Malaysia BNM Updated Technology Risk Policy
Bank Negara Malaysia — Policy Document on Risk Management in Technology (RMiT) (updated)
Malaysia
RAI-MY-NA-BNMDRXX-2023Malaysia's central bank reissued its Risk Management in Technology policy document on 28 November 2025 (BNM/RH/PD 028-98), superseding the June 2023 edition. It strengthens requirements on financial institutions covering board accountability, cyber resilience, technology risk management and third-party risk. The document is technology-neutral: it sets no AI-specific obligations, and Appendix 9 on emerging technologies requires consultation with the Bank before first-time adoption for critical systems without naming AI.
Summary
The Bank Negara Malaysia (BNM) Policy Document on Risk Management in Technology (RMiT), updated and issued on 28 November 2025, sets forth enhanced requirements for financial institutions to manage technology and cyber risks effectively. This revision significantly strengthens expectations around board accountability, cyber resilience, and the ethical governance of emerging technologies. It mandates stricter cybersecurity controls, including multi-factor authentication (MFA) and zero-trust architecture (ZTA), and introduces robust requirements for third-party risk management, emphasizing continuous monitoring and explicit exit strategies. The policy also reinforces incident reporting protocols and operational resilience through mandatory annual cyber drills. The RMiT aims to shift financial institutions from a compliance-based oversight model to one of proactive, risk-informed resilience, addressing the escalating cyber threats and the rapid adoption of innovative financial technologies within Malaysia's financial sector.
Full article
Read full text ↗Overview
The Bank Negara Malaysia (BNM) Policy Document on Risk Management in Technology (RMiT), officially updated and issued on 28 November 2025, serves as a cornerstone for regulating technology and cyber risk within the Malaysian financial sector. This comprehensive policy document outlines the stringent requirements that financial institutions (FIs) must adhere to in managing their technology-related risks, reflecting BNM's commitment to strengthening the resilience and security of the financial system against an evolving threat landscape. The 2025 revision represents a significant evolution from previous iterations, pushing beyond incremental updates to demand deeper accountability, broader coverage, and stronger resilience from regulated entities. It is designed to ensure that FIs not only comply with regulatory mandates but also proactively build robust frameworks capable of anticipating and mitigating complex digital threats.
The updated RMiT policy places a sharper emphasis on critical areas such as board accountability for technology risks, enhancing cyber resilience capabilities, and establishing ethical governance frameworks for emerging technologies, including artificial intelligence. It introduces new and reinforced requirements across various domains, including advanced cybersecurity controls, comprehensive third-party risk management, and rigorous operational resilience testing. The policy's overarching goal is to transition financial institutions from a reactive, compliance-centric approach to a proactive, risk-informed strategy, enabling them to navigate the complexities of accelerating cloud adoption, increasing regulatory scrutiny, and escalating cyber threats. By setting clear expectations and providing a structured framework, BNM aims to foster a secure and stable financial ecosystem that can confidently embrace technological innovation while effectively managing its inherent risks.
Definitions
While the full text of the 2025 RMiT policy document would provide exhaustive definitions, based on the context, several key terms are central to understanding its scope and requirements. 'Technology Risk' refers to the risk of financial loss, disruption, or reputational damage arising from the use of technology, including hardware, software, and data. This encompasses risks related to system failures, data breaches, cyberattacks, and inadequate technology infrastructure. 'Cybersecurity' is defined as the protection of information systems from theft or damage to the hardware, software, and electronic data, as well as from disruption or misdirection of the services they provide. The policy mandates specific controls and measures to achieve and maintain a high level of cybersecurity within financial institutions.
'Third-Party Risk Management (TPRM)' pertains to the processes and controls financial institutions must implement to manage risks associated with outsourcing services or engaging with external vendors, such as cloud service providers (CSPs) and fintech partners. This includes due diligence, contract management, and continuous monitoring of third parties. 'Operational Resilience' refers to an institution's ability to deliver critical functions in the face of adverse events, including cyber incidents. The policy emphasizes building resilience through measures like incident response planning and regular cyber drills. 'Emerging Technologies' encompasses new and rapidly evolving technologies, such as artificial intelligence (AI), distributed ledger technology (DLT), and advanced analytics, which introduce novel opportunities but also complex risks that require specific governance and risk management considerations. 'Multi-Factor Authentication (MFA)' is a security system that requires more than one method of authentication from independent categories of credentials to verify a user's identity, while 'Zero-Trust Architecture (ZTA)' is a security model that eliminates implicit trust in any network segment, requiring continuous verification for all users and devices, regardless of their location.
Governance and Institutional Framework
The updated RMiT policy significantly elevates the importance of robust governance and institutional frameworks within financial institutions, particularly emphasizing board-level accountability for technology and cyber risks. The policy mandates that the board of directors and senior management assume explicit and active oversight roles in managing technology risk at an enterprise level. This goes beyond mere compliance, requiring boards to demonstrate a deep understanding of the institution's technology risk posture, approve risk appetite statements, and ensure that adequate resources are allocated for technology risk management. This shift is intended to embed technology risk considerations into the core strategic decision-making processes of FIs, moving it from a purely operational concern to a fundamental aspect of corporate governance. The policy also requires clear reporting structures and oversight mechanisms to maintain accountability throughout the lifecycle of technology assets and services, ensuring that emerging risks are identified, assessed, and mitigated promptly.
Furthermore, the policy introduces enhanced governance requirements specifically for the adoption and use of innovative financial technologies. Financial institutions are now expected to establish an appropriately cautious approach to managing risks arising from emerging technologies, considering potential unintended consequences related to fairness, ethics, legal liabilities, and impacts on vulnerable customers. This necessitates the establishment of clear acceptance criteria for deploying new technologies, robust internal controls, and continuous monitoring mechanisms. The framework encourages FIs to integrate technology risk management into their broader enterprise risk management (ERM) framework, fostering a holistic view of risks across the organization. This integrated approach ensures that technology risk is not managed in isolation but is considered alongside other financial, operational, and strategic risks, thereby enhancing the overall resilience and stability of the institution.
Key Focus Areas
The 2025 RMiT policy introduces several key focus areas designed to fortify the technology and cyber resilience of financial institutions. A primary area is the mandatory implementation of advanced cybersecurity controls. This includes making multi-factor authentication (MFA) compulsory for high-risk transactions to safeguard against account takeovers and fraud, a critical measure given the prevalence of legacy banking systems in Malaysia. Furthermore, FIs are encouraged to adopt a zero-trust architecture (ZTA), which eliminates implicit trust within networks and demands continuous verification. This transition necessitates significant infrastructure overhauls, including micro-segmentation, identity-aware proxies, and real-time threat analytics, moving beyond traditional perimeter-based security models. Cloud security governance has also become a top priority, with BNM imposing stricter due diligence requirements for cloud service providers (CSPs) and explicit accountability for shared responsibility models, compelling FIs to assess CSP compliance on aspects like data localization and encryption standards.
Another significant focus is the fundamental transformation of third-party risk management (TPRM). The policy mandates enhanced due diligence for all external partners, including fintechs and critical vendors, requiring comprehensive assessments of their cybersecurity controls, data protection practices, and business continuity measures. A crucial new element is the continuous monitoring mandate, which demands ongoing oversight of third-party cyber risks, moving away from periodic reviews. This necessitates automated solutions for vulnerability assessment and risk tracking, as manual processes are deemed insufficient for the volume and complexity of vendor relationships. Additionally, the policy reinforces incident reporting and operational resilience. FIs must adhere to stringent new requirements for rapid reporting of cybersecurity incidents to BNM, demanding real-time monitoring and pre-approved escalation protocols. Beyond initial reporting, thorough post-incident reviews are mandated to implement long-term mitigations. Operational resilience is further strengthened through compulsory annual cyber drills, designed to demonstrate an institution's ability to respond effectively to cyber incidents and maintain critical functions under various threat scenarios.
Implementation Framework
The implementation framework for the updated RMiT policy presents significant challenges and strategic imperatives for financial institutions in Malaysia. Many FIs, particularly smaller ones, face a talent gap, lacking specialized in-house teams and qualified cybersecurity professionals with the expertise required to fulfill RMiT's stringent mandates. This includes areas such as advanced third-party vendor assessments, demonstrating board-level accountability for technology risks, and deploying complex security frameworks like zero-trust architectures and advanced threat monitoring. The policy's requirements for continuous monitoring, automated threat detection, and integrated response workflows necessitate a level of technical sophistication and human capital that many institutions currently do not possess. Bridging this talent and knowledge gap often requires FIs to seek external expert partners or invest heavily in upskilling their existing workforce, which can strain budgets and timelines.
Furthermore, technological debt accumulated through years of operating on outdated infrastructure poses another major hurdle. Many Malaysian FIs still rely on core banking systems designed decades before modern security requirements, such as MFA and API security protocols, became mandatory. These legacy platforms frequently lack the architectural flexibility to support RMiT's advanced security controls without extensive and expensive modifications. The cost of modernization extends beyond simple software upgrades, often requiring complete infrastructure overhauls, complex data migration projects, and extensive staff retraining. For smaller institutions, these capital expenditures can represent a significant portion of annual IT budgets, forcing difficult trade-offs between compliance initiatives and other strategic investments. The policy implicitly encourages a structured, knowledgeable approach to navigate these nuances, advocating for sustainable improvements to an institution's risk posture rather than ad-hoc measures that may not withstand regulatory scrutiny or provide lasting resilience.
Monitoring and Evaluation
The updated RMiT policy places a strong emphasis on continuous monitoring and rigorous evaluation mechanisms to ensure the ongoing effectiveness of technology risk management frameworks within financial institutions. FIs are mandated to implement continuous monitoring of potential security vulnerabilities, particularly in the context of third-party risk management. This implies an ongoing oversight of cyber risks associated with external vendors, moving beyond traditional annual or ad-hoc reviews. Such continuous monitoring requires sophisticated tools and processes for real-time threat intelligence, anomaly detection, and proactive identification of security gaps across interconnected systems. The objective is to enable institutions to detect and respond to emerging threats swiftly, thereby reducing the dwell time of attacks and preventing breaches from cascading across their digital ecosystems.
A critical component of the evaluation framework is the requirement for mandatory annual cyber drills. These drills are designed to test and demonstrate an institution's ability to respond effectively to cyber incidents and maintain critical functions through various threats and scenarios. The policy mandates that FIs conduct thorough post-incident reviews following any cybersecurity incident. These reviews are not merely for documenting events but are crucial for identifying root causes, assessing the effectiveness of response protocols, and implementing long-term mitigations to prevent recurrence. The goal is to foster a culture of continuous learning and improvement in operational resilience. Through these monitoring and evaluation requirements, BNM aims to ensure that financial institutions not only establish robust controls but also regularly assess and enhance their efficacy, adapting to the dynamic nature of cyber threats and technological advancements.
Penalties, Liability, and Appeals
While the provided context does not explicitly detail specific penalties, liability provisions, or an appeals process within the Bank Negara Malaysia (BNM) Policy Document on Risk Management in Technology (RMiT), it is universally understood that non-compliance with such a critical regulatory policy for financial institutions carries significant implications. Failure to adhere to the RMiT's stringent requirements can lead to severe regulatory scrutiny, which may result in formal warnings, directives for remediation, or more substantial enforcement actions by BNM. These actions could include administrative penalties, fines, or other supervisory measures designed to compel compliance and deter future violations. The financial sector is heavily regulated, and bodies like BNM possess broad powers to ensure the stability and integrity of the system. Therefore, institutions found to be in breach of RMiT requirements would likely face direct financial repercussions and reputational damage.
Beyond direct penalties, non-compliance with RMiT exposes financial institutions to heightened operational vulnerabilities. Weaknesses in technology risk management, cybersecurity controls, or third-party oversight can lead to data breaches, system outages, and other cyber incidents, which in turn can result in significant financial losses, legal liabilities to customers and other stakeholders, and a severe erosion of public trust. The policy's emphasis on board accountability suggests that individual directors and senior management could face increased scrutiny or even personal liability for systemic failures in technology risk governance. While a formal appeals process for specific RMiT-related enforcement actions is not outlined in the provided excerpts, financial institutions typically have avenues to engage with regulators regarding compliance interpretations or to challenge supervisory findings through established administrative procedures within the Malaysian legal and regulatory framework. The overarching goal of the policy is proactive risk mitigation, making the avoidance of non-compliance and its associated consequences a strategic imperative for all regulated entities.
Relationship to Other Instruments
The Bank Negara Malaysia (BNM) Policy Document on Risk Management in Technology (RMiT) operates within a broader regulatory ecosystem and, while specific to technology risk, interacts with and complements other regulatory instruments. The Capco source highlights a key challenge for financial institutions: 'regulatory fatigue, as institutions struggle to reconcile RMiT requirements with overlapping obligations from regulators such as the Securities Commission (SC).' This indicates that FIs must navigate a complex landscape where RMiT's mandates on cybersecurity, data protection, and governance may intersect with requirements from other Malaysian financial regulators concerning market integrity, investor protection, or specific capital market activities. Therefore, institutions need to adopt an integrated approach to compliance, ensuring that their technology risk management frameworks satisfy the demands of all relevant authorities without creating fragmented or contradictory processes.
While RMiT is a national policy document, its principles and requirements align with global best practices and emerging international regulatory trends in cybersecurity and operational resilience. The search results mention various international frameworks such as the EU's Digital Operational Resilience Act (DORA), the Network and Information Security (NIS2) Directive, NIST, and ISO 27001 in related discussions. Although RMiT is not directly derived from these, its focus on areas like board accountability, cyber resilience, third-party risk management, and incident reporting reflects a global convergence in regulatory expectations for financial sector technology risk. This alignment suggests that compliance with RMiT can contribute to an institution's ability to meet similar standards in other jurisdictions or to engage with international partners who adhere to comparable frameworks. The policy thus serves as a critical domestic instrument that is both tailored to the Malaysian context and informed by global developments in technology risk governance.
International Alignment
While the Bank Negara Malaysia (BNM) Policy Document on Risk Management in Technology (RMiT) is a national regulation tailored for the Malaysian financial sector, its core principles and requirements demonstrate a strong alignment with international best practices and emerging global standards in cybersecurity and operational resilience. The policy's emphasis on robust governance, board accountability for technology risks, comprehensive cyber resilience strategies, and stringent third-party risk management mirrors the concerns and regulatory directions seen in major financial hubs worldwide. For instance, the European Union's Digital Operational Resilience Act (DORA) and the Network and Information Security (NIS2) Directive, though distinct, share common objectives with RMiT in mandating enhanced ICT risk management, incident reporting, and supply chain security for critical entities, including financial institutions. This convergence suggests that BNM's approach is consistent with a global trend towards strengthening the digital resilience of the financial system against increasingly sophisticated cyber threats.
Furthermore, the policy's requirements for implementing advanced cybersecurity controls, such as multi-factor authentication (MFA) and zero-trust architecture (ZTA), and its focus on cloud security governance, reflect widely accepted security frameworks and recommendations from international bodies and standards organizations like NIST (National Institute of Standards and Technology) and ISO 27001. Although RMiT does not explicitly reference these international standards as binding, the underlying principles and technical controls it mandates are often consistent with them. This alignment facilitates a degree of interoperability and understanding for financial institutions operating across borders or engaging with international technology vendors. By adopting a policy framework that incorporates globally recognized security and risk management tenets, BNM not only enhances the stability of its domestic financial sector but also positions Malaysian financial institutions to better participate in the interconnected global financial system, fostering trust and facilitating cross-border collaborations while maintaining a high standard of digital security.
Implementation Timeline
| Milestone | Date | Notes |
|---|---|---|
| Exposure Draft Issued | 2024-11-07 | Consultative Exposure Draft issued by BNM for public feedback, proposing extensions of RMiT standards to smaller FIs and other market participants. |
| Policy Document Issued | 2025-11-28 | The revised Policy Document on Risk Management in Technology (RMiT) was officially issued by Bank Negara Malaysia. |
| Effective Date | 2025-11-28 | The updated RMiT policy came into effect for various organizations within the financial sector. |
Sources and References
| Source | Type |
|---|---|
| Bank Negara Malaysia: Revised Policy Document on Risk Management in Technology (RMiT) | government |
| Bank Negara Malaysia: Policy Document on Risk Management in Technology (RMiT) (PDF) | official |
Requirements for a company
What an organisation has to do under Malaysia BNM Updated Technology Risk Policy, at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
12- Obtain board approval for the Technology Risk Management Framework.Financial institutions.
- Senior management must implement the Technology Risk Management Framework.Senior management of financial institutions.
- Appoint accountable roles for technology risk, such as CISO or Head of Technology Risk.Senior management of financial institutions.
- Integrate technology risk into the enterprise risk management framework.Financial institutions.
- Report significant incidents to Bank Negara Malaysia.Financial institutions.
- Deploy multi-factor authentication as a standard control for access to sensitive systems.Financial institutions.
- +6 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under Malaysia BNM Updated Technology Risk Policy, most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Financial institutions. | Obtain board approval for the Technology Risk Management Framework. “Boards must approve a Technology Risk Management Framework (TRMF)” | — | — | Critical |
| 2 | Senior management of financial institutions. | Senior management must implement the Technology Risk Management Framework. “Senior management must implement the TRMF” | — | — | Critical |
| 3 | Senior management of financial institutions. | Appoint accountable roles for technology risk, such as CISO or Head of Technology Risk. “appoint accountable roles (e.g., Chief Information Security Officer, Head of Technology Risk)” | — | — | Critical |
| 4 | Financial institutions. | Integrate technology risk into the enterprise risk management framework. “integration of technology risk into enterprise risk management (ERM)” | — | — | Critical |
| 5 | Financial institutions. | Report significant incidents to Bank Negara Malaysia. “mandatory reporting to BNM for significant incidents” | Upon incident occurrence | — | Critical |
| 6 | Financial institutions. | Deploy multi-factor authentication as a standard control for access to sensitive systems. “multi-factor authentication (MFA) as a standard control for access to sensitive systems” | — | — | Critical |
| 7 | Financial institutions deploying cloud for critical workloads. | Document cloud risk assessments, mitigation, data flows, and contractual protections for critical workloads. “FIs required to document cloud risk assessments, mitigation measures, data flows, and contractual protections before deploying cloud for critical workloads.” | Before deploying cloud for critical workloads | — | Critical |
| 8 | Boards of financial institutions. | Ensure robust due diligence, contractual protections, and ongoing oversight for third parties. “boards must ensure robust due diligence, contractual protections and ongoing oversight.” | Before engaging third parties | — | Critical |
| 9 | Financial institutions. | Conduct regular security testing, tabletop exercises, and live recovery drills. “more emphasis on testing, including regular security testing, tabletop exercises, and live recovery drills” | — | — | Critical |
| 10 | Financial institutions. | Maintain evidence of testing, risk assessments, third-party due diligence, and management reports. “FIs must maintain evidence of testing, risk assessments, third-party due diligence, and management reports.” | — | — | Critical |
| 11 | Financial institutions. | Undertake self-assessments to determine if the institution meets the 'large financial institution' threshold. “FIs are required to undertake self-assessments to determine whether they meet the 'large financial institution' threshold” | — | — | Important |
| 12 | Financial institutions. | Update policies and procedures to align with the Technology Risk Management Framework. “FIs must embed TRMF into their ERM, update policies and procedures” | — | — | Important |
Related Regulations
Policy Document on Risk Management in Technology (RMiT)
Malaysia97% similar
Malaysia - Technology Risk Management Guidelines
Malaysia93% similar
Singapore - AI Model Risk Management
Singapore87% similar
Thailand - AI Risk Management Guidelines
Thailand87% similar
Qatar - AI Guidelines for Finance (2024)
Qatar86% similar
© Regulations.AI using Gemini 2.5 Flash · updated on 04-Aug-2026