Summary: PDPC/IMDA’s Model AI Governance Framework — two guiding principles, four practice areas, plus a self-assessment guide, a use-case compendium, and the AI Verify testing toolkit and Foundation.
Sources: raw/Laws/Singapore’s_Approach_to_AI_Governance_PDPC.md
Last updated: 2026-07-28
Voluntary, industry-facing, and notably concrete about implementation. First edition released 23 January 2019; second edition 21 January 2020 (source: Singapore’s_Approach_to_AI_Governance_PDPC.md).
Two guiding principles
- Decisions made by AI should be explainable, transparent and fair.
- AI systems should be human-centric.
Deliberately minimal compared with NIST’s seven characteristics or OECD’s five principles. The substance is in the practice areas.
Four practice areas — “From Principles to Practice”
1. Internal governance structures and measures — “Clear roles and responsibilities in your organisation,” “SOPs to monitor and manage risks,” “Staff training.”
2. Determining the level of human involvement in AI-augmented decision-making — “Appropriate degree of human involvement,” “Minimise the risk of harm to individuals.”
This is the framework’s distinctive contribution: it treats how much human as an explicit, per-use-case design decision rather than a binary. Compare AI Act Art 14, which requires effective human oversight but does not offer a calibration method.
3. Operations management — “Minimise bias in data and model,” “Risk-based approach to measures such as explainability, robustness and regular tuning.”
4. Stakeholder interaction and communication — “Make AI policies known to users,” “Allow users to provide feedback, if possible,” “Make communications easy to understand.”
The second edition “includes additional considerations (such as robustness and reproducibility)” and expanded the customer-relationship section into broader stakeholder interaction. It “continues to take a sector- and technology-agnostic approach that can complement sector-specific requirements.”
The supporting artefacts
What distinguishes Singapore’s approach is the tooling around the framework:
ISAGO — Implementation and Self Assessment Guide for Organisations. A companion guide to “help organisations assess the alignment of their AI governance practices with the Model Framework,” with “an extensive list of useful industry examples and practices.” Developed with the World Economic Forum’s Centre for the Fourth Industrial Revolution, “in close consultation with the industry, with contributions from over 60 organisations.”
Compendium of Use Cases — two volumes of real implementations. Volume 1: Callsign, DBS Bank, HSBC, MSD, Ngee Ann Polytechnic, Omada Health, UCARE.AI, Visa Asia Pacific. Volume 2: City of Darwin, Google, Microsoft, Taiger, plus AI Singapore’s 100 Experiments projects with IBM, RenalTeam, Sompo Asia Holdings and VersaFleet.
A Guide to Job Redesign in the Age of AI — launched 4 December 2020 with IMDA and the Lee Kuan Yew Centre for Innovative Cities at SUTD.
AI Verify Foundation — a not-for-profit that will “foster a community to contribute to the use and development of AI testing frameworks, code base, standards, and best practices” and “create a neutral platform for open collaboration and idea-sharing on testing and governing AI.” Seven premier members — Aicadium, Google, IBM, IMDA, Microsoft, Red Hat, Salesforce — plus more than 60 general members.
Why AI Verify is the interesting part for security
Every framework in this corpus asserts that AI systems must be tested. Almost none supply testing infrastructure. AI Verify is an attempt at a shared, open testing toolkit with industry governance.
That is the gap AI Act Art 15(2) identifies when it says the Commission “shall… encourage, as appropriate, the development of benchmarks and measurement methodologies” with metrology and benchmarking authorities — and the gap Code of Practice Appendix 3 addresses with “Qualified Evaluation Teams and Resources” and independent external evaluations.
Common measurement is the precondition for “state of the art” being a meaningful compliance standard rather than a self-declared one.
Governance
The Advisory Council on the Ethical Use of AI and Data oversees the work.
Position relative to the other frameworks
| Binding? | Testing tooling? | Sector-specific? | |
|---|---|---|---|
| EU AI Act | Yes | No (delegated to standards) | No, but Annex III is use-case keyed |
| NIST AI RMF | No | No (Playbook only) | No |
| OECD Principles | No (Recommendation) | No | No |
| Singapore Model Framework | No | Yes — AI Verify | No |
Singapore’s is the only one in this corpus that ships tools.