Singapore supervisory guidance for technology governance, cyber security, systems resilience, change and third-party risk.
TL;DR:
- Singapore supervisory guidance for technology governance, cyber security, systems resilience, change and third-party risk.
- Maintain board oversight, secure architecture, cyber controls, resilience, testing and third-party governance.
- Monitor incidents and report significant events to MAS under applicable notices.
Summary
Singapore supervisory guidance for technology governance, cyber security, systems resilience, change and third-party risk. Its scope covers technology supporting financial and payment services.
The main requirements are to maintain board oversight, secure architecture, cyber controls, resilience, testing and third-party governance.
Operational resilience focuses on the continued delivery of important services through disruption. Technology availability is one input, alongside people, processes, data, facilities and third parties. Mapping those dependencies exposes situations in which an apparently healthy component still cannot deliver the end-to-end service that customers or other institutions rely on.
Risk management seeks to prevent failures; continuity and recovery planning deal with failures that still occur. Scenario testing examines whether those arrangements work under severe but plausible conditions, including the loss of an important supplier or a shared dependency. Recovery objectives, communication and decision-making responsibilities need to be connected to the affected service rather than considered only as technical system settings.
For payment activity, disruption can affect initiation, authentication, processing, settlement support and access to funds in different ways. Evidence from incidents and tests helps identify weaknesses and track remediation. The instrument's scope determines which institutions or infrastructures are covered and how its governance, reporting and assurance expectations interact with other financial-sector rules.
The instrument also addresses reporting and evidence: monitor incidents and report significant events to MAS under applicable notices.
Keywords
- MAS Technology Risk Management Guidelines
- MAS TRM
- Technology Risk Management Guidelines
- MAS Technology Risk Management Guidelines summary
- MAS Technology Risk Management Guidelines requirements
- MAS Technology Risk Management Guidelines compliance
- Singapore payment regulation
- Singapore financial regulation
- Monetary Authority of Singapore regulation
- operational resilience