MAS TRM · Singapore
MAS TRM awareness training
for all staff, on record.
The MAS Technology Risk Management Guidelines of 18 January 2021 expect a comprehensive IT security awareness training programme for all staff, delivered at least annually to staff, contractors and service providers, with technology-risk training for the board.
- Framework
- MAS Guidelines on Risk Management Practices: Technology Risk, 18 January 2021
- Applies to
- MAS-regulated financial institutions
- Where awareness fits
- Section 3.6: training at least annually for all staff, contractors and service providers
- KeenSec evidence
- LMS completions and certificates, simulation results, report logs, policy acknowledgements
What MAS says about people
Annual training, plus
exercises that feel real.
The TRM Guidelines are unchanged since January 2021.
| Reference | What MAS says | Status |
|---|---|---|
| TRM 3.6.1 and 3.6.2 | A comprehensive IT security awareness training programme for all staff, conducted at least annually for staff, contractors and service providers. | In force |
| TRM 3.6.3 | The board of directors should undergo training on technology risk. | In force |
| TRM 13.3.1 | Cyber exercises could include social engineering, table-top or cyber range exercises. | In force |
| TRM 14.1.6 | Actively monitor for phishing campaigns targeting the institution and its customers. | In force |
| Information paper on deepfakes, September 2025 | On top of phishing exercises, run regular video and voice deepfake simulation exercises on employees. | Guidance |
All staff, all year
An awareness programme
that covers everyone.
- 01
Enrol everyone
Directory and SSO integration keeps the learner list current, including new joiners.
- 02
Train
Video, micro-learning and guided interactive lessons, with assessments.
- 03
Test
Realistic simulations on email, SMS, voice, WhatsApp, Teams and Slack show whether training carried into behaviour.
- 04
Prove
Completions, certificates and results stay in one record, ready for review.
Expectation to record
Proof the programme
reached all staff.
Every staff member trained.
LMS completions, assessments and certificates per person.
Nobody left out.
Directory sync, with reminders and escalations for anyone outstanding.
Training tested in practice.
Outcomes per channel, team and campaign.
Staff report suspicious messages.
Phishing Reporter logs with automated analysis.
KeenSec helps you produce evidence for your awareness obligations: simulation results, report logs, training completions and certificates, and policy acknowledgements. Your auditor decides compliance.
This page is general information, not legal advice. KeenSec helps you produce evidence for your awareness obligations; your auditor or regulator decides whether you are compliant.
Primary sources
What this page is based on.
Checked on the regulator’s own website on 24 September 2026. Read the original before you rely on it.
- MAS Guidelines on Risk Management Practices: Technology Risk18 January 2021 · sections 3.6, 13.3 and 14.1
- MAS information paper: Cyber Risks Associated with DeepfakesSeptember 2025 · MAS/TCRS/2025/06 · guidance
- MAS Notice FSM-N06 on Cyber HygieneIn force 10 May 2024 · replaced Notice 655 · technical controls
- Guidelines on the Shared Responsibility FrameworkEffective 16 December 2024 · MAS and IMDA
Questions buyers ask
Frequently asked questions.
Does MAS require phishing simulation?
The TRM Guidelines do not use the words. They suggest cyber exercises that could include social engineering, and MAS’s September 2025 deepfake paper suggests voice and video deepfake simulations on top of phishing exercises.
Have the TRM Guidelines been updated?
Not as of September 2026. The Guidelines are dated 18 January 2021. MAS consulted in June 2026 on changes to its technology risk management Notices, which are separate documents.
Does KeenSec make us compliant with MAS TRM?
No tool makes you compliant on its own. KeenSec helps you deliver and evidence the awareness programme; your auditors and MAS decide compliance.
How do we make sure every staff member is covered?
Directory and SSO integration keeps enrolment current, and automated reminders and manager escalations chase anyone who has not completed.
Let’s connect the dots
Every staff member trained.
Every record kept.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo