Source Document

MAS TRM Guidelines

MAS.TRM.2021.Sec9.1.2.p33.OBL1

9 Access Control > 9.1 User Access Management > 9.1.2

Obligation Summary

The FI should establish a user access management process to provision, change and revoke access rights to information assets.

SHOULDmedium priorityrecommendationprocessrequirement
Source TextVerbatimView Evidence
The FI should establish a user access management process<sup>19</sup> to provision, change and revoke access rights to information assets.

MAS TRM Guidelines, Section 9.1.2, p. 33 (2021) · Technology Risk Management Guidelines · p. 33

In the Documentp. 33

9.1.1 The principles of ‘never alone’,<sup>15</sup> ‘segregation of duties’,<sup>16</sup> and ‘least privilege’<sup>17</sup> should be applied when granting staff access to information assets so that no one person has access to perform sensitive system functions.<sup>18</sup> Access rights and system privileges should be granted according to the roles and responsibilities of the staff, contractors and service providers.

9.1.2 The FI should establish a user access management process<sup>19</sup> to provision, change and revoke access rights to information assets. Access rights should be authorised and approved by appropriate parties, such as the information asset owner.

9.1.3 For proper accountability, the FI should ensure records of user access and user management activities are uniquely identified and logged for audit and investigation purposes.

Highlighted Text Is This Obligation

What This Requires.

ProfytAI Regulatory Intelligence

Type: requirement

The FI should establish a user access management process to provision, change and revoke access rights to information assets.

Relationship

This is a standalone provision under Section 9.1.2.p33 (Access Control): it states a complete duty in its own sentence rather than implementing a broader governing clause.

Why This Exists

A defined joiner, mover and leaver process is the control backbone that keeps later access expectations (approval, review, revocation) operating consistently rather than ad hoc.

Implementation Considerations

Typically a documented access lifecycle procedure with request, approval, modification and revocation workflows, often supported by an identity management tool and applied to all in-scope systems.

Interpretation Note · The term 'user access' carries a source footnote (19); confirm the footnoted definition when scoping which account types the process covers. TRM is guidance, so this 'should' is a MAS supervisory expectation rather than a binding notice requirement.

This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.

Evidence Capturep. 33

The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.

Captured source page for MAS.TRM.2021.Sec9.1.2.p33.OBL1, MAS TRM Guidelines, Section 9.1.2, p. 33 (2021)