MAS Revises Guidelines on Technology Risk Management
MAS revised the guidelines that address technology and cyber risks of financial institutions, in an environment of growing use of cloud technologies, application programming interfaces, and rapid software development. Post a consultation, the enhancements include new guidance on effective cyber surveillance, secure software development, adversarial attack simulation exercise, and management of cyber risks posed by the emerging technologies such as Internet of Things. MAS also published a response to the feedback received during the consultation process, in addition to a set of the frequently asked questions (FAQs) on the guidelines.
The guidelines on technology risk management set out the risk management principles and best practices to guide financial institutions, including banks, to establish sound and robust technology risk governance and oversight and to maintain cyber resilience. In particular, for financial institutions, the guidelines set out:
- Expectations to have in place effective technology risk management practices and controls to protect the information technology infrastructure: the institutions are required to test and validate the effectiveness of the recovery process once every 12 months.
- Enhanced risk mitigation strategies to establish a robust process for the timely analysis and sharing of cyber threat intelligence within the financial ecosystem and to conduct cyber exercises to allow institutions to stress test their cyber defenses by simulating the attack tactics, techniques, and procedures used by real-world attackers.
- Expectations to exercise strong oversight of arrangements with third-party service providers, to ensure system resilience as well as maintain data confidentiality and integrity.
- Additional guidance on the roles and responsibilities of the board of directors and senior management: the board and senior management should ensure that a Chief Information Officer and a Chief Information Security Officer, with the requisite experience and expertise, are appointed and accountable for managing technology and cyber risks and the board should include members with the relevant knowledge to provide effective oversight of technology and cyber risks.
- Expectations to establish and continuously improve IT processes and controls to preserve confidentiality, integrity and availability of data and information technology systems. Security measures should be implemented to prevent and detect the use of unauthorized internet services that allow users to communicate or store confidential data; examples of such services include social media, cloud storage, and file sharing, e-mails, and messaging applications.
MAS expects financial institutions to observe the guidelines on technology risk management as this will be considered in the risk assessment of MAS with respect to the financial institutions. The guidelines provide general guidance and are not intended to be comprehensive nor replace or override any legislative provisions. They should be read in conjunction with the provisions of the relevant legislation, the subsidiary legislation made under the relevant legislation, as well as written directions, notices, codes, and other guidelines that MAS may issue from time to time pursuant to the relevant legislation and subsidiary legislation. In particular, the guidelines should be read with the Notice on Technology Risk Management and Notice on Cyber Hygiene.
Keywords: Asia Pacific, Singapore, Banking, Insurance, Securities, Technology Risk, Cyber Risk, FAQ, Internet of Things, Governance, Cyber Resilience, MAS
Previous Article
ESAs Publish Reporting Templates for Financial ConglomeratesRelated Articles
BIS and Central Banks Experiment with GenAI to Assess Climate Risks
A recent report from the Bank for International Settlements (BIS) Innovation Hub details Project Gaia, a collaboration between the BIS Innovation Hub Eurosystem Center and certain central banks in Europe
Nearly 25% G-SIBs Commit to Adopting TNFD Nature-Related Disclosures
Nature-related risks are increasing in severity and frequency, affecting businesses, capital providers, financial systems, and economies.
Singapore to Mandate Climate Disclosures from FY2025
Singapore recently took a significant step toward turning climate ambition into action, with the introduction of mandatory climate-related disclosures for listed and large non-listed companies
SEC Finalizes Climate-Related Disclosures Rule
The U.S. Securities and Exchange Commission (SEC) has finalized the long-awaited rule that mandates climate-related disclosures for domestic and foreign publicly listed companies in the U.S.
EBA Proposes Standards Related to Standardized Credit Risk Approach
The European Banking Authority (EBA) has been taking significant steps toward implementing the Basel III framework and strengthening the regulatory framework for credit institutions in the EU
US Regulators Release Stress Test Scenarios for Banks
The U.S. regulators recently released baseline and severely adverse scenarios, along with other details, for stress testing the banks in 2024. The relevant U.S. banking regulators are the Federal Reserve Bank (FED), the Federal Deposit Insurance Corporation (FDIC), and the Office of the Comptroller of the Currency (OCC).
Asian Governments Aim for Interoperability in AI Governance Frameworks
The regulatory landscape for artificial intelligence (AI), including the generative kind, is evolving rapidly, with governments and regulators aiming to address the challenges and opportunities presented by this transformative technology.
EBA Proposes Operational Risk Standards Under Final Basel III Package
The European Union (EU) has been working on the final elements of Basel III standards, with endorsement of the Banking Package and the publication of the European Banking Authority (EBA) roadmap on Basel III implementation in December 2023.
EFRAG Proposes XBRL Taxonomy and Standard for Listed SMEs Under ESRS
The European Financial Reporting Advisory Group (EFRAG), which plays a crucial role in shaping corporate reporting standards in European Union (EU), is seeking comments, until May 21, 2024, on the Exposure Draft ESRS for listed SMEs.
ECB to Expand Climate Change Work in 2024-2025
Banking regulators worldwide are increasingly focusing on addressing, monitoring, and supervising the institutions' exposure to climate and environmental risks.