- Data
- MAS
- Obligations
- MAS TRM, Section 14.1.5, p. 49 (2021)
Source Document
MAS TRM
MAS.TRM.2021.Sec14.1.5.p49.OBL1
Technology Risk Management Guidelines > 14 Online Financial Services > 14.1 Security of Online Financial Services > 14.1.5
Obligation Summary
The FI should distribute mobile applications and software to customers only through official mobile application stores or other secure delivery channels.
The FI should only make available mobile applications or software to customers through official mobile application stores, or other secure delivery channels.
MAS TRM, Section 14.1.5, p. 49 (2021) · Technology Risk Management Guidelines · p. 49
14.1.4 An FI offering online financial services access via a mobile device should be aware of the risks unique to mobile applications. Specific measures aimed at addressing the risks of mobile applications should be put in place. Refer to Annex C for guidance on Mobile Application Security.
14.1.5 The FI should only make available mobile applications or software to customers through official mobile application stores, or other secure delivery channels.
14.1.6 The FI should actively monitor for phishing campaigns targeting the FI and its customers. Immediate action should be taken to report phishing attempts to service providers to facilitate the removal of malicious content. The FI should alert its customers of such campaigns and advise them of security measures to adopt to protect against phishing.
What This Requires.
ProfytAI Regulatory Intelligence
Type: controlRelationship
Paragraph 14.1.5 is a single sentence forming the whole provision. It follows the mobile risk paragraph at 14.1.4 and precedes the phishing paragraph at 14.1.6.
Why This Exists
Software reaching customers through unmanaged channels can be tampered with or impersonated before it is installed. Restricting distribution to controlled channels gives customers a reliable way to tell the genuine application from a fake.
Watchouts
Direct download links from the FI's own site are not automatically covered by the "other secure delivery channels" wording. The channel has to actually be secure, which puts the burden on the FI to show integrity and authenticity of what is delivered.
Interpretation Note · This is a guideline "should", so it is a supervisory expectation rather than a binding notice requirement. "Only" makes this a restriction rather than a preference, so distribution outside the permitted routes is what is being ruled out. The permitted routes are official mobile application stores or other secure delivery channels, which leaves room for the FI to use an alternative channel provided it is secure. The scope covers mobile applications or software made available to customers, so it is not limited to store-published applications. The source does not define which stores count as official or what makes an alternative channel secure.
This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.
What the duty requires in practice, each with the condition that satisfies it and the evidence an examiner would expect. Derived by ProfytAI, anchored to the verbatim text above.
- 1
List every channel through which the FI's customer mobile applications and software are distributed.
Done When
A distribution channel list exists naming each channel in use and marking each as an official application store or as another channel.
EvidenceMobile application distribution channel list - 2
For each channel that is not an official application store, record the basis on which it is treated as secure.
Done When
Each non-store channel on the list carries a dated assessment stating the controls that make it secure and naming who approved that conclusion.
EvidenceDelivery channel security assessment
The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Reproduced from MAS Notices and Guidelines with permission, retrieved from mas.gov.sg. Refer to the MAS website for the latest available version. Highlighting and the verification stamp were added by ProfytAI. The stamp verifies ProfytAI's extraction only and does not represent approval or endorsement by the Monetary Authority of Singapore.