Singapore MAS TRM Guidelines
Monetary Authority of Singapore Technology Risk Management Guidelines (Jan 2021 revision).
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (15)
Access Control
| Code | Title |
|---|---|
| TRM-12.1 | Identity and Access Management Framework |
| TRM-12.2 | Privileged Access Management |
| TRM-12.3 | Multi-Factor Authentication |
| TRM-12.4 | User Access Review |
Cyber Security
| Code | Title |
|---|---|
| TRM-11.1 | Cyber Security Strategy and Governance |
| TRM-11.2 | Cyber Threat Intelligence and Information Sharing |
| TRM-11.3 | Cyber Security Operations |
| TRM-11.4 | Cyber Incident Response |
| TRM-11.5 | Cyber Exercises and Red Teaming |
| TRM-11.6 | Cyber Awareness and Training |
| TRM-11.7 | DDoS Protection |
Cyber Security Operations
| Code | Title |
|---|---|
| TRM-16.1 | Logging and Monitoring |
| TRM-16.2 | Time Synchronisation |
Data and Infrastructure Security
| Code | Title |
|---|---|
| TRM-10.1 | Data Classification and Protection |
| TRM-10.2 | Encryption and Cryptographic Key Management |
| TRM-10.3 | Network Security |
| TRM-10.4 | Endpoint Security |
| TRM-10.5 | Wireless Network Security |
| TRM-10.6 | Database Security |
IT Audit
| Code | Title |
|---|---|
| TRM-14.1 | IT Audit Function |
| TRM-14.2 | Audit Findings and Remediation |
IT Governance
| Code | Title |
|---|---|
| TRM-3.1 | Board and Senior Management Oversight |
| TRM-3.2 | Technology Risk Management Framework |
| TRM-3.3 | Roles and Responsibilities |
IT Operations
| Code | Title |
|---|---|
| TRM-9.1 | IT Operations Management |
| TRM-9.2 | Patch Management |
| TRM-9.3 | Vulnerability Management |
| TRM-9.4 | System Hardening |
| TRM-9.5 | Privileged Access Workstations and Jump Servers |
IT Project Management
| Code | Title |
|---|---|
| TRM-5.1 | IT Project Management |
| TRM-5.2 | Quality Assurance and Testing |
IT Resilience
| Code | Title |
|---|---|
| TRM-8.1 | Systems Reliability and Availability |
| TRM-8.2 | Business Continuity and Disaster Recovery |
| TRM-8.3 | Data Backup and Recovery |
| TRM-8.4 | Crisis Management and Communication |
IT Service Management
| Code | Title |
|---|---|
| TRM-7.1 | IT Service Management Framework |
| TRM-7.2 | Change Management |
| TRM-7.3 | Incident Management |
| TRM-7.4 | Problem Management |
| TRM-7.5 | Capacity Management |
| TRM-7.6 | Configuration and Asset Management |
Online Financial Services
| Code | Title |
|---|---|
| TRM-13.1 | Online Financial Services Security |
| TRM-13.2 | Mobile Application Security |
| TRM-13.3 | Payment Card and Transaction Security |
Regulatory Notice
| Code | Title |
|---|---|
| TRM-NOTICE-1 | Notice on Technology Risk Management Compliance |
| TRM-NOTICE-2 | Critical System Unscheduled Downtime |
| TRM-NOTICE-3 | Recovery Time Objective for Critical Systems |
| TRM-NOTICE-4 | Reporting of Relevant Incidents |
Systems Acquisition and Development
| Code | Title |
|---|---|
| TRM-6.1 | Systems Development Life Cycle |
| TRM-6.2 | Secure Coding Standards |
| TRM-6.3 | Application Security Testing |
| TRM-6.4 | Source Code Review and Repository Security |
| TRM-6.5 | API Security |
Technology Risk Management
| Code | Title |
|---|---|
| TRM-4.1 | Technology Risk Identification and Assessment |
| TRM-4.2 | Risk Treatment and Mitigation |
| TRM-4.3 | Risk Monitoring and Reporting |
Third Party Risk
| Code | Title |
|---|---|
| TRM-15.1 | Third Party and Vendor Risk Management |
| TRM-15.2 | Cloud Services Risk Management |
| TRM-15.3 | Outsourcing of Material Technology Services |
Frequently Asked Questions
What is Singapore MAS TRM Guidelines?
Singapore MAS TRM Guidelines is a compliance framework from Singapore with 15 domains and 59 controls. Monetary Authority of Singapore Technology Risk Management Guidelines (Jan 2021 revision). It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Singapore MAS TRM Guidelines have?
Singapore MAS TRM Guidelines has 59 controls organised across 15 domains. The largest domains are Cyber Security (7 controls), Data and Infrastructure Security (6 controls), IT Service Management (6 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Singapore MAS TRM Guidelines map to?
Singapore MAS TRM Guidelines does not currently have cross-framework mappings in our system. Check back as we continuously expand our mapping database.
How do I get started with Singapore MAS TRM Guidelines compliance?
Start your Singapore MAS TRM Guidelines compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Singapore MAS TRM Guidelines requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 59 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 769 frameworks.
Get Started Free →Free forever — no credit card required