M5 β RES5 β Rules, Ethics & Skills for Financial Advisory Services
How MAS technology-risk, cyber-hygiene, PDPA, DPI and digital-advisory (robo) rules apply to FA firms and reps: system resilience, cyber controls, personal-data protection, no-advice direct insurance, and algorithm-based advice.
7 sections~5 min read
Financial advice is now delivered on IT systems, apps and algorithms, so MAS's technology and digital rules bind FA firms and their representatives just like the older conduct Notices. RES5 pulls together four instruments: the Notice on Technology Risk Management (TRM) [FSM-N23], the Notice on Cyber Hygiene [FSM-N24] (the FSMA-2022 re-issue of the earlier FA cyber Notice FAA-N21), the Notice on the Distribution of Direct Purchase Insurance [DPI] [FAA-N19], and the Guidelines on Provision of Digital Advisory Services [CMG-G02].
Note the different legal bases: the TRM and Cyber Hygiene Notices are issued under s29(1) of the FSMA 2022 and both took effect on 10 May 2024; FAA-N19 is issued under s58 of the FAA 2001; and CMG-G02 is issued under s321 SFA and s64 FAA. Separately, the Personal Data Protection Act 2012 (PDPA) underpins how client data is handled (covered in RES5's ethics material).
The TRM Notice targets the reliability, availability and recoverability of a licensee's critical systems β systems whose failure would cause significant disruption to operations or materially impact service to customers (e.g. systems that process time-critical transactions or provide essential customer services). It also requires IT controls to protect customer information from unauthorised access or disclosure.
Core obligations:
Every note. Every question. One pass.
5 more sections of this note are part of Premium.
From β$14.83/mo on the 6-month pass
Ready to test yourself?
Drill exam questions on Technology Risk & Digital Advisory and lock it in, or sit the free CMFAS mock exam with no sign-up.