Singapore Model AI Governance Framework
PDPC (Personal Data Protection Commission) for data aspects. IMDA (Infocomm Media Development Authority) for AI Verify. No standalone AI regulator.
January 2019 (v1), updated 2020. AI Verify (2022).
Status
Published
Risk Level
Medium
Jurisdiction
Singapore
Enforcement
January 2019 (v1), updated 2020. AI Verify (2022).
medium risk framework
Private sector organizations in Singapore deploying AI, especially for decisions affecting individuals.
Overview
Singapore's Model AI Governance Framework provides detailed practical guidance for private sector organizations deploying AI. Developed by PDPC, emphasizes human-centric AI with detailed implementation guides. Supplemented by AI Verify - an AI governance testing toolkit and certification program.
Scope
Private sector organizations in Singapore deploying AI for decisions affecting individuals. Voluntary but strongly adopted as best practice across ASEAN. AI Verify provides voluntary certification.
Key Requirements
- Internal governance: define accountability for AI systems at board/executive level
- Human oversight: determine appropriate level of human involvement for AI decisions
- Operations management: data lineage, model documentation, version control
- Customer transparency: plain-language disclosure of AI use affecting customers
- Risk categorization: probability × severity of harm framework
- Bias testing: diverse training data and regular bias audits
- Explainability: provide reasons for AI decisions affecting individuals
- AI lifecycle documentation from design to decommission
Guardrails & Operational Controls
- Risk matrix: (probability of harm) × (severity) to determine required oversight level
- Explainability requirement: AI decisions must be explainable at least to internal reviewers
- Oversight calibration: higher-stakes decisions require more human oversight, not less
- Data quality: training data must be representative, accurate, and unbiased
- Testing evidence: bias and performance tests must be documented
- Vendor due diligence: third-party AI must be assessed against same standards
Implementation Guidance
- 1Download and self-assess using Singapore's AI Verify Toolkit
- 2Map AI systems to the framework's risk dimensions
- 3Use implementation guide case studies for sector-specific guidance
- 4Consider AI Verify certification for B2B trust signal
Industry Impact
Financial Services
MAS TRM Guidelines align with Model AI Governance Framework. Banks expected to adopt both.
Government
Singapore Government AI Governance Framework extends MGAIF to public sector.
Healthcare
MOH AI in Healthcare advisory aligns with framework. Clinical AI requires heightened human oversight.
Retail & eCommerce
AI personalization and pricing require transparency disclosures to customers.
Insurance
AI underwriting and claims processing require explainability mechanisms.
Regulatory Timeline
Jan 2019
Model AI Governance Framework v1 published
Jan 2020
Framework v2 published - expanded guidance
May 2022
AI Verify testing toolkit released
Jun 2023
AI Verify Foundation established for global AI governance testing
2024–2025
Singapore developing binding AI governance regulations for critical sectors
Penalties for Non-Compliance
No direct penalties. Non-compliance may affect PDPA obligations. MAS can act on financial services AI failures.
Framework Details
Short Name
Singapore AI Framework
Jurisdiction
Singapore
Enforcement Date
January 2019 (v1), updated 2020. AI Verify (2022).
Enforcing Authority
PDPC (Personal Data Protection Commission) for data aspects. IMDA (Infocomm Media Development Authority) for AI Verify. No standalone AI regulator.
Status
Risk Level
Affected Organizations
Private sector organizations in Singapore deploying AI, especially for decisions affecting individuals.
Tags
This is educational guidance only. Always consult qualified legal counsel for compliance decisions affecting your organization.