TwinEthosRequest access

Standard or framework

MAS FEAT Principles

Monetary Authority of Singapore (MAS) · Singapore (SG) · 4 provisions encoded · verified against the official source as of 2026-09-04.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Official text: www.mas.gov.sg.

Standard / soft law

AI models in financial decisions should be regularly validated for accuracy and bias (MAS FEAT)

MAS FEAT Principles — Fairness (Accuracy and Bias), Principles 3-4 · official text · Soft law or guidance (not binding law) · Singapore (SG)

Per MAS FEAT Fairness Principles 3-4, data and models used for AIDA-driven financial decisions must be regularly reviewed and validated for accuracy and relevance and to minimize unintentional bias, and decisions reviewed so models behave as intended (frequency calibrated to materiality/complexity). Detect a consequential AI-decision model with no documented recurring accuracy/bias validation.

Who it applies to

  • Duty falls on: deployer
  • Systems covered: automated decision
  • Sectors: lending, insurance, essential services
  • Financial institutions in Singapore using AIDA. Voluntary MAS principles; validation frequency calibrated to materiality + model complexity.

The guard to add

Compute per-group accuracy and bias metrics in the training pipeline of every consequential-decision model, keep the results per version, and rerun them on a schedule.

A validation stage that runs whenever a decision model is trained, fine-tuned, or retrained (the same module or pipeline step as fit(), Trainer, xgb.train, or fine_tuning.jobs.create) and again on a recurring schedule against recent decisions: accuracy and error rates per group, selection rates and disparity metrics (fairlearn MetricFrame, demographic_parity_difference, AIF360 disparate impact), and drift. Results go to a versioned validation report alongside a datasheet or data card for the training data, and a threshold gate blocks promotion of a model version whose metrics regress until a named owner reviews and records a decision. The validation cadence and owner are written in the model's validation record.

Where it goes: 1 application source code, 11 CI/CD pipeline, 12 repository artifacts, 13 tests and evals.

What this provision adds:

  • Validate data and models for accuracy and relevance as well as unintentional bias, with validation frequency calibrated to materiality and model complexity.

Example (scikit-learn + fairlearn), before:

clf = LogisticRegression(max_iter=1000).fit(X_train, y_train)
joblib.dump(clf, 'models/credit_v4.joblib')

After:

from fairlearn.metrics import MetricFrame, selection_rate, demographic_parity_difference
from sklearn.metrics import accuracy_score

clf = LogisticRegression(max_iter=1000).fit(X_train, y_train)
y_pred = clf.predict(X_test)
mf = MetricFrame(metrics={'accuracy': accuracy_score, 'selection_rate': selection_rate},
                 y_true=y_test, y_pred=y_pred, sensitive_features=A_test)
dpd = demographic_parity_difference(y_test, y_pred, sensitive_features=A_test)
write_validation_report('credit_v4', mf.by_group, dpd)
if dpd > MAX_DPD:
    raise SystemExit('bias gate failed: owner review required before release')
joblib.dump(clf, 'models/credit_v4.joblib')

Control: AI decision system without regular accuracy/bias validation. The same guard addresses 4 items with binding law in 1 jurisdiction. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id mas-feat.accuracy-bias-validation · review status: primary source derived

Standard / soft law

Financial AI decisions should offer enquiry, appeal, and review channels to affected people (MAS FEAT)

MAS FEAT Principles — Accountability (External), Principles 10-11 · official text · Soft law or guidance (not binding law) · Singapore (SG)

Per MAS FEAT External Accountability Principles 10-11, data subjects must have channels to enquire about, submit appeals for, and request reviews of AIDA-driven decisions affecting them, and verified supplementary data they provide must be taken into account on review. Detect an AIDA financial-decision path with no enquiry/appeal/review channel.

Who it applies to

  • Duty falls on: deployer
  • Systems covered: automated decision, consequential decision
  • Sectors: lending, insurance, essential services
  • Financial institutions in Singapore using AIDA in decisions affecting data subjects. Voluntary MAS principles.

The guard to add

Send the person an AI-use notice on the decision path, before or when an AI system makes or substantially factors a consequential decision about them, and record its delivery.

A notice step in the decision workflow itself (application intake, underwriting, eligibility, applicant or employee scoring, diagnostic support) that runs before the model call, e.g. send_admt_notice(consumer) ahead of underwrite(), or a notice block rendered on the intake page the person submits from. The notice says that AI is used in the decision, for what, and how to get more information or ask for review, and its delivery is stored with the decision (notice id, channel, timestamp). The template lives in the repo so its content is reviewable; a privacy-policy paragraph alone is not on the decision path.

Where it goes: 1 application source code, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Provide channels to enquire about, appeal, and request review of the AI-driven decision, and take verified supplementary data the person provides into account on review.

Example (FastAPI + OpenAI SDK), before:

@app.post('/applications')
def apply(app_in: Application):
    resp = client.chat.completions.create(model=MODEL, messages=underwriting_prompt(app_in))
    return {'decision': underwrite(resp.choices[0].message.content)}

After:

@app.post('/applications')
def apply(app_in: Application):
    notice = send_admt_notice(app_in.applicant_id, template='ai_decision_notice_v2')
    resp = client.chat.completions.create(model=MODEL, messages=underwriting_prompt(app_in))
    decision = underwrite(resp.choices[0].message.content)
    db.decisions.insert(app_in.id, decision, notice_id=notice.id)
    return {'decision': decision, 'ai_notice': notice.text}

Control: Consequential AI decision without consumer notice. The same guard addresses 6 items with binding law in 5 jurisdictions. Engineering guidance, not legal advice.

Rule id mas-feat.external-review-channels · review status: primary source derived

Standard / soft law

Personal-attribute inputs to AI financial decisions should be justified; no unjustified systematic disadvantage (MAS FEAT)

MAS FEAT Principles — Fairness (Justifiability), Principles 1-2 · official text · Soft law or guidance (not binding law) · Singapore (SG)

Per MAS FEAT Fairness Principles 1-2, financial institutions using AI/data-analytics (AIDA) in decisions must ensure individuals/groups are not systematically disadvantaged unless justified, and that the use of personal attributes as input factors is justified (e.g. via a documented governance rationale). Detect an AIDA financial-decision path that feeds personal/protected attributes without a documented justification or fairness review.

Who it applies to

  • Duty falls on: deployer
  • Systems covered: automated decision, consequential decision
  • Sectors: lending, insurance, essential services
  • Financial institutions in Singapore using AIDA in decision-making. Voluntary MAS principles; Veritas provides quantitative fairness-assessment methodology + open-source toolkit.
  • Whether it applies depends on facts outside the code; a person has to decide.

The guard to add

Build decision prompts and feature sets from an allowlist of decision-relevant fields, and redact protected attributes, known proxies, and free text before the model sees them.

At the prompt builder or feature-assembly step on the consequential-decision path, construct model inputs from an explicit allowlist (FEATURE_ALLOWLIST, APPROVED_FEATURES) instead of passing the whole person record or f-string interpolating its fields. Protected attributes (race, sex, religion, age, disability) and proxies (ZIP or postal code, surname, school, census tract) stay out unless a documented justification and a bias test exist, and free text (cover letters, notes, transcripts) goes through redaction (redact_pii, strip_protected_attributes) first. Log the features used and the model output per decision, and run disparity tests on outcomes; human review lowers the risk but does not replace the allowlist.

Where it goes: 1 application source code, 2 data models, 7 prompt construction, 13 tests and evals.

What this provision adds:

  • Record a justification for each personal attribute used as an input factor, such as a documented governance rationale, and check that no group is systematically disadvantaged without justification.

Example (Python + OpenAI SDK), before:

prompt = f"Applicant {a.last_name}, age {a.age}, zip {a.zip_code}.\nNotes: {a.applicant_notes}\nApprove the loan?"
resp = client.chat.completions.create(model=MODEL, messages=[{'role': 'user', 'content': prompt}])

After:

FEATURE_ALLOWLIST = ['income', 'debt_to_income', 'requested_amount', 'payment_history_months']

features = {k: getattr(a, k) for k in FEATURE_ALLOWLIST}
notes = strip_protected_attributes(a.applicant_notes)   # drops names, ages, places, etc.
messages = [{'role': 'system', 'content': LENDING_RUBRIC},
            {'role': 'user', 'content': json.dumps({'features': features, 'notes': notes})}]
resp = client.chat.completions.create(model=MODEL, messages=messages)
decision_log.record(a.id, features, resp.choices[0].message.content)

Control: Protected or proxy attribute reaches AI decision. The same guard addresses 4 items with binding law in 3 jurisdictions. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id mas-feat.fairness-justifiability · review status: primary source derived

Standard / soft law

Financial institutions should disclose AI use and explain AI-driven decisions on request (MAS FEAT)

MAS FEAT Principles — Transparency, Principles 12-14 · official text · Soft law or guidance (not binding law) · Singapore (SG)

Per MAS FEAT Transparency Principles 12-14, firms should proactively disclose their use of AIDA to data subjects, and on request provide clear explanations of what data is used, how it affects the decision, and the consequences — without exposing IP/source code. Detect an AIDA financial-decision or customer-interaction path with no AI-use disclosure or explanation-on-request capability.

Who it applies to

  • Duty falls on: deployer
  • Systems covered: automated decision
  • Sectors: lending, insurance, essential services
  • Financial institutions in Singapore using AIDA. Voluntary MAS principles; transparency calibrated to materiality (fraud models may justify less disclosure).

The guard to add

Send each adverse AI-assisted decision with its main reasons and the AI's role, plus a way to correct data and appeal to a human who can change the outcome.

Where model output becomes an adverse status (denied, declined, rejected, ineligible), the decision service stores reason codes or principal reasons, the model id and version, and an input snapshot or hash with the decision. The notice to the person (letter, email, portal response) says AI was involved and what role it played, lists the main factors, and links to data correction and to an appeal that creates a human-review task with authority to change the outcome. An explanation endpoint returns the stored record on request, so the deployer can explain a decision long after the model has changed.

Where it goes: 2 data models, 9 AI output handling, 14 user-facing text.

What this provision adds:

  • Proactively disclose AI use to data subjects and, on request, explain what data is used, how it affects the decision and the consequences, without exposing IP or source code.

Example (Python + OpenAI SDK + Pydantic), before:

resp = client.chat.completions.create(model=MODEL, messages=msgs)
if 'deny' in resp.choices[0].message.content.lower():
    application.status = 'denied'
    send_email(applicant.email, 'Your application was declined.')

After:

a = Assessment.model_validate_json(resp.choices[0].message.content)   # decision, reason_codes
if a.decision == 'deny':
    decisions.insert(app_id=application.id, status='denied', reason_codes=a.reason_codes,
                     model=resp.model, input_hash=hashlib.sha256(payload).hexdigest())
    send_email(applicant.email, render('adverse_action_notice.txt',
        reasons=a.reason_codes,
        role_of_ai='An AI model assessed your application; a reviewer can change the outcome.',
        correct_data_url='/profile/data', appeal_url=f'/appeals/new?decision={application.id}'))

Control: Adverse AI decision without explanation/appeal. The same guard addresses 6 items with binding law in 2 jurisdictions. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

  • UnitedHealth nH Predict claim-denial litigation (2023-11; alleged (not proven)). A class action filed in November 2023 alleges that UnitedHealth's nH Predict model had a 90% error rate, measured by denials reversed on appeal, while only about 0.2% of members appealed. UnitedHealth disputes the allegations; the litigation is ongoing. Source: STAT News · evidence grade: primary · cited by Explain adverse AI-assisted decisions and offer a way to contest them — everywhere

Rule id mas-feat.transparency-disclosure-explanation · review status: primary source derived