Featured Product

    MAS Revises Guidelines on Technology Risk Management

    January 18, 2021

    MAS revised the guidelines that address technology and cyber risks of financial institutions, in an environment of growing use of cloud technologies, application programming interfaces, and rapid software development. Post a consultation, the enhancements include new guidance on effective cyber surveillance, secure software development, adversarial attack simulation exercise, and management of cyber risks posed by the emerging technologies such as Internet of Things. MAS also published a response to the feedback received during the consultation process, in addition to a set of the frequently asked questions (FAQs) on the guidelines.

    The guidelines on technology risk management set out the risk management principles and best practices to guide financial institutions, including banks, to establish sound and robust technology risk governance and oversight and to maintain cyber resilience. In particular, for financial institutions, the guidelines set out:

    • Expectations to have in place effective technology risk management practices and controls to protect the information technology infrastructure: the institutions are required to test and validate the effectiveness of the recovery process once every 12 months.
    • Enhanced risk mitigation strategies to establish a robust process for the timely analysis and sharing of cyber threat intelligence within the financial ecosystem and to conduct cyber exercises to allow institutions to stress test their cyber defenses by simulating the attack tactics, techniques, and procedures used by real-world attackers.
    • Expectations to exercise strong oversight of arrangements with third-party service providers, to ensure system resilience as well as maintain data confidentiality and integrity.
    • Additional guidance on the roles and responsibilities of the board of directors and senior management: the board and senior management should ensure that a Chief Information Officer and a Chief Information Security Officer, with the requisite experience and expertise, are appointed and accountable for managing technology and cyber risks and the board should include members with the relevant knowledge to provide effective oversight of technology and cyber risks.
    • Expectations to establish and continuously improve IT processes and controls to preserve confidentiality, integrity and availability of data and information technology systems. Security measures should be implemented to prevent and detect the use of unauthorized internet services that allow users to communicate or store confidential data; examples of such services include social media, cloud storage, and file sharing, e-mails, and messaging applications.

    MAS expects financial institutions to observe the guidelines on technology risk management as this will be considered in the risk assessment of MAS with respect to the financial institutions. The guidelines provide general guidance and are not intended to be comprehensive nor replace or override any legislative provisions. They should be read in conjunction with the provisions of the relevant legislation, the subsidiary legislation made under the relevant legislation, as well as written directions, notices, codes, and other guidelines that MAS may issue from time to time pursuant to the relevant legislation and subsidiary legislation. In particular, the guidelines should be read with the Notice on Technology Risk Management and Notice on Cyber Hygiene.

     

    Keywords: Asia Pacific, Singapore, Banking, Insurance, Securities, Technology Risk, Cyber Risk, FAQ, Internet of Things, Governance, Cyber Resilience, MAS

    Related Articles
    News

    BIS Bulletin Examines Cognitive Limits of Large Language Models

    The use cases of generative AI in the banking sector are evolving fast, with many institutions adopting the technology to enhance customer service and operational efficiency.

    January 25, 2024 WebPage Regulatory News
    News

    ECB is Conducting First Cyber Risk Stress Test for Banks

    As part of the increasing regulatory focus on operational resilience, cyber risk stress testing is also becoming a crucial aspect of ensuring bank resilience in the face of cyber threats.

    January 24, 2024 WebPage Regulatory News
    News

    EBA Continues Momentum Toward Strengthening Prudential Rules for Banks

    A few years down the road from the last global financial crisis, regulators are still issuing rules and monitoring banks to ensure that they comply with the regulations.

    January 24, 2024 WebPage Regulatory News
    News

    EU and UK Agencies Issue Updates on Final Basel III Rules

    The European Commission (EC) recently issued an update informing that the European Council and the Parliament have endorsed the Banking Package implementing the final elements of Basel III standards

    December 19, 2023 WebPage Regulatory News
    News

    Industry Agency Expects Considerable Uptake for Swiss Climate Scores

    The Swiss Federal Council recently decided to further develop the Swiss Climate Scores, which it had first launched in June 2022.

    December 18, 2023 WebPage Regulatory News
    News

    BCBS Consults on Disclosure of Climate Risks, Issues Other Updates

    The Basel Committee on Banking Supervision (BCBS) launched consultation on a Pillar 3 disclosure framework for climate-related financial risks, with the comment period ending on February 29, 2024.

    December 18, 2023 WebPage Regulatory News
    News

    US Government Moves to Regulate Development and Use of AI Models

    The U.S. President Joe Biden signed an Executive Order, dated October 30, 2023, to ensure safe, secure, and trustworthy development and use of artificial intelligence (AI).

    December 18, 2023 WebPage Regulatory News
    News

    MAS Launches Gprnt Digital Platform for ESG Reporting for SMEs

    The Monetary Authority of Singapore (MAS) launched an integrated digital platform, Gprnt, also known as “Greenprint.”

    November 29, 2023 WebPage Regulatory News
    News

    EBA Finalizes Templates for One-Off Climate Risk Scenario Analysis

    The European Banking Authority (EBA) has published the final templates, and the associated guidance, for collecting climate-related data for the one-off Fit-for-55 climate risk scenario analysis.

    November 28, 2023 WebPage Regulatory News
    News

    NGFS Publishes Phase IV Long-term Climate Scenarios for Banks

    The Network for Greening the Financial System (NGFS) published its latest set of long-term climate macro-financial scenarios (Phase IV) for assessing forward-looking climate risks.

    November 28, 2023 WebPage Regulatory News
    RESULTS 1 - 10 OF 8947