AI Governance in APAC
By Alex Raso, Principal Cybersecurity Expert APAC, H&F Advisers AI Governance & Cybersecurity Expert
AI Governance in APAC, from Board policy to daily practice, just imagine your finance team wants an AI assistant to read invoices and prepare payments. The demo looks good. The time savings look better. Your company already has an AI policy, so everyone assumes the governance part is covered.
Then somebody asks whether the assistant can change a supplier's bank details. Who approves that? What checks happen before the change reaches the accounting system? Who can stop it if something goes wrong?
If those answers are still being worked out, the policy has some work left to do.
Useful AI governance gives people clear decisions, defined responsibilities and a workable route to deployment. It should help a team understand what it can build, what needs approval and what must be tested before customers or company money are involved.
Singapore's updated Model AI Governance Framework for Agentic AI is a useful reference. Version 1.5 was published on 20 May 2026 and updated on 5 June. Its focus is agents, systems that can plan and take actions through connected tools. It organises guidance around setting boundaries, human accountability, technical controls and responsible use. IMDA framework.
The wider governance gap is already visible. In April, Australia's APRA reported that oversight and assurance were struggling to keep pace with AI adoption among the financial institutions it reviewed. It also identified excessive reliance on vendor presentations. That is a fairly clear signal to look beyond the sales demo. APRA's April 2026 findings. Here is how I would translate the guidance into daily practice.
Put a name against each decision
Start with a business owner for every AI use case. For the invoice assistant, I would make the finance leader accountable for its business purpose, acceptable outcomes and use within the payment process.
The board sets the organisation's appetite for AI use and expects evidence that management is staying within it. IT owns the integration and operation. Cybersecurity checks access, testing and monitoring. Privacy, legal and procurement staff handle the relevant data and supplier requirements. The business owner brings those decisions together before requesting approval to launch.
Document who can authorise deployment, who accepts unresolved issues and who has authority to suspend the service. In a smaller business, one person might cover several functions. The responsibilities still need to be explicit. This approach is consistent with NIST's emphasis on documented roles, communication and executive accountability. NIST AI Risk Management Framework.
An AI committee can resolve difficult decisions. Someone still needs to own Tuesday morning's problem.Approve the job the AI will do
Make approval specific enough that another person could understand its limits. Record the task, users, data sources, connected systems, permitted actions and required checks. Include the evidence needed to move from a trial into live operation.
For our invoice example, my recommendation is to start with permission to extract invoice details and propose an accounting entry. Supplier bank-detail changes and payment release would remain with the existing verification and approval process. Giving the assistant authority to perform either action would require a separate decision and additional testing.
That is a concrete approval a team can build against.
Offer a faster approval route for clearly bounded work, such as drafting internal text from approved, non-sensitive material. A workflow influencing recruitment or credit decisions deserves deeper scrutiny of accuracy, fairness and consequences for the people affected. A short intake form should help reviewers make that distinction without sending every request through the same meeting.
Ask suppliers to show their working
Your supplier assessment needs to cover the actual product configuration and the organisations behind it. NIST's generative AI guidance recommends use-case-based supplier assessment, visibility of third parties and contracts covering security, service quality and incident responsibilities. NIST Generative AI Profile.
For a connected enterprise application, my suggestions would beQuestions | Jobs-to-be-done |
Where does our data go? | Identify storage and processing locations, retention, model-training use and other providers receiving it. |
What can the application access and change? | Demonstrate permissions, tenant separation, approval controls and activity logs. |
What happens when the product changes? | Explain notification arrangements for model, connector and data-handling changes, and opportunities to test them. |
What happens during an incident or outage? | Establish support response times, evidence access, notification responsibilities and a workable fallback. |
Record the answers and supporting evidence against your intended use. If the supplier cannot support a required control, that gap needs an explicit decision before deployment. A narrower initial scope may make the project workable while the gap is addressed.
Build the rules into the system
Take the invoice assistant again. An instruction telling it never to change bank details should be backed by application permissions that prevent it from making that change. Payment limits and approval requirements should be enforced by the systems executing the transaction.
This matters because an agent may encounter instructions planted in an invoice, email or webpage that attempt to redirect its behaviour. OpenAI's prompt-injection research recommends designing systems to constrain the consequences of manipulation, including when an attack succeeds. OpenAI's prompt-injection research.
For this workflow, test a deliberately misleading invoice, an unexpected recipient and an attempted bank-detail change before launch. The acceptance test is whether the system blocks or escalates the action as designed. A well-written response from the assistant is only part of the evidence.
Give monitoring an owner and a response
Monitoring needs to show what the agent actually did: which records it accessed, which tools it used, which actions it attempted and which approvals it received. Singapore's Cyber Security Agency provides practical guidance on logging, monitoring, alerts and stopping abnormal activity in its June 2026 agentic AI addendum. CSA's agentic AI security guidance.
For the invoice assistant, flag attempted changes outside its authority, unexplained increases in transaction volume and repeated processing failures. Agree who receives each alert, how quickly they must respond and what conditions automatically pause processing. Protect the logs themselves and set an appropriate retention period.
Check the human controls too. IMDA recommends examining override rates and review times for signs of ineffective oversight. A person clicking "approve" in two seconds on every request deserves a closer look at how that review is working. IMDA framework, human oversight guidance.
Retest when the model, instructions, data sources, connectors or permissions materially change. Agree the triggers in advance, and rehearse how to suspend the service and continue the work manually. APRA's review specifically identified weaknesses in monitoring after deployment, change management and contingency arrangements. APRA's findings.
Make the regional standard usable locally
For a business operating across Thailand, Singapore and Australia, I would build a common operating standard, then document the additions needed for each market and sector. That means checking applicable requirements for data handling, transfers, customer decisions and outsourcing against the actual workflow.
There are useful local references. Thailand's ETDA has published organisational guidance for governing generative AI. ASEAN's expanded guide also provides regional recommendations, while explicitly preserving obligations under member states' laws. ETDA's organisational guidance announcement, Expanded ASEAN Guide.
My practical recommendation is to test with the documents, languages and working habits the deployment will actually encounter. For our example, that includes Thai and English invoices, inconsistent formats and staff who need to understand why something was escalated. Build training around those situations, including how to challenge an output and report a problem.
You can start this month with one useful workflow. Name its owner, define its limits, gather supplier evidence and agree the tests and operating procedures. Measure the time saved alongside corrections, exceptions and review effort. Use what you learn to make the next approval easier.
A team should leave the governance process knowing exactly what it can deliver and who will keep it working. That is a standard worth holding your AI programme to.
About the Author Alex Raso is a cybersecurity strategist and founder of RASO Cyber, advising governments, financial institutions, and critical infrastructure operators across Asia-Pacific. With over two decades of experience spanning cyber resilience, regulatory compliance, threat intelligence, and enterprise risk, he helps organisations build secure, trusted foundations for digital and AI-driven transformation.




