Legal development

MAS SAFR Explained: Singapore's Runtime Governance Standard for Agentic AI in Finance

Blue digital wave

    Key Takeaways

    • AI agents are no longer confined to producing recommendations for human review. Financial institutions are increasingly using AI agents1 to initiate payments, execute trades and draft credit and wealth assessments with limited human intervention.
    • On 3 July 2026, the Monetary Authority of Singapore (MAS) published the Safeguards for Agentic Finance at Runtime (SAFR) white paper - a voluntary, industry-built framework that inserts a governance checkpoint at the moment between an agent's proposed action and its execution.
    • As a runtime, per-action governance architecture for finance, SAFR appears to be the first framework of its kind globally, ahead of comparable US and EU efforts, which either exclude agentic AI from scope or operate at a more general model-governance level.
    • SAFR sits within a wider, and partly-finished, governance stack: MAS' Guidelines on AI Risk Management remain unfinalised, while Infocomm Media Development Authority's (IMDA) economy-wide Model AI Governance Framework for Agentic AI has already been updated once since its launch in January 2026.

    What Changed: The Shift Has Already Happened

    For most of the past decade, AI in financial services meant a model that produced a score, a flag or a recommendation that a human reviewed before anything happened. That review step is now optional in a growing number of live deployments. Financial institutions are already using AI agents to initiate treasury transactions, execute consumer payments, spend digital currencies, and draft source-of-wealth assessments for compliance review.

    The common thread is that existing governance frameworks were not built for this moment. Model risk management validates a model before it goes live. Internal audit samples transactions after they have cleared, often hours or days later. Neither is positioned to catch a bad agent decision in the narrow window that matters, which is the interval between an agent proposing an action and that action executing. That gap is what MAS' SAFR framework is designed to close.

    What Does SAFR Actually Do?

    Published under MAS' BuildFin.ai initiative, and co-authored with several financial institutions and payment networks, SAFR's proposal is a governance checkpoint that operates in between pre-deployment model validation and post-execution audit: at the exact moment an agent proposes an action, before that action executes.

    • Agent Identity: confirms the agent proposing the action is who it claims to be, resolved against a registry, before the action is carried forward to the Controls Repository.
    • Controls Repository: the institution's configurable rulebook that holds the controls where the proposed actions are checked. Controls may be drawn from organisational policies, regulatory requirements and product rules. The mandate captures what the agent may do and the corresponding conditions and limits. An agent cannot expand its own mandate by reasoning inference; authority must be explicit.
    • Disposition Engine: evaluates each proposed action against the Controls Repository and resolves it to one of four outcomes: Auto-Execute, Observe, Escalate, or Deny. These outcomes are calibrated to the action's reversibility, financial materiality, customer impact, regulatory sensitivity and novelty.
    • Audit Log: an append-only, tamper-evident record of every decision, capable of reconstructing what happened without relying on the agent's own account of events.

    Each of these operates together inside what SAFR terms a "Governance Envelope". That is, a package that binds a specific proposed action to the identity that raised it, the mandate it is checked against, and the disposition it receives. Because the envelope wraps each action individually, authority has to be established fresh every time. A multi-step process is thus governed as a sequence of discrete, independently checked actions, not as one authorisation that carries an agent through to the end of a task.

    Is SAFR the First Framework of Its Kind?

    Most AI governance work published globally to date sits at the two ends of the AI lifecycle — policy and risk assessment at the start, audit and monitoring at the end. SAFR is unusual in that it sits in the middle, at the moment of execution, which is arguably where the actual risk of agentic AI lives. As a runtime governance standard specifically for financial services, SAFR appears, at the time of writing, to be the first framework of its kind published anywhere.

    • The EU AI Act primarily regulates AI at the level of the model and its surrounding risk-management system, not at the level of individual action. Moreover, its high-risk system obligations have recently been deferred to December 2027 (for stand-alone high-risk AI systems) and August 2028 (for AI embedded in regulated products).
    • In the United States, the Federal Reserve, the Office of the Comptroller of the Currency and the Federal Deposit Insurance Corporation issued SR 26-2 on 17 April 2026, the first refresh of model risk management guidance to banks in fifteen years. However, it explicitly places generative and agentic AI models outside its scope, describing them as "novel and rapidly evolving".
    • Singapore's own IMDA Model AI Governance Framework for Agentic AI operates one level up from SAFR. It addresses identity, access controls and audit trails for agentic AI deployments generally, but does not itself specify a per-action disposition mechanism of the kind SAFR's Disposition Engine provides.

    How Does SAFR Fit Within MAS' Wider AI Governance Stack?

    SAFR sits on top of a broader, and only partly finished, governance stack that MAS has been building for several years.

    • Proposed MAS Guideliwhnes on AI Risk Management: Consultation closed on 31 January 2026. These will set out MAS' supervisory expectations on AI governance, lifecycle controls and capability requirements for all financial institutions, with a proposed 12-month transition period once issued. The final Guidelines on AI Risk Management are expected to be announced soon.
    • Project MindForge: Pending the finalisation of the Guidelines on AI Risk Management, the industry consortium (MAS with banks, insurers, asset managers and technology firms) has produced an AI Risk Management Executive Handbook, an AI Risk Management Operationalisation Handbook and AI Risk Management Implementation Examples. The Operationalisation Handbook's agentic-specific practices are what SAFR operationalises at runtime.
    • The Future of Finance Institute (FFI): announced 25 June 2026 as part of MAS' efforts to accelerate the adoption of new financial technologies and catalyse innovation in the financial sector, the FFI will maintain an updated AI Risk Management Toolkit and a Programmable Compliance Toolkit as part of its Implementation Toolkits capability. The FFI will also support future adoption of SAFR through industry pilots and sandbox experimentations.

    What Is IMDA's Role Alongside MAS?

    MAS' work sits alongside a broader national push. Singapore's Ministry of Digital Development and Information announced the launch of IMDA's Model AI Governance Framework for Agentic AI (Version 1.0) on 22 January 2026 at the World Economic Forum in Davos. It was described as the first governance framework specifically designed for agentic AI systems.

    The framework applies to all organisations looking to deploy agentic AI in Singapore, whether built in-house or sourced from third parties, and is structured around four dimensions: assessing and bounding risk upfront, ensuring meaningful human accountability, implementing technical controls, and enabling end-user responsibility. IMDA updated the framework on 20 May 2026 (Version 1.5), adding real-world case studies and new best practices on multi-agent systems, third-party agents and automation bias. Compliance is voluntary, but organisations remain legally accountable for their agents' actions regardless. The Model AI Governance Framework has progressively evolved to address new types of AI, starting with Traditional AI (first released in 2019 and updated in 2020), Generative AI (released in 2024), and now Agentic AI. Together, they form one of the world's most comprehensive AI governance frameworks.

    How Does Singapore's Approach Compare?

    Taken together, MAS' and IMDA's publications reflect a deliberate Singapore posture: publish concrete, adoptable architecture and let the industry build directly against it, ahead of finalising the supervisory guidelines that will eventually sit above all of it. SAFR's co-authorship by major global banks and payment networks suggests MAS is deliberately using industry capability to set the technical bar before it writes the rulebook.

    In contrast, while the UK Financial Conduct Authority has stated that it will not introduce new regulations for AI and will instead rely on existing regulatory frameworks2, the Bank of England has recently expressed that "more sophisticated governance and accountability frameworks may be needed" as existing frameworks "were not built to contemplate autonomous agents"3. This could signal the start of a shift in the UK's existing stance.

    There is also a wider global shift towards dedicated agentic AI governance frameworks. The Financial Stability Board (FSB) on 10 June 2026 published a consultation report, Sound Practices for Responsible Adoption of Artificial Intelligence, providing a clear picture of the direction of travel. The report sets out twelve sound practices spanning organisation-wide AI governance and the AI lifecycle, and, notably, includes a dedicated discussion of agentic AI risks, effectively treating AI agents as a distinct risk category rather than an incremental extension of existing AI risk. The FSB consultation confirms that international standard-setters are converging on the same direction as Singapore, even if none has published anything matching SAFR’s move to a runtime, per-action specification – it is likely only a matter of time before comparable runtime frameworks emerge from other jurisdictions.

    Frequently Asked Questions

    What is MAS SAFR?

    SAFR (Safeguards for Agentic Finance at Runtime) is a voluntary framework published by the MAS on 3 July 2026, developed with major global banks and payment networks. It defines how an institution evaluates an AI agent's proposed action using four components: Agent Identity, Controls Repository, Disposition Engine and Audit Log.

    Is SAFR mandatory for financial institutions in Singapore?

    No. SAFR is an industry reference approach, not a regulatory requirement or supervisory expectation. Each institution remains responsible for aligning its own deployment with applicable MAS supervisory expectations and internal governance requirements.

    Is SAFR the first framework of its kind globally?

    SAFR appears to be a first-of-its-kind, runtime, per-action governance standard based on the frameworks publicly available as at August 2026. Comparable efforts elsewhere either exclude agentic AI from scope (the US Federal Reserve's SR 26-2) or govern at the model level rather than the individual action (the EU AI Act).

    Are MAS' AI Risk Management Guidelines already in force?

    No. The consultation closed on 31 January 2026, but the Guidelines have not yet been issued in final form as at the date of this article. MAS has proposed a 12-month transition period once they are finalised. The finalised guidelines are expected to be announced soon.

    What should financial institutions in Singapore do now?

    Three priorities: 

    1. inventory every AI agent capable of initiating payments, trades or other consequential actions, and classify each by reversibility and financial materiality;
    2. assess current governance architecture against SAFR's four components, since it may well become a reference point in MAS supervisory expectations despite its voluntary status; and
    3. begin a gap analysis against the proposed AI Risk Management Guidelines consultation paper, so implementation is not compressed once these are finalised. 

    Authors: Partick Phua (Associate Director / Partner, Singapore / Hong Kong) and Sheena Teng (Senior Associate, Singapore).

    This is a joint publication from ADTLaw LLC (a Singapore law practice) and Ashurst Perkins Coie UK LLP who together form Ashurst ADTLaw , which is a Formal Law Alliance in Singapore.

    Ashurst Perkins Coie UK LLP is licensed to operate as a foreign law practice in Singapore. Where advice on Singapore law is required, Ashurst Perkins Coie UK LLP will refer the matter to and work with ADTLaw LLC or other licensed Singapore law practices where necessary.

    Ashurst Perkins Coie UK LLP is part of the Ashurst Perkins Coie Group, which comprises Ashurst Perkins Coie UK LLP, Ashurst Perkins Coie US LLP, Ashurst Perkins Coie Australia and their respective affiliates (including independent local partnerships, companies or other entities) which are authorised to use the name "Ashurst Perkins Coie" or describe themselves as being affiliated with Ashurst Perkins Coie. Some members of the Ashurst Perkins Coie Group are limited liability entities. Some members of the Ashurst Perkins Coie Group provide legal services and some provide non-legal services. Different legal entities in the group may may operate in the same jurisdictions. Information about which Ashurst Perkins Coie Group entity operates in any country can be found on our website at www.ashurstperkinscoie.com.

    This material is current as at 8 Aug 2026 but does not take into account any developments after that date. It is not intended to be a comprehensive review of all developments in the law or in practice, or to cover all aspects of those referred to, and does not constitute professional advice. The information provided is general in nature, and does not take into account and is not intended to apply to any specific issues or circumstances. Readers should take independent advice. No part of this publication may be reproduced by any process without prior written permission from Ashurst Perkins Coie. We accept no liability for use of these materials and reliance upon it by any person.