
The proposed amendments seek to reinforce the importance of the stipulated risk management measures and strengthen financial institutions’ technology resilience amidst the increasing digitalisation and evolving risk landscape. A summary of the key areas is as follows.
- IT asset management
- Maintain a comprehensive and up-to-date inventory of all of their IT assets, which includes hardware, software, cryptographic assets, open-source and third-party components.
- IT risk assessment and monitoring
- Framework and process to conduct regular IT risk assessments and implement risk mitigation measures.
- Maintain an IT risk register that records the material identified risks, risk owners and mitigating measures.
- Key Risk Indicators to monitor the risks and effectiveness of the measures.
- Capacity planning and management
- Framework and process to ensure that the capacity of all critical systems, and the systems that the critical systems depend on, are sufficient to meet business needs, including projected business growth and potential surges in customer traffic.
- Change management controls
- Implement effective controls to prevent unauthorised system changes so as to maintain system integrity and availability.
- Framework and process to assess the risks arising from proposed changes to systems prior to implementation, and implement risk mitigation measures.
- Carry out testing for all changes to critical systems before they are implemented in the production environment. Have effective change recovery measures to recover any critical system affected by any issue arising during or after change implementation.
- Continuous system and security monitoring
- Framework and process to continuously monitor all critical systems by including (a) defined indicators and thresholds that trigger alerts; and (b) response procedures and remedial actions.
- Immutable or offline data backup
- Maintain an immutable or offline backup of data that are crucial for supporting the relevant business services.
- Incident management
- Incident management framework and process, with clearly defined roles and responsibilities for managing and responding to IT incidents, including procedures to collect and preserve evidence for incident investigation, stakeholder and customer communication, and prompt notification to FIs’ senior management upon identification of the IT incident to enable informed decision-making.
- Monitoring of unscheduled downtime
- Clear and explicit requirement that any partial or intermittent disruption must be included in the computation of unscheduled downtime for critical systems.
- Transition period
- Take effect 12 months after the date that the finalised Notice is published.
For the full details, refer to https://www.mas.gov.sg/publications/consultations/2026/consultation-paper-on-proposed-amendments-to-notices-on-technology-risk-management
Disclaimer: The information, views or opinions expressed are provided for general information and should not be relied upon as legal or professional advice.