Singapore's Model AI Governance Framework, explained for business owners

What IMDA's governance frameworks for traditional and generative AI actually ask of companies, which parts matter for SMEs, and how AI Verify fits in.

By TENONTECH Advisory Team · · 4 min read

Singapore has taken a distinctive approach to AI regulation. Rather than passing a single AI law, it has published voluntary frameworks, testing tools and sector guidance, while relying on existing laws such as the PDPA to cover specific harms. For businesses, this means fewer hard rules but more judgement about what responsible use looks like.

The centrepiece is the Model AI Governance Framework from the Infocomm Media Development Authority (IMDA) and the Personal Data Protection Commission (PDPC). This article explains what it says, in plain terms, and which parts are worth acting on if you run a small or mid-sized company.

Two frameworks, not one

There are now two related documents:

  • The Model AI Governance Framework (first published 2019, second edition 2020), written for what is now called traditional AI: systems that classify, predict or recommend, such as credit scoring or demand forecasting
  • The Model AI Governance Framework for Generative AI (2024), which extends the approach to large language models and image generators, where outputs are open-ended and harder to test

Both are voluntary. Neither creates legal obligations on its own. They are, however, widely referenced by regulators, larger clients and procurement teams, so aligning with them is a practical advantage.

The core ideas of the original framework

The 2020 framework rests on two principles: decisions made by AI should be explainable, transparent and fair, and AI systems should be human-centric. It turns these into four areas of practice.

Internal governance

Someone in the organisation is clearly responsible for AI. Roles are defined, staff are trained, and risks are managed through existing structures where possible.

Level of human involvement

Not every AI decision needs a human to approve it. The framework suggests weighing the severity and probability of harm. A product recommendation can run automatically. A decision to reject an insurance claim probably needs a person to review it.

Operations management

Data quality, model testing, monitoring and documentation. In practice: know what data trained or grounds the system, test it before launch, and keep checking it afterwards.

Stakeholder communication

Tell people when they are dealing with AI, explain decisions where it matters, and give them a way to raise concerns or ask for review.

What the generative AI framework adds

The 2024 framework recognises that generative AI involves many parties (model developers, application builders, companies deploying the tool) and that responsibility should be shared accordingly. It sets out nine dimensions:

DimensionWhat it means in practice
AccountabilityClear allocation of responsibility across developers, deployers and users
DataQuality of data used for training and grounding, and respect for personal data and copyright
Trusted development and deploymentFollowing good practice in building and releasing systems, with transparency about how they work
Incident reportingProcesses for spotting, reporting and learning from failures
Testing and assuranceIndependent and third-party testing, including red-teaming
SecurityProtection against new attack types such as prompt injection
Content provenanceWays to show whether content was AI-generated, such as watermarking or labelling
Safety and alignment researchInvestment in research to keep models safe
AI for public goodUsing AI to benefit society, including skills and access

Several of these, such as safety research, are aimed at governments and model developers rather than companies using AI. For a typical SME deploying a chatbot or an internal assistant, the relevant ones are accountability, data, incident reporting, testing, security and content provenance.

Where AI Verify fits

AI Verify is a testing framework and software toolkit developed by IMDA, now stewarded by the AI Verify Foundation. It lets organisations test AI systems against recognised governance principles and produce a report. For generative AI, the Foundation has also released tools for evaluating large language model applications.

Most SMEs will not run AI Verify themselves. It becomes relevant when you are building AI into a product you sell, when a large client asks for evidence of testing, or when you operate in a regulated sector.

Turning the framework into five actions

For a company deploying AI rather than building models, we usually recommend:

  1. Name an owner. One person accountable for AI use, with authority to approve or stop new use cases.
  2. Classify use cases by risk. A simple low, medium and high rating, based on the potential harm to customers, staff or the business if the AI is wrong.
  3. Match human oversight to the risk. High-risk uses get a human review before decisions take effect.
  4. Be open with customers. Label chatbots as automated, and give people an easy route to a human.
  5. Log and review incidents. Keep a record of wrong or harmful outputs and what was done about them.

These steps fit on a page and can be in place within a month. They also map neatly onto PDPA obligations, which we cover in our PDPA checklist for generative AI.

Sector rules still apply

Voluntary frameworks sit alongside binding rules in some sectors. Financial institutions, for example, are subject to the Monetary Authority of Singapore's guidance on the responsible use of AI and data analytics. Healthcare providers have their own guidelines. If you are in a regulated sector, start with your regulator's expectations.

Frequently asked questions

Is it compulsory to follow the Model AI Governance Framework?

No. It is voluntary guidance. However, it reflects how Singapore regulators think about responsible AI, and following it makes it easier to show you have acted reasonably if something goes wrong.

Does Singapore have an AI law?

There is no single, general AI act. AI is governed through existing laws such as the PDPA, sector regulations and targeted legislation, supported by voluntary frameworks and testing tools.

We only use off-the-shelf AI tools. Does the framework apply to us?

The principles still apply to how you deploy and use those tools: who is accountable, how much human oversight there is, and how you communicate with customers. The technical testing sections matter less if you are not building the model.

Need help applying this in your business? TENONTECH works with Singapore SMEs on AI strategy, implementation and governance. Book a consultation.

Related reading