MAS TRM · Singapore

MAS TRM awareness training
for all staff, on record.

The MAS Technology Risk Management Guidelines of 18 January 2021 expect a comprehensive IT security awareness training programme for all staff, delivered at least annually to staff, contractors and service providers, with technology-risk training for the board.

Framework
MAS Guidelines on Risk Management Practices: Technology Risk, 18 January 2021
Applies to
MAS-regulated financial institutions
Where awareness fits
Section 3.6: training at least annually for all staff, contractors and service providers
KeenSec evidence
LMS completions and certificates, simulation results, report logs, policy acknowledgements

What MAS says about people

Annual training, plus
exercises that feel real.

The TRM Guidelines are unchanged since January 2021.

ReferenceWhat MAS saysStatus
TRM 3.6.1 and 3.6.2A comprehensive IT security awareness training programme for all staff, conducted at least annually for staff, contractors and service providers.In force
TRM 3.6.3The board of directors should undergo training on technology risk.In force
TRM 13.3.1Cyber exercises could include social engineering, table-top or cyber range exercises.In force
TRM 14.1.6Actively monitor for phishing campaigns targeting the institution and its customers.In force
Information paper on deepfakes, September 2025On top of phishing exercises, run regular video and voice deepfake simulation exercises on employees.Guidance

All staff, all year

An awareness programme
that covers everyone.

  1. 01

    Enrol everyone

    Directory and SSO integration keeps the learner list current, including new joiners.

  2. 02

    Train

    Video, micro-learning and guided interactive lessons, with assessments.

  3. 03

    Test

    Realistic simulations on email, SMS, voice, WhatsApp, Teams and Slack show whether training carried into behaviour.

  4. 04

    Prove

    Completions, certificates and results stay in one record, ready for review.

Expectation to record

Proof the programme
reached all staff.

TRAINING

Every staff member trained.

LMS completions, assessments and certificates per person.

COVERAGE

Nobody left out.

Directory sync, with reminders and escalations for anyone outstanding.

SIMULATION RESULTS

Training tested in practice.

Outcomes per channel, team and campaign.

REPORT LOGS

Staff report suspicious messages.

Phishing Reporter logs with automated analysis.

KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.

PLEASE NOTE

This page is general information, not legal advice. KeenSec helps you produce evidence for your awareness obligations; your auditor or regulator decides whether you are compliant.

Primary sources

What this page is based on.

Checked on the regulator’s own website on 24 September 2026. Read the original before you rely on it.

  1. MAS Guidelines on Risk Management Practices: Technology Risk18 January 2021 · sections 3.6, 13.3 and 14.1
  2. MAS information paper: Cyber Risks Associated with DeepfakesSeptember 2025 · MAS/TCRS/2025/06 · guidance
  3. MAS Notice FSM-N06 on Cyber HygieneIn force 10 May 2024 · replaced Notice 655 · technical controls
  4. Guidelines on the Shared Responsibility FrameworkEffective 16 December 2024 · MAS and IMDA

Questions buyers ask

Frequently asked questions.

Does MAS require phishing simulation?

The TRM Guidelines do not use the words. They suggest cyber exercises that could include social engineering, and MAS’s September 2025 deepfake paper suggests voice and video deepfake simulations on top of phishing exercises.

Have the TRM Guidelines been updated?

Not as of September 2026. The Guidelines are dated 18 January 2021. MAS consulted in June 2026 on changes to its technology risk management Notices, which are separate documents.

Does KeenSec make us compliant with MAS TRM?

No tool makes you compliant on its own. KeenSec helps you deliver and evidence the awareness programme; your auditors and MAS decide compliance.

How do we make sure every staff member is covered?

Directory and SSO integration keeps enrolment current, and automated reminders and manager escalations chase anyone who has not completed.

Let’s connect the dots

Every staff member trained.
Every record kept.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo