Speed and quality only trade off when you govern every AI system as if it carried the same risk. Read the regulator carefully and the resolution is already there, sitting in a single clause most institutions skimmed past.
There is a kind of meeting I have learned to recognize by its silence. Someone presents a genuinely useful AI system, a document classifier or a claims-summarizer or a first-draft generator, and asks to ship it. Then the room splits. One half wants it live by Friday because the value is obvious. The other half wants six months of controls because the risk feels unbounded. Both halves are right, which is why the meeting ends where it began: a compromise slow enough to annoy the builders and loose enough to worry the risk officers. Everyone leaves faintly dissatisfied, having successfully defended a trade-off that did not need to exist.
On 13 November 2025, the Monetary Authority of Singapore issued its Consultation Paper on Guidelines on Artificial Intelligence Risk Management, designated P017-2025, and gave the industry until 31 January 2026 to respond. The commentary that followed did what commentary does. It counted up the new obligations and worried about the twelve-month transition clock. Most institutions read the paper as a list of things they would now have to do to every AI system they run.
That reading is what keeps the trade-off alive. And it is a misreading, of one sentence in particular.
The clause everyone quoted and nobody used
The consensus response to any new AI guideline is a defensive crouch: what controls do we add, and to what. The instinct is to take the longest, strictest reading of the requirement and apply it everywhere, because uniform is defensible and defensible is safe.
But the guidelines say something that uniform reading cannot accommodate. The expectations, the paper states, “may be applied in a proportionate manner, commensurate with the size and nature of FIs’ activities, use of AI, and their risk profiles.” That is not a footnote softening the rules. It is the regulator telling you to segment: to govern a marketing-copy generator and a reserving model as if they were different animals, because they are. The document everyone read as “more controls for everything” is, read literally, an instruction to stop treating your AI portfolio as one thing.
The thesis
Speed and quality are not opponents. They are two settings on a dial you have soldered into one position. Let the dial move by segment and the trade-off you have spent years managing turns into a routing problem you can actually solve.
A risk you never tiered is a risk you have already tiered as ordinary.
What’s inside
Why the speed-versus-quality fight is a symptom of an ungoverned portfolio, not a law of nature
The TRIZ principle that names the resolution, and why it sits first in the catalogue for a reason
A three-tier build: the boundary you draw on Day 1, the definitions you set in Week 1, the register you make auditable by Month 1
A diagnostic that reliably embarrasses the risk committee that runs it
Where this stops being a financial-services problem and becomes everyone’s
The principle hiding in plain sight
TRIZ, the theory of inventive problem-solving distilled from a few million patents, opens its catalogue of forty principles with the least glamorous one on the list. Principle #1: Segmentation. Divide the object into independent parts. Make it sectional. Increase the degree of its fragmentation.
It is first for a reason. A startling share of “hard” contradictions are not really contradictions. They come from insisting that one object hold two incompatible properties at once. A shipping container has to be strong enough to survive transit and weak enough to open easily. Segmentation resolves it: a strong body, a weak seam. The property you wanted everywhere, you now supply only where it earns its place.
The speed-versus-quality contradiction in AI delivery has exactly this shape. You want speed, because the copy generator should ship this week. You want quality, because the underwriting agent must not ship until it is provably safe. Hold both against a single, undifferentiated “AI governance process” and they are irreconcilable, and you will spend your career splitting the difference. Segment the portfolio by risk class and each property goes where it belongs. The generator moves at the speed of its consequences. The underwriting agent moves at the speed of its scrutiny. Nothing is compromised, because nothing is shared.
In that one proportionality clause, the regulator is not granting you a concession. It is describing the segmentation and daring you to implement it.
Day 1: Draw the boundary before you draw the governance
Item 1: Classify by consequence, not by technology.
The universal pattern. Before you can apply a property selectively, you have to cut the object into parts that can hold different properties. In any AI program, the meaningful cut is not model versus rules, or generative versus predictive. It is the blast radius of a wrong output: who gets harmed, how reversibly, and whether a human sees it before it acts.
The regulated-industries manifestation. MAS frames its expectations around “risk profiles” precisely because a hallucinated meeting summary and a biased credit decision are not the same event in different clothes. In financial services the consequence axis is unusually legible. Customer harm, prudential exposure, conduct breach, regulatory reportability: the tiers almost draw themselves once you agree to draw them. Firms that skip this step apply model-validation rigor to a chatbot that answers “what are your opening hours,” and chatbot-grade oversight to an agent that moves money.
Your translation. Three tiers is usually enough. Tier 1 is outputs that reach a customer or a regulated decision with no human in the loop. Tier 2 is outputs a human reviews before they act. Tier 3 is internal-only outputs with no external consequence. Every system in production gets exactly one tier. The AI risk committee owns the boundary; the builders own placement within it.
What to build by Friday. A one-page classification rubric: three tiers, three or four consequence questions, a decision rule that maps answers to a tier. Not a policy. Something a project lead can apply in ten minutes without calling legal.
Item 2: Separate the reversible decision from the irreversible one.
The universal pattern. Speed is cheap where mistakes are cheap to undo. The single most useful cut inside any tier is reversibility, because it tells you how much pre-deployment certainty you actually need, and how much you can buy back later with monitoring and a rollback.
The regulated-industries manifestation. Regulated firms systematically over-invest in front-loaded assurance and under-invest in the ability to reverse. A model whose decisions can be re-run and remediated within a day carries a very different risk from one whose outputs are posted to customers or booked to a ledger the moment they are produced. MAS puts weight on lifecycle controls, not just pre-deployment gates, and that is the reason why. Sometimes the control that matters is the undo button rather than the sign-off.
Your translation. For each Tier 1 and Tier 2 system, ask one question. If this is wrong tomorrow, how fast and how completely can we reverse it? Systems that reverse fast can move at Tier 3 speed with Tier 1 monitoring. Systems that cannot earn their slowness honestly.
What to build by Friday. A reversibility column in your AI inventory. Two values to start, recoverable or not, with the rollback path named for anything marked “not.”
Week 1: Give each segment its own definition of done
Item 3: Write a per-tier “definition of done,” and let it differ.
The universal pattern. Segmentation only works if the segments are genuinely allowed to behave differently. A cut you refuse to act on is decoration. Each part has to carry its own standard, or you have just drawn lines on something you still govern as one.
The regulated-industries manifestation. This is where most governance frameworks quietly collapse back into uniformity. A firm draws three tiers, then writes one control checklist and applies it to all three “for consistency.” Consistency of process is the enemy here. What you want is consistency of proportionality. When MAS says expectations apply “commensurate with” activity and risk, that is an explicit license for Tier 3 to reach production by a shorter path than Tier 1, and an implicit warning that a firm applying identical rigor everywhere has missed the instruction.
Your translation. Three definitions of done, one per tier, each naming what must be true before deployment. Tier 3 might need a data-handling check and a named owner. Tier 1 needs full validation, bias testing, human-oversight design, and a monitoring plan. The heads of each delivery team own their tier’s definition. The risk function owns the fact that they differ.
What to build by Friday. A single page: three columns, the deployment gates for each tier listed beneath. If Tier 1 and Tier 3 have the same gates, you are not done. You have a uniform process wearing a segmentation costume.
Item 4: Route the control weight to the tier, not the tool.
The universal pattern. The resource you are actually rationing is senior human attention. Segmentation is, in the end, a way to spend scarce attention where consequence concentrates, instead of spreading it thin across everything that happens to contain a model.
The regulated-industries manifestation. AI risk committees are a bottleneck by design. An ungoverned portfolio floods that bottleneck with low-consequence items, the fourth internal summarizer this quarter, while a genuinely consequential agent waits in the same queue. The proportionality clause exists so the committee’s time tracks risk. A firm that reviews all AI at the same depth is not being careful. It is being undifferentiated, which only feels like care.
Your translation. Tier 1 goes to the committee. Tier 2 goes to a delegated reviewer with an escalation trigger. Tier 3 self-certifies against its checklist and gets audited by sample. The committee’s calendar should visibly shift toward the systems that can actually hurt someone.
What to build by Friday. A routing table: tier in the left column, approval authority and review depth in the right. Circulate it to everyone who currently waits in the single queue.
Month 1: Make the segmentation something an examiner can read
Item 5: Turn the boundary into an auditable register.
The universal pattern. A segmentation that lives in someone’s head is a preference. A segmentation written down, with each item’s tier and the reason for it, is a control. The difference is whether a stranger can reconstruct your judgement without you in the room.
The regulated-industries manifestation. Supervisors do not mainly test whether your AI is safe. They test whether you can show that you knew which of your AI needed to be. MAS’s expectations around oversight and lifecycle documentation are, in practice, a demand for exactly this register: a record showing that the firm classified its portfolio, applied proportionate controls, and can explain any given placement. A firm that segmented well but wrote nothing down will fail an examination it should have passed.
Your translation. One register: every AI system in production, its tier, its reversibility, its definition-of-done status, and one line of rationale for the tier. It is owned by the AI risk function and refreshed on a fixed cadence, not when someone remembers.
What to build by Month 1. The register itself, populated for everything currently live, even if the first pass is rough. A rough complete register beats an elegant empty template every time an examiner walks in.
A note on confidence
Let me grade my own claims, because a senior reader deserves to know which parts to lean on. The dates and the text are fact: MAS issued P017-2025 on 13 November 2025, closed consultation on 31 January 2026, proposed a twelve-month transition, and wrote the proportionality language quoted above, all confirmed from the published consultation paper. Reading that clause as a mandate for risk-tiered segmentation is my inference. It is a strong one, consistent with how supervisors have historically read “commensurate with risk,” but the guidelines do not prescribe a tiering scheme, and you should not tell your board that they do. And the specific shape I am proposing, three tiers with a reversibility cut, is a design hypothesis. It has held up across the portfolios I have seen, but it is not law. Lean on the first as fact, take the second as a well-supported reading, and treat the third as a starting point to argue with.
The diagnostic that embarrasses the committee
Here is a test worth running before your next AI risk meeting. Ask for the list of every AI use case in production. Then ask the committee to assign each one a tier using nothing but the consequence questions above. Two things reliably happen. Somewhere between thirty and fifty per cent of the “AI” turns out to be deterministic rule-based automation that got relabelled as AI for budget or board-narrative reasons, and it has been eating model-grade governance it never needed. And one or two systems everyone treated as routine land, under honest classification, in Tier 1, reaching a customer or a booked decision with no human in the loop, and nobody had noticed. The list you thought was uniform never was. It was a segmentation you were already living inside, unwritten and so ungoverned.
This is not a financial-services peculiarity. A hospital running diagnostic support next to appointment-reminder bots, a pharmaceutical firm doing both adverse-event triage and internal literature search, a grid operator with load forecasting alongside a customer chatbot: each makes the same error, governing a portfolio of wildly different consequences as if it carried one risk profile. The pattern holds everywhere. The trade-off is manufactured by the refusal to segment.
What the Prompt Kit does
Knowing that segmentation resolves the contradiction is the easy part. Doing it to a live portfolio is the work: drawing defensible tiers, catching the relabelled automation, writing definitions of done that genuinely differ, and producing a register an examiner would accept. Prompt Kit 10 runs that sequence. Four prompts take you from an unsorted inventory to a tiered, reversibility-annotated, examiner-ready register, generating the classification rubric and the routing table along the way. It is built to run on your actual list, by a technical or non-technical owner, in an afternoon rather than a quarter.
Run this before Friday
Take your AI inventory, the real one and not the board slide, and do two things. Sort every item into Tier 1, 2, or 3 using only the consequence questions. Then, for each, write the one-sentence reason. When you are done, look for the rows where the tier and the current level of governance disagree: Tier 1 systems moving at Tier 3 speed, and Tier 3 systems drowning in Tier 1 process. Those disagreements are exactly where your speed-versus-quality trade-off has been hiding. You will not have added a single control. You will have found that you were applying the ones you already have to the wrong things, which is the more uncomfortable finding, and the more useful one.
If you are working through how to tier a live AI portfolio under MAS AIRG or an equivalent regime, and you want a structured outside read on where your governance weight is misrouted and what an examiner-ready register actually requires, mention it in your reply. I take one such conversation a month.
Replies to this post reach me directly. I read all of them.
Regulated Intelligence | TRIZ × AI | Regulated Markets. Written by JL CREPPY.


