The four principles in one paragraph.
The publication is short. The headline document presents fourteen numbered sub-principles, grouped under four headings, set against a one-page introduction. There is no Annex — the six definitions sit inline at § 3.3 — no enforcement schedule, no penalty regime. There is the four-letter acronym. There is the addressee: § 3.1 says the Principles can guide all firms using AIDA to provide financial products and services. And there is the drafting mood, which is the load-bearing detail. The fourteen sub-principles are written as declarative outcome statements, not duties. Individuals or groups of individuals are not systematically disadvantaged. Firms using AIDA are accountable. MAS asks firms to consider the Principles (§§ 1.2, 2.1); the Principles themselves describe the end state the firm's framework should reach.
FEAT is not a Notice and not a Guideline. Sections 27D and 55 of the Monetary Authority of Singapore Act 1970 — sometimes cited for the point — are both repealed; the current instrument-making powers sit in the Financial Services and Markets Act 2022, section 165 (codes, guidelines, policy statements, practice notes) and section 166 (written notice), with the sectoral notice power for banks at section 55 of the Banking Act 1970. FEAT was issued under none of them. It is a set of generally accepted principles, addressed at the firm's internal governance framework. MAS sets the calibration expectation itself, at § 2.3: firms can calibrate actions and requirements under their internal governance framework based on the materiality of the AIDA-driven decisions.
The four principle headings, in MAS order, with the count of sub-principles under each:
Fairness · sub-principles 1 to 4.
MAS organises the four Fairness sub-principles into two pairs. The first pair, Justifiability, addresses whether a decision can be defended after the fact. The second pair, Accuracy and Bias, addresses whether the system that produced the decision was sound at the time it produced it. The pairing matters. A decision that was sound when made can become unjustified six months later if the model has drifted or the population has shifted.
The drafting choice in sub-principle 1 — unless these decisions can be justified — is the operative escape valve. Differentiation between client segments is not, in itself, prohibited. What is prohibited is unjustified systematic disadvantage. The firm's burden is the justification, recorded contemporaneously.
Ethics · sub-principles 5 to 6.
The Ethics principle is two sub-principles long. It is the shortest of the four sections in the FEAT publication. The drafting takes a deliberate position: in the absence of a globally recognised ethics framework for AI, MAS pegs AI ethics to the firm's own existing ethics architecture.
Sub-principle 6 is the more enforceable of the two. It produces a concrete test the supervisor can apply: take an AIDA-driven decision the firm has made; ask whether a human, making the same decision under the same circumstances, would face disciplinary action under the firm's existing code; if yes, the AIDA-driven decision is also out of bounds. The asymmetry MAS is closing is the one where firms quietly let AI do what they would not let employees do.
Accountability · sub-principles 7 to 11.
Accountability is the longest of the four sections by sub-principle count. MAS splits it into two halves. The first half, Internal Accountability (sub-principles 7 to 9), addresses how the firm holds itself responsible inside its own governance perimeter. The second half, External Accountability (sub-principles 10 to 11), addresses how the firm holds itself responsible to data subjects affected by its AIDA-driven decisions.
One drafting note worth flagging at the top. MAS uses the heading Accountability, not Accountability and Auditability. Some downstream commentary conflates the two. Auditability is addressed in the December 2024 AIRM paper, at Section 6.3.16, Reproducibility and Auditability. The 2018 FEAT publication keeps Accountability as the standalone heading.
Sub-principle 8 is where the Singapore SaaS angle starts to bite. A Singapore-licensed bank using a foundation model from a US vendor is accountable for that model's behaviour to the same standard as if the bank had trained the model in-house. The vendor contract is a private-law artefact between two parties; the supervisory accountability runs from the bank to MAS, regardless.
Transparency · sub-principles 12 to 14.
Transparency is the shortest of the four sections by word count, but the most procedurally demanding. MAS asks for three layers of disclosure: a proactive baseline disclosure to all data subjects, an on-request explanation of the data used, and an on-request explanation of the consequences. The third is the one most firms underbuild.
Data subjects have comparable rights under the EU GDPR: Article 13, information to be provided where personal data are collected from the data subject, and Article 22, automated individual decision-making including profiling. MAS Transparency sub-principles 13 and 14 read like a financial-sector specialisation of the GDPR right to explanation. A firm that has built its GDPR Article 13 disclosure stack already has most of FEAT 12 to 14 in place. The work is in the financial-sector specifics — the consequences disclosure under sub-principle 14, particularly.
The Veritas consortium.
The 2018 FEAT principles defined the language. The Veritas Initiative, launched by MAS in November 2019, set out to operationalise it. The structure is an MAS-led industry consortium of, at peak, thirty-one industry players. Accenture and Bank of China were named as lead developers of the open-source Toolkit. Seven FIs piloted integration of FEAT/Veritas into their existing governance frameworks: BNY Mellon, DBS, HSBC, OCBC, Singlife, Standard Chartered Bank and UOB.
The Toolkit ships in two versions, both under the Apache License 2.0. Version 1.0 was released in February 2022 and covered fairness assessment only. Version 2.0 was released on 26 June 2023 and added assessment methodologies for ethics, accountability, and transparency. The toolkit is hosted on GitHub at github.com/veritas-toolkit.
What the Toolkit produces, mechanically, is per-use-case assessment notebooks — credit scoring, customer marketing, insurance underwriting — each walking an FI through the FEAT methodology and surfacing the artefacts the firm would otherwise assemble by hand. Adopting Veritas does not, in itself, satisfy FEAT. The Toolkit is an aid, not a certification. But the artefacts it produces are the closest thing to a standard format MAS has put forward.
A successor effort, Project MindForge, was established under the Veritas Initiative to address Generative AI. The first phase released a GenAI risk framework in November 2023, supported by a consortium of banks. The AIRM paper of December 2024 references both Veritas and MindForge as the operative industry-consortium efforts.
The AIRM Information Paper.
One naming point first, because the acronym is overloaded. AIRM in this reading means MAS's December 2024 Information Paper on AI model risk management, and nothing else. It is not the separate draft Guidelines on AI Risk Management consulted on as Consultation Paper P017-2025 (§ 8 below), and it is not a binding instrument.
The exact title is Artificial Intelligence Model Risk Management — Observations from a Thematic Review. It is dated December 2024 in the document header, and was published as an Information Paper, not a Consultation Paper. The thematic review on which it draws was conducted by MAS on selected banks in mid-2024. Section 1.2 then extends the relevance: the good practices highlighted should generally apply to other FIs, which should take reference from these when developing and deploying AI.
The structure is three thematic focus areas, each occupying its own section, with two cross-cutting Other Key Areas appended:
Auditability enters as a development focus area in the Section 6 overview — data management, model selection, robustness and stability, explainability and fairness, as well as reproducibility and auditability — and is treated substantively at Section 6.3.16, Reproducibility and Auditability. Section 6.1 itself lists seven standards-and-processes areas, a to g: data management, model selection, performance evaluation, documentation, validation, mitigating model limitations, monitoring and change management. Reproducibility and auditability are paired, deliberately. A model whose runs cannot be reproduced cannot be audited; a model that cannot be audited cannot be defended in front of an examination team.
Section 6.4 — Validation — distinguishes between independent validation and peer review, applied based on risk materiality. Section 6.5 — Deployment, Monitoring and Change Management — covers pre-deployment checks and post-deployment monitoring. On change, Section 6.5.9 records that most banks required significant or material changes to production AI to be reviewed and approved by control functions before implementation, with the appropriate development and validation requirements applied; Section 6.5.10 allows automatic updating for dynamic AI only under enhanced controls. A retraining cycle is not a free pass.
Section 7.1 on Generative AI flags the risk amplifications: hallucinations, opaque training-data provenance, evaluation difficulties for output bias. The paper asks FIs to extend the AIRM controls to GenAI rather than treating it as a separate regime. Section 7.2 on Third-Party AI records what banks were exploring — compensatory testing, contingency planning, legal agreements, staff awareness. The proposition that the FI's accountability does not transfer to the vendor is not Section 7.2's; its authority is FEAT sub-principle 8, which makes firms accountable for both internally developed and externally sourced AIDA models.
The supervisory expectation tier.
Neither FEAT nor AIRM carries a standalone penalty regime for AI-specific failures. MAS does not, as at 10 August 2026, have an AI-specific Notice analogous to the EU AI Act's Article 99 fine ceilings. What it has is a supervisory expectation set, enforceable through the existing examination architecture.
One instrument is proposed but not made, and belongs in the picture. MAS consulted on proposed Guidelines on Artificial Intelligence Risk Management — Consultation Paper P017-2025, start date 13 November 2025, closing date 31 January 2026. MAS's own consultation record marks that consultation Closed, and carries no response to feedback and no final Guidelines (mas.gov.sg, read 7 August 2026). Nothing in a draft consultation may be read as binding MAS guidance, and nothing in this reading relies on it — but a firm planning its AI governance in 2026 should read FEAT and AIRM knowing that a Guidelines instrument has been proposed and not yet made.
Three transmission mechanisms are operative. First, FEAT and AIRM expectations are read into existing risk-governance examinations. A bank's AI use is a topic an examination team can ask about, against the published principles. Second, MAS's existing instruments continue to apply — the Notice and Guidelines on Outsourcing, the Guidelines on Risk Management Practices – Technology Risk, and the Guidelines on Individual Accountability and Conduct; AIRM footnote 88 to Section 7.2 threads Third-Party AI explicitly through MAS' Notice and Guidelines on Outsourcing. Third, MAS retains the general supervisory tools — directions, examination findings, conditions on licence — that apply to any regulated activity.
The practical posture is that an MAS-regulated FI cannot point to FEAT and say it does not bind. It carries through the supervisory channel. What follows from that is a judgement rather than a published MAS position: an examination that reads a firm's AIDA governance against FEAT and AIRM is the channel through which weakness in it becomes the firm's problem. Neither document says so, and MAS has not published a statement of examination practice on the point.
Where Warrant maps FEAT and AIRM.
Two things to state before the rows. FEAT is non-binding guidance and AIRM records observed good practice; the rows below map evidence to them, not to obligations. And this is an editorial reading, not a coverage claim — Warrant's published regulation corpus carries no FEAT sub-principle and no section of the December 2024 Information Paper, so no row below is produced by an automated MAS mapping. Every field named below exists — emitted into the signed package, or carried by an ingested trace where the row says so — and where no field does the work, the row says that instead.
Cross-reference · HKMA, DNB, BNM, RBI.
The MAS AIRM paper itself, in footnote 21 to Section 4.4, names two peer-jurisdiction publications operating in adjacent space. The Hong Kong Monetary Authority issued guiding principles for the use of big data analytics and AI in 2019, covering governance and accountability, fairness, transparency and disclosure, and data privacy and protection. De Nederlandsche Bank — outside APAC, but cited by MAS in the same footnote — issued the SAFEST principles in 2019: Soundness, Accountability, Fairness, Ethics, Skills, Transparency. The vocabularies overlap heavily with FEAT; footnote 21 records both sets and says nothing about why.
Closer to home, the picture is patchier. Bank Negara Malaysia has not, as at 10 August 2026, published a counterpart to FEAT, though its August 2025 discussion paper Artificial Intelligence in the Malaysian Financial Sector — itself non-binding, and pointing to an industry-led responsible-AI framework rather than a BNM-issued one — touch the same themes. Reserve Bank of India sits in a different lineage — the FREE-AI committee report of 2025 addresses India's regulatory architecture rather than borrowing the FEAT acronym. The practical observation is that a Singapore-headquartered FI working backwards from FEAT and AIRM will generally be over-compliant with the rest of APAC; Singapore is the regional reference floor.
The Singapore-headquartered SaaS angle.
A practical observation, addressed to the AI-vendor side of the trade, and offered as Warrant's own reading as at 10 August 2026 rather than as a measured claim. Some share of AI infrastructure SaaS — model-routing, observability, evaluation, agent platforms — is incorporated in or operationally routed through Singapore, for the usual reasons: tax, talent, regional headquarters logic. The consequence we would expect, and cannot quantify, is that FEAT and AIRM start to function as procurement-gate requirements for those vendors.
The mechanism is AIRM Section 7.2 on Third-Party AI, read together with FEAT sub-principle 8 on accountability for externally sourced AIDA models. An MAS-regulated FI evaluating an AI vendor must satisfy itself that the vendor's product can be operated within the FI's FEAT and AIRM controls. The vendor that cannot show how its product enables the FI's reproducibility, auditability, and per-decision explainability obligations is the vendor that loses the procurement.
The shift we would expect, on the same basis, is from does the vendor have a SOC 2 report to does the vendor's product produce evidence the FI's MAS examination team can read. A SOC 2 report covers the vendor's own controls. A per-action evidence package covers the FI's controls, and is independently verifiable without contacting Warrant. It is addressable by package_id and timestamp — not by deployment: no deployment-identifier field is emitted, so AIRM Section 6.5, on pre-deployment checks and post-deployment monitoring, is not a section the package answers. What the package does carry is the model each pipeline stage ran, recorded in pipeline_models, alongside pipeline_config_sha256 — a digest over everything that can change a verdict. That is a reproducibility record, and it speaks to the AIRM Section 6.3.16 reproducibility-and-auditability practice rather than to Section 6.5. The EU AI Act's Article 12 logging obligation and that AIRM practice are not in conflict; the record one calls for is largely the record the other calls for. The vendor that ships one product with one evidence layer covers both markets.
Questions a compliance officer asks first.
Read the source directly.
- MAS · Principles to Promote FEAT in the Use of AI and Data Analytics in Singapore's Financial Sector · 12 November 2018
- MAS · Artificial Intelligence Model Risk Management — Observations from a Thematic Review · December 2024
- MAS · Veritas Initiative · launched November 2019
- Veritas Toolkit · GitHub · Apache 2.0 · v2.0 26 June 2023
- MAS · Project MindForge · GenAI risk framework first phase November 2023
- Warrant · MAS reading · FEAT and AIRM field notes
Authored by Warrant Compliance, the regulatory-analysis function at Warrant. [email protected]. Editorial commentary on regulatory text. Not legal advice. FEAT sub-principles 1 to 14 and Sections 1.1, 1.2, 2.1, 2.3, 3.1 and 3.3 are quoted or cited from the MAS FEAT Principles PDF. AIRM Section 1.1 and the section structure are quoted from the December 2024 MAS Information Paper PDF. Both were read directly from mas.gov.sg, re-verified 6 August 2026. Regulatory status statements carry the date on which they were checked; positions can change after that date.