Regulation

MAS AI risk management guidelines and AI use cases

Singapore's supervisory expectations for AI risk management at financial institutions, building on the FEAT principles.

Read the source text (Monetary Authority of Singapore)

High risk under the EU AI Act

Listed in Annex III or a safety component: risk management, data governance, logging, human oversight and conformity assessment are required.

  • AI credit scoring with alternative data for thin file applicants

    Annex III point 5(b): AI systems intended to evaluate the creditworthiness of natural persons or establish their credit score are high risk, except systems used to detect financial fraud. Providers need risk management, data governance, logging and human oversight. Deployers must carry out a fundamental rights impact assessment before use (Article 27), and affected persons have a right to an explanation of individual decisions from the deployer (Article 86).

Depends on design under the EU AI Act

The tier depends on how the system is used, for example whether it decides on access to an essential service.

  • AI agent for source of wealth due diligence in private banking

    Anti money laundering due diligence is not listed in Annex III, so an assistant that drafts source of wealth reports for a human decision is not high risk by default. It becomes high risk if it adds remote biometric identification of the client (Annex III point 1(a); verification that only confirms a claimed identity is excluded) or feeds an assessment of a natural person's creditworthiness, for example for lending to the client (Annex III point 5(b)). GDPR Article 22 on solely automated decisions applies if it ever refused a client on its own.

  • AI assistant for goal based financial planning

    Planning support for advisors is not listed in Annex III. A client facing version must disclose that the client is talking to AI (Article 50). It becomes high risk if it is used to assess the creditworthiness of individuals (Annex III point 5(b)) or for risk assessment and pricing of life or health insurance for individuals (Annex III point 5(c)).

  • AI assistant for investment suitability assessment and reports

    Investment suitability assessment is not listed in Annex III, so the tier depends on design. It becomes high risk where the same system assesses creditworthiness, for example for lending against a portfolio (Annex III point 5(b)). MiFID II suitability duties apply regardless of the AI Act tier.

  • AI cash flow underwriting for small business loans

    Annex III point 5(b) makes AI systems that evaluate the creditworthiness of natural persons or establish their credit score high risk. Scoring a company is outside that point, but a sole trader is a natural person, and a model that also assesses the personal credit of owners, partners or guarantors evaluates natural persons. The tier therefore depends on who the borrower is and whose creditworthiness the model assesses.

  • AI early warning and covenant monitoring for loan portfolios

    Monitoring the credit of companies is not listed in Annex III. Where the same system evaluates the creditworthiness of natural persons, such as sole traders or personal guarantors, it falls under Annex III point 5(b) and is high risk; because that evaluation profiles natural persons, the Article 6(3) exemption does not apply.

  • AI financial wellbeing coach in the banking app

    The conversational assistant carries the Article 50 transparency duty: customers must be told they are interacting with an AI system. The system becomes high risk if it is used to evaluate the creditworthiness of natural persons or establish their credit score (Annex III point 5(b)). Article 5(1)(b) prohibits AI that exploits vulnerabilities due to a person's specific social or economic situation to materially distort their behaviour in a way that causes, or is reasonably likely to cause, significant harm.

  • AI for business onboarding (KYB) and beneficial ownership discovery

    Customer due diligence on legal entities is not listed in Annex III, and an internal analyst tool usually carries no Article 50 transparency duty, so the system is usually minimal risk. The design decides the rest: biometric verification that only confirms a director is who they claim to be is excluded from Annex III point 1(a), but remote biometric identification (one to many matching) is high risk, and so is any use of the output to assess the creditworthiness of the natural persons involved (point 5(b)). GDPR applies to the personal data of owners and directors throughout. Keep biometric and credit steps in separately assessed components.

  • AI for market abuse surveillance alert triage

    Surveillance of orders and transactions as such is not listed in Annex III. Where the system monitors and evaluates the behaviour of the firm's own staff, in their communications or their trading, it can fall under Annex III point 4(b) (AI used to monitor and evaluate the performance and behaviour of persons in work relationships), so the tier depends on whether the system scores individual employees. Inferring employees' emotions from biometric data such as voice recordings is prohibited in the workplace under Article 5(1)(f).

  • AI for perpetual KYC and event driven customer due diligence

    Keeping customer due diligence files current is not listed in Annex III, so a back office system that assembles reviews for an analyst to decide is usually minimal risk. The design decides the rest: a conversational agent that asks customers for missing information must tell them they are interacting with an AI system (Article 50(1)); biometric verification that only confirms a person is who they claim to be is excluded from Annex III point 1(a), while remote biometric identification is high risk; and Article 5(1)(d) prohibits assessing the risk that a person will commit a criminal offence based solely on profiling, so behavioural triggers should open a review for a human rather than score the customer. GDPR applies to the collection and retention of KYC data, including Article 22 if an automated refresh leads to a decision with legal or similarly significant effect, such as closing an account.

  • AI generated client portfolio reports and commentary

    Drafting client reports for human review is not listed in Annex III and is not a practice prohibited by Article 5, so the tier turns on the firm's role under Article 50. A firm that deploys a third party generator (for example a feature of its portfolio platform) for private client reports has no Article 50 duty: the Article 50(4) disclosure duty covers AI generated text published to inform the public on matters of public interest, which private client reports are not, and it lapses anyway after human review under editorial responsibility. For that firm the tier is minimal. A firm that builds the generating system or places it on the market under its own name is a provider under Article 50(2) and must mark the synthetic text in a machine readable format; drafting whole commentaries goes beyond the exemption for an assistive function for standard editing, so for that firm the tier is limited.

  • AI next best action prompts for wealth advisors

    Ranking investment and service prompts for an advisor is not listed in Annex III. It becomes high risk if the system evaluates the creditworthiness of natural persons, for example to decide which clients are offered lending (Annex III point 5(b)), so keep credit decisions out of the prompt engine. It is also high risk if the system itself is used to monitor or evaluate advisors' performance and behaviour, for example by scoring or ranking advisors on how they act on prompts (Annex III point 4(b)), so keep adoption reporting separate from performance management.

  • AI portfolio drift monitoring and rebalancing proposals

    Monitoring portfolios and proposing trades for human approval is not listed in Annex III and is not a prohibited practice under Article 5, so the tier turns on the firm's role under Article 50. A firm that builds or brands the rationale writer in house is a provider under Article 50(2) and must mark the generated text in a machine readable format: drafting a rationale for the drift and the proposed trades goes beyond the exemption for an assistive function for standard editing, so for that firm the tier is limited. Article 50(1) also applies once the rationale reaches the client, as this page's own implementation step allows. A firm that only deploys a third party feature for internal approver use has no Article 50 duty, and for that firm the tier is minimal. Investment conduct rules such as MiFID II suitability and best execution still apply to the resulting trades.

  • AI summaries of investment research and the house view

    Summarizing research for staff is not an Annex III use and is not a practice prohibited by Article 5, so the tier turns on the firm's role under Article 50. It is minimal for a purchased internal tool with no client or public facing exposure. Article 50 transparency applies when the firm builds the generating system itself, which brings the Article 50(2) duty to mark synthetic text in a machine readable format; when the assistant is offered to clients as a chatbot, which brings the Article 50(1) duty to tell them they are interacting with AI; or when AI generated text is published to inform the public on matters of public interest, which brings the Article 50(4) disclosure duty unless the text has gone through human review or editorial control and a person holds editorial responsibility for it.

  • AI system and model inventory with shadow AI discovery

    Minimal for a system level register of systems and owners with no monitoring of individual employees; it is not listed in Annex III and is the instrument deployers use to meet obligations such as the Article 26 duties for high risk systems and the Article 49 registration of Annex III systems in the EU database. Limited where the plain language assistant that staff and auditors query is not obviously an AI system to its users: under Article 50(1) its provider must then design it so people are told they are dealing with AI. Possibly high risk under Annex III point 4(b) on worker management if the discovery process monitors or evaluates the behavior of individual employees rather than staying at the level of systems and owners.

  • Dynamic AML customer risk rating with machine learning

    An AML customer risk rating is not listed in Annex III. Article 5(1)(d) prohibits AI risk assessments that predict whether a natural person will commit or will likely commit a criminal offence based solely on profiling of that person or on assessing their personality traits and characteristics; it exempts only AI that supports the human assessment of a person's involvement in a criminal activity, which is already based on objective and verifiable facts directly linked to a criminal activity. An AML customer risk rating built from due diligence attributes, transaction behaviour and screening results is itself an automated evaluation of a person's situation and behaviour, which is profiling under GDPR Article 4(4), and due diligence facts such as occupation, geography and products are not facts directly linked to a criminal activity, so the rating does not sit squarely inside the exemption. What keeps it a defensible AML due diligence tool rather than an offence prediction is that it does not itself accuse a person of an offence: it sets a level of scrutiny, a human analyst reviews material moves, and regulatory minimum rules sit above the model as hard constraints. A rating driven mainly by nationality or other personal attributes weakens that position further, which is why the proxy discrimination guardrail matters. If the same score is used to evaluate the creditworthiness of natural persons or to establish their credit score, that use falls under Annex III point 5(b) and is high risk, so keep the AML rating and credit decisions separate.

  • Real time AI assist for contact centre agents

    As a pure assist tool for agents it is minimal risk; the customer does not interact with the AI. It becomes high risk under Annex III point 4(b) if its data is used to monitor and evaluate individual agents' performance, and inferring agents' emotions at work is prohibited under Article 5(1)(f).

Limited risk (transparency) under the EU AI Act

People must be told they are dealing with AI, and generated content must be identifiable (Article 50).

  • AI assistant for corporate and commercial client servicing

    A chatbot that interacts with people at client companies must disclose that it is AI (Article 50). It does not evaluate creditworthiness or decide on access to an essential service (Annex III point 5), so it is not high risk.

  • AI cash flow forecasting for corporate treasury

    Forecasting a company's cash flows is not listed in Annex III and makes no decision about a natural person, so the forecasting model itself carries no obligations beyond AI literacy (Article 4). The conversational layer interacts directly with treasury staff, so under Article 50(1) they must be informed that they are dealing with an AI system unless that is obvious from the context. Without a conversational layer the use case is minimal risk.

  • AI enterprise knowledge search for employees

    Article 50(1) requires that people who interact directly with an AI system are informed of it, unless this is obvious from the context, as it usually is for an internal assistant. The system would be high risk only if it were intended for an Annex III purpose, such as assessing the creditworthiness of natural persons (point 5(b)) or making decisions on or evaluating workers (point 4(b)).

  • AI knowledge assistant for wealth advisors and relationship managers

    Article 50(1) requires that people who interact directly with an AI system are informed of it, unless this is obvious from the context, as it usually is for an internal assistant labelled as AI; Article 50(2) requires providers of systems that generate text to mark the output as AI generated in a machine readable way. Helping advisors find information is not an Annex III use and not a prohibited practice under Article 5. It would become high risk only if the system were used to evaluate the creditworthiness of clients (point 5(b)) or to evaluate or make decisions about advisors (point 4(b)). If the assistant were opened to clients, they would have to be told they are dealing with AI.

  • AI orchestration of corporate account opening and channel setup

    Operational setup of accounts and entitlements for corporate clients is not listed in Annex III and makes no decision about a natural person's access to a service or creditworthiness. The agent chases documents directly with client staff, so Article 50(1) applies: the provider must design the system so that they are informed that they are interacting with an AI system, unless that is obvious from the context. A purely internal version without client contact would be minimal risk.

  • AI regulatory horizon scanning and obligation mapping

    An internal tool that monitors and classifies regulatory publications for staff makes no decisions about natural persons, so it is not listed in Annex III and is not a prohibited practice under Article 5. Staff know they are using an AI tool and its summaries are not published to the public, so the Article 50 duties to inform users and to disclose published generated text add little for the deploying organization. Article 50(2) still requires the provider of a system that generates text to mark its output, in a machine readable format, as AI generated: usually the vendor, but an organization that builds its own summariser can itself be that provider, which is what puts this use case at the limited tier rather than minimal. Beyond this and AI literacy (Article 4), no specific obligations apply. General model risk and third party rules still apply.

  • AI scam intervention for instant payments

    Annex III point 5(b) expressly excludes AI systems used to detect financial fraud from the high risk creditworthiness category, so the scoring is not high risk. The conversational part must disclose that it is AI under Article 50(1). If a voice component infers the customer's emotions from their voice, it becomes an emotion recognition system under Annex III point 1(c), which is high risk and needs the Article 50(3) notice, so keep coaching detection to what is said rather than to biometric signals.

Minimal risk under the EU AI Act

No specific obligations under the EU AI Act beyond AI literacy; voluntary codes apply.

  • AI copilot for corporate client briefings and call reports

    Bankers interact with the copilot directly, but Article 50(1) does not bite here: it requires telling people they are dealing with an AI system unless that is obvious to a reasonably well informed person, and an internal tool that is openly presented and labelled as an AI assistant meets that bar by design. The copilot never interacts with the client. Article 50(2) marking of generated text falls on the provider of the system, including a bank that builds it in house, but the copilot turns a banker's own notes into a call report, an assistive function for standard editing of the banker's input that does not substantially alter it, so the Article 50(2) exception applies and no machine readable marking is required. It is not an Annex III use: credit context about corporate clients is not the creditworthiness assessment of natural persons in Annex III point 5(b), so it falls outside the high risk tier. If a deployment starts to score individuals for credit, the tier changes. AI literacy duties under Article 4 still apply. If meeting capture is used, recording and transcription rules under data protection law apply separately.

  • AI copilot for model risk validation and monitoring

    A validation copilot supports internal governance and is not itself an Annex III use, and its drafts are internal, so Article 50 transparency duties do not normally apply. It often helps validate models that are high risk under Annex III (point 5(b), creditworthiness and credit scoring of natural persons; point 5(c), life and health insurance pricing), and the testing and documentation it supports feed the provider obligations of Articles 9, 11 and 15.

  • AI copilot for SAR and STR narrative drafting

    Drafting internal reports for a human investigator is not listed in Annex III (the law enforcement uses in point 6 cover systems used by or for law enforcement authorities, not a bank's own reporting), and the text is not published to inform the public, so the deployer disclosure duty for generated text in Article 50(4) does not apply. Confidentiality rules for suspicious activity reports and GDPR apply in full.

  • AI examination of trade documents under letters of credit and collections

    Checking trade documents for compliance with credit terms is not listed in Annex III and does not decide about natural persons. AI literacy duties under Article 4 apply, and the process falls under the bank's operational resilience and model governance.

  • AI for AML transaction monitoring alert triage

    AML transaction monitoring is not listed in Annex III; point 5(b) covers creditworthiness and credit scoring and excludes systems used to detect financial fraud. The Article 5(1)(d) ban on predicting criminal offences from profiling alone does not apply to systems that support a human assessment already based on objective and verifiable facts linked to criminal activity, which is how alert triage should be designed. A decision to restrict an account taken solely by automated means would fall under GDPR Article 22 and national AML law, so consequential decisions need human review.

  • AI for money mule account and network detection

    Detecting mule accounts is fraud and AML detection by a private firm, which Annex III does not list; point 5(b) explicitly excludes systems used to detect financial fraud from the credit scoring category. Restricting an account based solely on an automated score can be a decision with similarly significant effects under GDPR Article 22, so keep a human decision and a route to challenge.

  • AI for PEP and adverse media screening

    Adverse media and PEP screening for due diligence is not listed in Annex III. It processes personal data, including data about alleged offences, so GDPR Article 10 and national AML law govern what may be collected and how long it is kept.

  • AI for policy drafting and policy gap analysis

    Drafting internal policy text for human approval is not an Annex III use and has no direct effect on individuals. The Article 4 AI literacy measures still apply to the staff who use it.

  • AI for sanctions screening alert adjudication

    Sanctions screening by banks and payment firms is not listed in Annex III: point 5 covers credit scoring and life and health insurance pricing, and point 6 covers AI used by or on behalf of law enforcement authorities. It is not a prohibited practice under Article 5, and as an internal tool it carries no Article 50 transparency duty. It still processes personal data at scale, so GDPR applies, and decisions that block a payment or freeze assets remain human decisions.

  • AI meeting notes and CRM update for wealth advisors

    Transcribing and summarizing meetings for an employee is not a use listed in Annex III, and the advisor reviews every note before it is filed or sent. The tier would change if the tool inferred emotions: emotion recognition is high risk under Annex III point 1(c), and inferring the emotions of employees at work is prohibited under Article 5(1)(f). Both stay out of scope.

  • AI screening of trade finance transactions for trade based money laundering

    Financial crime screening of trade transactions is not listed in Annex III. It still processes personal data of individual parties, so GDPR applies, and supervisors expect it to be governed like any financial crime model.

  • Real time fraud scoring for card and instant payments

    Annex III point 5(b) lists creditworthiness assessment and credit scoring of natural persons as high risk but explicitly excludes AI systems used for the purpose of detecting financial fraud, and payment fraud scoring is not otherwise listed in Annex III or prohibited by Article 5. Behavioural biometrics used only to confirm that customers are who they claim to be fall under the biometric verification exclusion in Annex III point 1(a). The model does not interact with people, so Article 50 does not apply. GDPR Article 22 can still apply to solely automated declines with significant effects on customers.