Insight · AI Governance
Your people are using AI on client work. Has anyone written down how?
Fee earners draft with it. Business development pitches with it. Nobody has said which tools, what data, or who checks the output before it reaches a client. IMDA, PDPC and ASAS in plain English, the eight ways it goes wrong, and a one-page policy the management committee can adopt this month.

By Gary McRae
Management consultant · Singapore · PMC accredited · CAIG certified
Last reviewed 11 September 2026 · 10 min read
Somebody in your firm is drafting a pitch in ChatGPT. Somebody has pasted a client’s email thread into it for context. The coordinator generates images for the newsletter. A partner used it to summarise a prospect’s annual report on the way to the meeting. None of this is wrong. None of it is written down, and a client’s general counsel has started to ask.
Singapore’s rules sit with three bodies: IMDA, the PDPC and ASAS. The guidance is recent, scattered, and written for technology companies rather than firms. This is the map, the eight concrete risks, and a six-part policy that fits on one page.
The Singapore rules, in plain English
Five frameworks touch a firm’s use of AI today. Two are voluntary. Three carry teeth.
IMDA Model AI Governance Framework (Generative AI, May 2024)
Nine dimensions, including accountability, data, trusted development, security, content provenance, safety and alignment. Voluntary. If the firm uses AI at any scale, this is the standard it will be measured against in any future enforcement conversation. Extended in January 2026 with a framework for agentic AI: systems that act, rather than answer.
PDPC Advisory Guidelines on Personal Data in AI (March 2024)
Non-binding, treated as the enforcement standard. Covers recommendation and decision systems: lookalike audiences, churn prediction, automated segmentation. Requires explicit consent before personal data is used to train a model. The gap: the guidelines do not yet specifically cover generative AI. Putting a client’s data into ChatGPT sits in a grey zone, and the firm with no written policy has the weaker position in it.
ASAS Code of Advertising Practice
Pre-dates AI and applies. Misleading or unsubstantiated claims are prohibited, including AI-generated copy that invents a capability, an outcome or a client. The US Federal Trade Commission’s Operation AI Comply (September 2024) caught Rytr, Workado and Evolv on the same principle.
Elections (Integrity of Online Advertising) Act (January 2025)
The first Singapore statute to name AI. Bans digitally generated or manipulated election advertising. Relevant if the firm advises political clients; tangential otherwise. Penalties up to SGD 1 million.
AI Verify (voluntary)
An open-source testing toolkit against eleven governance principles. Used by organisations that need to show governance maturity to a regulator or a large client. Not mandated. A credibility tool, not a compliance requirement.
Eight ways it goes wrong in a firm
Ordered by how often they happen, not by how bad they are.
- Client data in free ChatGPT. An associate pastes a prospect’s confidential brief and the last twenty emails into free-tier ChatGPT to draft the pitch. OpenAI processes it outside Singapore and may train on it.
Why it matters: a direct PDPA breach, and very possibly a breach of the engagement letter. Penalties up to the higher of SGD 1 million or 10 percent of annual Singapore turnover. The single most frequent risk. The full obligation set is in the PDPA essay. - Invented claims. The newsletter says the firm has advised on “over 200 cross-border transactions.” Nobody checked. The number came from the model.
Why it matters: an ASAS complaint carries a 14-day window to correct, and the reputational cost lands first. For a law practice the Publicity Rules add a second problem: an unverifiable claim. - A realistic face that belongs to someone. An image tool produces a “client” for a testimonial graphic. The face is close enough to a real person.
Why it matters: Singapore defamation law applies to AI-generated content: injunction, damages, forced removal. GovTech reports 56 percent of businesses have experienced an audio deepfake fraud incident. - A prospect list that discriminates. An AI-scored invitation list built from the firm’s best clients (70 percent male, 25 to 45) quietly drops women and older decision-makers from the seminar, with no demographic targeting switched on.
Why it matters: no explicit anti-discrimination clause in Singapore privacy law, but the ASAS fairness principle and the reputational exposure are real, and rising. - A model trained without consent. A client attrition model trained on billing and contact behaviour. The privacy notice said “analytics.” It did not say “AI personalisation.”
Why it matters: a direct PDPA breach. The remedy is retroactive consent, or deleting the data and retraining the model. - A partner’s voice, cloned. A partner’s voice is used to train the client-service assistant. The partner did not consent to commercial use.
Why it matters: the PDPA treats voice as biometric personal data. Use without consent is a breach. Guidance is sparse, so this is a high-uncertainty zone. - The vendor processes data outside Singapore. The firm assumes the data stays here. Default routing sends it to the US. No DPA in place.
Why it matters: the PDPA permits export only with explicit consent or an approved data protection agreement. OpenAI announced Asia data residency in April 2024; Anthropic opened a Singapore office in 2026. Neither defaults to Singapore processing without configuration. - No record. A piece of marketing is challenged. Nobody can say which model produced it, from what prompt, with what data, or who approved it.
Why it matters: PDPC guidance recommends written policies and documentation. Their absence reads as negligence.
Seven of the eight are about process, not about the AI. That is the good news. A process can be written down.
The six-part policy
Six parts. One page. Take it to the management committee as the draft.
01
Approved tools
List what is approved: ChatGPT Enterprise (with a DPA and Singapore data residency), Claude (Anthropic, Singapore residency), an image tool for non-realistic imagery, the firm's own sandbox. List what is banned: any free tier, personal accounts, any tool without an enterprise DPA. For a new tool, three questions. Is there a DPA? Is Singapore data residency available? Does the contract prohibit training on the firm's data?
02
What never enters a prompt
Red, never: client names attached to matter details, anything covered by an engagement letter's confidentiality terms, personal data of client contacts, NRIC numbers, financial and health information, unannounced deal information. Amber, with approval and only in approved tools: de-identified engagement data, aggregate billing. Green: published articles, public filings, the firm's own marketing copy. De-identified does not mean safe in a free tier.
03
Review before it leaves the firm
Copy that makes a claim about the firm or a practice: a partner and marketing, two approvers. Realistic images of people: a second partner. AI-scored lists: someone checks who was left out. The standard is simple. Nothing AI-generated reaches a client or the public without one human approval.
04
Labelling
No Singapore legal requirement to label AI content yet, unlike the EU. ASAS principles point to disclosure where audience expectations matter. Document AI use internally; disclose visibly when realistic imagery could mislead; do not label routine AI-assisted edits. Revisit annually.
05
Consent
The privacy notice lists 'AI-based personalisation', 'predictive model training' and 'lookalike audience generation' as uses. Explicit consent before any model trained on client data goes live. Audit what the firm already holds: where consent is missing, obtain it or exclude the data. Fix the consent flow before the model, not after.
06
The record
Every AI-generated asset gets a line: date, model and version, a summary of the prompt, who reviewed it, the approval date, where it went. Keep it for two years, in line with PDPA expectations. It answers the regulator, trains the next coordinator, and answers a client questionnaire in an afternoon.
Write it, or buy it
Firms of 6 to 20 fee earners with simple use
Write your own. Use the six parts above as the template and adapt the data section to your practice. Cost: four to eight hours of a partner’s time, or roughly SGD 2,000 to 4,000 in external advisory. Governance at this size is documenting what the firm already does, not buying surveillance software.
Firms whose clients are regulated
If your clients sit under MAS or MOH, expect the questionnaire. Their regulators expect IMDA-aligned governance, and the question travels down to the firms they engage. Use the IMDA framework as the baseline. Consider OneTrust or IAPP-aligned tooling only if a client demands audit-grade documentation.
Firms above 60 fee earners, or running models in production
Buy the tooling or hire advisory. Governance software (OneTrust, Microsoft Purview and comparable) gives inventory, monitoring and continuous compliance. Cost: SGD 50,000 to 200,000 a year plus implementation. A one-off policy does not scale across dozens of models.
Most firms of this size need the policy, not the software. Governance is process and documentation. The software is for organisations running dozens of models in production.
Frequently asked questions
Can I put client emails in ChatGPT?
It depends on the tier. Free ChatGPT (a personal account): no. That is a PDPA breach; the data leaves Singapore without consent or a Data Processing Addendum. ChatGPT Enterprise with Singapore data residency and a signed DPA: yes, with explicit consent for any AI-based personalisation. The issue is the account tier and its configuration, not the tool. Most firms skip the distinction and end up in breach.
Does the firm need to label AI-generated copy?
There is no legal requirement in Singapore yet, unlike the EU. ASAS principles point to transparency where audience expectations matter. Best practice: document internally that copy was AI-generated; disclose visibly when realistic AI imagery could mislead; do not label routine AI-assisted edits. Revisit annually as guidance evolves.
Is lookalike audience targeting legal in Singapore?
Technically yes, but risky. Singapore privacy law has no explicit anti-discrimination clause for automated decisions. The ASAS fairness principle and the reputational exposure are real, however. Best practice: audit any lookalike audience for demographic gaps before a campaign of any size; document the audit; review the policy quarterly.
What happens if there is no explicit consent for AI model training?
The PDPC can require the firm to obtain consent retroactively or delete the data from the model. If consent cannot be obtained, deletion is the only path, which means retraining on a smaller dataset. The operational cost is significant; prevention is cheaper. Update the privacy notice and the consent flow before any model touches client data.
What if the AI generates a deepfake of a real person?
Singapore defamation law applies. The person can sue for damages and demand removal. In a political context POFMA applies, with fines up to SGD 1 million. The reputational damage is immediate. Prevention: never generate realistic AI imagery of a real person without explicit written consent; use clearly stylised or synthetic figures instead; check what your image tools do by default.
Does the firm need an external AI governance consultant?
Not necessarily. A firm of 6 to 20 fee earners with simple use (ChatGPT for drafts, an image tool for stylised assets) can implement the six-part policy internally in four to six weeks. A firm in regulated client work, or one running models in production (lookalike audiences at scale, attrition models), justifies external advisory or governance software.
Sources
- IMDA, Model AI Governance Framework for Generative AI (May 2024)
- IMDA, Model AI Governance Framework for Agentic AI (Jan 2026)
- PDPC, Advisory Guidelines on Personal Data in AI Recommendation/Decision Systems
- AI Verify Foundation
- ASAS Singapore, Code of Advertising Practice
- FTC, Operation AI Comply (September 2024)
- OpenAI, Introducing Data Residency in Asia (April 2024)
About the author
Gary McRae is a management consultant in Singapore. MCR.AE is management consultancy for how a professional services partnership wins work: business development, marketing, and who runs both, for firms of 6 to 60 fee earners. He ran digital and marketing technology inside a global law firm, as Associate Director of Marketing: the website, the CRM, the systems the firm paid for, under partner governance, with fee earners as internal clients. 12+ years in Singapore. PMC accredited (SBACC), CAIG certified (NTU). His own practice runs on AI, under the rules above.
Find him on LinkedIn.
This is where the Review starts.
The Review opens with what your people are already doing with AI on client work and in business development, and what it exposes the firm to. Four weeks. Written, evidenced, ends in a recommendation.
Related reading
- Marketing a Professional Services Firm. Partner, manager, director or consultant. The Singapore cost of each, and the four signals that say the firm needs senior ownership now.
- Law Firm Business Development. Who actually buys, three channels and no more, PDPA-clean outbound or none, credibility before volume. Five stages in order.
- MarTech Audit Framework. Half of what the firm pays for marketing software goes to tools nobody uses. A five-step audit one person runs in a week.
- PDPA Compliance for Firms. Your client list is personal data. Nine obligations, an eight-step checklist, and the business contact exemption most firms misread.
- The Enterprise Development Grant. EDG closes 29 September 2026. What it funds until then, the seven-step application, and what is published about EDGE.
Work with this thinking
- Review. The engagement shape this essay sits inside.
- Quarterly. The adjacent shape, depending on where you are.
- The Practice Growth Sequence. The methodology every engagement runs on.