Read Time: 3 minutes
The Monetary Authority of Singapore (MAS) proposes amendments to Technology Risk Management (TRM) Notices to strengthen sector-wide resilience. The updated requirements apply to a broad range of institutions including banks, insurers, payment service providers, and capital markets entities. New mandates take effect 12 months after the publication of the finalized Notice.
What the Amendment Requires
The following table summarizes the proposed 2026 requirements:
|
Focus Area |
2026 Proposed Requirement |
|
Downtime Computation |
Must explicitly include partial or intermittent disruptions. |
|
IT Asset Inventory |
Comprehensive inventory of hardware, software, cryptographic assets, open-source and third-party components. |
|
Risk Assessment |
Must specifically model emerging AI-enabled threats and supply chain risks. |
|
Capacity Planning |
Frameworks must proactively account for projected growth and traffic surges. |
|
Data Resilience |
Mandatory implementation of immutable or offline backups. |
|
Incident Management |
Formal incident management framework covering defined roles, evidence preservation, and senior management notification procedures. |
Establishing Governance and Visibility
The amendments mandate lifecycle management and formalized oversight across IT assets:
Detailed Asset Inventories: FIs must maintain granular records of every IT component, including vulnerability and patch management, system dependencies, and accountable owners.
IT Risk Registers: Organizations must document all material identified risks, assigned risk owners, and the specific measures implemented to mitigate them.
Performance Monitoring: FIs are required to maintain Key Risk Indicators (KRIs) to assess the effectiveness of their risk mitigation strategies over time.
Maintaining System Integrity
MAS is introducing stricter operational controls to prevent service degradation:
Rigorous Change Management: Assessments must evaluate impact on upstream and downstream systems, supported by testing commensurate with the risk.
Advanced Monitoring: Systems must be continuously monitored using defined alert thresholds for real-time detection of security or performance issues.
Incident Governance: Procedures must now explicitly include protocols for preserving evidence and prompt notification to senior management.
Strengthening Technology Resilience
Crowe helps financial institutions address the proposed requirements through practical, risk-based cybersecurity and GRC advisory services. The aim is to provide informed decisions and gradual, sustainable digital trust. Speak with our team to discover what these changes could mean for your organization.
Source: MAS Consultation Paper on Proposed Amendments to Notices on Technology Risk Management, 10 June 2026.