Singapore Marina Bay financial district at dusk
Regulation

MAS AI Governance Guidelines: A Practical Guide

How the Monetary Authority of Singapore expects financial institutions to govern artificial intelligence. The FEAT principles, the Veritas methodology, the newer model risk guidance, and the data controls that let a firm evidence all of it on every AI interaction.

DataReadyAI Published 30 August 2026 13 min read

01Why MAS sets the pace, at home and abroad

The MAS AI governance guidelines are the body of expectations the Monetary Authority of Singapore sets for how financial institutions use artificial intelligence and data analytics responsibly. At their centre sit four principles, Fairness, Ethics, Accountability and Transparency, known together as FEAT, supported by the Veritas assessment methodologies and, more recently, by MAS guidance on managing the risks of AI models.

The through line is consistent. An institution should be able to show, for any AI-assisted decision, that the data behind it was appropriate, the outcome was fair, a person remained accountable, and the whole chain can be explained.

MAS is Singapore’s central bank and integrated financial regulator, supervising banks, insurers and capital markets participants under one roof. That single mandate matters here, because it lets MAS speak to AI across the whole financial system rather than one sector at a time. Singapore itself has spent two decades building one of the most trusted financial centres in the world, and that reputation rests on regulatory clarity, legal and political stability, and a regulator widely regarded as both demanding and pragmatic.

The reason this reaches far beyond Singapore is timing and diffusion. MAS was among the first financial regulators anywhere to publish sector-specific AI principles, issuing FEAT in 2018, well before comparable frameworks appeared elsewhere. Regulatory expectations tend to travel across borders, especially when they originate from a leading hub, so a global bank running a model in its Singapore branch inherits FEAT directly, and many groups then adopt it as a convenient baseline across every market they operate in. Studying the MAS approach is therefore useful even for an institution that never files a return in Singapore.

The guidance has also broadened over time. It began with the FEAT principles in 2018, was made operational through the Veritas initiative and its open-source toolkit, and was extended by a December 2024 MAS information paper on AI model risk management drawn from a thematic review of banks. MAS has since consulted on proposed guidelines on AI risk management that reach across traditional AI, generative AI and AI agents. The direction of travel is clear: from a set of voluntary principles toward a more detailed and more supervised expectation.

02The FEAT principles explained

FEAT is the foundation everything else builds on. The 2018 document, titled Principles to Promote Fairness, Ethics, Accountability and Transparency in the Use of Artificial Intelligence and Data Analytics in Singapore’s Financial Sector, is deliberately a set of principles rather than a rulebook of clauses. It gives firms a common vocabulary and asks them to contextualise each principle to their own models, decisions and structures, particularly where AI and data analytics drive decisions that affect customers.

Fairness

AI-driven decisions should not systematically disadvantage individuals or groups without a justified basis. Institutions are expected to define what fairness means for a given use case, and to review data and models for unintended bias across the lifecycle rather than once at launch. In practice this rests entirely on knowing what data trained and fed the model, which is why fairness is as much a data question as a modelling one.

Ethics

The use of AI and data analytics should align with the institution’s own ethical standards and with broader societal expectations. The principle keeps consequential decisions under meaningful human oversight rather than fully delegated to a model, so that a person can question, override and take responsibility for outcomes that materially affect people.

Accountability

Responsibility for AI-driven outcomes must be assigned clearly inside the institution, reaching up to board and senior management, and supported by proper model risk management and audit trails. The test is simple: for any given decision, someone is answerable for it, both internally and to the customer affected. Accountability that cannot be traced to a named owner and a defensible record is accountability in name only.

Transparency

Institutions are expected to keep adequate internal documentation of how their AI systems work, and, where a decision materially affects a customer, to be able to provide a meaningful explanation of it. Transparency does not mean publishing model weights. It means the organisation can describe, in terms a person can act on, why a particular outcome occurred and on what information.

03Veritas: turning FEAT into assessment

Principles are hard to act on without a method, so MAS convened Veritas, an industry-led consortium that grew to include many financial institutions and technology firms, to translate FEAT into concrete assessment methodologies and an open-source toolkit. The work arrived in stages: Veritas Toolkit version 1.0, released in 2022, focused on a fairness assessment methodology, and version 2.0, released in 2023, improved the fairness methodology and added assessment methodologies for ethics, accountability and transparency. It is described as the first responsible-AI toolkit built specifically for the financial industry.

At a high level, a Veritas-style assessment defines the AI system and its decision context, identifies who could be affected and on which attributes, tests outcomes for unjustified disparity, documents the ethical justification and the human controls in place, and produces an assessment record that a reviewer can follow. The consortium published worked use cases across banking, insurance and payments to show the methodology applied to real systems rather than in the abstract.

The important point for practitioners is what the toolkit implies about compliance. FEAT is not met by a policy statement. It is met by producing evidence, per model, that each of the four principles was considered and can be defended. That evidence has to be reconstructed from the data and the decisions underneath the model, which is why an institution’s ability to assess against FEAT is only ever as good as the governance of the data feeding it.

04Beyond FEAT: AI model risk management

In December 2024 MAS published an information paper on AI model risk management, drawn from a thematic review of how banks, including their use of generative AI, manage AI models in practice. It sets out observed good practices rather than binding rules, and it is organised around three themes that map neatly onto FEAT and extend it into day-to-day risk management.

  • Governance and oversight. Cross-functional oversight forums, and clear internal statements that govern the fair, ethical, accountable and transparent use of AI, so that FEAT is owned by an identifiable body rather than left to individual teams.
  • Risk management systems and processes. Structured risk identification, a maintained inventory of AI models, and materiality assessments so that scrutiny is proportionate to the risk a model carries.
  • Development and deployment. Pre-deployment validation and checks, monitoring of models in production to confirm they behave as intended, and change management applied when models or their inputs move.

MAS has signalled that this is a staging post rather than the destination, consulting on proposed guidelines on AI risk management that span traditional AI, generative AI and increasingly autonomous AI agents. The consistent message across FEAT, the information paper and the proposed guidelines is that a maintained AI inventory, materiality-based controls, ongoing monitoring and defensible evidence are becoming the baseline of what a supervisor expects to see. All of it depends on the data foundations beneath the models.

05From FEAT to concrete data requirements

The most useful move a financial institution can make is to stop reading FEAT as an abstract set of values and start reading it as a set of data requirements. Each principle, followed to its practical conclusion, lands on a specific capability that lives at the data layer, not the model layer.

FEAT principle What it asks of an institution The data capability it depends on
Fairness Outcomes free of unjustified bias, reviewed across the lifecycle. Representative, quality-checked data and the ability to see exactly what fed each model.
Ethics Consequential decisions kept under meaningful human oversight. Controls that keep a person in the loop and record where and why they intervened.
Accountability A named owner answerable for every AI-driven outcome. Least-privilege access tied to identity, so who used which data is never in doubt.
Transparency A meaningful explanation of any material decision. End-to-end lineage from source to output, and an audit trail that reconstructs a decision.

Read as a set, those rows describe five data capabilities every institution has to stand up. Data readiness and quality comes first, because a fairness claim or a model result is only as sound as the data behind it, and unstructured records such as contracts, claims files and case notes have to be in scope, not just tidy database tables. Lineage and provenance must run in both directions, tracing upstream to where data came from and downstream into every output and action it shaped, so a wrong source or a queried decision can be followed all the way through.

Least-privilege access control ensures each model, copilot and agent can reach only the data a given use case genuinely needs, enforced consistently rather than granted unevenly system by system. Audit and explainability means an immutable record of what data a system consumed, under whose authority, and how an output was produced, available before anyone asks for it. And human oversight has to be a control the platform can enforce, requiring a person in the loop for material decisions and recording the intervention, not a line in a policy nobody can prove was followed.

06A practical operating model

Meeting these expectations is an organisational exercise as much as a technical one. The operating model that works starts with visibility and assigns accountability along lines the institution already trusts.

Inventory before anything else. An institution cannot govern models it has not catalogued, so the first deliverable is a live inventory of AI systems with a materiality rating for each. Materiality is what makes the rest proportionate: a model that prices credit or adjudicates a claim earns far more scrutiny than one that drafts internal summaries, and the inventory is where that judgement is recorded.

Assign accountability explicitly. The board and senior management own the institution’s risk tolerance for AI. A cross-functional oversight forum, drawing in risk, data, technology, compliance and the business, approves material use cases and reviews the evidence they produce. Each model has a named owner, second-line risk challenges the controls, and internal audit provides assurance. Where these accountabilities blur, every AI approval becomes a negotiation. Where they are explicit, approval becomes a checklist.

Build FEAT into the model lifecycle, not the launch. Fairness testing, documentation and human-in-the-loop conditions belong at the design, validation and deployment gates, applied as the model moves rather than assembled as a paper exercise at the end. Running Veritas-style assessments on material models turns FEAT from a statement of intent into a repeatable check with an output a reviewer can read.

Govern the data, not just the model. Because every FEAT principle resolves to a data question, the durable control sits at the data layer. One governed, consistent semantic layer, with access, lineage and audit applied the same way on every interaction, means each new model inherits the same controls instead of re-implementing them. That is also what keeps evidence current, because normal operation writes the record continuously and a supervisory query is answered from material that already exists.

07Evidencing FEAT on every interaction

This is where a governed control plane earns its place. Rather than a new data platform, it is a governed layer that sits above the data platform an institution already runs, working with the cloud and model providers of its choice. It presents a single, consistent semantic layer over the systems of record, and applies access control, lineage and audit on every interaction. That architecture maps directly onto the four FEAT principles.

Because the semantic layer resolves what each attribute means and where it came from, fairness testing works from the same governed definitions every time, rather than from a fresh extract per project. Access is governed with least-privilege controls over the underlying data sets and inherited from the institution’s existing identity system, so every request is attributable and accountability has a real record behind it. Lineage in both directions and an immutable audit trail let the organisation reconstruct any AI-assisted decision from source to output, which is exactly what transparency and explainability require. And policy can require a person in the loop for material actions and record that intervention, giving the ethics principle and human oversight an enforced form rather than a documented aspiration.

In practice · DataReadyAI

DataReadyAI is a governed layer above the data platform you already run, deploying on your own Databricks, Snowflake or BigQuery so regulated data never leaves your environment. It presents a unified, consistent semantic layer and enforces access control, lineage and audit on every AI interaction, with access governed by least-privilege controls over the underlying data sets. That is the machinery a financial institution needs to evidence FEAT on every request, and it reaches production-grade AI in weeks rather than years. DataReadyAI is working with organisations across financial services to put this foundation in place.

None of this is unique to Singapore. The same controls that evidence FEAT are the ones that answer supervisors elsewhere, which is why the data foundation matters more than any single regime. For the underlying discipline, see Data Governance for AI, and for how these questions play out in one sector, Enterprise AI in Insurance.

08Frequently asked questions

What are the MAS AI governance guidelines?

They are the body of expectations the Monetary Authority of Singapore sets for the responsible use of artificial intelligence and data analytics by financial institutions. At the centre sit four principles, Fairness, Ethics, Accountability and Transparency, known together as FEAT and published in 2018. These are supported by the Veritas assessment methodologies and open-source toolkit, and by a 2024 MAS information paper on AI model risk management drawn from a thematic review of banks. MAS has since consulted on broader guidelines on AI risk management covering traditional AI, generative AI and AI agents.

Who do the FEAT principles apply to?

MAS expects all the financial institutions it regulates to apply FEAT, including banks, insurers and capital markets intermediaries, and this extends to foreign institutions operating in Singapore through branches or subsidiaries under MAS supervision. Because Singapore is a major financial centre and regulatory expectations tend to travel, many global groups adopt FEAT as a baseline well beyond Singapore, so the guidelines shape practice for institutions that never file a return with MAS.

Are the MAS AI governance guidelines legally binding?

FEAT and the 2024 information paper are principles and good practices rather than black-letter rules, but MAS supervises institutions against them and expects to see them operationalised. The direction of travel is toward more formal supervisory guidance, which is why a financial institution should treat FEAT as a live expectation to evidence, not an optional aspiration. Waiting for a hard rule is the wrong posture when the supervisor is already asking how the principles are applied.

What is the Veritas Toolkit and do we have to use it?

Veritas is an MAS-led, industry-developed initiative that translates the FEAT principles into concrete assessment methodologies, packaged as an open-source toolkit. Version 1.0, released in 2022, covered fairness, and version 2.0, released in 2023, added ethics, accountability and transparency. Use of the toolkit itself is not compulsory, but it is a practical, recognised way to produce the per-model evidence that FEAT calls for, and its structure is a useful template even for institutions that build their own assessment process.

How do the MAS guidelines translate into data requirements?

Every FEAT principle resolves, in practice, to a data question. Fairness depends on representative, quality-checked data and the ability to see exactly what fed a model. Accountability depends on least-privilege access tied to identity, so who used which data is never in doubt. Transparency depends on lineage in both directions and an audit trail that can reconstruct any decision. Ethics and human oversight depend on controls that keep a person in the loop and record where they intervened. Meeting the guidelines therefore rests on governed data, not just governed models.

09Sources and further reading

Evidence FEAT on your own estate.

A technical briefing runs the FEAT-to-data mapping in this guide against your own systems: the estate scanned, least-privilege access enforced, and the lineage and audit trail that a supervisor expects to see.

Continue reading