Monetary Authority of Singapore Technology Risk Management Guidelines
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Access Control Cryptography Network - MAS TRM Chapters 9-10
Implement Access Control + Cryptography + Network and Infrastructure Security per MAS TRM Chapters 9 + 10. Chapter 9 Access Control + Cryptography - access control policy + user identification + authentication (Multi-Factor Authentication MFA required for privileged access per Notice 655 + biometric + smart cards + soft tokens) + authorisation (Role-Based Access Control RBAC + Attribute-Based Access Control ABAC + Mandatory Access Control MAC) + accountability (audit logging + monitoring) + least privilege + separation of duties + privileged access management (PAM) with session recording + just-in-time access + service accounts management + machine identities + Cryptography per ISO/IEC 18033 + FIPS 140-2/140-3 validated modules + key management (key generation + storage + rotation + destruction) + Hardware Security Module (HSM) for key storage + Public Key Infrastructure (PKI) + Certific
- Access control policy + RBAC matrix + least privilege evidence
- MFA enforcement for all privileged access (Notice 655 requirement)
- PAM tooling with session recording + JIT access
- FIPS 140-2/140-3 validated cryptographic modules + HSM-backed key management
- PKI/CA + certificate lifecycle management + algorithm strength (AES-256 + RSA-3072+ + SHA-256+)
- Post-Quantum Cryptography preparation roadmap
- Network segmentation evidence + firewall + IDS/IPS + DDoS + WAF + NAC + zero trust architecture progress
- MFA not enforced for all administrative paths (Notice 655 baseline failure)
- PAM without session recording (audit gap)
- Service accounts without management lifecycle
- TLS 1.0/1.1 still enabled on some interfaces
- Post-Quantum Cryptography roadmap absent
Cyber Resilience - MAS TRM Chapter 11
Implement Cyber Resilience per MAS TRM Chapter 11 including Cyber Threat Intelligence + Penetration Testing + Vulnerability Assessment + Cyber Incident Response and Notification. Cyber Threat Intelligence (CTI) programme - subscription to commercial feeds (CrowdStrike + Microsoft + Mandiant + Recorded Future + Anomali + Intel 471 + Flashpoint) + open-source intelligence (OSINT) + dark web monitoring + ISAC participation (FS-ISAC + ABS Cybersecurity Standards + IMDA SingCERT) + government sharing (CSA NCSC ASEAN CSO) + STIX 2.x/TAXII 2.x exchange + Indicators of Compromise (IOCs) + Indicators of Attack (IOAs) + ATT&CK mapping + threat hunt programmes. Penetration Testing - critical systems triennial penetration testing per Notice 644 + Singapore Cyber Resilience Framework (CRF) + Red Team exercises + Purple Team exercises + Bug Bounty programmes + CREST/OSCP certified testers + ATT&CK-ali
- Cyber Threat Intelligence programme + commercial feed subscriptions + FS-ISAC + SingCERT participation
- Penetration testing triennial per critical system (Notice 644) + Red/Purple Team exercises + Bug Bounty
- Vulnerability management programme with remediation SLA (critical 24-48h + high 7d + medium 30d)
- 24x7 SOC + CSIRT operational evidence + ATT&CK-aligned playbooks
- **MAS NOTICE 644 PARAGRAPH 6 - Relevant Incident 1-HOUR notification to MAS evidence**
- Root cause analysis within 14 days + remediation plan + customer notification per Notice 644 paragraph 7
- Cyber resilience tabletop exercises + simulation exercises
- **1-hour notification SLA missed for Relevant Incident (Notice 644 paragraph 6 BREACH)**
- CTI commercial feeds without operationalisation in SOC
- Penetration testing triennial gap (more than 3 years between tests)
- Vulnerability remediation SLA breached for critical/high
Governance and Framework - MAS TRM Chapters 2-3-5
Implement Technology Risk Governance + Technology Risk Management Framework + Information Asset Management per MAS TRM Chapters 2 + 3 + 5. Chapter 2 Technology Risk Governance and Oversight - Board responsibility for technology risk + Senior Management implementation + Chief Information Officer (CIO) role + Chief Information Security Officer (CISO) role + Technology Risk Committee + Risk Appetite Statement for technology risk + Three Lines of Defence (1st line Technology + 2nd line Risk Management + 3rd line Internal Audit). MAS Notice 644 paragraph 4 binding Board and Senior Management responsibility. Chapter 3 Technology Risk Management Framework - risk identification + risk assessment + risk treatment + risk monitoring + risk reporting + ISO 31000 alignment + COSO ERM integration + risk taxonomy + risk register + Key Risk Indicators (KRIs) + Risk and Control Self-Assessment (RCSA) + r
- Board-approved Technology Risk Appetite Statement
- CIO + CISO designation + role description + reporting line
- Technology Risk Committee charter + meeting minutes
- Three Lines of Defence documentation
- Risk register + KRI dashboard + RCSA records
- Information asset inventory + classification + ownership records
- CMDB + ITAM + SAM integration
- No Risk Appetite Statement for technology risk
- CISO reporting to CIO (not independent reporting to CEO/Board)
- Information asset classification incomplete (especially data assets)
- RCSA outdated or not refreshed annually
Online Authentication and Payment Card - MAS TRM Chapters 12-13
Implement Online Financial Services Authentication + Payment Card Security per MAS TRM Chapters 12 + 13. Chapter 12 Online Financial Services Authentication - Two-Factor Authentication (2FA) for customer-facing online services + Strong Customer Authentication (SCA) for high-risk transactions including biometric + OTP + cryptographic tokens + hardware tokens + behavioural biometrics + device intelligence + risk-based authentication (RBA) + transaction signing for high-value or high-risk transfers + transaction monitoring + fraud detection systems + anti-Account Takeover (ATO) controls + bot mitigation + CAPTCHA + IP reputation + impossible travel + velocity controls + cooling-off period for high-risk transactions + secure session management + cookie security + secure customer onboarding (eKYC compliant with MAS PIDM + Personal Identity Number SingPass MyInfo). Chapter 13 Payment Card Secu
- 2FA for customer-facing online services + Strong Customer Authentication for high-risk transactions
- Risk-based authentication + transaction signing for high-value transfers
- Anti-ATO controls + bot mitigation + impossible travel + velocity controls
- PCI DSS v4.0 compliance + QSA engagement + AoC + segmentation
- Tokenisation + EMV + 3D Secure 2.0 + dynamic CVV
- eKYC + SingPass MyInfo integration + PayNow security + cross-border SWIFT CSP
- 2FA bypassed for low-risk pathways that enable elevation
- PCI DSS v3.2.1 not refreshed for v4.0 (effective March 2024)
- 3D Secure 1.0 deprecated but still in production for some merchants
- Risk-based authentication thresholds not calibrated
Project SDLC and Service Management - MAS TRM Chapters 4-6
Implement IT Project Management + Software Development Lifecycle + IT Service Management per MAS TRM Chapters 4 + 5 + 6. Chapter 4 IT Project Management - project initiation approval + business case + risk assessment + technology security review + steering committee + status reporting + change advisory + go/no-go gates + project close-out review + PMO programme management office governance. Chapter 5 Software Development Lifecycle (SDLC) - secure coding standards (OWASP Top 10 + OWASP ASVS + CWE Top 25 + CERT Secure Coding) + threat modelling (STRIDE + DREAD + PASTA) + secure design review + code review (static SAST + dynamic DAST + interactive IAST + software composition analysis SCA) + security testing + UAT + penetration testing prior to production + open-source license compliance + Software Bill of Materials (SBOM) + SDLC integration with DevSecOps + CI/CD pipeline security + Infrast
- IT project governance evidence + steering committee + go/no-go gates
- SDLC documentation including secure coding (OWASP) + threat modelling + SAST/DAST/IAST/SCA + SBOM
- ITIL 4-aligned ITSM with change/release/incident/problem/configuration/capacity/availability mgmt
- Change Advisory Board (CAB) minutes + emergency change procedure
- DevSecOps + CI/CD pipeline security evidence + IaC security + container security
- Pre-production penetration testing skipped under tight delivery deadlines
- SBOM not generated for in-house developed software
- DevSecOps shift-left not implemented for legacy applications
- Emergency change procedure abused for normal changes
Scope and Authority - MAS TRM 2021
Establish the scope of Monetary Authority of Singapore Technology Risk Management Guidelines (MAS TRM Guidelines) current edition January 2021 + supplementary binding MAS Notice 644 on Technology Risk Management + MAS Notice 655 on Cyber Hygiene (effective 6 August 2020 + amended 2022). Foundational Singapore financial sector technology risk management baseline. Applies to MAS-regulated entities under: Banking Act + Finance Companies Act + Insurance Act + Securities and Futures Act + Financial Advisers Act + Payment Services Act. Covered entities include: banks (DBS + OCBC + UOB + foreign branches Standard Chartered + HSBC + Citibank) + finance companies + insurance (general + life + reinsurance) + capital markets services (securities + futures + fund management + research + corporate finance) + financial advisers + payment service providers (MPI + SPI) + designated financial holding com
- MAS TRM 2021 + Notice 644 + Notice 655 applicability assessment
- MAS-regulated entity license verification (Banking Act + Insurance Act + SFA + FAA + PSA)
- D-SIB designation if applicable + ABS Cybersecurity Standards adoption
- CSA Cybersecurity Code of Practice / CII designation cross-walk if applicable
- Sectoral coordination evidence (ABS + LIA + GIA + SAS + DCO)
- TRM 2021 not refreshed against 2013 baseline
- Notice 655 Cyber Hygiene 6 baseline measures not fully implemented
- D-SIB designation triggers not assessed (DBS + OCBC + UOB cross-reference)
Systems Reliability and Data Centre - MAS TRM Chapters 7-8
Implement Systems Reliability Availability and Recoverability + Data Centre Resilience per MAS TRM Chapters 7 + 8. Chapter 7 Systems Reliability + Availability + Recoverability - Recovery Time Objective (RTO) definition + testing + Recovery Point Objective (RPO) definition + testing + system downtime tracking + Business Continuity Plan (BCP) + Disaster Recovery Plan (DRP) + crisis management + tabletop exercises + simulation exercises + full-scale annual DR test + Maximum Tolerable Period of Disruption (MTPD) + Maximum Tolerable Data Loss (MTDL) + critical system identification + system criticality categorisation + dependency mapping + cascading failure analysis. **MAS NOTICE 644 PARAGRAPH 5 BINDING REQUIREMENT**: System downtime no more than 4 hours within any 12-month period for systemically-important systems (systemically-important systems = systems supporting essential financial serv
- RTO + RPO definitions per critical system + tested evidence
- **MAS NOTICE 644 PARAGRAPH 5 - system downtime tracking within 4-hour 12-month threshold for systemically-important systems**
- Annual full-scale DR test report + tabletop exercises + simulation exercises
- Tier III+ data centre evidence + geographic separation + power/cooling resilience
- Critical system identification + dependency mapping + cascading failure analysis
- Cloud DR + multi-region architecture if cloud-hosted
- **System downtime exceeded 4 hours within 12 months for systemically-important systems (Notice 644 paragraph 5 BREACH)**
- Annual DR test not full-scale (partial only)
- RTO/RPO not tested under realistic load
- Critical system identification limited to obvious systems (missing dependencies)
Third Party Risk and IT Audit - MAS TRM Chapters 14-15
Implement IT Audit + Third-Party Risk Management per MAS TRM Chapters 14 + 15 + MAS Notice 658 on Outsourcing. Chapter 14 IT Audit - IT audit charter approved by Board Audit Committee + IT audit plan risk-based + IT audit methodology + IT auditor competency (CISA + CIA + CRISC + CGEIT) + audit reporting to Board Audit Committee + remediation tracking + IT general controls (ITGC) coverage + application controls (input + processing + output) coverage + interface controls + IT operations audit + cybersecurity audit + IT outsourcing audit + cloud audit + co-sourcing with external IT auditors where required + alignment with COSO + COBIT 2019 + ISACA IT Audit Framework + ISAE 3402/SOC 2. Chapter 15 Third-Party Risk Management - third-party risk register + due diligence on prospective service providers + ongoing monitoring + contractual security requirements (right to audit + breach notificatio
- Board Audit Committee approved IT audit charter + risk-based plan
- Third-party risk register + due diligence + ongoing monitoring evidence
- Material Outsourcing Notice 658 30-day prior notification evidence + business continuity provisions + exit strategy
- Cloud as Material Outsourcing assessment (AWS + Azure + GCP) + MAS Industry Standards on Cloud 2020 adoption
- Concentration risk monitoring (single-vendor + single-cloud-provider risk)
- Annual third-party assurance reports (SOC 2 Type 2 + ISAE 3402 + ABS Cloud Cyber Resilience)
- Material Outsourcing Notice 658 30-day prior notification skipped
- Cloud egress strategy absent (vendor lock-in risk)
- Concentration risk monitoring at vendor level only (not sub-component level)
- Annual third-party assurance reports not reviewed by Board Audit Committee
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Monetary Authority of Singapore Technology Risk Management Guidelines framework page.