Back to Frameworks

Singapore MAS TRM Guidelines

Singapore
15 domains
59 controls

Monetary Authority of Singapore Technology Risk Management Guidelines (Jan 2021 revision).

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (15)

Access Control

4 controls
Controls in the Access Control domain of Singapore MAS TRM Guidelines4 controls
CodeTitle
TRM-12.1Identity and Access Management Framework
TRM-12.2Privileged Access Management
TRM-12.3Multi-Factor Authentication
TRM-12.4User Access Review

Cyber Security

7 controls
Controls in the Cyber Security domain of Singapore MAS TRM Guidelines7 controls
CodeTitle
TRM-11.1Cyber Security Strategy and Governance
TRM-11.2Cyber Threat Intelligence and Information Sharing
TRM-11.3Cyber Security Operations
TRM-11.4Cyber Incident Response
TRM-11.5Cyber Exercises and Red Teaming
TRM-11.6Cyber Awareness and Training
TRM-11.7DDoS Protection

Cyber Security Operations

2 controls
Controls in the Cyber Security Operations domain of Singapore MAS TRM Guidelines2 controls
CodeTitle
TRM-16.1Logging and Monitoring
TRM-16.2Time Synchronisation

Data and Infrastructure Security

6 controls
Controls in the Data and Infrastructure Security domain of Singapore MAS TRM Guidelines6 controls
CodeTitle
TRM-10.1Data Classification and Protection
TRM-10.2Encryption and Cryptographic Key Management
TRM-10.3Network Security
TRM-10.4Endpoint Security
TRM-10.5Wireless Network Security
TRM-10.6Database Security

IT Audit

2 controls
Controls in the IT Audit domain of Singapore MAS TRM Guidelines2 controls
CodeTitle
TRM-14.1IT Audit Function
TRM-14.2Audit Findings and Remediation

IT Governance

3 controls
Controls in the IT Governance domain of Singapore MAS TRM Guidelines3 controls
CodeTitle
TRM-3.1Board and Senior Management Oversight
TRM-3.2Technology Risk Management Framework
TRM-3.3Roles and Responsibilities

IT Operations

5 controls
Controls in the IT Operations domain of Singapore MAS TRM Guidelines5 controls
CodeTitle
TRM-9.1IT Operations Management
TRM-9.2Patch Management
TRM-9.3Vulnerability Management
TRM-9.4System Hardening
TRM-9.5Privileged Access Workstations and Jump Servers

IT Project Management

2 controls
Controls in the IT Project Management domain of Singapore MAS TRM Guidelines2 controls
CodeTitle
TRM-5.1IT Project Management
TRM-5.2Quality Assurance and Testing

IT Resilience

4 controls
Controls in the IT Resilience domain of Singapore MAS TRM Guidelines4 controls
CodeTitle
TRM-8.1Systems Reliability and Availability
TRM-8.2Business Continuity and Disaster Recovery
TRM-8.3Data Backup and Recovery
TRM-8.4Crisis Management and Communication

IT Service Management

6 controls
Controls in the IT Service Management domain of Singapore MAS TRM Guidelines6 controls
CodeTitle
TRM-7.1IT Service Management Framework
TRM-7.2Change Management
TRM-7.3Incident Management
TRM-7.4Problem Management
TRM-7.5Capacity Management
TRM-7.6Configuration and Asset Management

Online Financial Services

3 controls
Controls in the Online Financial Services domain of Singapore MAS TRM Guidelines3 controls
CodeTitle
TRM-13.1Online Financial Services Security
TRM-13.2Mobile Application Security
TRM-13.3Payment Card and Transaction Security

Regulatory Notice

4 controls
Controls in the Regulatory Notice domain of Singapore MAS TRM Guidelines4 controls
CodeTitle
TRM-NOTICE-1Notice on Technology Risk Management Compliance
TRM-NOTICE-2Critical System Unscheduled Downtime
TRM-NOTICE-3Recovery Time Objective for Critical Systems
TRM-NOTICE-4Reporting of Relevant Incidents

Systems Acquisition and Development

5 controls
Controls in the Systems Acquisition and Development domain of Singapore MAS TRM Guidelines5 controls
CodeTitle
TRM-6.1Systems Development Life Cycle
TRM-6.2Secure Coding Standards
TRM-6.3Application Security Testing
TRM-6.4Source Code Review and Repository Security
TRM-6.5API Security

Technology Risk Management

3 controls
Controls in the Technology Risk Management domain of Singapore MAS TRM Guidelines3 controls
CodeTitle
TRM-4.1Technology Risk Identification and Assessment
TRM-4.2Risk Treatment and Mitigation
TRM-4.3Risk Monitoring and Reporting

Third Party Risk

3 controls
Controls in the Third Party Risk domain of Singapore MAS TRM Guidelines3 controls
CodeTitle
TRM-15.1Third Party and Vendor Risk Management
TRM-15.2Cloud Services Risk Management
TRM-15.3Outsourcing of Material Technology Services

Frequently Asked Questions

What is Singapore MAS TRM Guidelines?

Singapore MAS TRM Guidelines is a compliance framework from Singapore with 15 domains and 59 controls. Monetary Authority of Singapore Technology Risk Management Guidelines (Jan 2021 revision). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does Singapore MAS TRM Guidelines have?

Singapore MAS TRM Guidelines has 59 controls organised across 15 domains. The largest domains are Cyber Security (7 controls), Data and Infrastructure Security (6 controls), IT Service Management (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does Singapore MAS TRM Guidelines map to?

Singapore MAS TRM Guidelines does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.

How do I get started with Singapore MAS TRM Guidelines compliance?

Start your Singapore MAS TRM Guidelines compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Singapore MAS TRM Guidelines requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 59 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.

Get Started Free →

Free forever — no credit card required