IMDA AI Governance Framework Singapore: A Plain-English Breakdown for Business Owners
In May 2024, Singapore's Infocomm Media Development Authority published the third iteration of its AI governance guidance — this time focused specifically on Generative AI. The Model AI Governance Framework for Generative AI covers nine dimensions of responsible AI development and deployment, from accountability and data to security and transparency. It's voluntary today, but it signals where Singapore's regulatory direction is heading. For business owners using AI tools, APIs, or AI-assisted decision-making in their operations, this framework is the clearest map available of what "responsible AI governance" looks like in Singapore's context. This guide breaks down all nine dimensions in plain English and tells you what each means for your business.
What IMDA Published and When
The Infocomm Media Development Authority (IMDA) has been building Singapore's AI governance architecture since 2019, when it published the first edition of the Model AI Governance Framework alongside the Personal Data Protection Commission. A revised edition followed in 2020. The 2024 publication — the Model AI Governance Framework for Generative AI — is the third iteration, specifically updated to address the unique risks and challenges posed by large language models, image generators, and other generative AI systems.
The 2024 framework was published as part of a broader package of AI governance outputs from Singapore, including the AI Verify Foundation's testing tools and IMDA's engagement with the Global AI Governance Alliance. It sits within Singapore's Smart Nation strategy and complements the government's National AI Strategy, which targets Singapore as a trusted AI hub in Asia.
The framework is currently voluntary — it does not carry the force of law. But "voluntary" in the Singapore regulatory context often means "not yet mandatory." The PDPA started as principles-based guidance before becoming enforceable regulation. The trajectory of IMDA's framework is toward greater regulatory weight, and companies building AI governance systems today are building against the standard that matters tomorrow.
Enterprise procurement teams, government agencies, and institutional partners are already using IMDA's framework as a questionnaire template. "Voluntary" doesn't mean irrelevant — it means the cost of ignoring it falls on your sales pipeline before it falls on your compliance budget.
The 9 Dimensions Explained
The IMDA framework organises responsible AI governance across nine dimensions. Here's what each one means in practice:
Dimension 1: Accountability. Who owns the AI? This dimension requires clear assignment of responsibility for AI systems — at the board or senior leadership level, not just in the technology team. It covers governance structures, escalation paths for AI incidents, and human oversight mechanisms. For most businesses, this means designating an AI owner and defining what decisions that person has authority to make and escalate.
Dimension 2: Data. What data feeds the AI, and how is it managed? This covers training data quality and provenance (for AI developers), data used in prompts and inputs (for AI operators), and data generated by AI outputs. For businesses using third-party AI APIs, this dimension asks: do you know what data you are sending to those APIs, and do you have the contractual rights and user consents to send it?
Dimension 3: Trusted Development & Deployment. How was the AI built, and how is it being put into production? For AI operators (which is what most Singapore businesses are), this dimension focuses on deployment controls: what safeguards are in place before an AI system goes live, what testing was done, and what monitoring exists post-deployment.
Dimension 4: Incident Reporting & Response. What happens when the AI produces harmful or incorrect outputs? This dimension requires a defined process for identifying, reporting, and responding to AI incidents. It mirrors the incident response processes that well-run organisations already have for cybersecurity — the same discipline applied to AI failures.
Dimension 5: Testing & Assurance. How do you know the AI is working as intended? This covers pre-deployment testing (functionality, bias, adversarial robustness), ongoing monitoring, and third-party assurance where appropriate. For generative AI specifically, this includes red-teaming — deliberately trying to make the model produce harmful outputs — as a standard safety practice.
Dimension 6: Security. How is the AI system protected from adversarial attack? AI systems face unique security threats beyond traditional cybersecurity: prompt injection (attackers manipulating AI behaviour through crafted inputs), model extraction (reverse-engineering proprietary models), and data poisoning (corrupting training data). This dimension requires security controls designed specifically for AI, not just the controls applied to conventional software.
Dimension 7: Content Provenance. How can users distinguish AI-generated content from human-generated content? This dimension covers watermarking, metadata tagging, and disclosure mechanisms that help users understand when they are interacting with or consuming AI-generated material. As deepfakes and AI-generated text become more convincing, content provenance mechanisms are becoming a trust and legal requirement.
Dimension 8: Safety & Alignment. Is the AI behaving in accordance with intended values and objectives? This is the broadest dimension — it covers the alignment of AI behaviour with human values, the prevention of harmful outputs, and the avoidance of unintended consequences. For most businesses, this translates to output filters, content moderation, and human review processes for high-stakes AI decisions.
Dimension 9: Transparency. Can users and stakeholders understand what the AI is doing and why? This dimension covers disclosure to end users (when AI is involved in decisions affecting them), documentation for regulators (audit trails, system descriptions), and communication to the public about AI use. Transparency is increasingly an expectation from employees, customers, and regulators alike.
Who the Framework Applies To
One of the most useful aspects of IMDA's 2024 framework is its explicit distinction between three categories of AI participants, each with different obligations:
AI Developers are organisations that train and develop foundation models — companies like OpenAI, Anthropic, Google DeepMind, and Meta. They bear the heaviest responsibilities under the framework: training data governance, model safety testing, red-teaming, and transparency about model capabilities and limitations. Very few Singapore businesses are AI Developers in this sense.
AI Operators are organisations that deploy AI capabilities — built by developers — into products, services, and workflows. This is where most Singapore businesses sit. If you use ChatGPT, Claude, Gemini, or any third-party AI API to power a product feature, automate a process, or support a decision, you are an AI Operator. Operators are responsible for how the AI is deployed within their context: what inputs they send, what safeguards they implement, how they disclose AI use to end users, and how they respond when the AI fails.
AI Users are the end users of AI-powered products — your customers, employees, or members of the public who interact with AI systems you have deployed. The framework focuses primarily on how Developers and Operators protect and inform Users.
Understanding which category you occupy is the first step to understanding your specific obligations. For most Singapore SMEs and mid-market companies, the AI Operator obligations are what matter — and they are more manageable than many assume.
How the IMDA Framework Relates to ISO 42001
A frequent question from Singapore businesses navigating AI governance is: should we follow IMDA's framework or ISO 42001? The answer is both — because they do different things and are designed to work together.
IMDA's framework is guidance: it tells you what responsible AI governance should look like, dimension by dimension. It describes the goal. It does not tell you how to build a management system to achieve and demonstrate that goal, and it doesn't come with third-party certification.
ISO/IEC 42001:2023 is the world's first AI management system standard. Published in December 2023 and adopted by Singapore as SS ISO/IEC 42001:2024 (with SAC certification available since February 2025), it provides the operational structure: policies, risk assessments, controls, internal audits, management review, continual improvement. It's the operational skeleton that your IMDA-aligned governance sits inside.
The relationship is analogous to the relationship between a food safety regulatory guideline and ISO 22000. The guideline tells you what food safety looks like. ISO 22000 tells you how to build a management system that reliably achieves it. Both are necessary; neither alone is sufficient.
Singapore's government agencies and enterprise procurement teams are beginning to ask for ISO 42001 certification or conformance evidence as proof of AI governance maturity. Implementing ISO 42001 as your operational framework, with IMDA's 9 dimensions as your reference for content, is the most robust approach.
ISO 42001's Annex A lists 65 controls across 9 control categories. VerityOS's AI Governance workspace maps each control to implementation guidance and tracks your Statement of Applicability — the document that tells auditors which controls you've implemented and why.
The Accountability Dimension in Depth
Of all nine IMDA dimensions, Accountability is the most important for businesses to get right first — because every other dimension depends on it. You cannot manage AI risks if no one is accountable for them.
The Accountability dimension asks three fundamental questions. First: who owns AI decisions in your organisation? This means a named individual or committee with defined authority — not a vague statement that "AI decisions are reviewed by the team." For SMEs, this might be the CEO or a designated AI lead. For larger organisations, it might be a Chief AI Officer, a Risk Committee, or an AI Governance Committee with clear terms of reference.
Second: what escalation paths exist when AI produces a harmful or unexpected output? If your AI system gives a customer incorrect medical, legal, or financial information — or makes a discriminatory decision — what happens next? Who is notified? Who makes the call on remediation? How is the affected user informed? These paths need to be defined before an incident occurs, not improvised during one.
Third: how is human oversight built in? This is where the concept of human-in-the-loop becomes concrete. Not every AI decision needs human review, but high-stakes decisions — those that significantly affect customers, employees, or third parties — should have a defined review gate. The IMDA framework explicitly calls for human oversight to be proportionate to the risk level of the AI application. Low-stakes applications (summarising meeting notes) can run with minimal oversight. High-stakes applications (underwriting decisions, medical triage support, employee performance assessment) need robust human review processes.
Demonstrating accountability means more than having a policy. It means having documented processes, trained personnel, and evidence that the processes are being followed — the kind of evidence that an ISO 42001 audit would expect to see.
The Data Dimension: Where Most Companies Fall Short
The Data dimension of IMDA's framework is where the largest gap between aspiration and reality exists in most Singapore organisations. Here's why:
Most businesses using AI APIs (ChatGPT, Claude, Gemini, or other models via their providers) have not documented what data those APIs process. They may be sending customer data, employee data, proprietary business information, or third-party confidential information in their prompts — without understanding whether the API provider uses that data for model training, how long it is retained, or what protections apply.
Under Singapore's PDPA, sending personal data to a third-party processor requires contractual data protection safeguards. Most major AI API providers offer data processing agreements, but most businesses using those APIs have not reviewed or executed them. This is a compliance gap with immediate implications — not a future risk.
Beyond compliance, data quality drives AI quality. Garbage in, garbage out is as true for AI as it is for conventional analytics. If you are using AI to analyse customer sentiment, generate product descriptions, or assess risk, and the input data is incomplete, biased, or outdated, the AI outputs will be systematically flawed in ways that may not be immediately obvious.
The IMDA framework's data dimension asks businesses to: document what data is used in AI systems (training, fine-tuning, and inference); verify that data collection has appropriate consent and purpose limitation; assess data quality and representativeness; and understand the data-handling practices of third-party AI providers. These are not exotic requirements — they are extensions of good data governance practice into the AI context.
Practical First Steps for a Singapore Business
Implementing IMDA framework alignment doesn't require a six-month consultancy project. It starts with clear-eyed inventory and honest documentation. Here are the most impactful first steps:
Step 1 — Inventory your AI systems. List every AI tool, API, and automated system your business uses or operates. Include obvious systems (ChatGPT for content, AI customer service bots) and less obvious ones (AI-powered spam filters, algorithmic scheduling tools, predictive analytics in your CRM). Most businesses are surprised by how many AI touchpoints exist when they look systematically.
Step 2 — Document data flows. For each AI system, map what data flows in (inputs, prompts, training data) and what data flows out (outputs, logs, derived insights). Identify where personal data is involved and check whether the appropriate data processing agreements and consent mechanisms are in place.
Step 3 — Assign accountability owners. For each material AI system, designate an accountable owner — the person responsible for its performance, its safeguards, and its compliance with IMDA and PDPA requirements. Document this assignment in writing.
Step 4 — Build approval gates for high-stakes outputs. Identify AI applications where errors could harm customers, create legal exposure, or damage the business. For each of these, define a human review requirement before the AI output is acted upon or communicated externally.
Step 5 — Review third-party AI providers.For every AI API you use, check the provider's data processing terms, understand their model training policies (does your data train their models?), and ensure appropriate contractual protections are in place.
These five steps — inventory, data flows, accountability, approval gates, and third-party review — won't make you ISO 42001 certified. But they will give you a defensible foundation that demonstrates good faith alignment with IMDA's framework and puts you on the right trajectory for deeper implementation.
VerityOS's AI Governance workspace tracks all 65 ISO 42001 controls, manages your AI systems registry, and generates your Statement of Applicability — the key document for both internal governance and external certification audits. Built for Singapore, with IMDA alignment built in.
Frequently Asked Questions
Build Your AI Governance System Aligned to IMDA and ISO 42001
VerityOS's AI Governance workspace gives Singapore businesses the operational infrastructure to align with IMDA's framework and ISO 42001. AI systems registry, 65-control tracker, Statement of Applicability, and human-in-the-loop approval workflows — all in one place.