01 · FEAT · FOUR PRINCIPLES
Fairness · Ethics · Accountability · Transparency.
"This document sets out Principles for firms to consider when assessing existing or developing new internal frameworks to govern the use of AIDA. This set of Principles is not intended to replace existing relevant internal governance frameworks." "This set of Principles is not intended to be prescriptive."
MAS · Principles to Promote FEAT in the Use of AI and Data Analytics in Singapore's Financial Sector · paras 2.1–2.2 · published 12 November 2018
FEAT was published on 12 November 2018 as a MAS information paper and it creates no obligation: it says so twice in its own paragraph 2. It sets out 14 numbered principles, grouped under Fairness (justifiability, then accuracy and bias), Ethics, Accountability (internal, then external) and Transparency. The proposed Guidelines on AI Risk Management do not replace it — Consultation Paper P017-2025 says at paragraph 2.8 that the Guidelines "build on the FEAT principles" and "complement" them. The Veritas Initiative, started November 2019, is the industry-consortium work that helps firms put FEAT into code; its two public repositories are a Python diagnosis tool and a Java assessment tool. For the principle-by-principle reading, see MAS FEAT and AIRM, read against the AI agent.
F · Fair
Adverse-impact metrics per decision class.
WARRANT · warrant-v1 has no field carrying fairness or adverse-impact metrics. authorizations[*].justification carries the per-action rationale; the obligation row carries compliance="gap" where the trace shows no metric.
E · Ethics
Purpose alignment evidenced per action.
WARRANT · authorizations[*].within_purpose per-action assessment.
A · Acct.
Clear owner of every AI-driven decision.
WARRANT · regulated_entity, a root field of the submitted trace, names the firm. No field in warrant-v1 names an accountable individual, so a per-decision owner is not evidenced in the package.
T · Trans.
Explainability surfaced to data subject and supervisor.
WARRANT · authorizations[*].justification per action, carried in the evidence package. That is Warrant's assessment of the action, not the agent's own words: a firm's reasoning travels in the free-form trace[*].outputs it submits — the sample traces put a rationale key there — and warrant-v1 does not re-emit it.
02 · LIFECYCLE SCOPE
Design through decommissioning.
The proposed Guidelines run across the life cycle, which P017-2025 defines as "its evolution from inception to retirement or decommissioning", a definition it adapts from ISO/IEC 22989. Paragraph 4.1 asks an FI to "plan for and implement robust controls covering the entire life cycle of an AI use case, system or model and assign clear roles and responsibilities for such controls"; paragraph 4.26 addresses "the eventual retirement or decommissioning" of a model. The paper does not publish a fixed five-stage list, so Warrant does not assert one. Per-trace authorization is assessed live; cross-trace lifecycle roll-up ships v0.5, 2026 Q3.
14principles
FEAT, NON-PRESCRIPTIVE
Fairness (justifiability; accuracy and bias), Ethics, Accountability (internal; external), Transparency.
2018
FEAT PUBLISHED
Published 12 Nov 2018 as a MAS information paper, para 1.4 updated 7 Feb 2019. Not a binding instrument.
Per-decision evidence is what survives a change of policy. Not the policy. The trail.Warrant · reading of P017-2025 s.4 · 2026-08-06
03 · VERITAS · INDUSTRY REFS
Open-source toolkit.
Veritas Toolkit version 2.0 was released on 26 June 2023, at the conclusion of the initiative's third phase. MAS records that Accenture and Bank of China enhanced the toolkit to provide full FEAT assessment functionality; the Phase 3 consortium ran to some thirty organisations, HSBC, OCBC Bank, United Overseas Bank and Swiss Re among them. The two public repositories are a Python diagnosis tool and a Java assessment tool. The date comes from MAS's own Veritas page, cited below; secondary summaries of the toolkit circulate with other dates, and we do not rely on them. As at the MAS Veritas page, read 2026-08-06.
04 · WHY THIS REGULATOR NOW
What is actually in force in Singapore?
MAS published the FEAT principles on 12 November 2018 and updated paragraph 1.4 on 7 February 2019. They have shaped supervisory conversation in Singapore since, but they have never been prescriptive, and MAS says so in the document. Between then and now the record runs through the Veritas Initiative from November 2019, an information paper on AI model risk management in 2024, and Project MindForge on generative AI. The instrument that would turn expectation into issued guidance is the set of Guidelines on AI Risk Management proposed in Consultation Paper P017-2025. The consultation paper was issued; the Guidelines were not.
What the record actually shows. MAS issued P017-2025 in November 2025 and the consultation closed on 31 January 2026. A MAS media release of 20 March 2026 states that MAS "is presently reviewing responses to an earlier public consultation on a set of Guidelines on AI Risk Management" — so as at that date the proposed final Guidelines had not issued. Nothing on this page treats the draft as if it had. MAS's 2024 publication on artificial intelligence model risk management is an information paper, not a consultation, and it is not the vehicle for the Guidelines. We do not put a finalisation date on the Guidelines, because no MAS document sets one. Status as at the MAS media release of 20 March 2026: nothing later has been verified, so a firm should check the MAS website for anything issued after that date.
Two things this page will not assert. The MAS Technology Risk Management Guidelines, revised January 2021, are Guidelines and not Notices, and no MAS instrument states that they carry the weight of an enforcement directive — so we do not say it. Nor do we point at AI-specific addendums under consultation, because we cannot point to one. What remains is the part a firm can act on: the draft Guidelines are organised as AI oversight, AI inventory, and AI life cycle controls, and P017-2025 states at paragraph 1.2 that they "should be generally applicable to different AI applications and technologies, including Generative AI, as well as newer developments such as AI agents". That is draft text, and it binds nobody until MAS issues the Guidelines.
05 · MAPPING · FEAT PRINCIPLES
Per-principle field map.
"This document contains a set of generally accepted Principles for the use of artificial intelligence and data analytics ("AIDA") in decision-making in the provision of financial products and services." Firms "can calibrate actions and requirements under their internal governance framework based on the materiality of the AIDA-driven decisions."
MAS · FEAT principles · paras 1.1, 2.3 · published 12 November 2018
The mapping below quotes each FEAT principle as numbered in the document's own Summary of Principles, and names what the warrant-v1 evidence package actually carries against it. The published schema, api/spec/warrant-v1-evidence.schema.json, sets additionalProperties: false at its root and on every action, so the field list is closed: a package carries no fairness metrics, no bias-test record, no sign-off, no record of alternatives considered, no model id or version, and no policy version. The rows below name the fields that do exist and state plainly where there is none. These are principles a firm calibrates, not clauses a supervisor enforces — Warrant does not claim to know what any examiner pulls, and the rows below say what the document says.
FEAT 1
Justifiability · "Individuals or groups of individuals are not systematically disadvantaged through AIDA-driven decisions unless these decisions can be justified."
WARRANT · authorizations[*].justification per action, carried in the evidence package. That is Warrant's assessment of the action, not the agent's own words: a firm's reasoning travels in the free-form trace[*].outputs it submits — the sample traces put a rationale key there — and warrant-v1 does not re-emit it.
FEAT 3
Accuracy and bias · "Data and models used for AIDA-driven decisions are regularly reviewed and validated for accuracy and relevance, and to minimize unintentional bias."
WARRANT · warrant-v1 has no field for fairness metrics and none for a bias-test record. A firm can put Veritas assessment output in the free-form trace inputs, but the package defines no field for it and the obligation row carries compliance="gap".
FEAT 6
Ethics · "AIDA-driven decisions are held to at least the same ethical standards as human-driven decisions." A floor, not an equivalence.
WARRANT · authorizations[*].within_purpose per-action check.
FEAT 7
Internal accountability · "Use of AIDA in AIDA-driven decision-making is approved by an appropriate internal authority." An appropriate internal authority — FEAT does not require a named individual per decision.
WARRANT · warrant-v1 has no field for an approving internal authority, so this row is unevidenced in the package. FEAT does not require a named individual per decision.
FEAT 10
External accountability · data subjects "are provided with channels to enquire about, submit appeals for and request reviews of AIDA-driven decisions that affect them."
WARRANT · authorizations[*].reversible records whether each action can be undone, which is what an appeal or a review has to act on. warrant-v1 has no field for an enquiry, appeal or review channel and none for alternatives considered, so the channel obligation is not evidenced.
FEAT 12
Transparency · "use of AIDA is proactively disclosed to data subjects as part of general communication." General communication, not a per-decision notice.
WARRANT · the decision, and an AIDA-influence flag where the firm sets one, travel in the free-form trace[*].outputs the firm submits. The signed package keeps actions[*], whose only properties are action_id, actor, action and subject, so a disclosure to the customer drawn from the decision payload has to come from the firm's trace store, not from the package. What the package carries against this principle is the per-action authorizations[*] row and the obligations.<action_id>[] rows.
FEAT 13–14
Explanations · data subjects are provided, upon request, clear explanations of what data is used and how it affects the decision, and of the consequences it may have. The duty runs to the data subject; FEAT does not name the supervisor here.
WARRANT · authorizations[*].justification per action, carried in the evidence package. That is Warrant's assessment of the action, not the agent's own words: a firm's reasoning travels in the free-form trace[*].outputs it submits — the sample traces put a rationale key there — and warrant-v1 does not re-emit it.
5.2 · Consultation Paper P017-2025 · DRAFT · not cited as binding
§ 2.5 · draft
AI oversight · the Board or a delegated committee approves the governance approach for AI risk management and ensures material AI risks are addressed in the risk appetite framework.
WARRANT · regulated_entity, a root field of the submitted trace, names the firm. warrant-v1 has no policy-version field. Board-level artefacts sit above the trace; Warrant records what the trace can carry and no more.
§ 3.4 · draft
AI inventory · "An FI should establish and maintain an accurate and up-to-date inventory of AI use cases, systems or models across the FI."
WARRANT · agent_id, a root field of the submitted trace, is rendered on the package as the agent identifier, and actions[*].actor names the actor per action. warrant-v1 has no model-id field and no model-version field, so an inventory entry keyed on a model rather than on the agent is not evidenced.
§ 4.1 · draft
Life cycle controls · "An FI should plan for and implement robust controls covering the entire life cycle of an AI use case, system or model and assign clear roles and responsibilities for such controls."
WARRANT · actions[*] (action_id, actor, action, subject) bound into a record independently verifiable without contacting Warrant. The package is per-trace: warrant-v1 has no life-cycle-phase field and none for role assignment, so those two limbs are not evidenced.
§ 4.11 · draft
Third-party AI · onboarding, development and deployment controls adequate for the risk materiality of the use case, including testing third-party AI in the context of the FI's own use cases and data.
WARRANT · actions[*].actor names the actor the trace attributes each action to, which for an agent step is normally the model. warrant-v1 has no upstream-provider field and no field for third-party test results, so neither is evidenced.
§ 4.26 · draft
Retirement · controls for "the eventual retirement or decommissioning" of an AI model.
WARRANT · warrant-v1 has no policy-version field and the package is per-trace, so a retirement or decommissioning control is not evidenced. Cross-trace lifecycle roll-up ships v0.5, 2026 Q3.
The rows above carry the paper's own paragraph numbers, and no scheme of our own: a five-stage LC1-to-LC5 labelling circulates in secondary commentary and appears nowhere in the instrument, so this page does not use it. Every row above is draft text from a consultation paper. None of it is cited as binding in an evidence package, and none of it takes effect until MAS issues the Guidelines.
06 · FAQ
Questions a CCO and MAS-licensed FI asks first.
Does the proposed MAS AI Risk Management guidance apply to a non-Singapore firm with a SG subsidiary or branch?
Neither instrument imposes a binding obligation today. The proposed Guidelines on Artificial Intelligence Risk Management exist only as Consultation Paper P017-2025, issued November 2025; the consultation closed 31 January 2026 and no final Guidelines had been issued as at the corpus source date of 20 March 2026. FEAT is a set of principles, and states at paragraph 2.2 that it "is not intended to be prescriptive". What the paper does say about reach is that the Guidelines "aim to establish a set of expectations that are generally applicable across the financial sector, and may be applied in a proportionate manner across FIs of different sizes and risk profiles", where FI takes its meaning from section 2 of the Financial Services and Markets Act 2022. A group running an AI agent from a parent outside Singapore should read the proposal as a signal of supervisory direction, not as a duty that has attached. As at P017-2025, November 2025.
How does Veritas Toolkit relate to the proposed AI Risk Management guidance?
Veritas is the MAS-led industry consortium initiative, started November 2019, that helps firms incorporate the FEAT principles into their AI and data analytics work. Veritas Toolkit version 2.0 was released on 26 June 2023 at the conclusion of the initiative's third phase; MAS records that Accenture and Bank of China enhanced the toolkit to provide full FEAT assessment functionality, with the wider Phase 3 consortium of some thirty organisations, HSBC, OCBC Bank, United Overseas Bank and Swiss Re among them. The public repositories are a Python diagnosis tool and a Java assessment tool. Using Veritas satisfies nothing by itself, and cannot satisfy Guidelines that have not been issued. The firm still owes per-decision evidence, lifecycle documentation, and an internal approval path it can name. As at the MAS Veritas record, read 2026-08-06.
How do i generate Singapore evidence if my agent runs on a non-Singapore LLM provider?
The location of the model vendor is not material. What is material is which entity answers for the decision. Warrant produces a per-action evidence record in the same shape it produces for the binding regimes, mapped to the FEAT principles and to the sections of the proposed Guidelines, and independently verifiable without contacting Warrant. Because the proposed Guidelines are still a consultation paper, Warrant labels those rows as draft and does not cite them as binding. Same artefact whether the LLM is Anthropic, OpenAI, or open-source.
What does FEAT actually require on accountability?
Less than is often claimed. FEAT's Accountability principles are: internal — "Use of AIDA in AIDA-driven decision-making is approved by an appropriate internal authority", firms "are accountable for both internally developed and externally sourced AIDA models", and firms "proactively raise management and Board awareness of their use of AIDA"; external — data subjects "are provided with channels to enquire about, submit appeals for and request reviews of AIDA-driven decisions that affect them", and verified supplementary data they provide is taken into account on review. FEAT requires an appropriate internal authority, not a single named individual per decision, and it does not say what a supervisor will pull on examination. Warrant carries a named sign-off where the firm supplies one, because it is useful evidence, not because FEAT compels it. As at the FEAT principles, published 12 November 2018.
What lifecycle stages does the proposed guidance cover?
Consultation Paper P017-2025 organises its proposed Guidelines as AI oversight, AI inventory, and AI life cycle controls, and defines the AI life cycle as "its evolution from inception to retirement or decommissioning", adapted from ISO/IEC 22989. Paragraph 4.1 asks an FI to "plan for and implement robust controls covering the entire life cycle"; paragraph 4.26 covers "the eventual retirement or decommissioning" of an AI model; paragraph 4.11 covers third-party AI. The paper does not enumerate a fixed five-stage list, and this page does not present one. Per-decision evidence is operative in deployment and monitoring; cross-trace lifecycle roll-up ships v0.5, 2026 Q3. As at P017-2025, November 2025.
Are non-financial-services firms in scope for FEAT or the proposed AI Risk Management guidance?
No. Both are MAS documents addressed to financial institutions, where FI takes its meaning from section 2 of the Financial Services and Markets Act 2022. Non-financial-services firms in Singapore sit outside that perimeter, though the Personal Data Protection Act 2012 may apply to their handling of personal data. Neither MAS document is binding in any event: FEAT states it "is not intended to be prescriptive" and the AI Risk Management Guidelines remain a consultation proposal. As at P017-2025, November 2025.
07 · READ THE SOURCE
Primary citations.
MAS Consultation Paper P017-2025, Consultation Paper on Guidelines on Artificial Intelligence Risk Management, November 2025: mas.gov.sg (PDF, 30pp). MAS FEAT principles, published 12 November 2018: publication record and the principles themselves. MAS Veritas Initiative record, which carries the phase dates and consortium membership: mas.gov.sg/veritas. Veritas open-source repositories: github.com/veritas-toolkit. Every date and quotation on this page was read against these MAS documents on 2026-08-06. Secondary explainers are not cited here: where one disagrees with a MAS document, the MAS document governs.
W
No MAS sample: Warrant does not cite a draft. EU/UK/US/India samples demonstrate the per-decision evidence shapeINDEPENDENTLY VERIFIABLE OFFLINE
→ eu-fintech.pdf