What are the MAS TRM Guidelines and how do they govern technology risk in Singapore?
The MAS TRM Guidelines (Technology Risk Management Guidelines, revised January 2021) set out the Monetary Authority of Singapore’s expectations for technology governance, cyber resilience, and risk management. Specifically, they apply to all Financial Institutions (FIs) operating in Singapore. Moreover, they require FIs to establish strong oversight, apply a defense-in-depth strategy, and continuously improve controls to protect the confidentiality, integrity, and availability of systems and data.
In practice, FIs use the MAS TRM Guidelines alongside two companion frameworks. The MAS Outsourcing Guidelines govern third-party arrangements broadly. Furthermore, the ABS Cloud Computing Implementation Guide 2.0 provides practical guidance on vendor due diligence, outsourcing governance, and cloud-specific security controls. Together, these three frameworks define the full regulatory environment for technology and cloud risk in Singapore. As a result, a single core principle applies at all times: controls in the cloud must be at least equivalent to those used for in-house systems.
How do you classify cloud outsourcing arrangements under the ABS Cloud Guide?
The ABS Cloud Computing Implementation Guide 2.0 classifies cloud outsourcing arrangements as either Non-Material or Material, based on inherent risk and business impact. Specifically, an arrangement is Material when a failure or breach could disrupt operations, damage reputation, affect profitability, or impair regulatory compliance. Moreover, any arrangement involving customer information where loss or unauthorized access would materially harm customers also qualifies as Material.
In practice, Material workloads include MAS Critical systems, core banking platforms, financial risk systems, corporate email and document storage, and authentication services such as OTP and two-factor authentication. As a result, this classification determines the level of controls required. Specifically, Material workloads demand enhanced security, deeper due diligence, and stricter ongoing oversight.
What are the Board and Senior Management responsibilities under MAS TRM?
The MAS TRM Guidelines make technology risk a leadership responsibility, not an IT department concern. Specifically, the Board of Directors approves the risk framework and risk appetite. In addition, the Board ensures an independent audit function covers technology risk. Moreover, both the Board and Senior Management must maintain sufficient knowledge of technology risk to fulfill their governance roles effectively.
In practice, Senior Management carries four core duties:
- Implementing the technology risk framework across the organization
- Enforcing security policies and controls at the operational level
- Reporting material incidents and adverse developments to the Board in a timely manner
- Promoting a security-aware culture across all staff
What due diligence and contractual safeguards apply when selecting a Cloud Service Provider (CSP)?
Before engaging a CSP, FIs must assess the provider’s ability to meet security requirements for the intended workload. Specifically, the MAS TRM Guidelines and ABS Cloud Guide expect FIs to conduct structured pre-engagement due diligence. Moreover, contracts must clearly define accountability across the shared responsibility model.
In practice, due diligence covers five areas:
- Evaluating the CSP’s development and security practices
- Identifying where data is stored and processed, including all sub-processors
- Assessing legal, political, and operational risks of the hosting jurisdictions
- Conducting Threat and Vulnerability Risk Assessments (TVRA) on relevant data centers
- Reviewing physical and environmental security of the CSP’s facilities
Furthermore, contracts must include audit and inspection rights for MAS, access to investigation information, contractual control over data deletion and termination, and a clear definition of the shared responsibility boundary between the FI and the CSP.
What enhanced controls apply to Material cloud workloads under MAS TRM?
Material workloads require security measures that go beyond the baseline controls expected of all FIs. Specifically, the MAS TRM Guidelines set higher resilience and access control expectations for systems where a failure would have material impact. Moreover, if a third-party SaaS provider manages MAS Critical systems, contracts must require the provider to notify the FI immediately after any incident, so the FI can notify MAS within 60 minutes.
In practice, enhanced controls for Material workloads include:
- Privileged User Access Management (PUAM): MFA for all privileged access, detection of unauthorized account creation, and restricted remote access with private connectivity where feasible
- Multi-region architecture: critical systems must use multi-region deployments to meet higher resilience requirements
- Disaster recovery planning: DR plans must cover total cloud outages and partial failure scenarios
- Annual DR testing: tests must simulate full-site loss and partial failure, not just routine failover
- Multi-provider or hybrid approaches: FIs must consider these alternatives to reduce concentration risk on a single CSP