- Data
- MAS
- Obligations
- MAS TRM, Section 8.2.3, p. 29 (2021)
Source Document
MAS TRM
MAS.TRM.2021.Sec8.2.3.p29.OBL1
Technology Risk Management Guidelines > 8 IT Resilience > 8.2 System Recoverability > 8.2.3
Obligation Summary
During recovery the FI should follow its established disaster recovery plan, and that plan should already have been tested and approved by management.
During the recovery process, the FI should follow the established disaster recovery plan that has been tested and approved by management.
MAS TRM, Section 8.2.3, p. 29 (2021) · Technology Risk Management Guidelines · p. 29
8.2.2 The FI’s disaster recovery plan should include procedures to recover systems from various disaster scenarios, as well as the roles and responsibilities of relevant personnel in the recovery process. The disaster recovery plan should be reviewed at least annually and updated when there are material changes to business operations, information assets or environmental factors.
8.2.3 During the recovery process, the FI should follow the established disaster recovery plan that has been tested and approved by management. The FI should avoid deviating from the plan as untested recovery measures could exacerbate the incident and prolong the recovery process. In exceptional circumstances where untested recovery measures need to be used, the FI should perform a risk assessment and ensure adequate controls are in place, as well as obtain approval from senior management.
8.2.4 The FI should endeavour to operate from its recovery, secondary or alternate site periodically so as to have the assurance that its infrastructure and systems at these sites are able to support business needs for an extended period of time when production systems failover from the primary or production site.
What This Requires.
ProfytAI Regulatory Intelligence
Type: controlRelationship
Opening sentence of 8.2.3. It states the governing rule, and the two sentences that follow deal with deviation and the exception route.
Why This Exists
An incident is the worst moment to discover that a recovery route does not work. Prior testing and management approval mean the steps executed under pressure have been proven and owned in advance.
Watchouts
Testing and approval have to precede the incident. A plan revised since the last test is, on this wording, not the tested plan.
Interpretation Note · Two conditions attach to the plan being followed. It has been tested, and it has been approved by management. Note that this approval sits with "management", a lower bar than the "senior management" approval the same paragraph attaches to the exception route. Guideline "should", so a supervisory expectation rather than a binding notice requirement.
This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.
What the duty requires in practice, each with the condition that satisfies it and the evidence an examiner would expect. Derived by ProfytAI, anchored to the verbatim text above.
- 1
Show that the recovery actions taken during an event matched the established plan.
Done When
For each recovery event, a record maps the actions performed to the corresponding steps of the approved plan and identifies any step not followed.
EvidenceIncident recovery record - 2
Confirm the plan version in use has been tested and carries management approval.
Done When
The current plan version carries a dated management approval and a test record that post-dates that version.
EvidenceApproved and tested disaster recovery plan
The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Reproduced from MAS Notices and Guidelines with permission, retrieved from mas.gov.sg. Refer to the MAS website for the latest available version. Highlighting and the verification stamp were added by ProfytAI. The stamp verifies ProfytAI's extraction only and does not represent approval or endorsement by the Monetary Authority of Singapore.