Lifecycle controls
Collection, access, storage, transfer and disposal of customer information.
A customer information protection review checks a financial institution's handling of customer information against both BNM's MCIPD policy and the PDPA. Financial institutions answer to two data regimes: the PDPA and BNM's policy on Management of Customer Information and Permitted Disclosures. We review your controls, disclosures and breach processes against both, so one incident does not become two findings.
A compliance review of how your institution handles customer information across its lifecycle, the disclosures it makes under the secrecy provisions, and how breach notification to BNM and to the Commissioner work together.
BNM's revised policy, issued on 31 October 2025, added a duty to notify BNM of customer information breaches that cause or are likely to cause significant harm or affect more than 1,000 customers, and to notify affected customers. The PDPA separately requires notification to the Commissioner within 72 hours. Institutions that treat these as one process miss one of them.
Collection, access, storage, transfer and disposal of customer information.
Disclosures to agents, group entities and third parties tested against the statutory schedules.
BNM and PDPA notification thresholds, timelines and decision rights mapped into one playbook.
Outsourced and technology providers handling customer information.
Access controls, monitoring and staff conduct.
What the board should see on customer information risk.
Notification decisions made once, correctly.
Gaps closed before supervision finds them.
Staff know what they may share.
Records that show compliance.
Customer information risk reported properly.
Entities, products and channels in scope.
Policies, procedures and past incidents.
Sample disclosures, access and breach cases.
Against MCIPD and the PDPA.
Findings, remediation and an aligned breach playbook.
MCIPD and PDPA gaps.
Tested sample results.
BNM, Commissioner and customer notifications.
Owners and dates.
Position and key risks.
We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.
Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.
Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.
Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.
Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.
MCIPD is Bank Negara Malaysia's Policy Document on Management of Customer Information and Permitted Disclosures, revised on 31 October 2025. It sets how financial service providers protect customer information across its lifecycle, what disclosures the secrecy provisions permit, and when customer information breaches must be notified to BNM and to customers.
Where a customer information breach causes or is likely to cause significant harm, or affects or is likely to affect more than 1,000 customers. Affected customers must be notified as well. We map the exact decision points, owners and timelines into your breach playbook so the BNM and PDPA notifications run together.
No. The PDPA separately requires notification to the Commissioner within 72 hours, so a single customer information breach can trigger two regulatory notifications. The review aligns both processes, so one incident does not become two findings because a team followed only the procedure it knew.
Financial service providers regulated by BNM, including banks, insurers, takaful operators and development financial institutions. Payment companies and other BNM-regulated entities should confirm which parts apply to them. We confirm scope for your licence type at the start of the review.
No. It is a compliance review of controls, processes and disclosures: how customer information is handled, who can disclose it and on what basis, and how breaches are escalated and notified. Technical security testing is a separate engagement and can be arranged alongside it.