01 · Bound the use
Start with the decision, not the model
Write down the task, affected users, failure modes and the decisions that must remain with a person. A generic “AI policy” is not a control.
- Intended and prohibited uses
- Human approval points
- Escalation and shutdown conditions
02 · Make accountability visible
One owner for the outcome
Assign business, technical and risk owners. The business owner remains responsible even when a vendor supplies the model.
- Named service owner
- Documented change approval
- Incident and appeal route
03 · Test what matters
Evaluate in the Singapore deployment context
Use realistic prompts and local workflows. Measure factuality, robustness, harmful output and data handling before launch and after material changes.
Open responsible source ↗04 · Protect people and data
Privacy is a lifecycle control
Minimise personal data, define a lawful purpose, set retention and access controls, and review vendors before information crosses organisational boundaries.
Open responsible source ↗FREQUENTLY ASKED
Two points worth making clear
Is Singapore AI governance a certification?+
No. The frameworks guide accountable deployment; a framework alone does not certify a product or remove an organisation’s legal duties.
Do small pilots need governance?+
Yes, proportionately. A pilot still needs a defined purpose, data boundary, owner and stop condition.