- Data
- MAS
- Obligations
- MAS TRM, Section 5.1.4, p. 15 (2021)
Source Document
MAS TRM
MAS.TRM.2021.Sec5.1.4.p15.OBL1
Technology Risk Management Guidelines > 5 IT Project Management and Security-by-Design > 5.1 Project Management Framework > 5.1.4
Obligation Summary
A risk management process should be established to identify, assess, treat and monitor project risks throughout the IT project life cycle.
As project risks can adversely impact the IT project delivery timeline, budget and quality of the project deliverables, a risk management process should be established to identify, assess, treat and monitor the attendant risks throughout the project life cycle.
MAS TRM, Section 5.1.4, p. 15 (2021) · Technology Risk Management Guidelines · p. 15
5.1.3 Key documentation in the IT project life cycle, including the feasibility analysis, cost-benefit analysis, business case analysis, project plan, as well as the implementation plan, should be maintained and approved by the relevant business and IT management.
5.1.4 As project risks can adversely impact the IT project delivery timeline, budget and quality of the project deliverables, a risk management process should be established to identify, assess, treat and monitor the attendant risks throughout the project life cycle.
5.2 Project Steering Committee
What This Requires.
ProfytAI Regulatory Intelligence
Type: processRelationship
It is the whole of paragraph 5.1.4 and closes section 5.1, adding a risk dimension on top of the framework, plan and documentation duties in 5.1.1 to 5.1.3.
Why This Exists
The provision states the reason itself. Project risks can damage the delivery timeline, the budget and the quality of what is delivered. Poor quality deliverables are the route by which project risk becomes production and operational risk.
Watchouts
Project risk here is broader than technology risk. Timeline and budget risks fall squarely within the process, so a log restricted to security and technical issues does not cover what the sentence describes.
Interpretation Note · A guideline "should", so a supervisory expectation. Four activities are named and the sequence is deliberate. Identify, assess, treat, then monitor. "Throughout the project life cycle" is the binding qualifier on monitoring, which rules out a one-off risk assessment at initiation. The opening clause about timeline, budget and deliverable quality is stated as rationale, and it also indicates the impact dimensions the process is expected to address. The paragraph does not prescribe a risk methodology, scoring scale or tool, and it does not set a project size threshold.
This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.
What the duty requires in practice, each with the condition that satisfies it and the evidence an examiner would expect. Derived by ProfytAI, anchored to the verbatim text above.
- 1
Document the project risk management process.
Done When
A written process exists covering identification, assessment, treatment and monitoring of project risks, and each of the four steps has a defined output.
EvidenceProject risk management process - 2
Maintain a project risk record for each project across its life cycle.
Done When
For each project sampled a risk record exists with dated entries falling in more than one project phase, each showing the assessment, the treatment applied and the current status.
EvidenceProject risk register
The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Reproduced from MAS Notices and Guidelines with permission, retrieved from mas.gov.sg. Refer to the MAS website for the latest available version. Highlighting and the verification stamp were added by ProfytAI. The stamp verifies ProfytAI's extraction only and does not represent approval or endorsement by the Monetary Authority of Singapore.