Skip to main content

Roles

Start from your job, not from the law.

10 ROLE CHECKLISTS · 94 ORDERED STEPS · 2 JURISDICTIONS

The short answer

Nobody reads a governance stack front to back. They arrive with a job and a deadline. Each checklist below walks one role through the instruments that matter to it, in the order they matter, with the legal force of each one shown on the step. Read your row, follow the links, stop when you hit something voluntary you do not need.

Singapore

Data Protection Officer

DPOs and privacy teams in Singapore organisations deploying AI

Your binding floor is the PDPA; everything else in this stack is guidance that helps you meet it. Read the statute first, then PDPC's two AI advisories, then the assurance tooling that evidences compliance.

  1. 01
    Binding

    Start with the binding law: PDPA 2012

    Every AI use of personal data sits under this Act, it is the only economy-wide binding instrument in the stack.

  2. 02
    Binding

    Consent Obligation (s 13)

    If your AI feature collects or uses personal data, you need consent or a schedule exception before anything else.

  3. 03
    Binding

    Notification Obligation (s 20)

    Individuals must be told the purposes of collection, vague "product improvement" wording will not carry AI training uses.

  4. 04
    Binding

    Purpose limitation (s 18)

    AI uses must stay within purposes a reasonable person would consider appropriate, check this before re-purposing data for training.

  5. 05
    Binding

    Know when vendors are data intermediaries

    Your AI vendor's obligations differ from yours; misallocating them is the most common contract gap I see.

  6. 06
    Guidance

    PDPC AI advisory (1 Mar 2024)

    This is how PDPC reads the PDPA for ML recommendation and decision systems, your primary interpretive text.

  7. 07
    Guidance

    Business improvement exception

    Often the only realistic basis for training on existing customer data without fresh consent, learn its conditions cold.

  8. 08
    Guidance

    Data minimisation in development

    PDPC expects you to train on the minimum attributes and volume, document why you needed what you used.

  9. 09
    Guidance

    PDPC GenAI advisory (final, 20 Jul 2026)

    The July 2026 finals govern GenAI development and deployment, they run alongside, not instead of, the 2024 guidelines.

  10. 10
    ConsultationConsultation

    Publicly-available exception for web-scraped data

    Scraping is not automatically lawful; the exception analysis now turns on digital barriers.

  11. 11
    Guidance

    Document your publicly-available assessment

    If you rely on the exception for data behind digital barriers, a DPIA or written record producible to PDPC is now expected.

  12. 12
    Guidance

    AI-specific notifications

    General privacy notices are insufficient for training consent, plan explicit AI-specific wording and an opt-out path.

  13. 13
    Binding

    Breach notification (Part 6A)

    A poisoned or leaking training set can be a notifiable breach, wire this into your AI incident runbook.

  14. 14
    Binding

    Penalty exposure: 10% of Singapore turnover

    Board-level number: enforcement now carries turnover-based penalties, which is how you get budget for the programme above.

ML Engineer / AI Builder

Engineers and data scientists building or integrating AI systems in Singapore

You will never be regulated by a single document, you inherit obligations from PDPA, expectations from frameworks, and tests from AI Verify. This path follows the build lifecycle.

  1. 01
    Guidance

    MGF 2.0: the base operating model

    The four areas are the mental model every Singapore framework reuses, internal governance, human involvement, operations, stakeholder comms.

  2. 02
    Guidance

    Operations management

    Data quality, lineage, bias minimisation and post-deployment monitoring are your engineering checklist, verbatim from the framework.

  3. 03
    Guidance

    Separate training and test datasets

    A basic the auditors will ask about first, keep the split clean and documented.

  4. 04
    Guidance

    Pick the human-involvement model deliberately

    In/over/out-of-the-loop is a design decision you must justify by severity and probability of harm, not a default.

  5. 05
    Guidance

    MGF for Generative AI: nine dimensions

    If you build or fine-tune GenAI, these nine dimensions are the canonical risk map your compliance team will quiz you against.

  6. 06
    Guidance

    "Food label" disclosures

    Ship transparency artefacts with your model, downstream deployers depend on your disclosures for their own compliance.

  7. 07
    Guidance

    MGF for Agentic AI

    The January 2026 framework is the reference design for governing agents, read it before wiring tools to an LLM.

  8. 08
    Guidance

    Bound agent limits upfront

    Minimum tools and data access per task is the single highest-leverage control you can implement.

  9. 09
    Guidance

    Baseline testing before deployment

    Execution accuracy, policy adherence and tool use are the new test dimensions, add them to your eval harness.

  10. 10
    Guidance

    Gradual rollout with continuous monitoring

    Ship agents behind staged rollouts; production behaviour, not offline evals, is where agent risk shows up.

  11. 11
    Guidance

    CSA Guidelines on Securing AI Systems

    Security across five lifecycle stages including end-of-life, the companion guide turns each stage into concrete controls.

  12. 12
    Guidance

    CSA Agentic Addendum (final, 17 Jun 2026)

    Threat modelling, taint tracing and rogue-action controls purpose-built for agentic systems, your security review template.

  13. 13
    Guidance

    AI Verify toolkit

    Government-built, open-source tests mapped to 11 principles, run it and keep the report; it is your evidence.

  14. 14
    Guidance

    Project Moonshot

    Benchmarking plus red teaming for LLMs, use it for pre-deployment safety baselining of any GenAI feature.

Financial Services Risk Officer

Risk, compliance and model-risk teams at MAS-regulated financial institutions

MAS regulates you through binding TRM notices, supervisory expectations (FEAT), and a pending AI risk guideline. Read what is binding first, then what is proposed, then the industry tooling built to satisfy both.

  1. 01
    Binding, sectoral

    MAS TRM Notices: the binding baseline

    These notices under the FSM Act are law for your institution, AI systems sit inside this perimeter, not outside it.

  2. 02
    Binding, sectoral

    The 1-hour incident notification rule

    A relevant incident on a critical system must reach MAS within one hour of discovery, test this clock with AI failures in scope.

  3. 03
    Binding, sectoral

    Max 4 hours unscheduled downtime per 12 months

    If an AI system is critical, its downtime budget is four hours a year, architecture decisions follow from this.

  4. 04
    Supervisory expectation

    FEAT Principles

    MAS's fairness, ethics, accountability and transparency expectations, the standard your AIDA use is informally measured against.

  5. 05
    Supervisory expectation

    Board awareness of AIDA use

    FEAT puts AIDA on the board agenda; your reporting line should make AI risk visible upward, not buried in model inventories.

  6. 06
    Guidance

    Veritas methodology and toolkit

    The MAS-industry FEAT assessment methodology, use it to evidence fairness testing on credit, marketing and fraud models.

  7. 07
    ConsultationConsultation

    MAS P017-2025: proposed AI Risk Management Guidelines

    Still at consultation as of 17 Aug 2026, but this is the shape of coming supervisory expectations; gap-assess now.

  8. 08
    ConsultationConsultation

    Proposed: board and senior management oversight

    The draft guidelines put AI oversight squarely on the board and senior management, prepare your governance charter early.

  9. 09
    ConsultationConsultation

    Proposed: AI inventory

    A current inventory of AI use cases is the first thing supervisors will ask for; build it before the guidelines finalise.

  10. 10
    ConsultationConsultation

    Proposed: risk materiality assessment

    The proposed proportionality model, materiality determines control depth, so your assessment methodology matters.

  11. 11
    Guidance

    MindForge AI Risk Management Toolkit (Mar 2026)

    The industry-built handbook aligned to the proposed guidelines, your most practical implementation reference.

  12. 12
    Guidance

    Implementation examples (DBS, Julius Baer, Prudential)

    Peer case studies show what "good" looks like to the consortium, benchmark your controls against them.

  13. 13
    Guidance

    ABS GenAI Guardrails Handbook

    Nine guardrail approaches for banking GenAI, an important input to the MAS toolkit, practical for vendor and use-case reviews.

  14. 14
    ConsultationConsultation

    Watch P012-2026: TRM amendments

    Proposed amendments to all 11 TRM notices closed 31 Jul 2026, final text could tighten incident and change management for AI.

C-Suite / Board Member

Directors and executives accountable for organisational AI governance

You do not need every clause, you need the accountability map: what is binding, what is expected, what is coming, and what your name goes on. Fifteen minutes per node.

  1. 01
    Guidance

    MGF 2.0 in one page

    Singapore's baseline framework, its four areas are the agenda for your AI governance committee.

  2. 02
    Guidance

    Internal governance structures

    Roles, SOPs, training and periodic review, this is the management system you are personally answerable for.

  3. 03
    Guidance

    AI solutions should be human-centric

    One of two guiding principles, the tone-setter for every policy your organisation writes.

  4. 04
    Binding

    PDPA: where the legal risk lives

    The only binding economy-wide law here; AI misuse of personal data is enforced with turnover-based penalties.

  5. 05
    Binding

    10% of Singapore turnover

    The number that makes AI data governance a board topic, not an IT topic.

  6. 06
    Guidance

    PDPC GenAI finals (20 Jul 2026)

    Fresh, final guidance, ask your DPO for a one-page gap assessment against its four tightened positions.

  7. 07
    Guidance

    Agentic AI: the 2026 frontier

    The world's first agentic framework came from IMDA, if your strategy includes agents, this is your governance baseline.

  8. 08
    Guidance

    Make humans meaningfully accountable

    The core ask: named humans accountable for agent behaviour, with approval checkpoints on irreversible actions.

  9. 09
    Guidance

    CSA agentic security addendum

    Security guidance your CISO should already have mapped, rogue actions and data disclosure are board-visible incidents.

  10. 10
    ConsultationConsultation

    MAS direction of travel

    For financial groups: proposed guidelines signal board-level AI oversight is becoming supervisory expectation.

  11. 11
    Supervisory expectation

    FEAT: board awareness

    MAS expects the board itself to be aware of AIDA use, a standing agenda item satisfies this.

  12. 12
    Standard

    SS ISO/IEC 42001 certification

    The certifiable management-system standard, a credible signal to regulators, partners and customers.

  13. 13
    Guidance

    AI Verify as your evidence layer

    Government-built testing that turns "trust us" into reports, fund it before you need it.

  14. 14
    Guidance

    The regional frame

    ASEAN's roadmap and DEFA will shape cross-border AI business, strategy teams should track the November 2026 signature target.

Legal Counsel

In-house and external lawyers advising on Singapore AI deployments

Advising on AI in Singapore means distinguishing binding law from guidance, and final text from consultation. This path is ordered by legal force, then by instrument, with the crosswalks you will be asked about.

  1. 01
    Binding

    PDPA 2012: the binding anchor

    All AI-personal-data advice starts here; note Parts 3-6 obligations and the Part 9C enforcement toolkit.

  2. 02
    Binding

    Enforcement: directions and financial penalties

    s 48I directions and s 48J penalties are what your risk advice quantifies against.

  3. 03
    Binding, sectoral

    MAS TRM Notices: binding sectoral law

    For FI clients, these notices carry statutory force under the FSM Act, the 1-hour rule is the classic exam question.

  4. 04
    Guidance

    Advisory guidelines are not law

    PDPC's own words: advisory, not legally binding, calibrate client advice and contract wording accordingly.

  5. 05
    Guidance

    GenAI finals of 20 Jul 2026

    Final text supersedes the June draft analysis; the notify-the-source proposal was dropped, replaced by documented assessment.

  6. 06
    Guidance

    Consent cannot be a condition of service

    s 14(2)(a) PDPA applied to AI training, review client consent flows for overreach.

  7. 07
    Guidance

    Anonymisation as an alternative

    The finals accept anonymisation as an alternative to minimisation, a practical out for training-data design.

  8. 08
    ConsultationConsultation

    P017-2025 is still a proposal

    As of 17 Aug 2026 there is no final guideline, advise clients on trajectory, not compliance obligations, here.

  9. 09
    Guidance

    CSA addendum: final but voluntary

    Published 17 Jun 2026 as guidance, expressly non-mandatory, relevant to duty-of-care arguments, not statutory compliance.

  10. 10
    Standard

    SS ISO/IEC 42001 status

    Voluntary standard unless incorporated by contract or regulation, check procurement documents for incorporation by reference.

  11. 11
    Guidance

    Official NIST crosswalk

    For clients with US touchpoints, the IMDA-NIST mapping is the interoperability evidence.

  12. 12
    Guidance

    Official ISO 42001 crosswalk

    AI Verify ↔ ISO/IEC 42001 mapping supports dual-compliance arguments in certification discussions.

  13. 13
    Binding

    Contrast: Vietnam's binding AI law

    ASEAN's first binding AI statute in force 1 Mar 2026, relevant for regional clients and for "Singapore is not the EU" advice.

  14. 14
    EmergingNot yet in force

    DEFA: the coming regional layer

    Negotiations concluded 29 May 2026; signature targeted November 2026, monitor for cross-border AI and data provisions.

United States

US general counsel or compliance lead

Legal and compliance leads at US companies deploying AI

There is no federal AI statute to read. Your binding exposure is old law applied to new systems, plus state law. Start with what can actually be enforced against you, then read the federal policy layer to see where it is heading.

  1. 01
    Binding

    Accept the shape of the problem

    There is no single federal AI law to comply with. Anyone who tells you otherwise is selling something.

  2. 02
    Binding

    Section 5 of the FTC Act is your general purpose exposure

    Every claim you make about your AI is an advertising claim, and every tool you ship is capable of being a means of deception.

  3. 03
    Binding

    Then go to the states

    This is where binding AI specific obligation lives today. Work the 50-State AI Law Atlas for the jurisdictions you operate in.

  4. 04
    Binding, sectoral

    Watch the preemption fight, do not plan around it

    The federal government is litigating against state AI laws. Until a court rules, the state law still binds you.

  5. 05
    Guidance

    Adopt the AI RMF because your counterparties will ask for it

    It is voluntary, and it is what contracts, insurers and state statutes point at.

Vendor selling AI to the federal government

Companies whose buyer is a US federal agency

For you the executive orders are not policy commentary. They arrive as contract terms. Read the acquisition memorandum first, then the use memorandum your buyer is complying with, then the procurement conditions on the model itself.

  1. 01
    Binding, sectoral

    M-25-22 is how your buyer is required to buy

    Competitive marketplace, measurable performance, cross functional review. Your proposal is read against it.

  2. 02
    Binding, sectoral

    M-25-21 is what your buyer must be able to say about your system

    Chief AI Officer sign off, use case inventory entry, and the minimum practices if the use is high impact.

  3. 03
    Binding, sectoral

    Know whether your use case is high impact

    If it is, and the practices cannot be met, the agency is directed to stop using it. That is a contract risk, not a policy risk.

  4. 04
    Binding, sectoral

    If you sell an LLM, the Unbiased AI Principles are contract terms

    Truth seeking and ideological neutrality, written into new contracts and retrofitted into existing ones.

  5. 05
    Binding, sectoral

    Expect your deployment to appear in a public inventory

    Agencies publish their AI use cases annually with risk determinations attached.

HR or talent leader using AI in hiring

HR, talent acquisition and employment counsel

The federal guidance you may have bookmarked in 2024 is gone from the agency websites. The statutes it interpreted are unchanged. Read the law, not the guidance index.

  1. 01
    Binding

    Title VII binds you, tool or no tool

    You are liable for the selection procedure you use, including one a vendor built and scores.

  2. 02
    Binding

    The four fifths rule is the arithmetic

    Adverse impact analysis is a 1978 regulation, and it is what your AI screening tool will be measured against.

  3. 03
    BindingWithdrawn

    Withdrawn guidance is not repealed law

    The EEOC removed its AI documents in January 2025. Nothing about your exposure changed.

  4. 04
    Binding

    The ADA is the second exposure, and the one people miss

    Screen out risk, and the duty to offer an alternative format on request.

  5. 05
    Binding

    Then check your states

    Several states and cities regulate automated employment decision tools directly. The Atlas has them.

Lender or credit risk lead

Consumer lenders, fintechs and their compliance teams

Two circulars were withdrawn in 2025. Regulation B was not amended. The adverse action notice still has to state the actual principal reasons, which is why model explainability is a legal requirement here and not an engineering preference.

  1. 01
    Binding

    ECOA and Regulation B are the binding floor

    Specific and accurate principal reasons for adverse action. The rule does not care how complex the model is.

  2. 02
    BindingWithdrawn

    Read what was actually withdrawn

    Circulars 2022-03 and 2023-03 went in the bulk withdrawal of 12 May 2025. The regulation behind them did not.

  3. 03
    Guidance

    Use the AI RMF as your documented method

    When an examiner asks how you govern model risk, a recognised framework is a better answer than an internal memo.

  4. 04
    Binding

    State law is where the AI specific duties are

    Check the Atlas for the states you lend in.

CISO or AI security lead

Security leaders responsible for AI systems and AI enabled attackers

The federal security layer moved fastest of any part of this stack in 2026. None of it binds a private company directly, and all of it is what you will be asked about after an incident.

  1. 01
    Guidance

    Start with the CISA joint guidance

    AI data security and secure deployment, voluntary and widely cited.

  2. 02
    Binding, sectoral

    Know the Treasury clearinghouse exists

    Voluntary coordination on AI driven vulnerability scanning with industry and critical infrastructure operators.

  3. 03
    Binding, sectoral

    Understand covered frontier models

    Classified benchmarking of model cyber capability, and a voluntary access framework for developers.

  4. 04
    Binding, sectoral

    Read the bar on licensing before you assume a regime exists

    The order expressly disclaims mandatory licensing, preclearance or permitting.

  5. 05
    Guidance

    Track the agent standards work

    Agent identity and authorisation is the open control gap, and this is where the US answer is being written.

These checklists are a reading order, not legal advice, and they do not replace advice from someone who knows your facts. If your work touches United States state law, the 50-State AI Law Atlas carries that layer.