2024-05-09

Added · Updated

Notice on Technology Risk Management

Operators and settlement institutions of designated payment systems, as well as digital payment token service providers, must establish frameworks to identify critical systems and maintain high availability, limiting unscheduled downtime to 4 hours annually. These entities are required to set a recovery time objective of no more than 4 hours for each critical system and validate this through testing at least once every 12 months. Upon discovering a relevant incident, entities must notify the Authority within 1 hour and submit a root cause and impact analysis report within 14 days. The notice takes effect on 10 May 2024 for operators and settlement institutions, and on 6 November 2024 for digital payment token service providers.

Monetary Authority of Singapore logo

Singapore

Monetary Authority of Singapore

Click to view thumbnail

MAS Notice No.: FSM-N13 Notice to operators and settlement institutions of designated payment systems and holders of payment services licence (digital payment token service) Financial Services and Markets Act 2022 Issue Date: 09 May 2024 NOTICE ON TECHNOLOGY RISK MANAGEMENT Introduction

  1. This Notice is issued pursuant to section 29(1) of the Financial Services and Markets Act 2022 (the “Act”) and applies to all the following entities regulated under the Payment Services Act 2019: (a) operators and settlement institutions of designated payment systems; (b) holders of a payment services licence that carry on a business of providing digital payment token service (“digital payment token service providers”), (each a “relevant entity”). Definitions
  2. For the purpose of this Notice---- “critical system” in relation to a relevant entity, means a system, the failure of which will cause significant disruption to the operations of the relevant entity or materially impact the relevant entity’s service to its customers, such as a system which— (a) processes transactions that are time critical; or (b) provides essential services to customers; “designated payment system” has the meaning given by section 2(1) of the Payment Services Act 2019; “digital payment token service” has the meaning given by section 2(1) of the Payment Services Act 2019;

“IT security incident” means an event that involves a security breach, such as hacking of, intrusion into, or denial of service attack on, a critical system, or a system which compromises the security, integrity or confidentiality of customer information; “operator” has the meaning given by section 2(1) of the Payment Services Act 2019; “payment service” has the meaning given by section 2(1) of the Payment Services Act 2019; “relevant incident” means a system malfunction or IT security incident, which has a severe and widespread impact on the relevant entity’s operations or materially impacts the relevant entity’s service to its customers; “settlement institution” has the meaning given by section 2(1) of the Payment Services Act 2019; “system” means any hardware, software, network, or other information technology (“IT”) component which is part of an IT infrastructure; “system malfunction” means a failure of any of the relevant entity’s critical systems. 3. Except where defined in this Notice or if the context otherwise requires, the expressions used in this Notice have the same meanings as in the Act. Technology Risk Management 4. A relevant entity must put in place a framework and process to identify critical systems. 5. A relevant entity must make all reasonable efforts to maintain high availability for critical systems. The relevant entity must ensure that the maximum unscheduled downtime for each critical system that affects the relevant entity’s operations or service to its customers does not exceed a total of 4 hours within any period of 12 months. 6. A relevant entity must establish a recovery time objective (“RTO”) of not more than 4 hours for each critical system. The RTO is the duration of time, from the point of disruption, within which a system must be restored. The relevant entity must validate and document at least once every 12 months, how it performs its system recovery testing and when the RTO is validated during the system recovery testing.

  1. A relevant entity must notify the Authority as soon as possible, but not later than 1 hour, upon the discovery of a relevant incident.
  2. A relevant entity must submit a root cause and impact analysis report to the Authority, within 14 days or such longer period as the Authority may allow, from the discovery of the relevant incident. The report must contain— (a) an executive summary of the relevant incident; (b) an analysis of the root cause which triggered the relevant incident; (c) a description of the impact of the relevant incident on the relevant entity’s— (i) compliance with laws and regulations applicable to the relevant entity; (ii) operations; and (iii) service to its customers; and (d) a description of the remedial measures taken to address the root cause and consequences of the relevant incident.
  3. A relevant entity must implement IT controls to protect customer information from unauthorised access or disclosure. Effective Date
  4. This Notice shall take effect on the following dates: (a) where a relevant entity is an operator or settlement institution of a designated payment system, on 10 May 2024; and (b) where a relevant entity is a digital payment token service provider, on 06 November