Source Document

MAS TRM Guidelines

MAS.TRM.2021.Sec15.1.2.p53.OBL1

15 IT Audit > 15.1 Audit Function > 15.1.2

Obligation Summary

The FI should identify a comprehensive set of auditable areas for technology risk so that an effective risk assessment can be performed during audit planning.

SHOULDmedium priorityrecommendationprocessrequirement
Source TextVerbatimView Evidence
A comprehensive set of auditable areas for technology risk should be identified so that an effective risk assessment could be performed during audit planning.

MAS TRM Guidelines, Section 15.1.2, p. 53 (2021) · Technology Risk Management Guidelines · p. 53

In the Documentp. 53

15.1.1 Audit plays an important role to assess the effectiveness of the controls, risk management and governance process in the FI. The FI should ensure IT audit is performed to provide the board of directors and senior management an independent and objective opinion of the adequacy and effectiveness of the FI’s risk management, governance and internal controls relative to its existing and emerging technology risks.

15.1.2 A comprehensive set of auditable areas for technology risk should be identified so that an effective risk assessment could be performed during audit planning. Auditable areas should include all IT operations, functions and processes.

15.1.3 The frequency of IT audits should be commensurate with the criticality of and risk posed by the IT information asset, function or process.

Highlighted Text Is This Obligation

What This Requires.

ProfytAI Regulatory Intelligence

Type: requirement

A comprehensive set of auditable areas for technology risk should be identified so that an effective risk assessment can be performed during audit planning.

Relationship

First obligation extracted from paragraph 15.1.2; the paragraph's second sentence, captured as a separate obligation, specifies that these auditable areas should include all IT operations, functions and processes.

Why This Exists

An audit plan can only be risk-based if the full technology risk landscape is visible to the planners. Cataloguing the audit universe up front prevents higher-risk IT areas from escaping coverage simply because no one listed them.

Implementation Considerations

Typically involves building and maintaining a documented IT audit universe that is refreshed through a periodic risk assessment feeding the audit plan.

Interpretation Note · This clause concerns audit planning, not execution: identifying an area as auditable does not itself dictate how often it is audited, which paragraph 15.1.3 ties to criticality and risk. As TRM guidance, 'should' states an MAS expectation rather than a binding notice requirement.

This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.

Evidence Capturep. 53

The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Captured source page for MAS.TRM.2021.Sec15.1.2.p53.OBL1, MAS TRM Guidelines, Section 15.1.2, p. 53 (2021)