
Singapore's central bank just set up a new team — and if your business supplies, supports, or services a bank, the ripple is already heading your way.
The Monetary Authority of Singapore (MAS), together with the Association of Banks in Singapore, has established the AI-Driven Cyber and Technology Risk Taskforce — ACT for short. Its mandate: monitor hackers using AI to break into financial systems and harden the banks before that happens.
If you don't run a bank, you might move on. Don't. Here's why it matters to you.
ACT is a joint MAS–banking industry body, focused specifically on AI-driven cyber threats to Singapore's financial infrastructure.
AI-powered attacks are accelerating. MAS is acting now — which means banks will act soon, and their suppliers will feel it next.
Regulation rarely stays inside one sector. When MAS raises the bar for banks, the bar rises for every business in the supply chain.
Banks in Singapore have followed the same pattern for years. When MAS tells a bank to manage a risk, the bank doesn't just fix its own systems — it checks whether every company it works with is managing that risk too.
Think about who a bank works with: payment processors, software vendors, marketing agencies, law firms, accountants. If your business sends an invoice to a bank, handles their data, or plugs into their systems in any way — you are on that list.
Strip away the official language and ACT is worried about three specific threats. None of them are unique to banks — a 50-person logistics firm or a family-run trading business faces the exact same risks.
Instead of a person spending weeks searching for a gap in your systems, AI tools can scan for one in minutes — at a scale no human team can match.
AI now writes emails, voice messages, and video that sound exactly like your boss, your bank, or your biggest client. The old advice — "look for bad grammar" — no longer works.
AI can try thousands of password combinations faster than any human, running around the clock until it finds the one that works.
The only difference between banks and most SMEs? Banks now have a taskforce dedicated to these risks. Most SMEs have nothing.
Here's what will likely happen over the next one to two years. Banks working with ACT will start asking their suppliers new, pointed questions about AI risk management — and suppliers without clear answers risk losing contracts.
The cascade above is not hypothetical. It is the established pattern every time MAS introduces new requirements. Regulatory pressure flows downstream — from regulator, to bank, to you.
When a bank's procurement or risk team follows up, expect questions like these. The businesses that win are not the ones scrambling to write a policy the night before a client review — they're the ones who already have a simple, honest answer ready.
A vague answer signals unpreparedness. A short, clear one-pager signals a business that takes this seriously.
If staff are using ChatGPT or similar tools with no oversight, this question will expose the gap immediately.
Incident response doesn't need to be elaborate — but it needs to exist. Silence is not an acceptable answer.
You don't need a taskforce. You don't need a big budget. You need three things in place before the client questionnaire arrives.
Even a short, honest one-pager beats silence. Document what AI tools your team uses, who approves them, and what the rules are. That alone puts you ahead of most SMEs.
It doesn't have to be a full-time hire. It just needs to be someone's clear, named responsibility — not everyone's vague concern.
Many SMEs have staff using ChatGPT or similar tools with zero oversight. That is almost always the first gap a client questionnaire finds — and the easiest one to fix.
MAS built ACT to protect banks. But regulatory ripples from Singapore's financial sector have a consistent track record — they reach suppliers faster than most SMEs anticipate, and they arrive as a client question, not a regulatory letter.
Vulnerability scanning, impersonation, and credential attacks — all already targeting businesses your size.
The window before supplier questionnaires become standard practice across Singapore's banking sector.
A single honest document on your AI risk approach is enough to differentiate your business from most competitors.
Ewashi helps ASEAN SMEs build a simple, honest AI risk answer — before a client ever asks the question. No jargon. No unnecessary complexity. Just a clear position you can stand behind.
MAS and ABS Establish Taskforce to Strengthen Cyber and Technology Resilience against AI-driven Threats — Monetary Authority of Singapore, official media release.
Ewashi · All rights reserved.