author image
Arun Singh
Published
Updated
Share this on:

SAFR vs AIRG: What Singapore Businesses Need to Know About AI Governance

SAFR vs AIRG: What Singapore Businesses Need to Know About AI Governance

SAFR vs AIRG

Summarize this post with AI

Way enterprises win time back with AI

Samta.ai enables teams to automate up to 65%+ of repetitive data, analytics, and decision workflows so your people focus on strategy, innovation, and growth while AI handles complexity at scale.

Start for free >

Most teams preparing for MAS scrutiny treat SAFR vs AIRG as a single question with one answer, when it is actually two frameworks solving two different problems. AIRG is a broad supervisory guideline covering how a financial institution governs AI across its full lifecycle. SAFR is a narrow runtime standard covering what happens the instant an AI agent tries to act. Confusing the two leads firms to either overbuild controls for a model that never acts autonomously, or underbuild controls for an agent that executes trades and payments in real time. Here is what each one actually covers, how they relate, and what to build first.

SAFR vs AIRG:

SAFR (Safeguards for Agentic Finance at Runtime) is an industry white paper published by the Monetary Authority of Singapore on 3 July 2026 under its BuildFin.ai initiative, proposing governance checkpoints that verify and record an AI agent's proposed action before execution. AIRG (Guidelines on Artificial Intelligence Risk Management) is a broader supervisory consultation MAS issued on 13 November 2025, setting institution wide expectations for AI governance, covering board oversight, AI inventory, risk materiality assessment, and lifecycle controls. SAFR governs agent behavior at the point of action, while AIRG governs how the whole organization manages AI risk. Neither replaces the FEAT principles, both build on them.

What is SAFR and what is AIRG

SAFR stands for Safeguards for Agentic Finance at Runtime. It is a technical, runtime governance layer that sits between an AI agent and the systems it acts on, evaluating each proposed action against predefined mandates before allowing it to execute, escalating it to a human, or rejecting it outright. It was developed jointly by MAS and financial institutions specifically for agentic AI, systems that plan, select tools, and initiate actions without continuous human direction. The white paper describes this as a shift from static model oversight, where a system generates an output for later human review, toward runtime control, where a system can act directly in a live environment and therefore needs a checkpoint at the moment of action.


AIRG stands for Guidelines on Artificial Intelligence Risk Management. It is a proposed SAFR AI governance framework counterpart at the institutional level, requiring financial institutions to maintain a complete AI inventory, run risk materiality assessments across impact, complexity, and reliance, and apply proportionate controls to data management, fairness, transparency, explainability, and human oversight across the full AI lifecycle. This is the broader AI risk management Singapore standard that SAFR operates underneath. Where FEAT set out voluntary principles, AIRG turns those principles into supervisory expectations that boards and risk functions can be held accountable for.

Why the distinction matters now in 2026

Singapore's AI governance architecture has become layered, and firms that treat it as one document risk missing half the obligation.

  • AIRG's consultation closed on 31 January 2026, and MAS has signaled the guidelines will be finalized before the end of the year, with a proposed twelve month transition window once issued.

  • SAFR is not regulatory guidance. It is framed as an industry reference standard, not supervisory expectations, so adoption is currently voluntary even though MAS jointly developed it.

  • Agentic AI adoption is accelerating faster than static model use, so institutions running autonomous agents for payments, treasury, or advisory tasks face a runtime risk that AIRG's lifecycle controls alone were not built to address in real time.

  • Fragmentation is already a known problem. MAS has noted that institutions building agentic guardrails independently, per team, end up with controls that are not interoperable, which is part of why SAFR exists as a shared standard.

Firms building out their broader responsible ai governance framework should read how MAS's supervisory expectations are evolving in our guide on what MAS actually expects from AI governance, and how that fits alongside broader AI governance and compliance obligations financial institutions already carry.

Make Smarter AI Decisions with a Free Readiness Assessment

From FEAT to AIRG to SAFR: the evolution of Singapore's AI governance stack

  • Singapore's AI governance approach did not appear all at once, and understanding the sequence helps explain why SAFR and AIRG look so different from each other.MAS first published the FEAT principles, Fairness, Ethics, Accountability, and Transparency, as a voluntary, principles based starting point for financial institutions using AI and data analytics. FEAT gave firms a shared vocabulary for responsible AI without prescribing specific controls, timelines, or enforcement mechanisms.

  • As generative AI and agentic systems moved from pilots into production, that voluntary approach stopped being sufficient. AIRG is MAS's answer at the institutional level, translating FEAT's principles into formal expectations: name an accountable owner, maintain an inventory, assess materiality, and apply lifecycle controls proportionate to risk. It is broad by design, since it needs to cover every AI model, system, and use case a financial institution might run, from a simple credit scoring model to a fully autonomous trading agent.

  • SAFR fills a gap AIRG's institutional lifecycle controls do not close on their own, real time verification of an agent's action. A firm can have a complete AI inventory and a well documented risk materiality assessment and still have no mechanism to stop an agent from executing a payment outside its mandate in the seconds before the transaction clears. SAFR was jointly built with industry to solve that operational gap, which is also why it reads more like a technical specification than a governance policy.

  • Readers who want the fuller regulatory picture, including how FEAT, AIRG, and SAFR sit alongside Singapore's Model AI Governance Framework and Project MindForge, should see the complete guide to Singapore's AI governance landscape, and our broader AI governance framework for 2026 roadmap.

    The framework and process: how SAFR and AIRG fit together

Both frameworks are best understood as layers, not competitors.

SAFR and AIRG
  1. AIRG sets the institutional layer. Board and senior management define AI risk appetite, maintain an AI inventory, and classify each model or agent by impact, complexity, and reliance.

  2. AIRG defines lifecycle controls. Data management, fairness testing, explainability, and human oversight requirements apply across development, deployment, and monitoring.

  3. SAFR defines the runtime layer for agentic systems specifically. Where an AI agent can initiate a payment, trade, or filing, SAFR adds governance checkpoints that evaluate the proposed action deterministically before it executes.

  4. SAFR produces the audit trail AIRG expects. The decision point logging SAFR generates becomes part of the evidence an institution needs to demonstrate AIRG level oversight for its agentic deployments.

  5. Both trace back to FEAT. Fairness, ethics, accountability, and transparency remain the underlying principles both frameworks operationalize differently.

This is where the engineering execution layer matters. Samta.ai builds the ai implementation controls that turn AIRG's inventory and risk materiality requirements into a working system, and the runtime checkpoints SAFR describes into actual deployed code, often integrating with existing Databricks, Snowflake, or Microsoft data infrastructure so the control layer sits on top of systems you already run. Firms mapping this against their existing model governance work should also see our guide to AI model risk management, since AIRG's risk materiality assessment builds directly on that discipline. Institutions that want a single system of record for their AI and agent inventory, aligned to both frameworks, typically evaluate the VEDA AI decision analytics platform, which centralizes the governance evidence both SAFR and AIRG require.

SAFR vs AIRG at a glance

SAFR and AIRG do not sit in isolation, they are part of a wider stack of AI governance frameworks Singapore firms now need to track. The table below places both alongside the other frameworks most relevant to BFSI and enterprise AI teams.

Framework

Governance Layer

Scope

Binding Status

Best For

FEAT (2018)

Principles, foundational

Financial institutions using AI and data analytics in decision making

Voluntary principles

Firms setting a baseline responsible AI standard

Model AI Governance Framework for Agentic AI (IMDA, updated May 2026)

Institutional, agentic design

Agentic AI systems across all sectors, not just BFSI

Voluntary guidance

Firms bounding agent autonomy and defining human checkpoints

AIRG

Institutional, full lifecycle

All AI models, systems, and use cases at financial institutions

Supervisory guidelines, expected to finalize in 2026

All MAS regulated financial institutions

SAFR

Runtime, point of action

Agentic AI in financial services

Industry white paper, voluntary

Firms deploying autonomous payment, treasury, or advisory agents

NIST AI RMF

Institutional, international benchmark

Any organization managing AI risk

Voluntary framework, United States origin

Firms benchmarking against a global standard alongside local rules

Identify Hidden Risks Across Your AI Models

Real world enterprise use cases

BFSI: a bank deploying an agentic treasury workflow

A bank rolling out an AI agent to execute intra day treasury transfers needed both layers at once. AIRG governance required a documented risk materiality assessment and a named accountable owner before deployment. SAFR then supplied the runtime checkpoint that verified each proposed transfer against the agent's mandate before execution, closing the gap between policy and live action. Without that runtime layer, the bank's AIRG documentation would have described a control that did not actually exist at the point of execution.

Insurance: a claims advisory agent with escalation limits

An insurer testing an AI agent to triage claims payouts faced a narrower but still material risk, an agent recommending a payout outside its delegated authority. Mapping this to AIRG's materiality dimensions, impact, complexity, and reliance, classified it as medium risk, which under a proportionate approach still required human sign off above a defined payout threshold. A SAFR style runtime checkpoint enforced that threshold automatically rather than relying on staff to catch exceptions manually.

General enterprise: a proptech firm preparing to sell into BFSI clients

A proptech firm building an AI agent for lease negotiation support does not fall under MAS supervision directly, but its BFSI customers now ask for evidence of an ai agent governance framework during procurement. Aligning its controls to SAFR's runtime pattern, even voluntarily, gave the firm a credible answer during vendor security reviews, and referencing AI security and compliance services as part of its own vendor documentation helped shorten procurement cycles with regulated clients.

What a governance platform needs to support both frameworks

Meeting AIRG and SAFR together is less about buying a single tool and more about having one system of record that both layers can write to. A platform supporting this needs at minimum an AI and agent inventory with risk materiality tagging, a runtime log of agent decisions and escalations, and dashboards that map both back to named accountable owners for board reporting.


This differs from a general data intelligence platform, since most of those are built for analytics rather than governance evidence. Firms evaluating vendors should look closely at how VEDA compares to other data intelligence platforms, since the distinction matters when an examiner asks for a specific agent's decision history rather than an aggregate dashboard. The VEDA platform is built around that inventory and decision log requirement from the ground up. Teams that have already implemented this kind of governance layer, including Samta.ai case studies across BFSI and proptech, generally report that the hardest part is not the runtime checkpoint logic, it is getting a clean, complete inventory in place first, which is exactly where AIRG's requirements and SAFR's operational needs overlap. Firms scoping this work alongside broader technology delivery should also see our overview of enterprise AI engineering in Singapore, since governance platform build outs are usually planned alongside wider AI infrastructure decisions rather than in isolation.

Key risks and failure modes

  • Treating SAFR as a compliance requirement. Since SAFR is currently voluntary, firms sometimes deprioritize it entirely, then discover their AIRG audit trail has no runtime evidence for agentic decisions.

  • Treating AIRG as covering runtime behavior. AIRG sets lifecycle expectations, but it does not specify how an agent's action should be verified in the moment, that is SAFR's job.

  • Building agent controls per team, per deployment. Without a shared framework, institutions end up with fragmented, non interoperable guardrails, which is precisely the fragmentation MAS built SAFR to address.

  • Waiting for AIRG to finalize before acting. The proposed transition period is generous, but firms mapping their ai security governance framework now avoid a scramble once the guidelines are issued.

  • Assuming a general purpose analytics tool covers governance evidence. A dashboard built for business intelligence rarely captures the decision point logging an examiner needs for an individual agent action.

When to prioritize SAFR versus AIRG

Prioritize SAFR first when:

  • You already have AI agents executing payments, trades, or filings autonomously

  • Your current guardrails were built independently per team and are not interoperable

  • You need decision point logging to support an upcoming AIRG level audit

Prioritize AIRG first when:

  • You do not yet have a complete AI and agent inventory

  • You have not run risk materiality assessments across your model base

  • Board and senior management oversight structures for AI are not yet defined

Most institutions will end up building both in parallel rather than sequentially, since AIRG's inventory work naturally surfaces which systems are agentic and therefore need SAFR level controls in the first place.

Need Expert Advice on Your AI Strategy?

SAFR vs AIRG

Conclusion

SAFR vs AIRG is not a choice between two competing standards, it is two layers of the same governance problem. AIRG tells you what your organization must oversee. SAFR tells you how an agent's action gets checked in the moment it happens. Firms that map both now, and build the inventory and runtime evidence to support them, will not be scrambling once AIRG is finalized.

About Samta

Samta.ai is a Singapore-headquartered AI Product Engineering & Data Intelligence partner helping enterprises build production-grade AI systems for regulated and data-intensive environments.We help organizations move beyond experimentation by engineering scalable, explainable, and enterprise-ready AI solutions from data foundations and model development to workflow automation and deployment.


Our capabilities combine deep AI expertise, data engineering, and product engineering to deliver measurable business impact across FinTech, BFSI, cybersecurity, regulatory technology, and enterprise operations.


Our enterprise AI products power real-world intelligence systems:

TATVA : AI-driven data intelligence platform for governed analytics, monitoring, and operational insights

VEDA : Explainable and audit-ready AI decisioning engine built for compliance-sensitive enterprise workflows

CORA-Property Management Solutions: : Predictive intelligence platform for real-estate pricing, portfolio optimization, and investment analytics


Backed by ecosystem partnerships with Microsoft, Databricks, Snowflake, and AWS,
Samta.ai delivers agile, cost-efficient AI engineering with faster turnaround and enterprise-grade scalability. Trusted by enterprises across FinTech, BFSI, and digital transformation initiatives, Samta.ai embeds AI governance, data privacy, and compliance-by-design principles directly into the AI lifecycle , enabling organizations to scale AI with transparency, accountability, and operational control. 


Enterprises leveraging
Samta.ai automate 65%+ of repetitive data, analytics, and decision workflows while maintaining governance, explainability, and measurable business outcomes. Samta.ai provides the strategic consulting, AI engineering, and data modernization expertise needed to align enterprise operations with next-generation AI transformation goals.

Frequently asked questions

  1. What does SAFR stand for and what does it govern?

    SAFR stands for Safeguards for Agentic Finance at Runtime. It governs how an AI agent's proposed action is verified, escalated, or rejected at the moment it tries to execute, focused on agentic AI in financial services rather than static models.

  2. What does AIRG stand for and what does it govern?

    AIRG stands for Guidelines on Artificial Intelligence Risk Management. It governs institution wide AI oversight, covering board accountability, AI inventory, risk materiality assessment, and lifecycle controls across every AI model, system, and use case.

  3. Is SAFR mandatory for financial institutions in Singapore?

    No. SAFR is an industry white paper and reference standard, not supervisory guidance. Adoption is currently voluntary, unlike AIRG, which is expected to carry supervisory weight once finalized.

  4. How does AIRG relate to the existing MAS FEAT principles?

    AIRG builds on the FEAT principles, extending fairness, ethics, accountability, and transparency into formal, enforceable expectations for AI governance across the full lifecycle, rather than the voluntary approach FEAT set out.

  5. Do institutions need to comply with both SAFR and AIRG?

    Institutions with agentic AI in production should treat both as complementary. AIRG sets the institutional governance obligation, while SAFR provides the runtime mechanism to evidence that governance for autonomous agents.

Related Keywords

SAFR vs AIRGSAFR vs AIRG SingaporeSAFR AI governance frameworkAIRG AI governance frameworkAI risk management Singaporeai security governance frameworkresponsible ai governance frameworkai agent governance frameworkAI regulatory complianceSingapore financial sector AIAI implementation controls
Why SAFR vs AIRG Decisions Shape Singapore AI Enterprise ROI