Skip to content

Evidence request lists

Singapore AI Governance Framework

Evidence request list. 21 controls, 21 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Determining the Level of Human Involvement in AI-Augmented Decision Making

AIGF-2.1
Human-in-the-Loop

AI provides recommendations while a human makes the final decision and is accountable

Artefacts an auditor will ask for
  • HITL procedure documentation
  • decision review records
  • training documentation
  • override logs
Where this commonly fails
  • no HITL procedure
  • weak training
  • missing override logs
AIGF-2.2
Human-on-the-Loop

AI makes decisions but a human can override or intervene when necessary

Artefacts an auditor will ask for
  • HOTL procedure documentation
  • monitoring records
  • intervention logs
  • training documentation
Where this commonly fails
  • no HOTL design
  • weak monitoring
  • missing intervention logs
AIGF-2.3
Human-out-of-the-Loop

AI makes decisions autonomously; appropriate only when probability and severity of harm are low

Artefacts an auditor will ask for
  • HOOTL risk assessments
  • guardrails documentation
  • monitoring procedures
  • kill switch records
Where this commonly fails
  • no HOOTL risk assessment
  • weak guardrails
  • missing kill switch
AIGF-2.4
Risk-Severity Assessment

Determine appropriate level of human involvement based on probability and severity of harm to individuals

Artefacts an auditor will ask for
  • risk-severity methodology
  • AI tier assignments
  • control mapping per tier
  • review records
Where this commonly fails
  • no methodology
  • weak tier assignments
  • missing review

GenAI

SGAIGOV-5
GenAI Safe Use, Provenance, Watermarking

Per MAF + GenAI Companion Paper: GenAI specifics. Requirements include (a) GenAI Output Verification and Safe Use + (b) Provenance and Watermarking of AI-Generated Content + (c) hallucination + misuse prevention + (d) maintain documentation.

Artefacts an auditor will ask for
  • SG AI Gov evidence for SGAIGOV-5
Where this commonly fails
  • AI ethics body + GenAI provenance partial

Governance

SGAIGOV-1
Internal Governance Structures and AI Ethics

Per Singapore Model AI Governance Framework (MAF) v2: governance. Requirements include (a) Internal Governance Structures and Measures + AI Ethics Governance Body + (b) Risk Management and Internal Controls + (c) Roles + Responsibilities + Accountability + (d) align with PDPC + IMDA guidance.

Artefacts an auditor will ask for
  • SG AI Gov evidence for SGAIGOV-1
Where this commonly fails
  • AI ethics body + GenAI provenance partial

Internal Governance Structures and Measures

AIGF-1.1
Risk Management and Internal Controls

Establish clear internal governance structures for AI deployment including risk management and internal controls

Artefacts an auditor will ask for
  • AI risk management procedures
  • internal control documentation
  • audit records
  • executive reports
Where this commonly fails
  • no AI-specific controls
  • weak audit
  • missing executive reports
AIGF-1.2
AI Ethics Governance Body

Set up an ethics review board or governance body for oversight of AI systems

Artefacts an auditor will ask for
  • AI ethics committee charter
  • membership records
  • meeting minutes
  • decision logs
Where this commonly fails
  • no ethics body
  • weak charter
  • missing minutes
AIGF-1.3
Data Management

Implement data accountability practices including data quality, lineage, and governance

Artefacts an auditor will ask for
  • data management framework
  • data quality records
  • lineage documentation
  • review cadence
Where this commonly fails
  • no data framework
  • weak quality controls
  • missing lineage
AIGF-1.4
Algorithm Design and Training

Ensure AI model design, selection, and training is governed by responsible practices

Artefacts an auditor will ask for
  • algorithm design documentation
  • training procedure records
  • model versioning
  • approval logs
Where this commonly fails
  • no design documentation
  • weak versioning
  • missing approvals

Operations

SGAIGOV-3
Operations Management - Data, Algorithms, Robustness

Per MAF: operations. Requirements include (a) Data Management + Data Quality and Provenance for Training + (b) Algorithm Design and Training + (c) safety + reliability + robustness + (d) Third-Party AI Component Due Diligence.

Artefacts an auditor will ask for
  • SG AI Gov evidence for SGAIGOV-3
Where this commonly fails
  • AI ethics body + GenAI provenance partial

Operations Management

AIGF-3.1
Minimising Bias in Data

Implement measures to minimise inherent biases in data collection and pre-processing

Artefacts an auditor will ask for
  • bias assessment reports
  • data sampling documentation
  • mitigation records
  • monitoring dashboards
Where this commonly fails
  • no bias assessment
  • weak mitigation
  • missing dashboards
AIGF-3.2
Explainability

Ensure AI decision-making processes can be explained in understandable terms relative to the risk level

Artefacts an auditor will ask for
  • explainability technique documentation
  • SHAP or LIME outputs
  • explanation interfaces
  • user testing records
Where this commonly fails
  • no explanation techniques
  • weak interfaces
  • no user testing
AIGF-3.3
Repeatability and Traceability

Ensure AI systems produce consistent and traceable outcomes for review and audit

Artefacts an auditor will ask for
  • reproducibility documentation
  • model versioning
  • training trace records
  • audit trail
Where this commonly fails
  • weak reproducibility
  • no versioning
  • missing trace
AIGF-3.4
Regular Tuning and Monitoring

Continuously monitor and tune AI models to detect and correct drift, bias, and performance degradation

Artefacts an auditor will ask for
  • monitoring dashboards
  • tuning records
  • drift detection alerts
  • retraining triggers
Where this commonly fails
  • no monitoring
  • weak tuning records
  • missing drift detection

Risk and Human Involvement

SGAIGOV-2
Risk Assessment and Determining Human Involvement

Per MAF: risk + human involvement. Requirements include (a) risk assessment for AI applications + (b) Human-in-the-Loop or Human-over-the-Loop as appropriate + (c) determine level of human involvement per risk + (d) safety + reliability + robustness.

Artefacts an auditor will ask for
  • SG AI Gov evidence for SGAIGOV-2
Where this commonly fails
  • AI ethics body + GenAI provenance partial

Stakeholder Interaction

SGAIGOV-4
Stakeholder Interaction, Communication, Transparency

Per MAF: stakeholder interaction. Requirements include (a) transparency to users + (b) explainability + (c) communication of AI use + (d) recourse mechanisms + (e) user awareness.

Artefacts an auditor will ask for
  • SG AI Gov evidence for SGAIGOV-4
Where this commonly fails
  • AI ethics body + GenAI provenance partial

Stakeholder Interaction and Communication

AIGF-4.1
General Transparency

Be transparent about the use of AI in products and services through disclosure to stakeholders

Artefacts an auditor will ask for
  • public transparency documents
  • AI use disclosures
  • stakeholder communications
  • policy documents
Where this commonly fails
  • no transparency documents
  • weak disclosures
  • missing communications
AIGF-4.2
Accessible Communication

Communicate AI-related policies in plain and accessible language to relevant stakeholders

Artefacts an auditor will ask for
  • plain-language communications
  • accessibility-compliant materials
  • multilingual records
  • user research
Where this commonly fails
  • jargon-heavy materials
  • no accessibility
  • missing multilingual
AIGF-4.3
Feedback Mechanisms

Provide accessible channels for individuals to raise concerns or provide feedback on AI-driven decisions

Artefacts an auditor will ask for
  • feedback channels documentation
  • complaint procedures
  • response records
  • improvement tracking
Where this commonly fails
  • no feedback channels
  • weak complaint procedures
  • missing improvement tracking
AIGF-4.4
Disclosure of AI Use

Proactively notify individuals when AI is used to make decisions that significantly affect them

Artefacts an auditor will ask for
  • AI use disclosure standards
  • user notification templates
  • consent records
  • compliance dashboards
Where this commonly fails
  • no AI disclosure
  • weak notification design
  • missing consent
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Singapore AI Governance Framework framework page.