- Data
- MAS
- Obligations
- MAS TRM, Section 14.2.11, p. 52 (2021)
Source Document
MAS TRM
MAS.TRM.2021.Sec14.2.11.p52.OBL2
Technology Risk Management Guidelines > 14 Online Financial Services > 14.2 Customer Authentication and Transaction Signing > 14.2.11
Obligation Summary
There has to be a working process for revoking and replacing authentication credentials and mechanisms once they have been compromised.
A process and procedure should also be implemented to revoke and replace authentication credentials and mechanisms that have been compromised.
MAS TRM, Section 14.2.11, p. 52 (2021) · Technology Risk Management Guidelines · p. 52
14.2.10 Where alternate controls and processes (e.g. maker-checker function) are implemented for corporate or institutional customers to authorise transactions, the FI should perform a security risk assessment of controls or processes to ensure they are commensurate with the risk of the activities that are being carried out.
14.2.11 To safeguard the confidentiality of authentication credentials, such as biometric templates and passwords, the FI should store these credentials in a form that is resistant to reverse engineering. A process and procedure should also be implemented to revoke and replace authentication credentials and mechanisms that have been compromised.
14.3 Fraud Monitoring
What This Requires.
ProfytAI Regulatory Intelligence
Type: processRelationship
The response half of 14.2.11. The preceding obligation protects credentials at rest; this one addresses the case where that protection has already failed.
Why This Exists
Detecting a credential compromise achieves nothing if the firm cannot act on it quickly. Without a rehearsed process, revocation becomes an improvised project during an incident, and the compromised credential stays valid for exactly as long as that takes.
Watchouts
'Revoke and replace' is often built for one customer at a time. The scenario that matters is bulk compromise, where a per-customer manual path is technically present and practically unusable.
Interpretation Note · Both a process and a procedure are named, so the intent is a defined route rather than a general capability. Scope covers mechanisms as well as credentials, which reaches the authentication method itself and not only individual customer secrets.
This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.
What the duty requires in practice, each with the condition that satisfies it and the evidence an examiner would expect. Derived by ProfytAI, anchored to the verbatim text above.
- 1
Write and approve a documented procedure for revoking and replacing compromised authentication credentials and mechanisms.
Done When
A dated and approved procedure document exists stating the steps for both revocation and replacement and naming who may invoke them.
EvidenceCredential revocation and replacement procedure - 2
Record each invocation of the procedure with the credential or mechanism affected and the dates of revocation and replacement.
Done When
A log exists in which each compromise event carries the credential or mechanism identifier, a revocation date and a replacement date, or an open status with a named owner.
EvidenceCredential compromise log
The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Reproduced from MAS Notices and Guidelines with permission, retrieved from mas.gov.sg. Refer to the MAS website for the latest available version. Highlighting and the verification stamp were added by ProfytAI. The stamp verifies ProfytAI's extraction only and does not represent approval or endorsement by the Monetary Authority of Singapore.