Regulation

MAS Notice 626 and AI use cases

Singapore's anti money laundering and counter terrorism financing requirements for banks.

Read the source text (Monetary Authority of Singapore)

Depends on design under the EU AI Act

The tier depends on how the system is used, for example whether it decides on access to an essential service.

  • AI agent for source of wealth due diligence in private banking

    Anti money laundering due diligence is not listed in Annex III, so an assistant that drafts source of wealth reports for a human decision is not high risk by default. It becomes high risk if it adds remote biometric identification of the client (Annex III point 1(a); verification that only confirms a claimed identity is excluded) or feeds an assessment of a natural person's creditworthiness, for example for lending to the client (Annex III point 5(b)). GDPR Article 22 on solely automated decisions applies if it ever refused a client on its own.

  • AI assistant for digital account onboarding and KYC

    The conversational assistant falls under the Article 50 transparency duty. Biometric verification whose sole purpose is to confirm that a person is who they claim to be is excluded from the Annex III biometric category. The system becomes high risk when the same journey assesses creditworthiness or a credit score of a natural person, for example for a credit card or overdraft (Annex III point 5(b)).

  • AI for business onboarding (KYB) and beneficial ownership discovery

    Customer due diligence on legal entities is not listed in Annex III, and an internal analyst tool usually carries no Article 50 transparency duty, so the system is usually minimal risk. The design decides the rest: biometric verification that only confirms a director is who they claim to be is excluded from Annex III point 1(a), but remote biometric identification (one to many matching) is high risk, and so is any use of the output to assess the creditworthiness of the natural persons involved (point 5(b)). GDPR applies to the personal data of owners and directors throughout. Keep biometric and credit steps in separately assessed components.

  • AI for perpetual KYC and event driven customer due diligence

    Keeping customer due diligence files current is not listed in Annex III, so a back office system that assembles reviews for an analyst to decide is usually minimal risk. The design decides the rest: a conversational agent that asks customers for missing information must tell them they are interacting with an AI system (Article 50(1)); biometric verification that only confirms a person is who they claim to be is excluded from Annex III point 1(a), while remote biometric identification is high risk; and Article 5(1)(d) prohibits assessing the risk that a person will commit a criminal offence based solely on profiling, so behavioural triggers should open a review for a human rather than score the customer. GDPR applies to the collection and retention of KYC data, including Article 22 if an automated refresh leads to a decision with legal or similarly significant effect, such as closing an account.

  • Dynamic AML customer risk rating with machine learning

    An AML customer risk rating is not listed in Annex III. Article 5(1)(d) prohibits AI risk assessments that predict whether a natural person will commit or will likely commit a criminal offence based solely on profiling of that person or on assessing their personality traits and characteristics; it exempts only AI that supports the human assessment of a person's involvement in a criminal activity, which is already based on objective and verifiable facts directly linked to a criminal activity. An AML customer risk rating built from due diligence attributes, transaction behaviour and screening results is itself an automated evaluation of a person's situation and behaviour, which is profiling under GDPR Article 4(4), and due diligence facts such as occupation, geography and products are not facts directly linked to a criminal activity, so the rating does not sit squarely inside the exemption. What keeps it a defensible AML due diligence tool rather than an offence prediction is that it does not itself accuse a person of an offence: it sets a level of scrutiny, a human analyst reviews material moves, and regulatory minimum rules sit above the model as hard constraints. A rating driven mainly by nationality or other personal attributes weakens that position further, which is why the proxy discrimination guardrail matters. If the same score is used to evaluate the creditworthiness of natural persons or to establish their credit score, that use falls under Annex III point 5(b) and is high risk, so keep the AML rating and credit decisions separate.

Minimal risk under the EU AI Act

No specific obligations under the EU AI Act beyond AI literacy; voluntary codes apply.

  • AI copilot for SAR and STR narrative drafting

    Drafting internal reports for a human investigator is not listed in Annex III (the law enforcement uses in point 6 cover systems used by or for law enforcement authorities, not a bank's own reporting), and the text is not published to inform the public, so the deployer disclosure duty for generated text in Article 50(4) does not apply. Confidentiality rules for suspicious activity reports and GDPR apply in full.

  • AI for AML transaction monitoring alert triage

    AML transaction monitoring is not listed in Annex III; point 5(b) covers creditworthiness and credit scoring and excludes systems used to detect financial fraud. The Article 5(1)(d) ban on predicting criminal offences from profiling alone does not apply to systems that support a human assessment already based on objective and verifiable facts linked to criminal activity, which is how alert triage should be designed. A decision to restrict an account taken solely by automated means would fall under GDPR Article 22 and national AML law, so consequential decisions need human review.

  • AI for PEP and adverse media screening

    Adverse media and PEP screening for due diligence is not listed in Annex III. It processes personal data, including data about alleged offences, so GDPR Article 10 and national AML law govern what may be collected and how long it is kept.

  • AI for sanctions screening alert adjudication

    Sanctions screening by banks and payment firms is not listed in Annex III: point 5 covers credit scoring and life and health insurance pricing, and point 6 covers AI used by or on behalf of law enforcement authorities. It is not a prohibited practice under Article 5, and as an internal tool it carries no Article 50 transparency duty. It still processes personal data at scale, so GDPR applies, and decisions that block a payment or freeze assets remain human decisions.

  • AI screening of trade finance transactions for trade based money laundering

    Financial crime screening of trade transactions is not listed in Annex III. It still processes personal data of individual parties, so GDPR applies, and supervisors expect it to be governed like any financial crime model.