Why Submitting Your RMiT Gap Analysis in 2026 Was Only Step One

For most Malaysian financial institutions, the initial submission under Bank Negara Malaysia’s revised Risk Management in Technology (RMiT BNM/RH/PD 028-98) is officially behind them. The 90-day post-issuance deadline passed in late February 2026, the gap analysis is logged, and compliance teams have moved to the next fire. But treating RMiT as a "completed project" exposes a dangerous misconception.

Under the revised framework, the gap analysis is an entry ticket—not the finish line.

1. Paragraph 18.1: A Standing Obligation, Not a Milestone

Paragraph 18.1 required institutions to submit a gap analysis and implementation action plan within 90 days of the 28 November 2025 issuance.

However, the regulatory language is unambiguous:

  • Continuous Conformance: Meeting the February deadline proved only past intent, not ongoing compliance.

  • On-Demand Production: Institutions must maintain a current, annual assessment of compliance levels and produce it immediately upon BNM’s request.

If supervisory examiners walk in today, producing the February filing only proves what was true months ago. Conformance is measured by what you can evidence right now.

2. The 2027 Resilience Deadlines You Must Build for Now

RMiT took effect on 28 November 2025, but several high-impact operational resilience controls carry extended implementation windows. A static compliance program risks missing these multi-year engineering milestones:

AKATI RMiT forward-obligations table preview

RMiT forward obligations

Requirements dated beyond the reissue

RMiT requirements with effective dates after 28 November 2025, their paragraph references and key deliverables
Requirement Paragraph Effective date Key deliverable
Early Warning & Stand-in Processing Para 10.31 30 September 2027 Automated degradation alerts and operational stand-in processing arrangements
Public Service-Availability Disclosures Para 10.35 15 October 2027 Quarterly track record disclosures (within 15 calendar days of quarter-end)

Treating RMiT as a single-event deadline leaves infrastructure teams underprepared for the architectural rework required by late 2027.

3. High-Scrutiny Focus Areas: Cloud and Cyber Incidents

BNM’s supervisory focus centers on verifiable operational artifacts rather than static policies:

  • Critical Cloud Deployments (Paragraph 17.1): Institutions must consult BNM prior to their first adoption of public cloud or emerging tech for critical systems. This consultation requires three artifacts: a comprehensive risk assessment, a formal CISO/Board readiness confirmation, and an independent pre-implementation review.

  • Incident Notification Triggers (Paragraph 11.18): RMiT does not establish a standalone clock for incident notification. Instead, it explicitly routes timelines through BNM’s policy documents on Operational Risk Reporting, Business Continuity Management, and Merchant Acquiring Services.

4. Regulatory Enforcement Is Active

The cost of treating RMiT compliance as a checkbox exercise is tangible. BNM has demonstrated consistent willingness to issue Administrative Monetary Penalties (AMPs) for technology governance failures.

In mid-2025, BNM imposed over RM7 million in cumulative administrative penalties across several licensed institutions for compliance and technology-risk breaches—including direct enforcement actions for prolonged critical service disruptions and recovery delays.

The RMiT 2026 Health Check

To evaluate whether your technology risk posture satisfies BNM’s active expectations, verify that your compliance function can produce:

  1. A live, updated RMiT compliance assessment that reflects post-February remediation progress.

  2. Documented consultation packages for any public cloud or emerging technology tied to critical systems.

  3. An incident-response playbook mapped directly to BNM's cross-referenced operational reporting timelines.

  4. An active engineering roadmap targeted at the September and October 2027 resilience requirements.


AKATI RMiT FAQ widget preview

Frequently asked

Questions on the reissued RMiT

Risk Management in Technology (RMiT) is Bank Negara Malaysia's policy document, BNM/RH/PD 028-98, setting the minimum requirements for regulated financial institutions to manage technology and cyber risk across governance, operations, cybersecurity, digital services and cloud adoption. In practice it requires board-approved technology risk appetite, a designated Chief Information Security Officer (paragraph 9.4), notification of cyber incidents to the Bank, prior engagement before adopting public cloud or emerging technology for critical systems, and a maintained gap analysis. Compliance is a continuous obligation evidenced against the reissued text, not a one-time submission.

RMiT applies to ten categories of regulated institution: licensed banks, licensed investment banks, licensed Islamic banks, licensed insurers and professional reinsurers, licensed takaful and retakaful operators, prescribed development financial institutions, approved e-money issuers, operators of a designated payment system, registered merchant acquirers, and intermediary remittance institutions. Certain paragraphs carry carve-outs for specific institution types, so applicability should be read against paragraph 2.2 rather than assumed to be uniform across all provisions.

RMiT requires financial institutions to notify Bank Negara Malaysia of cyber incidents (paragraph 11.18). The clause sets no standalone timeframe of its own: it directs institutions to report in adherence with the Bank's policy documents on Operational Risk Reporting, Business Continuity Management, and Merchant Acquiring Services, so the operative deadline is defined in those cross-referenced documents rather than in RMiT. Institutions should map their notification procedure to those referenced documents and be able to evidence it on request.

RMiT requires a financial institution to consult Bank Negara Malaysia before it first adopts public cloud or emerging technology for critical systems (paragraph 17.1), and to notify the Bank on subsequent adoptions (paragraph 17.2). Before consulting, the institution must complete a comprehensive cloud risk assessment (paragraph 10.50 and Appendix 10), obtain a readiness confirmation from the CISO, senior management or the designated board committee, and commission a third party pre-implementation review. Appendix 10 also expects a robust cloud architecture and a tested cloud exit strategy, so a running cloud deployment without a first-time consultation record is a documented gap.

The reissued RMiT came into effect on 28 November 2025 (paragraph 4.1) and supersedes the version issued on 1 June 2023 (paragraph 7.1(d)), but it is phased rather than fully in force from that date. Institutions had to submit a gap analysis and action plan within 90 days of issuance (paragraph 18.1), while several resilience duties fall due later: early-warning and stand-in processing mechanisms by 30 September 2027 (paragraph 10.31) and quarterly service-availability disclosure from 15 October 2027 (paragraph 10.35). A financial institution should therefore track each requirement to its own effective date and maintain a current compliance assessment for the Bank on request.

Previous
Previous

Identity Is the New Perimeter

Next
Next

Zero Trust Without the Product Pitch