Source Document

MAS TRM

MAS.TRM.2021.Sec6.4.6.p21.OBL1

Technology Risk Management Guidelines > 6 Software Application Development and Management > 6.4 Application Programming Interface Development > 6.4.6

Obligation Summary

Robust security screening and testing of an API should be carried out between the FI and its third parties before the API is deployed into production.

SHOULDrecommendationprocessassessment
Source TextVerbatimView Evidence
A robust security screening and testing of the API should be performed between the FI and its third parties before it is deployed into production.

MAS TRM, Section 6.4.6, p. 21 (2021) · Technology Risk Management Guidelines · p. 21

In the Documentp. 21

6.4.5 Strong encryption standards and key management controls should be adopted to secure transmission of sensitive data through APIs.

6.4.6 A robust security screening and testing of the API should be performed between the FI and its third parties before it is deployed into production. The FI should log the access sessions by third parties, such as the identity of the party making the API connections, date and time, as well as the data being accessed.

6.4.7 Detective measures, such as technologies that provide real-time monitoring and alerting, should be instituted to provide visibility of the usage and performance of APIs, and detect suspicious activities. Robust measures should be established to promptly revoke the API keys or access token in the event of a breach.

Highlighted Text Is This Obligation

What This Requires.

ProfytAI Regulatory Intelligence

Type: assessment

Relationship

This is the first of two sentences in 6.4.6, setting the pre-deployment gate, while the second sentence covers logging of live access.

Why This Exists

An API that behaves correctly in isolation can still fail at the join between two organisations. Testing the actual connection before it goes live catches misconfiguration and weak handling that neither side would find on its own.

Watchouts

The joint element is often lost. Testing the FI's side thoroughly while the third party self-attests to its own side does not match the wording.

Interpretation Note · A guideline "should". The words "between the FI and its third parties" make this a joint exercise rather than something the FI can complete alone in its own environment. Timing is explicit, so completion is a precondition of production deployment. "Robust" is not defined and the source names no test type, coverage level or tooling. The second sentence of the paragraph adds logging of live access, and 6.4.7 adds detective monitoring, so this pre-production gate is the front end of a control set that continues after go-live.

This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.

Duties and Evidence Checklist1 duty

What the duty requires in practice, each with the condition that satisfies it and the evidence an examiner would expect. Derived by ProfytAI, anchored to the verbatim text above.

  1. 1

    Complete security screening and testing of each API with the third party before production deployment.

    Done When

    For each API in production, a test record exists naming the third party involved, the screening and tests performed and the date, which precedes the production deployment date.

    EvidenceAPI security screening and test report
Evidence Capturep. 21

The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Captured source page for MAS.TRM.2021.Sec6.4.6.p21.OBL1, MAS TRM, Section 6.4.6, p. 21 (2021)

Reproduced from MAS Notices and Guidelines with permission, retrieved from mas.gov.sg. Refer to the MAS website for the latest available version. Highlighting and the verification stamp were added by ProfytAI. The stamp verifies ProfytAI's extraction only and does not represent approval or endorsement by the Monetary Authority of Singapore.