Singapore Regulatory Collection · 380 Obligations

Every Core MAS Technology and Outsourcing Duty in One Register, TRM Plus Both Binding Notices.

All 380 obligations, spanning the complete TRM Guidelines, the Cyber Hygiene Notice, and the Outsourcing Notice. The whole technology-risk perimeter, structured and cited.

$9,500one-time license

Secure Checkout via Stripe · Enterprise via Private Offer

BindingMAS Outsourcing Notice
MAS.OUT.2023.Sec12.4.p15.OBL1
Summary

Document the customer-information due diligence and provide it to MAS on request.

VerbatimMUSTobligation
A bank in Singapore must document the due diligence checks required under paragraphs 12.2 and 12.3 and furnish the documentation to the Authority upon request.

MAS Notice 658 (Outsourced Relevant Services), paragraph 12.4, p. 15 (2023)

ActorA bank in Singapore
ActionDocument the due diligence checks and furnish the documentation to the Authority on request
ObjectDocumentation of customer-information due diligence
Tagsdue-diligencecustomer-information
Requirements Relating to Outsourced Relevant Services That Involve the Disclosure of Customer Information · p.15high severitysupervisory sanction

Non-compliance with this Notice may attract MAS supervisory and enforcement action; a MAS notice imposes legally binding requirements on the relevant entities.

Source · Notice 658 Management of Outsourced Relevant ServicesRegulator PDF ↗

One record, straight from the full dataset

The Whole Perimeter

Every Core MAS Technology Duty, in One License.

Three Instruments, One Register

The TRM Guidelines plus both binding Notices, decomposed the same way in one schema. No duty hides between documents.

The Binding Notices, Sold Only Here

The Cyber Hygiene and Outsourcing Notices are Collection exclusives. If a legally binding duty exists in the perimeter, it is in this register.

Evidence on Every Duty

Pending MAS Approval

380 source-verified page captures, one per obligation, a Collection exclusive. When the examiner asks, you show them the page.

Product Details

What You License.

Coverage
380 obligations, each individually cited to the source.
Instruments
MAS TRM Guidelines (2021), Cyber Hygiene Notice FSM-N06 (2024), and Outsourcing Notice 658 (2023).
Schema
51 fields in five structured layers: verbatim, normalized, parsed, context, semantic intelligence. The same flat width as Complete TRM and the Free Sample.
Regulatory Intelligence
A generated summary, purpose, relationship, and implementation notes on every record.
Semantic Enrichment
Typed qualifications, evidence expectations, responsible roles, instrument force, domains, and cross-instrument links on every record, with per-field confidence in the JSON. Single TRM modules omit this layer and ship 47 fields across four layers.
Evidence
380 source-verified page captures, one per obligation. A Collection exclusive.Pending MAS Approval
Formats
Excel workbook, JSON, and CSV. Official source documents linked, not redistributed.
Updates
Point-in-time and versioned; an annual update subscription is optional, never required.
License
Single-organization commercial license, delivered by instant download.

Guidance and the two binding Notices, honestly labelled and decomposed the same way, so one register covers the whole MAS technology and outsourcing perimeter.

In Every Format

Excel

Cover, Obligations, Data Dictionary, Methodology, Change Log

JSON

Versioned, checksummed envelope for pipelines and AI

CSV

Flat table for spreadsheets, BI, and SQL

Official regulator source documents linked, not redistributed.

What It Solves.

Months of Manual Extraction

Reading three MAS instruments and re-keying every duty into a register is weeks of work. It arrives finished and cited.

Findings You Cannot Trace

Every obligation is quoted verbatim and page-anchored, so an examiner's question traces to the source in one step.

Gaps Hiding Between Instruments

Guidance and the two binding Notices sit in one register, so a duty in the Cyber Hygiene or Outsourcing Notice is not missed.

Interpretation Bottlenecks

Regulatory intelligence on every record explains what a duty means and how teams implement it, without waiting on one analyst.

Real Records

Two Records, Across the Instruments.

Real records pulled straight from this dataset. A binding Cyber Hygiene duty sits beside TRM guidance, decomposed the same way across all 380.

Get 20 Records in the Free Sample

MAS.CH.2024.Sec4.1.p3.OBL1

p.3
Cyber Security Requirements · Administrative AccountsMUSThigh priority

MAS Cyber Hygiene

Source TextVerbatim · Binding
A relevant entity must ensure that every administrative account in respect of any operating system, database, application, security appliance or network device, is secured to prevent any unauthorised access to or use of such account.
In Plain Language

Secure every administrative account against unauthorised access or use.

In the Documentp.3

The clauses around this duty, as written in the source

Notice FSM-N06 on Cyber Hygiene › 4 Cyber Security Requirements › Administrative Accounts › 4.1

4.1

Administrative Accounts: A relevant entity must ensure that every administrative account in respect of any operating system, database, application, security appliance or network device, is secured to prevent any unauthorised access to or use of such account.

4.2

Security Patches: (a) A relevant entity must ensure that security patches are applied to address vulnerabilities to every system, and apply such security patches within a timeframe that is commensurate with the risks posed by each vulnerability.

Parsed Duty
ActorA relevant entity
ActionEnsure that every administrative account is secured to prevent unauthorised access to or use of the account
ObjectAdministrative accounts on any operating system, database, application, security appliance or network device
Structured FieldsDeontic · obligation

Deontic

obligation

Type

Process

Strength

Mandatory

Frequency

Ongoing

Status

In Force

Sanction

supervisory

Marker

4.1

Amendment

New · First Edition

admin-accountsnetwork-security

MAS Notice FSM-N06 (Cyber Hygiene), paragraph 4.1, p. 3 (2024)

Consequence. Non-compliance with this Notice may attract MAS supervisory and enforcement action; a MAS notice imposes legally binding requirements on the relevant entities.

Source · Notice FSM-N06 on Cyber HygieneRegulator PDF ↗

MAS.TRM.2021.Sec7.2.1.p23.OBL1

p.23
IT Service Management · Configuration ManagementSHOULDmedium priority

MAS TRM

Source TextVerbatim · Guidance
The FI should implement a configuration management process to maintain accurate information of its hardware and software to have visibility and effective control of its IT systems.
In Plain Language

The FI should implement a configuration management process to maintain accurate information of its hardware and software in order to have visibility and effective control of its IT systems.

In the Documentp.23

The clauses around this duty, as written in the source

Technology Risk Management Guidelines › 7 IT Service Management › 7.2 Configuration Management › 7.2.1

7.2.1

The FI should implement a configuration management process to maintain accurate information of its hardware and software to have visibility and effective control of its IT systems.

7.2.2

The FI should review and verify the configuration information of its hardware and software on a regular basis to ensure it is accurate and up-to-date.

Parsed Duty
ActorFI
ActionImplement a configuration management process to maintain accurate hardware and software information
ObjectHardware and software configuration information
Structured FieldsDeontic · recommendation

Deontic

recommendation

Type

Process

Strength

Recommended

Frequency

Ongoing

Status

In Force

Sanction

supervisory

Marker

7.2.1

Amendment

New · First Edition

it-service-managementconfiguration-management

MAS TRM Guidelines, Section 7.2.1, p. 23 (2021)

Consequence. Non-adherence may attract MAS supervisory action; the TRM Guidelines set out the standards MAS expects financial institutions to meet.

Source · Technology Risk Management GuidelinesRegulator PDF ↗

Each card shows the key fields for readability. Every delivered record carries the complete five-layer schema.

The Evidence Chain
Pending MAS Approval

When the Examiner Asks, Show Them the Page.

A structured record is a claim. The evidence capture is the proof. It shows the source page with the duty highlighted, stamped with the obligation ID, document, page, capture time, and source URL. When an auditor asks where a requirement came from, you hand them the page.

Evidence capture for MAS.CH.2024.Sec4.1.p3.OBL1: the source page with the obligation highlighted and the verification footer
Cyber Hygiene · BindingMAS.CH.2024.Sec4.1.p3.OBL1Notice FSM-N06, paragraph 4.1, p. 3
Evidence capture for MAS.TRM.2021.Sec7.2.1.p23.OBL1: the source page with the obligation highlighted and the verification footer
TRM · GuidanceMAS.TRM.2021.Sec7.2.1.p23.OBL1TRM Guidelines, Section 7.2.1, p. 23

Shown here as an on-page preview of the evidence layer. MAS packages currently ship without the capture image files while MAS approval to redistribute reproductions of MAS documents is pending. Every record still carries its full citation and official source link, and captures join the packages the moment approval lands.

ProfytAI Regulatory Intelligence

The Rule, and What It Means.

Every obligation across all three instruments ships with generated regulatory intelligence. Here is a conditional termination stem from the binding Outsourcing Notice: the structure a raw quote cannot explain, decoded.

One Record From This Dataset

MUSTBindingMAS Outsourcing NoticeMAS.OUT.2023.Sec10.1.p12.OBL1
Section 10.1Page 12

Verbatim

If any of the circumstances specified in paragraph 10.3 has arisen, a bank in Singapore must –

ProfytAI Regulatory Intelligence

Requires a bank in Singapore, once any circumstance specified in paragraph 10.3 has arisen, to take the actions listed under paragraph 10.1.

Requirement Type

Requirement

Relationship

Stem of the paragraph 10.1 list in the termination section; the limbs differentiate the required response by which paragraph 10.3 circumstance has arisen, with sub-paragraph (a) addressing circumstances under paragraph 10.3(a) or 10.3(e), or both.

Why This Exists

It ensures that defined termination-relevant events in a material outsourcing relationship trigger prescribed responses rather than being handled ad hoc.

Implementation Considerations

Typically involves monitoring material arrangements against the defined trigger circumstances and a documented response playbook mapping each trigger category to the required actions.

Interpretation Note · The duty is conditional on a paragraph 10.3 circumstance actually arising, and the required action depends on which circumstance it is, so paragraph 10.3 must be read alongside this stem. 'Has arisen' points to events that have occurred, not anticipated ones.

Why It Matters on Every Record

From Raw Regulation to Operational Knowledge.

Interpretation Already Done

A plain-language read of what the regulator is actually requiring, on every record.

Traceable to the Source

Each explanation stays anchored to the citation and the verbatim clause it came from.

Ready to Operationalize

Structured for registers, control libraries, policy drafting, and AI grounding from day one.

On Every Record

summary
The plain-language read of the duty
obligation_kind
Requirement, prohibition, or permission
relationship_to_parent
Where the clause sits among its siblings
why_this_obligation_exists
The regulator's purpose behind it
implementation_considerations
How teams typically satisfy it
interpretation_notes
Scope, force, and how to read it

The intelligence is generated from the structured obligation and preserves traceability back to the citation and the supporting evidence. It accelerates understanding, and the byte-exact verbatim text remains the authority you cite.

Compare

Start Small, or Take the Whole Perimeter.

Every tier is the same structured data, cited the same way. The only question is how much of the Singapore technology-risk perimeter you need today.

MAS TRM Module
From $400
Obligations
One theme
Instruments
TRM only
TRM Themes
1 of 13
Regulatory Intelligence
Semantic Enrichment
Implementation Controls
Evidence Captures
Policy Statements
Official Sources
Linked
Formats
Excel · JSON · CSV
View MAS TRM Module
Cyber Hygiene Bundle
$3,900
Obligations
9 (Cyber Hygiene)
Instruments
Cyber Hygiene Notice (9)
TRM Themes
Regulatory Intelligence
Joins by obligation ID
Semantic Enrichment
Implementation Controls
12, NIST-mapped, with audit tests
Evidence Captures
Policy Statements
Official Sources
How-to booklet
Formats
Excel · JSON · CSV
View Cyber Hygiene Bundle
Complete MAS TRM
$6,500
Obligations
331 (all TRM)
Instruments
TRM only (331)
TRM Themes
All 13
Regulatory Intelligence
Semantic Enrichment
Implementation Controls
Evidence Captures
Policy Statements
Official Sources
Linked
Formats
Excel · JSON · CSV
View Complete MAS TRM
You Are HereSingapore Collection
$9,500
Obligations
380 (all three)
Instruments
TRM 331 + Cyber Hygiene 9 + Outsourcing 40
TRM Themes
All 13
Regulatory Intelligence
Semantic Enrichment
Implementation Controls
Evidence Captures
Pending MAS Approval
Policy Statements
Official Sources
All three, linked
Formats
Excel · JSON · CSV
AI Policy Statement Library
From $25,000
Obligations
380 (all three)
Instruments
TRM 331 + Cyber Hygiene 9 + Outsourcing 40
TRM Themes
All 13
Regulatory Intelligence
Semantic Enrichment
Implementation Controls
12, NIST-mapped, with audit tests
Evidence Captures
Pending MAS Approval
Policy Statements
100, across 44 domains, with the Word manual
Official Sources
All three, linked
Formats
Excel · JSON · CSV + Word
View AI Policy Statement Library

The Full Singapore Perimeter, in One Register.

380 obligations across three MAS instruments, cited, structured, and traceable to the official source on every one. Buy the license, or prove the depth with the free sample first.

SampleConsultationRegisterPlatformSubscription