Monetary Authority of Singapore Technology Risk Management Guidelines
Third Party Risk and IT Audit - MAS TRM Chapters 14-15

Monetary Authority of Singapore Technology Risk Management Guidelines MAS-TRM-Third-Party-IT-Audit-Chapters-14-15-Outsourcing-Notice-658-Concentration-Risk-Exit-Strategy: MAS TRM Third Party + IT Audit + Chapters 14-15 + Outsourcing + Notice 658 + Concentration Risk + Exit Strategy

Implement IT Audit + Third-Party Risk Management per MAS TRM Chapters 14 + 15 + MAS Notice 658 on Outsourcing. Chapter 14 IT Audit - IT audit charter approved by Board Audit Committee + IT audit plan risk-based + IT audit methodology + IT auditor competency (CISA + CIA + CRISC + CGEIT) + audit reporting to Board Audit Committee + remediation tracking + IT general controls (ITGC) coverage + application controls (input + processing + output) coverage + interface controls + IT operations audit + cybersecurity audit + IT outsourcing audit + cloud audit + co-sourcing with external IT auditors where required + alignment with COSO + COBIT 2019 + ISACA IT Audit Framework + ISAE 3402/SOC 2. Chapter 15 Third-Party Risk Management - third-party risk register + due diligence on prospective service providers + ongoing monitoring + contractual security requirements (right to audit + breach notification + sub-outsourcing restrictions + data location + data sovereignty + termination + transition assistance) + concentration risk monitoring (concentration with single vendor + cloud provider AWS/Azure/GCP) + exit strategy and transition planning + Material Outsourcing classification per MAS Notice 658 (notification to MAS + business continuity provisions + concentration risk + exit strategy + sub-outsourcing flow-down + 30-day prior notification for material outsourcing + critical service provider designation) + Cloud as Material Outsourcing (MAS Industry Standards on Cloud 2020 + cloud-specific provisions in Chapter 11 + multi-cloud strategy + cloud egress + cloud security posture management CSPM + cloud workload protection CWPP + cloud-native application protection CNAPP). FSI specific Cyber Resilience Framework (CRF) for outsourced services. ABS Cloud Cyber Resilience standard. Annual third-party assurance reports.

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.