The Monetary Authority of Singapore, MAS, has issued all new frequently asked questions (FAQs) on „Technology Risk Management“ of MAS supervised financial institutions, including brokers, banks, insurance undertakings, payment service providers, financial advisers, fund managers, REIT managers, capital management companies, and many others. The FAQs address the following key issues (we refrain from listing all FAQs individually due to their large number):
– which MAS notice on technology risk management requirements apply to which financial market participant?
– must a firm have its framework for the identification of critical systems approved by MAS?
– what are critical systems?
– must unscheduled downtimes be recorded?
– how should firms notify MAS of technology incidents?
– what documentation must be provided to MAS?
– what constitutes a reportable event?
– do attempted attacks need to be reported?