AI Risk Governance
Framework
Operationalising AI Governance - A Practical 7
Pillar Framework for Risk and Gap Assessment
Disclaimer: This framework is based on industry practice and regulatory research
and is intended for discussion purposes only. It does not constitute legal advice.
4
How to do gap assessment using this framework
Benchmark your AI governance against the 7-pillar framework
Assess your current AI governance posture by mapping your existing Group or entity-level framework against this 7-pillar structure.
Step 5
Contents
Step 4
Contents 5. Assess each identified gap using a
defined maturity scale (1 = least
compliant, 5 = fully compliant). Priorities
4. Validate lifecycle & remediation based on risk tier and
Step 3
Contents oversight (Pillars 6–7): potential customer impact, addressing
Check model lifecycle high-risk exposures first.
3. Apply risk controls and board
Step 2
Contents assessment (Pillar 5): reporting readiness.
Score each use case by
2. Build AI impact, complexity,
Step 1
Contents inventory (Pillar 4): customer/conduct risk.
Register all AI systems,
1. Map existing policies/ including third-party and
This structured approach
Build new agentic AI. delivers a clear remediation
policies (Pillars 1–3): roadmap aligned with
Strategy, governance regulatory expectations and
policy, control standards.
industry standards
Direction → Rules → Controls → Inventory → Assessment → Lifecycle → Oversight
Appendix
Pillar 1 - AI Strategy and Risk Appetite
Establish clear board-endorsed direction, boundaries, accountability and governance architecture for AI use across the
enterprise.
AI scope and permitted AI Governance Structure
AI Strategy Statement AI Risk Appetite use statement and Approval Framework
Why are we using AI and How much AI risk are we willing What counts as AI and what Who is accountable and
where? (Illustrative) to take? is allowed? who approves AI?
o What business problems AI o Defined tolerance levels. (e.g. for o Clear AI definition o AI Governance Forum and
is solving discrimination, regulatory breach) o Enterprise-wide scope (incl. o Mandate
o Where AI will be deployed o Monitoring & breach management third parties) o Approval Workflow
o What we will NOT use AI for o Alignment with capital / resilience o Risk-tier classification o Formal escalation
o Permitted vs prohibited use pathways
o Mandatory human oversight
for high-impact AI
Primary Cross
Anchor reference
P2 - AI Governance P5- Enterprise wise Risk P2- AI Governance Policy
P2 - AI Governance Policy
Policy Appetite Statement
Risk Management Policy/ Board/ Board or
Corporate Strategy / Risk Management Policy/ AI Outsourcing / Third-Party Management Risk
Business Plan Governance Policy Risk Policy Committee Charter
Pillar 2 - AI Risk Governance Policy
To establish a structured, risk-based governance framework for the identification, assessment, approval, monitoring and
control of AI systems, ensuring alignment with MAS expectations.
Scope & Definition of AI AI Risk Identification &
Purpose Governance & Accountability
Systems Classification
o Clear policy objective o Practical AI definition o AI Governance Forum o Mandatory pre-deployment risk
o Applicability (entity-wide) o Inclusion of third-party AI o Three Lines of Defense assessment
o Regulatory references (linkage o Materiality thresholds responsibilities o Risk-tier classification
to MAS TRM, MRM, FEAT, o Risk-tier classification o RACI methodology
Outsourcing) o Permitted vs prohibited use o Board oversight role o Risk dimensions (Model risk,
Operational risk, conduct risk,
Tech risk, Outsourcing risk etc.)
Fairness, Accountability & Monitoring & Incident Third-Party & Outsourced AI
Risk & Approval
Human Oversight Management Controls
o Documentation requirements o Bias assessment requirements o Performance monitoring o Due diligence requirements
o Second-line review o Human-in-the-loop thresholds requirements o Contractual safeguards
requirement o Override protocols o Drift detection expectations o Ongoing monitoring
o Approval authority by risk tier o Decision explainability o Revalidation frequency o Concentration risk
o Prohibition of production expectations o Incident reporting triggers considerations
without approval o Accountability for outcomes o Breach escalation procedures o Data residency considerations
o Escalation triggers (if applicable)
Documentation, Audit & Record Keeping
AI inventory requirement I Record of approvals I Audit access I Regulatory reporting readiness I Retention standards
Pillar 3 – Control Standards (1/2)
To establish minimum enterprise-wide control standards governing the design, deployment, monitoring and remediation of AI
systems to ensure safe, fair and compliant operation.
1. AI Risk Management 2. Ethical & Customer Protection 3. Third-Party AI Oversight
✓ All AI systems must undergo documented risk ✓ AI systems must be assessed for bias and ✓ All third-party AI solutions shall undergo
assessment before deployment. discriminatory outcomes. structured risk assessment
✓ AI use cases must be classified by impact (Low / ✓ High-impact customer decisions must ✓ AI-specific due diligence must be performed
Medium / High). include human oversight. before engagement.
✓ High-impact AI requires independent second-line ✓ Customer-facing AI must be explainable and ✓ Contracts must include transparency, audit
review. reviewable. rights, and data protections.
✓ Models must be validated before production and ✓ AI-driven decisions must be challengeable ✓ Vendor performance and model changes must
periodically thereafter. by customers. be monitored.
✓ Performance and drift must be monitored with ✓ Conduct risk assessments must include AI- ✓ Critical outsourced AI must have contingency
defined escalation thresholds. related risks. or exit plans.
✓ AI risks must align with enterprise risk appetite ✓ Material ethical concerns must be escalated ✓ All outsourced AI must comply with MAS
and be reported to governance forums.. to governance committees. Outsourcing Guidelines.
Focus: Controlled deployment, Focus: Fair treatment of policyholders Focus: No blind reliance on vendors
validation, monitoring
Primary Cross
Anchor reference
Enterprise Risk Management Policy Fair Treatment of Customers Policy Outsourcing Policy
AI Governance Policy (Pillar 2) I Complaint AI Governance Policy (Pillar 2) I Information
AI Governance Policy (Pillar 2)
Handling Policy Security Policy
Pillar 3 – Control Standards (2/2)
4. Data Governance Linkage 5. AI Incident & Remediation 6. AI Cyber & Technology Risk
✓ AI data must meet defined quality and validation ✓ AI-related incidents must be formally ✓ AI systems shall operate within secure,
standards. defined and reported promptly. segregated and access-controlled
✓ Data lineage and ownership must be clearly environments.
✓ High-risk incidents must trigger immediate
documented. containment. ✓ Access to AI models, data, and APIs must
✓ Personal and sensitive data use must comply follow strict role-based controls.
✓ Root cause analysis must be conducted for
with data protection laws. material failures. ✓ Models must be protected against
✓ Access to AI datasets and models must be adversarial, extraction, and manipulation risks.
✓ Customer impact must be assessed and
controlled. addressed. ✓ Secure MLOps must govern deployment,
✓ Data drift must be monitored for material AI change management, and rollback.
✓ Remediation actions must be documented
systems. and tracked. ✓ High-impact AI must undergo independent
✓ Data breaches impacting AI must trigger security testing.
✓ Regulatory notification obligations must be
escalation. assessed. ✓ AI incidents must follow enterprise cyber
response and resilience frameworks.
✓ Lessons learned must feed back into control
improvements.
Focus: Data integrity and privacy Focus: Controlled response and Focus: Secure, resilient, and
regulatory defensibility. controlled AI deployment
Primary Cross
Anchor reference
Data Governance Policy (if any) Enterprise Risk Management Policy Technology Risk Management Guidelines
AI Governance Policy (Pillar 2) I Data Privacy Policy
Customer Remediation Policy AI Governance Policy (Pillar 2) I Third Party
I Technology Risk Management Policy
Pillar 4 – AI Inventory
Maintain a complete and accurate register of all AI systems to enable oversight, accountability and regulatory defensibility.
System Identification Risk Materiality Governance & approval Validation & Controls
o Risk Tier (Low / Medium / o Risk Assessment Completed
o AI System Name (Yes/No) o Validation Required (Yes/No)
High)
o Unique Identifier o Approval Authority (Business / o Validation Status (Completed
o Customer Impact (Yes/No)
o Business Owner AI Forum / CRO / Board) / Pending / Overdue)
o Regulatory Sensitivity
o Technical Owner o Deployment Approved (Yes/No) o Bias Testing Completed
(Yes/No)
o Deployment Status (Dev / o Board Reporting Required (Yes/No)
o Use of Personal / Sensitive
UAT / Prod / Retired) (Yes/No) o Human Oversight Required
Data (Yes/No)
o Go-Live Date (Yes/No)
o Traditional ML models, Gen
AI, or Agentic AI
Monitoring Status Third-Party & Outsourcing Data Governance Lifecycle Status
o Primary Data Source o Last Material Model
o Monitoring Owner o Vendor Involved (Yes/No) o Personal Data Used
o Drift Monitoring Change
o Vendor Name (Yes/No)
Implemented (Yes/No) o Next Review Due
o Critical Outsourcing o Sensitive Data Used
o Incident in Last 12 o Retirement Planned
(Yes/No) (Yes/No)
Months (Yes/No) (Yes/No)
o AI-Specific Due Diligence o Data Lineage
o Highest Incident Severity) o Record Status
Completed (Yes/No) Documented (Yes/No)
o Exit/Contingency plan
Pillar 5– AI Risk Assessment
Evaluate every AI system across six risk dimensions before deployment and throughout its lifecycle.
Strategic and Business Risk Operational & Resilience Risk Model & Data Risk
o Purpose of AI use case o Model complexity
o System integration risk
o Alignment with AI Strategy o Model lifecycle controls
o Fallback mechanism?
o Materiality to business processes o Transparency level
o Business continuity plan?
o Revenue or capital impact potential o Training methodology
o Incident response defined?
o Dependency risk o Independent review required?
o Cyber exposure?
o Performance monitoring design
o Drift risk
Third-Party & Outsourcing Risk Customer & Conduct Risk Regulatory & Compliance Risk
o Internal vs outsourced? o Customer impact (Yes/No) o MAS sensitivity?
o Critical outsourcing? o Automated decisioning? o Cross-border implications?
o Vendor concentration risk? o Business sensitivity? o Disclosure obligations?
o Contractual safeguards in place? o Fairness & bias risk o Audit trail sufficiency
o Data residency risk? o Human oversight required? o Personal data used?
o Explainability level required? o Sensitive data (health, financial)?
o Data quality validation performed?
o Data lineage documented?
o Data drift risk?
Note: AI systems already in production should be onboarded into Pillar 4 (Inventory) and assessed under Pillar 5 from day one, not just new
deployments.
Pillar 6– Model Lifecycle Governance (1/2)
To ensure AI systems are governed throughout their operational lifecycle, from development through decommission
Stage 1 – Initiation & Risk Stage 2 – Design & Stage 3 – Independent Stage 4 – Approval &
Classification Development Validation Deployment
Key Controls Key Controls Key Controls Approval Authority
✓ Define business purpose ✓ Clear model documentation ✓ Validation independent from ✓ Low: Business Owner
✓ Identify data sources ✓ Data quality standards model developer ✓ Medium: AI Governance
✓ Perform AI Risk Assessment ✓ Bias testing methodology ✓ Assess: methodology, data Forum
✓ Assign risk tier (Low / ✓ Explainability design integrity, assumptions, ✓ High: ERC / Board visibility
Medium / High) ✓ Embedded lifecycle controls stability, performance, bias, Deployment Controls
✓ Identify regulatory sensitivity ✓ Version control & traceability regulatory alignment ✓ Version control
(customer impact / financial High-Risk Add-ons ✓ Monitoring metrics defined
decision impact) ✓ Formal documentation pack Outputs ✓ Escalation thresholds
✓ Stress & scenario testing ✓ Formal Validation Report established
Outputs ✓ Clear human oversight ✓ Remediation Tracking Log ✓ Monitoring ownership
✓ Risk Assessment Record design ✓ Approval Recommendation assigned
✓ Approval to Proceed (per Control Rule
Approval Framework Outputs ✓ No production deployment Outputs
Model documentation pack (tier- without validation clearance ✓ Deployment approval / go-
based) (Medium/High) live sign-off
Connected with
P1, P2, P4, P5 P2, P3, P4 P3, P5, P7 (High risk) P1, P2, P4
Pillar 6– Model Lifecycle Governance (2/2)
To ensure AI systems are governed throughout their operational lifecycle, from development through decommission
Stage 5 – Ongoing Stage 6 – Change Stage 7 – Periodic Review Stage 8 –
Monitoring Management & Re-Certification Decommissioning
Key Controls Key Controls Key Controls Key Controls
✓ Performance monitoring ✓ Re-assessment ✓ Re-validation ✓ Document reason
✓ Drift detection ✓ Re-validation (if material) ✓ Risk tier re-assessment ✓ Ensure safe shutdown
✓ Fairness metrics ✓ Re-approval ✓ Performance back-testing ✓ Archive documentation
✓ Exception tracking & incident ✓ Governance review ✓ Remove from inventory
logging Material Change Examples ✓ Confirm no residual
✓ Override rate monitoring ✓ New data sources, new Outputs dependencies
✓ Complaint trends logic, recalibration, change ✓ Re-certification decision
High-Risk Add-ons in use, performance shift (continue / remediate / retire) Outputs
✓ Periodic formal performance ✓ Retirement record +
review Outputs inventory update
✓ Reporting to governance ✓ Change control record + re-
committees approval decision Governance Requirement
Outputs ✓ Board visibility for material
✓ Monitoring dashboards & model retirement
exception logs
Connected with
P3, P4, P5, P7 P2, P3 - P7 P1, P3 - P7 P2, P3, P4
Pillar 7– Enterprise Monitoring & Board Reporting
To ensure ongoing enterprise-wide monitoring, reporting, independent assurance and continuous improvement of AI
governance, commensurate with risk and regulatory expectations.
1. Operational Level 2. Enterprise AI Risk Aggregation 3. Board Level Reporting
AI Governance Forum / Model Owners Executive Risk Committee Reporting Board Risk Committee / Board
Are individual AI systems operating safely Is AI risk exposure within appetite and are Are we protected, compliant, and strategically
and within defined controls? controls effective? aligned?
Focus Area Focus Area Focus Area
Enterprise Risk Exposure: AI risk-tier AI Risk Position: Aggregate AI exposure, High-
Model Health - Drift monitoring, Performance distribution (Low / Medium / High), Customer- risk AI count, Material AI systems
thresholds, Override rates impacting AI systems, High-risk vendor
concentration, Exposure trend over time Significant Events: Material AI incidents
Lifecycle Compliance - Validation due /
Regulatory inquiries, Customer impact events
overdue, Change approvals, Re-certification Control Effectiveness: % of high-risk AI
status validated on time, Incident trend, Drift / bias Governance Effectiveness: Validation
monitoring trend, Independent validation coverage coverage, Control effectiveness summary,
Incident & Remediation - Open issues, Root
Internal audit findings, Outstanding remediation
cause analysis, Remediation progress Risk Appetite Alignment- Exposure vs tolerance, actions
Near breaches, Escalations
Vendor Oversight - SLA breaches, Model
Strategic & Regulatory Alignment: AI use
updates pending review Emerging Risk View: New high-risk AI aligned with approved strategy, Compliance with
deployments, Regulatory developments, Technology Risk/ Outsourcing /Cross-border or
Concentration risks sensitive AI exposure
o Monthly dashboard o Quarterly ERC report o Quarterly Board AI Risk Report
o Escalation of material exceptions to Executive o Material issues escalated to Board Risk o Formal Board Attestation / Management
Risk Committee Committee Assurance
The Path Forward
We are Here
Executive Governance AI Risk & Gap Executable Embedding AI Board Level
Alignment Forum Assessment plan controls Monitoring
1-2 months 1–2 months 2–3 months 1–2 months 3–4 months Starts by month
(overlapping with (can overlap 6–8, then
Phase 1 end) with Phase 3) ongoing
9 –12 months Journey
Thank You
A practical 7-pillar blueprint for operationalising AI governance