Complete MAS TRM · 357 Obligations

Every TRM Duty, Cited and Ready.

Everything in Compliance Intelligence, plus adoption-ready bank-voice policy statements, written per obligation group and anchored to the citation each one stands on.

$28,000one-time

One-Time Purchase · Single-Org License · Enterprise via Private Offer

GuidanceMAS TRM
MAS.TRM.2021.Sec13.1.1.p45.OBL1
VerbatimSHOULDrecommendation
The FI should establish a process to conduct regular vulnerability assessment (VA) on their IT systems to identify security vulnerabilities and ensure risk arising from these gaps are addressed in a timely manner.

MAS TRM Guidelines, Section 13.1.1, p. 45 (2021)

ActorFI
ActionEstablish a process to conduct regular vulnerability assessments
ObjectIT systems, to identify security vulnerabilities and address the risks in a timely manner
Tagscyber-securityvulnerability-assessment
Cyber Security Assessment · Vulnerability Assessment · p.45medium severitysupervisory sanction

Non-adherence may attract MAS supervisory action; the TRM Guidelines set out the standards MAS expects financial institutions to meet.

Source · Technology Risk Management Guidelines

One record, straight from the full dataset

Every TRM Theme

The Complete MAS TRM Guidelines, Ready to Cite.

All 15 Themes, One Register

From board oversight to IT audit, every TRM theme arrives in one consistent schema. Nothing falls between owners, nothing gets read twice.

357 Duties, Cited to the Page

Each obligation is quoted word for word and page-anchored, so a TRM exam finding traces back to the exact clause in a single step.

Stand It Up the Same Day

The months of reading the Guidelines and re-keying every duty are already done. Load the register and start assessing, not transcribing.

Evidence on Every Duty

MAS Approved

An annotated capture of the source page ships with every obligation, all 357 of them. When the examiner asks, you show them the page.

Product Details

What You License.

Coverage
357 obligations across all 15 TRM themes, from board oversight to IT audit.
Instrument
MAS Technology Risk Management Guidelines (2021).
Schema
46 documented columns, measured from the shipped file. Source anchors, byte-exact verbatim text, the reading window, deontic classification, ProfytAI regulatory intelligence, and checklist coverage. The same flat width as the Free Sample.
Structure
On every record, the parsed duty with actor, action, modal, and conditions, plus regulatory context, hierarchy, and page-anchored citations into the official MAS PDF.
Evidence Captures
357 annotated source-page captures, one per obligation, each showing the duty highlighted on the page the regulator printed it on. Reproduced with MAS's written permission.MAS Approved
ProfytAI Regulatory Intelligence
On every record, a plain-language summary, the obligation kind, why the duty exists, interpretation notes, its relationship to the parent clause, and reader watchouts.
Fulfillment
On every duty, the fulfillment requirements and an evidence checklist, so a register moves from the obligation to what satisfies it.
Policy Statements
Adoption-ready, bank-voice policy prose written per obligation group, each statement anchored to the citation it stands on.
Formats
Excel workbook, JSON, and CSV, plus the evidence capture pack. Official source document linked, not redistributed.
Updates
Point-in-time and versioned. The licence is perpetual for the edition you purchase, with no updates. A new edition, when published, is a separate product sold separately.
License
Single-organization commercial licence, one-time purchase, delivered by instant download.

Who It Is For

Bank and fintech compliance teams, technology risk officers, internal audit, and the consultancies that advise them. It suits any institution that must evidence its posture against MAS technology risk expectations.

Why It Exists

Published regulation is authoritative but unstructured. Hundreds of duties sit buried in prose across a long PDF. Building a usable, cited register by hand is slow, fragile and hard to prove. This dataset does that work once, correctly, and ships it as structured data.

Expected Business Outcomes

Wording a Bank Can Adopt

Policy prose arrives in bank voice, per obligation group, anchored to its citations, so adoption starts from text rather than from a blank page.

Proof Built In

Every record quotes the regulator byte-exactly and cites the exact pages of the published PDF. A certification script in the folder re-proves the whole package.

Audit-Ready Provenance

Every duty is quoted verbatim and page-anchored, so a finding traces to the source in one step.

Lower Key-Person Risk

The regulator's expectations are captured as structured data, not held in one analyst's spreadsheet.

The whole of the TRM Guidelines as a defensible register, so you start from finished, cited obligations rather than a blank page.

In Every Format

Excel

Cover, Obligations, Requirements and Checklist on intelligence tiers, Data Dictionary, Methodology, Change Log

JSON

Versioned, checksummed envelope for pipelines and AI

CSV

Flat table for spreadsheets, BI, and SQL

Evidence Pack

MAS Approved

One annotated source-page capture per obligation, stamped with its ID and citation

Official regulator source document linked, not redistributed.

Licensed Under the ProfytAI Commercial Data License · View Licensing Terms

What It Solves.

A Blank-Page TRM Register

Standing up a Technology Risk Management register from the Guidelines is weeks of reading and re-keying. This is the finished, cited set.

Themes Reviewed in Isolation

All 15 themes, from board oversight to IT audit, arrive in one consistent schema so nothing falls between owners.

Findings You Cannot Trace

Every obligation is quoted verbatim and page-anchored, so a TRM exam finding traces to the exact clause in one step.

Interpretation Bottlenecks

Regulatory intelligence on every record explains what a duty requires and how teams implement it, without waiting on one analyst.

A Real Record

A TRM Record, in Full.

A real record pulled straight from this dataset. The regulator's exact words beside the parsed duty, the generated intelligence, and the evidence checklist, on every one of the 357.

Get 20 Records in the Free Sample

MAS.TRM.2021.Sec5.1.1.p15.OBL1

IT Project Management and Security-by-Design
SHOULDmedium priorityMAS TRMp.15
Source TextVerbatim · Guidance
A project management framework should be established to ensure consistency in project management practices, and delivery of outcomes that meets project objectives and requirements.
In Plain Language

A project management framework should be established that delivers consistent project management practice and outcomes meeting project objectives and requirements.

Parsed Duty
ActorFI
Actionestablish a project management framework
Objectproject management framework
Structured FieldsDeontic · recommendation

Deontic

recommendation

Type

Process

Strength

Recommended

Frequency

Ongoing

Status

In Force

Sanction

supervisory

IT & Technology RiskProject Management
Duties and Evidence Checklist3 Duties
1

Establish and approve a project management framework.

Done WhenAn approved project management framework document exists, carrying an approval record that names the approver and the date.

EvidenceProject management framework

2

Show projects are run consistently against the framework.

Done WhenFor a sample of projects, each project's practices can be mapped to the framework, and every deviation is recorded with a reason.

EvidenceProject records

3

Check delivered outcomes against the stated project objectives and requirements.

Done WhenFor each closed project there is a record comparing the outcomes delivered with the documented objectives and requirements, and stating whether each was met.

EvidenceProject closure record

ProfytAI Regulatory IntelligenceAnalysis · governance

Why This Exists

Projects run to individual habit produce uneven controls, and weaknesses introduced during delivery surface later as production risk. A common framework makes project behaviour predictable and reviewable across the firm.

Relationship

It is the opening sentence of paragraph 5.1.1 and the governing duty for section 5.1. The rest of the section builds on it, starting with the coverage requirement in the next sentence.

Interpretation

A guideline "should", so this is a supervisory expectation rather than a binding notice requirement. Two outcomes are stated and both shape what an adequate framework looks like. Consistency of practice, and delivery of outcomes that meet project objectives and requirements. The provision names no methodology, no external standard and no project size threshold, so the firm chooses the approach. The second sentence of the same paragraph sets the framework's minimum coverage, and the following paragraphs then add specific content requirements for individual project plans.

Watchouts

The framework is treated as the deliverable, so its existence is read as compliance. The stated purpose is consistency in practice and delivery of outcomes meeting objectives, both of which are properties of projects rather than of the document, so a framework nobody follows does not meet it.

Generated regulatory intelligence, traceable to the citation below. The verbatim source text remains the authority you cite.

MAS TRM, Section 5.1.1, p. 15 (2021)

Consequence. Non-adherence may attract MAS supervisory action; the TRM Guidelines set out the standards MAS expects financial institutions to meet.

Source · Technology Risk Management Guidelines

The record shows the key fields for readability. Every delivered record carries the complete schema: verbatim, normalized, parsed, context, ProfytAI regulatory intelligence, and fulfillment.

Policy Statements
A Separate Dataset in the Package

Bank-Voice Policy,Written and Ready to Adopt.

A register tells you what MAS requires. Your examiner still expects the policy that answers it. Policy Suite adds 65 bank-voice policy statements, one per obligation group, together covering all 357 TRM obligations. They ship as their own dataset and every record references one by statement_id, so the prose lives once per group and never bloats the register. Compliance Intelligence does not include this layer.

DraftedBank-Voice Policy Statement
PS-f474029e1540

3.1 Role of the Board of Directors and Senior Management

Role of the Board of Directors and Senior Management

Covers 9 Obligations · Group MAS.TRM.2021.Sec3.OBL.GRP.01

The Board of Directors and senior management of the Bank ensure that internal controls and risk management practices are effective and are implemented, so that the Bank's information technology (IT) operating environment achieves security, reliability and resilience. Both bodies include members who hold the knowledge needed to understand and manage technology risks, including the risks posed by cyber threats. The Board of Directors and senior management set the tone from the top. They cultivate a strong culture of technology risk awareness and management at every level of staff. They also ensure that a technology risk management strategy is established and implemented, and that key IT decisions are made in accordance with the Bank's risk appetite.

The Bank appoints a Chief Information Officer (CIO), Chief Technology Officer (CTO) or Head of IT, and a Chief Information Security Officer (CISO) or Head of Information Security, each with the requisite expertise and experience. The Board of Directors and senior management ensure these appointments are made, and the Chief Executive Officer (CEO) approves them as a minimum. The CIO, CTO or Head of IT holds principal responsibility for establishing and implementing the overall information technology strategy. That role also oversees day-to-day information technology operations and manages the technology risks of the Bank. The CISO or Head of Information Security holds principal responsibility for the Bank's information security strategy and programme. That responsibility covers information security controls, the management of information security, and the information security policies and procedures that safeguard information assets.

The Board of Directors, or a committee it delegates, is accountable for the following. (a) A robust and sound risk management framework for technology risks is established and maintained. (b) A technology risk management function exists to oversee that framework and the strategy, and to provide an independent view of the technology risks the Bank faces. (c) Senior executives responsible for executing the technology risk management strategy are given sufficient authority, resources and access to the Board of Directors. (d) The risk appetite and risk tolerance statement, articulating the nature and extent of technology risks the Bank is willing and able to assume, is approved. (e) The technology risk management strategy is reviewed regularly for continued relevance. (f) Management competencies for managing technology risks are assessed. (g) An independent audit function is established, and it assesses the effectiveness of the Bank's controls, risk management and governance.

Senior management is accountable for the following. (a) Establishing the technology risk management framework and strategy. (b) Managing technology risks on the basis of that established framework and strategy. (c) Policies, standards and procedures for managing technology risks are sound and prudent, established and maintained, and the standards and procedures are implemented effectively. (d) Delineating clearly the roles and responsibilities of staff in managing technology risks. (e) Apprising the Board of Directors, in a timely manner, of salient and adverse technology risk developments and incidents likely to have a major impact on the Bank. The Bank may define and track these roles and responsibilities using a Responsibility Assignment Matrix, also known as RACI, which outlines who is responsible and accountable for the functions and who is consulted or informed.

Covers These Obligations

MAS.TRM.2021.Sec3.1.1.p7.OBL1MAS.TRM.2021.Sec3.1.2.p7.OBL1MAS.TRM.2021.Sec3.1.3.p7.OBL1MAS.TRM.2021.Sec3.1.3.p7.OBL2MAS.TRM.2021.Sec3.1.4.p7.OBL1MAS.TRM.2021.Sec3.1.5.p7.OBL1MAS.TRM.2021.Sec3.1.6.p7.OBL1MAS.TRM.2021.Sec3.1.7.p8.OBL1MAS.TRM.2021.Sec3.1.8.p8.OBL1

ProfytAI-authored bank-voice policy prose, not regulatory text, anchored to its source citation.

Source · Technology Risk Management Guidelines, 2021, 3.1.1 (Technology Risk Governance and Oversight), pp.7-8

Ships Aspolicy_groups.jsonpolicy_group_members.csv
ProfytAI Regulatory Intelligence

The Rule, and What It Means.

Every TRM obligation ships with generated regulatory intelligence beside the regulator's exact words. Here is the configuration-management duty from IT Service Management.

One Record From This Dataset

SHOULDGuidanceMAS TRMMAS.TRM.2021.Sec7.2.1.p23.OBL1
Section 7.2.1Page 23

Verbatim

The FI should implement a configuration management process to maintain accurate information of its hardware and software to have visibility and effective control of its IT systems.

ProfytAI Regulatory Intelligence

The FI should implement a configuration management process that keeps accurate information about its hardware and software so it has visibility and effective control of its IT systems.

Requirement Type

process

Relationship

The second sentence of 7.2.1. The first sentence defines configuration management, and this sentence turns that definition into a duty on the FI.

Why This Exists

A firm cannot patch, refresh or restore what it cannot accurately describe. Wrong configuration data quietly undermines every downstream process that depends on knowing which version of what is running where.

Reader Watchouts

The examples in the definition are prefixed 'e.g.', so model, version and specifications illustrate rather than complete the field list. Scoping the repository to only those three attributes rarely delivers the visibility the sentence asks for.

Interpretation Note · The definition sits in the same paragraph. Configuration management means maintaining key information about the configuration of the hardware and software that makes up each IT system, with model, version and specifications given as examples. 'Accurate' is the quality standard, and the stated purpose, visibility and effective control, is how adequacy is judged. No tool, repository type or data model is named. It is a guideline 'should', a supervisory expectation rather than a binding notice requirement.

Why It Matters on Every Record

From Raw Regulation to Operational Knowledge.

Interpretation Already Done

A plain-language read of what the regulator is actually requiring, on every record.

Traceable to the Source

Each explanation stays anchored to the citation and the verbatim clause it came from.

Ready to Operationalize

Structured for registers, control libraries, policy drafting, and AI grounding from day one.

On Every Record

summary
The plain-language read of the duty
obligation_kind
Requirement, prohibition, or permission
relationship_to_parent
Where the clause sits among its siblings
why_this_obligation_exists
The regulator's purpose behind it
reader_watchouts
Where readers commonly over- or under-read it
interpretation_notes
Scope, force, and how to read it

The intelligence is generated from the structured obligation and preserves traceability back to the citation and the supporting evidence. It accelerates understanding, and the byte-exact verbatim text remains the authority you cite.

Compare

Start Small, or Take the Whole Perimeter.

Every tier is the same structured data, cited the same way. The only question is how much of the Singapore technology-risk perimeter you need today.

MAS TRM Foundation
$4,800
Obligations
357 (all TRM)
TRM Themes
All 15
Parsed Duty & Context
Evidence Captures
One per obligation
Regulatory Intelligence
Fulfillment (Requirements + Checklists)
Policy Statements
License
One-time
Formats
Excel · JSON · CSV
View MAS TRM Foundation
Compliance Intelligence
$15,000
Obligations
357 (all TRM)
TRM Themes
All 15
Parsed Duty & Context
Evidence Captures
One per obligation
Regulatory Intelligence
Fulfillment (Requirements + Checklists)
Policy Statements
License
One-time
Formats
Excel · JSON · CSV
View Compliance Intelligence
You Are HerePolicy Suite
$28,000
Obligations
357 (all TRM)
TRM Themes
All 15
Parsed Duty & Context
Evidence Captures
One per obligation
Regulatory Intelligence
Fulfillment (Requirements + Checklists)
Policy Statements
License
One-time
Formats
Excel · JSON · CSV

The Entire MAS TRM Guidelines, on Day One.

357 obligations across 15 themes, cited and structured. Buy the license, or prove the depth with the free sample first.

SampleConsultationRegisterPlatformSubscription