What We CoverOur ApproachClient StoriesInsightsAboutSchedule a Consultation
All insights

MAS AI Risk Management Guidelines and what they mean for Singapore technology vendors: three insurance coverages now under review

MAS has rolled out AI Risk Management Guidelines for Singapore's financial sector. A 12-month transition period is running. For technology vendors supplying AI systems to banks and insurers, the guidelines change the contract conversations already starting. Three insurance coverages that matter.

The Monetary Authority of Singapore has rolled out its Guidelines on Artificial Intelligence Risk Management for the financial sector. The guidelines, which apply to all financial institutions in Singapore, set out MAS's supervisory expectations across four areas: AI oversight and governance, AI risk management systems, AI lifecycle controls, and the organisational capabilities needed to support responsible AI use.

A 12-month transition period applies. That clock is now running.

For most banks, insurers, and capital markets firms in Singapore, the guidelines are a significant compliance exercise. For the technology vendors, data providers, and third-party AI solution suppliers serving those institutions, the guidelines are something slightly different: they are a signal that the institutions you sell to are about to look much more carefully at the AI risk that sits in their supply chain.

And that scrutiny flows directly to you.

What the MAS guidelines actually require

The guidelines are structured around four areas, according to MAS's published consultation paper and the AI Risk Management Toolkit published in March 2026 following Project MindForge.

First, AI oversight. Boards and senior management of financial institutions are expected to establish governance structures, policies, and processes for AI risk management and to integrate AI risk into existing enterprise risk frameworks. This is not an IT department exercise. It is a board-level accountability question.

Second, AI risk management systems. Institutions must maintain a comprehensive inventory of all AI use cases, assess risk materiality for each, and implement policies and procedures appropriate to the risk profile.

Third, AI lifecycle controls. This covers the full span of an AI system's life: data management, model development, validation, testing, monitoring, and decommissioning. For higher-risk applications, including those involved in credit decisions, risk modelling, and customer-facing advice, MAS expects independent validation, stress testing, and enhanced human oversight.

Fourth, organisational enablers. Institutions must have the skills, infrastructure, and risk culture to support responsible AI use, including adequate training and third-party AI governance arrangements.

That last point is where the insurance question becomes concrete.

The third-party AI governance question

Most Singapore financial institutions do not build their own AI systems from scratch. They buy them, licence them, or integrate them from technology vendors. The MAS guidelines make clear that institutions are expected to govern these third-party AI arrangements with the same rigour they apply to internally developed systems.

In practical terms: if you supply AI-powered tools, data feeds, analytical models, or software systems to a Singapore financial institution, that institution is now under MAS supervisory expectation to assess the risk your product introduces, validate how it behaves, monitor it over time, and be able to account for it to the regulator.

What that means for you as a vendor is that your contractual position with your FI clients is changing. Institutions that previously took your system on trust will increasingly require representations about model governance, explainability, audit trails, data quality, and what happens when the system produces an incorrect output that causes a client a financial loss.

That last question is the insurance question.

Three insurance coverages that matter under the MAS AI framework

Technology errors and omissions.

If an AI system you supplied to a financial institution produces an incorrect output that causes the institution or its clients a financial loss, a professional negligence claim may follow. Standard professional indemnity insurance covers human professional advice. Technology errors and omissions insurance, sometimes called technology PI or technology liability insurance, covers claims arising from the failure of a technology system or product to perform as expected, including AI-driven outputs.

For technology vendors supplying AI systems to MAS-regulated institutions, technology E&O is the foundational coverage. The MAS guidelines heighten the standard of expected AI performance, and they raise the stakes of an AI output failure. Your policy limit and the scope of what it covers should reflect the scale and criticality of the AI systems you supply.

Cyber insurance.

AI systems are data-intensive. They rely on training data, operational data, and client data flowing through them continuously. A cybersecurity incident that compromises an AI system, corrupts its training data, or exposes the client data it processes creates liability that sits at the intersection of cyber and professional liability.

Under the PDPA, your organisation remains accountable for the personal data it processes. A breach in an AI system you supply that exposes a financial institution's client data creates simultaneous obligations: notification under the PDPA, notification to the institution, and potential civil liability from the institution for the downstream costs of the breach. Cyber insurance addresses the investigation costs, notification obligations, and business interruption, as well as third-party liability to the institutions affected.

Directors and officers insurance.

The MAS guidelines place AI governance at the board and senior management level. That is not an accident. It reflects a regulatory expectation that AI risk is a governance matter, not just a technology matter. For technology companies whose directors and senior management make decisions about how AI systems are designed, validated, and deployed into regulated financial sector clients, the governance dimension of those decisions carries personal liability exposure alongside the company's corporate liability.

D&O insurance covers claims brought against directors and officers personally for decisions made in the performance of their duties. As AI governance becomes a board-level responsibility across Singapore's financial sector, the decisions technology company directors make about their AI systems and how they represent them to FI clients sit squarely within that exposure.

The timing question

The MAS guidelines come with a 12-month transition period for financial institutions. That transition period means institutions are now beginning to review their AI risk programmes, their third-party vendor governance frameworks, and the contractual representations they require from technology suppliers.

The contract conversations are already starting. The procurement teams of Singapore banks and insurers are beginning to ask the questions that the MAS guidelines require them to ask. Technology vendors who are not prepared for those conversations, including on the insurance representations their contracts will require, are at a disadvantage.

Reviewing whether your technology E&O, cyber, and D&O programme reflects the AI systems you supply and the regulatory environment your clients now operate in is not a speculative exercise. It is a practical preparation for the contract conversations that are already under way.

You can read more about technology liability insurance in our post on Technology Liability Insurance in Singapore: Why It Is Increasingly a Contract Requirement, about cyber insurance for Singapore businesses in our post on Cyber Insurance in Singapore: What SMEs Get as Premiums Fall and Coverage Widens in 2026, and about the insurance obligations for Singapore financial institutions in our post on Insurance for Singapore Financial Institutions: What MAS Requires and What a Well-Governed FI Holds.

You can read more about our technology liability cover and cyber insurance on the products page.

If you are a technology company, AI solutions provider, or data vendor supplying to Singapore financial institutions and would like to review whether your current insurance programme reflects the obligations the MAS AI guidelines now place on your clients and on you, we would be glad to work through it with you.

This article provides general information only. It is not insurance or legal advice. MAS Guidelines on Artificial Intelligence Risk Management and the AI Risk Management Toolkit are sourced from MAS published consultation paper dated November 2025 and the Project MindForge Toolkit published March 2026. The 12-month transition period reflects the MAS published proposal and is subject to final guidelines. Policy availability, terms, conditions, and exclusions vary by insurer and product, and cover is subject to the full policy wording. Please contact TZY CO for advice on your specific situation.

Wondering how this applies to your business?

Schedule a Consultationor message us on WhatsApp →
Back to all insights