IMDA released MGF v1.5 at ATxSummit 2026. One case study shows what enforcement-layer governance actually requires. Read the analysis →
agentic AIAI governanceruntime controlsfinancial servicesSingaporeassurance

Who Checks the Harness?

Arjen Hendrikse · · 6 min read

Three BCG articles published in September 2026 set out how enterprises should move on agentic AI. Read together, they leave one question open for Asia-Pacific financial institutions.


In the space of about a week in September 2026, Boston Consulting Group published three pieces on AI agents.

The first, from its Singapore office, tells CEOs to stop waiting and commit to one or two large AI bets in the functions that drive market share or cost. The second, also from Singapore, describes the “harness” BCG builds around agents, drawing on a fully agentic advisory platform delivered for a large Southeast Asian bank. The third, from BCG’s cyber and risk practitioners, opens with an uncomfortable observation: most organisations cannot say which agents they run, who authorised them, or what stops an agent that pursues its goal the wrong way.

Each piece is sensible on its own terms. Read side by side, they describe an accelerator, an engine and a warning light. What none of them assigns is the job of checking that the brakes work.

Where the three pieces agree

The strategy piece is about speed. Asia-Pacific CEOs are leading AI from the front, setting targets above 50% improvement in core functions, and refusing to wait for clean data or the next model release.

The harness and authorization pieces are about control, and they arrive at the same model from different directions. The harness article breaks the operating layer around agents into specifications that define purpose and boundaries, a “constitution” of deterministic rules, a control panel that records what agents did, a context hub, and a set of quality gates. The authorization article argues for tying an agent’s authority to what it may achieve and how it may pursue that goal, with fixed rules rather than AI judgement wherever the cost of error is high, and an audit trail that can explain intent after the fact.

Two separate BCG practices have converged on the same position: define what the agent is for, define how it may get there, enforce the hard limits in the execution path, and keep a record that explains each decision. Written policy does none of that by itself. That is the position Aivance holds: policy is not a control.

Where they pull against each other

The tension shows up in four places.

Who grades the grader. The harness model relies on critic agents evaluating worker agents, and on a compliance agent checking outputs against regulatory standards. The authorization article warns against letting one probabilistic system police another in high-stakes work, and says a second agent can act as a checker only if its independence is deliberately engineered. Both positions can hold at once, but only if someone decides which gates must be deterministic and then tests that they behave that way.

Build, don’t buy. The harness article recommends a bespoke harness because it encodes a firm’s own processes, context and institutional knowledge. The competitive logic is sound. The consequence is that every institution ends up with controls that are unique to it and best understood by the team that built them. When a supervisor, internal audit or the board asks whether the harness works, the builder is the least independent party available to answer.

The maturity ladder needs evidence. The harness article describes moving a workflow from “check everything” to occasional spot checks as trust in its output grows. That move is a risk decision. The authorization article says an agent’s purpose and limits should be reconfirmed on a schedule, possibly after every model update. Neither piece says what evidence justifies a downgrade or what forces a workflow back up the ladder. The strategy piece’s advice to run several models side by side multiplies the number of update cycles that could trigger one.

Speed concentrates exposure. Placing one or two large bets in core functions means the first agents at scale will sit in the highest-stakes workflows: advice, payments, customer communication, production systems. The authorization article names exactly these as the places that need hard limits and human reviewers with the authority and time to say no.

The Singapore gap

The authorization article anchors its regulatory argument in the EU’s Digital Operational Resilience Act and a NIST concept paper on agent identity, with a brief nod to other jurisdictions. For an institution in Singapore, the relevant reference points sit closer to home. MAS’s Technology Risk Management Guidelines set expectations on access control, privileged access and segregation of duties that agents now strain. MAS’s Safeguards for Agentic Finance at Runtime (SAFR) paper addresses runtime safeguards for agentic systems in financial services directly. IMDA’s Model AI Governance Framework for Agentic AI adds cross-sector guidance on managing agent autonomy and accountability. None of these is written as a harness specification, and SAFR and the IMDA framework are guidance rather than binding requirements, but together they provide a practical Singapore reference set for well-governed agent deployments.

BCG argues that regulators are moving from principle-based guidance on agents toward requirements about architecture. If that shift continues, a policy document describing the harness will carry less weight than evidence of how it behaves. Institutions will want to show that each control fires, that each checker is independent of what it checks, and that each decision can be traced back to the authority that permitted it.

Five questions to ask of any harness

Whoever built it, an agent harness in a regulated institution should be able to answer these.

  1. Which rules are deterministic, and have they been tested to fire? Pick the hard limits, such as payment ceilings, external communications and changes to customer entitlements, and try to push an agent past them under controlled conditions.
  2. Is each checker independent of what it checks? If the critic agent shares a model, a prompt lineage or an owner with the worker agent, treat that gate as advisory and do not count it toward segregation of duties.
  3. Can the named human actually refuse? Look at whether reviewers receive enough context, time and authority to reject an action, and whether refusals are recorded. A reviewer who has never refused anything is a signal worth investigating.
  4. What evidence moved this workflow down the maturity ladder, and what moves it back up? Model updates, scope changes and incidents should each have a defined effect on the level of oversight.
  5. Can you reconstruct one decision end to end? Take a completed agent action and trace who delegated the authority, which purpose it served, which rules evaluated it, what data and tools it touched, and who could have stopped it. If that takes days of work across separate system logs, the harness does not yet produce the record an auditor or supervisor would expect to see.

Moving fast with controls that hold

None of this argues for slowing down. Institutions in the region that move early on agents are building an advantage, and BCG is right that it compounds.

That advantage lasts only if the controls around those agents survive scrutiny from someone other than the people who built them. The harness is where an institution’s governance becomes executable. All three articles leave open the question of who tests it. Independent testing against relevant Singapore supervisory expectations and industry guidance is the control-testing gap Aivance helps institutions close.


Sources

AH
Arjen Hendrikse
Founder of Aivance Consulting. ISO/IEC 42001:2023 Lead Auditor. Thirty years working at the edge of what technology can do. More about Arjen
This article was drafted with AI assistance and reviewed for accuracy by Arjen Hendrikse before publication. AI Use Policy

Put what you just read to work

If this article raised questions about your own governance posture, the 30-minute Authority & Control Review is the right next step. A written scoping note follows within 48 hours.

Book an Authority & Control Review