- Data
- MAS
- Obligations
- MAS TRM, Section 7.7.5, p. 26 (2021)
Source Document
MAS TRM
MAS.TRM.2021.Sec7.7.5.p26.OBL1
Technology Risk Management Guidelines > 7 IT Service Management > 7.7 Incident Management > 7.7.5
Obligation Summary
The FI should keep senior management regularly informed of the status of major incidents so that decisions to limit the impact of a crisis can be taken in time.
The FI should regularly apprise its senior management of the status of major incidents so that decisions to mitigate the impact of the crisis can be made in a timely manner, such as activation of IT disaster recovery.
MAS TRM, Section 7.7.5, p. 26 (2021) · Technology Risk Management Guidelines · p. 26
7.7.4 The FI should configure system events or alerts to provide an early indication of issues that may affect its IT systems’ performance and security. System events or alerts should be actively monitored so that prompt measures can be taken to address the issues early.
7.7.5 In some situations, a major incident may develop unfavourably into a crisis. The FI should regularly apprise its senior management of the status of major incidents so that decisions to mitigate the impact of the crisis can be made in a timely manner, such as activation of IT disaster recovery.
7.7.6 A communications plan that covers the process and procedures to apprise customers of impact on services, and to handle media or public queries should be maintained. The plan should also include identifying the spokespersons and subject matter experts to address the media or public queries as well as the communication channels to disseminate information.
What This Requires.
ProfytAI Regulatory Intelligence
Type: reportingRelationship
The second sentence of a two sentence provision. The first sentence supplies the rationale, which is that a major incident may develop unfavourably into a crisis, and this sentence carries the duty.
Why This Exists
Some decisions, including invoking IT disaster recovery, sit above the incident team. If senior management hears about a major incident late, the window for those decisions has often already closed.
Watchouts
The duty attaches to "major incidents", so the severity criteria inside the framework decide when it bites. Criteria drawn narrowly keep incidents below the reporting threshold, and that is the point most likely to be challenged.
Interpretation Note · This is a "should", so it is a supervisory expectation rather than a binding notice requirement. "Regularly" is not tied to any stated interval, so the cadence is left to the firm and would be judged against the purpose, which is timely decision making. The trigger is a "major incident", a term this provision does not define, so the firm's own severity classification carries the weight. Activation of IT disaster recovery is given as an example of the kind of decision in view, not as the only one.
This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.
What the duty requires in practice, each with the condition that satisfies it and the evidence an examiner would expect. Derived by ProfytAI, anchored to the verbatim text above.
- 1
Report the status of each major incident to senior management on a regular basis.
Done When
For each major incident, dated status reports to senior management exist and recur at intervals until the incident is closed.
EvidenceMajor incident status report to senior management - 2
Record the decisions senior management takes on the reported incidents, including any activation of IT disaster recovery.
Done When
For each major incident escalated, a record shows the decisions taken by senior management and the time they were taken.
EvidenceSenior management incident decision record
The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Reproduced from MAS Notices and Guidelines with permission, retrieved from mas.gov.sg. Refer to the MAS website for the latest available version. Highlighting and the verification stamp were added by ProfytAI. The stamp verifies ProfytAI's extraction only and does not represent approval or endorsement by the Monetary Authority of Singapore.