Free Sample · No Credit Card

See a Real MAS Obligation Register, Free.

Twenty real obligations stratified across the whole TRM instrument, in all three formats. Every field of the paid tiers except the Policy Suite prose, so you can judge the depth, the citations, and the parsing for yourself.

  • 20 real obligations stratified across the whole TRM instrument
  • Byte-exact verbatim and a legal citation on every record
  • The same 46-column schema as the Compliance Intelligence tier, measured from the shipped file
  • ProfytAI Regulatory Intelligence on every record
  • An annotated source-page evidence capture with every record, reproduced with MAS's written permission
  • JSON for pipelines and RAG, CSV for Excel and BI
  • Official MAS source link and full citation on every record

Get the Free Sample

Preview the depth, the citations, and the parsing for yourself. We use your details to follow up and to keep you posted as new jurisdictions go live.

Sample pack zip · 20 obligations · No credit card

Dataset Details

Dataset Details

Twenty real MAS TRM obligations, stratified across the whole instrument, with every layer except the Policy Suite prose. Each record carries the regulator's byte-exact words and citation, the parsed duty, ProfytAI Regulatory Intelligence, an evidence checklist, and an annotated capture of its source page, reproduced with MAS's written permission.

Verify the depth against the official MAS PDF at no cost, then license the tier you need.

Who It Is For

Bank and fintech compliance teams, technology risk officers, internal audit, and the consultancies that advise them. It suits any institution that must evidence its posture against MAS technology risk expectations.

Why It Exists

Published regulation is authoritative but unstructured. Hundreds of duties sit buried in prose across a long PDF. Building a usable, cited register by hand is slow, fragile and hard to prove. This dataset does that work once, correctly, and ships it as structured data.

Expected Business Outcomes

Judge It Before You Commit

Twenty complete records, verifiable against the official PDF at no cost, so the evaluation is of the data rather than of a brochure.

Proof Built In

Every record quotes the regulator byte-exactly and cites the exact pages of the published PDF. A certification script in the folder re-proves the whole package.

Audit-Ready Provenance

Every duty is quoted verbatim and page-anchored, so a finding traces to the source in one step.

Lower Key-Person Risk

The regulator's expectations are captured as structured data, not held in one analyst's spreadsheet.

Licensed Under the ProfytAI Commercial Data License · View Licensing Terms

A Real Record

A Real Record, in Full.

A real record pulled straight from the full register. The download carries twenty records of this same shape, stratified across the whole TRM instrument.

See the Full 357-Obligation Register

MAS.TRM.2021.Sec6.4.2.p21.OBL1

Software Application Development and Management
SHOULDmedium priorityMAS TRMp.21
Source TextVerbatim · Guidance
A well-defined vetting process should be implemented for assessing third parties’ suitability in connecting to the FI via APIs, as well as governing third party API access.
In Plain Language

A well-defined vetting process should be implemented to assess whether third parties are suitable to connect to the FI via APIs and to govern their API access.

Parsed Duty
ActorFI
Actionimplement a well-defined vetting process
Objectthird parties’ suitability to connect via APIs and third party API access
Structured FieldsDeontic · recommendation

Deontic

recommendation

Type

Process

Strength

Recommended

Frequency

Ongoing

Status

In Force

Sanction

supervisory

IT & Technology RiskSecure Development
Duties and Evidence Checklist3 Duties
1

Document the vetting process applied to third parties seeking API connectivity.

Done WhenA written vetting process exists, stating the assessment steps, who performs them and who decides the outcome, and it is dated and approved.

EvidenceThird party API vetting process document

2

Run the vetting process for each third party before it is connected via an API.

Done WhenFor each third party with API connectivity, a completed vetting record exists and is dated before the connection was enabled.

EvidenceCompleted third party vetting record

3

Maintain the controls that govern third party API access after onboarding.

Done WhenA record exists showing, for each third party, which APIs it is authorised to access and the approval on which that access rests.

EvidenceThird party API access record

ProfytAI Regulatory IntelligenceAnalysis · process

Why This Exists

An API connection hands a counterparty a live route into the FI's systems. Judging counterparties case by case without a defined process gives inconsistent decisions and lets weak parties through on the strength of a commercial relationship.

Relationship

This is the first of two sentences in 6.4.2, creating the process, while the second sentence sets what the criteria must consider.

Interpretation

A guideline "should", so a supervisory expectation. Two jobs sit in one sentence. The process assesses suitability, and it also governs third party API access, so this is not only an onboarding gate. "Well-defined" points at a documented and repeatable process rather than individual judgement. The criteria the process must weigh come from the second sentence of the same paragraph. 6.4.3 adds a separate risk assessment before connection, so vetting the party does not discharge the assessment of the connection itself.

Watchouts

The words "as well as governing third party API access" are easy to skim past. They turn a point-in-time due diligence exercise into a continuing control over live connections.

Generated regulatory intelligence, traceable to the citation below. The verbatim source text remains the authority you cite.

MAS TRM, Section 6.4.2, p. 21 (2021)

Consequence. Non-adherence may attract MAS supervisory action; the TRM Guidelines set out the standards MAS expects financial institutions to meet.

Source · Technology Risk Management Guidelines

The record shows the key fields for readability. Every delivered record carries the complete schema: verbatim, normalized, parsed, context, ProfytAI regulatory intelligence, and fulfillment.

You Have Seen Twenty. The Register Has 357.

When the sample proves the depth, license the full register: all 357 TRM obligations, each addressed, classified, and quoted byte-exactly.

SampleConsultationRegisterPlatformSubscription