Cybersecurity / Financial Sector

RMiT and NCII Code of Practice Gap Assessment

An RMiT and NCII code of practice gap assessment checks a financial institution's policies, processes and evidence against BNM's RMiT and its Appendix 12. BNM added the Cyber Security Act code of practice for designated financial institutions to RMiT as Appendix 12 on 25 September 2026. We assess your compliance clause by clause, map each gap to RMiT, and give you a plan and a compliance report for your governance committee.

Clause-by-clause against Appendix 12 and RMiT Audit, risk assessment and notification duties tested Gap plan and annual compliance report
Overview

RMiT and NCII Code of Practice Gap Assessment

What it is

A compliance gap assessment of your policies, processes and evidence against RMiT and Appendix 12. It is a documentation and control review, not a technical penetration test.

Why organisations need it

Appendix 12 is legally binding on financial institutions designated as NCII entities by BNM. It requires annual cyber risk assessments and audits at least every two years by a NACSA-approved auditor, each reported to NACSA within 30 days, notice of material NCII changes within 30 days, incident notification immediately and within 6 hours, and an annual review of code compliance. It prevails over the rest of RMiT where they differ.

Key features

What the engagement covers

Governance and policy

Cyber security policy, objectives and roles.

Resources and awareness

CISO, budget and training.

Audit and risk assessment

Plans, cycles and NACSA reporting.

Assets and changes

Inventory and material change notice.

Incidents and continuity

Notification timelines, CSIRT and testing.

Controls evidence

Data, access, network and vulnerability management records.

Business value

What the business gets out of it

Clear position

Know where you stand on Appendix 12.

Mapped to RMiT

No duplicate effort.

Deadlines met

30-day and 6-hour duties covered.

Committee-ready

Annual compliance report drafted.

Independent

Objective view for the board.

How it works

How the engagement runs

01

Scoping

Entities and NCII systems.

02

Evidence collection

Policies, records and reports.

03

Assessment

Clause by clause.

04

Validation

Interviews and walkthroughs.

05

Report

Gaps, plan and compliance report.

Deliverables

What you receive

Gap assessment report

Every clause.

RMiT mapping

Appendix 12 to main body.

Remediation plan

Owners and dates.

Compliance report draft

For the governance committee.

Board summary

Position and risks.

Who it is for

Who this is built for

Industries

Banks and Islamic banksInsurers and takaful operatorsDevelopment financial institutionsE-money issuersPayment companiesMoney services businesses

Company sizes

BNM-designated NCII entitiesInstitutions that may be designated

Departments

CISOTechnology riskComplianceInternal auditBoard risk committee
Why Orbix

Why organisations choose Orbix

A governance approach, not a tool sale

We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.

Recommendations you can actually implement

Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.

Consultants who have sat on your side of the table

Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.

Built for the Malaysian operating context

Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.

HRD Corp expertise where it applies

Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.

Questions

Questions we get asked

Is Appendix 12 in force?

BNM states that the code of practice requirements were endorsed by NACSA and included in RMiT as Appendix 12 on 25 September 2026. It is legally binding on financial institutions designated as NCII entities, and prevails over the rest of RMiT where they differ.

Is this the mandatory NACSA audit?

No. The mandatory audit, due at least every two years, must be performed by a NACSA-approved auditor and reported to NACSA within 30 days. This assessment prepares you for it by finding and closing the gaps first.

Do you perform technical testing?

No. This is a compliance and evidence review of policies, processes and records against RMiT and Appendix 12. Technical testing, such as penetration testing, is performed separately by specialist providers, and we check whether its results are evidenced.

We are not designated. Is it useful?

Yes, if designation as an NCII entity is possible for your institution, since the requirements apply quickly once designated. Institutions that are not designated also use it as a benchmark against RMiT, which applies to them regardless.

How long does it take?

Typically four to eight weeks, depending on the size of the institution and how much evidence is already organised. The assessment ends with a clause-by-clause gap list mapped to RMiT, a remediation plan and a compliance report for your governance committee.