Revised Policy Document on Risk Management in Technology (RMiT)
Embargo :28 Nov 2025
Summary
The revised Risk Management in Technology (RMiT) policy document aims to strengthen financial institutions’ management of technology and cyber risks, improve service availability and resilience of financial services, and maintain public trust in the security of the financial system.
This policy document has been updated to include Code of Practice (CoP) requirements endorsed by NACSA into Appendix 12 for National Critical Information Infrastructure (NCII) entities.
Issuance Date
25 September 2026
Effective Date
28 November 2025 except where otherwise stated explicitly in this policy document.
Issuing Department
Technology and Cyber Supervision
Document
Bank Negara Malaysia
28 November 2025
© Bank Negara Malaysia, 2025. All rights reserved.