- Data
- MAS
- Obligations
- MAS TRM, Section 3.1.1, p. 7 (2021)
Source Document
MAS TRM
MAS.TRM.2021.Sec3.1.1.p7.OBL1
Technology Risk Management Guidelines > 3 Technology Risk Governance and Oversight > 3.1 Role of the Board of Directors and Senior Management > 3.1.1
Obligation Summary
The board of directors and senior management should ensure that effective internal controls and risk management practices are implemented to achieve security, reliability and resilience of the institution's IT operating environment.
It is vital that the FI’s board of directors and senior management ensure effective internal controls and risk management practices are implemented to achieve security, reliability and resilience of its IT operating environment.
MAS TRM, Section 3.1.1, p. 7 (2021) · Technology Risk Management Guidelines · p. 7
3.1 Role of the Board of Directors and Senior Management
3.1.1 Technology is a key business enabler in the financial sector and FIs rely on technology to deliver financial services. It is vital that the FI’s board of directors and senior management ensure effective internal controls and risk management practices are implemented to achieve security, reliability and resilience of its IT operating environment.
3.1.2 Both the board of directors and senior management should have members with the knowledge to understand and manage technology risks, which include risks posed by cyber threats.
What This Requires.
ProfytAI Regulatory Intelligence
Type: governanceRelationship
It is the second and operative sentence of paragraph 3.1.1, following a scene-setting sentence about reliance on technology, and it opens the block of board and senior management duties in 3.1.
Why This Exists
The provision opens by noting that financial institutions rely on technology to deliver financial services. If the IT operating environment fails, service delivery fails, so accountability for the control environment is placed at the level that can direct resources and hold executives to account.
Watchouts
Reliability sits alongside security in the objective list. A control programme built purely around cyber and information security would leave the reliability limb, which covers things like availability and stable operation, only partly addressed.
Interpretation Note · This is the opening governance expectation in section 3 and uses "It is vital that", which reads as a strong expectation rather than a binding requirement. The verb is "ensure ... are implemented", so the duty is oversight and assurance rather than hands-on control building. Two things must be in place, internal controls and risk management practices, and both are qualified by "effective", which points at outcome rather than existence. Three named objectives govern what effective means here. Security, reliability and resilience. The object is the IT operating environment as a whole. The duty rests on the board and senior management, so it is not discharged by delegation to the IT function alone.
This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.
What the duty requires in practice, each with the condition that satisfies it and the evidence an examiner would expect. Derived by ProfytAI, anchored to the verbatim text above.
- 1
Have the board of directors and senior management satisfy themselves that the internal controls and risk management practices over the IT operating environment are implemented and effective.
Done When
A dated board or senior management record states which controls and risk management practices were reviewed, the evidence of effectiveness considered, and the conclusion reached.
EvidenceBoard or management committee minutes - 2
Show the controls in place address security, reliability and resilience of the IT operating environment.
Done When
A mapping exists linking each of security, reliability and resilience to the controls and practices relied on, and names any of the three for which no control is mapped.
EvidenceControl mapping
The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Reproduced from MAS Notices and Guidelines with permission, retrieved from mas.gov.sg. Refer to the MAS website for the latest available version. Highlighting and the verification stamp were added by ProfytAI. The stamp verifies ProfytAI's extraction only and does not represent approval or endorsement by the Monetary Authority of Singapore.