Tier confirmation
Transaction value and volume tested against the tiers.
BNM's Technology Requirements for e-money issuers, merchant acquirers, money services businesses and payment system operators come into effect on 12 March 2027. We confirm your tier, close the gaps from your 90-day gap analysis, and build the evidence BNM will ask for.
A readiness engagement against the Technology Requirements for Payment Services Regulatees (BNM/RH/PD 040-1): tiering, gap assessment, remediation planning and evidence building.
The policy was issued on 12 March 2026, takes effect one year later, and required a gap analysis and action plan within 90 days of issuance. It applies proportionately through four tiers and covers governance, technology risk, operations, cyber security, digital services, cloud, fraud detection, payment devices and QR codes. With the deadline approaching, many payment companies still have open gaps.
Transaction value and volume tested against the tiers.
Updating your 90-day gap analysis.
Board, framework and policies.
Controls and evidence.
Appendix requirements.
Ready for BNM review.
Ready by 12 March 2027.
Tier-appropriate controls.
Not just controls.
Progress reported.
Plans your team can execute.
Confirming applicable requirements.
Current state.
Sequenced remediation.
Policies and evidence.
Before the effective date.
Your tier and why.
Updated.
Sequenced.
Where needed.
For supervision.
We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.
Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.
Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.
Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.
Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.
On 12 March 2027, one year after issuance.
Tiers depend on annual transaction value and volume, with tier one under RMiT. We confirm yours.
Prepare it now and engage BNM. We can help build it quickly.
No. This is a compliance readiness service. Technical testing is separate.
Typically two to four months depending on gaps.
Tell us your licence type and transaction volumes. We will scope readiness support.