulted on 13 Nov 2025 – 31 Jan 2026; final expected 2026; proposed 12-month transition. All FIs; generative AI and autonomous agents in scope. Not yet in force. Source: MAS, Consultation Paper on Guidelines on Artificial Intelligence Risk Management, 13 November 2025. Consultation closed 31 January 2026; guidelines expected in 2026, with a proposed 12-month transition period. Consulted on — not yet in force. | Evidence packs map to the draft's expectations so you start the transition ready; the enforcement layer governs the agents the draft names. |
|---|
| MAS Information Paper on AI Model Risk Management | Published 5 Dec 2024 after a mid-2024 thematic review of banks; spans governance and oversight, risk management systems, and AI development/deployment; generally applicable to other FIs. Source: MAS, Information Paper on AI Model Risk Management, 5 December 2024. | Evidence structure mirrors the paper's three areas — oversight, risk systems, lifecycle — so supervisory questions land on prepared ground. |
|---|
| PDPC Advisory Guidelines on Personal Data in AI Systems | Issued 1 March 2024. Not legally binding, but PDPC will take enforcement positions consistent with them. Source: PDPC, Advisory Guidelines on Use of Personal Data in AI Recommendation and Decision Systems, 1 March 2024. | Discovery and tiering identify where personal data meets AI recommendation and decision systems; evidence shows the controls around it. |
|---|
| Singapore PDPA — penalty ceiling | In force since 1 Oct 2022: higher of S$1 million or 10% of annual turnover in Singapore. Source: Personal Data Protection Act 2012 (as amended), financial penalty provisions in force since 1 October 2022. Source: IBM Security, Cost of a Data Breach Report 2025 (July 2025). | The local ceiling is why discovery comes first: 1 in 5 breached organisations were compromised through shadow AI. |
|---|
| EU AI Act — Article 99 | Maximum fines: €7.5M or 1% (incorrect information to regulators); €15M or 3% (provider and deployer obligations); €35M or 7% (prohibited practices) — whichever is higher. Source: Regulation (EU) 2024/1689 (EU AI Act), Article 99. | For European exposure, framework mapping covers AI Act obligations; the evidence model supports regulator-facing transparency. |