Source Document

MAS TRM

MAS.TRM.2021.Sec5.6.1.p17.OBL1

Technology Risk Management Guidelines > 5 IT Project Management and Security-by-Design > 5.6 System Design and Implementation > 5.6.1

Obligation Summary

During the design phase and before implementation, the FI reviews the proposed architecture and design of the IT system, including the IT controls to be built into it, against the defined requirements.

SHOULDrecommendationprocessassessment
Source TextVerbatimView Evidence
As part of the design phase, the FI should review the proposed architecture and design of the IT system, including the IT controls to be built into the system, to ensure they meet the defined requirements, before implementation.

MAS TRM, Section 5.6.1, p. 17 (2021) · Technology Risk Management Guidelines · p. 17

In the Documentp. 17

5.6 System Design and Implementation

5.6.1 As part of the design phase, the FI should review the proposed architecture and design of the IT system, including the IT controls to be built into the system, to ensure they meet the defined requirements, before implementation.

5.6.2 The FI should verify that system requirements are met by the current system design and implementation. Any changes to, or deviations from, the defined requirements should be endorsed by relevant stakeholders.

Highlighted Text Is This Obligation

What This Requires.

ProfytAI Regulatory Intelligence

Type: assessment

Relationship

Standalone sentence forming the whole of 5.6.1 and the opening provision of the System Design and Implementation section. 5.6.2 then extends the check from proposed design to the design and implementation as actually delivered.

Why This Exists

Design faults are cheap to fix on paper and expensive to fix in production. A review before build catches architecture and control gaps while they are still drawings.

Watchouts

The requirement to engage domain experts comes from 5.6.3, not from this paragraph. Read on its own, 5.6.1 says nothing about who the reviewer is.

Interpretation Note · The source uses "should", so this is a supervisory expectation. The timing words carry most of the weight. "As part of the design phase" and "before implementation" fix the review at a point, so a post-build assurance review does not answer this paragraph. Scope expressly includes the IT controls to be built into the system, so a functionality-only architecture review falls short. The benchmark is "the defined requirements", meaning the requirements set under section 5.5, which include performance, resilience and security. The paragraph is silent on who performs the review.

This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.

Duties and Evidence Checklist3 duties

What the duty requires in practice, each with the condition that satisfies it and the evidence an examiner would expect. Derived by ProfytAI, anchored to the verbatim text above.

  1. 1

    Carry out a design review of the proposed architecture and design of the IT system.

    Done When

    A design review record exists for the IT system, dated within the design phase and before the implementation start date, identifying the architecture and design artefacts reviewed.

    EvidenceDesign review record
  2. 2

    Confirm the design review covers the IT controls to be built into the system.

    Done When

    The design review record lists the IT controls that are to be built into the system and records a review outcome for each.

    EvidenceDesign review record listing the built-in IT controls
  3. 3

    Record the conclusion that the design meets the defined requirements.

    Done When

    The design review record states, for each defined requirement, whether the proposed architecture and design meet it, and no requirement is left without a conclusion.

    EvidenceDesign review record with requirement-by-requirement conclusions
Evidence Capturep. 17

The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Captured source page for MAS.TRM.2021.Sec5.6.1.p17.OBL1, MAS TRM, Section 5.6.1, p. 17 (2021)

Reproduced from MAS Notices and Guidelines with permission, retrieved from mas.gov.sg. Refer to the MAS website for the latest available version. Highlighting and the verification stamp were added by ProfytAI. The stamp verifies ProfytAI's extraction only and does not represent approval or endorsement by the Monetary Authority of Singapore.