MAS and AI in financial institutions
Notice FSM-N05, paragraph 9 — Notice on Technology Risk Management
Paragraph 9 of Notice FSM-N05 is one sentence long and carries no materiality gate: a bank must implement IT controls to protect customer information from unauthorised access or disclosure. It is legally binding. Whether it reaches an embedding, a vector index or a prompt log turns on a single word in the Notice’s own definition — referable — and almost no firm has made that determination.
§ 1 — Who it binds
Which institutions, and which information
All banks in Singapore, by paragraph 1 of Notice FSM-N05, with bank in Singapore taking its meaning from section 2(1) of the Banking Act 1970; insurers owe the equivalent duty under Notice FSM-N03. Nothing in paragraph 9 is gated on criticality, materiality or technology, and no AI carve-out exists. The gate is the definition of customer information and its referability test, applied to each place that information comes to rest.
§ 2 — In practice
Referable, not readable
A Notice is the binding end of MAS’s taxonomy: Notices primarily impose legally binding requirements on a specified class of financial institutions or persons, and FSM-N05 is issued under section 29(1) of the Financial Services and Markets Act 2022. The class matters as much as the requirement. There is no single MAS Notice on technology risk management, and citing one is a live error in secondary commentary: the sectoral Notices — 644 for banks, 127 for insurers, 506, PSN05, and 655 on cyber hygiene — were cancelled on 10 May 2024 and replaced by the FSM-N series, which remains segmented by licence class. FSM-N05 binds banks in Singapore, FSM-N03 is the insurers’ technology risk Notice and FSM-N06 is cyber hygiene for banks. A firm whose AI policy quotes a cancelled Notice number has cited nothing.
Paragraph 9 carries no threshold, so the definition does all the gating. Customer information means information relating to, or particulars of, an account of a customer of the bank, together with deposit information covering deposits, funds under management and safe deposit or safe custody arrangements — and each limb expressly excludes information that is not referable to any named customer or group of named customers. Referable, not readable. A firm’s usual position on embeddings is that a vector is not customer information because a person cannot read it, which answers a question the Notice does not ask. A retrieval system that returns the right customer’s record in response to a query about that customer performs referability by construction, because that is what it was built to do. The same question has to be put separately to a fine-tuning corpus, a retrieval index, an evaluation set and the prompt and completion logs, and the answers may honestly differ. What does not survive contact with an assessor is that nobody asked.
The prompt log is where customer information most often escapes the controls applied to its source. Data enters a model in a prompt drawn from a system with classification, access control, retention and a deletion process attached, and leaves in a log with none of them: a different retention period, a different access list, frequently a different jurisdiction, and often a third party operating the store. Nothing in the Notice treats a log differently from any other place the information comes to rest. The access question is worth putting at the artefact level rather than the application level, because the interesting principal is usually not a person — a model’s own service credentials commonly hold standing read access to the index and the log, which is the same problem tool permissions and least privilege describe, arriving through a data control instead of an authorisation one.
Paragraphs 4 to 8 of the Notice are gated on criticality — critical systems, their availability, their recovery, and the incidents that affect them. Paragraph 9 is gated on nothing. A firm that scoped its AI data controls by system criticality, which is the natural thing to do once the rest of the Notice has been read, has scoped paragraph 9 by a test paragraph 9 does not contain, and its non-critical systems are precisely the ones running informal prompt logs. Two adjacent regimes should be named and not merged. Unauthorised disclosure of customer information also engages banking-secrecy obligations under the Banking Act, which are a separate and heavier exposure. And the Personal Data Protection Act is a different statute with a different regulator; where personal data is involved both apply, and a firm that has already answered the data governance questions for a Union deployment will find the artefacts transfer even though the duty does not.
§ 3 — What a weak answer looks like
The provider’s assurance answering the bank’s duty
The vendor’s security page offered as the control. A firm asks whether customer data is safe with the model provider, receives a well-produced answer about encryption in transit and at rest, certification and a training opt-out, and files it. Every statement in it may be true and none of it addresses the paragraph. The duty runs to the bank, over the information wherever it now sits — including inside artefacts the bank itself created, the index it built and the logging it switched on, none of which the provider’s assurance was written about.
§ 4 — What discharges it
What the determination has to show
The artefacts an assessor asks to see, and what makes each one sufficient rather than merely present.
01
The referability determination for each AI data artefact
Training corpus, fine-tuning set, embeddings, vector index, prompt and completion logs, evaluation sets: for each, whether it is referable to a named customer, who decided, and on what reasoning. One blanket answer covering all of them is a policy statement, not a determination.
02
A data-flow map for one use case, caches included
Every place the information comes to rest, taken past the application into caches, logs, temporary files and the provider’s side of the boundary. The interesting entries are always the ones nobody designed.
03
Access evidence at artefact level, service accounts included
Who and what can read the vector store and the log, tested rather than described, with an explicit answer on whether the model’s own service credentials appear in the list.
04
The retention position for prompt and completion logs
The period applied, reconciled to the period applied to the systems the information came from. A log outliving its source has created a second record with different rules and no owner.
05
The third-party disclosure record for a model provider
What leaves the bank, under which contractual term, into which jurisdiction, and whether it may be used for the provider’s own purposes. The contractual answer and the observed traffic should be checked against each other.
06
A deletion request executed to completion, indexes included
Traced end to end through source system, cache, index, log and any derived artefact. This is the test that separates a data map somebody drew from one somebody used, and very little passes it first time.
§ 5 — Worked example
Worked example — the index, the log and the sign-off
A bank deploys a retrieval-augmented assistant for relationship managers. It indexes account notes, transaction summaries and correspondence into a vector store hosted by the model provider, and answers questions such as what was agreed with this client about the facility renewal. Legal signed it off on the basis that the embeddings are numerical and the provider contract prohibits training on bank data. Prompts and completions are retained ninety days for quality monitoring, in the provider’s tenancy.
Where does paragraph 9 bite, and what has the sign-off missed?
It bites in three places and the sign-off reached none of them. The vector store is the first: the index was built so that a query naming a client returns that client’s material, which is referability, while the numerical form of the stored representation goes to readability instead. The log is the second and usually the worst — ninety days of relationship managers’ questions and the assistant’s answers, both full of named-customer detail, under a retention period nobody reconciled to the source systems and an access list nobody has reviewed. The third is the boundary itself: the information has left the bank’s tenancy, which is a disclosure to a third party whether or not the provider trains on it, and the training prohibition answers a different question. Paragraph 9 asks for IT controls over all of it, with no materiality gate to fall back on. The workable answer is not to unwind the deployment but to make the determination explicitly, artefact by artefact, and to bring the log inside the controls that govern the account notes it was drawn from.
§ 6 — Elsewhere
The same data question from other directions
Where another instrument addresses the same obligation. These are correspondences, not comparisons — the Council does not rank one framework against another.
Article 10 governs the governance of training, validation and testing data for a high-risk system. It reaches the dataset as a development artefact; paragraph 9 reaches customer information wherever it has come to rest.
The same access question arrives from the other side: what a model or an agent is entitled to read. Service credentials holding standing access to an index are a least-privilege matter and a customer-information matter at once.
Testing a control over customer information inside a hosted model raises the evidence question directly, because much of what would prove the control sits with the provider rather than with the bank.
A correspondence indicates that two instruments address the same underlying obligation. It is not a mapping endorsed by either body, not a statement that one satisfies the other, and not a judgement about which is more demanding.
§ 7 — When it applies
The Notice that replaced the cancelled ones
10 May 2024
The date FSM-N05 took effect, stated in the Notice itself. The predecessor sectoral Notices on technology risk management, including Notice 644 for banks, were cancelled the same day.
§ 8 — Exposure
What a binding Notice actually exposes
A legally binding requirement. Contravention is an enforcement matter rather than a supervisory observation, and no monetary figure is stated here.
FSM-N05 is issued pursuant to section 29(1) of the Financial Services and Markets Act 2022. MAS describes Directions, of which Notices are a kind, as instruments that have legal effect, meaning that MAS could specify whether a contravention of a direction is a criminal offence; and Notices as instruments that primarily impose legally binding requirements on a specified class of financial institutions or persons. The provision text setting out the consequence of contravention could not be retrieved from a primary source, so no ceiling is asserted. Separately, unauthorised disclosure of customer information engages banking-secrecy obligations under the Banking Act — a distinct exposure with its own route, and one this page does not quantify either.
§ 9 — provenance
The provision itself
This page sets out what the instrument requires and what discharges it. The official text is the authority — these go straight to it.
- Notice FSM-N05 on Technology Risk Management, paragraph 9, with the defined terms customer information and deposit information and their referability exclusions.
- The Notice states that it takes effect on 10 May 2024 and records its issue under section 29(1) of the Financial Services and Markets Act 2022.
- MAS’s own statement of the legal effect of Directions and Notices, quoted rather than paraphrased.
- The cancellation record for Notice 644, cancelled 10 May 2024, directing readers to Notice FSM-N05. Notices 127, 506, PSN05 and 655 carry equivalent records.
§ 10 — Also read
Also read
Tool permissions and least privilege for agents
Certification
Assessed on the same standard of evidence
Every Council credential is examined on applied judgement against a published anchor, set out the way the obligations on this page are. The free AI Literacy Certificate is open to any adult today, and the register lists what is open for enrolment.