Malaysia - Technology Risk Management Guidelines

Securities Commission Malaysia — Guidelines on Technology Risk Management (GTRM) (revised)

Malaysia

RAI-MY-NA-SCMGTXX-2024
Effective: August 19, 2024
In Force (Amended)(In Force (Amended))
GuidelineGovernance and OversightRisk ManagementCybersecurity and Model Security
Export PDF

The Securities Commission Malaysia (SC) revised its Guidelines on Technology Risk Management (GTRM) and brought the revised version into effect on 19 August 2024. The GTRM expands the prior cyber-only focus to a comprehensive technology risk framework covering governance, third-party management, change management, testing and reporting (including near-miss reporting), and guiding principles for ethical AI/ML adoption.

Summary

The Guidelines on Technology Risk Management (GTRM), issued by the Securities Commission Malaysia (SC) originally on 1 August 2023 and revised on 19 August 2024, establish mandatory expectations and practical guidance for capital market entities (CMEs) in managing technology risk across the entire lifecycle of critical systems and services. The GTRM supersedes the earlier Guidelines on Management of Cyber Risk (GMCR, 2016) and shifts the supervisory emphasis from cyber resilience alone to a broader technology risk management (TRM) approach that includes operational reliability, change control, secure system development/deployment practices, third-party/vendor governance, testing and assurance (including penetration testing and pre-deployment cybersecurity assessments), incident and near-miss reporting, and controls for new technologies including AI/ML.

The GTRM is framed as supplementary to securities laws and other SC guidelines (for example, outsourcing rules) and applies to all CMEs licensed, registered, approved, recognised or authorised by the SC under the Capital Markets and Services Act 2007 (CMSA). Key governance responsibilities are placed on the board and senior management to set the TRM Framework, risk appetite and tolerances, allocate resources, and ensure independent assurance through technology audits. The revised 2024 version added explicit requirements for (a) reporting near-miss events to the SC, (b) conducting cyber security assessments prior to the deployment of systems, (c) performing penetration testing for any new critical systems before deployment, and (d) enabling the SC to appoint independent reviewers (including technology auditors) at the CME's expense where necessary.

Operationally, the GTRM requires CMEs to: maintain a documented TRM framework commensurate with their technology exposure; run structured project governance and change management for technology initiatives; implement lifecycle security controls (development, test, staging, production separation); ensure vendor/service provider due diligence, contractual protections and oversight; apply cryptographic and access controls; meet specific recovery time objectives and conduct regular DR/BCP and IT recovery testing; and report technology-related implementations and incidents using SC templates (updated in Appendix 5). In addition, the Guidelines include appendices providing guidance on risk identification/assessment/mitigation, cyber risk methodologies and specific guiding principles for ethical adoption of AI and ML.

Enforcement: the SC's FAQs state that breach of the GTRM may lead to administrative actions under securities laws administered by the SC. The revised Guidelines also explicitly provide for the SC to require independent reviews and for the costs to be borne by the CME. Where multiple regulators have overlapping requirements, CMEs must comply with the most stringent obligations. The GTRM's intent is both prescriptive (mandatory expectations and reporting) and supervisory (assessment, engagement, and, where required, independent auditing) to strengthen technology resilience of the Malaysian capital market.

Primary SC source materials, including the full Guidelines, the Summary of Amendments (19 August 2024) and Frequently Asked Questions, are published on the SC website and should be consulted for the full text, specific paragraph references and reporting templates. These documents are authoritative and set out the detailed requirements and the notification forms to be used by CMEs.

Full article

Read full text ↗

Overview

The Securities Commission Malaysia's Guidelines on Technology Risk Management (GTRM) establish a single, cohesive TRM framework for all capital market entities regulated by the SC. Issued first on 1 August 2023 and revised on 19 August 2024, the Guidelines expand the regulatory scope beyond cyber risk to cover technology risks that can arise from systems, operations, supply chains, change processes and new technologies such as AI/ML. The revision emphasises operational reliability, resilience and pre-deployment assurance (for example, mandatory cybersecurity assessments and penetration testing for critical systems) and introduces near-miss reporting to enhance supervisory visibility. The GTRM is supplementary to the Capital Markets and Services Act 2007 (CMSA) and other SC guidelines and applies proportionately to entities depending on their technology dependency and risk exposure. The Guidelines include appendices with risk identification, cyber risk methodologies and guiding principles for ethical AI/ML adoption, and they provide notification templates for implementation and incident reporting. For the authoritative text, see the SC's published PDF and related materials: SC media release (19 Aug 2024) and the Summary of Amendments (19 Aug 2024).

Definitions

The Guidelines define core terms to establish consistent application across CMEs. ‘‘Capital market entity’’ is defined broadly (exchange operators; clearing houses; CMSL holders; recognised market operators; registered persons under schedule provisions; private retirement scheme administrators; and persons providing capital market services under section 76A of the CMSA). ‘‘Critical technology’’ denotes technology whose failure would significantly impair services, reputation, legal compliance or business continuity. Terms such as ‘‘cyber incident,’’ ‘‘technology incident,’’ ‘‘near miss event,’’ ‘‘information assets,’’ ‘‘IT systems,’’ ‘‘recovery time objective (RTO)’’ and third‑party service provider are each specifically defined to align supervisory expectations and reporting. The Definitions chapter clarifies that the Guidelines operate in addition to other securities laws and SC guidelines, and that where multiple requirements exist between regulators, the more stringent requirement prevails.

Governance and Institutional Framework

The GTRM places primary governance responsibility with the board of directors and senior management. Boards must approve and oversee the TRM Framework, risk appetite, risk tolerance and key performance indicators for technology risk. Senior management must implement policies, designate accountable roles (including a responsible technology officer or function), ensure adequate resourcing, and maintain independent assurance through technology audits or an equivalent independent review. The Guidelines require segregation of duties, conflict-of-interest management, and reporting lines that permit escalation to the board. Where groups centralise TRM at the holding level, the Guidelines treat such arrangements as outsourcing — requiring the CME board to remain fully accountable. The 2024 revision also grants the SC the power to appoint independent parties to review a CME's compliance (including conducting a technology audit) and to charge the CME for the cost of such engagement. Relevant SC resource pages for governance and obligations include the main GTRM PDF and the SC's regulatory guidance pages: Technology Risk (SC guidelines page).

Key Focus Areas

The GTRM covers several substantive domains. Technology Risk Management requires a documented TRM Framework that identifies, assesses and mitigates technology-related risks and sets out monitoring and reporting arrangements. Technology Operation Management prescribes change management, secure development and deployment processes, environment separation (development/test/staging/production), data protection controls, cryptography and access control, configuration and patch management, end-of-life (EOL) management, and business continuity and disaster recovery objectives with periodic testing. Technology Service Provider Management sets expectations on due diligence, contractual clauses (including security, data protection, audit rights and exit plans), service-level monitoring, sub-contractor mapping and contingency arrangements. Cyber Security Management mandates detection, prevention and response capabilities, penetration testing, vulnerability management and proactive monitoring. The revised Guidelines added specific pre-deployment cybersecurity assessments and explicit penetration testing prior to deploying critical systems, and introduced reporting of near-miss events to improve proactive supervisory intelligence. Appendix guidance assists CMEs to adopt proportionate controls based on their scale and reliance on technology.

Implementation Framework

Implementation is outcome-focused and proportionate. CMEs must tailor the TRM Framework to their business models and technology dependency; the degree of control and the sophistication of assurance activities should be commensurate with exposure. The GTRM sets minimum expectations for board approval, senior management ownership, appointed accountable personnel, documented policies/procedures, and independent assurance. Key operational steps include: (1) conduct business impact analyses to identify critical systems and functions; (2) establish change control and release management processes; (3) conduct pre-deployment cybersecurity assessments and penetration tests for critical systems (per the 19 August 2024 amendments); (4) maintain third-party registers and contractual protections; (5) implement strong cryptographic controls and least-privilege access; and (6) test recovery capabilities against defined RTOs. The Guidelines provide templates and notification forms (see Appendix 4 and Appendix 5) for regulatory notifications and technology implementation notices: GTRM PDF (full text).

Monitoring and Evaluation

The SC will monitor compliance through supervisory engagement, review of notifications and incident reports, thematic reviews and onsite examinations. The Guidelines require CMEs to maintain logs, monitoring dashboards, incident/near-miss records and audit trails to support supervisory review. The SC's ability to appoint independent reviewers provides an additional supervisory tool where concerns arise. CMEs should maintain management information (MI) that enable the board and senior management to assess TRM effectiveness, including metrics on system availability, incident response times, patching lead times, third-party performance, penetration test results and remediation status. The SC signals that supervisory assessments will consider proportionality and the CME's level of technology dependency and systemic importance.

Penalties, Liability, and Appeals

The Guidelines themselves are supervisory instruments; the SC's FAQs confirm that breaches may lead to administrative actions under securities laws administered by the SC. Potential outcomes include regulatory directions to remedy deficiencies, issuance of enforcement notices, monetary penalties or fines where powers under the CMSA and related rules permit, suspension or revocation of licences, and public enforcement actions. The 19 August 2024 revisions also allow the SC to commission independent reviews or technology audits at a CME's expense. Where CMEs disagree with SC determinations, customary rights under the securities laws (including internal review procedures and judicial review where available) remain. The exact sanctioning powers depend on the specific statutory provisions and facts of an enforcement case and are applied in accordance with SC enforcement policies as set out in other SC materials.

Relationship to Other Instruments

The GTRM expressly supersedes the Guidelines on Management of Cyber Risk (2016) and sits alongside other SC guidelines (for example, outsourcing/third-party provisions in sectoral guidelines, Guidelines on Recognised Markets, Guidelines on Digital Assets and Guiding Principles on Business Continuity) and statutory obligations under the CMSA. The GTRM does not displace other regulators' requirements; where multiple regulators apply, the more stringent rule prevails. Consequential amendments to other SC guidelines were published contemporaneously with the 19 August 2024 revision to ensure coherence across the SC's regulatory suite. CMEs must therefore cross-reference applicable sectoral SC guidelines and relevant laws (for example, data protection laws) when implementing TRM controls.

International Alignment

The GTRM reflects international good practice and aligns with global supervisory trends emphasising resilience and governance for technology and cyber risks. The Guidelines incorporate established control objectives such as board oversight, independent assurance, vendor governance, incident reporting and pre-deployment testing. The SC's approach is consistent with prudential technology/cyber guidance issued by other leading financial regulators (for example, requirements for penetration testing, third-party oversight and incident notifications) while introducing Malaysian-specific reporting forms and supervisory mechanisms. The inclusion of AI/ML guiding principles also mirrors emerging international regulatory interest in ethical and accountable AI use within financial services. CMEs with cross-border operations should ensure compliance with local rules and the GTRM where applicable.

Implementation Timeline

EventDate
GTRM first issued2023-08-01
GTRM one-year familiarisation period begins (public announcement)2023-08-01
FAQs revised (interim)2024-06-07
Revised GTRM issued (amendments published)2024-08-19
Revised GTRM effective date (implementation)2024-08-19

Sources and References

SourceType
Guidelines on Technology Risk Management (SC-GL/2-2023) — full text (PDF)Primary Source
Summary of Amendments to the Revised Guidelines on Technology Risk Management (19 Aug 2024) (PDF)Primary Source
Frequently Asked Questions on the Guidelines on Technology Risk Management (PDF)Primary Source
SC Media Release — GTRM takes effect (19 Aug 2024)Primary Source

Requirements for a company

What an organisation has to do under Malaysia - Technology Risk Management Guidelines, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

9
  • Maintain a documented Technology Risk Management Framework.Capital market entities regulated by the SC.
  • Approve and annually review the Technology Risk Management Framework.Boards of capital market entities regulated by the SC.
  • Designate a responsible technology officer or function.Senior management of capital market entities regulated by the SC.
  • Conduct business impact analyses to identify critical systems and functions.Capital market entities regulated by the SC.
  • Perform pre-deployment cybersecurity assessments and penetration tests for critical systems.Capital market entities regulated by the SC.
  • Maintain a register of third-party providers and robust contractual protections.Capital market entities regulated by the SC.
  • +3 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Malaysia - Technology Risk Management Guidelines, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Capital market entities regulated by the SC.Maintain a documented Technology Risk Management Framework.
Technology Risk Management requires a documented TRM Framework that identifies, assesses and mitigates technology-related risks.
Key Focus AreasCritical
2Boards of capital market entities regulated by the SC.Approve and annually review the Technology Risk Management Framework.
Boards must approve and oversee the TRM Framework, risk appetite, risk tolerance and key performance indicators for technology risk.
Governance and Institutional FrameworkCritical
3Senior management of capital market entities regulated by the SC.Designate a responsible technology officer or function.
Senior management must... designate accountable roles (including a responsible technology officer or function).
Governance and Institutional FrameworkCritical
4Capital market entities regulated by the SC.Conduct business impact analyses to identify critical systems and functions.
Key operational steps include: (1) conduct business impact analyses to identify critical systems and functions.
Implementation FrameworkCritical
5Capital market entities regulated by the SC.Perform pre-deployment cybersecurity assessments and penetration tests for critical systems.
The revised Guidelines added specific pre-deployment cybersecurity assessments and explicit penetration testing prior to deploying critical systems.
Before placing on marketKey Focus AreasCritical
6Capital market entities regulated by the SC.Maintain a register of third-party providers and robust contractual protections.
Technology Service Provider Management sets expectations on due diligence, contractual clauses (including security, data protection, audit rights and exit plans).
Key Focus AreasCritical
7Capital market entities regulated by the SC.Report technology incidents and near-miss events promptly using the SC notification template.
The revised Guidelines... introduced reporting of near-miss events to improve proactive supervisory intelligence.
PromptlyKey Focus AreasCritical
8Capital market entities regulated by the SC.Maintain independent assurance through technology audits or equivalent independent reviews.
Senior management must... maintain independent assurance through technology audits or an equivalent independent review.
Governance and Institutional FrameworkCritical
9Capital market entities regulated by the SC using AI/ML.Adopt guiding principles for ethical AI/ML and document related policies.
The Guidelines include appendices with... guiding principles for ethical AI/ML adoption.
OverviewImportant

© Regulations.AI · updated on 13-Jun-2026