RiskPedia
SG
Singapore Hub
Where rules align, conflict and layer

Regulator Overlap Matrix.

MAS TRM × MAS Notice 655 × PDPA × CSA × MindForge — mapped across 10 control dimensions.

Dimension
MAS TRM
MAS-regulated FIs
MAS 655
All MAS FIs
PDPA
All organisations
CSA / CCoP
CII operators
MindForge
AI-using FIs
GovernanceBoard + ITRCDPO mandatoryCybersecurity OfficerAI governance committee
Incident Reporting1 hour (material)Per incident≤3 days to PDPCPer CSA timeline
Data ProtectionAligned to PDPA9 obligationsData quality + lineage
Cyber ControlsTRM §10–116 baselines mandatoryReasonable safeguardsCCoP 2.0 controlsAI security
Third-Party RiskTRM §13Transfer LimitationYes — vendorsFoundation-model vendors
Business ContinuityTRM §8Mandatory exercise
AuditAnnual IS auditSelf-auditAnnual auditModel validation
AI RiskVeritas-alignedIndirect (data quality)Core focus
Personnel/TrainingTRM §5AwarenessPDPA trainingCyber trainingAI ethics training
PenaltiesMAS ActUp to S$100k10% turnover / S$1mS$100k + 2yrVia MAS TRM

Scroll horizontally to compare. Cells show the regulator's specific requirement for each dimension. — indicates 'not directly addressed'.

Made with Emergent