Artificial intelligence has moved from pilot projects to daily practice inside private equity, venture capital and alternative investment firms across Asia. Deal teams use AI to evaluate potential targets and draft memos; operations teams use it to reconcile data and monitor portfolios; and investor relations teams use it to prepare communications for limited partners. Until now, none of this activity has been guided by a formal regulatory framework in Singapore.
That is changing. On 13 November 2025, the Monetary Authority of Singapore (MAS) published a consultation paper proposing Guidelines on Artificial Intelligence Risk Management (AIRG), setting out supervisory expectations for how financial institutions should manage their use of AI. The guidelines have a wide scope, applying to all financial institutions that use, develop, obtain, or deploy AI – including AI accessed via third-party tools and vendors – and cover everything from board-level oversight to controls across the entire AI lifecycle.
For banks and insurers with well-established model risk functions, this represents an extension of existing practice. For private equity, venture capital and other alternative investment managers, many of whom have adopted AI tools faster than they have built the governance to support them, it represents a more significant shift. This article translates MAS’s proposals into practical considerations for fund managers, COOs, compliance teams and technology leaders to address now, ahead of finalisation.
Why This Matters Even If You're "Just Using" AI Tools
Smaller and mid-sized managers often assume that formal AI governance is a concern for banks running proprietary trading algorithms or credit models – not for firms using a generative AI copilot to summarise data room documents or draft investment committee papers.
MAS’s proposed approach does not support that assumption. The guidelines are designed to apply proportionately, scaled to a firm’s size, complexity and the materiality of its AI use. Even firms with limited AI exposure are expected to maintain baseline controls: clear rules on permitted and prohibited use cases, defined ownership of AI systems, and basic oversight. Assistive tools such as copilots and analytics engines fall explicitly within scope and are not exempt simply because a human remains “in the loop” at some point in the process.
This means fund managers can no longer rely on informal AI adoption – a partner trialling a new tool, an analyst signing up for a chatbot, or a vendor gradually adding AI features to an existing platform. Regulatory expectations are moving toward requiring firms to formally and comprehensively understand where AI is used across their operations.
Where AI Is Actually Showing Up in Fund Operations
Before governance can be established, managers need a candid assessment of where AI currently sits within the firm. In private markets, this typically includes:
- Deal sourcing and due diligence – AI-assisted screening of targets, summarisation of data rooms, and drafting of preliminary diligence findings
- Portfolio monitoring – automated extraction and analysis of portfolio company financials and KPIs
- Valuation support – AI-assisted modelling inputs and scenario analysis
- Investor relations and reporting – drafting of LP updates, quarterly reports and marketing materials
- Fund operations – reconciliation, NAV support, document generation and workflow automation
- Compliance and legal – contract review, regulatory monitoring and policy drafting
Many of these use cases run through third-party platforms rather than in-house development, which places the vendor relationship under closer scrutiny – a point addressed further below.
Data Quality, Privacy and Security: The Foundation
The reliability of AI outputs depends entirely on the quality of the data behind them, and this is an area where many private-market firms remain underprepared. Portfolio data is often fragmented across spreadsheets, portals and legacy systems, with inconsistent formatting and limited data lineage. Feeding that data into AI tools without first addressing its quality only accelerates and compounds existing errors.
Fund managers preparing for MAS’s expectations should be asking:
- Do we know what data is being fed into which AI tools, and where that data is processed and stored?
- Is confidential deal information, LP data, or portfolio company financial information being shared with third-party AI systems in a way that breaches confidentiality obligations or data protection requirements?
- Are controls in place to prevent sensitive data from being used to train external AI models?
- Is there a clear data retention and deletion policy for AI-generated outputs?
These are not new questions in principle –they align with existing obligations under Singapore’s data protection framework –but the introduction of AI has significantly raised their importance and broadened their scope.
Human Oversight: Where AI Assists and Where Humans Decide
A consistent theme in MAS’s proposed guidelines is that AI use should be accompanied by human oversight appropriate to the level of risk and impact involved. This is particularly important for investment decisions, where the line between “AI-assisted analysis” and “AI-driven decision” can blur quickly in practice.
Fund managers should be explicit, in policy and in practice, about:
- Which decisions AI can support versus which decisions require independent human judgement and sign-off
- Who is accountable when an AI-assisted recommendation informs an investment decision that goes wrong
- How outputs from generative AI tools are checked for accuracy before they inform investor communications, valuations or compliance filings
Accountability cannot be outsourced to the technology. If an error appears in an AI-prepared portfolio valuation or LP report, the fund manager – not the software vendor – must answer for it to investors and regulators.
Managing Third-Party AI Tools and Vendors
Many fund managers do not build their own AI models; instead, they rely on AI embedded within CRM systems, portfolio monitoring platforms, document review tools and communication software. MAS’s proposed guidelines make clear that AI accessed through third-party tools falls within scope, not outside it.
Practical steps include:
- Maintaining an inventory of which vendors and platforms use AI, and what that AI does
- Understanding what data those vendors access, retain and may reuse
- Reviewing vendor contracts for AI-specific clauses on data handling, confidentiality, liability and model updates
- Requiring vendors to disclose material changes to AI functionality, since a routine software update can quietly introduce new AI capabilities into a firm’s workflow
In effect, vendor due diligence now requires an AI lens – not as a one-off exercise, but as an ongoing element of vendor management.
Documentation, Monitoring and Governance: Building the Paper Trail
MAS’s approach is expected to require firms to identify AI use cases, assess the materiality of associated risks, and maintain an AI inventory as part of their governance arrangements, policies and procedures – with oversight at board and senior management level, and potentially through a dedicated committee where AI risk exposure is high.
For a fund manager, this translates into practical documentation:
- An AI use case register, however simple, listing what AI tools are used, by whom, for what purpose, and with what oversight
- A risk assessment for each use case, considering the potential impact of errors, the complexity of the tool, and the degree of reliance placed on its output
- Periodic review cycles to catch new AI use introduced through vendor updates or ad hoc adoption by individual teams
- Clear policies on acceptable use, escalation paths for AI-related issues, and training for staff who rely on these tools
This does not need to be a full-scale compliance exercise from the outset. MAS’s proportionality principle is intended to allow a framework sized appropriately to the firm’s scale and extent of AI exposure.
Practical Steps to Take Now
Fund managers do not need to wait for the guidelines to be finalised before preparing. Useful initial steps include:
- Run an AI discovery exercise across investment, operations, compliance and IR functions to identify where AI is already in use, including within third-party platforms
- Assign clear ownership for AI governance, even if it initially sits with an existing compliance or COO function rather than a dedicated committee
- Review data flows into AI tools, particularly for confidential deal and portfolio information
- Set baseline usage policies covering what AI can and cannot be used for, and where human sign-off is mandatory
- Revisit vendor contracts for AI-specific provisions on data handling and disclosure
- Build a simple AI inventory as the foundation for more formal risk assessments later
Technology Alone Is Not the Answer
There is a natural tendency, when adopting AI, to focus on selecting the right tools –the most effective deal-screening model or the most user-friendly reporting copilot. MAS’s proposed guidelines are a reminder that tool selection is only half the equation. For AI to be used responsibly and sustainably in private markets, the underlying infrastructure must also be in place: clean, well-governed data; clearly defined accountability; documented oversight; and a technology environment capable of supporting monitoring and control at scale.
For private equity, venture capital and other alternative investment managers operating in or from Singapore, now is the time to move AI governance from an informal, ad hoc approach to a proper, defensible framework – not because the guidelines demand perfection today, but because the direction of travel is clear, and firms that act early will be far better positioned once these expectations become mandatory requirements.
Reference: Monetary Authority of Singapore, “MAS Guidelines for Artificial Intelligence Risk Management,” media release, 13 November 2025. Available at mas.gov.sg.