Source Document

MAS TRM

MAS.TRM.2021.Sec3.4.3.p10.OBL1

Technology Risk Management Guidelines > 3 Technology Risk Governance and Oversight > 3.4 Management of Third Party Services > 3.4.3

Obligation Summary

The FI should satisfy itself on a continuing basis that any third party it uses applies a high standard of care and diligence in protecting data confidentiality and integrity and in maintaining system resilience.

SHOULDrecommendationprocessprocess
Source TextVerbatimView Evidence
On an ongoing basis, the FI should ensure the third party employs a high standard of care and diligence in protecting data confidentiality4 and integrity as well as ensuring system resilience.

MAS TRM, Section 3.4.3, p. 10 (2021) · Technology Risk Management Guidelines · p. 10

In the Documentp. 10

3.4.2 The FI should assess and manage its exposure to technology risks that may affect the confidentiality, integrity and availability of the IT systems and data at the third party before entering into a contractual agreement or partnership.

3.4.3 On an ongoing basis, the FI should ensure the third party employs a high standard of care and diligence in protecting data confidentiality4 and integrity as well as ensuring system resilience.

3.5 Competency and Background Review

Highlighted Text Is This Obligation

What This Requires.

ProfytAI Regulatory Intelligence

Type: process

Relationship

The provision is a single sentence, and this duty is the whole of it.

Why This Exists

Outsourcing moves the processing but not the accountability, and a third party's controls can decay after the deal is signed. The duty closes the gap between due diligence at selection and the actual state of protection during the life of the relationship.

Watchouts

The FI is not asked to perform the protection itself. It is asked to ensure the third party does, which is an assurance duty. Firms that only hold a signed contract clause and no ongoing evidence have addressed 3.4.2 rather than 3.4.3.

Interpretation Note · This is a guideline "should", so it is a supervisory expectation rather than a binding notice requirement. The load-bearing words are "on an ongoing basis", which distinguish this paragraph from 3.4.2, where the same subject matter is assessed before contracting. The standard imposed on the third party is qualitative, described as a high standard of care and diligence, and the text does not define what evidence discharges it. The footnoted definition limits data confidentiality to protecting sensitive or confidential data such as customer details from unauthorised access and disclosure, and the paragraph adds integrity and system resilience alongside it.

This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.

Duties and Evidence Checklist2 duties

What the duty requires in practice, each with the condition that satisfies it and the evidence an examiner would expect. Derived by ProfytAI, anchored to the verbatim text above.

  1. 1

    Operate ongoing oversight of the third party's protection of data and its system resilience.

    Done When

    Oversight records exist covering the period since the engagement began, each dated and stating what was examined for data confidentiality, data integrity and system resilience and the conclusion reached.

    EvidenceThird party oversight record
  2. 2

    Follow up any shortfall in the third party's standard of care with corrective action.

    Done When

    Each shortfall recorded during oversight has a corresponding remediation action, a named owner and a closure date or a recorded reason for accepting it.

Evidence Capturep. 10

The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Captured source page for MAS.TRM.2021.Sec3.4.3.p10.OBL1, MAS TRM, Section 3.4.3, p. 10 (2021)

Reproduced from MAS Notices and Guidelines with permission, retrieved from mas.gov.sg. Refer to the MAS website for the latest available version. Highlighting and the verification stamp were added by ProfytAI. The stamp verifies ProfytAI's extraction only and does not represent approval or endorsement by the Monetary Authority of Singapore.