
Summarize this post with AI
Most blockchain analytics vendors assume blockchain analytics ai governance singapore rules do not apply to them directly, since they are not licensed financial institutions themselves. That assumption is only half right, and the half that is wrong matters. A blockchain analytics firm selling an on chain risk scoring tool is usually not itself regulated under the Payment Services Act, but the moment a bank or digital payment token service provider buys that tool, its AI risk scoring model falls squarely inside AIRG's third party AI scope and MAS's July 2026 AML supervisory expectations for digital payment token service providers. The obligation does not sit with the vendor, it sits with the buyer, and that distinction changes what each side needs to prepare for.
Blockchain Analytics AI Governance Singapore: The Direct Answer
Blockchain analytics ai governance singapore rules apply indirectly to most blockchain analytics vendors and directly to the regulated institutions that buy their tools. MAS's proposed AI Risk Management Guidelines cover third party AI a financial institution procures, and MAS's July 2026 Information Paper on AML/CFT Supervisory Expectations for Digital Payment Token Service Providers sets out detailed expectations for how DPT service providers must assess and monitor ML/TF risk detection tools, including AI driven on chain risk scoring. A blockchain analytics firm that is not itself a licensed DPT service provider is not directly examined by MAS, but its AI model becomes subject to scrutiny the moment a regulated client deploys it.
What blockchain analytics AI governance actually covers
Mas airg blockchain analytics questions usually come down to one thing, on chain risk models. These are AI systems that score wallet addresses, transactions, and counterparties for money laundering or terrorism financing risk using blockchain transaction data, often the core product a blockchain analytics vendor sells.
Digital assets and the tools built to monitor them sit at an unusual regulatory intersection. The vendor building the model is typically a technology company, not a licensed financial institution, while the institution using the model, a bank or a digital payment token service provider, carries the full regulatory weight of both the Payment Services Act and, once finalized, AIRG. Our guide on AI governance for MAS supervised institutions covers how this third party scope applies generally, and our comparison of AI governance framework versus risk management framework covers the distinction between the policy layer and the technical risk layer this specific case sits between.
See Where Your Business Stands on AI Readiness
Why 2026 is the year this distinction stopped being theoretical
Crypto ai compliance singapore obligations moved from a gray area to a documented expectation for three specific reasons.
MAS published detailed AML/CFT expectations for DPT service providers on 13 July 2026. The Information Paper sets out supervisory expectations across the full risk lifecycle, identification, assessment, monitoring, reporting, and governance, applying directly to any AI driven risk detection capability a DPT service provider relies on, whether built internally or bought from a vendor.
AIRG's third party AI clause applies regardless of the vendor's own regulatory status. A blockchain analytics vendor with no MAS licence at all still triggers full due diligence obligations for any regulated institution that deploys its risk scoring model.
The Payment Services Act already gives MAS extraterritorial reach over DPT activity. Since 2021, MAS has directed offshore exchanges serving Singapore users to obtain a licence or exit the market, meaning the AI governance question extends beyond firms physically based in Singapore.
Our guide on Singapore BFSI governance and our overview of AI governance and compliance both cover how this layered obligation, vendor technology plus institutional accountability, plays out in practice for regulated buyers.
The governance framework for blockchain analytics AI
Whether you are the vendor or the buyer, the governance obligation follows a consistent structure.

Determine who holds the direct regulatory obligation. If your institution is a bank or DPT service provider using a vendor's tool, the obligation sits with you, not the vendor, regardless of how sophisticated the vendor's own compliance marketing is.
Assess the vendor's model transparency and fairness practices. AIRG expects due diligence on data, model, and technology risk from third party AI providers, which for an on chain risk model means understanding what data trains its risk scores.
Apply the July 2026 AML expectations to any AI driven detection capability. MAS's information paper expects DPT service providers to assess whether their risk detection tools remain effective, whether built internally or licensed from a vendor.
Document why the specific tool fits your risk profile. A vendor's general accuracy claims do not substitute for your own documented rationale for why its risk scoring approach suits your specific customer base and transaction patterns.
Maintain an ongoing review cycle, not a one time onboarding check. A vendor's on chain risk model updated to reflect new laundering patterns needs re assessment, since your original due diligence no longer reflects the current system.
This is where the engineering execution layer matters. Samta.ai builds the VEDA AI decision analytics platform to track vendor AI risk models, including on chain risk scoring tools, alongside internally built systems in one inventory, integrating with existing Databricks, Snowflake, or Microsoft data infrastructure through our data integration consulting services rather than treating crypto specific tooling as a separate, ungoverned category. Institutions evaluating whether a general analytics platform can hold this evidence should see how VEDA compares to other data intelligence platforms, and the VEDA platform treats vendor and internal AI models under the same governance standard by design. Our AI risk management model governance committee guide covers how this committee structure should actually review a vendor's on chain risk tool before approving it.
Blockchain analytics AI governance by entity type
Entity Type | Directly MAS Regulated? | AI Governance Obligation Source | Third Party AI Due Diligence Needed | Typical Example |
Blockchain analytics vendor, not DPT licensed | No, not directly under the Payment Services Act | Indirect, through clients' AIRG and AML obligations | Should support client due diligence requests | On chain risk scoring tool sold to banks and DPT service providers |
DPT service provider using a vendor's tool | Yes, under the Payment Services Act and Notice PSN02 | AIRG's third party clause plus the July 2026 AML information paper | Full due diligence on the vendor's risk scoring model | A licensed exchange using a vendor's wallet screening API |
Bank using a vendor's on chain risk model | Yes, under existing banking regulation and AIRG | AIRG's third party AI due diligence for procured tools | Full due diligence, contractual protections, ongoing review | A bank screening crypto linked payments using a vendor tool |
Bank operating its own on chain risk model | Yes, under existing banking regulation and AIRG | AIRG's full lifecycle controls for internally built models | Not applicable, the model is built in house | A bank's internally built crypto exposure scoring model |
Analytics firm that is itself a licensed DPT service provider | Yes, if the firm also provides DPT services directly | Both the July 2026 AML paper and AIRG, applied to itself | Applies to its own third party AI vendors, if any | An analytics firm that also operates a token exchange |
Is Your AI Model Risk-Ready? Find Out
Real world enterprise use cases
BFSI: a bank screening crypto linked payments with a vendor's risk model
A bank offering crypto linked payment services relied on a blockchain analytics vendor's risk scoring API to screen transactions, but had never documented why that specific vendor's approach fit its customer risk profile. Extending AI security and compliance services to cover the vendor relationship closed that documentation gap ahead of a scheduled AML review referencing MAS's July 2026 expectations directly.
General enterprise: a blockchain analytics firm preparing for institutional buyers
A blockchain analytics firm selling its on chain risk scoring tool to Singapore banks recognized that institutional buyers would increasingly ask for evidence of model transparency and fairness testing as part of procurement, even though the firm itself carries no direct MAS obligation. Reviewing enterprise AI engineering in Singapore helped the firm build documentation proactively, shortening procurement cycles with regulated buyers who needed that evidence for their own AIRG due diligence.
Key risks and failure modes
Assuming a vendor's compliance marketing satisfies your due diligence obligation. A blockchain analytics vendor's claims about its own model accuracy do not substitute for your institution's documented assessment of fit for your specific use case.
Treating crypto specific AI tools as outside your standard AI governance framework. An on chain risk model is still an AI model subject to the same AIRG expectations as any other procured AI system.
No re assessment when a vendor updates its risk scoring methodology. Laundering patterns evolve, and a vendor's model updated to address new patterns needs fresh due diligence, not a reference to the original onboarding review.
Blockchain analytics vendors assuming no regulatory exposure at all. While the vendor itself may not be directly examined, institutional buyers increasingly require evidence the vendor previously never needed to produce.
Confusing DPT service provider obligations with general AI governance. The July 2026 AML information paper is specific to ML/TF risk, and does not replace the broader AIRG expectations that apply to all AI use, not only crypto specific tools.
When to prioritize this governance gap now
Prioritize immediately when:
Your institution uses a vendor's on chain risk scoring tool for a regulated AML or KYC decision
You are a DPT service provider that has not yet assessed your risk detection capabilities against the July 2026 information paper
No documented rationale exists for why your specific vendor's model fits your customer risk profile
A standard review cycle is enough when:
Due diligence and fit for use documentation already exist for your on chain risk tools
Your vendor relationship already includes contractual protections covering model updates and performance review
Your institution's crypto exposure is limited enough that a lighter touch, proportionate review already applies
Reach out through Samta.ai to scope which side of this relationship you need documentation for first.
Talk to an AI Expert About Your Business Needs

Conclusion
Blockchain analytics ai governance singapore obligations split cleanly along one line, the vendor builds the technology, the regulated institution using it carries the accountability. Institutions that document due diligence against both AIRG and MAS's July 2026 AML expectations, and vendors that get ahead of what their institutional buyers will ask for, will not be scrambling once AIRG finalizes.
About Samta
Samta.ai is a Singapore-headquartered AI Product Engineering & Data Intelligence partner helping enterprises build production-grade AI systems for regulated and data-intensive environments.We help organizations move beyond experimentation by engineering scalable, explainable, and enterprise-ready AI solutions from data foundations and model development to workflow automation and deployment.
Our capabilities combine deep AI expertise, data engineering, and product engineering to deliver measurable business impact across FinTech, BFSI, cybersecurity, regulatory technology, and enterprise operations.
Our enterprise AI products power real-world intelligence systems:
• TATVA : AI-driven data intelligence platform for governed analytics, monitoring, and operational insights
• VEDA : Explainable and audit-ready AI decisioning engine built for compliance-sensitive enterprise workflows
• CORA-Property Management Solutions: : Predictive intelligence platform for real-estate pricing, portfolio optimization, and investment analytics
Backed by ecosystem partnerships with Microsoft, Databricks, Snowflake, and AWS, Samta.ai delivers agile, cost-efficient AI engineering with faster turnaround and enterprise-grade scalability. Trusted by enterprises across FinTech, BFSI, and digital transformation initiatives, Samta.ai embeds AI governance, data privacy, and compliance-by-design principles directly into the AI lifecycle , enabling organizations to scale AI with transparency, accountability, and operational control.
Enterprises leveraging Samta.ai automate 65%+ of repetitive data, analytics, and decision workflows while maintaining governance, explainability, and measurable business outcomes. Samta.ai provides the strategic consulting, AI engineering, and data modernization expertise needed to align enterprise operations with next-generation AI transformation goals.
Frequently asked questions
Does MAS AIRG apply to blockchain analytics firms?
Indirectly. AIRG applies directly to MAS regulated financial institutions, so a blockchain analytics firm without its own licence is not directly examined, but its AI model becomes subject to AIRG's third party due diligence requirements the moment a regulated institution deploys it.
What AI governance rules cover crypto risk scoring models?
Crypto risk scoring models are covered by AIRG's third party AI provisions when procured by a regulated institution, and by MAS's July 2026 Information Paper on AML/CFT Supervisory Expectations for Digital Payment Token Service Providers when used for ML/TF risk detection specifically.
Is a blockchain analytics vendor itself regulated by MAS?
Only if the vendor itself provides digital payment token services directly, such as operating an exchange or custody service. A vendor that purely sells risk scoring software to banks and DPT service providers is not typically a licensed entity under the Payment Services Act.
What changed with MAS's July 2026 AML information paper?
The July 2026 paper set out detailed supervisory expectations for digital payment token service providers across the full ML/TF risk lifecycle, identification, assessment, monitoring, reporting, and governance, giving DPT service providers a specific benchmark to assess their AI driven risk detection capabilities against.
Do banks need to re assess a vendor's on chain risk tool after it is updated?
Yes. A vendor's risk scoring methodology updated to address new laundering patterns changes the system's behavior, meaning the original due diligence no longer reflects the current tool and needs to be reassessed rather than assumed to still apply.
