SAFR A Runtime Governance for Agentic AI

SAFR - A Runtime Governance for Agentic AI

9/15/2026
SAFR A Runtime Governance for Agentic AI

Read time: 5 minutes

 

AI agents can now initiate payments, submit trading orders, approve loan applications, file regulatory reports, and settle claims, in some cases without human review of each action. Safeguards for Agentic Finance at Runtime (SAFR) is an industry framework, published by the Monetary Authority of Singapore, that introduces AI governance checkpoint addressing the risk of AI agents.

 

Why SAFR Important

The SAFR framework addresses three specific risks

  • Model risk frameworks assess systems before deployment. Audit processes remain retrospective, reviewing actions only after executions.
  • No consistent standard for when a human should review an agent's action. Escalation is typically ad hoc, with no defined response deadline and no audit record of the decision.
  • Agentic guardrails, where they exist, are usually built independently, producing controls that are not interoperable and not consistently auditable.

 

How the SAFR Works

SAFR is designed to sit between an AI agent and the systems it acts on. Evaluating each proposed action against institutional controls before deciding whether the action can proceed, must be escalated for human review, or must be rejected.

 

SAFR within the financial technology stack

Figure 1. SAFR within the financial technology stack

 

 

Key Components of SAFR

The framework has four main components:

  • Agent Identity: binds each proposed action to a recognised, registered agent, verified before any other evaluation proceeds
  • Controls Repository: the institution's configurable rulebook, drawn from organisational policies, regulatory requirements, product rules, and user-provided mandates
  • Disposition Engine evaluates each proposed action against the Controls Repository and returns one of four outcomes: Deny, Escalate, Auto-Execute, or Observe
  • Audit Log: a tamper-evident, append-only log capturing every governance decision

 

Together, the four components mean no agentic action can reach execution until it has been declared, authorised, and assessed.

 

Assurance in the Rise of Agentic AI

Crowe believes in responsibly AI practices and the deployment of Agentic AI in Financial Systems requires tighter assurance via control, traceability and accountability that frameworks like SAFR are designed to enforce.

Speak to our expert.
Crowe can provide specialized industry consulting services to help tackle the specific challenges you face.