Complete MAS TRM · 331 Obligations

The Entire MAS TRM Guidelines As a Defensible Register, on Day One.

All 331 TRM obligations across all 13 themes, each decomposed into who must do what, with the exact source wording and a citation.

$6,500one-time license

Secure Checkout via Stripe · Enterprise via Private Offer

GuidanceMAS TRM
MAS.TRM.2021.Sec13.1.1.p45.OBL1
Summary

The FI should establish a process to conduct regular vulnerability assessments on its IT systems to identify security vulnerabilities and ensure risks arising from these gaps are addressed in a timely manner.

VerbatimSHOULDrecommendation
The FI should establish a process to conduct regular vulnerability assessment (VA) on their IT systems to identify security vulnerabilities and ensure risk arising from these gaps are addressed in a timely manner.

MAS TRM Guidelines, Section 13.1.1, p. 45 (2021)

ActorFI
ActionEstablish a process to conduct regular vulnerability assessments
ObjectIT systems, to identify security vulnerabilities and address the risks in a timely manner
Tagscyber-securityvulnerability-assessment
Cyber Security Assessment · Vulnerability Assessment · p.45medium severitysupervisory sanction

Non-adherence may attract MAS supervisory action; the TRM Guidelines set out the standards MAS expects financial institutions to meet.

Source · Technology Risk Management GuidelinesRegulator PDF ↗

One record, straight from the full dataset

Every TRM Theme

The Complete MAS TRM Guidelines, Ready to Cite.

All 13 Themes, One Register

From board oversight to IT audit, every TRM theme arrives in one consistent schema. Nothing falls between owners, nothing gets read twice.

331 Duties, Cited to the Page

Each obligation is quoted word for word and page-anchored, so a TRM exam finding traces back to the exact clause in a single step.

Stand It Up the Same Day

The months of reading the Guidelines and re-keying every duty are already done. Load the register and start assessing, not transcribing.

Inside the Corpus

All Thirteen Themes, Inside.

Every theme of the Guidelines, from board oversight to IT audit, with its real obligation count. This is the breadth you are licensing.

0126

Technology Risk Governance and Oversight

Board and senior-management accountability for technology risk.

26Obligations
0220

Technology Risk Management Framework

The framework, policies, and risk processes MAS expects.

20Obligations
0338

IT Project Management and Security-by-Design

Delivering IT projects with security built in from the start.

38Obligations
0428

Software Application Development and Management

Secure coding, source-code review, and application lifecycle.

28Obligations
0535

IT Service Management

Change, incident, and configuration management for IT services.

35Obligations
0637

IT Resilience

System availability, redundancy, disaster recovery, and continuity.

37Obligations
0718

Access Control

User access management, privileged access, and segregation of duties.

18Obligations
0818

Cryptography

Algorithms, key management, and cryptographic controls.

18Obligations
0940

Data and Infrastructure Security

Data loss prevention, network security, and infrastructure hardening.

40Obligations
1019

Cyber Security Operations

Threat intelligence, monitoring, and situational awareness.

19Obligations
1116

Cyber Security Assessment

Vulnerability assessment, penetration testing, and remediation.

16Obligations
1231

Online Financial Services

Securing customer-facing online and digital financial services.

31Obligations
135

IT Audit

Independent assurance over technology risk for the board.

5Obligations
Product Details

What You License.

Coverage
331 obligations across all 13 TRM themes, from board oversight to IT audit.
Instrument
MAS Technology Risk Management Guidelines (2021).
Schema
51 fields in five structured layers: verbatim, normalized, parsed, context, semantic intelligence. The same flat width as the Free Sample and the Collection.
Regulatory Intelligence
A generated summary, purpose, relationship, and implementation notes on every record.
Semantic Enrichment
Typed qualifications, evidence expectations, responsible roles, instrument force, domains, and cross-instrument links on every record, with per-field confidence in the JSON. Single TRM modules omit this layer and ship 47 fields across four layers.
Formats
Excel workbook, JSON, and CSV. Official source document linked, not redistributed.
Updates
Point-in-time and versioned; an annual update subscription is optional, never required.
License
Single-organization commercial license, delivered by instant download.

The whole of the TRM Guidelines as a defensible register, so you start from finished, cited obligations rather than a blank page. Need the binding Notices too? The Collection adds them.

In Every Format

Excel

Cover, Obligations, Data Dictionary, Methodology, Change Log

JSON

Versioned, checksummed envelope for pipelines and AI

CSV

Flat table for spreadsheets, BI, and SQL

Official regulator source document linked, not redistributed.

What It Solves.

A Blank-Page TRM Register

Standing up a Technology Risk Management register from the Guidelines is weeks of reading and re-keying. This is the finished, cited set.

Themes Reviewed in Isolation

All 13 themes, from board oversight to IT audit, arrive in one consistent schema so nothing falls between owners.

Findings You Cannot Trace

Every obligation is quoted verbatim and page-anchored, so a TRM exam finding traces to the exact clause in one step.

Interpretation Bottlenecks

Regulatory intelligence on every record explains what a duty requires and how teams implement it, without waiting on one analyst.

Real Records

Two TRM Records, in Full.

Real records pulled straight from this dataset. A plain-language summary, the regulator's exact words, a citation, and the parsed duty on every one of the 331.

Get 20 Records in the Free Sample

MAS.TRM.2021.Sec6.1.1.p19.OBL1

p.19
Software Application Development and Management · Secure Coding, Source Code Review and Application Security TestingSHOULDmedium priority

MAS TRM

Source TextVerbatim · Guidance
To minimise the bugs and vulnerabilities in its software, the FI should adopt standards on secure coding, source code review and application security testing.
In Plain Language

The FI should adopt standards on secure coding, source code review and application security testing to minimise bugs and vulnerabilities in its software.

In the Documentp.19

The clauses around this duty, as written in the source

Technology Risk Management Guidelines › 6 Software Application Development and Management › 6.1 Secure Coding, Source Code Review and Application Security Testing › 6.1.1

6.1.1

To minimise the bugs and vulnerabilities in its software, the FI should adopt standards on secure coding, source code review and application security testing.

6.1.2

The secure coding and source code review standards should cover areas such as secure programming practices, input validation, output encoding, access controls, authentication, cryptographic practices, and error and exception handling.

Parsed Duty
ActorFI
ActionAdopt standards on secure coding, source code review, and application security testing
ObjectSecure coding, source code review, and application security testing standards
Structured FieldsDeontic · recommendation

Deontic

recommendation

Type

Process

Strength

Recommended

Frequency

Ongoing

Status

In Force

Sanction

supervisory

Marker

6.1.1

Amendment

New · First Edition

software-developmentsecure-coding

MAS TRM Guidelines, Section 6.1.1, p. 19 (2021)

Consequence. Non-adherence may attract MAS supervisory action; the TRM Guidelines set out the standards MAS expects financial institutions to meet.

Source · Technology Risk Management GuidelinesRegulator PDF ↗

MAS.TRM.2021.Sec5.7.1.p17.OBL3

p.17
IT Project Management and Security-by-Design · System Testing and AcceptanceSHOULDmedium priority

MAS TRM

Source TextVerbatim · Guidance
A test plan should be established and approved before testing.
In Plain Language

The FI should establish and obtain approval for a test plan before testing begins.

In the Documentp.17

The clauses around this duty, as written in the source

Technology Risk Management Guidelines › 5 IT Project Management and Security-by-Design › 5.7 System Testing and Acceptance › 5.7.1

5.7.1

A methodology for system testing should be established. The scope of testing should cover business logic, system function, security controls and system performance under various load and stress conditions. A test plan should be established and approved before testing.

5.7.2

The FI should trace the requirements during the testing phase, and ensure each requirement is covered by appropriate test cases.

Parsed Duty
ActorFI
ActionEstablish and obtain approval for a test plan
ObjectTest plan
Structured FieldsDeontic · recommendation

Deontic

recommendation

Type

Process

Strength

Recommended

Frequency

Ongoing

Status

In Force

Sanction

supervisory

Marker

5.7.1

Amendment

New · First Edition

it-project-managementsystem-testing

MAS TRM Guidelines, Section 5.7.1, p. 17 (2021)

Consequence. Non-adherence may attract MAS supervisory action; the TRM Guidelines set out the standards MAS expects financial institutions to meet.

Source · Technology Risk Management GuidelinesRegulator PDF ↗

Each card shows the key fields for readability. Every delivered record carries the complete five-layer schema.

ProfytAI Regulatory Intelligence

The Rule, and What It Means.

Every TRM obligation ships with generated regulatory intelligence beside the regulator's exact words. Here is the configuration-management duty from IT Service Management.

One Record From This Dataset

SHOULDGuidanceMAS TRMMAS.TRM.2021.Sec7.2.1.p23.OBL1
Section 7.2.1Page 23

Verbatim

The FI should implement a configuration management process to maintain accurate information of its hardware and software to have visibility and effective control of its IT systems.

ProfytAI Regulatory Intelligence

The FI should implement a configuration management process that maintains accurate hardware and software information, giving it visibility and effective control of its IT systems.

Requirement Type

Requirement

Relationship

This is a standalone provision under Section 7.2.1.p23 (IT Service Management): it states a complete duty in its own sentence rather than implementing a broader governing clause.

Why This Exists

Reliable configuration records underpin nearly every other IT control. Systems cannot be patched, recovered or secured if they cannot be accurately enumerated.

Implementation Considerations

A configuration management database or inventory with defined update triggers tied to the change and asset management processes.

Interpretation Note · The surrounding text frames configuration management as maintaining key information such as model, version and specifications; accuracy is the operative quality, since stale records defeat the stated purpose. SHOULD carries TRM guidance force.

Why It Matters on Every Record

From Raw Regulation to Operational Knowledge.

Interpretation Already Done

A plain-language read of what the regulator is actually requiring, on every record.

Traceable to the Source

Each explanation stays anchored to the citation and the verbatim clause it came from.

Ready to Operationalize

Structured for registers, control libraries, policy drafting, and AI grounding from day one.

On Every Record

summary
The plain-language read of the duty
obligation_kind
Requirement, prohibition, or permission
relationship_to_parent
Where the clause sits among its siblings
why_this_obligation_exists
The regulator's purpose behind it
implementation_considerations
How teams typically satisfy it
interpretation_notes
Scope, force, and how to read it

The intelligence is generated from the structured obligation and preserves traceability back to the citation and the supporting evidence. It accelerates understanding, and the byte-exact verbatim text remains the authority you cite.

Compare

Start Small, or Take the Whole Perimeter.

Every tier is the same structured data, cited the same way. The only question is how much of the Singapore technology-risk perimeter you need today.

MAS TRM Module
From $400
Obligations
One theme
Instruments
TRM only
TRM Themes
1 of 13
Regulatory Intelligence
Semantic Enrichment
Implementation Controls
Evidence Captures
Policy Statements
Official Sources
Linked
Formats
Excel · JSON · CSV
View MAS TRM Module
Cyber Hygiene Bundle
$3,900
Obligations
9 (Cyber Hygiene)
Instruments
Cyber Hygiene Notice (9)
TRM Themes
Regulatory Intelligence
Joins by obligation ID
Semantic Enrichment
Implementation Controls
12, NIST-mapped, with audit tests
Evidence Captures
Policy Statements
Official Sources
How-to booklet
Formats
Excel · JSON · CSV
View Cyber Hygiene Bundle
You Are HereComplete MAS TRM
$6,500
Obligations
331 (all TRM)
Instruments
TRM only (331)
TRM Themes
All 13
Regulatory Intelligence
Semantic Enrichment
Implementation Controls
Evidence Captures
Policy Statements
Official Sources
Linked
Formats
Excel · JSON · CSV
Singapore Collection
$9,500
Obligations
380 (all three)
Instruments
TRM 331 + Cyber Hygiene 9 + Outsourcing 40
TRM Themes
All 13
Regulatory Intelligence
Semantic Enrichment
Implementation Controls
Evidence Captures
Pending MAS Approval
Policy Statements
Official Sources
All three, linked
Formats
Excel · JSON · CSV
View Singapore Collection
AI Policy Statement Library
From $25,000
Obligations
380 (all three)
Instruments
TRM 331 + Cyber Hygiene 9 + Outsourcing 40
TRM Themes
All 13
Regulatory Intelligence
Semantic Enrichment
Implementation Controls
12, NIST-mapped, with audit tests
Evidence Captures
Pending MAS Approval
Policy Statements
100, across 44 domains, with the Word manual
Official Sources
All three, linked
Formats
Excel · JSON · CSV + Word
View AI Policy Statement Library

The Entire MAS TRM Guidelines, on Day One.

331 obligations across 13 themes, cited and structured. Buy the license, or prove the depth with the free sample first.

SampleConsultationRegisterPlatformSubscription