The next phase of RMiT: operational resilience as the new regulatory battleground

  • Jessie Lim, Jacqueline Foong

Last November, Bank Negara Malaysia (BNM) released a revised Risk Management in Technology policy document. In this article we explore what has changed, what enforcement actions are revealing about supervisory priorities, and where institutions should focus their efforts to strengthen RMiT readiness.

In June last year, Capco published a whitepaper exploring the challenges posed by Bank Negara Malaysia’s Risk Management in Technology (RMiT) in relation to cybersecurity complexity, third-party risk management, cloud adoption, emerging technologies and resource constraints.  While these themes remain highly relevant, the November 2025 enhancements to the RMiT framework signal a significant shift in regulatory focus. 

Increasingly, institutions are being assessed not only on the existence of governance frameworks and controls, but on their practical ability to demonstrate operational resilience, recovery effectiveness and sustainable technology risk management. 

Recent enforcement actions reinforce this insight and further suggest that supervisory attention is moving beyond policy documentation towards operational execution and resilience outcomes.

 

What has changed?

The revised RMiT published in November introduces greater emphasis on resilience outcomes and operational execution across several key areas.

Operational resilience becomes a core supervisory focus 

Institutions are increasingly expected to demonstrate effective operational resilience through annual cyber exercises, resilience testing, recovery readiness and mature incident response capabilities. 

The revised framework places greater emphasis on validating resilience through cyber drills, Cyber Emergency Response Team (CERT) readiness, out-of-band communications and recovery testing to demonstrate an institution’s ability to withstand and recover from operational disruptions.2

Fraud prevention expectations expand 

Appendix 11 represents one of the most significant additions to the revised RMiT. Institutions are expected to strengthen fraud prevention capabilities through behavioral analytics, mule account detection, device profiling and fraud response processes.

Regulatory scrutiny is increasingly extending beyond cybersecurity controls to include the effectiveness of fraud prevention and detection mechanisms, particularly where customer harm and financial crime risks intersect.3

Cybersecurity expands beyond traditional controls 

Cybersecurity expectations now sit within a broader resilience framework. Financial institutions are increasingly expected to demonstrate effective implementation of multi-factor authentication (MFA), zero-trust architecture (ZTA), Security Operations Centre (SOC) capabilities, cyber operations readiness and cloud security governance.4

Emerging technology governance 

The growing adoption of artificial intelligence, cloud services and emerging technologies has elevated governance expectations. New requirements place greater emphasis on end-of-life (EOL) management, vulnerability management and patch governance, recognizing that technology lifecycle weaknesses can directly impact resilience and customer outcomes.5 

 

What are enforcement actions telling us?

Recent enforcement actions provide important insight into evolving supervisory priorities and the areas where regulators are increasingly scrutinizing operational resilience, recovery effectiveness and technology risk management.6

  • Operational resilience shortcomings. Institutions have been penalized for prolonged disruptions affecting online banking, ATM services, payment channels and customer-facing digital services beyond acceptable recovery thresholds. 
  • Recovery weaknesses. Several enforcement actions identified failures in incident response and recovery execution, including delayed restoration of disrupted systems and weaknesses in recovery processes.
  • Governance and control failures. Recent penalties also demonstrate increasing scrutiny of cybersecurity controls, incident response arrangements and the effectiveness of governance mechanisms designed to prevent recurrence of technology and information protection breaches.

In addition, third-party arrangements represent a growing supervisory concern as institutions become increasingly dependent on cloud providers, outsourced services and complex technology ecosystems.

 

Why institutions continue to struggle

Despite significant investment in compliance and remediation programs, many institutions continue to face challenges operationalizing RMiT requirements in a sustainable manner.

Capability and skills represent one of the most fundamental constraints. Specialized expertise in cybersecurity, operational resilience, cloud governance, fraud risk management and resilience testing remains scarce across the industry. Institutions frequently face difficulties scaling these capabilities while simultaneously managing transformation programs and day-to-day operations.

Another issue is that legacy infrastructure, cloud adoption, emerging technologies and increasingly interconnected digital ecosystems continue to multiply implementation complexity. As technology environments become more distributed, maintaining consistent governance and resilience controls becomes even more challenging.

Institutions must increasingly demonstrate not only recovery capability but also the ability to quantify customer impact during disruptions and maintain critical services through alternative processing arrangements.

Areas receiving greater regulatory attention include customer impact monitoring, service degradation detection, stand-in processing capabilities and availability disclosures.7

 

Next steps – Practical priorities for institutions 

Boards increasingly require visibility over technology risk, recovery readiness and operational resilience to fulfill risk management oversight obligations and ensure compliance. 

This will mean extending dashboards beyond traditional cyber metrics to include aspects such as cyber drill outcomes, recovery maturity, mean time to recover (MTTR), CERT readiness, critical service availability and third-party concentration risks. These metrics provide boards with a clearer view of operational resilience effectiveness and preparedness for major cyber disruption scenarios.8

Institutions should also conduct a targeted review of third-party risk and cloud resilience. This will involve a rigorous assessment of critical vendors, cloud dependencies, recovery obligations, concentration risks and exit readiness.

More generally, the November RMiT revisions have increased the need for rigorous compliance at the most practical and operational level. The aim must be to identify resilience gaps before these expose institutions and their customers to risk – or translate into regulatory findings that are reputationally damaging and difficult to manage in a cost efficient and strategic manner.9

 

How Capco can help

Capco supports financial institutions in strengthening operational resilience, recovery readiness and governance effectiveness under RMiT through regulatory advisory, remediation support and Independent Assessor capabilities.

Building on Capco’s RMiT thought leadership and delivery experience, our RMiT Compliance Accelerator helps institutions strengthen resilience, operationalize sustainable remediation and reduce enforcement exposure.

 

Ready to strengthen your RMiT readiness?

Complete the form below, and our team will be in touch.

 

References:

1 https://www.capco.com/intelligence/capco-intelligence/empowering-compliance-with-bank-negara-malaysias-rmit

https://www.bnm.gov.my/-/pd-rmit-nov25, Sections 11.12 - 11.17

https://www.bnm.gov.my/-/pd-rmit-nov25, Appendix 11

https://www.bnm.gov.my/-/pd-rmit-nov25, Sections 11.12 - 11.17

https://www.bnm.gov.my/-/pd-rmit-nov25,  Sections 10.17 - 10.19

BNM Enforcement Actions relating to operational resilience, recovery failures and cybersecurity control weaknesses (2024–2026)

https://www.bnm.gov.my/-/pd-rmit-nov25, Sections 10.31 - 10.35

https://www.bnm.gov.my/-/pd-rmit-nov25,  Sections 11.12 - 11.17

https://www.bnm.gov.my/-/pd-rmit-nov25,  Sections 10.46 – 10.50, Appendix 10 and Section 17.5

 

Get in touch

To find out more about working with Capco and how we can help you overcome any potential challenges, contact our experts or subscribe for the latest insights below.