Camp Fire Academy
Learning path
Complete UI/UX Masterclass UI/UX Design Foundations UI/UX Design Intermediate Advanced UX Strategy
Specialisations
Fintech & Banking UI/UX UI/UX with AI Training UX for Leaders Design Thinking Figma Training
Most requested
AI for Workplace Productivity Excel for Business Power BI & Business Intelligence Cybersecurity Awareness PDPA Compliance Data Protection Officer Browse the full catalogue →
For teams
Corporate & In-House Training LMS & Self-Paced Learning Events
Company
About Contact Verify Certificate WhatsApp

BNM RMiT Compliance (Risk Management in Technology)

RMiT is not a short document, and the parts that cause trouble at examination are rarely the ones institutions spend their time on. Bank Negara reissued the policy document in a revised form in November 2025, tightening expectations on resilience and third-party arrangements. This day translates the policy into a control set with named owners and evidence requirements, then works through where institutions most often find themselves unable to demonstrate what they have in fact been doing.

Programme Agenda

Scope, Proportionality and Self-Assessment

Which institutions the policy binds, how the enhanced requirements attach to larger and more complex institutions, and the self-assessment that determines where you sit. Applying proportionality without using it as an excuse.

Technology Risk Governance

Board and senior management accountability, the risk management function's role, technology risk appetite, and the reporting that has to reach the board rather than stop at a committee.

The Technology Risk Management Framework

Risk identification, assessment and treatment applied to technology assets. Keeping the framework connected to the enterprise risk framework instead of running it as a parallel exercise.

Cyber Security Requirements

Control expectations across access management, network security, cryptography, security operations and incident response. Mapping them to what you already run so gaps surface rather than duplicate work.

Technology Operations and Resilience

Change management, capacity, availability targets, data centre and cloud arrangements, backup and recovery. Demonstrating resilience rather than asserting it.

Third Party and Cloud Arrangements

Assessment before engagement, contractual requirements, ongoing oversight, concentration risk, and access for the institution and the regulator. The area where findings cluster most reliably.

Incident Notification and Reporting

What has to be reported to Bank Negara, on what timing, and in what form. Running RMiT notification alongside any PDPA or Act 854 duty triggered by the same event.

Gap Assessment Workshop

Participants score their own institution against the requirement set, separate genuine control gaps from evidence gaps, and leave with a prioritised remediation list.

Learning Outcomes:
Establish which RMiT requirements apply to your institution and at what intensity
Set up technology risk governance with board-level accountability
Connect the technology risk framework to enterprise risk management
Map RMiT cyber security expectations onto your existing control set
Evidence technology operations resilience rather than assert it
Manage third party and cloud arrangements to the standard the policy expects
Report an incident to Bank Negara within the required timing and form
Distinguish a control gap from an evidence gap and prioritise accordingly

Duration: 1 Day (8 Hours)
Training Hours: 9:00 AM to 5:00 PM
Level: All levels
Training Mode: Physical, Online, or Hybrid
HRD Corp SBL-KHAS Claimable
Certificate of Completion included

Frequently Asked Questions

Chief information security officers, heads of IT, technology risk and operational risk officers, compliance officers, internal auditors, and board or senior management members with technology oversight at licensed financial institutions, insurers, takaful operators and digital banks.

The current version, including the revisions issued in November 2025. Where a requirement changed from the earlier version, the session says what changed so institutions with an existing programme know what to revisit.

Partly. The cyber security and operations modules assume familiarity with IT infrastructure, but the governance, third party and reporting modules are accessible to compliance, audit and risk participants without a technical background.

The workshop does a structured self-scoring exercise, which is not the same as an independent assessment. For in-house delivery we work from your control inventory so the output is specific to your institution.

Yes, this programme is HRD Corp SBL-KHAS claimable. Our team can assist your HR department with the documentation required for the grant application.

Yes. Any programme can be booked as a team day. Everyone works the same brief together, so your people come away having built something and knowing each other better.

If you are claiming under HRD Corp, the session has to fall at least 14 days after your HRD Corp approval. If you are not claiming, the date is flexible and we work around your calendar.

Put them on the self-paced e-learning instead. Your team works through the modules on our LMS in their own time, sits the assessment, and earns the same certificate, so nobody has to clear a full day together.

More in Financial Services Compliance