- Data
- MAS
- Obligations
- MAS TRM, Section 6.4.6, p. 21 (2021)
Source Document
MAS TRM
MAS.TRM.2021.Sec6.4.6.p21.OBL1
Technology Risk Management Guidelines > 6 Software Application Development and Management > 6.4 Application Programming Interface Development > 6.4.6
Obligation Summary
Robust security screening and testing of an API should be carried out between the FI and its third parties before the API is deployed into production.
A robust security screening and testing of the API should be performed between the FI and its third parties before it is deployed into production.
MAS TRM, Section 6.4.6, p. 21 (2021) · Technology Risk Management Guidelines · p. 21
6.4.5 Strong encryption standards and key management controls should be adopted to secure transmission of sensitive data through APIs.
6.4.6 A robust security screening and testing of the API should be performed between the FI and its third parties before it is deployed into production. The FI should log the access sessions by third parties, such as the identity of the party making the API connections, date and time, as well as the data being accessed.
6.4.7 Detective measures, such as technologies that provide real-time monitoring and alerting, should be instituted to provide visibility of the usage and performance of APIs, and detect suspicious activities. Robust measures should be established to promptly revoke the API keys or access token in the event of a breach.
What This Requires.
ProfytAI Regulatory Intelligence
Type: assessmentRelationship
This is the first of two sentences in 6.4.6, setting the pre-deployment gate, while the second sentence covers logging of live access.
Why This Exists
An API that behaves correctly in isolation can still fail at the join between two organisations. Testing the actual connection before it goes live catches misconfiguration and weak handling that neither side would find on its own.
Watchouts
The joint element is often lost. Testing the FI's side thoroughly while the third party self-attests to its own side does not match the wording.
Interpretation Note · A guideline "should". The words "between the FI and its third parties" make this a joint exercise rather than something the FI can complete alone in its own environment. Timing is explicit, so completion is a precondition of production deployment. "Robust" is not defined and the source names no test type, coverage level or tooling. The second sentence of the paragraph adds logging of live access, and 6.4.7 adds detective monitoring, so this pre-production gate is the front end of a control set that continues after go-live.
This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.
What the duty requires in practice, each with the condition that satisfies it and the evidence an examiner would expect. Derived by ProfytAI, anchored to the verbatim text above.
- 1
Complete security screening and testing of each API with the third party before production deployment.
Done When
For each API in production, a test record exists naming the third party involved, the screening and tests performed and the date, which precedes the production deployment date.
EvidenceAPI security screening and test report
The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Reproduced from MAS Notices and Guidelines with permission, retrieved from mas.gov.sg. Refer to the MAS website for the latest available version. Highlighting and the verification stamp were added by ProfytAI. The stamp verifies ProfytAI's extraction only and does not represent approval or endorsement by the Monetary Authority of Singapore.