Home › Insights › Frameworks & Regulation
Frameworks & Regulation

What Does MAS TRM Require for Penetration Testing — and How Often? A Compliance Guide for Singapore Financial Institutions

MAS's Technology Risk Management Guidelines require regulated financial institutions to run independent, qualified penetration testing at least annually, scoped to internet-facing and critical systems, with documented evidence for MAS inspection. This guide explains the requirement, how it differs from MAS Notice 655, and what a compliance lead should verify when engaging a provider.

By Infracom Team11 September 20266 min read

MAS's Technology Risk Management Guidelines require financial institutions to conduct penetration testing using qualified, independent assessors, with frequency set by system criticality rather than a single fixed rule — though the accepted baseline is at least annually, plus additional testing after significant system changes. Testing must combine black box and grey box methods, and testers must have had no prior role in building or maintaining the systems under test. Compliance and IT risk leads preparing for an MAS inspection need evidence of all three: independence, methodology, and remediation.

What MAS TRM Actually Requires

The MAS Technology Risk Management Guidelines set out a dedicated section covering security testing. The guidelines address Penetration Testing alongside Cyber Exercises and Adversarial Attack Simulation Exercise as distinct expectations. They apply to all financial institutions regulated by MAS — including banks, insurance companies, capital markets services providers, payment services firms, and licensed fintech entities.

Independence of the tester

Under the MAS Technology Risk Management Guidelines, financial institutions in Singapore are required to test their systems using qualified, independent assessors. This is not a formality. Testers who previously installed, maintained, or supported the assets being tested are disqualified from testing those same assets under MAS's independence rule. A compliance lead should ask any prospective provider directly whether the team proposed for the engagement has had any prior involvement — design, build, patching, or managed services — with the systems in scope.

Methodology: black box and grey box, not a single scan

Section 13.2 specifically requires a combination of black box and grey box testing, not just an external scan. The Association of Banks in Singapore's own testing guidance reinforces this distinction. There are three types of penetration testing styles – Blackbox, Greybox, and Whitebox, each differing in how much internal knowledge the tester is given. A quote that only describes an automated vulnerability scan, or a single external black box test, does not meet the combined-methodology expectation.

Frequency: annual baseline, risk-adjusted upward

MAS TRM Guidelines require penetration testing by qualified, independent assessors, with the frequency set by system criticality and risk exposure. In practice this means an annual floor for most systems, rising for higher-risk or customer-facing platforms. Institutions are expected to conduct penetration testing at least once a year or whenever there are significant changes to their IT environment. The Association of Banks in Singapore's guidance describes the same pattern from an industry-practice angle: penetration tests are typically carried out periodically, for example through annual penetration test, and when existing systems undergo changes or new systems are implemented.

Scope: what must be covered

Scope is not left to the provider's discretion. The expectation is testing at least annually, conducted by independent qualified assessors, covering internet-facing systems, critical internal systems, and any new application before it goes into production. A test that covers only the public website, and excludes internal systems that process customer data or a new application about to launch, will not satisfy the guideline even if it is conducted annually and by an independent firm.

Evidence: what MAS looks for on inspection

Findings need to be usable, not just filed. Reports should carry severity ratings, clear reproduction steps, and a documented remediation trail — because that is what an examiner will ask to see during a technology risk inspection or thematic review, not just the fact that a test took place.

MAS TRM Guidelines vs MAS Notice 655: Don't Conflate the Two

A common point of confusion for compliance teams is treating MAS Notice 655 as the source of the penetration testing obligation. It isn't. The Cyber Hygiene Notice (MAS Notice 655, 2019) is legally binding and sets minimum baseline security practices, while the TRM Guidelines are broader supervisory expectations covering governance, SDLC, IT service management, and more. MAS issued Notice 655 on 6 August 2019, applicable to all banks in Singapore and taking effect from 6 August 2020, setting requirements across administrative accounts, security patches, security standards, network perimeter defence, malware protection, and multi-factor authentication. Penetration testing is not one of those six categories — it sits in the TRM Guidelines, not the Notice.

← Swipe to compare →

DimensionMAS TRM GuidelinesMAS Notice 655 (Cyber Hygiene)
Legal statusSupervisory guidance and expectations, not a legal noticeLegally binding notice under the MAS Act
Primary scopeIT governance, SDLC, cyber resilience, penetration testing, cyber exercisesBaseline hygiene: admin accounts, patching, network perimeter, malware, MFA
ApplicabilityAll MAS-regulated financial institutionsAll banks in Singapore
Penetration testingExplicit requirement, Section 13Not directly addressed
Relevance to a pentest engagementDefines scope, frequency, tester independenceDefines the baseline controls a pentest will assess

How to Prepare Before an MAS Audit or Examination

A structured governance, risk and compliance (GRC) programme is what turns a one-off pentest into audit-ready evidence. Practical steps for a compliance or IT risk lead:

  • Map every internet-facing system, critical internal system, and any application due for launch, and confirm each has a current test date within the last 12 months or a documented risk-based schedule.
  • Request written confirmation that the assigned testers had no prior role in building, patching, or operating the systems in scope — the independence rule is checked at the individual tester level, not just the firm level.
  • Confirm the test methodology explicitly combines black box and grey box approaches, not a single external scan dressed up as a "penetration test."
  • Check that the provider holds a valid CSRO licence for penetration testing services — this is a legal requirement in Singapore, separate from any quality credential. CSA adopts a light-touch approach to license only two types of service providers currently, namely penetration testing and managed security operations centre (SOC) monitoring.
  • Verify the reporting format includes severity ratings, reproduction steps, and a remediation tracker that maps findings to closure dates — this is what an examiner will ask to review.
  • Keep evidence of retesting for previously identified critical or high findings, showing they were closed, not just documented.
  • Align the pentest schedule with a broader GRC calendar that also covers vulnerability assessment, cyber exercises, and third-party risk reviews, rather than treating the pentest as an isolated annual event.

Why the CSRO Licence Matters as Much as the Report

Under the Cybersecurity Act, penetration testing is one of a small number of licensable cybersecurity services in Singapore. CSA launched a licensing framework for penetration testing and managed SOC monitoring providers, administered by the new Cybersecurity Services Regulation Office (CSRO), with the regime designed to protect consumers by ensuring high provider standards. A compliance lead engaging a provider should verify the CSRO licence directly, rather than assuming that a well-known name or an overseas quality mark satisfies the Singapore legal requirement. This licence check sits alongside, not instead of, the MAS TRM requirements around independence and methodology.

How Infracom Helps

Infracom is a CSA CSRO-licensed provider and a CREST Pathway+ Organisation, delivering penetration testing scoped to MAS TRM's black box and grey box requirements, with an all-Singaporean SQEP team and reporting built for MAS inspection — severity ratings, reproduction steps, and a remediation trail your compliance function can hand to an examiner. Where a client needs the wider picture, our GRC advisory work sits alongside the technical testing to keep the testing schedule, evidence, and governance documentation aligned ahead of an audit, at rates accessible to SMEs as well as larger financial institutions. See our VAPT service page for scope and methodology detail.

Sources (7)
  1. MAS Technology Risk Management Guidelines
  2. MAS Notice 655
  3. Cybersecurity Act
  4. CSRO
  5. CSA Kicks Off Licensing Framework for Cybersecurity Service Providers
  6. ABS Penetration Testing Guidelines 2.0
  7. Cyber hygiene and MAS Notice 655

Get Infracom Insights by email

Practical cybersecurity governance and regulatory updates for Singapore and Australia. No more than a few emails a month; unsubscribe any time.

Infracom Consultancy Integration Pte Ltd

Your one-stop IT & cybersecurity partner — Singapore HQ since 2008, expanding to Australia in 2026.

506 Chai Chee Lane

Singapore 469026

Services
IT InfrastructureCloud SolutionsCybersecurityManaged ServicesData Center SolutionsIT Consulting
Consulting
SQEPGRCVAPT
Approach
MethodologyAbout UsInsightsNewsletterPrivacy Policy
Hours

Mon – Fri
9AM – 6PM SGT

Follow us
© Infracom Consultancy Integration Pte Ltd. All rights reserved.Privacy Policy