by Dean
Share
Share
The Monetary Authority of Singapore (MAS) published a consultation paper on 10 June 2026 proposing amendments to the MAS Notices on Technology Risk Management. The consultation closes at 11.30 PM on 31 July 2026—giving MAS-regulated firms just under two months to assess the proposed changes and, where warranted, submit a formal response.
This article explains what the consultation covers, why it matters, and how your firm should approach the response process.
Background: TRM Guidelines vs TRM Notices
MAS’s Technology Risk Management (TRM) Guidelines (last updated 2021) set out MAS’s supervisory expectations for technology risk governance. They are principles-based guidance: comprehensive, but not legally binding in the same way as a MAS Notice.
MAS Notices on Technology Risk Management are legally binding. Issued under the Securities and Futures Act, the Banking Act, and other applicable statutes, non-compliance can attract supervisory action and regulatory sanctions.
The June 2026 consultation proposes to amend the Notices—the legally binding instruments. What MAS finalises here will be enforceable, not merely aspirational.
What the Consultation Proposes
The proposed amendments target four key areas:
1. IT Asset Management
Firms will be required to maintain a comprehensive, up-to-date inventory of IT assets—including hardware, software, and cloud services. The proposals go beyond cataloguing assets: firms must actively track asset lifecycle status, including end-of-life and end-of-support milestones, and ensure unsupported assets are upgraded or decommissioned promptly.
2. IT Risk Assessment and Continuous Monitoring
MAS is proposing a stronger emphasis on continuous monitoring—moving away from point-in-time assessments toward ongoing visibility over IT risk posture. Assessments must also be triggered by material changes to a firm’s IT environment, not only on a scheduled basis.
3. Change Management Controls
The proposals require stricter controls around changes to IT systems, including mandatory testing requirements, change review and approval processes, and post-implementation review. Emergency changes—historically a source of technology incidents—receive particular attention.
4. Data Backup and Recovery
Firms must maintain and regularly test data backup and recovery capabilities, including defined recovery time objectives (RTOs) and recovery point objectives (RPOs) for critical systems. The proposals require firms to demonstrate the ability to recover data and resume operations within those timeframes.
In addition, the consultation addresses incident management and unscheduled downtime monitoring, proposing escalation protocols and reporting requirements for significant technology incidents.
Who Should Respond?
Any MAS-regulated entity subject to a TRM Notice should assess whether to submit a formal response—including capital markets intermediaries such as licensed fund managers. Even if your firm does not intend to formally respond, read the consultation paper and assess the proposed changes against your current controls. The finalised Notice will apply to your firm, and MAS typically implements changes within 12 to 18 months of a consultation closing.
How to Structure Your Response
- Address MAS’s specific questions: Each question is an invitation for feedback, particularly about unintended consequences, proportionality concerns, or technical ambiguities.
- Be specific about your firm type and size: Make clear who is responding and why a proposed requirement may have a disproportionate impact on your firm category.
- Provide practical examples: Concrete examples of implementation challenges are more persuasive than theoretical objections.
- Propose alternatives: If a proposed requirement is disproportionate, suggest a workable alternative rather than simply objecting.
- Keep it concise: A focused submission is more likely to be read carefully than a lengthy document that buries key points.
Practical Steps for Your Firm Before 31 July 2026
5 Action Steps Before the Consultation Deadline
Read the Consultation Paper: Designate a senior owner—such as your Chief Information Officer or Head of Compliance—to review it in detail.
Map Current Controls Against Proposals: Identify where existing controls align with proposed requirements and pinpoint critical gaps.
Assess Cost & Operational Impact: For every identified gap, estimate the necessary time and resources required to achieve full compliance.
Decide on Formal Response: If operational impact is significant, submit a response—industry feedback directly shapes finalised MAS requirements.
Begin Remediation Planning: Initiate early roadmap planning to minimize last-minute pressure once the finalized Notice is officially published.
What Happens After the Consultation?
MAS will review all submissions and typically publish a response to feedback paper before finalising the Notice. For TRM updates, MAS has historically allowed 12 to 18 months for compliance. Based on the timeline, firms should anticipate the revised TRM Notice taking effect in mid-2027 at the earliest—though proactive firms will begin planning and remediation well before then.
How Alder Can Help
Alder’s compliance team works with MAS-regulated entities across fund management, payment services, and financial advisory to assess technology risk management controls and identify gaps against MAS requirements. If your firm needs assistance reviewing the proposed TRM Notice amendments, preparing a consultation response, or planning your technology risk remediation programme, contact Alder.
Does your firm need support reviewing the MAS TRM proposals or submitting a response?
Contact our technology risk and regulatory compliance specialists at Alder today for expert assistance.
This article is for general information only and does not constitute legal or regulatory advice. Contact Alder for advice specific to your circumstances.
A surprising number of Capital Markets Services (CMS) licensees in Singapore are still operating on the compliance policy manual they drafted at the point of licensing — sometimes years earlier, with no formal review in between. Keeping policies current is not a bureaucratic nicety; it is one of the more common gaps that surfaces during
The Monetary Authority of Singapore (MAS) can take a range of enforcement actions for breaches of the laws it administers — reprimands, composition penalties, prohibition orders, civil penalties, and referrals for criminal prosecution. MAS’s own stated enforcement priorities for 2025–26 centre on market misconduct, AML/CFT failures, and technology risk. A review of MAS’s recent
Suspicious transaction reporting is a core AML/CFT obligation for every MAS-licensed fund manager in Singapore. Yet it remains one of the compliance areas most likely to have inadequate policies, insufficient training, and underdocumented decision-making. This guide explains the legal framework, the filing timeline, and the practical steps your firm should take to meet its STR



