MAS Compliance for Document AI: What Singapore Financial Institutions Must Prove

Since December 11, 2024, MAS compliance for document AI has meant more than a data-residency clause. The Monetary Authority of Singapore's revised Guidelines on Outsourcing already treat a document AI platform as an ICT outsourcing arrangement subject to due diligence, contractual, and notification requirements — and in November 2025, MAS went further still, publishing a consultation paper that names AI governance as its own supervisory domain, distinct from general outsourcing risk. For a bank, insurer, or lender evaluating a document AI vendor in Singapore, that's two separate rulebooks converging on the same question: not just where a KYC packet or claims file is stored, but who is accountable for the model that reads it, and what an examiner can ask to see. This guide walks through what both frameworks actually require, article by article, and what a procurement team needs in writing before it signs.
What Is MAS, and Why Does It Cover Document AI Vendors?
The Monetary Authority of Singapore is both the country's central bank and its integrated financial regulator, overseeing banks, insurers, payment service providers, and finance companies under one roof. That combined mandate is why MAS's outsourcing and technology-risk guidance reaches further into a vendor relationship than a data-protection regulator's would on its own — MAS isn't just asking whether customer data is handled lawfully, it's asking whether the institution's operational resilience holds up if the vendor fails, misbehaves, or gets it wrong.
MAS's revised Guidelines on Outsourcing, effective December 11, 2024, replaced the 2016 version with three parallel instruments: Notice 658 for banks, Notice 1121 for merchant banks, and a standalone set of guidelines for financial institutions other than banks (FIOBs) — insurers, payment service providers, and finance companies among them. A document AI platform that classifies, extracts, or reads a regulated document on a financial institution's behalf is an outsourced ICT service under every one of the three, the same way it's an "ICT service" under DORA in the EU: there's no carve-out because the function happens to be "just AI."
What Does MAS Compliance for Document AI Actually Require in a Contract?
The 2024 guidelines embed stronger information-protection and oversight expectations into every outsourcing contract, with a few provisions that matter specifically for a document AI vendor.
Data Location Rights, Not Just a Residency Promise
The revised guidelines give the institution a standing right to be notified of any change to where its data is held, and of any local legal requirement that could compel the service provider to disclose that data to a third party — a broader obligation than a one-time regional-hosting commitment. A vendor that can name a storage region at signing but can't commit to notifying the institution when that changes, or when a foreign legal process could reach the data, hasn't actually satisfied this expectation, even if the initial answer sounds reassuring.
Sub-Contracting Needs the Institution's Prior Approval
Where a document AI platform sub-contracts any part of the arrangement — most often, licensing a general-purpose frontier model from a separate provider and reselling that inference as its own product — the guidelines require the institution's prior approval before that sub-contracting happens, not disclosure after the fact. That's a meaningfully higher bar than most cloud document AI contracts are written to clear: "we use industry-leading AI models" in a vendor's marketing copy isn't the same as identifying the specific sub-processor and getting sign-off before the document ever reaches it.
Material Outsourcing Arrangements Carry Extra Duties
Where a document AI function counts as a material outsourcing arrangement — a bank's core KYC or underwriting extraction workflow typically does — the institution takes on additional obligations: enhanced due diligence before signing, ongoing monitoring of the vendor's performance and control environment, and advance notification to MAS itself before entering or materially changing the arrangement. A vendor that hasn't been built with that level of institutional scrutiny in mind tends to surface the gap only once a compliance team asks for evidence a sales deck never anticipated providing.
What Does MAS's New AI Risk Management Guidance Add Beyond Outsourcing?
On November 13, 2025, MAS published a consultation paper proposing Guidelines on AI Risk Management — a document distinct from, and additional to, the outsourcing framework above. It builds on years of prior MAS work: the FEAT Principles (Fairness, Ethics, Accountability, Transparency) published in 2018, the industry-wide Veritas initiative on fairness assessment, and Project MindForge's work on generative-AI risk, extended explicitly to cover large language models and autonomous AI agents.
The proposed guidelines set supervisory expectations across the full AI life cycle, and several named control domains map directly onto a document AI system: data management (what the model was trained or fine-tuned on, and how outputs are validated), transparency and explainability (whether a decision traces back to what the model actually saw), human oversight (who reviews a low-confidence or high-impact extraction before it's acted on), and — the domain that connects straight back to the outsourcing guidelines — third-party risk. MAS's own announcement is direct on that last point: an institution stays accountable for AI governance even when the AI is licensed from, or hosted by, a third party, so due diligence, contractual protections, performance monitoring, and a workable exit strategy all have to exist regardless of who built the model. The consultation closes January 31, 2026, but the direction — AI governance as its own supervisory line, not a subset of outsourcing review — is already the assumption a Singapore-regulated institution should procure against today.
How Do MAS's Outsourcing Rules and AI Risk Guidance Interact for a Document AI Vendor?
The two frameworks ask overlapping but distinct questions. Outsourcing guidance asks whether the arrangement — the contract, the data flows, the sub-processor chain — is properly governed. AI risk guidance asks whether the model itself — its training data, its explainability, the human oversight around its decisions — is properly governed. A vendor evaluation that only satisfies one of the two leaves a real gap: an impeccable outsourcing contract that can't explain why a model flagged (or missed) a discrepancy in a loan file, or strong model documentation sitting on top of an undisclosed sub-processor. Full MAS compliance for document AI means both records exist together, because that's how an examiner working from either framework will eventually ask to see them.
Does Using a Third-Party Frontier Model Satisfy MAS's Third-Party AI Risk Expectations?
Only partially, and that gap is the practical question worth asking before a vendor goes into a procurement pipeline at all. A platform reselling a licensed frontier model can describe its own controls in detail, but it typically can't extend audit access, sub-processor visibility, or model-training documentation into infrastructure it doesn't operate — which is precisely the visibility both MAS frameworks are asking for. Gartner's inaugural Magic Quadrant for Intelligent Document Processing Solutions, published September 2025, is worth reading with that gap in mind: most vendors evaluated there are built cloud-first, with deployment flexibility retrofitted rather than architected in from the start.
Proof Perimeter's fine-tuned document AI models are built so that gap doesn't exist in the first place: inference runs inside the bank, insurer, or lender's own environment — cloud-hosted, within the customer's infrastructure, or fully on-premise — so there's no undisclosed frontier-model subcontractor sitting between the institution and the document being read, and no sub-contracting approval to chase down after the fact. On Proof Perimeter's internal benchmarks, that fine-tuned model delivers 20% higher accuracy and 50% lower token consumption than general-purpose frontier models on the same document-extraction tasks, and every extracted field carries field-level provenance — what the model saw, what it decided, and why — which is the artifact that answers both MAS's outsourcing-contract audit rights and its proposed AI-guidance human-oversight expectations with the same underlying record, rather than building separate evidence for each.
A Practical MAS Readiness Checklist for Document AI Procurement
- Get data-location notification rights in writing — not just an initial storage-region commitment, but the standing right to be told if that changes.
- Ask for the full sub-processor chain before signing, including any underlying frontier model, and confirm MAS's prior-approval requirement for sub-contracting is actually satisfied, not assumed.
- Confirm whether the arrangement is "material" — most core KYC, underwriting, or claims extraction workflows are, which means enhanced due diligence, ongoing monitoring, and advance notice to MAS apply.
- Ask how the vendor documents model governance, not just contractual governance: training data, explainability, and human-oversight design for low-confidence extractions.
- Check whether SOC 2 controls and data-residency commitments cover inference, not just storage — both MAS frameworks reach further than either document typically does alone.
A demo call is a faster way to pressure-test these answers than a compliance questionnaire — bring a KYC packet or loan file and ask, specifically, who the sub-processor chain includes and where the model actually runs. Our broader look at cloud document AI compliance risk and the DORA compliance guide cover the same underlying question — where inference happens, not just where data sits — across other regulatory regimes.
Frequently Asked Questions
Does MAS's Guidelines on Outsourcing apply to a document AI vendor that isn't itself a regulated financial institution?
Yes. MAS regulates the financial institution directly, but the Guidelines on Outsourcing require that institution to impose specific contractual and oversight obligations on every outsourced ICT service provider it uses — a document AI vendor included, regardless of the vendor's own regulatory status.
Is the November 2025 AI risk management consultation already in force?
Not yet — it's a consultation paper, with the comment period closing January 31, 2026, so the specific guidelines are still being finalized. But MAS has already signaled the direction (AI governance as its own supervisory domain, extending to third-party and outsourced AI), which is worth procuring against now rather than waiting for the final text.
Does a regional data-storage guarantee satisfy MAS's requirements for a document AI vendor?
No. MAS's outsourcing guidelines separately require notification rights over where data is processed and held, and its proposed AI risk guidance adds model-governance and human-oversight expectations that a storage commitment alone doesn't address. Both frameworks reach past storage into how the vendor's AI is actually governed.
The Takeaway
MAS compliance for document AI isn't satisfied by a single certification — it's two frameworks converging on one accountability question: can the institution show who governs the model, where it runs, and who approved every party that touches the document along the way? A platform that runs inference inside the institution's own environment removes the sub-processor chain both frameworks are asking about, rather than trying to document access to infrastructure it doesn't control after the fact.

DORA Compliance for Document AI: What EU and UK Financial Institutions Must Prove
DORA's Article 30 and its new subcontracting RTS reach past data storage into where a document AI vendor's model actually runs — here's what to prove.

Why Cloud Document AI APIs Are a Compliance Risk for Banks and Insurers
DORA, RBI's outsourcing rules, and SAMA's Cloud Computing Framework all reach past where a document is stored to where the AI reading it actually runs.

The Sovereign AI Gap: Data Residency Risk
Data residency rules govern where a document sits — not where the AI model reads it. DORA Article 28 holds financial institutions responsible either way.
Proof Perimeter runs document AI inside your own perimeter — with a provenance record on every field.
Get Started for Free