Financial services watchdog Monetary Authority of Singapore (MAS) is proposing a number of changes to its Technology Risk Management (TRM) Notices that would place software testing, validation and operational resilience more firmly at the centre of banking supervision, reinforcing the regulator’s growing emphasis on evidence-based technology assurance.
The consultation, which seeks industry feedback on amendments covering technology risk management across banks, insurers and other financial institutions, follows a series of MAS initiatives that have steadily moved from high-level AI governance principles towards practical frameworks for validation, monitoring and operational control.
Coming just days after the publication of its Safeguards for Agentic Finance at Runtime (SAFR) framework for AI agents, as reported by QA Financial, the latest consultation broadens that philosophy to the wider technology estate, proposing stronger requirements around testing, change management, continuous monitoring, dependency management and recovery planning.
Unlike many regulators, MAS publishes detailed technology risk requirements rather than relying solely on broad principles.
Those requirements are closely watched well beyond Singapore because international banks operating in one of the world’s largest financial centres frequently align their technology governance and operational resilience programmes with MAS expectations.
Poor testing
The consultation contains one particularly significant message. MAS makes clear that poor testing has been a contributing factor behind major technology failures.
The regulator explained that “MAS has noted that a significant number of IT incidents in [financial institutions] were attributed to poor change management.”
The watchdog added that “the lapses observed include insufficient risk and impact assessment of changes, poor understanding of system dependencies, inadequate testing of changes, and the absence of effective change recovery plans.”
That observation underpins one of the consultation’s most important proposals as MAS said “it is essential that FIs implement controls to prevent unauthorised changes, carry out robust testing and validation of system changes to minimise the introduction of system defects and misconfigurations to the production environment, and have in place effective change recovery plans to deal with potential issues during the change implementation.”

The proposed requirements become even more explicit as the consultation stated: “FIs must carry out testing for all changes to critical systems before they are implemented in the production environment.”
It also requires firms to “have in place effective change recovery measures to recover any critical system affected by any issue arising during or after change implementation.”
For quality engineering teams, the proposals move well beyond conventional release testing. MAS is requiring financial institutions to establish formal processes for assessing the risks associated with proposed system changes before deployment, including evaluating “the impact on upstream and downstream systems.”
Financial institutions would then be expected to implement “risk mitigation measures that are commensurate with the risks identified.”
The emphasis on system dependencies is particularly notable as banks increasingly operate highly distributed technology environments built on cloud platforms, third-party software, APIs, open-source components and, increasingly, autonomous AI systems.
Understanding how changes propagate across interconnected platforms is becoming as important as validating the individual change itself.
Tech governance
The consultation also significantly expands expectations around technology governance. MAS proposes that firms maintain “a comprehensive and up-to-date inventory of all of their IT assets, which includes hardware, software, cryptographic assets, open-source and third-party components.”
It argued that maintaining such inventories supports vulnerability management, technology obsolescence management and “the identification and management of risks relating to specific third-party components and supply chain issues.”
The regulator is also proposing more structured IT risk management, requiring institutions to conduct regular IT risk assessments, maintain formal risk registers, assign accountable risk owners and establish key risk indicators to monitor both material risks and the effectiveness of mitigation measures.
“Lapses include … poor understanding of system dependencies, inadequate testing, and the absence of effective change recovery plans.”
– MAS
Continuous monitoring forms another major pillar of the proposals. MAS stressed it has observed “that a number of major IT incidents have also been attributed to lack of monitoring, delayed detection and/or slow response to rectify the causes of the incidents.”
It added that “the incidents could have been averted if the FIs had promptly discovered and responded to the issues.”
To address this, the regulator proposes that financial institutions establish frameworks “to continuously monitor all critical systems for timely detection and response to issues affecting the system performance or security.”
Those frameworks would include “defined indicators and thresholds that trigger alerts” together with response procedures and remedial actions appropriate to the identified issue.
The consultation also strengthens expectations around immutable or offline backups, incident management, evidence preservation, recovery planning and more explicit accounting for partial or intermittent service disruptions when calculating system downtime.
Wider policy
Taken together, the proposals reinforce a direction that has become increasingly visible across MAS initiatives over the past year.
In April, the regulator launched its MindForge AI Risk Management Toolkit, developed alongside major financial institutions including HSBC, Citi, UBS, BlackRock, DBS, Standard Chartered, UOB and Prudential.

At the time, MAS described the toolkit as supporting the “responsible adoption of AI in finance”, while MAS Chief FinTech Officer Kenneth Gray said the initiative would strengthen “AI governance and risk management practices across the industry”.
Alan Lim, Director in MAS’ Financial Infrastructure & AI Office, explained that the package was designed to help firms move “from theory to practice”.
That framework attracted widespread support across the industry. BlackRock’s Marko Milek said it helped translate “responsible AI principles into actionable risk management”, while DBS Chief Analytics Officer Sameer Gupta argued that “to fully realise AI’s value, governance must be treated as a strategic imperative”.
Those themes have continued to emerge in subsequent MAS initiatives.
In May, MAS launched a proof-of-value project using data from multiple banks to explore AI-driven scam detection. The regulator said “prompt identification could enable timely assessment, intervention and reduction of customer losses to scams.”
More significantly, the project demonstrated how governance, model validation and operational controls increasingly have to be tested together rather than treated as separate disciplines.
And only last week, MAS published its SAFR framework for autonomous AI agents, arguing that “financial institutions need real-time safeguards” as AI agents increasingly operate “at speed beyond practical human intervention.”
The framework introduced concepts including “policy bound execution, real time validation, auditability and interoperability” to help ensure AI agents remain within predefined mandates and risk boundaries.
The latest consultation extends many of those same principles beyond AI into mainstream technology governance.
One of the strongest connections is around dependencies. While SAFR highlighted interoperability between AI agents and runtime validation of autonomous systems, the TRM consultation focuses on understanding dependencies between upstream and downstream systems before changes reach production.
In both cases, MAS is increasingly concerned with how complex technology environments behave under real operational conditions rather than whether individual components perform correctly in isolation.
Partnership with FCA
The consultation also reinforces Singapore’s wider regulatory philosophy around operational resilience.
Last year, MAS and the UK’s Financial Conduct Authority announced a partnership focused on advancing AI testing, regulatory quality assurance and supervised experimentation.
Jessica Rusu, the FCA’s Chief Data, Information and Intelligence Officer, said the collaboration would “be championing safe and responsible AI innovation across UK and Singapore markets.”

That initiative reflected a broader shift towards shared validation environments and practical testing rather than relying solely on firms to self-certify emerging technologies.
The same philosophy has also shaped Singapore’s digital banking sector. Regulatory expectations around resilience, governance and operational continuity have encouraged banks to embed continuous testing, automated controls and evidence generation directly into software delivery pipelines, making quality engineering an increasingly important component of regulatory compliance.
Viewed individually, the consultation updates change management requirements, technology inventories and operational resilience expectations.
Viewed alongside MindForge, the scam-detection proof-of-value, the FCA collaboration and SAFR, however, a broader pattern emerges.
MAS is steadily moving from governance principles towards operational assurance.
Whether the subject is AI models, autonomous agents or traditional banking platforms, the regulator is increasingly asking financial institutions to demonstrate that systems have been properly tested, that controls work under real operating conditions, that dependencies are understood, that monitoring is continuous and that evidence can be produced when supervisors ask for it.
For QA and software testing teams, that may be the consultation’s most significant message. Testing is no longer presented simply as an engineering discipline that improves software quality. Increasingly, it is becoming a core supervisory expectation that underpins operational resilience, technology governance and trust across some of the world’s most complex financial systems.
16 SEPTEMBER IN LONDON

REGISTER TODAY – SIMPLY CLICK HERE
Why not become a QA Financial subscriber?
It’s entirely FREE
* Receive our weekly newsletter every Wednesday * Get priority invitations to our Forum events *
REGULATION & COMPLIANCE
Looking for more news on regulations and compliance requirements driving developments in software quality engineering at financial firms? Visit our dedicated Regulation & Compliance page here.
READ MORE
- AI adoption strains JPMorgan testing
- Can banks ‘outsource’ AI accountability?
- HDFC Bank raises testing stakes
- Is observability banking QA’s next discipline?
- Barclays on AI testing, telemetry and kill switches
WATCH NOW


QA FINANCIAL PODCASTS

CLICK HERE TO LISTEN TO OUR EXCLUSIVE CONVERSATIONS



