MAS's AI Rules Reach 52 Licence Types. The Hard Half Lands in 2028.
Singapore's financial regulator has told every institution it licenses how it expects AI to be governed, and given them two dates. The first, 7 October 2027, covers oversight and inventories. The second, a year later, covers the controls most people are quoting today.
October 8th, 2026
Last updated: October 8
Key takeaways
- MAS issued its Guidelines on AI Risk Management on 7 October 2026. They take effect on 7 October 2027.
- The MAS page lists 52 licence categories in scope, including major and standard payment institutions and money-changing licensees.
- Sections 3 to 4, on oversight, AI inventory and risk materiality, are due by 7 October 2027. Sections 5 to 6 may wait until 7 October 2028.
- The third-party AI clause is paragraphs 5.10 to 5.11, in the 2028 half, though high-risk use cases should not wait.
- MAS proposed a 12-month transition. Respondents asked for 18 to 24 months, and 135 responses were received.
- MAS will consult again in 2027 on additional guidance for agentic AI.
Data highlight
52licence categories
Licence categories listed by MAS as in scope of its Guidelines on AI Risk Management, issued 7 October 2026
7 October 2026 to 7 October 2028
Compiled by HaiPay on 8 October 2026 from three documents published by the Monetary Authority of Singapore on 7 October 2026: the media release "MAS Sets Out Supervisory Expectations on Responsible AI Adoption by Financial Institutions", the Guidelines on Artificial Intelligence Risk Management (30 pages, six sections), and the Response to Feedback Received on the Guidelines (57 pages), together with the MAS consultation page for paper P017-2025, published 13 November 2025 and closed 31 January 2026. The figure of 52 is HaiPay's count of the entries in the "Applies to" list on the MAS guidelines page as read on 8 October 2026; MAS does not publish a total. Of those 52, HaiPay classifies five as payment licences: Designated Payment System Operator, Designated Payment System Settlement Institution, Major Payment Institution, Standard Payment Institution and Money-changing Licensee. Credit and Charge Card Licensee and Credit/Charge Card Issuer are listed separately and are not included in the five. Dates are from paragraph 1.8 of the guidelines and paragraph 5 of the media release: the guidelines take effect on 7 October 2027, Sections 3 to 4 apply from that date, and Sections 5 to 6 must be met by 7 October 2028. Page counts are from the contents page of the guidelines: Sections 3 to 4 occupy pages 10 to 16 and Sections 5 to 6 occupy pages 17 to 30. The count of twelve life-cycle control areas is from Figure 1 of the guidelines; the 26 paragraphs are 5.1 to 5.26. The eight third-party AI considerations are items (a) to (h) of paragraph 5.11. The transition history is from Section 13 of the response paper: MAS proposed 12 months, many respondents asked for 18 to 24 months, and MAS adopted 12 months for Sections 3 to 4 and 24 months for Sections 5 to 6. The respondent count of 135 is HaiPay's addition of the 95 named respondents in Annex A of the response paper and the 11 plus 29 respondents recorded there as requesting confidentiality of identity. HaiPay did not contact MAS or any respondent and does not assess any institution's compliance.
Singapore's financial regulator has told every institution it licenses how it expects AI to be governed, and given them two dates. The first, 7 October 2027, covers oversight and inventories. The second, a year later, covers the controls most people are quoting today.
The Monetary Authority of Singapore issued its Guidelines on Artificial Intelligence Risk Management on 7 October 2026, together with a 57-page response to the feedback on its November 2025 consultation. The guidelines run to 30 pages in six sections. They apply to all financial institutions and all forms of AI, and each institution may decide how to meet them according to the scale and risk of its own AI use.
Who is in scope
The MAS page for the guidelines carries an "applies to" list. HaiPay counted 52 licence categories on it, from locally incorporated full banks to Lloyd's brokers. Five are payment licences: designated payment system operator, designated payment system settlement institution, major payment institution, standard payment institution and money-changing licensee. Credit and charge card licensees and issuers appear separately.
That is the first thing a payment company should take from the document. The guidelines are usually described as a banking matter. The list says otherwise.
The two deadlines
Paragraph 1.8 sets the dates. The guidelines take effect on 7 October 2027. Sections 3 and 4 apply from that day; Sections 5 and 6 may be met by 7 October 2028.
The split is not even. Sections 3 and 4 run from page 10 to page 16, seven pages covering board and senior management oversight, AI identification, the AI inventory and risk materiality assessment. Sections 5 and 6 run from page 17 to page 30, fourteen pages covering twelve life-cycle control areas in 26 paragraphs, plus staff capability and technology infrastructure.
The response paper explains how the gap arose. MAS had proposed a single 12-month transition. Many respondents asked for 18 to 24 months, citing the difficulty of hiring, of applying the rules to third-party AI, and of retrofitting them to AI already in production. MAS agreed to a phased 12 and 24 months, with one condition: life-cycle controls for high-risk use cases should be applied as soon as possible, not held to the end of the second year.

Where the third-party clause sits
The sentence that has travelled furthest is from the media release: institutions remain accountable for AI developed, operated or provided by third parties, and where the risk cannot be brought within appetite they should consider limiting, suspending or replacing the service.
In the document that is paragraphs 5.10 and 5.11. They are in Section 5, so the deadline is 2028. Paragraph 5.11 lists eight things an institution should weigh before onboarding third-party AI: transparency, supply chain assessment, concentration risk, change management, contingency plans, legal agreements, staff capability and complexity. On transparency it says an institution may rely on certifications or external assessments by independent parties, and adds, in brackets, "not self-attestations". Under legal agreements it names the right to audit and notification when AI is introduced or updated.
The definition is wide. Footnote 10 covers any system, model, service or tool incorporating AI that an institution procures, subscribes to or relies on. Footnote 21 gives the example of software-as-a-service that is not sold as AI but contains AI features. Respondents asked MAS to limit the scope to procured AI solutions with lighter treatment for embedded AI. MAS kept the broad definition.
What has to exist by October 2027
Sections 3 and 4 ask for structure rather than testing. The board, or a committee it delegates to, approves the AI governance approach and sets a risk appetite with qualitative and quantitative measures. Footnote 18 offers an example of the latter: the number of material AI use cases that depend on a single provider.
A designated control function becomes what the text calls the final arbiter of whether a given use counts as AI. The inventory it keeps should record, for each use case, system or model, the purpose, approved scope, model type, data used, dependencies, life-cycle status, risk rating and owners. Risk materiality is assessed on three dimensions: impact, complexity and reliance.
There is a lighter path. Under paragraph 2.3, an institution whose AI use would not have a material impact if it failed may run basic policies instead. Paragraph 2.4 gives six examples of such use, including drafting emails, summarising documents and generating charts for internal reference. Paragraph 2.5 lists the six things the basic policies must contain, among them an approved list of AI tools and a process for adding to it. The response paper puts that lighter path on the 12-month clock as well.

Agentic AI is named, not ruled
Paragraph 1.5 brings AI agents within the guidelines. Paragraph 1.11 describes the risk as an agent with tool access executing actions that diverge from the goals it was given. Footnote 25 says the inventory should capture, for agents, their identifiers, the tools and systems they can reach and the guardrails on them, and paragraph 5.23 extends monitoring to reasoning processes, actions taken and tools used.
What the guidelines do not contain is a separate regime. The media release says MAS intends to consult the sector in 2027 on what additional guidance on agentic AI would be useful.
What this is not
HaiPay read the media release, the 30-page guidelines and the 57-page response to feedback. The licence count and the page counts are HaiPay's; MAS does not publish either. The guidelines are principles-based, and the sections described here set expectations rather than a checklist.
The response paper lists 95 named respondents and records a further 40 who asked for their identity to be withheld, 135 in all. HaiPay did not contact MAS or any respondent, and does not assess whether any institution, in Singapore or elsewhere, meets these expectations.
What to watch
The 2027 consultation on agentic AI, which will decide whether agents get their own section or stay inside this document.
Whether MAS or the industry settles on a format for the independent assessments paragraph 5.11 prefers to self-attestation. Nothing in the guidelines prescribes one.
And 7 October 2027, when a payment institution in Singapore should be able to show a regulator its AI inventory and name the person responsible for it.
How to cite
HaiPay News, "MAS's AI Rules Reach 52 Licence Types. The Hard Half Lands in 2028.", https://www.haipay.net/news/mas-ai-risk-guidelines-52-licence-types-2028, October 8th, 2026
About the author

HongMing Dong
Content Specialist
Content Specialist at HaiPay, where I explore global payment infrastructure, local acquiring, and cross-border commerce. I turn complex payment topics into practical insights for merchants, platforms, and businesses expanding into international markets.
Reviewed by WeiJun TangEditorial policy
5 sources
Monetary Authority of SingaporeMAS Sets Out Supervisory Expectations on Responsible AI Adoption by Financial Institutions, media release, 7 October 2026
Monetary Authority of SingaporeGuidelines on Artificial Intelligence Risk Management for Financial Institutions, guidelines page with list of institutions in scope
Monetary Authority of SingaporeGuidelines on Artificial Intelligence Risk Management, full document (PDF), 7 October 2026
Monetary Authority of SingaporeResponse to Feedback Received on Guidelines on Artificial Intelligence Risk Management (PDF), 7 October 2026




