- Data
- MAS
- Obligations
- MAS TRM, Section 3.4.3, p. 10 (2021)
Source Document
MAS TRM
MAS.TRM.2021.Sec3.4.3.p10.OBL1
Technology Risk Management Guidelines > 3 Technology Risk Governance and Oversight > 3.4 Management of Third Party Services > 3.4.3
Obligation Summary
The FI should satisfy itself on a continuing basis that any third party it uses applies a high standard of care and diligence in protecting data confidentiality and integrity and in maintaining system resilience.
On an ongoing basis, the FI should ensure the third party employs a high standard of care and diligence in protecting data confidentiality4 and integrity as well as ensuring system resilience.
MAS TRM, Section 3.4.3, p. 10 (2021) · Technology Risk Management Guidelines · p. 10
3.4.2 The FI should assess and manage its exposure to technology risks that may affect the confidentiality, integrity and availability of the IT systems and data at the third party before entering into a contractual agreement or partnership.
3.4.3 On an ongoing basis, the FI should ensure the third party employs a high standard of care and diligence in protecting data confidentiality4 and integrity as well as ensuring system resilience.
3.5 Competency and Background Review
What This Requires.
ProfytAI Regulatory Intelligence
Type: processRelationship
The provision is a single sentence, and this duty is the whole of it.
Why This Exists
Outsourcing moves the processing but not the accountability, and a third party's controls can decay after the deal is signed. The duty closes the gap between due diligence at selection and the actual state of protection during the life of the relationship.
Watchouts
The FI is not asked to perform the protection itself. It is asked to ensure the third party does, which is an assurance duty. Firms that only hold a signed contract clause and no ongoing evidence have addressed 3.4.2 rather than 3.4.3.
Interpretation Note · This is a guideline "should", so it is a supervisory expectation rather than a binding notice requirement. The load-bearing words are "on an ongoing basis", which distinguish this paragraph from 3.4.2, where the same subject matter is assessed before contracting. The standard imposed on the third party is qualitative, described as a high standard of care and diligence, and the text does not define what evidence discharges it. The footnoted definition limits data confidentiality to protecting sensitive or confidential data such as customer details from unauthorised access and disclosure, and the paragraph adds integrity and system resilience alongside it.
This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.
What the duty requires in practice, each with the condition that satisfies it and the evidence an examiner would expect. Derived by ProfytAI, anchored to the verbatim text above.
- 1
Operate ongoing oversight of the third party's protection of data and its system resilience.
Done When
Oversight records exist covering the period since the engagement began, each dated and stating what was examined for data confidentiality, data integrity and system resilience and the conclusion reached.
EvidenceThird party oversight record - 2
Follow up any shortfall in the third party's standard of care with corrective action.
Done When
Each shortfall recorded during oversight has a corresponding remediation action, a named owner and a closure date or a recorded reason for accepting it.
The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Reproduced from MAS Notices and Guidelines with permission, retrieved from mas.gov.sg. Refer to the MAS website for the latest available version. Highlighting and the verification stamp were added by ProfytAI. The stamp verifies ProfytAI's extraction only and does not represent approval or endorsement by the Monetary Authority of Singapore.