Singapore MAS Proposes to Amend Notices

Singapore MAS Proposes to Amend Notices on Technology Risk Management

8/3/2026
Singapore MAS Proposes to Amend Notices

Read Time: 3 minutes

The Monetary Authority of Singapore (MAS) proposes amendments to Technology Risk Management (TRM) Notices to strengthen sector-wide resilience. The updated requirements apply to a broad range of institutions including banks, insurers, payment service providers, and capital markets entities. New mandates take effect 12 months after the publication of the finalized Notice.

 

What the Amendment Requires

The following table summarizes the proposed 2026 requirements:

Focus Area

2026 Proposed Requirement

Downtime Computation

Must explicitly include partial or intermittent disruptions.

IT Asset Inventory

Comprehensive inventory of hardware, software, cryptographic assets, open-source and third-party components.

Risk Assessment

Must specifically model emerging AI-enabled threats and supply chain risks.

Capacity Planning

Frameworks must proactively account for projected growth and traffic surges.

Data Resilience

Mandatory implementation of immutable or offline backups.

Incident Management

Formal incident management framework covering defined roles, evidence preservation, and senior management notification procedures.

 

Establishing Governance and Visibility

The amendments mandate lifecycle management and formalized oversight across IT assets:

  • Detailed Asset Inventories: FIs must maintain granular records of every IT component, including vulnerability and patch management, system dependencies, and accountable owners.

  • IT Risk Registers: Organizations must document all material identified risks, assigned risk owners, and the specific measures implemented to mitigate them.

  • Performance Monitoring: FIs are required to maintain Key Risk Indicators (KRIs) to assess the effectiveness of their risk mitigation strategies over time.

 

Maintaining System Integrity

MAS is introducing stricter operational controls to prevent service degradation:

  • Rigorous Change Management: Assessments must evaluate impact on upstream and downstream systems, supported by testing commensurate with the risk.

  • Advanced Monitoring: Systems must be continuously monitored using defined alert thresholds for real-time detection of security or performance issues.

  • Incident Governance: Procedures must now explicitly include protocols for preserving evidence and prompt notification to senior management.

 

Strengthening Technology Resilience

Crowe helps financial institutions address the proposed requirements through practical, risk-based cybersecurity and GRC advisory services. The aim is to provide informed decisions and gradual, sustainable digital trust. Speak with our team to discover what these changes could mean for your organization.

Source: MAS Consultation Paper on Proposed Amendments to Notices on Technology Risk Management, 10 June 2026.


Speak to our expert.
Crowe can provide specialized industry consulting services to help tackle the specific challenges you face.