Singapore's Model AI Governance Framework, explained for business owners
What IMDA's governance frameworks for traditional and generative AI actually ask of companies, which parts matter for SMEs, and how AI Verify fits in.
Singapore has taken a distinctive approach to AI regulation. Rather than passing a single AI law, it has published voluntary frameworks, testing tools and sector guidance, while relying on existing laws such as the PDPA to cover specific harms. For businesses, this means fewer hard rules but more judgement about what responsible use looks like.
The centrepiece is the Model AI Governance Framework from the Infocomm Media Development Authority (IMDA) and the Personal Data Protection Commission (PDPC). This article explains what it says, in plain terms, and which parts are worth acting on if you run a small or mid-sized company.
Two frameworks, not one
There are now two related documents:
- The Model AI Governance Framework (first published 2019, second edition 2020), written for what is now called traditional AI: systems that classify, predict or recommend, such as credit scoring or demand forecasting
- The Model AI Governance Framework for Generative AI (2024), which extends the approach to large language models and image generators, where outputs are open-ended and harder to test
Both are voluntary. Neither creates legal obligations on its own. They are, however, widely referenced by regulators, larger clients and procurement teams, so aligning with them is a practical advantage.
The core ideas of the original framework
The 2020 framework rests on two principles: decisions made by AI should be explainable, transparent and fair, and AI systems should be human-centric. It turns these into four areas of practice.
Internal governance
Someone in the organisation is clearly responsible for AI. Roles are defined, staff are trained, and risks are managed through existing structures where possible.
Level of human involvement
Not every AI decision needs a human to approve it. The framework suggests weighing the severity and probability of harm. A product recommendation can run automatically. A decision to reject an insurance claim probably needs a person to review it.
Operations management
Data quality, model testing, monitoring and documentation. In practice: know what data trained or grounds the system, test it before launch, and keep checking it afterwards.
Stakeholder communication
Tell people when they are dealing with AI, explain decisions where it matters, and give them a way to raise concerns or ask for review.
What the generative AI framework adds
The 2024 framework recognises that generative AI involves many parties (model developers, application builders, companies deploying the tool) and that responsibility should be shared accordingly. It sets out nine dimensions:
| Dimension | What it means in practice |
|---|---|
| Accountability | Clear allocation of responsibility across developers, deployers and users |
| Data | Quality of data used for training and grounding, and respect for personal data and copyright |
| Trusted development and deployment | Following good practice in building and releasing systems, with transparency about how they work |
| Incident reporting | Processes for spotting, reporting and learning from failures |
| Testing and assurance | Independent and third-party testing, including red-teaming |
| Security | Protection against new attack types such as prompt injection |
| Content provenance | Ways to show whether content was AI-generated, such as watermarking or labelling |
| Safety and alignment research | Investment in research to keep models safe |
| AI for public good | Using AI to benefit society, including skills and access |
Several of these, such as safety research, are aimed at governments and model developers rather than companies using AI. For a typical SME deploying a chatbot or an internal assistant, the relevant ones are accountability, data, incident reporting, testing, security and content provenance.
Where AI Verify fits
AI Verify is a testing framework and software toolkit developed by IMDA, now stewarded by the AI Verify Foundation. It lets organisations test AI systems against recognised governance principles and produce a report. For generative AI, the Foundation has also released tools for evaluating large language model applications.
Most SMEs will not run AI Verify themselves. It becomes relevant when you are building AI into a product you sell, when a large client asks for evidence of testing, or when you operate in a regulated sector.
Turning the framework into five actions
For a company deploying AI rather than building models, we usually recommend:
- Name an owner. One person accountable for AI use, with authority to approve or stop new use cases.
- Classify use cases by risk. A simple low, medium and high rating, based on the potential harm to customers, staff or the business if the AI is wrong.
- Match human oversight to the risk. High-risk uses get a human review before decisions take effect.
- Be open with customers. Label chatbots as automated, and give people an easy route to a human.
- Log and review incidents. Keep a record of wrong or harmful outputs and what was done about them.
These steps fit on a page and can be in place within a month. They also map neatly onto PDPA obligations, which we cover in our PDPA checklist for generative AI.
Sector rules still apply
Voluntary frameworks sit alongside binding rules in some sectors. Financial institutions, for example, are subject to the Monetary Authority of Singapore's guidance on the responsible use of AI and data analytics. Healthcare providers have their own guidelines. If you are in a regulated sector, start with your regulator's expectations.
Frequently asked questions
Is it compulsory to follow the Model AI Governance Framework?
No. It is voluntary guidance. However, it reflects how Singapore regulators think about responsible AI, and following it makes it easier to show you have acted reasonably if something goes wrong.
Does Singapore have an AI law?
There is no single, general AI act. AI is governed through existing laws such as the PDPA, sector regulations and targeted legislation, supported by voluntary frameworks and testing tools.
We only use off-the-shelf AI tools. Does the framework apply to us?
The principles still apply to how you deploy and use those tools: who is accountable, how much human oversight there is, and how you communicate with customers. The technical testing sections matter less if you are not building the model.
Need help applying this in your business? TENONTECH works with Singapore SMEs on AI strategy, implementation and governance. Book a consultation.