Skip to content
Cyber Horizon
All frameworks

// APAC Standards

MAS Technology Risk Management Guidelines Compliance Software

The Monetary Authority of Singapore Technology Risk Management Guidelines set out risk management principles and best practices for all MAS-regulated financial institutions including banks, insurers, and payment firms.

Framework at a glance

Short name

MAS TRM

Version

2021

Category

APAC Standards

Controls

45

What MAS TRM covers

45 controls across 6 domains — every one tracked, owned and evidenced in Cyber Horizon.

Govern

9 controls
  • TRM-1.1 Board and Senior Management Oversight
  • TRM-1.2 Technology Risk Framework
  • TRM-1.3 Technology Risk Awareness
  • TRM-2.1 IT Strategic Plan
  • TRM-2.2 IT Project Management

Protect

18 controls
  • TRM-2.3 IT Service Management
  • TRM-3.1 IT Infrastructure Resilience
  • TRM-3.2 Capacity Management
  • TRM-3.3 Change Management
  • TRM-3.4 Patch Management

Identify

6 controls
  • TRM-5.2 Cyber Risk Assessment
  • TRM-5.4 Vulnerability Management
  • TRM-8.1 Third-Party Risk Management
  • TRM-8.2 Outsourcing Risk Assessment
  • TRM-9.2 Application Security Testing

Detect

7 controls
  • TRM-5.3 Security Operations and Monitoring
  • TRM-6.2 Incident Detection and Reporting
  • TRM-8.3 Ongoing Monitoring of Third Parties
  • TRM-10.1 Audit Logging and Monitoring
  • TRM-10.2 Log Retention

Respond

1 controls
  • TRM-6.1 Cyber Incident Response Plan

Recover

4 controls
  • TRM-6.3 Post-Incident Review
  • TRM-7.1 Business Continuity Planning
  • TRM-7.2 Recovery Time and Recovery Point Objectives
  • TRM-7.3 Crisis Communication

How Cyber Horizon automates MAS TRM

Every MAS TRM control lives in a shared control library, crosswalked to the other frameworks you run — evidence collected once counts everywhere it applies.

Evidence is collected automatically from your connected tools, with owners, review cadences and gaps tracked continuously instead of at audit time.

Audit packs generate on demand, and the risk register, vendor risk and threat intelligence sit in the same platform — one evidence trail across your whole programme.

Frequently asked questions

What is MAS Technology Risk Management Guidelines?

The Monetary Authority of Singapore Technology Risk Management Guidelines set out risk management principles and best practices for all MAS-regulated financial institutions including banks, insurers, and payment firms.

How many controls does MAS Technology Risk Management Guidelines have?

MAS Technology Risk Management Guidelines (2021) has 45 controls in Cyber Horizon's catalogue, organised across 6 domains.

How does Cyber Horizon help with MAS Technology Risk Management Guidelines?

Cyber Horizon maps MAS Technology Risk Management Guidelines into a shared control library alongside every other framework you run, so evidence collected once counts towards MAS TRM and everything else it overlaps with. Controls, evidence status and audit packs live in one place, with automated collection from your connected tools.

See MAS TRM mapped to your environment

Start with the free 20-question readiness check — no signup — or get a personal walkthrough of MAS TRM in Cyber Horizon.