MAS Technology Risk Management Guidelines and Notices FSM-N05 / FSM-N06 compliance software
MAS's Technology Risk Management Guidelines (18 Jan 2021) plus the binding Notices on Technology Risk Management (FSM-N05) and Cyber Hygiene (FSM-N06), both effective 10 May 2024 — 289 obligations across 15 domains, with every MAS clock tracked.
- RegulatorMonetary Authority of Singapore (MAS)
- InstrumentsTRM Guidelines (18 Jan 2021, guidance) + Notices FSM-N05 / FSM-N06 (eff. 10 May 2024, binding)
- Structure15 domains, chapters 3-15 and Annexes A-C; 289 assessable controls
- MAS clocks1 h incident notification · 4 h RTO, validated every 12 mo · 4 h downtime ceiling/12 mo · 14-day root cause report
What SG MAS TRM requires
Who it applies to
- All banks in Singapore, for whom Notices FSM-N05 and FSM-N06 are directly binding under s 29(1) of the Financial Services and Markets Act 2022
- Merchant banks, finance companies, insurers and capital markets services licensees, each under their own FSM-N-numbered Technology Risk Management and Cyber Hygiene Notices carrying the same substantive requirements
- Every MAS-regulated financial institution, for which the Technology Risk Management Guidelines themselves apply as supervisory guidance regardless of licence class
- Digital token (crypto) service providers, under Notice FSM-N30's technology risk management requirements
The Guidelines are MAS's own supervisory expectations, not a standard of care: para 2.2 states implementation "should be commensurate with the level of risk and complexity" of the FI's services, but "the degree of observance with the spirit of the Guidelines by an FI is an area of consideration by MAS" in supervision. Unchanged since 18 January 2021, they run chapters 3 to 15 — governance, the risk management framework, project management and security-by-design, software development, IT service management, IT resilience, access control, cryptography, data and infrastructure security, cyber security operations, cyber security assessment, online financial services and IT audit — plus Annexes A to C on application security testing, BYOD and mobile application security.
Notices FSM-N05 (Technology Risk Management) and FSM-N06 (Cyber Hygiene) sit on top of the Guidelines as binding law under section 29(1) of the Financial Services and Markets Act 2022, both effective 10 May 2024. FSM-N05 fixes numbers the Guidelines leave to judgement: a 4-hour ceiling on cumulative unscheduled downtime per critical system per rolling 12 months, a 4-hour recovery time objective validated at least every 12 months, notification to MAS within 1 hour of a relevant incident, and a root cause and impact report within 14 days. FSM-N06 makes six cyber hygiene practices binding — administrative account security, patch timeliness, written security standards, network perimeter defence, malware protection and multi-factor authentication for administrative accounts on critical systems and for internet access to customer information. GRCLens sourced this catalogue from the Notices addressed to banks; MAS issues the same substantive text under separate FSM-N numbers to merchant banks, finance companies, insurers, capital markets services licensees and digital token service providers.
MAS opened a consultation (10 June to 31 July 2026) on amending the FSM-N05/N06 Notices to add IT asset management, capacity management, immutable backups and continuous monitoring duties, expected in force around 2027 with a 12-month transition. GRCLens marks the rows those changes would touch as carrying a proposed requirement, never as if it were already binding.
How GRCLens supports SG MAS TRM
SG MAS TRM runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.
Guidance and binding duties, tagged apart
Every row carries its own source — 'guidance' for the Guidelines' 'should' paragraphs, 'binding' for the two Notices' 'must' paragraphs — so a bank can see at a glance which gaps are a supervisory expectation and which are a breach under s 29(1) FSMA 2022.
Every MAS clock as an indicator
The 1-hour incident notification, the 4-hour RTO validated every 12 months, the 4-hour cumulative downtime ceiling and the 14-day root cause report are one key risk indicator with amber at a single unmet duty — because a missed regulatory clock is not a maturity gap on a curve.
Cyber Hygiene tracked as its own floor
FSM-N06's six binding practices — administrative accounts, patching, security standards, perimeter defence, malware protection, MFA — sit in their own domain and their own indicator, distinct from the Guidelines' broader access and data security chapters.
2026 amendments flagged, never presented as in force
MAS's consultation on IT asset management, capacity management, immutable backups and continuous monitoring runs to 31 July 2026 with change expected around 2027. GRCLens marks the affected rows 'proposed' so a bank cannot mistake a consultation for a current obligation.
SG MAS TRM frequently asked questions
Are MAS's Technology Risk Management Guidelines legally binding?
No. Para 2.2 states the Guidelines are not a statement of the standard of care and should be applied commensurate with risk and complexity — but MAS considers an FI's observance of them in supervision. What is binding is the two Notices sitting alongside them: FSM-N05 (Technology Risk Management) and FSM-N06 (Cyber Hygiene), both issued under s 29(1) of the Financial Services and Markets Act 2022 and effective 10 May 2024.
What is the difference between FSM-N05 and FSM-N06?
FSM-N05 sets the numeric duties around critical systems: identify them, cap unscheduled downtime at 4 hours per rolling 12 months, validate a 4-hour RTO at least every 12 months, notify MAS within 1 hour of a relevant incident, file a root cause and impact report within 14 days, and protect customer information. FSM-N06 sets six cyber hygiene practices: administrative account security, patch timeliness, written security standards, network perimeter defence, malware protection and multi-factor authentication.
Does MAS require 99.95% system availability for banks?
No — that figure does not appear in the Notice. FSM-N05 para 5 sets a different kind of limit: maximum unscheduled downtime of 4 hours in total per critical system within any rolling 12-month period, not an availability percentage.
One platform, many obligations
See all supported frameworks → Every framework that applies in Singapore →

Talk to us about SG MAS TRM
Security Solution Consultants provides MAS TRM compliance advisory alongside the platform, so you can combine tooling with hands-on expertise.