2025-08-06

Added · Updated

Circular No. 22 of 2025 - Pre-Qualification, Compliance and Reporting Requirements for Digital Platforms by Digital Asset Management Companies

This circular mandates comprehensive cybersecurity, technical, and operational requirements for Digital Asset Management Companies (Digital AMCs) providing services through digital platforms and mobile applications. It establishes strict standards for infrastructure security, data protection, incident monitoring, and vulnerability management to ensure investor safety and operational integrity. Additionally, Digital AMCs must adhere to standardized monthly compliance reporting and implement formal complaint redressal and call center codes of conduct to enhance transparency and investor protection.

Mutual Funds Association of Pakistan logo

Pakistan

Mutual Funds Association of Pakistan

Click to view thumbnail

Circular No. 22 of 2025 - Pre-Qualification, Compliance and Reporting Requirements for Digital Platforms by Digital Asset Management Companies

The Securities and Exchange Commission of Pakistan (the "Commission") in exercise of its powers conferred under Section 282B(3) of the Companies Ordinance, 1984 (XLVII of 1984) read with provisions of Regulation 67AL(a)(ii) of the Non-Banking Finance Companies and Notified Entities Regulations, 2008 (the "NBFC Regulations") hereby specifies the following pre-qualification requirements for Digital Asset Management Company (Digital AMC) for seeking NOC from respective trustees.

1. Scope and Applicability

These requirements are applicable to Digital AMCs as well as the AMCs which are utilizing Digital Platforms for provision of services to their investors/unitholders.

2. Prerequisites for Obtaining NOC for Digital Platforms

The Digital AMC shall adhere to the following requirements for provision of Digital Asset Management Services through digital platforms:

2.1. The Digital AMCs are encouraged to comply with the below listed standard guidelines as may be amended/improved/replaced from time to time: a. Open Web Application Security Project (OWASP) Mobile Application Security Verification Standard; b. OWASP Mobile Application Security Testing Guide; and c. OWASP Web Application Security Testing.

2.2. The Digital AMCs providing DAMS or AMCs providing services through Digital Platforms shall ensure that adequate cybersecurity measures and controls are in place to ensure confidentiality, integrity and availability of the data and information. The controls shall include but not limited to: a. Secure Access Management infrastructure ensuring:

  • Implementation of approved policies and procedures for secure access management are available;
  • Policy of disabling user accounts of such employees who have left the organization in an immediate manner is effective;
  • Separation of user accounts across technology environments e.g. separate accounts to be used in development, test and production environments;
  • All IT administrative activities are performed using Privilege (Admin) Access Management Solution;
  • Minimum number of such Privilege (Admin) access user accounts with formal approval requirements and complete log of activity/access;
  • Clearly defined and efficiently implemented Inventory of Privileged Accounts and review frequency;
  • Access rights review document/policy for application is in place;
  • Creation, modification of rights, revocation of rights are performed after approvals from line manager with a clear policy framework in place;
  • Strong password policy is implemented which covers password complexity, minimum length, history and minimum age;
  • Access control requirements for information and information systems based on business needs and classification of information are defined considering the principle of least privilege access;
  • Shared accounts are discouraged unless approved by the CTO/CISO for a documented business reason;
  • Services accounts are configured to: disable interactive logon; and be monitored for inappropriate use.
  • Configure maximum number of failed attempts of authentication for user and service accounts, after which access to the accounts shall be blocked;
  • User access requests for third-party service suppliers shall be approved & validated subject to the condition that access is restricted to services supplied under contracts or agreements;
  • User accounts for third-party service suppliers shall be disabled upon expiry or cessation of contract or agreement; and
  • Implementation of multi-factor authentication shall be ensured for registration/signup of users.

b. Perimeter and Network Security is effective to:

  • Maintain high level network diagram of mobile application environment indicating the location of network devices, app and database servers and other attached components;
  • Ensure implementation of adequate security measures to protect against unauthorized access or attacks;
  • Validate that inbound security policies are enabled for in scope application environment;
  • Secure authentication mechanism is in placed to ensure that only Trusted Users are allowed to access the applications;
  • Logging and monitoring process on firewall are in place;
  • Validate the details of Encryption mechanism, Transport Layer Security (TLS) version, Digital certificate on application portal;
  • Prevent malware, such as viruses, spam, phishing attacks, denial-of-service attacks and other unauthorized access attempts, using specialized network security software and other appropriate prevention and detection resources, such as firewalls, intrusion detection systems and intrusion prevention systems;
  • Regularly review all software associated with network perimeter breach prevention systems and applications and the rules for analyzing suspicious code are updated regularly to remain current with existing and unplanned threats; and
  • A formal process is established and documented for identifying possible breaches in a network perimeter, capturing and containing the malicious code if possible, assessing the breach, determining the nature and impact of the breach, notifying management of the breach, minimizing the impact of the breach and documenting the steps taken when dealing with the incident. This process will apply to all network perimeters, whether internal, hybrid and/or public clouds.

c. Endpoint, Server and cloud security:

  • Versions and patches of all endpoints are updated till stable versions and secured;
  • Ensure that software installation and upgradation rights on servers/instance is only limited to the Authorized Person;
  • Software installation on endpoints are restricted and approved on a need-to-use basis;
  • End point must be secured using well known end point security solution including Endpoint Detection and Response (EDR) & advanced threat detection capabilities; and
  • Implementation of Continuous Threat monitoring external service including digital risk to identify any security weakness at the internet exposed infrastructure for timely remediation.

d. Application level Security ensuring:

  • All the components required for the application such as webserver and other components are updated and running on latest stable versions;
  • Web Application Firewall (WAF) are effectively implemented on customer facing interfaces;
  • Details are maintained on the latest Vulnerability Assessment and Penetration Testing (VAPT) conducted at least on annual basis of digital platforms, in-scope system, IT Infrastructure and database;
  • APIs are not using outdated Secure Sockets Layers (SSL)/Transport Layer Security (TLS) protocols;
  • Secure Software Development Life Cycle (SSDLC) process during each phase must be implemented which will include Static Application Security Testing (SAST) & Dynamic Application Security Testing (DAST) activities before promoting any release to production environment; and
  • API security requirements must be considered including Weak authentication/authorization controls, misconfiguration, business logic abuse (credential stuffing, account takeover), Server-side request forgery (SSRF).

e. Data Security:

  • Data security policy and procedure are in place;
  • Classification of data against pre-defined categories in light of the approved policy;
  • Relevant documentation is maintained and reviewed at a defined frequency to ensure adherence and effective implementation;
  • Appropriate access controls are established for accessing the data, including requiring authentication for access, which is not public;
  • Encrypt data at rest (including backups) and in transit use strong and non-obsolete cryptographic algorithms;
  • Appropriate measures are undertaken to avoid accidental deletion or overwrite of data/information;
  • Ensure that the separate channels are being used for storage and transmission of critical data; and
  • Appropriate controls must be implemented for the prevention of data leakage incidents.

f. Incident surveillance and monitoring;

  • Ensure that incident management Policies and Procedures are in place for Incident Management and Reporting covering responsibilities for planning, detecting and responding to cyber security incidents, resources assigned to cyber security incident planning, detection and response activities including guidelines for triaging and responding to cyber security events and cyber security incidents;
  • Ensure that the anomalies are detected and resolved in a timely manner;
  • Ensure that incident management procedure is implemented and appropriate reporting matrix for such incidents is maintained;
  • Incident response functions shall be implemented in application system, responses to any incident should be documented for record;
  • Ensure that cyber security incident response plan is exercised during regular intervals to ensure it remains fit for purpose; and
  • Ensure that the potential risks and vulnerabilities are identified in a timely manner, which could impact business continuity.

g. Vulnerability Management:

  • Ensure that security patches or updates are being identified & applied in a timely manner to applications, operating systems, drivers and firmware. It is essential that all assets are regularly identified within the environment using an automated method of asset discovery tool or a vulnerability scanner. Moreover, ensure review and updating of the risk assessment.

h. Patch Management:

  • Log of patches deployed are documented;
  • Formal process of approval is in place for patch testing, User Acceptance Testing (UAT) and migration to production;
  • Approved patch management policies and procedures should be in place;
  • Procedure for approval of tested patches should be defined. UATs of the patches should be in segregated environment; and
  • Validate that patches are applied on test system first before provisioning to live.

i. Logging and backups:

  • Validate that policies and procedures are approved and implemented for Backup and recovery of in-scope application
  • Validate that appropriate logging with sufficient details is enabled at application, platform, database and operating system levels;
  • Validate that system log files are protected against unauthorized modification through appropriate technical controls. Logs must be stored in a secure manner to ensure tamper-evidence. Administrative access to logs must be monitored, and any changes or access attempts shall be recorded and auditable;
  • Frequency of backups should be defined in the system for both production and development and the same shall be documented in relevant policy;
  • Backups must be encrypted;
  • Adopt the 3-2-1 rule for data storage i.e. have 3 copies of information (1 original and 2 backups), saved on 2 different media types, with 1 copy kept off site;
  • Back-ups maintained must be kept immutable form. It would be more appropriate to consider air-gapped backup solution ensuring the availability of clean copy of back-up in case of a ransomware attack;
  • Data restoration process should be in place in application system and documented; and
  • Backup logs should be generated and verification of the backup restoration log should be in practice.

2.3. The Digital AMC shall avail cybercrime insurance policy to indemnify losses that may arise due to cyber-attack/cybercrime on their digital platforms.

2.4. The Digital AMCs shall ensure compliance with the additional requirements relating to the Smartphone Application, as provided in Annexure – A to this Circular.

2.5. In case of a smart phone application, the Digital AMC at the time of launching of app shall provide license status along with NOC granted by the Trustees for respective App to Google Play Store and/or App Store. Proof for the same shall subsequently be provided to the Commission and maintained by the Digital AMC as record. The App on Google Play Store/App Store (Apple Inc.) shall only be hosted with the URL which is provided on SECP Approved Digital Platform List.

2.6. Data related to Personal Identifiable Information (PII) shall not be stored on any cloud infrastructure outside the jurisdiction of Pakistan. Explanation: PII means any information relating to an identified or identifiable natural person who can be identified, directly or indirectly, in particular by reference to an identifier. However, the global cloud infrastructure resources and computing services may be utilized, including but not limited to networks, servers, applications, and services such as on-demand self-service, broad network access, and resource pooling. Furthermore, when utilizing software application services through global cloud infrastructure, Digital AMCs shall ensure the encryption or anonymization of customers' PII, preventing their identities from being readily inferred. For purposes of clarification, the Digital AMCs shall store sensitive PII within Pakistan with one cloud provider, while it may employ another local or foreign cloud provider for specific software application services. These services may include, but are not limited to, Infrastructure as a Service (IaaS), Platform as a Service (PaaS), Software as a Service (SaaS), Function as a Service (FaaS), Backup as a Service (BaaS), Disaster Recovery as a Service (DRaaS), or Security as a Service (SECaaS). Data collected by Digital AMCs through Digital Platforms is subject to privacy of the investor/unitholder/user and shall be used only for activities related to registration and operations of an account by an individual with the respective Digital AMCs. A Digital AMC shall keep the data of the investor/unitholder/user strictly confidential, except in the following circumstances: a. Disclosure of information with the specific written or recorded consent of investor/unitholder/user. b. Release, submission or exchange of information with other financial institutions/licensed entities for transaction processing including Centralized KYC/AML/CFT screening activities. c. Disclosure of information upon orders of a court of competent jurisdiction or any government office or agency authorized by law. d. Disclosure to third party service providers solely for the purpose of assisting or rendering services to the Digital AMC in the administration and provision of its DAMS business; and e. Disclosure to third parties such as insurance companies, solely for the purpose of insuring the investor/unitholder/user from fraud or unauthorized charges.

3. Compliance Reporting and Grievance Redressal Mechanism/Guidelines

3.1. The Digital AMC shall: a. ensure compliance with the requirements as laid down under Circular No. 01 of 2010 dated January 15, 2010 related to Specialized Companies Return System (SCRS) or any other subsequent requirement as may be specified from time to time by the Commission; b. conduct a self-assessment every six months to evaluate its compliance with the prevailing regulatory framework, including the specific requirements of this Circular, and must duly inform its BOD of the results; c. prepare and submit a monthly report to the Commission, containing unitholders' data for each CIS under its management. The unitholders shall be categorized into two distinct classes, namely "corporate" and "retail". The report shall include, but not be limited to, the following information for each class of unitholders:

  • Total number of unitholders in each class (corporate and retail);
  • Total number of units held by each class of unitholders;
  • Aggregate value of assets held by each class of unitholders;
  • Any significant transactions or changes in the CIS's composition affecting each class of unitholders;
  • Any material information or disclosures relevant to the interests of corporate and retail unitholders; and
  • Gender Disaggregated Data as per Annexure – B. d. share a monthly list of distributors appointed for distribution of CIS on Digital Platform along with following details:
  • Total Monthly CIS Sales through the distributors (digital distributor and other than digital distributor AUM); and
  • Percentage of CIS Sales through Digital Distributor and other than digital distributor on cumulative basis. e. establish and implement written policies and procedures to ensure that complaints from investors are handled in a timely and appropriate manner. f. develop an efficient complaint management process for effective handling of related complaints. It shall prominently display on its website the Complaint redressal mechanism. A system shall be developed whereby the investors can lodge their complaints through the following multiple channels:
  • Call Centre - Investor shall be able to call at a toll-free number of the digital portal/platform/website during the business hours; Such access may also be offered through other cost-effective mediums of audio/visual communication (i.e., WhatAapp messaging, call or any other). Code of Conduct for Call Centers is enclosed as Annexure C.
  • Details of Dedicated Point of Contact - Provide name, designation, email address and phone number of personnel designated to deal with DAMS related enquiries and complaints/issues; and
  • Lodge Online Complaint - Investor shall also be able to lodge his/ her complaint through a complaint form available at the digital platforms. g. Every Complainant shall be given a unique Complaint Number for future tracking and all necessary information of the complainant including nature of complaint shall be logged to facilitate its investigation and resolution; h. specify maximum timelines for acknowledgement and resolution of complaints; and i. report to the Commission on a monthly basis, the following information:
  • No. of complaints outstanding from previous month;
  • Total no. of complaints during current month;
  • Nature of repetitive complaints;
  • No. of complaints resolved;
  • No. of complaints outstanding;
  • Satisfaction ratio;
  • Average time taken for disposal of a complaint; and
  • Monthly trend analysis of complaints received and disposed.

3.2. The Digital AMC shall adhere to all the standard requirements applicable to an AMC, unless expressly modified or relaxed by the above-stipulated requirements.

More like this from MUFAP

We email you every new MUFAP publication the day it's published.

Topics
Share