Security & Assurance/MAS AI Risk Readiness
Preparation for the MAS Guidelines on AI Risk Management, still in draft: the inventory, the materiality tiering and the evidence a financial institution needs to show a supervisor how it governs the AI already in use.
MAS consulted on Guidelines on AI Risk Management from 13 November 2025 to 31 January 2026 and has said they will be finalised soon, with a proposed twelve-month transition once they are. They will apply to every financial institution, proportionately, and they name generative models and autonomous agents directly. Most institutions already run AI they have never had to evidence, and few people anywhere have prepared one for a supervisory review of it.
The draft requires each AI use scored by impact, complexity and reliance, inherent and residual, with a control function as final arbiter. An institution that cannot tier its own AI cannot answer any later question about it.
The guidelines are unissued; the industry AI risk management toolkit published with MAS is not — an executive handbook from November 2025, an operationalisation handbook with worked examples from March 2026. A supervisor will expect an institution to have read it.
A supervisor asks what the model was told and what it answered on a given day. Rebuilding one real historic decision, with its data lineage, is the direct test of that question.
A written approval process with nothing recorded under it is the gap a policy review never finds. Real cases from each tier are checked against the policy that claims to govern them.
The draft’s own applicability test asks whether losing the AI would disrupt workflows the institution materially depends on. An institution on the assistive side of that line is told so, and receives a basic policy set rather than a full programme.
Agile Labs does not attest to a regulator and signs nothing filed with one. The institution receives the evidence — inventory, methodology, gap register, board paper — and files it under its own name.
The draft’s annex asks two questions — would losing the AI disrupt workflows the institution materially depends on, and is it built into systems that are. Each business line lands on one side of that line before the engagement is scoped.
Each use captured with a named owner and the attributes the draft requires, plus a sweep for unapproved usage — expense data, sign-on logs, browser extensions — because the AI nobody registered is the core inventory risk.
Impact, complexity and reliance, inherent and residual, compared against risk appetite, with the methodology written for a control function to adopt and the board to minute.
Cases from each tier checked against the policy that governs them, then one historic AI-influenced decision rebuilt end to end — what the model was told, what it answered, on what data.
Every gap keyed to the paragraph it fails, with an owner, a date and a cost; a board paper a non-technical director can follow; remediation sequenced backward from issuance plus twelve months.