Raymond Cheung
Chartered Actuary · CRO · Board Adviser · Singapore
Every Singapore insurer has a TRM programme. Most boards approve the annual attestation in under fifteen minutes without understanding what they are signing. MAS's Technology Risk Management guidelines place substantive obligations on the board -- not just the CIO and CISO. This is what those obligations actually require, and where Singapore insurance boards are routinely falling short.
I was in a Singapore insurer's board risk committee meeting when the CIO presented the annual TRM attestation package. Forty-three pages. The board approved it in nine minutes. The only question from the floor was whether the company was compliant. The CIO said yes. The chair nodded. The board moved to the next agenda item. Nobody asked what the company's technology risk appetite was, whether it had been breached in the past year, whether the CISO had escalated anything that had not reached the board, or what the most significant technology risk the insurer would face in the next twelve months actually was. The attestation was signed. The governance was not done.
That meeting is not unusual. It is close to the norm. Singapore insurers have invested heavily in their TRM programmes at the management level -- CIO-CISO structures, incident response frameworks, vendor risk assessments, cloud governance policies. What most have not built is meaningful board governance of technology risk. The distinction matters because MAS's Technology Risk Management guidelines do not just regulate the IT department. They place explicit obligations on the board and senior management. When a supervisor reviews your TRM programme, they will eventually ask what the board knew, what it challenged, and what it decided. The attestation signature is not the answer.
What MAS's TRM guidelines require from the board -- not the IT team
The MAS Technology Risk Management guidelines, revised in January 2021 and applicable to all MAS-regulated financial institutions including insurers under MAS Notice 127, set out a governance layer that sits above the operational controls. The key board and senior management requirements are: board members should collectively have the knowledge to understand and manage technology risks, including cyber threats; the board should ensure a CIO, CTO or head of IT and a CISO or head of information security with the requisite expertise and experience are appointed; and the board should ensure that technology risk is managed in line with the institution's risk appetite.
These requirements have a standard compliance interpretation and a governance interpretation. The compliance interpretation produces the forty-three-page attestation package. The governance interpretation requires the board to be able to answer three questions before it approves anything.
- What is our technology risk appetite, and what event or breach would require immediate board escalation rather than management handling?
- When was the last material technology incident, what did it cost the institution in recovery and reputational terms, and what specifically changed as a result?
- Is our CISO genuinely operationally independent of the CIO, and can they escalate a technology risk concern directly to the board risk committee without going through management?
If a Singapore insurance board cannot answer those three questions at the time it approves the TRM attestation, it is approving a compliance document, not exercising governance. The distinction will eventually matter when a technology incident occurs and a supervisor asks the board what it knew.
The MAS Notice 127 context Singapore insurance boards overlook
Singapore insurers operate under both the general MAS TRM guidelines and MAS Notice 127, which specifies technology risk management requirements for licensed insurers. Notice 127 requires insurers to establish a technology risk management framework approved by the board; to maintain a technology risk register identifying material technology risks; and to submit technology risk incident reports to MAS for qualifying incidents within defined timeframes.
The board's role in the Notice 127 framework is not passive approval. The technology risk management framework must be board-approved, which means the board must have reviewed and challenged the framework's scope, its risk classification criteria, its escalation thresholds, and its coverage of cloud, third-party, and legacy system risks. Most boards approve a framework document that management has prepared without the forensic review that approval is supposed to represent. The question a MAS supervisor would ask is not whether the framework was approved -- they can read the minutes. The question is whether the approval reflected genuine board understanding of what was being approved.
“If the board cannot tell you its technology risk appetite in one sentence, it does not have one -- it has an attestation.”
Where Singapore insurance boards are falling short on TRM governance
Three patterns come up repeatedly when I look at how Singapore insurers are actually governing technology risk at board level. The first is consolidation without distinction. Technology risk, cyber risk, data risk, and operational technology risk are bundled into a single board agenda item, often within the operational risk section of the risk committee report. Each of these risk categories has a different MAS regulatory reference, a different incident profile, and requires different board competencies to challenge. Bundling them produces a high-level summary that satisfies no one supervisory requirement in depth.
The second pattern is approving attestations without reading qualifications. TRM attestations often contain material qualifications -- exceptions noted, timelines slipped, controls assessed as 'in progress'. Boards that approve attestation packages without specifically addressing the qualifications are accepting risk that management has formally noted but the board has not formally acknowledged. In a post-incident review, those qualifications become evidence of known risk that the board failed to act on.
The third pattern is the CISO access problem. The MAS guidelines require the board to ensure a CISO with requisite expertise is appointed. They do not require the CISO to attend the board or have direct board access. Most Singapore insurance boards receive technology risk information through the CIO's reporting line. The CISO's independent assessment of technology risk posture -- which may differ materially from the CIO's -- rarely reaches the board directly. This creates a structural blind spot at exactly the layer where independent oversight is most valuable.
What substantive TRM governance looks like in practice
The boards I have seen handle technology risk governance well do four things differently from the standard approach. They schedule a dedicated TRM agenda item -- not combined with cyber or operational risk -- at least twice a year, with the CISO attending to present directly to the board rather than through the CIO. They maintain a technology risk appetite statement that is short enough to be memorised by each board member, specific enough to define a clear escalation trigger, and reviewed annually before the TRM attestation is approved. They track the age and status of all significant technology risk exceptions through a separate risk committee paper, not buried in an annex. And they treat the annual TRM attestation as a checkpoint, not a conclusion -- what changed since last year, what the current material risks are, and what the board is explicitly accepting versus requiring management to remediate.
The MAS TRM guidelines are not ambiguous about what the board's role is. They are clear that governance of technology risk sits at board level. What is ambiguous is whether most Singapore insurance boards have accepted that responsibility or delegated it to the IT function with a signature. As MAS's supervisory focus on governance quality intensifies, that ambiguity is going to resolve itself in the form of post-incident questions that the board has not prepared answers for.
Common Questions
What do MAS's Technology Risk Management guidelines require of the board of a Singapore insurer?
The MAS TRM guidelines require the board and senior management to have collective knowledge to understand and manage technology risks including cyber threats; to ensure a CIO and CISO with requisite expertise are appointed; to approve the technology risk management framework; and to ensure technology risk is managed in line with the institution's stated risk appetite. These are board-level obligations, not IT department compliance tasks. MAS Notice 127 adds insurer-specific requirements including board approval of the technology risk management framework and incident reporting obligations for material technology events.
How is MAS Notice 127 different from the general TRM guidelines for Singapore insurers?
The general MAS TRM guidelines apply to all MAS-regulated financial institutions and set the governance and operational standards for technology risk management. MAS Notice 127 is insurer-specific and imposes additional requirements including maintaining a technology risk register, submitting incident reports to MAS for qualifying technology events within defined timeframes, and having the technology risk management framework explicitly approved by the board of directors. For licensed insurers, both the general guidelines and Notice 127 apply concurrently.
What should a Singapore insurance board actually do when the CIO presents the annual TRM attestation?
Before approving the attestation, the board should be able to confirm: what the institution's current technology risk appetite is and whether any exceptions represent a breach; what material technology incidents occurred in the past year and what specifically changed as a result; whether any qualifications or exceptions in the attestation package require explicit board acknowledgement rather than passive approval; and whether the CISO's independent assessment aligns with the CIO's presentation. If the board cannot answer these questions at the meeting, the attestation should not be approved until the information is supplied.
How often should technology risk be reported to the board of a Singapore insurer?
MAS's TRM guidelines require technology risk reporting to the board at 'reasonable frequency' -- the guidelines do not specify a minimum. Best practice for a Singapore insurance board is a dedicated TRM agenda item at least twice per year, with the CISO attending to present directly to the board rather than through the CIO reporting line. Material technology incidents should be escalated to the board on an ad hoc basis rather than waiting for the scheduled reporting cycle. The annual attestation alone is not sufficient as the primary vehicle for board oversight of technology risk.
Related insights
About the author
Raymond Cheung is a Chartered Actuary, C-suite executive and board adviser with more than 20 years of experience across Asia in risk management, insurance, ESG and corporate governance. He is the CEO of CER Consultancy and an accredited trainer at SMU Academy and the Singapore College of Insurance.