BNM RMiT Compliance in 2026: What the November 2025 Revision Means for Malaysian Financial Institutions

Primary Guard · July 21, 2026 · 8 min read

Bank Negara Malaysia revised its RMiT policy on 28 November 2025. Here is what changed, who must comply, the key deadlines, and how to prepare.

On 28 November 2025, Bank Negara Malaysia (BNM) issued a revised Risk Management in Technology (RMiT) policy document. It is the most significant update to the framework since 2019, and it changes what compliance actually looks like for financial institutions operating in Malaysia. If your last RMiT gap assessment was built around the June 2023 version, parts of it are now out of date.

This guide explains what RMiT is, who it now applies to, exactly what changed in the 2025 revision, the deadlines you need to plan around, and the practical steps a Malaysian financial institution can take to close the gap. It is written for boards, chief information security officers, technology risk teams, and the smaller institutions newly brought into scope.

What is BNM RMiT?

RMiT is Bank Negara Malaysia's policy document setting out the minimum standards financial institutions must meet when managing technology and cyber risk. First introduced in July 2019 and effective from January 2020, it consolidated the central bank's expectations into a single framework covering governance, technology risk management, cybersecurity, technology operations, and independent assurance.

The policy is mandatory, not advisory. It is issued under Malaysia's financial services legislation, and non-compliance carries supervisory and enforcement consequences. RMiT sits alongside two other Malaysian technology risk regimes that regulated entities increasingly need to read together: the National Cyber Security Agency's Cyber Security Act and its sector guidelines, and the Securities Commission's Guidelines on Technology Risk Management for capital market participants.

The framework has been revised twice since launch. The June 2023 version added detailed cloud technology risk requirements and multi-factor authentication controls. The 28 November 2025 version, the subject of this guide, is now the current standard.

Who must comply with RMiT in 2026?

RMiT applies to financial institutions licensed and regulated by Bank Negara Malaysia, including licensed banks, insurers, takaful operators, and the licensed digital banks. Larger and more complex institutions, identified through a self-assessment against BNM's criteria, carry a heavier set of enhanced requirements.

The 2025 revision widens this population. RMiT now extends to non-bank merchant acquirers and intermediary remittance institutions where each holds a market share of at least 5 per cent of the total transaction value or volume for their respective service in a given year. For these newly captured players, many of whom have never operated under a formal technology risk policy of this depth, the practical burden is substantial. Governance charters, cyber resilience frameworks, and third-party monitoring programmes that established banks built over years now need to be stood up on a compressed timeline.

What changed in the November 2025 revision

Bank Negara framed the revision around five broad aims:

  • Expanding applicability
  • Enhancing resilience to service disruption
  • Heightening cyber security controls in line with global standards
  • Strengthening the security of digital services
  • Enabling the secure adoption of advanced technologies
  • Underneath those aims sit a set of concrete, and in several cases time-bound, new obligations. These are the changes that matter most.

    Operational resilience becomes prescriptive

    The old framework asked institutions to manage availability. The revision makes it measurable and time-bound. Institutions are now expected to conduct proactive capacity planning that factors in peak loads, projected growth, and upcoming architecture changes, and to run early-warning systems that detect service degradation and failed transactions before customers feel them.

    Resilience is now tied explicitly to customer impact. Institutions need to measure the number of affected customers and transaction volumes during outages, and to review IT interdependencies regularly to prevent cascading failures across services. The single hardest new obligation is the requirement to establish stand-in processing capability, with fraud controls, for the least-substitutable services by 30 September 2027. This is a genuine engineering programme, not a policy edit.

    Third-party and supply chain risk moves to continuous monitoring

    Supply chain compromise is treated as a first-class threat in the revision. Institutions must perform mandatory due diligence on all service providers and their subcontractors, and move from point-in-time vendor reviews to continuous monitoring of vendor risk, service-level compliance, and cybersecurity posture.

    Contracts carry a new weight. Service-level agreements need to be reviewed and renegotiated to include incident disclosure and resilience clauses by the second quarter of 2026, requiring providers to disclose incidents immediately and commit to remediation timelines. The revision also introduces cyber supply chain controls, including the adoption of a Software Bill of Materials to automate vulnerability detection in third-party components, and secure open-source software practices covering repository access, secure coding, and malware prevention.

    Cyber resilience is raised to global standards

    The Cyber Resilience Framework is expanded to include layered defences such as zero-trust architecture and centralised technology asset tracking, and institutions are expected to establish a dedicated cyber risk management function to strengthen oversight.

    Proactive security testing is now mandatory and specified by cadence: quarterly vulnerability assessments, annual penetration tests, and Red Team exercises every three years. Cyber incident response plans must be updated to include out-of-band communication channels and cross-border incident handling, and institutions must run annual cyber drills with active board and senior management engagement.

    Secure by design and technology architecture

    The revision embeds security into how systems are built rather than bolting it on afterwards. Institutions must develop a Technology Architecture Framework that maps infrastructure, system interconnectivity, dependencies, and security controls, so that single points of failure can be identified and business impact analysis can be performed. Adoption of DevSecOps practices, integrating security throughout the software development life cycle, is now an expectation rather than a maturity nicety.

    Digital fraud and customer protection

    Reflecting the surge in scams targeting bank customers, the scope of cybersecurity threats and mitigation now extends to customers' own mobile devices and access points. Institutions must:

  • Deploy real-time fraud detection using behavioural analytics with automated blocking
  • Maintain and annually review a fraud management playbook
  • Update incident procedures to include rapid credential revocation and re-issuance where customer data may be compromised Customer empowerment through regular awareness programmes is treated as part of the control set, not an optional extra.
  • Board-level accountability

    The revision sharpens governance. Boards and senior management must actively govern and review technology risk, including emerging threats, as a standing agenda item, and institutions must formally identify their critical technology functions and interdependencies. The independence and authority of the chief information security officer is reinforced, closing the common gap where the CISO reports into the very function they are meant to challenge.

    The deadlines to plan around

    Three dates should anchor your programme plan:

  • 28 November 2025: the revised policy document is in effect and is the current benchmark for supervisory review.
  • Second quarter of 2026: service-level agreements renegotiated to include incident disclosure and resilience clauses.
  • 30 September 2027: stand-in processing capability established for least-substitutable services.

Working backwards from these dates matters, because the 2027 stand-in processing requirement in particular depends on architecture decisions and vendor arrangements that need to be settled well before the deadline.

How to approach the gap

For institutions already under RMiT, the sensible first move is a delta assessment: map your current control set against the 2025 requirements and identify only what is new or strengthened, rather than re-auditing the entire framework. For newly captured merchant acquirers and remittance institutions, the priority is standing up the governance spine first, the board charter, the technology risk management framework, and the CISO function, before layering on the technical controls.

Across both groups, a few areas tend to carry the longest lead times and are worth starting early: continuous third-party monitoring and SBOM tooling, real-time fraud detection with behavioural analytics, the Red Team and penetration testing cadence, and the operational telemetry needed to measure customer impact during outages. These are capability builds, not documentation exercises, and they are difficult to complete in-house at short notice.

Where a managed security partner fits

Several of the 2025 requirements map cleanly onto capabilities that a managed security services provider can deliver faster than an internal build. Continuous cyber monitoring, threat detection, and incident response align with a managed detection and response and security operations centre model. The mandated testing cadence of quarterly vulnerability assessments, annual penetration tests, and triennial Red Team exercises aligns with breach and attack simulation and offensive security services. Continuous vendor risk monitoring and supply chain controls align with third-party risk and attack surface intelligence. Governance, the technology risk management framework, and evidence for supervisory review align with a structured security services programme.

Primary Guard works with financial institutions across Malaysia, Indonesia, and Thailand on exactly these areas, combining a regional security operations capability with governance and testing services suited to a regulated environment. For institutions weighing whether to build or partner, a free assessment is a practical starting point, and the November 2025 deadlines make the buy-versus-build calculation more urgent than it was under the previous version of the policy.

If your institution also processes customer data in Malaysia, read this guide alongside our PDPA compliance guide, since regulated financial institutions fall under both RMiT and the PDPA.

Key takeaways

The November 2025 RMiT revision moves Malaysian financial institutions from compliance-based oversight to proactive, measurable resilience. It widens the population of regulated entities, hardens supply chain and cyber testing requirements, ties operational resilience to customer impact, and sets firm deadlines in 2026 and 2027. The institutions that treat this as an engineering and capability programme, rather than a documentation refresh, will be the ones ready when Bank Negara's supervisory teams come to review.


This article is provided for general information and does not constitute legal or regulatory advice. Financial institutions should refer to the full RMiT policy document and consult qualified advisers on their specific obligations.

Frequently Asked Questions

Is RMiT compliance mandatory?

Yes. RMiT is a mandatory policy document issued by Bank Negara Malaysia under Malaysia's financial services legislation. Non-compliance can attract supervisory action and enforcement consequences.

When did the latest RMiT revision take effect?

The revised RMiT policy document was issued on 28 November 2025 and is the current standard, superseding the June 2023 version.

Who does RMiT apply to after the 2025 revision?

It applies to financial institutions regulated by Bank Negara Malaysia, including banks, insurers, takaful operators, and licensed digital banks. The 2025 revision extends it to non-bank merchant acquirers and intermediary remittance institutions holding at least a 5 per cent market share of their respective service.

What are the key new RMiT deadlines?

Service-level agreements must be renegotiated to include incident disclosure and resilience clauses by the second quarter of 2026, and stand-in processing capability for least-substitutable services must be established by 30 September 2027.

What is the difference between RMiT and the Cyber Security Act?

RMiT is Bank Negara Malaysia's technology risk policy for regulated financial institutions. The Cyber Security Act, administered by the National Cyber Security Agency, is a broader national law covering critical information infrastructure across multiple sectors. Many financial institutions fall under both.

What are the main new technical requirements in the 2025 RMiT?

Zero-trust architecture, a Software Bill of Materials for supply chain vulnerability monitoring, real-time behavioural fraud detection, mandatory penetration testing and Red Team cadences, DevSecOps and a technology architecture framework, and prescriptive operational resilience measures tied to customer impact.