BNM Technology Requirements for Payment Services Regulatees

On 12 March 2026 Bank Negara Malaysia issued its Technology Requirements for Payment Services Regulatees, a 74-page policy document for approved e-money issuers, registered merchant acquirers, licensed money services businesses and operators of designated payment systems. It comes into effect one year after issuance, on 12 March 2027, and replaces the technology paragraphs of the existing e-money, merchant acquiring, money services and payment system operator policy documents. It applies proportionately through four tiers: tier one institutions stay under RMiT, tier two covers those with annual transaction value above RM1.5 billion or volume above seven million, tier three covers smaller players, and tier four covers non-digital money changers. Every regulatee had to submit a gap analysis and action plan within ninety days of issuance, and BNM can require external reviews, remediation plans or additional capital where technology risk management is materially weak.

This two-day course is for the technology, risk, compliance and operations teams, and the boards, of Malaysian payment companies and fintechs. It goes through the policy document section by section, from governance and technology risk management to operations, cyber security, digital services, audits and external assurance, and the appendices on cloud, mobile apps, fraud detection, payment acceptance devices and QR codes. Day two focuses on implementation: confirming your tier, closing gaps from the ninety-day assessment, and evidencing compliance before March 2027. Banks and other RMiT institutions should see BNM RMiT Compliance.

HRD Corp Training Provider Malaysia HRD Corp SBL-Khas Claimable

Programme Agenda

01

Day 1, 9:00 AM - 9:15 AM

Welcome and Programme Overview

Introduction to the session, objectives, and housekeeping.

02

Day 1, 9:15 AM - 10:15 AM

Scope, Tiers and Timeline

Which regulatees the policy covers and which it excludes, the four tiers and how transaction value and volume are measured, including combining group entities that share infrastructure, the provisions marked as standards versus guidance, the 12 March 2027 effective date and the ninety-day gap analysis.

03

Day 1, 10:15 AM - 10:30 AM

Break

04

Day 1, 10:30 AM - 11:30 AM

Governance and Technology Risk Management

Board and senior management responsibilities, the technology risk management framework, and the tier-based differences in what is required.

05

Day 1, 11:30 AM - 12:30 PM

Technology Operations Management

System development and change, capacity and availability, data centre and cloud operations, backups and recovery, and the controls on removable media and self-service terminals.

06

Day 1, 12:30 PM - 1:30 PM

Lunch

07

Day 1, 1:30 PM - 3:15 PM

Cyber Security Management

The cyber security requirements and appendix controls, threat monitoring, vulnerability management, penetration testing, and incident response.

08

Day 1, 3:15 PM - 3:30 PM

Break

09

Day 1, 3:30 PM - 4:45 PM

Digital Services, Mobile Apps and Fraud Detection

Controls for digital services and mobile applications, the fraud detection standards, and the specific requirements for payment acceptance devices and QR codes.

10

Day 1, 4:45 PM - 5:00 PM

Day 1 Close

Recap and what to review before day two.

11

Day 2, 9:00 AM - 9:15 AM

Day 1 Review

Recap of day one and the questions it left open.

12

Day 2, 9:15 AM - 10:15 AM

Third Parties and Cloud

IT and cyber risks from third-party service providers, the key risks and control measures for cloud services, and what to put in contracts and oversight.

13

Day 2, 10:15 AM - 10:30 AM

Break

14

Day 2, 10:30 AM - 12:30 PM

Audits, External Assurance and the Simplified Approach

Technology audit expectations, when external party assurance is required, internal awareness and training, and the simplified approach available to some regulatees.

15

Day 2, 12:30 PM - 1:30 PM

Lunch

16

Day 2, 1:30 PM - 3:15 PM

Closing Gaps Before March 2027

Turning the ninety-day gap analysis into a funded, sequenced remediation plan, board reporting, and preparing for BNM supervisory review.

17

Day 2, 3:15 PM - 3:30 PM

Break

18

Day 2, 3:30 PM - 4:45 PM

Workshop: Tiering and Gap Review

Teams confirm the tier for a case payment company, review its gap analysis against the policy, and prioritise the remediation actions due before the effective date.

19

Day 2, 4:45 PM - 5:00 PM

Wrap-Up and Q&A

Key takeaways, next steps, and close.

Key Outcomes

  • Determine which tier your institution falls into and which provisions apply
  • Explain the governance, operations, cyber security and digital service requirements
  • Apply the cloud, third-party, fraud detection, device and QR code controls
  • Prepare for technology audits and external assurance
  • Turn the gap analysis into a remediation plan that lands before 12 March 2027
  • Report progress and residual risk to the board

Training Mode   Physical / Online / Hybrid / e-learning

HRD Corp   SBL-Khas Claimable

Level   Intermediate. For technology, risk, compliance and operations leads, and directors, at e-money issuers, merchant acquirers, money services businesses, payment system operators and payment fintechs.

Duration   2 Days (16 Hours)  |  9:00 AM to 5:00 PM daily

Venue   In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)

Assessment   A tiering decision and gap review for a case payment company, plus a written knowledge check

Certificate   Certificate of Completion issued to all participants upon full attendance

Enquiries   Contact us to register or discuss scheduling

Frequently Asked Questions

Yes. BNM Technology Requirements for Payment Services Regulatees is HRD Corp SBL-Khas claimable. Employers registered with HRD Corp (PSMB) can claim the training fee against their levy, as Orbix Tech Sdn Bhd is an HRD Corp certified training provider. Submit the SBL-Khas application before the session date.

BNM Technology Requirements for Payment Services Regulatees runs for 2 days (16 hours) | 9:00 AM to 5:00 PM daily. It is delivered as an in-house closed group session, so the schedule can be adjusted to fit your team's working hours.

Yes. Delivery options are physical, online, hybrid, e-learning. In-house sessions run at your premises anywhere in Malaysia, online sessions run live over video conference, and hybrid combines both for teams split across sites.

Certificate of Completion issued to all participants upon full attendance. Each certificate carries a certificate number that can be checked at orbixtech.my/certificate-verify.

Level: Intermediate. For technology, risk, compliance and operations leads, and directors, at e-money issuers, merchant acquirers, money services businesses, payment system operators and payment fintechs. The session is built around worked examples and group exercises rather than theory, so participants apply the material to their own organisation during the session.

Half-day and full-day sessions are quoted per session for a closed group, from RM 800 and RM 1,750 respectively. Advanced 2-day programmes are quoted per participant, from RM 4,000. All figures are before any HRD Corp levy claim.