AI governance in APAC: Singapore's PDPA and MAS expectations
Singapore governs AI through a layered model: the binding PDPA data-protection statute as the floor, voluntary PDPC/IMDA governance frameworks, and sector-specific MAS expectations for financial institutions. This article maps the instruments and what regulated APAC teams must operationally evidence.
The floor: the PDPA and the PDPC
The Personal Data Protection Act 2012 (PDPA) is Singapore's core data-protection statute, enforced by the Personal Data Protection Commission (PDPC). Since 1 October 2022 the PDPC can impose financial penalties of up to the higher of S$1 million or 10% of an organisation's annual turnover in Singapore (section 48J). The PDPA applies across the AI lifecycle, from data collection and training through to deployment.
To clarify how the statute applies to AI, in March 2024 the PDPC issued the Advisory Guidelines on the Use of Personal Data in AI Recommendation and Decision Systems. These interpret the existing law rather than create a new obligation, but they sharpen expectations on consent, purpose limitation and accountability when personal data feeds AI systems.
Voluntary frameworks: the Model AI Governance Framework and AI Verify
Above the statutory floor sits a layer of voluntary but widely referenced governance guidance. The IMDA and PDPC first published the Model AI Governance Framework in 2019, with a second edition in 2020. In May 2024 the Model AI Governance Framework for Generative AI followed, developed jointly by the IMDA and the AI Verify Foundation. It addresses generative risks such as hallucination, copyright, content provenance and systemic risk, and allocates responsibility across the value chain — model developers, deployers and cloud providers.
Complementing this, AI Verify — a testing framework and toolkit backed by the IMDA and the AI Verify Foundation — provides a structured self-assessment through which organisations can evidence, technically and procedurally, how their systems align with recognised governance principles.
Financial services: MAS FEAT and the AI model-risk Information Paper
For financial institutions, the Monetary Authority of Singapore (MAS) sets its own expectations. The FEAT principles — Fairness, Ethics, Accountability and Transparency — published in 2018, are high-level, non-binding guidance for the use of AI and data analytics in the financial sector. They were translated into measurable assessment methodologies through the Veritas consortium.
On 5 December 2024 MAS published the Information Paper "Artificial Intelligence Model Risk Management", setting out good practices observed in a thematic review of banks. It is organised around three areas: governance and oversight; risk-management systems and processes; and the development, validation and deployment of AI. The paper is not binding, but MAS has signalled further supervisory guidance — regulated institutions should treat it as a clear statement of expectations.
What this means for regulated APAC teams
Singapore's approach pairs a hard statutory floor (the PDPA) with soft but influential governance frameworks and sectoral expectations. For regulated organisations — including in the first APAC pilot setting of softScheck Singapore — this means data-protection duties are enforceable, while the voluntary frameworks define the demonstrable maturity that supervisors, customers and auditors increasingly presume.
- Maintain a current inventory of all AI use cases with data lineage and purpose (PDPA baseline).
- Document human oversight and model validation, especially for generative AI (MAS expectation).
- Align governance to FEAT and the Model frameworks and make conformance auditable (e.g. via AI Verify).
Treat the PDPA as an enforceable duty and the PDPC, IMDA and MAS frameworks as the demonstrable maturity bar — and hold both together through an auditable AI inventory with documented human oversight.
- PDPC — Amendments to Enforcement under the PDPA (increased financial penalties in force from 1 Oct 2022)
- IMDA / AI Verify Foundation — Model AI Governance Framework for Generative AI (30 May 2024)
- MAS — FEAT Principles (2018)
- MAS — Artificial Intelligence Model Risk Management, Information Paper (5 Dec 2024)