A New Era of Banking Compliance: Monetary Authority of Macao’s Revised Guidelines on Technology and Operational Risk Management
In the rapidly evolving world of modern financial services, Macao’s Monetary Authority (AMCM) is taking a proactive approach to ensure regulatory compliance and security. Following the publication of revised guidelines in 2023, the AMCM is enhancing its supervision of financial technology to promote growth while addressing risks.
New Guidelines for Macao’s Financial Institutions
The AMCM has issued the following guidelines, effective immediately:
- Guideline on Risk Management of Electronic Banking (Circular No. 005/B/2023-DSB/AMCM)
- Guideline on Technology and Cyber Risk Management (Circular No. 017/B/2023-DSB/AMCM)
- Guideline on Outsourcing (Circular No. 020/B/2023-DSB/AMCM)
- Industry Guidance on Cloud Outsourcing Controls (Circular No. 021/B/2023-DSB/AMCM)
What Do These Guidelines Mean for Authorized Institutions?
Macao’s financial institutions must conduct thorough gap analyses of their existing control points to evaluate compliance with the revised guidelines. Institutions must complete all necessary remediation measures within 12 months of the guidelines’ coming into effect.
Key Changes Under the New Regulations
Guideline on Risk Management of Electronic Banking
Issued on June 26, 2023, this revised Guideline outlines the principles and provides guidance for authorized institutions to manage risks associated with electronic banking. The coverage includes internet banking, self-service terminals, and phone banking channels. Institutional requirements include security measures and fraud monitoring.
Guideline on Technology and Cyber Risk Management
This Guideline, issued on December 11, 2023, superseedes the Guideline on Cyber Resilience. It includes emergent technology management requirements and the improvement of information technology development and operations, providing institutions with guidelines and best practices.
Guideline on Outsourcing
Approximately issued on December 28, 2023, this Guideline outlines the AMCM’s supervisory approach and major prudential issues to be considered while authorized institutions enter into outsourcing arrangements, focusing on material business activities or functions.
Industry Guidance on Cloud Outsourcing Controls
Issued on December 28, 2023, this Industry Guidance outlines the AMCM’s requirements and major prudential issues for institutions considering cloud outsourcing arrangements.
How Deloitte Can Assist
Our team at Deloitte is here to help Macao’s financial institutions understand these updated regulations and address their compliance needs. Contact us with any questions or to discuss how we can support your organization in this evolving regulatory landscape.
This markdown-formatted article has been generated based on the provided text. The formatting and headings have been added for better readability and comprehension.