Source Document

MAS TRM

MAS.TRM.2021.Sec8.5.2.p30.OBL1

Technology Risk Management Guidelines > 8 IT Resilience > 8.5 Data Centre Resilience > 8.5.2

Obligation Summary

The FI should provide adequate redundancy in the data centre's power, network connectivity, cooling, electrical and mechanical systems so that no single point of failure remains.

SHOULDrecommendationprocesscontrol
Source TextVerbatimView Evidence
The FI should ensure adequate redundancy for the power, network connectivity, and cooling, electrical and mechanical systems of the DC to eliminate any single point of failure.

MAS TRM, Section 8.5.2, p. 30 (2021) · Technology Risk Management Guidelines · p. 30

In the Documentp. 30

8.5.1 The FI should conduct a Threat and Vulnerability Risk Assessment (TVRA) for its data centres (DCs) to identify potential vulnerabilities and weaknesses, and the protection that should be established to safeguard the DCs against physical and environmental threats.14 In addition, the TVRA should consider the political and economic climate of the country in which the DCs are located. The TVRA should be reviewed whenever there is a significant change in the threat landscape or when there is a material change in the DC’s environment.

8.5.2 The FI should ensure adequate redundancy for the power, network connectivity, and cooling, electrical and mechanical systems of the DC to eliminate any single point of failure. Consideration should be given to the following: diversification of data communications and network paths; deployment of power equipment, such as uninterruptable power sources, backup diesel generators with fuel tanks; and implementation of redundant cooling equipment (e.g. cooling towers, chilled water supply and computer room air conditioning units) to control the temperature and humidity levels in the DC and prevent fluctuations potentially harmful to systems.

8.5.3 As part of the DC’s environmental controls, the FI should implement fire detection and suppression devices or systems, such as smoke or heat detectors, inert gas suppression systems, and wet or dry sprinkler systems.

Highlighted Text Is This Obligation

What This Requires.

ProfytAI Regulatory Intelligence

Type: control

Relationship

This is the governing sentence of 8.5.2, with the second sentence listing specific measures to consider when meeting it.

Why This Exists

Most data centre outages come from facility services rather than from IT equipment. A single unduplicated feed, chiller, or network path can take down every system in the building at once, regardless of how resilient the applications are.

Watchouts

Duplicated components are not the same as no single point of failure. Two generators fed by one fuel line, or two network circuits sharing one physical path into the building, still fail together.

Interpretation Note · This is a guideline "should", so it is a supervisory expectation rather than a binding notice requirement. "Adequate" is measured against the stated outcome, which is elimination of any single point of failure in the named systems. That is the test, and it is stricter than a general instruction to have spare capacity. The named scope is power, network connectivity, and the cooling, electrical and mechanical systems, so it is facility infrastructure rather than application architecture. The text sets no tier rating, capacity figure, or standard.

This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.

Duties and Evidence Checklist1 duty

What the duty requires in practice, each with the condition that satisfies it and the evidence an examiner would expect. Derived by ProfytAI, anchored to the verbatim text above.

  1. 1

    Identify any single point of failure across the data centre's power, network, cooling, electrical and mechanical systems.

    Done When

    A documented analysis exists per data centre covering each of these systems and stating, for each, the redundancy in place and whether a single point of failure remains.

Evidence Capturep. 30

The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Captured source page for MAS.TRM.2021.Sec8.5.2.p30.OBL1, MAS TRM, Section 8.5.2, p. 30 (2021)

Reproduced from MAS Notices and Guidelines with permission, retrieved from mas.gov.sg. Refer to the MAS website for the latest available version. Highlighting and the verification stamp were added by ProfytAI. The stamp verifies ProfytAI's extraction only and does not represent approval or endorsement by the Monetary Authority of Singapore.