Security & Assurance/MAS AI Risk Readiness

The guidelines are coming. The AI is already running.

Preparation for the MAS Guidelines on AI Risk Management, still in draft: the inventory, the materiality tiering and the evidence a financial institution needs to show a supervisor how it governs the AI already in use.

Every institution that waits will buy the same twelve months at once

MAS consulted on Guidelines on AI Risk Management from 13 November 2025 to 31 January 2026 and has said they will be finalised soon, with a proposed twelve-month transition once they are. They will apply to every financial institution, proportionately, and they name generative models and autonomous agents directly. Most institutions already run AI they have never had to evidence, and few people anywhere have prepared one for a supervisory review of it.

13 Nov to 31 JanThe consultation window. The guidelines are drafted, answered and awaiting final text.MAS consultation, 2025 to 2026
12 monthsThe proposed transition once the guidelines are issued.MAS consultation paper, Nov 2025
Dec 2024MAS published what a thematic review of banks’ AI model risk management found — the clearest signal of what inspection looks like.MAS information paper

What a supervisor will actually ask for

Materiality tiering is the spine

The draft requires each AI use scored by impact, complexity and reliance, inherent and residual, with a control function as final arbiter. An institution that cannot tier its own AI cannot answer any later question about it.

The reading list already exists

The guidelines are unissued; the industry AI risk management toolkit published with MAS is not — an executive handbook from November 2025, an operationalisation handbook with worked examples from March 2026. A supervisor will expect an institution to have read it.

One reconstructed decision outweighs a shelf of policy

A supervisor asks what the model was told and what it answered on a given day. Rebuilding one real historic decision, with its data lineage, is the direct test of that question.

Approvals get sampled, not admired

A written approval process with nothing recorded under it is the gap a policy review never finds. Real cases from each tier are checked against the policy that claims to govern them.

Assistive use may owe far less than feared

The draft’s own applicability test asks whether losing the AI would disrupt workflows the institution materially depends on. An institution on the assistive side of that line is told so, and receives a basic policy set rather than a full programme.

Readiness, not attestation

Agile Labs does not attest to a regulator and signs nothing filed with one. The institution receives the evidence — inventory, methodology, gap register, board paper — and files it under its own name.

The engagement, in order

SCOPE

The applicability test first

The draft’s annex asks two questions — would losing the AI disrupt workflows the institution materially depends on, and is it built into systems that are. Each business line lands on one side of that line before the engagement is scoped.

INVENTORY

Record every AI in use

Each use captured with a named owner and the attributes the draft requires, plus a sweep for unapproved usage — expense data, sign-on logs, browser extensions — because the AI nobody registered is the core inventory risk.

TIER

Score and arbitrate materiality

Impact, complexity and reliance, inherent and residual, compared against risk appetite, with the methodology written for a control function to adopt and the board to minute.

TEST

Sample the controls, reconstruct a decision

Cases from each tier checked against the policy that governs them, then one historic AI-influenced decision rebuilt end to end — what the model was told, what it answered, on what data.

BRIEF

Register, board pack, sequence

Every gap keyed to the paragraph it fails, with an owner, a date and a cost; a board paper a non-technical director can follow; remediation sequenced backward from issuance plus twelve months.

When organisations call us

Call us when

A bank, insurer, asset manager or payments firm running AI it has never had to evidence to a supervisor.Risk or compliance owns the question, and nobody inside has prepared an institution for this before.The board wants to know before issuance what the transition year will take.The honest answer might be “not much” — and that answer is worth having in writing.

Not us when

An institution whose model-risk function has already mapped the draft — it needs hands for remediation, not a second assessment.Anyone expecting a certificate — the guidelines are unissued, and nothing can be certified against them yet.

Find the security gaps that matter.

Know where your AI controls fall short