HomeFrameworksMalaysia BNM RMiT
Bank Negara Malaysia (BNM) · Malaysia

Risk Management in Technology (RMiT), BNM/RH/PD 028-98 compliance software

Bank Negara Malaysia's technology risk policy, revised and effective 28 November 2025 — 173 controls across 14 domains, with the 90-day gap analysis and annual self-assessment tracked as their own indicator.

At a glance
  • RegulatorBank Negara Malaysia (BNM)
  • InstrumentBNM/RH/PD 028-98 — revised, effective 28 November 2025
  • Structure14 domains — 11 Part B + Appendices 5, 10, 11
  • Controls173 — 111 Standard + 10 Guidance paragraphs, 52 appendix controls
Malaysia BNM RMiTAvailable
Overview

What Malaysia BNM RMiT requires

Who it applies to

  • Licensed banks, investment banks and Islamic banks
  • Licensed insurers, takaful operators and prescribed development financial institutions
  • Approved e-money issuers and designated payment system operators
  • Registered non-bank merchant acquirers and intermediary remittance institutions with 5%+ market share

Risk Management in Technology (RMiT), Bank Negara Malaysia's policy document BNM/RH/PD 028-98, was revised with effect from 28 November 2025, superseding the 2023 version, the 2019 e-banking guidelines, two 2022 fraud specification circulars and other prior guidance it consolidates. It applies to licensed banks, licensed investment and Islamic banks, licensed insurers and takaful operators, prescribed development financial institutions, approved e-money issuers, designated payment system operators, and — new in this revision — registered non-bank merchant acquirers and intermediary remittance institutions holding 5% or more market share.

The policy sets 111 Standard and 10 Guidance paragraphs across eleven Part B domains — governance, technology risk management, technology operations management, cybersecurity management, digital services, technology audits, external party assurance, security awareness and education, notification for technology-related applications, consultation and notification for cloud services and emerging technology, and assessment and gap analysis — plus 52 further controls from Appendix 5 (cybersecurity control measures), Appendix 10 (cloud services risks and controls) and Appendix 11 (fraud detection standards). 173 controls in total.

Every institution has a hard clock from the effective date: a gap analysis and action plan within 90 days, due by late February 2026, followed by an ongoing annual compliance self-assessment. RMiT is the one catalogue GRCLens carries in English only — Bank Negara Malaysia publishes the policy in English, and no Arabic edition exists to transcribe.

In the platform

How GRCLens supports Malaysia BNM RMiT

Malaysia BNM RMiT runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.

The 90-day clock as an indicator

The gap analysis and action plan due within 90 days of the 28 November 2025 effective date, and the annual compliance self-assessment after it, are tracked as their own readiness indicator.

Standard and Guidance kept apart

The policy's own S/G distinction is carried on every control, so a Guidance paragraph is never reported as an unmet mandatory requirement.

Appendices as their own controls

Appendix 5's cybersecurity control measures, Appendix 10's cloud risks and controls, and Appendix 11's fraud detection standards are individually assessable, not summarised inside the Part B paragraph that references them.

Applicability by institution type

Sections that exclude payment system operators, e-money issuers, merchant acquirers or intermediary remittance institutions are flagged per control, so an in-scope institution is not assessed against a section RMiT does not address to it.

Questions

Malaysia BNM RMiT frequently asked questions

Who is newly in scope under the 2025 revision?

Registered non-bank merchant acquirers and intermediary remittance institutions holding 5% or more market share are newly captured, alongside the institutions already covered by the 2023 version.

What is due within 90 days of the effective date?

A gap analysis against the revised policy and an action plan to close it, due by around 26 February 2026 — 90 days after the 28 November 2025 effective date — followed by an ongoing annual compliance self-assessment.

Is RMiT available in Bahasa Malaysia or Arabic?

Bank Negara Malaysia publishes RMiT in English only. GRCLens carries the catalogue as published; there is no Arabic or Bahasa Malaysia edition to transcribe.

Talk to us about Malaysia BNM RMiT

Security Solution Consultants provides Malaysia technology risk advisory alongside the platform, so you can combine tooling with hands-on expertise.