Insights · AI Governance & Risk



Your Firm Adopted AI. Did Your Controls Keep Up?

Why the real AI risk in Singapore businesses isn’t the technology — it’s the governance gap around it.

By Bin Ma, Paul Wan & Co

Across Singapore, AI has quietly moved from “nice to have” to “already running half your back office.” Document processing, predictive analytics, client-facing chatbots, even draft financial analysis: AI is in the workflow, often before anyone formally decided it should be.

That speed is the problem. MAS, IMDA, and Enterprise Singapore have all built frameworks to support responsible AI adoption; the guidance exists. But in most organisations, the controls have not caught up with the rollout. And for accounting, audit, and advisory firms, where confidentiality and audit quality are non-negotiable, that gap isn’t just an IT issue. It’s a professional liability issue.


Five Risks Hiding Behind Every AI Tool

AI risk doesn’t fit neatly into the risk register your firm already has. It shows up in five overlapping ways, and each one makes the others worse if nobody owns the whole picture.

Data risk. Garbage in, garbage out, except the AI rarely tells you it’s happening. Biased or incomplete source data quietly degrades outputs, and PDPA exposure follows if personal data goes through AI tools without proper safeguards.

Model risk. An AI model applied outside its intended scope can produce confidently wrong answers. MAS’s FEAT Principles were written for finance, but the risk applies anywhere AI informs pricing, hiring, credit, or client decisions.

Operational risk. What happens when the AI tool you’ve built a workflow around goes down, updates overnight, or starts behaving differently? Automation doesn’t remove your responsibility for the outcome. It just hides where the responsibility sits.

Cybersecurity risk. AI systems are now both targets and leak points. Staff pasting client data into a public AI tool can be just as damaging as a system being attacked directly.

Accountability risk. When an AI output causes harm, “the AI did it” isn’t an answer regulators or clients accept. Singapore’s frameworks place accountability squarely on the firm that deployed the tool, not the vendor that built it.


The Frameworks Already Exist

Singapore is not short on guidance. The PDPC’s Model AI Governance Framework lays out a two-tier approach: organisational policy plus model-level oversight. AI Verify, built jointly by IMDA and PDPC, gives firms a structured way to test AI systems and produce documentation they can actually show a regulator or client. And MAS’s FEAT Principles set out what “explainable, fair, and accountable” AI looks like in practice.

None of this is theoretical or aspirational. It’s the standard regulators increasingly expect firms to meet, framework or no framework.


So Where’s the Gap?

Not in the frameworks. In the wiring. Most firms treat AI governance as a side project: separate from enterprise risk management, separate from internal audit, separate from the quality management system that already governs everything else the firm does.

Closing that gap comes down to five practical moves: knowing which AI tools are actually in use (most firms can’t list them), controlling what data goes into them, reviewing outputs before anyone relies on them, vetting vendors properly, and training staff on where AI tools fall short, hallucinated outputs included.


The Productivity Gains Are Real. So Is the Exposure.

AI adoption in Singapore isn’t slowing down, and it shouldn’t. But the firms that get the most out of it, without the regulatory, client, or reputational fallout, are the ones that built governance into their existing controls rather than bolting it on after something went wrong.


Related Posts