SC Guidelines on Technology Risk Management
The Securities Commission's Guidelines on Technology Risk Management took effect on 19 August 2024, replacing the older Guidelines on Management of Cyber Risk and widening the scope from cyber security to technology risk generally. For many capital market entities that meant new obligations on project management, service provider oversight and near-miss reporting rather than a simple continuation. This day sets out the requirement set, and concentrates on the parts most often missed by smaller licensed entities without a dedicated technology risk function.
Programme Agenda
What Changed and Who Is Caught
Applicability across licensed, registered, approved, recognised and authorised capital market entities. What the guidelines added over the superseded cyber risk guidelines, and the compliance declaration expected of entities.
The Technology Risk Framework
Establishing and operating a framework proportionate to your size and activity. Risk identification and assessment, control selection, and the governance structure that has to sit over it.
Board Oversight and Accountability
What the board and senior management are accountable for, the reporting that must reach them, and the difference between oversight and delegation. Documenting that oversight actually happened.
Technology Project Management
Requirements attaching to technology projects and change, including assessment before deployment. Building the gate into your existing project process rather than bolting on a separate review.
Technology Service Provider Management
Assessment before appointment, contractual terms, ongoing monitoring, and access rights. Managing the outsourced or vendor-hosted platform most smaller entities run on.
Cyber Security Management
Control expectations, cyber security assessment before a system is deployed, and penetration testing before new critical systems go live. Scoping a test so it satisfies the requirement and is worth the money.
Reporting Obligations
Reporting to the Securities Commission, including near-miss events. What counts as a near miss, who decides, and the internal process needed for the judgement to be made consistently.
Readiness Workshop
Participants assess their own entity against the requirement set, identify what they could evidence today, and build a remediation list sized to their resources.
Learning Outcomes:
Confirm your entity's status under the guidelines and the obligations that follow
Establish a technology risk framework proportionate to your activity
Set up board oversight and evidence that it operates
Insert the required assessment gates into technology projects and change
Manage technology service providers to the standard the guidelines require
Scope pre-deployment cyber assessment and penetration testing usefully
Recognise and report a near-miss event correctly
Duration: 1 Day (8 Hours)
Training Hours: 9:00 AM to 5:00 PM
Level: All levels
Training Mode: Physical, Online, or Hybrid
HRD Corp SBL-KHAS Claimable
Certificate of Completion included
Frequently Asked Questions
More in Financial Services Compliance
- Compliance Essentials for Asset Management · Beginner, 1 day
- Compliance Professional Training for Banking Institutions · Intermediate, 1 day
- E-Invoicing (LHDN MyInvois) Staff Readiness · All levels, 1 day
- AML/CFT Staff Awareness Training · Beginner, 1 day
- AML/CFT Compliance Officer Essentials · Beginner, 1 day
- AML/CFT Compliance Officer Advanced · Advanced, 2 days
- BNM RMiT Compliance (Risk Management in Technology) · All levels, 1 day