- Data
- MAS
- Obligations
- MAS TRM Guidelines, Section 15.1.2, p. 53 (2021)
Source Document
MAS TRM Guidelines
MAS.TRM.2021.Sec15.1.2.p53.OBL1
15 IT Audit > 15.1 Audit Function > 15.1.2
Obligation Summary
The FI should identify a comprehensive set of auditable areas for technology risk so that an effective risk assessment can be performed during audit planning.
A comprehensive set of auditable areas for technology risk should be identified so that an effective risk assessment could be performed during audit planning.
MAS TRM Guidelines, Section 15.1.2, p. 53 (2021) · Technology Risk Management Guidelines · p. 53
15.1.1 Audit plays an important role to assess the effectiveness of the controls, risk management and governance process in the FI. The FI should ensure IT audit is performed to provide the board of directors and senior management an independent and objective opinion of the adequacy and effectiveness of the FI’s risk management, governance and internal controls relative to its existing and emerging technology risks.
15.1.2 A comprehensive set of auditable areas for technology risk should be identified so that an effective risk assessment could be performed during audit planning. Auditable areas should include all IT operations, functions and processes.
15.1.3 The frequency of IT audits should be commensurate with the criticality of and risk posed by the IT information asset, function or process.
What This Requires.
ProfytAI Regulatory Intelligence
Type: requirementA comprehensive set of auditable areas for technology risk should be identified so that an effective risk assessment can be performed during audit planning.
Relationship
First obligation extracted from paragraph 15.1.2; the paragraph's second sentence, captured as a separate obligation, specifies that these auditable areas should include all IT operations, functions and processes.
Why This Exists
An audit plan can only be risk-based if the full technology risk landscape is visible to the planners. Cataloguing the audit universe up front prevents higher-risk IT areas from escaping coverage simply because no one listed them.
Implementation Considerations
Typically involves building and maintaining a documented IT audit universe that is refreshed through a periodic risk assessment feeding the audit plan.
Interpretation Note · This clause concerns audit planning, not execution: identifying an area as auditable does not itself dictate how often it is audited, which paragraph 15.1.3 ties to criticality and risk. As TRM guidance, 'should' states an MAS expectation rather than a binding notice requirement.
This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.
The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.
