Reviewed 30 September 2026Singapore financial services

MAS IAC software: what a solution should support for the five accountability outcomes.

The Monetary Authority of Singapore's Guidelines on Individual Accountability and Conduct are an outcomes framework, not a software specification. A useful IAC system should make responsibilities, evidence, changes, approvals, conduct issues, and oversight easier to inspect without pretending that buying a product creates compliance.

MAS published the Guidelines on 10 September 2020. The official MAS IAC page describes five high-level outcomes and broad financial-sector applicability, while the MAS FAQ page was revised on 30 September 2026. Applicability and implementation choices should be checked against the current MAS materials and, where appropriate, qualified Singapore counsel or the institution's MAS supervisor.

Start with the regulator

The five MAS IAC outcomes are the requirements anchor.

Software selection should begin with what the institution must be able to operate and evidence. The system is supporting infrastructure for the governance model; it is not the governance model itself.

1. Identify accountable senior managers

Maintain an accurate record of the senior managers responsible for core functions. The record should reflect real oversight and decision authority, not only job titles or an organisation chart frozen at implementation.

2. Evidence fitness, propriety, and responsibility

Connect each accountable senior manager to role scope, responsibilities, approvals, relevant fit-and-proper evidence, and the issues or actions under that manager's purview.

3. Make governance and reporting relationships clear

Represent management structures, committees, reporting lines, delegations, shared responsibilities, temporary coverage, and changes over time so reviewers can see how the framework actually operates.

4. Govern material risk personnel

Identify material risk personnel and preserve evidence around role suitability, risk governance, conduct expectations, incentives, review, training, and oversight appropriate to the institution.

5. Sustain desired conduct across employees

Connect policy, training, issues, investigations, consequences, remediation, monitoring, and management information so conduct expectations are supported by observable operating evidence.

Proportionality still needs an evidence trail

MAS describes an outcomes-focused approach. A smaller or less complex institution may implement different measures from a large group, but the rationale for those choices should remain explicit and reviewable.

MAS IAC solution requirements

What MAS IAC software should actually do.

A credible product should reduce ambiguity and evidence friction. It should not replace legal interpretation, management judgment, fit-and-proper assessment, HR processes, or supervisory engagement.

Responsibility mapping

  • Named senior managers and core functions
  • Primary and shared accountability
  • Reporting lines and committees
  • Delegations and temporary coverage
  • Effective dates and version history

Role evidence

  • Role statements and approvals
  • Fit-and-proper evidence references
  • Attestations and review cycles
  • Training and competency records
  • Succession and handover evidence

Material risk personnel

  • Identification criteria
  • Role and risk linkage
  • Oversight and review
  • Conduct standards
  • Incentive and consequence evidence

Conduct workflow

  • Issues and case intake
  • Conflict and complaint linkage
  • Investigations and findings
  • Remediation owners and due dates
  • Escalation and closure approval

Governance evidence

  • Committee decisions
  • Policy and control linkage
  • Board or senior-management approvals
  • Exception rationale
  • Reviewable change history

Reporting and export

  • Responsibility maps
  • Open issues by accountable owner
  • Overdue reviews and attestations
  • Change and approval history
  • Portable evidence packages
Design for traceability

A useful IAC data model connects people, responsibilities, evidence, and time.

A flat spreadsheet can list names and titles, but it becomes fragile when responsibilities overlap, people change roles, entities share services, committees change, or a reviewer needs to reconstruct who owned a decision six months ago. The minimum useful model is relational: a person holds a role; a role owns or shares a responsibility; a responsibility belongs to a function and legal entity; each assignment has an effective period, approvals, evidence, and change history.

Core records

  • Legal entities, business units, and regulated activities
  • People, roles, senior-manager status, and material-risk-personnel status
  • Core functions, responsibilities, delegations, committees, and reporting relationships
  • Policies, controls, attestations, training, issues, investigations, and remediation actions
  • Evidence objects with source, owner, period, reviewer, retention, and access classification

Temporal controls

  • Effective-from and effective-to dates rather than overwriting history
  • Reason for change and approving authority
  • Previous and successor owner where responsibilities move
  • Open obligations carried into a handover
  • Point-in-time reporting so an auditor can reconstruct the framework as it existed on a past date
Operate, do not merely document

The workflow should keep the accountability map alive.

Change-driven review

Trigger review when a senior manager changes, a core function moves, a new product or entity is added, material outsourcing changes, reporting lines move, a significant incident occurs, or an issue exposes unclear ownership.

Periodic review

Run scheduled confirmations for responsibilities, material-risk-personnel populations, conduct controls, training, open issues, delegations, and evidence currency. Make overdue reviews visible to accountable owners and oversight functions.

Maker-checker approval

Separate proposal, review, and approval where independence matters. High-impact changes should preserve who requested the change, what changed, who approved it, when it became effective, and the supporting evidence.

Exception management

Do not hide gaps behind an overall green status. Record the requirement or outcome affected, rationale, risk owner, compensating measures, due date, approval, review cadence, and closure evidence.

MAS IAC software buyer checklist

Questions to ask a vendor before you buy.

  1. Can the system represent shared and delegated accountability without flattening everything into one owner?
  2. Can it produce a point-in-time responsibility map for a historical date?
  3. Can it distinguish senior managers, material risk personnel, and other employees with configurable criteria?
  4. Can role statements, attestations, training, issues, and remediation be linked to the same accountable person and function?
  5. Does every material change retain author, reviewer, approver, timestamp, previous value, and rationale?
  6. Can review and approval workflows vary by entity, function, or change type?
  1. Can dashboards surface overdue reviews, unresolved issues, role gaps, conflicting assignments, and orphaned responsibilities?
  2. Can the institution control access by role, entity, function, and sensitivity?
  3. Can evidence be exported in a portable, human-readable form without vendor assistance?
  4. How are retention, legal hold, deletion, and version history handled?
  5. Can the product integrate with HR, identity, GRC, case-management, learning, and document systems without making any one integration the system of truth?
  6. What evidence shows the product's own security, resilience, backup, incident-response, and change-management controls?

A product demonstration should use one realistic lifecycle: appoint a senior manager, assign a core responsibility, record approval and evidence, change the reporting structure, open a conduct issue, transfer responsibility, and then reproduce the before-and-after audit trail. That exposes far more than a dashboard tour.

Implementation sequence

Configure from the governance model outward.

1. Confirm applicability

Identify the regulated entities, current MAS source material, relevant core functions, senior-manager population, material-risk-personnel approach, and local interpretation before encoding requirements into software.

2. Clean the source data

Reconcile organisation charts, HR records, committee structures, job descriptions, delegated authorities, issue registers, and existing responsibility maps before migration. Do not automate contradictions.

3. Define the evidence model

Decide what proves each operating step, who owns it, who reviews it, how long it is retained, and what must be reproducible for audit or supervisory review.

4. Configure workflow and access

Implement maker-checker approvals, role-based access, entity scoping, reminders, escalation, exception handling, and change control around the actual operating model.

5. Test real scenarios

Walk through appointment, departure, interim coverage, reorganisation, material incident, outsourcing change, conduct investigation, and unresolved issue transfer. Verify the audit trail after each scenario.

6. Govern the system itself

Assign product ownership, change approval, access review, integration monitoring, backup, recovery, data quality, retention, and periodic control testing. IAC evidence is only useful if the supporting system is trustworthy.

Quick answers

MAS IAC software questions

What is MAS IAC?

MAS IAC refers to the Monetary Authority of Singapore Guidelines on Individual Accountability and Conduct. MAS describes five high-level outcomes covering senior-manager accountability, governance, material risk personnel, and employee conduct.

Does MAS mandate specific IAC software?

No specific product is prescribed on the MAS Guidelines page. The framework is outcomes-focused. The financial institution remains responsible for choosing and operating measures appropriate to its circumstances.

What is the most important software capability?

Traceability. The system should let a reviewer move from an outcome to the accountable person, role, responsibility, evidence, approvals, issues, changes, and historical state without reconstructing the story across disconnected spreadsheets.

Verify at the source

Primary MAS material

This guide is operational decision support, not legal advice. Use the current MAS material as the authority and confirm institution-specific interpretation where needed.

Continue learning

Related guides after MAS IAC Software & Implementation Guide

Follow the next implementation topic without returning to search.

Put this guide to work

Turn MAS IAC Software & Implementation Guide: 5 Outcomes and Requirements | Zeph Tech into a decision-ready next step.

Use the source-backed research to pressure-test assumptions, then build a reusable evaluation brief before you compare products, scope implementation, or request a fit review.