Path M1 · 6 stops
Four-Agency Map
Orient yourself: who issues what in Singapore AI governance, and what each instrument's legal weight is.
- 1
- 2
- 3
- 4
- 5
- 6
Path M4 · 8 stops
Agentic AI Governance (MGF for Agentic AI)
Deep-dive the world's first agentic AI governance framework, from agent anatomy to organisational accountability.
- 1
Read the framework overview
Guidance
Start with what the framework is for: structured overview of agentic risks and best practices for deployers.
- 2
- 3
- 4
Multi-agent patterns
Guidance
Sequential, supervisor, swarm, the pattern determines where accountability can attach.
- 5
Five risk types
Guidance
Erroneous, unauthorised, biased actions, data breaches, disruption, your risk-register skeleton.
- 6
- 7
- 8
Track v1.5
Guidance
The May 2026 update added case studies and multi-agent risk guidance, a living document to watch.
Path M5 · 8 stops
PDPA and Personal Data in AI
From statute to advisory guidelines: how personal data law applies across the AI and GenAI lifecycle.
- 1
PDPA baseline
Binding
The binding Act, obligations apply to AI exactly as to any other processing.
- 2
Consent
Binding
The default gateway for collection, use and disclosure.
- 3
- 4
2024 AI advisory
Guidance
PDPC's interpretation for ML systems, business improvement and research exceptions operationalised.
- 5
Anonymisation guidance
Guidance
Anonymised data is outside the PDPA but carries re-identification risk, the guidance sets the test.
- 6
2026 GenAI finals
Guidance
The July 2026 guidelines cover development, deployment and post-deployment for GenAI.
- 7
- 8
Access and correction for GenAI
Consultation
Best practices for honouring individual requests against trained models, a hard problem with official expectations.
Path M6 · 8 stops
MAS and Financial-Sector AI
The financial-sector stack: binding TRM notices, FEAT expectations, Veritas methodology, and the pending AI risk guidelines.
- 1
Binding: TRM Notices
Binding, sectoral
Statutory technology risk requirements, the floor for any FI deploying AI.
- 2
RTO of 4 hours
Binding, sectoral
Recovery objectives constrain how critical AI services must be architected.
- 3
FEAT Principles
Supervisory expectation
Fourteen principles that define MAS's fairness/ethics/accountability/transparency expectations.
- 4
- 5
Veritas
Guidance
The methodology and open-source toolkit for assessing FEAT conformance.
- 6
- 7
MindForge toolkit
Guidance
The industry handbook aligned to the proposal, your implementation bridge.
- 8
Path M8 · 8 stops
Crosswalks and Assurance
Proving it: testing tooling, certification standards, and official crosswalks to NIST and ISO frameworks.
- 1
AI Verify framework
Guidance
Eleven internationally accepted principles, technical tests plus process checks.
- 2
AI Verify toolkit
Guidance
Run the open-source toolkit; the report is your primary assurance artefact.
- 3
Moonshot
Guidance
LLM benchmarking and red teaming to operationalise the GenAI testing dimensions.
- 4
- 5
- 6
- 7
SS ISO/IEC 42001
Standard
The certifiable standard, Annex ZA expressly names AI Verify as a voluntary alignment tool.
- 8
Path M11 · 8 stops
Capstone: Build a Governance Dossier
Assemble a complete organisational AI governance dossier: governance structure, risk assessments, data controls, security, and assurance evidence.
- 1
Governance charter
Guidance
Adapt internal governance structures and measures, the dossier's first chapter.
- 2
- 3
Risk-rating method
Guidance
Use the severity-probability matrix to justify human-involvement decisions per use case.
- 4
- 5
Documented assessments
Guidance
DPIA-style written records for data-source decisions, the artefact regulators ask for.
- 6
- 7
AI inventory
Guidance
A maintained inventory of AI systems and capabilities, every regime expects one.
- 8
Evidence: process checks
Guidance
Documentary evidence validating processes, the difference between claimed and demonstrated governance.