MAS TRM Compliance — Technology Risk Management Audit
Security Brigade provides MAS TRM compliance audit services aligned to the Monetary Authority of Singapore's TRM Notice and Guidelines. CERT-In empanelled since 2008.
Trusted by India's leading enterprises
What kind of instrument this is
Guidance whose observance MAS weighs when it supervises you
The status of the TRM Guidelines is the thing most often got wrong, in both directions, and it changes how an assessment should be scoped.
-
What they are
Guidelines, issued January 2021
They set out sound practice for managing technology risk across governance, the risk management framework, system development, service management, resilience, access control, cryptography, data and infrastructure security, cyber security operations and online financial services.
-
How MAS uses them
Observance is a supervisory consideration
The Guidelines state it directly: in supervising a financial institution, the degree of observance with their spirit is an area of consideration by MAS. That is a different thing from a rule with a penalty attached, and a stronger thing than a suggestion.
-
How much is expected
Proportionate to risk and complexity
The extent and degree of implementation should be commensurate with the level of risk and complexity of the financial services offered and the technology supporting them.
-
What sits beside them
Notices and written directions
The Guidelines say they provide general guidance, are not intended to be comprehensive, and do not replace or override legislative provisions, and are read together with the notices, directions and codes MAS issues. The binding obligations, including specific incident and availability requirements, live in those instruments, not here.
What an assessment covers
The areas the Guidelines organise, and what evidences each
| Area | What the Guidelines address | What we evidence |
|---|---|---|
| Governance and oversight | The role of the board and senior management, policies and standards, management of information assets, management of third-party services, competency and background review, and security awareness. | Board reporting, the policy set, and the third-party assurance chain |
| Risk management framework | Risk identification, assessment, treatment, and monitoring, review and reporting as a running cycle. | The register, the treatment decisions, and evidence the cycle actually turns |
| Development and service management | IT project management, software application development, and IT service management including change and incident handling. | Secure development testing, change records, and release evidence |
| Access control and cryptography | Access management across users and privilege, and the cryptographic controls protecting data. | Access review records and technical testing of the controls as deployed |
| Data and infrastructure security | Protection of data and of the infrastructure carrying it, and the cyber security operations around both. | Application, API, network and infrastructure testing with findings closed and retested |
| Resilience | IT resilience, including recovery objectives for systems and the arrangements behind them. | Architecture review against the stated objectives |
Governance and oversight
- What the Guidelines address
- The role of the board and senior management, policies and standards, management of information assets, management of third-party services, competency and background review, and security awareness.
- What we evidence
- Board reporting, the policy set, and the third-party assurance chain
Risk management framework
- What the Guidelines address
- Risk identification, assessment, treatment, and monitoring, review and reporting as a running cycle.
- What we evidence
- The register, the treatment decisions, and evidence the cycle actually turns
Development and service management
- What the Guidelines address
- IT project management, software application development, and IT service management including change and incident handling.
- What we evidence
- Secure development testing, change records, and release evidence
Access control and cryptography
- What the Guidelines address
- Access management across users and privilege, and the cryptographic controls protecting data.
- What we evidence
- Access review records and technical testing of the controls as deployed
Data and infrastructure security
- What the Guidelines address
- Protection of data and of the infrastructure carrying it, and the cyber security operations around both.
- What we evidence
- Application, API, network and infrastructure testing with findings closed and retested
Resilience
- What the Guidelines address
- IT resilience, including recovery objectives for systems and the arrangements behind them.
- What we evidence
- Architecture review against the stated objectives
Scoping it honestly
Proportionality is an instruction, not an escape
The proportionality language in the Guidelines is frequently read as licence to do less, and it is better read as an instruction to be able to explain what you did. If implementation is to be commensurate with the level of risk and complexity of the services you offer, then the position you have to be able to defend is that you assessed your risk and complexity, decided a proportionate depth, and can show the reasoning. That is a documentary position as much as a technical one, and it is the one we build towards. In practice it means an engagement starts by establishing what the institution actually does, which systems carry it, and what a failure of each would mean for customers and for the market, before any control is assessed. A payments firm with a single customer-facing product and a licensed bank running a full estate will both produce a defensible position, and they will not look alike. The failure we see most often is an institution that has done sensible things for sensible reasons and cannot evidence the reasoning, so a supervisor sees a set of controls with no visible logic connecting them to the business.
Working from India
What a Singapore engagement looks like from here
A CERT-In empanelled team
Empanelment is an Indian credential, and it is the assurance regime our testing is held to, continuously since 2008, and it travels with the work.
Data residency decided at the outset
Where an engagement requires data and access to remain in a particular jurisdiction, that is set at scoping and delivered on that basis. Access from outside the agreed region happens only where you have agreed to it.
Evidence that answers more than MAS
The technical testing behind a TRM assessment is the same evidence an ISO 27001 ISMS or a SOC 2 readiness programme needs, which matters for institutions carrying obligations in more than one market.
Written for two readers
A board-ready view of the risk position and a technical report an engineer can act on without a follow-up call, tracked to verified closure in Lemon.
"I've bought penetration tests from five firms over the last decade. The difference with Security Brigade is that quality isn't dependent on who walks through the door. Their platform enforces the methodology, their senior reviewers catch what juniors miss, and the final report is something you can hand to an enterprise customer's security team without embarrassment. That's rare."
FAQ
MAS TRM, answered
Status, scope and proportionality. Talk to our team about your Singapore obligations.
Contact usAre the TRM Guidelines mandatory?
How much implementation is expected of a smaller institution?
What areas does an assessment cover?
Can an Indian firm perform this work?
How does this relate to our other compliance work?
Start Your MAS TRM Compliance Assessment
One scoping call to align on TRM domain coverage, institution size, and regulatory timeline.
Typically responds within 1 business day · No commitment required