Data Protection / Financial Institutions

Customer Information Protection Review (BNM MCIPD)

A customer information protection review checks a financial institution's handling of customer information against both BNM's MCIPD policy and the PDPA. Financial institutions answer to two data regimes: the PDPA and BNM's policy on Management of Customer Information and Permitted Disclosures. We review your controls, disclosures and breach processes against both, so one incident does not become two findings.

Mapped to the MCIPD policy of 31 October 2025 BNM and PDPA breach notification aligned Permitted disclosures under FSA, IFSA and DFIA tested
Overview

Customer Information Protection Review

What it is

A compliance review of how your institution handles customer information across its lifecycle, the disclosures it makes under the secrecy provisions, and how breach notification to BNM and to the Commissioner work together.

Why organisations need it

BNM's revised policy, issued on 31 October 2025, added a duty to notify BNM of customer information breaches that cause or are likely to cause significant harm or affect more than 1,000 customers, and to notify affected customers. The PDPA separately requires notification to the Commissioner within 72 hours. Institutions that treat these as one process miss one of them.

Key features

What the engagement covers

Lifecycle controls

Collection, access, storage, transfer and disposal of customer information.

Permitted disclosures

Disclosures to agents, group entities and third parties tested against the statutory schedules.

Breach notification

BNM and PDPA notification thresholds, timelines and decision rights mapped into one playbook.

Third parties

Outsourced and technology providers handling customer information.

Staff and access

Access controls, monitoring and staff conduct.

Board reporting

What the board should see on customer information risk.

Business value

What the business gets out of it

One process for two regimes

Notification decisions made once, correctly.

Fewer findings

Gaps closed before supervision finds them.

Clear disclosures

Staff know what they may share.

Evidence ready

Records that show compliance.

Board visibility

Customer information risk reported properly.

How it works

How the engagement runs

01

Scoping

Entities, products and channels in scope.

02

Document review

Policies, procedures and past incidents.

03

Testing

Sample disclosures, access and breach cases.

04

Gap analysis

Against MCIPD and the PDPA.

05

Report

Findings, remediation and an aligned breach playbook.

Deliverables

What you receive

Gap report

MCIPD and PDPA gaps.

Disclosure review

Tested sample results.

Breach notification playbook

BNM, Commissioner and customer notifications.

Remediation plan

Owners and dates.

Board summary

Position and key risks.

Who it is for

Who this is built for

Industries

Banks and Islamic banksInsurers and takaful operatorsDevelopment financial institutionsE-money issuersPayment companiesMoney services businesses

Company sizes

Licensed financial institutionsPayment and e-money institutions

Departments

ComplianceData protectionOperationsTechnology riskInternal audit
Why Orbix

Why organisations choose Orbix

A governance approach, not a tool sale

We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.

Recommendations you can actually implement

Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.

Consultants who have sat on your side of the table

Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.

Built for the Malaysian operating context

Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.

HRD Corp expertise where it applies

Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.

Questions

Questions we get asked

What is MCIPD?

MCIPD is Bank Negara Malaysia's Policy Document on Management of Customer Information and Permitted Disclosures, revised on 31 October 2025. It sets how financial service providers protect customer information across its lifecycle, what disclosures the secrecy provisions permit, and when customer information breaches must be notified to BNM and to customers.

When must we notify BNM?

Where a customer information breach causes or is likely to cause significant harm, or affects or is likely to affect more than 1,000 customers. Affected customers must be notified as well. We map the exact decision points, owners and timelines into your breach playbook so the BNM and PDPA notifications run together.

Does this replace PDPA notification?

No. The PDPA separately requires notification to the Commissioner within 72 hours, so a single customer information breach can trigger two regulatory notifications. The review aligns both processes, so one incident does not become two findings because a team followed only the procedure it knew.

Who does MCIPD apply to?

Financial service providers regulated by BNM, including banks, insurers, takaful operators and development financial institutions. Payment companies and other BNM-regulated entities should confirm which parts apply to them. We confirm scope for your licence type at the start of the review.

Is this a technical security test?

No. It is a compliance review of controls, processes and disclosures: how customer information is handled, who can disclose it and on what basis, and how breaches are escalated and notified. Technical security testing is a separate engagement and can be arranged alongside it.