- Data
- MAS
- Obligations
- MAS TRM Guidelines, Section 9.1.2, p. 33 (2021)
Source Document
MAS TRM Guidelines
MAS.TRM.2021.Sec9.1.2.p33.OBL1
9 Access Control > 9.1 User Access Management > 9.1.2
Obligation Summary
The FI should establish a user access management process to provision, change and revoke access rights to information assets.
The FI should establish a user access management process<sup>19</sup> to provision, change and revoke access rights to information assets.
MAS TRM Guidelines, Section 9.1.2, p. 33 (2021) · Technology Risk Management Guidelines · p. 33
9.1.1 The principles of ‘never alone’,<sup>15</sup> ‘segregation of duties’,<sup>16</sup> and ‘least privilege’<sup>17</sup> should be applied when granting staff access to information assets so that no one person has access to perform sensitive system functions.<sup>18</sup> Access rights and system privileges should be granted according to the roles and responsibilities of the staff, contractors and service providers.
9.1.2 The FI should establish a user access management process<sup>19</sup> to provision, change and revoke access rights to information assets. Access rights should be authorised and approved by appropriate parties, such as the information asset owner.
9.1.3 For proper accountability, the FI should ensure records of user access and user management activities are uniquely identified and logged for audit and investigation purposes.
What This Requires.
ProfytAI Regulatory Intelligence
Type: requirementThe FI should establish a user access management process to provision, change and revoke access rights to information assets.
Relationship
This is a standalone provision under Section 9.1.2.p33 (Access Control): it states a complete duty in its own sentence rather than implementing a broader governing clause.
Why This Exists
A defined joiner, mover and leaver process is the control backbone that keeps later access expectations (approval, review, revocation) operating consistently rather than ad hoc.
Implementation Considerations
Typically a documented access lifecycle procedure with request, approval, modification and revocation workflows, often supported by an identity management tool and applied to all in-scope systems.
Interpretation Note · The term 'user access' carries a source footnote (19); confirm the footnoted definition when scoping which account types the process covers. TRM is guidance, so this 'should' is a MAS supervisory expectation rather than a binding notice requirement.
This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.
The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.
