- Data
- MAS
- Obligations
- MAS TRM, Section 11.3.4, p. 40 (2021)
Source Document
MAS TRM
MAS.TRM.2021.Sec11.3.4.p40.OBL1
Technology Risk Management Guidelines > 11 Data and Infrastructure Security > 11.3 System Security > 11.3.4
Obligation Summary
The FI should ensure anti-malware signatures stay up to date and that systems are regularly scanned for malicious files or anomalous activities.
The FI should ensure that anti-malware signatures are kept up-to-date and the systems are regularly scanned for malicious files or anomalous activities.
MAS TRM, Section 11.3.4, p. 40 (2021) · Technology Risk Management Guidelines · p. 40
11.3.3 Endpoint protection, which includes but is not limited to behavioural-based and signature-based solutions, should be implemented to protect the FI from malware infection and address common delivery channels of malware, such as malicious links, websites, email attachments or infected removable storage media.
11.3.4 The FI should ensure that anti-malware signatures are kept up-to-date and the systems are regularly scanned for malicious files or anomalous activities.
11.3.5 To facilitate early detection and prompt remediation of suspicious or malicious systems activities, the FI should implement detection and response mechanisms to perform scanning of indicators of compromise (IOCs) in a timely manner, and proactively monitor systems’, including endpoint systems’, processes for anomalies and suspicious activities.
What This Requires.
ProfytAI Regulatory Intelligence
Type: controlRelationship
This is the whole of paragraph 11.3.4, a single standalone sentence carrying two coordinated duties. It follows directly from the endpoint protection duty in 11.3.3.
Why This Exists
Signature-based detection is only as good as its most recent update, and a system that has silently stopped updating gives false assurance. Regular scanning finds material that slipped past detection at the moment of arrival.
Watchouts
"Ensure" is doing real work here. Evidence that auto-update is switched on does not answer the question of whether signatures are actually current on every system.
Interpretation Note · This is a guideline "should", so it is a supervisory expectation rather than a binding notice requirement. The verb is "ensure", which frames both limbs as outcomes the FI is answerable for rather than mechanisms it merely enables. That distinction matters for signature currency, because configuring automatic updates is not the same as knowing every system is current. Two objects of scanning are named, being malicious files and anomalous activities. "Regularly" and "up-to-date" are not quantified, and no scan type, scope or interval is prescribed.
This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.
What the duty requires in practice, each with the condition that satisfies it and the evidence an examiner would expect. Derived by ProfytAI, anchored to the verbatim text above.
- 1
Confirm the currency of anti-malware signatures across systems.
Done When
A report shows, for each protected system, the signature version in use and the date it was issued, so out of date systems are visible.
EvidenceAnti-malware signature status report - 2
Run the regular scans and retain the results.
Done When
A dated scan record exists for each in-scope system showing the scan completed and listing any malicious files or anomalous activities found, and the records recur at the interval the FI has set as regular.
The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Reproduced from MAS Notices and Guidelines with permission, retrieved from mas.gov.sg. Refer to the MAS website for the latest available version. Highlighting and the verification stamp were added by ProfytAI. The stamp verifies ProfytAI's extraction only and does not represent approval or endorsement by the Monetary Authority of Singapore.