BNM Technology Requirements for Payment Services Regulatees
On 12 March 2026 Bank Negara Malaysia issued its Technology Requirements for Payment Services Regulatees, a 74-page policy document for approved e-money issuers, registered merchant acquirers, licensed money services businesses and operators of designated payment systems. It comes into effect one year after issuance, on 12 March 2027, and replaces the technology paragraphs of the existing e-money, merchant acquiring, money services and payment system operator policy documents. It applies proportionately through four tiers: tier one institutions stay under RMiT, tier two covers those with annual transaction value above RM1.5 billion or volume above seven million, tier three covers smaller players, and tier four covers non-digital money changers. Every regulatee had to submit a gap analysis and action plan within ninety days of issuance, and BNM can require external reviews, remediation plans or additional capital where technology risk management is materially weak.
This two-day course is for the technology, risk, compliance and operations teams, and the boards, of Malaysian payment companies and fintechs. It goes through the policy document section by section, from governance and technology risk management to operations, cyber security, digital services, audits and external assurance, and the appendices on cloud, mobile apps, fraud detection, payment acceptance devices and QR codes. Day two focuses on implementation: confirming your tier, closing gaps from the ninety-day assessment, and evidencing compliance before March 2027. Banks and other RMiT institutions should see BNM RMiT Compliance.
HRD Corp SBL-Khas Claimable
Programme Agenda
Day 1, 9:00 AM - 9:15 AM
Welcome and Programme Overview
Introduction to the session, objectives, and housekeeping.
Day 1, 9:15 AM - 10:15 AM
Scope, Tiers and Timeline
Which regulatees the policy covers and which it excludes, the four tiers and how transaction value and volume are measured, including combining group entities that share infrastructure, the provisions marked as standards versus guidance, the 12 March 2027 effective date and the ninety-day gap analysis.
Day 1, 10:15 AM - 10:30 AM
Break
Day 1, 10:30 AM - 11:30 AM
Governance and Technology Risk Management
Board and senior management responsibilities, the technology risk management framework, and the tier-based differences in what is required.
Day 1, 11:30 AM - 12:30 PM
Technology Operations Management
System development and change, capacity and availability, data centre and cloud operations, backups and recovery, and the controls on removable media and self-service terminals.
Day 1, 12:30 PM - 1:30 PM
Lunch
Day 1, 1:30 PM - 3:15 PM
Cyber Security Management
The cyber security requirements and appendix controls, threat monitoring, vulnerability management, penetration testing, and incident response.
Day 1, 3:15 PM - 3:30 PM
Break
Day 1, 3:30 PM - 4:45 PM
Digital Services, Mobile Apps and Fraud Detection
Controls for digital services and mobile applications, the fraud detection standards, and the specific requirements for payment acceptance devices and QR codes.
Day 1, 4:45 PM - 5:00 PM
Day 1 Close
Recap and what to review before day two.
Day 2, 9:00 AM - 9:15 AM
Day 1 Review
Recap of day one and the questions it left open.
Day 2, 9:15 AM - 10:15 AM
Third Parties and Cloud
IT and cyber risks from third-party service providers, the key risks and control measures for cloud services, and what to put in contracts and oversight.
Day 2, 10:15 AM - 10:30 AM
Break
Day 2, 10:30 AM - 12:30 PM
Audits, External Assurance and the Simplified Approach
Technology audit expectations, when external party assurance is required, internal awareness and training, and the simplified approach available to some regulatees.
Day 2, 12:30 PM - 1:30 PM
Lunch
Day 2, 1:30 PM - 3:15 PM
Closing Gaps Before March 2027
Turning the ninety-day gap analysis into a funded, sequenced remediation plan, board reporting, and preparing for BNM supervisory review.
Day 2, 3:15 PM - 3:30 PM
Break
Day 2, 3:30 PM - 4:45 PM
Workshop: Tiering and Gap Review
Teams confirm the tier for a case payment company, review its gap analysis against the policy, and prioritise the remediation actions due before the effective date.
Day 2, 4:45 PM - 5:00 PM
Wrap-Up and Q&A
Key takeaways, next steps, and close.
Key Outcomes
- Determine which tier your institution falls into and which provisions apply
- Explain the governance, operations, cyber security and digital service requirements
- Apply the cloud, third-party, fraud detection, device and QR code controls
- Prepare for technology audits and external assurance
- Turn the gap analysis into a remediation plan that lands before 12 March 2027
- Report progress and residual risk to the board
Training Mode Physical / Online / Hybrid / e-learning
HRD Corp SBL-Khas Claimable
Level Intermediate. For technology, risk, compliance and operations leads, and directors, at e-money issuers, merchant acquirers, money services businesses, payment system operators and payment fintechs.
Duration 2 Days (16 Hours) | 9:00 AM to 5:00 PM daily
Venue In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)
Assessment A tiering decision and gap review for a case payment company, plus a written knowledge check
Certificate Certificate of Completion issued to all participants upon full attendance