author image
Arun Singh
Published
Updated
Share this on:

Does MAS AIRG Apply to AI You Buy? The Third-Party Clause Every FI Missed

Does MAS AIRG Apply to AI You Buy? The Third-Party Clause Every FI Missed

Does MAS AIRG Apply to AI You Buy?

Summarize this post with AI

Way enterprises win time back with AI

Samta.ai enables teams to automate up to 65%+ of repetitive data, analytics, and decision workflows so your people focus on strategy, innovation, and growth while AI handles complexity at scale.

Start for free >

Most financial institutions read the MAS AI Risk Management Guidelines and assumed the scope stopped at models their own data science team built. Does MAS AIRG apply to AI you buy? Yes, and the consultation paper is explicit about it, AIRG applies to every financial institution that uses, develops, procures, or deploys AI, including third party AI tools, cloud hosted models, and embedded copilots you never classified as an AI project at all. That single clause turns a manageable internal governance exercise into a full vendor inventory problem, and most institutions have not yet run that inventory.

Does MAS AIRG Apply to AI You Buy: The Direct Answer

Does MAS AIRG apply to AI you buy? Yes. MAS's Guidelines on Artificial Intelligence Risk Management, out for consultation since 13 November 2025, define AI broadly as any system generating predictions, recommendations, decisions, or content through learning or inference, and state explicitly that this scope covers third party AI tools an institution procures, not only systems it builds internally. Even assistive tools like copilots and analytics engines used for decision support, not just autonomous decision making, are expected to carry baseline AI controls under the proposed guidelines.

What counts as AI you buy, and why the term MAS gets confusing

Financial institutions typically think of AI you buy as a licensed machine learning product with a vendor contract and a sales cycle. MAS's proposed scope is wider than that. It covers cloud hosted large language model APIs billed by usage, copilots bundled into software you already license for another purpose, and AI features a vendor added to an existing core banking or CRM system without renegotiating the contract.


There is also a naming collision worth clearing up early. What is MAS in AI? In a regulatory context, MAS is the Monetary Authority of Singapore. In a technical context, MAS also stands for multi agent system, multiple AI agents coordinating to complete a task. Both meanings matter here, since the Monetary Authority of Singapore's AIRG guidelines increasingly need to govern technical multi agent systems, particularly ones procured from a vendor rather than built in house. Our guide on what a multi agent system actually is and how it relates to runtime governance frameworks like SAFR covers this distinction in more technical depth.

See Where Your Business Stands with AI

Why this third party clause matters now in 2026

Mas guidelines on ai risk management have moved from a strategy conversation to a vendor inventory problem for three reasons.

  • The consultation closed on 31 January 2026, and MAS has signaled the guidelines will finalize later this year, with a proposed twelve month transition period once issued, which is a shorter runway than most vendor renegotiation cycles.

  • Third party AI due diligence is explicitly named in the consultation text. The paper sets out expectations for assessing transparency from third party AI providers on data, model, technology, and cybersecurity risks, and for exercising due diligence on a vendor's fairness practices, not just its uptime or security certifications.

  • Multi agent orchestration platforms raise the stakes further. A multi agent ai mas accountability framework now needs to account for emergent behavior between agents from different vendors interacting inside one workflow, which single vendor risk assessments were never designed to catch.

Our third party AI risk guide and our overview of why AI governance for financial institutions has shifted toward vendor accountability both cover this shift in more depth than this article alone can.

The third party AI accountability framework

Closing this gap is less about a single audit and more about a repeatable discovery and monitoring process.

Does MAS AIRG Apply to AI You Buy?
  1. Run a vendor AI discovery exercise. Many AI features arrive bundled inside existing software contracts, a copilot added to a CRM, a fraud scoring feature added to a payments platform, without triggering a new procurement review.

  2. Classify third party AI by risk materiality. Impact, complexity, and reliance determine how much due diligence a given vendor tool needs, in line with the proportionate approach MAS applies throughout the AIRG.

  3. Assess vendor transparency before and after onboarding. Where a vendor cannot provide explainability for its model, compensatory measures, additional testing, greater human oversight, or clearer user disclosures, become the fallback MAS expects.

  4. Secure contractual protections covering data handling and performance standards. Existing vendor contracts signed before AIRG's scope was clear often lack these clauses entirely and need amendment.

  5. Review third party AI performance on a recurring cycle, not only at onboarding. A vendor model retrained or updated after initial due diligence needs re assessment, not a one time sign off.

  6. Maintain an exit plan for critical AI vendors. Outsourcing the technology should not mean outsourcing accountability for what happens if the vendor relationship ends.

This is where the engineering execution layer matters. Samta.ai builds the vendor AI inventory and monitoring infrastructure that turns this six step process into a working system, using the VEDA AI decision analytics platform to track vendor AI risk materiality alongside internally built models in one place, rather than in a separate spreadsheet nobody updates after the first review. Firms scoping the cost of a formal review should also see our guide to AI model risk assessment, and our broader overview of AI governance for MAS supervised institutions covers how this fits the wider examination cycle.

AI sourcing models and AIRG coverage at a glance

AI Sourcing Model

Covered by AIRG?

Due Diligence Required

Contractual Protections Needed

Accountability Owner

Internally built models

Yes, full lifecycle controls apply

Standard model risk validation

Not applicable, built in house

Model risk governance committee

Licensed AI software or copilots

Yes, as third party AI

Vendor AI capability assessment before procurement

Data handling and performance standard clauses

Business unit plus vendor risk function

Cloud hosted large language model APIs

Yes, as third party AI

Ongoing performance review, not only at onboarding

Data residency and model version change clauses

Technology risk plus model owner

Vendor multi agent orchestration platforms

Yes, treated as higher risk given emergent behavior

Testing of agent to agent interactions, not only single agent behavior

Escalation and kill switch clauses for autonomous actions

CRO plus technology risk jointly

AI embedded inside another vendor's core system

Yes, even when not marketed as an AI feature

Discovery exercise to surface AI inside existing contracts

Amendment of existing contracts to cover AI specific risk

Vendor risk management function

Understand Your AI Model Risk Exposure

Real world enterprise use cases

BFSI: a bank discovering embedded AI across six vendor contracts

A bank running a vendor AI discovery exercise for the first time found AI features embedded in six existing contracts, none of which had been through an AI specific risk review, a fraud scoring add on, a document processing copilot, and a chat based customer service layer among them. Aligning this with our overview of Singapore BFSI governance and AI security and compliance services gave the bank a prioritized remediation list rather than six separate emergency contract renegotiations.

General enterprise: a proptech firm relying on a vendor's multi agent leasing assistant

A proptech firm using a vendor supplied multi agent system to automate parts of its leasing workflow had never assessed how the individual agents interacted with each other, only that the vendor's overall output looked correct. Reviewing this against our enterprise AI engineering in Singapore overview helped the firm add agent to agent interaction testing to its vendor review process before a client audit raised it first.

Key risks and failure modes

  • Assuming procurement review already covers AI risk. A standard vendor security review rarely asks about model transparency, fairness testing, or explainability, which are the specific questions AIRG's third party clause raises.

  • Treating embedded AI as outside scope because it was not sold as an AI product. MAS's broad definition covers any system generating predictions, recommendations, or decisions through learning or inference, regardless of how the vendor marketed it.

  • Reviewing a multi agent vendor platform as if it were a single model. Emergent behavior between agents is a distinct risk category that single agent testing does not surface.

  • No re assessment cadence after initial vendor onboarding. A vendor model updated or retrained after the original due diligence needs a fresh review, not a reference to the original sign off.

  • No exit plan for a critical AI vendor. Institutions that have not tested what happens if a vendor relationship ends discover this gap during the worst possible moment, not during a calm planning cycle.

When to escalate a third party AI gap

Escalate immediately when:

  • A vendor AI tool influences a credit, fraud, or advisory decision without a documented risk materiality assessment

  • A multi agent vendor platform can take autonomous action with no tested escalation or kill switch clause

  • An existing vendor contract has no data handling or performance clause covering its AI features at all

A standard review cycle is enough when:

  • The vendor AI tool is assistive rather than decision making, and already has baseline controls in place

  • The gap is a documentation update rather than a missing due diligence step

  • The vendor has already provided the transparency and fairness evidence MAS expects, just not in a centralized location

Reviewing our guide on AI regulatory compliance in Singapore alongside Samta.ai's case studies gives a useful benchmark for how other institutions have sequenced this work.

Explore the Right AI Strategy for Your Business

Does MAS AIRG apply to AI you buy?

Conclusion

Does MAS AIRG apply to AI you buy? Yes, and that clause is the part of the guidelines most institutions have not yet operationalized. The gap is rarely a lack of internal model governance, it is a vendor inventory nobody has run against the AIRG's actual definition of AI. Institutions that close that gap now will not be scrambling once the guidelines finalize.

About Samta

Samta.ai is a Singapore headquartered AI product engineering and data intelligence partner helping enterprises build production grade AI systems for regulated and data intensive environments. We help organizations move beyond experimentation by engineering scalable, explainable, and enterprise ready AI solutions, from data foundations and model development to workflow automation and deployment.

Our capabilities combine deep AI expertise, data engineering, and product engineering to deliver measurable business impact across FinTech, BFSI, cybersecurity, regulatory technology, and enterprise operations.

Our enterprise AI products power real world intelligence systems:

  • TATVA: AI driven data intelligence platform for governed analytics, monitoring, and operational insights

  • VEDA: Explainable and audit ready AI decisioning engine built for compliance sensitive enterprise workflows

  • CORA Property Management Solutions: Predictive intelligence platform for real estate pricing, portfolio optimization, and investment analytics

Backed by ecosystem partnerships with Microsoft, Databricks, and Snowflake, Samta.ai delivers agile, cost efficient AI engineering with faster turnaround and enterprise grade scalability. Samta.ai embeds AI governance, data privacy, and compliance by design principles directly into the AI lifecycle, enabling organizations to scale AI with transparency, accountability, and operational control. Institutions evaluating fit should ask for measurable outcomes from a comparable prior engagement rather than headline automation figures alone.

Frequently asked questions

  1. Does MAS AIRG apply to AI you buy from a vendor?

    Yes. The AIRG consultation paper explicitly states the guidelines apply to financial institutions that use, develop, procure, or deploy AI, including third party AI tools, not only systems built internally by the institution's own teams.

  2. What is MAS in the context of AI, the regulator or the technical term?

    Both meanings apply here. MAS refers to the Monetary Authority of Singapore, the regulator issuing the AIRG guidelines, and separately to multi agent system, a technical term for multiple AI agents coordinating on a task, which the regulator's guidelines increasingly need to cover.

  3. Does a copilot or assistive AI tool count as AI under AIRG?

    Yes. MAS's proposed guidelines state that even AI assistive tools used for decision support, such as copilots and analytics engines, are expected to maintain baseline AI controls, even where the institution's overall AI use is otherwise limited.

  4. What due diligence does AIRG expect for third party AI vendors?

    Institutions are expected to assess a vendor's transparency around data, model, technology, and cybersecurity risks, exercise due diligence on the vendor's fairness practices, and apply compensatory measures such as additional testing where full explainability is not available.

  5. How does a multi agent vendor platform change third party AI risk?

    Multi agent platforms introduce emergent behavior between agents that single agent testing does not catch, which is why a multi agent ai mas accountability framework typically requires testing agent to agent interactions specifically, not only the vendor's overall output quality.

Related Keywords

Does MAS AIRG Apply to AI You Buy?multi agent ai mas accountabilitymas guidelines on aiwhat is mas in aimulti agent ai mas accountability frameworkmas guidelines on ai risk managementmas multi agent systemwhat is a multi-agent system mas