Back to Frameworks

HKMA TM-G-1

Hong Kong
5 domains
42 controls

HKMA Supervisory Policy Manual TM-G-1 General Principles for Technology Risk Management plus TM-E-1, TM-G-2, OR-2, C-RAF 2.0.

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (5)

C-RAF 2.0

3 controls
Controls in the C-RAF 2.0 domain of HKMA TM-G-13 controls
CodeTitle
CRAF-2.0.1Inherent Risk Assessment under C-RAF 2.0
CRAF-2.0.2Maturity Assessment under C-RAF 2.0
CRAF-2.0.3Intelligence-led Cyber Attack Simulation Testing (iCAST)

OR-2

3 controls
Controls in the OR-2 domain of HKMA TM-G-13 controls
CodeTitle
OR-2.2.1Operational Resilience Framework
OR-2.3.1Severe but Plausible Scenario Testing
OR-2.4.1Third Party and Concentration Risk for Resilience

TM-E-1

5 controls
Controls in the TM-E-1 domain of HKMA TM-G-15 controls
CodeTitle
TM-E-1.2.1Governance of E-banking
TM-E-1.3.1Customer Authentication for E-banking
TM-E-1.3.2Transaction Monitoring and Fraud Detection
TM-E-1.3.3Customer Protection and Awareness
TM-E-1.4.1Application Security for E-banking

TM-G-1

26 controls
Controls in the TM-G-1 domain of HKMA TM-G-126 controls
CodeTitle
TM-G-1.2.1Board and Senior Management Oversight of Technology Risk
TM-G-1.2.2Technology Risk Management Framework
TM-G-1.2.3Roles and Responsibilities
TM-G-1.3.1IT Strategy and Planning
TM-G-1.3.2IT Policies, Standards and Procedures
TM-G-1.3.3Technology Risk Assessment
TM-G-1.4.1Project and Programme Management
TM-G-1.4.2System Development and Acquisition
TM-G-1.4.3Change Management
TM-G-1.5.1IT Operations Management
TM-G-1.5.2Capacity and Performance Management
TM-G-1.5.3Problem and Incident Management
TM-G-1.6.1Information Security Programme
TM-G-1.6.2Access Control and Identity Management
TM-G-1.6.3Privileged Access Management
TM-G-1.6.4Network Security
TM-G-1.6.5Cryptographic Controls
TM-G-1.6.6Data Loss Prevention and Data Protection
TM-G-1.6.7Vulnerability and Patch Management
TM-G-1.6.8Endpoint and Mobile Security
TM-G-1.7.1Security Monitoring and SIEM
TM-G-1.7.2Cyber Threat Intelligence
TM-G-1.7.3Cyber Incident Response
TM-G-1.8.1Independent Audit of Technology Risk
TM-G-1.9.1Outsourcing and Third Party Risk
TM-G-1.9.2Cloud Computing Risk Management

TM-G-2

5 controls
Controls in the TM-G-2 domain of HKMA TM-G-15 controls
CodeTitle
TM-G-2.2.1Business Continuity Governance
TM-G-2.3.1Business Impact Analysis
TM-G-2.3.2Recovery Strategy and Plans
TM-G-2.3.3Backup and Restoration
TM-G-2.4.1BCP Testing and Exercising

Frequently Asked Questions

What is HKMA TM-G-1?

HKMA TM-G-1 is a compliance framework from Hong Kong with 5 domains and 42 controls. HKMA Supervisory Policy Manual TM-G-1 General Principles for Technology Risk Management plus TM-E-1, TM-G-2, OR-2, C-RAF 2.0. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does HKMA TM-G-1 have?

HKMA TM-G-1 has 42 controls organised across 5 domains. The largest domains are TM-G-1 (26 controls), TM-E-1 (5 controls), TM-G-2 (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does HKMA TM-G-1 map to?

HKMA TM-G-1 does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with HKMA TM-G-1 compliance?

Start your HKMA TM-G-1 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about HKMA TM-G-1 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 42 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.

Get Started Free →

Free forever — no credit card required