MAS TRM Modules · 13 Themes

Own a Single Technology-Risk Theme, Structured and Cited, Without Buying the Whole Book.

Any one of the 13 TRM themes, sold on its own and priced by size. Start where your exam or your gap is, from Access Control to IT Resilience.

From $400one-time / theme

Secure Checkout via Stripe · Enterprise via Private Offer

GuidanceMAS TRM
MAS.TRM.2021.Sec6.1.1.p19.OBL1
Summary

The FI should adopt standards on secure coding, source code review and application security testing to minimise bugs and vulnerabilities in its software.

VerbatimSHOULDrecommendation
To minimise the bugs and vulnerabilities in its software, the FI should adopt standards on secure coding, source code review and application security testing.

MAS TRM Guidelines, Section 6.1.1, p. 19 (2021)

ActorFI
ActionAdopt standards on secure coding, source code review, and application security testing
ObjectSecure coding, source code review, and application security testing standards
Tagssoftware-developmentsecure-coding
Software Application Development and Management · Secure Coding, Source Code Review and Application Security Testing · p.19medium severitysupervisory sanction

Non-adherence may attract MAS supervisory action; the TRM Guidelines set out the standards MAS expects financial institutions to meet.

Source · Technology Risk Management GuidelinesRegulator PDF ↗

One record, straight from the full dataset

One Theme at a Time

Buy the Theme Your Exam Is About, Not the Whole Book.

Start Where the Gap Is

Your exam finding names one theme, not thirteen. License Access Control or IT Resilience on its own and close that gap this week.

The Same Schema as the Register

Every module ships in the identical structure as the full TRM dataset, so what you buy today slots straight into what you expand later.

Honest Upgrade Math

Themes are priced by size, $400 to $1,000. Once you need three or more, Complete MAS TRM at $6,500 is the obvious upgrade.

Product Details

What You License.

Coverage
One TRM theme on its own, from 5 to 40 obligations depending on the theme.
Pricing
By theme size: $400, $700, or $1,000, one-time. Choose a theme below.
Instrument
MAS Technology Risk Management Guidelines (2021).
Schema
47 fields in four structured layers: verbatim, normalized, parsed, context. Complete MAS TRM and the Collection add Semantic Enrichment for 51 fields.
Regulatory Intelligence
A generated summary, purpose, relationship, and implementation notes on every record.
Semantic Enrichment
Not included in single modules. Typed qualifications, evidence expectations, responsible roles, and cross-instrument links ship with Complete MAS TRM and the Collection (51 fields).
Formats
Excel workbook, JSON, and CSV. Official source document linked, not redistributed.
License
Single-organization commercial license, delivered by instant download.

Every module ships in the same schema as the full register. Buy one theme now. If you need three or more, Complete MAS TRM is the better value.

In Every Format

Excel

Cover, Obligations, Data Dictionary, Methodology, Change Log

JSON

Versioned, checksummed envelope for pipelines and AI

CSV

Flat table for spreadsheets, BI, and SQL

Official regulator source document linked, not redistributed.

What It Solves.

Paying for the Whole Book

When your exam or gap covers one theme, buy that theme on its own from $400, not the full 331-obligation register.

A Blank Page on One Topic

The theme arrives as a finished, cited obligation set, from Access Control to IT Resilience, in the same schema as the full register.

Findings You Cannot Trace

Every obligation is quoted verbatim and page-anchored, so a finding traces to the exact clause in one step.

Interpretation Bottlenecks

Regulatory intelligence on every record explains what a duty requires and how teams implement it.

Buy by Theme

Pick the Theme You Need.

Start where your exam or your gap is. Each theme is a structured set of that theme’s obligations, licensed one-time and priced by size. Once you need three or more, Complete MAS TRM is the better value.

01Standard Module

Technology Risk Governance and Oversight

Board and senior-management accountability for technology risk.

26Obligations
$700One-Time License
Purchase License
02Standard Module

Technology Risk Management Framework

The framework, policies, and risk processes MAS expects.

20Obligations
$700One-Time License
Purchase License
03Large Module

IT Project Management and Security-by-Design

Delivering IT projects with security built in from the start.

38Obligations
$1,000One-Time License
Purchase License
04Standard Module

Software Application Development and Management

Secure coding, source-code review, and application lifecycle.

28Obligations
$700One-Time License
Purchase License
05Large Module

IT Service Management

Change, incident, and configuration management for IT services.

35Obligations
$1,000One-Time License
Purchase License
06Large Module

IT Resilience

System availability, redundancy, disaster recovery, and continuity.

37Obligations
$1,000One-Time License
Purchase License
07Standard Module

Access Control

User access management, privileged access, and segregation of duties.

18Obligations
$700One-Time License
Purchase License
08Standard Module

Cryptography

Algorithms, key management, and cryptographic controls.

18Obligations
$700One-Time License
Purchase License
09Large Module

Data and Infrastructure Security

Data loss prevention, network security, and infrastructure hardening.

40Obligations
$1,000One-Time License
Purchase License
10Standard Module

Cyber Security Operations

Threat intelligence, monitoring, and situational awareness.

19Obligations
$700One-Time License
Purchase License
11Small Module

Cyber Security Assessment

Vulnerability assessment, penetration testing, and remediation.

16Obligations
$400One-Time License
Purchase License
12Standard Module

Online Financial Services

Securing customer-facing online and digital financial services.

31Obligations
$700One-Time License
Purchase License
13Small Module

IT Audit

Independent assurance over technology risk for the board.

5Obligations
$400One-Time License
Purchase License

Themes are priced by size: $400, $700, or $1,000, one-time, with an optional annual update subscription. Need three or more? Complete MAS TRM at $6,500 is the better buy.

Real Records

Two Module Records, in Full.

Real records pulled straight from two different themes. Whichever theme you license arrives in this same structure.

Get 20 Records in the Free Sample

MAS.TRM.2021.Sec13.1.1.p45.OBL1

p.45
Cyber Security Assessment · Vulnerability AssessmentSHOULDmedium priority

MAS TRM

Source TextVerbatim · Guidance
The FI should establish a process to conduct regular vulnerability assessment (VA) on their IT systems to identify security vulnerabilities and ensure risk arising from these gaps are addressed in a timely manner.
In Plain Language

The FI should establish a process to conduct regular vulnerability assessments on its IT systems to identify security vulnerabilities and ensure risks arising from these gaps are addressed in a timely manner.

In the Documentp.45

The clauses around this duty, as written in the source

Technology Risk Management Guidelines › 13 Cyber Security Assessment › 13.1 Vulnerability Assessment › 13.1.1

13.1.1

The FI should establish a process to conduct regular vulnerability assessment (VA) on their IT systems to identify security vulnerabilities and ensure risk arising from these gaps are addressed in a timely manner. The frequency of VA should be commensurate with the criticality of the IT system and the security risk to which it is exposed.

13.1.2

When performing VA, the scope should minimally include vulnerability discovery, identification of weak security configurations, and open network ports, as well as application vulnerabilities. For web-based systems, the scope of VA should include checks on common web-based vulnerabilities.

Parsed Duty
ActorFI
ActionEstablish a process to conduct regular vulnerability assessments
ObjectIT systems, to identify security vulnerabilities and address the risks in a timely manner
Structured FieldsDeontic · recommendation

Deontic

recommendation

Type

Process

Strength

Recommended

Frequency

Regular

Status

In Force

Sanction

supervisory

Marker

13.1.1

Amendment

New · First Edition

cyber-securityvulnerability-assessment

MAS TRM Guidelines, Section 13.1.1, p. 45 (2021)

Consequence. Non-adherence may attract MAS supervisory action; the TRM Guidelines set out the standards MAS expects financial institutions to meet.

Source · Technology Risk Management GuidelinesRegulator PDF ↗

MAS.TRM.2021.Sec5.7.1.p17.OBL3

p.17
IT Project Management and Security-by-Design · System Testing and AcceptanceSHOULDmedium priority

MAS TRM

Source TextVerbatim · Guidance
A test plan should be established and approved before testing.
In Plain Language

The FI should establish and obtain approval for a test plan before testing begins.

In the Documentp.17

The clauses around this duty, as written in the source

Technology Risk Management Guidelines › 5 IT Project Management and Security-by-Design › 5.7 System Testing and Acceptance › 5.7.1

5.7.1

A methodology for system testing should be established. The scope of testing should cover business logic, system function, security controls and system performance under various load and stress conditions. A test plan should be established and approved before testing.

5.7.2

The FI should trace the requirements during the testing phase, and ensure each requirement is covered by appropriate test cases.

Parsed Duty
ActorFI
ActionEstablish and obtain approval for a test plan
ObjectTest plan
Structured FieldsDeontic · recommendation

Deontic

recommendation

Type

Process

Strength

Recommended

Frequency

Ongoing

Status

In Force

Sanction

supervisory

Marker

5.7.1

Amendment

New · First Edition

it-project-managementsystem-testing

MAS TRM Guidelines, Section 5.7.1, p. 17 (2021)

Consequence. Non-adherence may attract MAS supervisory action; the TRM Guidelines set out the standards MAS expects financial institutions to meet.

Source · Technology Risk Management GuidelinesRegulator PDF ↗

Each card shows the key fields for readability. Every delivered record carries the complete five-layer schema.

ProfytAI Regulatory Intelligence

The Rule, and What It Means.

Every module record ships with generated regulatory intelligence beside the regulator's exact words. Here is a board-oversight duty from the Governance module.

One Record From This Dataset

SHOULDGuidanceMAS TRMMAS.TRM.2021.Sec3.1.2.p7.OBL1
Section 3.1.2Page 7

Verbatim

Both the board of directors and senior management should have members with the knowledge to understand and manage technology risks, which include risks posed by cyber threats.

ProfytAI Regulatory Intelligence

The board and senior management should include members who are capable of understanding and managing technology risk, including cyber threat risk. MAS expects technology-literate leadership at the top of the institution.

Requirement Type

Requirement

Relationship

One of the sequential governance expectations in section 3.1 on the role of the board and senior management, sitting between the general reliance-on-technology premise (3.1.1) and the appointment of accountable technology officers (3.1.3).

Why This Exists

MAS expects technology risk to be governed at the top of the institution; without technology-literate leadership, board oversight of IT and cyber risk is nominal rather than effective.

Implementation Considerations

Typically evidenced through board composition and skills matrices, technology-risk training records, and recruitment or advisory arrangements that add technology expertise to the board.

Interpretation Note · This is TRM guidance (SHOULD), not a binding notice requirement; it addresses collective competence of the board and senior management, not a named individual.

Why It Matters on Every Record

From Raw Regulation to Operational Knowledge.

Interpretation Already Done

A plain-language read of what the regulator is actually requiring, on every record.

Traceable to the Source

Each explanation stays anchored to the citation and the verbatim clause it came from.

Ready to Operationalize

Structured for registers, control libraries, policy drafting, and AI grounding from day one.

On Every Record

summary
The plain-language read of the duty
obligation_kind
Requirement, prohibition, or permission
relationship_to_parent
Where the clause sits among its siblings
why_this_obligation_exists
The regulator's purpose behind it
implementation_considerations
How teams typically satisfy it
interpretation_notes
Scope, force, and how to read it

The intelligence is generated from the structured obligation and preserves traceability back to the citation and the supporting evidence. It accelerates understanding, and the byte-exact verbatim text remains the authority you cite.

Compare

Start Small, or Take the Whole Perimeter.

Every tier is the same structured data, cited the same way. The only question is how much of the Singapore technology-risk perimeter you need today.

You Are HereMAS TRM Module
From $400
Obligations
One theme
Instruments
TRM only
TRM Themes
1 of 13
Regulatory Intelligence
Semantic Enrichment
Implementation Controls
Evidence Captures
Policy Statements
Official Sources
Linked
Formats
Excel · JSON · CSV
Cyber Hygiene Bundle
$3,900
Obligations
9 (Cyber Hygiene)
Instruments
Cyber Hygiene Notice (9)
TRM Themes
Regulatory Intelligence
Joins by obligation ID
Semantic Enrichment
Implementation Controls
12, NIST-mapped, with audit tests
Evidence Captures
Policy Statements
Official Sources
How-to booklet
Formats
Excel · JSON · CSV
View Cyber Hygiene Bundle
Complete MAS TRM
$6,500
Obligations
331 (all TRM)
Instruments
TRM only (331)
TRM Themes
All 13
Regulatory Intelligence
Semantic Enrichment
Implementation Controls
Evidence Captures
Policy Statements
Official Sources
Linked
Formats
Excel · JSON · CSV
View Complete MAS TRM
Singapore Collection
$9,500
Obligations
380 (all three)
Instruments
TRM 331 + Cyber Hygiene 9 + Outsourcing 40
TRM Themes
All 13
Regulatory Intelligence
Semantic Enrichment
Implementation Controls
Evidence Captures
Pending MAS Approval
Policy Statements
Official Sources
All three, linked
Formats
Excel · JSON · CSV
View Singapore Collection
AI Policy Statement Library
From $25,000
Obligations
380 (all three)
Instruments
TRM 331 + Cyber Hygiene 9 + Outsourcing 40
TRM Themes
All 13
Regulatory Intelligence
Semantic Enrichment
Implementation Controls
12, NIST-mapped, with audit tests
Evidence Captures
Pending MAS Approval
Policy Statements
100, across 44 domains, with the Word manual
Official Sources
All three, linked
Formats
Excel · JSON · CSV + Word
View AI Policy Statement Library

Start With One Theme. Add the Rest Anytime.

A single theme gets you moving. When you need the whole framework, Complete MAS TRM is the better value.

SampleConsultationRegisterPlatformSubscription