Policy Document on Risk Management in Technology (RMiT)

Policy Document on Risk Management in Technology (RMiT)

Malaysia

RAI-MY-NA-FINANCI-2023
Repealed(No longer in effect)
PolicyRisk ManagementSafety, Testing, and Evaluation
Export PDF

Malaysia's 2023 BNM RMiT policy updated technology risk management for financial institutions, enhancing cybersecurity and operational resilience against evolving digital threats.

Summary

The Bank Negara Malaysia (BNM) Policy Document on Risk Management in Technology (RMiT), issued on June 1, 2023, updated the regulatory framework for technology risk in Malaysia's financial sector. It aimed to fortify the resilience and security of financial institutions against evolving cyber threats, ensuring robust technology risk management capabilities. The policy applied broadly to various licensed financial entities, emphasizing proactive management of emerging risks from increasing digitalization.

Full article

Read full text ↗

Overview

The Bank Negara Malaysia (BNM) Policy Document on Risk Management in Technology (RMiT), issued on June 1, 2023, represented a significant update to the regulatory framework governing technology risk within Malaysia's financial sector. This crucial document superseded an earlier version issued on January 1, 2020, aiming to fortify the resilience and security of financial institutions against an evolving landscape of technological and cyber threats. The primary objective of the 2023 RMiT was to ensure that financial institutions operating within Malaysia maintain robust technology risk management capabilities, thereby safeguarding public confidence in the financial system. It applied broadly to licensed banks (including digital banks), investment banks, Islamic banks, insurers, takaful operators, prescribed development financial institutions, approved e-money issuers, and operators of designated payment systems. The policy document underscored the necessity for these entities to not only manage existing technology risks effectively but also to proactively address emerging risks associated with new technologies and increasing digitalisation.

The issuance of the 2023 RMiT was a direct response to the prevalent use of technology in financial services, which necessitated enhanced controls and expertise to prevent operational disruptions and combat sophisticated digital crimes. It sought to improve financial institutions' management of technology risk, including cyber risk, by setting out clear policy objectives and minimum requirements. The document emphasized a risk-based approach, acknowledging that the robustness of risk controls should be commensurate with the size, complexity, and level of technology use by each financial institution. Consequently, larger and more complex institutions, or those with a high degree of digitalisation and third-party linkages, were expected to adopt more stringent risk controls. The policy's overarching goal was to ensure a secure and resilient financial ecosystem capable of withstanding advanced cyber threats and maintaining continuous service availability.

Definitions

While the full text of the 2023 Policy Document on Risk Management in Technology (RMiT) is not publicly detailed in the provided snippets, regulatory documents of this nature typically define key terms to ensure consistent interpretation and application across the regulated entities. Central to the RMiT would be the definition of 'Technology Risk,' encompassing potential losses arising from the failure or inadequacy of information technology systems, infrastructure, or processes, including cybersecurity incidents. 'Cyber Risk' would be a subset, specifically referring to risks related to cyberattacks, data breaches, and other malicious activities targeting digital assets and systems.

Other critical terms likely defined or implicitly understood within the RMiT include 'Critical Systems,' referring to technology systems whose failure would significantly impair a financial institution's ability to provide essential services or cause substantial financial or reputational damage. 'Third-Party Technology Providers' would cover external vendors and service providers that financial institutions rely on for technology-related services, highlighting the need for robust oversight of outsourced functions. 'Operational Resilience' would likely be defined as the ability of a financial institution to deliver critical operations through disruption, emphasizing preparedness, response, and recovery capabilities. These definitions would form the bedrock for financial institutions to accurately assess their risk exposure and implement appropriate controls as mandated by the policy.

Governance and Institutional Framework

The 2023 RMiT placed significant emphasis on strengthening the governance and institutional framework for technology risk management within financial institutions. It mandated clear roles and responsibilities for the Board of Directors and Senior Management, holding them accountable for the overall effectiveness of the technology risk management framework. The Board was expected to provide strategic direction, approve the technology risk appetite, and ensure adequate resources are allocated for technology and cybersecurity initiatives. Senior Management, in turn, was responsible for implementing the Board's directives, establishing appropriate policies and procedures, and overseeing day-to-day technology risk management operations.

A critical aspect of the governance framework was the requirement for a robust Chief Information Security Officer (CISO) function. The CISO was expected to be independent from day-to-day technology operations, possess the requisite technical skills and experience in audit, governance, and risk management, and be responsible for apprising the board and senior management of current and emerging technology risks. This structure aimed to ensure that technology and cyber risks receive appropriate attention at the highest levels of the organization, facilitating informed decision-making and proactive risk mitigation strategies. The policy also likely detailed requirements for establishing dedicated technology risk committees or integrating technology risk into existing enterprise risk management committees to ensure comprehensive oversight.

Key Focus Areas

The 2023 RMiT introduced several key focus areas to enhance technology risk management within financial institutions. A significant update was the additional guidance provided to strengthen cloud risk management capabilities. This included a shift to a risk-based approach in the cloud consultation and notification process, requiring financial institutions to conduct comprehensive risk assessments before adopting cloud services, especially for critical systems. The policy outlined expectations for managing risks associated with cloud service providers (CSPs), including their compliance with relevant laws and regulations such as the Personal Data Protection Act 2010.

Another crucial area was the heightening of cybersecurity controls and practices, bringing them in line with global standards and best practices. The policy explicitly denoted the use of multi-factor authentication (MFA) as a standard requirement, particularly for remote access to critical systems or sensitive data. This aimed to strengthen the security of digital services through more robust fraud detection, proactive monitoring, and customer empowerment. Furthermore, the RMiT addressed the need for enhanced operational resilience against sophisticated and malicious cyber threats, requiring financial institutions to build capabilities to withstand and recover from disruptions, ensuring continuous availability of critical financial services.

Implementation Framework

The implementation framework outlined in the 2023 RMiT required financial institutions to establish and maintain a comprehensive set of policies, procedures, and controls to manage technology risk effectively. This included developing a technology risk management framework that is integrated with the institution's overall enterprise risk management framework. Institutions were mandated to conduct regular and comprehensive risk assessments to identify, measure, monitor, and control technology risks, taking into account the size and complexity of their operations, the level of technology use, and external stress exposure.

Furthermore, the policy emphasized the importance of robust internal controls, including those related to information security, access management, system development and acquisition, and data management. Financial institutions were expected to implement a strong change management process for technology systems and to ensure that third-party technology service providers adhere to the same stringent risk management standards. The framework also called for adequate resources, including skilled personnel and technology infrastructure, to support the implementation and ongoing maintenance of the technology risk management program. This holistic approach aimed to embed technology risk considerations into all aspects of a financial institution's operations.

Monitoring and Evaluation

The 2023 RMiT mandated a rigorous approach to the monitoring and evaluation of technology risk management frameworks within financial institutions. This included requirements for continuous monitoring of technology risks, cyber threats, and the effectiveness of implemented controls. Financial institutions were expected to establish key risk indicators (KRIs) and key performance indicators (KPIs) to track their technology risk posture and the performance of their security measures. Regular reporting to the Board and Senior Management on the state of technology risk, including significant incidents and remediation efforts, was also a crucial component.

Beyond continuous monitoring, the policy required periodic independent reviews and audits of the technology risk management framework to assess its adequacy and effectiveness. These reviews were intended to identify any weaknesses or gaps and ensure compliance with the RMiT document. Financial institutions were also expected to conduct regular cyber drills and simulations to test their operational resilience and incident response capabilities, demonstrating their ability to respond effectively to cyber incidents and maintain critical functions during disruptions. Post-incident reviews were also mandated to ensure lessons learned are incorporated into future risk management strategies and controls.

Penalties, Liability, and Appeals

The Bank Negara Malaysia's (BNM) Policy Document on Risk Management in Technology (RMiT) is a regulatory compliance document, and non-compliance with its provisions can lead to significant enforcement or supervisory actions. The policy document itself is issued pursuant to various sections of key Malaysian financial legislation, including the Financial Services Act 2013 (FSA), the Islamic Financial Services Act 2013 (IFSA), and the Development Financial Institutions Act 2002 (DFIA). This statutory backing provides BNM with the authority to impose penalties for non-adherence.

Enforcement actions can be taken against financial institutions, as well as their directors, officers, and employees, for any non-compliance with provisions marked as “S” (Standard) within the policy document. If BNM determines that a financial institution's technology risk management has material weaknesses that are not promptly addressed, the Bank may impose various measures. These could include requiring an independent external review of the institution's technology risk management or other supervisory interventions. While specific monetary penalties or detailed appeal processes are typically outlined in the overarching acts (FSA, IFSA, DFIA) rather than the policy document itself, the RMiT clearly establishes the regulatory expectation and the potential for serious consequences for failures in technology risk governance and control.

Relationship to Other Instruments

The 2023 Policy Document on Risk Management in Technology (RMiT) did not exist in isolation but was part of an evolving regulatory landscape. It specifically superseded the previous Policy Document on Risk Management in Technology issued on January 1, 2020. This indicates a continuous effort by Bank Negara Malaysia to update and strengthen its regulatory framework in response to technological advancements and emerging risks in the financial sector. The 2023 document incorporated new requirements and enhanced existing ones, particularly concerning cloud technology risks and multi-factor authentication.

Furthermore, the 2023 RMiT itself was subsequently superseded by a revised Policy Document on Risk Management in Technology issued on November 28, 2025. This later revision further expanded applicability, enhanced resilience requirements, heightened cybersecurity controls, and facilitated the secure adoption of new technologies. The RMiT policy documents are issued under the authority granted by various Malaysian financial acts, including the Financial Services Act 2013 (FSA), the Islamic Financial Services Act 2013 (IFSA), and the Development Financial Institutions Act 2002 (DFIA), providing the legal basis for its requirements and enforcement. It also references other related policy documents and guidelines, such as those on Electronic Money, Merchant Acquiring Services, and Payment System Operator, ensuring a cohesive regulatory environment.

International Alignment

Bank Negara Malaysia's (BNM) Policy Document on Risk Management in Technology (RMiT) generally reflects a commitment to aligning with international best practices and standards in technology and cyber risk management for the financial sector. While the document is specific to the Malaysian context, its principles and requirements often draw from global frameworks established by international bodies such as the Basel Committee on Banking Supervision (BCBS), the Financial Stability Board (FSB), and other cybersecurity standards organizations. The emphasis on robust governance, comprehensive risk assessments, stringent cybersecurity controls, and operational resilience mirrors global regulatory trends aimed at safeguarding financial stability in an increasingly digital and interconnected world.

The policy's focus on areas like cloud risk management, multi-factor authentication, and third-party risk management indicates an awareness of common challenges and solutions being addressed by regulators worldwide. By setting out minimum requirements that are often benchmarked against international norms, BNM aims to ensure that Malaysian financial institutions maintain a level of technology and cyber resilience comparable to their global counterparts. This alignment facilitates cross-border cooperation, enhances the credibility of Malaysia's financial sector, and contributes to the overall stability of the international financial system by mitigating the transmission of technology-related risks across jurisdictions.

Implementation Timeline

MilestoneDateNotes
Issuance and General Effective Date of 2023 RMiT2023-06-01Policy Document on Risk Management in Technology (RMiT) issued, superseding the 2020 version. Generally effective for most provisions.
Effective Date for Cloud Provisions (Digital Banks)2023-06-01New amendments specifically related to cloud technology risk management took effect for licensed digital banks and Islamic digital banks.
Effective Date for Cloud Provisions (Other FIs)2024-06-01New amendments specifically related to cloud technology risk management took effect for financial institutions other than licensed digital banks and Islamic digital banks.
Superseded by New RMiT Policy Document2025-11-28The 2023 RMiT Policy Document was superseded by a revised version issued on this date.

Sources and References

SourceType
Bank Negara Malaysia - Policy Document on Risk Management in Technology (RMiT) (Issued 28 November 2025)official

Requirements for a company

What an organisation has to do under Policy Document on Risk Management in Technology (RMiT), at a glance. Not legal advice.

No current requirements. This instrument is repealed; it imposes nothing today.

© Regulations.AI — created on 11-Apr-2026 using Gemini 2.5 Flash · updated on 04-Aug-2026