Live2m agoOneLearn Global and Singapore Shipping Association Partner to Build AI-Powered Maritime Training Hub
← Back to stories

MAS agentic finance safeguards push banks to govern AI agents like privileged users

Source: Singapore Business Review

Singapore's banks have been among the fastest in Asia to put agentic AI into real production work — and the Monetary Authority of Singapore has now made explicit what their risk teams have been circling for months: an AI agent that initiates a payment or approves a loan must be governed like a

MAS agentic finance safeguards push banks to govern AI agents like privileged users
SGAI Daily

Singapore's banks have been among the fastest in Asia to put agentic AI into real production work — and the Monetary Authority of Singapore has now made explicit what their risk teams have been circling for months: an AI agent that initiates a payment or approves a loan must be governed like a privileged user, not a software component that behaves predictably once configured. That distinction stops being academic the moment an agent is actually acting autonomously in payments, lending, fraud management or customer servicing.

The shift is crystallised in Safeguards for Agentic Finance at Runtime (SAFR), which MAS published in July after developing it with banks and fintechs through the BuildFin.ai initiative. SAFR is framed as industry guidance rather than a supervisory requirement, but its core recommendation is unusually concrete: institutions should verify and record an agent's intended action before it initiates a payment, approves a loan, executes a trade or files a regulatory report — rather than reviewing what happened after the fact. For banks already running agentic AI in production, that operational specificity matters more than the paper's voluntary status.

The guidance lands as regulators across the region converge on the same principle. Hong Kong's Privacy Commissioner has urged organisations deploying agentic AI to adopt stronger governance and limit agents to the minimum access rights needed for each task, while China's TC260 has released draft guidance covering the deployment, operation and retirement of AI agents across their lifecycle. MAS has effectively translated that shared concern into practical, sector-specific guidance for financial services — the industry where autonomous systems can move money, and where the downside of weak controls is most immediate.

The hard part is identity, not model accuracy. Bank access models were designed around two kinds of actors: employees governed by role-based access, approval workflows and segregation of duties, and machine identities granted fixed permissions because they once did one narrow thing. AI agents fit neither category — they chain tasks across systems at machine speed, retrieving customer records and touching treasury systems in a single session in ways no static permission set anticipated. That is why accountability now sits with CISOs and identity teams rather than model risk functions: the question is whether this actor was authorised to take this specific action, right now, within this scope.

Why it matters for Singapore: MAS has effectively given the local market a template for agentic finance governance before expectations harden into binding rules. Banks that extend identity governance to autonomous actors now — access scoped to defined tasks, permissions that expire when the task ends, continuous logging of privileged actions — will spend far less retrofitting when supervisors formalise expectations, and will be free to scale agentic AI across payments and lending without governance becoming the limiting factor. With MAS, Hong Kong and China all pointing the same direction within months of each other, planning around the principle now is the cheaper bet.

Your daily AI edge in Singapore: in <5 minutes.

We do the reading so you don't have to. Get the essential TL;DR on local AI moves delivered to your inbox every morning.