MAS Technology Risk Management Guidelines

MAS Technology Risk Management Guidelines — 88% of in-scope requirements covered.

4 requirements · 4 in scope (3 enforced · 1 designed). The 88% is weighted over the in-scope base.

Source: Monetary Authority of Singapore, Technology Risk Management Guidelines (January 2021) — access control, audit logging, IT incident management, and third-party risk for financial institutions.

By category

CategoryReqsEnforcedDesignedAdvisoryDeferredCoverage
Access control11000100%
Audit logging & retention11000100%
IT incident management1010050%
Third-party risk management11000100%

Every requirement → the KYE™ artefact that enforces it

IDTitleStatusKYE™ enforcement
mas-trm.access-controlMAS TRM Guidelines — strong access controls, including least-privilege and just-in-time privileged access for systems handling financial dataenforcedaudit_events: kye.purpose.admissibility.v1, kye.risk.authority_register.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
mas-trm.audit-loggingMAS TRM Guidelines — comprehensive, tamper-resistant audit logging of system and security events with adequate retentionenforcedaudit_events: kye.evidence.pack.v1, kye.replay.context_seal.v1
engines: internal, internal
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md, constitution/35-STREAMING-LOGS.md
mas-trm.incident-managementMAS TRM Guidelines — IT incident management, including timely detection, escalation and notification to MAS of relevant incidentsdesignedaudit_events: kye.signal.incident.opened.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
mas-trm.third-party-riskMAS TRM Guidelines — manage technology risk arising from third-party service providers across the lifecycle of the arrangementenforcedaudit_events: kye.risk.authority_register.v1, kye.risk_assessment.v1
engines: internal, internal
constitution_refs: constitution/51-NO-SPOF.md

Canonical KYE™ surfaces referenced on this page: KYE Protocol™.