Source Document

MAS TRM Guidelines

MAS.TRM.2021.Sec15.1.2.p53.OBL2

15 IT Audit > 15.1 Audit Function > 15.1.2

Obligation Summary

Auditable areas for technology risk should include all IT operations, functions and processes.

SHOULDmedium priorityrecommendationprocessrequirement
Source TextVerbatimView Evidence
Auditable areas should include all IT operations, functions and processes.

MAS TRM Guidelines, Section 15.1.2, p. 53 (2021) · Technology Risk Management Guidelines · p. 53

In the Documentp. 53

15.1.1 Audit plays an important role to assess the effectiveness of the controls, risk management and governance process in the FI. The FI should ensure IT audit is performed to provide the board of directors and senior management an independent and objective opinion of the adequacy and effectiveness of the FI’s risk management, governance and internal controls relative to its existing and emerging technology risks.

15.1.2 A comprehensive set of auditable areas for technology risk should be identified so that an effective risk assessment could be performed during audit planning. Auditable areas should include all IT operations, functions and processes.

15.1.3 The frequency of IT audits should be commensurate with the criticality of and risk posed by the IT information asset, function or process.

Highlighted Text Is This Obligation

What This Requires.

ProfytAI Regulatory Intelligence

Type: requirement

The auditable areas identified for technology risk should include all IT operations, functions and processes.

Relationship

Second sentence of paragraph 15.1.2; it defines the breadth of the 'comprehensive set of auditable areas' that the paragraph's first sentence expects the FI to identify.

Why This Exists

It closes coverage gaps in the audit universe. Any IT operation, function or process left outside the auditable areas never has its risks assessed during audit planning.

Implementation Considerations

Usually done by reconciling the audit universe against the FI's inventories of IT systems, functions and processes and documenting the mapping so omissions are visible.

Interpretation Note · 'All IT operations, functions and processes' scopes what belongs in the audit universe; it does not mean every area is audited at the same frequency, since paragraph 15.1.3 links frequency to criticality and risk. As TRM guidance, 'should' states an MAS expectation rather than a binding notice requirement.

This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.

Evidence Capturep. 53

The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Captured source page for MAS.TRM.2021.Sec15.1.2.p53.OBL2, MAS TRM Guidelines, Section 15.1.2, p. 53 (2021)