Governance and policy
Cyber security policy, objectives and roles.
An RMiT and NCII code of practice gap assessment checks a financial institution's policies, processes and evidence against BNM's RMiT and its Appendix 12. BNM added the Cyber Security Act code of practice for designated financial institutions to RMiT as Appendix 12 on 25 September 2026. We assess your compliance clause by clause, map each gap to RMiT, and give you a plan and a compliance report for your governance committee.
A compliance gap assessment of your policies, processes and evidence against RMiT and Appendix 12. It is a documentation and control review, not a technical penetration test.
Appendix 12 is legally binding on financial institutions designated as NCII entities by BNM. It requires annual cyber risk assessments and audits at least every two years by a NACSA-approved auditor, each reported to NACSA within 30 days, notice of material NCII changes within 30 days, incident notification immediately and within 6 hours, and an annual review of code compliance. It prevails over the rest of RMiT where they differ.
Cyber security policy, objectives and roles.
CISO, budget and training.
Plans, cycles and NACSA reporting.
Inventory and material change notice.
Notification timelines, CSIRT and testing.
Data, access, network and vulnerability management records.
Know where you stand on Appendix 12.
No duplicate effort.
30-day and 6-hour duties covered.
Annual compliance report drafted.
Objective view for the board.
Entities and NCII systems.
Policies, records and reports.
Clause by clause.
Interviews and walkthroughs.
Gaps, plan and compliance report.
Every clause.
Appendix 12 to main body.
Owners and dates.
For the governance committee.
Position and risks.
We do not resell products, so nothing here is shaped by a vendor margin. The recommendation is whatever your risk and your budget actually justify, including telling you that you do not need the engagement yet.
Findings come with a sequence, an owner and a realistic effort estimate, sized to the team you have rather than the team a framework assumes. A report that cannot be acted on is an expense, not a control.
Our people have carried the obligation internally, not only audited it. That shows up in what we consider proportionate, and in how much documentation we think you genuinely need.
Work is grounded in Malaysian law and regulator expectation, from the PDPA and the Cyber Security Act 2024 to Bursa, BNM and SC requirements, rather than translated from a European or American template.
Where an engagement includes training, the training component is structured to be HRD Corp SBL-Khas claimable, which changes what the programme costs you in practice.
BNM states that the code of practice requirements were endorsed by NACSA and included in RMiT as Appendix 12 on 25 September 2026. It is legally binding on financial institutions designated as NCII entities, and prevails over the rest of RMiT where they differ.
No. The mandatory audit, due at least every two years, must be performed by a NACSA-approved auditor and reported to NACSA within 30 days. This assessment prepares you for it by finding and closing the gaps first.
No. This is a compliance and evidence review of policies, processes and records against RMiT and Appendix 12. Technical testing, such as penetration testing, is performed separately by specialist providers, and we check whether its results are evidenced.
Yes, if designation as an NCII entity is possible for your institution, since the requirements apply quickly once designated. Institutions that are not designated also use it as a benchmark against RMiT, which applies to them regardless.
Typically four to eight weeks, depending on the size of the institution and how much evidence is already organised. The assessment ends with a clause-by-clause gap list mapped to RMiT, a remediation plan and a compliance report for your governance committee.