Skip to main content
CERT-In Empanelled Since 2008

MAS TRM Compliance — Technology Risk Management Audit

Security Brigade provides MAS TRM compliance audit services aligned to the Monetary Authority of Singapore's TRM Notice and Guidelines. CERT-In empanelled since 2008.

MAS TRM
Singapore Coverage
TRM-Aligned
Methodology
6,700+
Assessments
Since 2008
CERT-In Empanelled

Trusted by India's leading enterprises

ICICI Bank
NPCI
HDFC
Mahindra
Aditya Birla
PhonePe
Pernod Ricard
Swiggy
Asian Paints
Yes Bank
Tata Play
Larsen & Toubro
Voltas
DHL Express
Etihad Airways
Amazon Pay
Go Digit
Pharmeasy
BillDesk
Jubilant Foods
UltraTech
Titan
Infosys
Capgemini
Groww
Sephora

What kind of instrument this is

Guidance whose observance MAS weighs when it supervises you

The status of the TRM Guidelines is the thing most often got wrong, in both directions, and it changes how an assessment should be scoped.

What an assessment covers

The areas the Guidelines organise, and what evidences each

AreaWhat the Guidelines addressWhat we evidence
Governance and oversight The role of the board and senior management, policies and standards, management of information assets, management of third-party services, competency and background review, and security awareness. Board reporting, the policy set, and the third-party assurance chain
Risk management framework Risk identification, assessment, treatment, and monitoring, review and reporting as a running cycle. The register, the treatment decisions, and evidence the cycle actually turns
Development and service management IT project management, software application development, and IT service management including change and incident handling. Secure development testing, change records, and release evidence
Access control and cryptography Access management across users and privilege, and the cryptographic controls protecting data. Access review records and technical testing of the controls as deployed
Data and infrastructure security Protection of data and of the infrastructure carrying it, and the cyber security operations around both. Application, API, network and infrastructure testing with findings closed and retested
Resilience IT resilience, including recovery objectives for systems and the arrangements behind them. Architecture review against the stated objectives

Governance and oversight

What the Guidelines address
The role of the board and senior management, policies and standards, management of information assets, management of third-party services, competency and background review, and security awareness.
What we evidence
Board reporting, the policy set, and the third-party assurance chain

Risk management framework

What the Guidelines address
Risk identification, assessment, treatment, and monitoring, review and reporting as a running cycle.
What we evidence
The register, the treatment decisions, and evidence the cycle actually turns

Development and service management

What the Guidelines address
IT project management, software application development, and IT service management including change and incident handling.

Access control and cryptography

What the Guidelines address
Access management across users and privilege, and the cryptographic controls protecting data.
What we evidence
Access review records and technical testing of the controls as deployed

Data and infrastructure security

What the Guidelines address
Protection of data and of the infrastructure carrying it, and the cyber security operations around both.
What we evidence
Application, API, network and infrastructure testing with findings closed and retested

Resilience

What the Guidelines address
IT resilience, including recovery objectives for systems and the arrangements behind them.
What we evidence
Architecture review against the stated objectives

Scoping it honestly

Proportionality is an instruction, not an escape

The proportionality language in the Guidelines is frequently read as licence to do less, and it is better read as an instruction to be able to explain what you did. If implementation is to be commensurate with the level of risk and complexity of the services you offer, then the position you have to be able to defend is that you assessed your risk and complexity, decided a proportionate depth, and can show the reasoning. That is a documentary position as much as a technical one, and it is the one we build towards. In practice it means an engagement starts by establishing what the institution actually does, which systems carry it, and what a failure of each would mean for customers and for the market, before any control is assessed. A payments firm with a single customer-facing product and a licensed bank running a full estate will both produce a defensible position, and they will not look alike. The failure we see most often is an institution that has done sensible things for sensible reasons and cannot evidence the reasoning, so a supervisor sees a set of controls with no visible logic connecting them to the business.

Working from India

What a Singapore engagement looks like from here

The credential

A CERT-In empanelled team

Empanelment is an Indian credential, and it is the assurance regime our testing is held to, continuously since 2008, and it travels with the work.

Your call

Data residency decided at the outset

Where an engagement requires data and access to remain in a particular jurisdiction, that is set at scoping and delivered on that basis. Access from outside the agreed region happens only where you have agreed to it.

Reuse

Evidence that answers more than MAS

The technical testing behind a TRM assessment is the same evidence an ISO 27001 ISMS or a SOC 2 readiness programme needs, which matters for institutions carrying obligations in more than one market.

The report

Written for two readers

A board-ready view of the risk position and a technical report an engineer can act on without a follow-up call, tracked to verified closure in Lemon.

"I've bought penetration tests from five firms over the last decade. The difference with Security Brigade is that quality isn't dependent on who walks through the door. Their platform enforces the methodology, their senior reviewers catch what juniors miss, and the final report is something you can hand to an enterprise customer's security team without embarrassment. That's rare."
CTO, Enterprise SaaS Company
Chief Technology Officer

Read more client stories →

FAQ

MAS TRM, answered

Status, scope and proportionality. Talk to our team about your Singapore obligations.

Contact us
Are the TRM Guidelines mandatory?+
They are guidelines, and their own text is precise about what that means: in supervising a financial institution, the degree of observance with the spirit of the Guidelines is an area of consideration by MAS. They also state that they provide general guidance, are not intended to be comprehensive, and do not replace or override legislative provisions, and are read together with the notices and written directions MAS issues, and the binding obligations live in those. So the practical answer is that observance is examined even though the Guidelines are not themselves the enforcement instrument.
How much implementation is expected of a smaller institution?+
The Guidelines answer this directly: implementation should be commensurate with the level of risk and complexity of the financial services offered and the technologies supporting them. That is an instruction to assess your own risk and complexity and to be able to explain the depth you chose. A defensible small-institution position and a defensible bank position look very different, and both are defensible because the reasoning is visible.
What areas does an assessment cover?+
The areas the Guidelines organise: technology risk governance and oversight, the risk management framework, IT project management and software application development, IT service management, IT resilience, access control, cryptography, data and infrastructure security, cyber security operations, and online financial services. In practice governance and the risk framework carry the documentary weight while access control, data and infrastructure security carry the technical testing.
Can an Indian firm perform this work?+
Yes. The question that matters to a supervisor is the competence and independence of the assessment. Security Brigade has been CERT-In empanelled continuously since 2008 and works with institutions across Asia. Where an engagement requires data and access to remain in a particular jurisdiction, that is agreed at scoping and delivered on that basis.
How does this relate to our other compliance work?+
The technical evidence is largely shared. Application, API, network and infrastructure testing performed for a TRM assessment answers the equivalent expectations in an ISO 27001 ISMS, a SOC 2 readiness programme, and Indian frameworks if you carry obligations in both markets. The governance and risk-framework documentation is where the Singapore-specific work concentrates.

Start Your MAS TRM Compliance Assessment

One scoping call to align on TRM domain coverage, institution size, and regulatory timeline.

Typically responds within 1 business day · No commitment required

Request a Scoping Call