新加坡金管局發布 AI 風險管理指引,明確第三方與代理式 AI 的最終責任仍在金融機構Singapore's MAS issues AI risk management guidelines, placing final accountability for third-party and agentic AI on the financial institution
- 事件
- 10 月 7 日,新加坡金融管理局發布《人工智能風險管理指引》,適用於所有金融機構及所有 AI 技術。指引要求董事會與高層問責、建立 AI 用例清單、並就第三方提供的 AI 取得充分保證;分階段自 2027 年 10 月 7 日起生效,2028 年 10 月 7 日全面達標。On 7 October, the Monetary Authority of Singapore issued Guidelines on AI Risk Management applying to all financial institutions and all AI technologies. They require board and senior management accountability, an inventory of AI use cases, and sufficient assurance from third-party AI providers, taking effect in phases from 7 October 2027 and fully by 7 October 2028.
- 背後
- 指引源於 2025 年 11 月的公眾諮詢,最終文本把過渡期由單一 12 個月改為兩階段,並收緊第三方 AI 的責任歸屬。MAS 同時表明將於 2027 年就代理式 AI 的額外指引再作諮詢,反映監管機構承認自主系統的規則尚未定型。The guidelines follow a public consultation in November 2025. The final text replaces a single 12-month transition with two stages and tightens the allocation of responsibility for third-party AI. MAS also said it will consult again in 2027 on additional guidance for agentic AI, acknowledging that rules for autonomous systems are not yet settled.
我們認為,這份指引最值得非金融企業借鏡之處,在於它拒絕把外包當作免責。條文寫得很清楚:金融機構對其提供服務所用的 AI,包括由第三方開發、營運或供應者,仍負最終責任;若風險無法納入自身風險胃納,就應考慮限制、暫停或更換該服務。這等於把「AI 出事誰負責」由供應商問題改寫為採購與治理問題。In our view, the most transferable lesson for non-financial firms is that this framework refuses to treat outsourcing as a shield. The text is explicit: a financial institution remains accountable for the AI used in the services it delivers, including AI developed, operated or supplied by third parties, and should consider limiting, suspending or replacing a service whose risks cannot be brought within its risk appetite. That reframes 'who is liable when AI fails' from a vendor question into a procurement and governance question.
- 對日常工作的影響
- 對法務與合規而言,供應商合約需要加入 AI 專屬的保證、審計與退出條款;對 IT 與採購而言,需要一份可交代的 AI 清單與補償控制;對企業決策者而言,AI 風險自此是董事會層級的議題。For legal and compliance, supplier contracts need AI-specific assurance, audit and exit clauses. For IT and procurement, a defensible AI inventory and compensating controls become necessary. For owners, AI risk is now a board-level agenda item.
- 如何改善
- 本週挑一項外包的 AI 服務,列出服務商、用途、風險等級與現有保證文件;若拿不出保證,先草擬一份補償控制或退出方案。This week, pick one outsourced AI service and list its provider, use, risk tier and existing assurance documents. If assurance cannot be produced, draft a compensating control or an exit plan.
