HomeBlogThird-Party Risk
Third-Party Risk

RMiT 2025 for Malaysian financial institutions: the 90-day clock, cloud, and the supplier you forgot

Sep 2026 · 8 min read

A bank tower reflected in glass, with a chain of linked supplier nodes drawn across the reflection

Risk Management in Technology is the policy document Bank Negara Malaysia uses to hold financial institutions to account for technology and cyber risk. The revision that took effect on 28 November 2025 consolidated the 2023 policy, the older e-banking guidelines and two 2022 fraud circulars into one instrument, widened its scope, and put every institution on a 90-day clock to say where it stood. The clock has run; the annual self-assessment is now the rhythm.

What the 2025 revision changed

Scope grew: registered non-bank merchant acquirers and intermediary remittance institutions with five per cent or more market share joined licensed banks, Islamic and investment banks, insurers and takaful operators, development financial institutions, e-money issuers and designated payment system operators. Content consolidated: Part B now runs through governance, technology risk management, operations, cybersecurity management, digital services, technology audit, external-party assurance, security awareness, notification for technology applications, consultation and notification for cloud and emerging technology, and assessment and gap analysis, with appendices on cybersecurity control measures, cloud services and fraud detection.

Every paragraph carries BNM's Standard or Guidance marking. Standards are binding; Guidance is what BNM expects a prudent institution to consider. Reporting a Guidance paragraph as an unmet mandatory requirement overstates the gap, and reporting a Standard as advisory understates it, so an honest self-assessment keeps the marking on every line.

Where the gaps sit

Institutions that completed the 90-day gap analysis by late February 2026 reported a recognisable pattern. Governance and cybersecurity management were largely in place, inherited from the 2023 policy. The gaps clustered in three places: external-party assurance, where the register of technology suppliers existed but the assurance evidence — independent reports, right-to-audit exercise, concentration analysis — did not; cloud consultation, where arrangements had been entered into without the notification or consultation BNM expects for material cloud services; and fraud detection under Appendix 11, where real-time monitoring covered cards but not newer payment rails.

The common thread is the supplier nobody owns. A cloud platform procured by a product team, a fraud-scoring service procured by operations, a managed SOC procured by security: each is a technology outsourcing arrangement in BNM's terms, and each needs a risk assessment, contractual controls, ongoing assurance and an exit plan.

Cloud and the consultation duty

RMiT expects an institution to assess cloud risk before adoption, to consult BNM on material arrangements and to notify it of others, and to keep the controls in Appendix 10 — data residency and segregation, key management, provider assurance, exit and portability — evidenced for the life of the service. Because the same provider often serves many institutions, BNM's concern is concentration as much as any single control; a supplier register that can answer 'how many of our critical services run on one provider?' is the starting point.

Keeping the annual self-assessment honest

The annual compliance self-assessment is only as good as the evidence behind each 'compliant'. Three disciplines keep it honest: assess at the paragraph level, not the section level, so a partially met Standard is visible; attach the evidence to the paragraph at the time the work is done, not in the month before submission; and track the actions from the gap analysis to closure with owners and dates, so this year's self-assessment can show what moved.

GRCLens carries RMiT as 173 individually assessable controls — every Part B Standard and Guidance paragraph and the appendix controls — with the Standard/Guidance marking preserved, applicability by institution type, the 90-day and annual clocks as a readiness indicator, and the supplier register feeding the external-party assurance paragraphs directly.

This article is general information, not legal advice. Regulations change, so confirm current requirements with the relevant regulator before relying on them. Questions?info@grclens.net.

← All articles