Source Document

MAS TRM Guidelines

MAS.TRM.2021.Sec6.4.4.p21.OBL1

6 Software Application Development and Management > 6.4 Application Programming Interface Development > 6.4.4

Obligation Summary

The FI should establish security standards for designing and developing secure APIs.

SHOULDmedium priorityrecommendationprocessrequirement
Source TextVerbatimView Evidence
Security standards for designing and developing secure APIs should be established.

MAS TRM Guidelines, Section 6.4.4, p. 21 (2021) · Technology Risk Management Guidelines · p. 21

In the Documentp. 21

6.4.3 The FI should perform a risk assessment before allowing third parties to connect to its IT systems via APIs, and ensure the implementation for each API is commensurate with the sensitivity and business criticality of the data being exchanged, and the confidentiality and integrity requirements of the data.

6.4.4 Security standards for designing and developing secure APIs should be established. The standards should include the measures to protect the API keys or access tokens,<sup>10</sup> which are used to authorise access to APIs to exchange confidential data. A reasonable timeframe should be defined and enforced for access token expiry to reduce the risk of unauthorised access.

6.4.5 Strong encryption standards and key management controls should be adopted to secure transmission of sensitive data through APIs.

Highlighted Text Is This Obligation

What This Requires.

ProfytAI Regulatory Intelligence

Type: requirement

Security standards for designing and developing secure APIs should be established.

Relationship

First sentence of paragraph 6.4.4; the following sentences require the standards to include protection of API keys and access tokens and an enforced token expiry timeframe.

Why This Exists

A written standard makes API security repeatable across teams instead of dependent on individual developer judgment.

Implementation Considerations

An API security standard covering design and development requirements, referenced by development teams and checked during review and testing.

Interpretation Note · As TRM Guidelines guidance, SHOULD marks a MAS supervisory expectation rather than a binding notice requirement.

This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.

Evidence Capturep. 21

The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Captured source page for MAS.TRM.2021.Sec6.4.4.p21.OBL1, MAS TRM Guidelines, Section 6.4.4, p. 21 (2021)