Skip to content

MAS Notice FSM-N30 — Notice on Technology Risk Management (Holders of Digital Token Service Licence)

Back to Technology & Cyber

Previous Next


MAS Notice FSM-N30

30 May 2025

NOTICE TO LICENSED DIGITAL TOKEN SERVICE PROVIDERS FINANCIAL SERVICES AND MARKETS ACT 2022

NOTICE ON TECHNOLOGY RISK MANAGEMENT

Introduction

  1. This Notice is issued under section 29(1) of the Financial and Services Market Act 2022 (the "FSM Act") and applies to a holder of a licence granted under section 138 of the FSM Act ("digital token service provider").

  2. This Notice takes effect from 30 June 2025.

Definitions

  1. For the purpose of this Notice----

"critical system" in relation to a digital token service provider, means a system, the failure of which will cause significant disruption to the operations of the digital token service provider or materially impact the digital token service provider's service to its customers, such as a system which—

(a) processes transactions that are time critical; or

(b) provides essential services to customers;

"IT security incident" means an event that involves a security breach, such as hacking of, intrusion into, or denial of service attack on, a critical system, or a system which compromises the security, integrity or confidentiality of customer information;

"relevant incident" means a system malfunction or IT security incident, which has a severe and widespread impact on the digital token service provider's operations or materially impacts the digital token service provider's service to its customers;

"system" means any hardware, software, network, or other information technology ("IT") component which is part of an IT infrastructure;

"system malfunction" means a failure of any of the digital token service provider's critical systems;

  1. Except where defined in this Notice or where the context requires, expressions used in this Notice have the same meanings as in section 2 or 136(1) of the FSM Act.

Technology Risk Management

  1. A digital token service provider must put in place a framework and process to identify critical systems.

  2. A digital token service provider must make all reasonable efforts to maintain high availability for critical systems. The digital token service provider must ensure that the maximum unscheduled downtime for each critical system that affects the digital token service provider's operations or service to its customers does not exceed a total of 4 hours within any period of 12 months.

  3. A digital token service provider must establish a recovery time objective ("RTO") of not more than 4 hours for each critical system. The RTO is the duration of time, from the point of disruption, within which a system must be restored. The digital token service provider must validate and document at least once every 12 months, how it performs its system recovery testing and when the RTO is validated during the system recovery testing.

  4. A digital token service provider must notify the Authority as soon as possible, but not later than 1 hour, upon the discovery of a relevant incident.

  5. A digital token service provider must submit a root cause and impact analysis report to the Authority, within 14 days or such longer period as the Authority may allow, from the discovery of the relevant incident. The digital token service provider must ensure that the report contains —

(a) an executive summary of the relevant incident;

(b) an analysis of the root cause which triggered the relevant incident;

(c) a description of the impact of the relevant incident on the digital token service provider's—

(i) compliance with laws and regulations applicable to the digital token service provider;

(ii) operations; and

(iii) service to its customers; and

(d) a description of the remedial measures taken to address the root cause and consequences of the relevant incident.

  1. A digital token service provider must implement IT controls to protect customer information from unauthorised access or disclosure.

Previous Next

Back to Technology & Cyber