Financial AI · Governance
AI enters the control environment.
Singapore's new AI rules should get the attention of U.S. CFOs.
Not because Singapore regulates American companies.
Because its financial regulator just laid out a practical framework for governing AI inside the financial control environment, and U.S. regulators already have many of the mechanisms needed to adopt something similar.
The Monetary Authority of Singapore now expects financial institutions to inventory AI use, assess the materiality of each use case, establish clear executive accountability, apply lifecycle controls, and manage third-party AI risk. The framework covers traditional, generative, and increasingly autonomous AI.
The key principle:
The financial institution remains accountable even when the AI comes from a third party.
That has direct CFO implications.
CFO perspective
AI Is Becoming Part of Internal Control
An AI that summarizes a meeting presents limited financial risk.
An AI agent that can access the ERP, modify customer records, interact with accounts payable, influence credit decisions, or execute workflows presents something very different.
It has authority.
That means finance leaders increasingly need to understand:
- where AI is operating
- which systems it can access
- which use cases are financially material
- what actions it can execute
- what requires human approval
- which external models critical workflows depend upon
- whether those actions can be audited afterward
This is essentially delegated authority for digital workers.
CFO perspective
Why the U.S. Could Follow
The Federal Reserve, OCC, and FDIC already regulate model risk, vendor risk, operational resilience, and internal controls.
Their April 2026 model-risk guidance specifically excluded generative and agentic AI from its scope, leaving an obvious policy gap.
State bank supervisors have since introduced an AI examination framework, while federal regulators are updating third-party risk guidance.
MAS provides a logical way to connect those pieces.
Instead of creating an entirely new AI regulatory regime, U.S. supervisors could begin asking familiar questions:
Do you know what AI you're using?
Have you classified the risk?
Who approved it?
What can it access?
How do you monitor it?
Can you shut it down or replace the provider?
That approach could spread well beyond banks into insurance, mortgage, fintech, payments, and other regulated financial businesses.
CFO perspective
The CFO Takeaway
Companies do not need to wait for U.S. regulations.
Four controls make sense now:
- Maintain an AI inventory.
- Classify financially material AI use.
- Define agent authority and human approval thresholds.
- Maintain an exit strategy for critical third-party AI providers.
AI governance does not need to become another giant compliance program.
It needs to become part of the existing control environment.
Because once AI can touch the money, it becomes a finance issue.
Primary sources
- Download the MAS AI Risk Management Guidelines — October 7, 2026 (PDF)
- MAS AI Risk Management Guidelines
- MAS announcement and implementation timetable
- Federal Reserve SR 26-2: Revised Guidance on Model Risk Management
- CSBS AI Supervisory Framework announcement
- OCC proposed third-party risk management guidance