Source Document

MAS TRM

MAS.TRM.2021.Sec4.3.1.p13.OBL2

Technology Risk Management Guidelines > 4 Technology Risk Management Framework > 4.3 Risk Assessment > 4.3.1

Obligation Summary

In assessing technology risks the FI should take financial, operational, legal, reputational and regulatory factors into consideration.

SHOULDrecommendationprocessassessment
Source TextVerbatimView Evidence
The FI should take into consideration financial, operational, legal, reputational and regulatory factors in assessing technology risks.

MAS TRM, Section 4.3.1, p. 13 (2021) · Technology Risk Management Guidelines · p. 13

In the Documentp. 13

4.3 Risk Assessment

4.3.1 The FI should perform an analysis of the potential impact and consequences of the threats and vulnerabilities on the overall business and operations. The FI should take into consideration financial, operational, legal, reputational and regulatory factors in assessing technology risks.

4.3.2 To facilitate the prioritisation of technology risks, a set of criteria measuring and determining the likelihood and impact of the risk scenarios should be established.

Highlighted Text Is This Obligation

What This Requires.

ProfytAI Regulatory Intelligence

Type: assessment

Relationship

Second sentence of 4.3.1, qualifying the analysis required by the first sentence rather than creating a separate assessment.

Why This Exists

Assessments that measure only outage duration or direct loss miss consequences that often bite harder, including regulatory exposure and damage to customer trust.

Watchouts

Legal and regulatory are listed as separate factors. Collapsing them into one category loses a distinction the text draws.

Interpretation Note · Five factor categories are named and all five apply to the assessment described in the first sentence of 4.3.1. They are considerations to be weighed, not scoring dimensions the text mandates, and no weighting or scale is set. The list carries no qualifier such as "where relevant", so a firm that leaves a category out should be able to explain why. This is a "should", which makes it a supervisory expectation rather than a binding notice requirement.

This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.

Duties and Evidence Checklist1 duty

What the duty requires in practice, each with the condition that satisfies it and the evidence an examiner would expect. Derived by ProfytAI, anchored to the verbatim text above.

  1. 1

    Evidence each factor this provision names in the technology risk assessment.

    Done When

    For each risk assessed, the assessment record shows a documented consideration against each of the factors named in the provision, with none left blank or unexplained.

    EvidenceTechnology risk assessment
Evidence Capturep. 13

The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Captured source page for MAS.TRM.2021.Sec4.3.1.p13.OBL2, MAS TRM, Section 4.3.1, p. 13 (2021)

Reproduced from MAS Notices and Guidelines with permission, retrieved from mas.gov.sg. Refer to the MAS website for the latest available version. Highlighting and the verification stamp were added by ProfytAI. The stamp verifies ProfytAI's extraction only and does not represent approval or endorsement by the Monetary Authority of Singapore.