2024-05-09

Added · Updated

Notice on Technology Risk Management for Licensed Credit Bureaus

Licensed credit bureaus must establish a framework to identify critical systems and maintain high availability, ensuring maximum unscheduled downtime does not exceed 4 hours within any 12-month period. Each critical system requires a recovery time objective of no more than 4 hours, with validation and documentation of system recovery testing conducted at least annually. Upon discovering a relevant incident, bureaus must notify the Authority within 1 hour and submit a root cause and impact analysis report within 14 days. Additionally, licensed credit bureaus are required to implement IT controls to protect relevant person information from unauthorized access or disclosure.

Monetary Authority of Singapore logo

Singapore

Monetary Authority of Singapore

Click to view thumbnail

MAS Notice No.: FSM-N17 Notice to licensed credit bureaus Financial Services and Markets Act 2022 Issue Date: 09 May 2024 NOTICE ON TECHNOLOGY RISK MANAGEMENT Introduction 1 This Notice is issued pursuant to section 29(1) of the Financial Services and Markets Act 2022 (the “Act”) and applies to all licensed credit bureaus. Definitions 2 For the purpose of this Notice — “credit facility” has the meaning given by section 2 of the Credit Bureau Act 2016; “critical system” in relation to a licensed credit bureau, means a system, the failure of which will cause significant disruption to the operations of the licensed credit bureau or materially impact the licensed credit bureau’s service to a relevant person, such as a system which— (a) processes transactions that are time critical; or (b) provides essential services to relevant persons; “customer” has the meaning given by section 2 of the Credit Bureau Act 2016; “data subject” has the meaning given by section 2 of the Credit Bureau Act 2016; “IT security incident” means an event that involves a security breach, such as hacking of, intrusion into, or denial of service attack on, a critical system, or a system which compromises the security, integrity or confidentiality of relevant person information; “licensed credit bureau” has the meaning given by section 2 of the Credit Bureau Act 2016;

“member” has the meaning given by section 2 of the Credit Bureau Act 2016; “relevant incident” means a system malfunction or IT security incident, which has a severe and widespread impact on the licensed credit bureau’s operations or materially impacts the licensed credit bureau’s service to relevant persons; “relevant person” means a customer, data subject, or member; “relevant person information” means any information relating to, or any particulars of, any relevant person, where a named relevant person or group of named relevant persons can be identified, or is capable of being identified, from such information; “system” means any hardware, software, network, or other information technology (“IT”) component which is part of an IT infrastructure; and “system malfunction” means a failure of any of the licensed credit bureau’s critical systems. 3 Except where defined in this Notice or if the context otherwise requires, the expressions used in this Notice have the same meanings as in the Act. Technology Risk Management 4 A licensed credit bureau must put in place a framework and process to identify critical systems. 5 A licensed credit bureau must make all reasonable efforts to maintain high availability for critical systems. The licensed credit bureau must ensure that the maximum unscheduled downtime for each critical system that affects the licensed credit bureau’s operations or service to its relevant persons does not exceed a total of 4 hours within any period of 12 months. 6 A licensed credit bureau must establish a recovery time objective (“RTO”) of not more than 4 hours for each critical system. The RTO is the duration of time, from the point of disruption, within which a system must be restored. The licensed credit bureau must validate and document at least once every 12 months, how it performs its system recovery testing and when the RTO is validated during the system recovery testing.

7 A licensed credit bureau must notify the Authority as soon as possible, but not later than 1 hour, upon the discovery of a relevant incident. 8 A licensed credit bureau must submit a root cause and impact analysis report to the Authority, within 14 days or such longer period as the Authority may allow, from the discovery of the relevant incident. The report must contain — (a) an executive summary of the relevant incident; (b) an analysis of the root cause which triggered the relevant incident; (c) a description of the impact of the relevant incident on the licensed credit bureau’s— (i) compliance with laws and regulations applicable to the licensed credit bureau; (ii) operations; and (iii) service to relevant persons; and (d) a description of the remedial measures taken to address the root cause and consequences of the relevant incident. 9 A licensed credit bureau must implement IT controls to protect relevant person information from unauthorised access or disclosure. Effective Date 10 This Notice shall take effect on 10 May 2024.