01 · Bound the use

Start with the decision, not the model

Write down the task, affected users, failure modes and the decisions that must remain with a person. A generic “AI policy” is not a control.

  • Intended and prohibited uses
  • Human approval points
  • Escalation and shutdown conditions
Open responsible source ↗

02 · Make accountability visible

One owner for the outcome

Assign business, technical and risk owners. The business owner remains responsible even when a vendor supplies the model.

  • Named service owner
  • Documented change approval
  • Incident and appeal route
Open responsible source ↗

03 · Test what matters

Evaluate in the Singapore deployment context

Use realistic prompts and local workflows. Measure factuality, robustness, harmful output and data handling before launch and after material changes.

Open responsible source ↗

04 · Protect people and data

Privacy is a lifecycle control

Minimise personal data, define a lawful purpose, set retention and access controls, and review vendors before information crosses organisational boundaries.

Open responsible source ↗

FREQUENTLY ASKED

Two points worth making clear

Is Singapore AI governance a certification?+

No. The frameworks guide accountable deployment; a framework alone does not certify a product or remove an organisation’s legal duties.

Do small pilots need governance?+

Yes, proportionately. A pilot still needs a defined purpose, data boundary, owner and stop condition.

NEXT STEP

Apply the framework to your actual task

Desk AI can help structure evaluation questions and controls. It does not make procurement decisions or retain chat data.