As banks race to deploy increasingly autonomous systems, a new framework from Singapore offers a message that will resonate far beyond the city-state: governance alone is not enough.
The Model AI Governance Framework for Agentic AI, published by Singapore’s MDA regulator recently, argued that organisations cannot rely on policies, ethics committees or simply putting a human “in the loop” when deploying autonomous software systems.
Instead, they need technical controls, testing and continuous assurance mechanisms capable of proving that these systems remain safe, reliable and within acceptable risk boundaries.
Singapore’s MDA
For software testing and quality engineering teams in financial services, that may be the framework’s most important contribution.
The MDA document effectively treats governance as an engineering challenge that requires evidence, validation and ongoing monitoring rather than a compliance exercise.
That comes at a significant moment for banking. Financial institutions are accelerating investments in agentic systems capable of taking decisions and executing tasks with limited human intervention.
Lloyds Banking Group recently announced plans to hire hundreds of specialists to develop agentic capabilities. Deutsche Bank has spoken about using new technologies to dramatically compress software delivery cycles, while JPMorgan Chase has argued that as more code is generated automatically, the importance of engineering fundamentals, including testing and governance, only increases.
At the same time, regulators are becoming increasingly focused on operational resilience and proof that controls remain effective.
The EU’s Digital Operational Resilience Act (DORA) requires firms to demonstrate robust testing and resilience capabilities, while supervisors including the European Central Bank have repeatedly warned about the risks associated with rapidly adopting new technologies without appropriate safeguards.
Against that backdrop, the Singapore framework reads almost like a blueprint for what many are now calling evaluation engineering.
Singapore
The document called for organisations to assess and bound risks before deployment, considering factors such as the level of autonomy, access to sensitive data, system complexity and deployment environment.
It advocated meaningful human accountability but also emphasises the need for technical controls and clearly defined processes that limit the behaviour of autonomous systems.
Crucially, the framework places significant emphasis on testing and validation. It calls for pre-deployment evaluations, continuous monitoring once systems are in production, testing of interactions between agents and external tools, scenario-based evaluations and mechanisms to detect and respond to incidents and unexpected behaviour.
QA capabilities
For quality engineering teams, those recommendations map directly onto capabilities that are already becoming critical in financial services.
Pre-deployment validation resembles traditional testing disciplines but at a much greater level of complexity, requiring organisations to examine not only whether systems function correctly but also whether autonomous agents behave appropriately under different conditions.
The requirement to continuously monitor deployed systems points towards a future of ongoing assurance rather than periodic testing exercises.

Risk-based evaluations and scenario testing closely resemble resilience testing and chaos engineering practices that are increasingly being adopted across the banking sector.
The framework’s emphasis on constraining behaviour and bounding autonomy also has important implications for model validation and governance functions.
Banks will need mechanisms to demonstrate that autonomous systems cannot exceed predefined authority levels, access inappropriate information or take actions that violate policy or regulation.
Perhaps most importantly, the document implicitly acknowledges a reality that many institutions are only beginning to confront: agentic systems cannot simply be tested once and then left alone.
Unlike conventional software applications, autonomous systems can exhibit unpredictable behaviour depending on context, data inputs and interactions with other systems. Assurance therefore becomes a continuous process involving monitoring, testing, feedback loops and ongoing evaluation.
That requirement for evidence may ultimately prove to be the framework’s most significant message for financial services.
Regulators demand proof
Regulators increasingly want proof that systems are being properly governed, tested and controlled. As autonomous technologies become more deeply embedded within banking operations, policy documents and governance committees alone are unlikely to satisfy supervisors.
Instead, firms may need to demonstrate that they can continuously evaluate and constrain these systems in practice.
For software testing and quality engineering teams, that could represent a profound shift in responsibilities. Testing is no longer simply about verifying code quality before release.
It is becoming central to how organisations govern, manage and prove the safety and resilience of increasingly autonomous systems.
Singapore’s latest framework may therefore go down less as another piece of AI guidance and more as an early indication of where regulation and industry expectations are heading: towards a world in which governance is inseparable from testing, and assurance becomes a continuous engineering discipline.
REGISTER TODAY – SIMPLY CLICK HERE
Why not become a QA Financial subscriber?
It’s entirely FREE
* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *
REGULATION & COMPLIANCE
Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.
READ MORE
WATCH NOW
QA FINANCIAL PODCASTS




