IIMMPACT – RMIT MAPPING & APPLICABILITY ASSESSMENT

RMiT decomposed and mapped to IIMMPACT: a good-faith alignment assessment

Bank Negara Malaysia's Risk Management in Technology (RMiT) policy document, reference BNM/RH/PD 028-98, issued 28 November 2025, is written for financial institutions. IIMMPACT is not a financial institution and is not obligated by RMiT. This document is a voluntary exercise: RMiT is decomposed provision by provision, and each element that is relevant to an infrastructure and API provider like IIMMPACT is mapped and assessed for how IIMMPACT aligns to its intent, directly or indirectly.

Why this exists

IIMMPACT sits behind financial institutions as a payments and services infrastructure provider. Its clients carry RMiT obligations; IIMMPACT does not. This assessment is offered in good faith to show, transparently, that IIMMPACT has taken RMiT seriously as a design reference: it has read the framework, identified the provisions that genuinely bear on a provider in its position, and structured its own posture to align with their intent where relevant.

The purpose is not to claim regulated status, and not to imply obligation. It is to demonstrate effort and structure: where IIMMPACT aligns directly, where it aligns by enabling its clients' compliance, and where a provision is simply an internal financial-institution duty with no provider analogue.

The two things this document contains

Method. How RMiT was decomposed, and the three-way test applied to every provision to classify it Direct, Indirect, or Not applicable to IIMMPACT. Read this first; it is how the mapping is meant to be read.

The mapping. Every RMiT paragraph, with its requirement, its classification, and the alignment approach IIMMPACT takes toward it. Browsable by RMiT section.

On the alignment column

The alignment approach stated against each relevant provision describes the posture an infrastructure provider like IIMMPACT takes toward that provision's intent. It is written as approach, not as an audited claim about IIMMPACT's internal state. Each line is a position IIMMPACT can confirm and harden against its own documentation; it is the structure of the alignment, offered for IIMMPACT to substantiate.

METHOD

How RMiT was decomposed and mapped to IIMMPACT

Every provision in RMiT was put through one question: does this provision's intent create something an infrastructure provider like IIMMPACT can align to, directly or by enabling its clients? The answer places each provision in one of three tiers. This is the whole method, and the tiers below are how the entire mapping should be read.

Tier 1
58

Direct

The provision's intent maps onto something IIMMPACT owns and controls, its own platform, network, hosting, cryptography, access, incident response, or its provider-side contract terms. IIMMPACT can align to these on its own account.

Tier 2
31

Indirect

IIMMPACT aligns by enabling its financial-institution clients' compliance: being documentable, assessable, audit-ready, and transparent, and by carrying the right controls through the IIMMPACT-processed step of a client's service.

Tier 3
32

Not applicable

A financial-institution internal governance, board, staffing, or filing duty with no meaningful provider analogue. Marked Not applicable on principle, not by omission, so the boundary of the exercise is explicit.

Aligns directly, on IIMMPACT's own account
Aligns by enabling clients' compliance
Internal FI duty, no provider analogue

How to read the mapping

01

Start from the classification, not the requirement

89 of RMiT's 121 mapped provisions are relevant to IIMMPACT, 58 directly and 31 indirectly. The Not-applicable rows are kept visible so the reader can see that the boundary was drawn deliberately, and see exactly where.

02

Read the alignment approach as posture

For every Direct and Indirect row, the final column states the approach IIMMPACT takes toward that provision's intent. It answers “how does a provider in IIMMPACT's position align to this,” not “what must an FI do about IIMMPACT.” The framing is deliberately from IIMMPACT's side.

03

Treat each line as substantiable

The alignment lines are structural, not audited. Each is a position IIMMPACT can confirm against its own controls and evidence. Read together, they are the shape of IIMMPACT's good-faith alignment; substantiating them is IIMMPACT's to complete.

The structural basis

RMiT paragraph 5.2 defines ten categories of financial institution; IIMMPACT is in none of them. RMiT paragraph 5.1 separately defines a “third party service provider” to explicitly include platform and infrastructure providers, which is what IIMMPACT is. That distinction is what makes the exercise coherent: RMiT reaches a provider like IIMMPACT through its intent and through the third-party mechanism, not as a direct obligation, and the mapping follows that logic throughout.

THE MAPPING S · standardG · guidance

RMiT decomposed, mapped, and assessed for IIMMPACT alignment

Every numbered RMiT paragraph. “S” is a standard, “G” is guidance, both taken from the RMiT text. The Mapping column classifies the provision Direct, Indirect, or Not applicable to IIMMPACT; the final column states IIMMPACT's alignment approach where relevant. Browse by RMiT section; the badge shows how many provisions in each section are relevant to IIMMPACT.

RMiT's own applicability exceptions (paragraph 2.2) narrow which provisions bind which institution types. They are noted here for completeness: Part C (sections 16–17) and Appendices 6–7 do not apply to designated payment system operators, eligible e-money issuers, non-bank registered merchant acquirers, or intermediary remittance institutions; paragraphs 12.3–12.9 and 13.3 carry their own narrower exceptions. These shape the FI-side picture; the IIMMPACT mapping is drawn on relevance to a provider regardless.

Part B, Section 8: Governance

0 direct0 indirect7 n/a
Para.TypeRMiT requirement (intent)MappingIIMMPACT alignment approach
8.1 S Board must establish and approve the technology risk appetite aligned with the institution's risk appetite statement, including risk tolerances, risk owner identification, key risk indicators, resourcing, and periodic review. Not applicable FI board risk-appetite duty. No provider analogue; IIMMPACT sets its own product and platform risk posture separately.
8.2 S Board oversight duties: approve and review 3-year IT and cybersecurity strategic plans; endorse the TRMF and CRF; require senior management assurance on critical system and emerging technology risk assessments; review IT policies at least once every three years; support technology-related application submissions to BNM. Not applicable FI board oversight of its own IT and cybersecurity strategy. No provider analogue.
8.3 S Board must designate a board-level committee for technology oversight, including at least one member with technology experience and competencies. Not applicable FI's own board committee composition.
8.4 S Board must obtain regular technology and cyber threat updates, allocate sufficient time to discuss cyber risk impact, and participate in cybersecurity awareness training. Not applicable FI board's own training and engagement duty.
8.5 S Board Audit Committee is responsible for the effectiveness of the internal technology audit function, audit scope and frequency, and closure of technology audit findings. Not applicable FI's Board Audit Committee mandate over its own internal audit.
8.6 S Senior management bears day-to-day responsibility for technology and cyber risk: implement TRMF and CRF into policy, maintain crisis management and escalation plans, report key performance indicators to the board. Not applicable FI senior-management internal risk duty.
8.7 S Senior management must establish a cross-functional technology committee (cyber, technology, and business units) to oversee the strategic technology plan, report to the board, and approve policy deviations. Not applicable FI's internal cross-functional technology committee.

Part B, Section 9: Technology Risk Management

0 direct2 indirect3 n/a
Para.TypeRMiT requirement (intent)MappingIIMMPACT alignment approach
9.1 S The Technology Risk Management Framework (TRMF) must be an integral part of the institution's enterprise risk management framework. Not applicable FI's internal ERM integration.
9.2 S TRMF must define technology risk, assign responsibilities, identify risks including emerging technology risk, classify assets by criticality, define risk measurement and mitigation approaches, provide continuous monitoring, maintain an accurate risk profile, identify key resources and third party interdependencies, conduct scenario analysis, and set incident management procedures. Indirect Align by being documentable: maintain a clear service description, interdependency map, and criticality classification IIMMPACT can hand to any FI so the FI can place IIMMPACT accurately in its own risk register.
9.3 S Must establish an independent enterprise-wide technology risk management function to implement the TRMF and CRF, advise on critical projects, and provide independent views on third party assessments. Indirect Align by being independently assessable: make third party assessment material available so an FI's risk function can form an independent view without bespoke effort each time.
9.4 S Must designate a Chief Information Security Officer (CISO) with sufficient authority, independence, resources, technical skill, and appropriate certification. Not applicable FI's own CISO appointment. IIMMPACT names its own security ownership independently.
9.5 S CISO is responsible for formulating TRMF and CRF policies, enforcing compliance, and advising senior management on technology and security risk. Not applicable FI's CISO internal policy duties.

Part B, Section 10: Technology Operations Management

42 direct8 indirect7 n/a
Para.TypeRMiT requirement (intent)MappingIIMMPACT alignment approach
10.1 S Governance requirements for technology projects must be proportionate to risk and complexity. Not applicable FI project governance for systems the FI builds itself.
10.2 S Risk assessments for technology projects must cover resource adequacy, system complexity, security control adequacy, requirement specification completeness, testing robustness, deployment and fallback strategy, and disaster recovery readiness. Not applicable FI's internal project risk assessment.
10.3 S Board and senior management must receive timely reports on the risk management of significant technology projects. Not applicable FI internal board reporting on its own projects.
10.4 S Must establish an enterprise technology architecture framework covering baseline components, interconnectivity mapping, business function mapping, network design principles, and a longer-term roadmap. Not applicable FI's own enterprise architecture.
10.5 S Must adopt a System Development Life Cycle (SDLC) methodology integrating enterprise architecture, risk management, and security principles. Direct Align directly: run a defined SDLC over IIMMPACT's own API platform, integrating security principles, so the software FIs integrate against is itself built to a governed lifecycle.
10.6 S Rapid development methodologies such as DevOps must meet enterprise security, governance, and compliance requirements, including automated IT security compliance review. Direct Align directly: where IIMMPACT ships rapidly, automate security compliance and vulnerability checks in its own pipeline rather than relying on manual review.
10.7 S Production environments must be physically segregated from development and testing environments; cloud environments must not share the same virtual host. Direct Align directly: segregate IIMMPACT's own production from development and testing, including not sharing a virtual host in cloud environments.
10.8 S Must have a rigorous system testing methodology prior to deployment; sensitive test data requires proper authorization controls. Direct Align directly: run rigorous pre-deployment testing on IIMMPACT's own releases; protect any sensitive test data used.
10.9 G Guidance on testing scope: unit, integration, user acceptance, application security, stress and load, and regression testing. Direct Align directly: apply the testing types listed (unit, integration, UAT, security, load, regression) to IIMMPACT's own release process.
10.10 S Source code changes to critical systems require adequate code review prior to introducing system changes. Direct Align directly: subject IIMMPACT's own critical source-code changes to review before release.
10.11 S Must establish procedures to independently review and approve system changes, and test contingency plans for unsuccessful material changes. Direct Align directly: operate an independent change review-and-approval process with tested contingency for IIMMPACT's own changes.
10.12 S For critical systems developed or maintained by a third party service provider: contractual requirement for prior notice of changes, demonstrated secure-by-design methodology, and continued source code accessibility for business continuity. Direct Align directly to the provider side of this clause: be ready to give FIs advance notice of platform changes, demonstrate secure-by-design, and keep source accessible for continuity, i.e. be the well-behaved third party this paragraph describes.
10.13 S Decommissioning of critical systems must minimize customer and operational impact; contingency plans must be established and tested. Indirect Align by enabling clean offboarding: support an orderly transition if an FI decommissions an IIMMPACT integration.
10.14 G May deploy automated tools for software development, testing, deployment, change management, code scanning, and version control. Direct Align directly: use automated build, test, scanning, and version-control tooling on IIMMPACT's own platform.
10.15 G Guidance on third party software supply chain risk: consider adopting a Software Bill of Materials (SBOM) and an open-source software security policy. Direct Align directly: maintain a software supply-chain posture (SBOM, open-source security policy) for IIMMPACT's own components.
10.16 S Must implement policies to identify and reduce shadow IT risk. Direct Align directly: control shadow IT within IIMMPACT so integrations FIs rely on are sanctioned and inventoried.
10.17 S Must maintain a current security baseline, apply timely patching, plan remediation for end-of-life systems, and require management-approved, risk-assessed, annually reviewed exceptions for continued use of unsupported technology. Direct Align directly: keep IIMMPACT's own platform free of known vulnerabilities and off end-of-life technology, and be able to show this to FIs.
10.18 S Must establish a patch and end-of-life management framework: asset risk assessment, patch prioritization and turnaround time, compatibility testing, deployment workflow, and end-user awareness. Direct Align directly: run a patch and end-of-life management framework over IIMMPACT's own estate.
10.19 S Must continually monitor technology effectiveness and security against evolving threats: board advisory on impact, long-term strategy, and migration roadmap. Direct Align directly: monitor the security of technology IIMMPACT uses and maintain a migration roadmap.
10.20 S Must establish a cryptography policy covering encryption standards, key lifecycle management, at least annual review of cryptographic standards in use, a cryptographic asset inventory, and compromise-recovery plans. Direct Align directly: operate a cryptography policy over IIMMPACT's own platform, since transaction and credential data flow through it.
10.21 S Must conduct due diligence on cryptographic controls: retain encryption key ownership and control with limited exceptions, manage third-party-generated keys securely, and assess reliance on third party cryptographic assessments. Direct Align directly: manage encryption keys and cryptographic controls for the data IIMMPACT handles, with clear key-ownership terms toward FIs.
10.22 S Cryptographic protocols must reflect a high degree of protection for secret and private keys, based on recognized international standards, supported by hardware security modules or equivalent for higher-risk cases. Direct Align directly: base IIMMPACT's cryptographic protocols on recognised standards, protected appropriately for higher-risk paths.
10.23 S Public cryptographic keys must be stored in certificates issued by recognized Certificate Authorities, with strong protection of authentication and signature protocols. Indirect Align where IIMMPACT issues or manages certificates on an FI's behalf: use recognised Certificate Authorities and strong protection.
10.24 S Must specify data centre resilience and availability objectives aligned with business recovery objectives. Direct Align directly: set resilience and availability objectives for IIMMPACT's own hosting supporting FI-facing services.
10.25 S Data centres must have redundant capacity components and multiple distribution paths to eliminate single points of failure. Direct Align directly: build redundancy and eliminate single points of failure in IIMMPACT's own infrastructure.
10.26 S Critical systems must be hosted in a dedicated, physically secured, non-disaster-prone production data centre with no single point of failure in critical components, and with continuous monitoring. Direct Align directly: host IIMMPACT's production in a secure, monitored, non-disaster-prone environment with no single point of failure.
10.27 S Must establish data centre operational control procedures, including automated batch processing tools, change implementation controls, and error handling. Direct Align directly: operate defined data-centre control procedures over IIMMPACT's own operations.
10.28 S Must segregate incompatible data centre operations activities; vendor or programmer access to production must be authorized and monitored. Direct Align directly: segregate incompatible duties in IIMMPACT's own operations environment; authorise and monitor privileged access.
10.29 S System capacity planning must account for peak processing periods, business growth plans, and architecture changes. Direct Align directly: plan IIMMPACT's capacity for peak load and growth, since FI-facing throughput depends on it.
10.30 S Must establish real-time capacity and performance monitoring with actionable alerts and periodically updated thresholds. Direct Align directly: run real-time capacity and performance monitoring with actionable alerts on IIMMPACT's own platform.
10.31 S Must enhance resilience of key digital services and delivery channels: early degradation detection capability (by 30 September 2027), review of vulnerable system interdependencies, and stand-in processing arrangements (by 30 September 2027). Indirect Align by supporting the FI's resilience of key digital services: provide degradation signalling and continuity behaviour on the IIMMPACT-processed path.
10.32 S Critical systems requiring immediate customer or counterparty delivery must be designed for high availability: no more than 4 hours cumulative unplanned downtime per rolling 12 months, and no more than 120 minutes maximum tolerable downtime per incident. Direct Align directly and measurably: engineer IIMMPACT's own availability so an FI relying on it can meet the 4-hour and 120-minute standards; back the marketing uptime figure with real service-level evidence.
10.33 G Smaller eligible e-money issuers, non-bank merchant acquirers, and intermediary remittance institutions (non-NCII) are encouraged, not required, to adopt the paragraph 10.31 measures. Not applicable Guidance addressed to smaller FIs directly.
10.34 S Must prioritize technology diversity in critical systems infrastructure to avoid concentrated exposure to similar technology risk. Indirect Align by supporting the FI's concentration-risk planning: be transparent about where IIMMPACT is a single dependency for a given rail.
10.35 S During a digital service interruption, must escalate and resume service promptly, define clear accountabilities, maintain a customer communication plan, publish availability status, and disclose quarterly service availability track record from 15 October 2027. Indirect Align by supporting interruption response on the IIMMPACT-processed path: prompt escalation, clear status, defined recovery.
10.36 S Must design a reliable, scalable, and secure enterprise network supporting business activities and growth. Direct Align directly: design IIMMPACT's own network to be reliable, scalable, and secure.
10.37 S Network services for critical systems must be reliable with no single point of failure. Direct Align directly: no single point of failure in IIMMPACT's own network serving FI-facing services.
10.38 G Expected network fault prevention measures: component redundancy, service diversity, alternate network paths. Direct Align directly: use redundancy, service diversity, and alternate paths in IIMMPACT's own network.
10.39 S Must establish real-time network bandwidth monitoring and resilience metrics, including traffic anomaly detection. Direct Align directly: run real-time bandwidth monitoring and anomaly detection on IIMMPACT's network.
10.40 S Network services supporting critical systems must ensure confidentiality, integrity, and availability of data. Direct Align directly: ensure confidentiality, integrity, and availability of data across IIMMPACT's network.
10.41 S Must maintain a network design blueprint covering physical and logical connectivity and segmentation. Direct Align directly: maintain a network design blueprint for IIMMPACT's own estate, including the FI-facing interfaces.
10.42 S Network device logs must be retained for at least three years for investigation and forensic purposes. Direct Align directly: retain IIMMPACT's own network device logs for at least three years for investigation and forensics.
10.43 S Must implement safeguards, such as logical network segmentation, to prevent a system compromise in one group entity from affecting others. Not applicable Intra-FI-group segmentation duty. IIMMPACT applies its own tenant-isolation posture separately.
10.44 S Must establish a backup strategy: backup and restoration procedures, adequate backup copies, secure storage, removable media controls per Appendix 1, periodic restoration testing, and an independent risk assessment of backup management. Direct Align directly: run a backup strategy over the transaction data IIMMPACT holds, with tested restoration.
10.45 S Must establish a tamper-proof backup arrangement and an isolated recovery environment for resilience against ransomware and other destructive attacks. Direct Align directly: maintain tamper-proof backups and an isolated recovery environment against destructive attacks.
10.46 S Board and senior management must exercise effective oversight of third party service providers engaged for critical technology functions; the institution remains accountable for all resulting risk. Indirect Align by being oversight-ready: give FI boards and senior management what they need to exercise the oversight this paragraph requires of them.
10.47 S Must conduct due diligence on a third party service provider before onboarding and throughout the engagement, considering the risks in Appendix 8. Indirect Align by being due-diligence-ready: maintain a standing due-diligence pack covering the Appendix 8 categories so any FI can assess IIMMPACT efficiently.
10.48 S Must establish a Service Level Agreement with the third party service provider covering: regulator access rights, sub-contracting notice, secrecy and confidentiality undertakings, disaster recovery and backup arrangements, uptime service level objectives, exit and termination continuity, prompt disclosure of incidents, compliance with recognized standards, and provider participation in the institution's security awareness program. Direct Align directly to the provider side: structure IIMMPACT's standard contract to carry the nine required SLA terms (regulator access, sub-contracting notice, secrecy, DR, uptime SLO, exit continuity, incident disclosure, standards compliance, awareness participation).
10.49 S Must build a roadmap for continuous monitoring of third party cybersecurity posture: measuring IT footprint and data exposure, adopting relevant security controls, integrating incident response, prioritizing high-assurance controls, higher-frequency incident monitoring, automated metric testing, and a process to respond to breached thresholds. Direct Align directly to the provider side: support continuous posture monitoring by sharing security posture and incident data with FIs on an ongoing basis.
10.50 S Must conduct a comprehensive risk assessment before cloud adoption covering deployment model, migration, jurisdiction and legal risk, multi-tenancy, vendor lock-in, security configuration, cyber-attack exposure, termination and data retrieval, responsibility demarcation, and regulatory compliance. Indirect Align where IIMMPACT's own hosting is cloud-based: give FIs the cloud-risk information they need to assess the integration.
10.51 G For critical systems on public cloud, expected to follow the Appendix 10 common risk and control guidance, or demonstrate equally or more effective alternative measures. Not applicable Guidance to the FI's own public-cloud hosting decisions.
10.52 S Must implement safeguards for customer, counterparty, and proprietary data on cloud services, retaining ownership and control including cryptographic key management. Direct Align directly: safeguard customer and counterparty data IIMMPACT handles on cloud, retaining control and key management, with clear data-ownership terms.
10.53 S Must implement an access control policy for identification, authentication, and authorization proportionate to the risk of unauthorized access. Direct Align directly: operate an access-control policy over IIMMPACT's own platform and the FI-facing integration surface.
10.54 S Access control principles: deny-all by default, least privilege, time-bound access, segregation of incompatible functions, defined dual authorization criteria, and risk-based authentication strength. Direct Align directly: apply deny-all, least-privilege, time-bound access and segregation of duties within IIMMPACT.
10.55 S Must employ multi-factor authentication combining two or more factor types, resistant to social engineering, for access to critical systems. Direct Align directly: enforce MFA on administrative and privileged access to IIMMPACT's own systems.
10.56 S Must establish and periodically review a user access matrix outlining access rights and approving authorities. Direct Align directly: maintain a user access matrix for IIMMPACT's own access, reviewed periodically.
10.57 S Must ensure enterprise-wide access control monitoring, anomaly investigation, and at least three years of retained and reviewed activity logs for critical systems. Direct Align directly: log and retain activity on IIMMPACT's own critical systems for at least three years.

Part B, Section 11: Cybersecurity Management

15 direct2 indirect3 n/a
Para.TypeRMiT requirement (intent)MappingIIMMPACT alignment approach
11.1 S Cyber risk management must be an enterprise-wide focus reflecting collective responsibility of business and technology lines. Not applicable FI's enterprise cyber-risk focus. IIMMPACT holds its own equivalent posture separately.
11.2 S Must develop a Cyber Resilience Framework (CRF) articulating governance, resilience objectives, and risk tolerance, supporting identification, protection, detection, response, and recovery (IPDRR). Direct Align directly: operate IIMMPACT's own cyber-resilience posture supporting identify-protect-detect-respond-recover across its platform.
11.3 S CRF must include risk context understanding, asset and system classification, threat and vulnerability identification, layered defence including zero-trust principles, timely detection, incident handling and crisis playbook, information-sharing procedures, centralized asset inventory tracking, and a dedicated cyber risk management function. Direct Align directly: apply the CRF elements (asset classification, layered defence, detection, incident handling, threat intel) to IIMMPACT's own environment.
11.4 S Institutions designated as National Critical Information Infrastructure (NCII) must comply with the Cyber Security Act 2024 and NACSA requirements. Not applicable NCII / Cyber Security Act designation is the FI's regulatory status.
11.5 S Must adopt the Appendix 5 control measures to enhance cyber-attack resilience. Direct Align directly, and pointedly: Appendix 5 Part E is API security. As an API provider, IIMMPACT aligning to the Appendix 5 controls (network, data, SOC, VAPT, API security) is core, not peripheral.
11.6 S Must conduct a realistic Red Team simulation attack at least once every three years. Direct Align directly: run Red Team style adversarial testing against IIMMPACT's own infrastructure.
11.7 G May implement crowdsourced security testing programs as a complement to existing assessments, using reputable providers. Direct Align directly, optional: consider crowdsourced security testing as a complement for IIMMPACT's own platform.
11.8 S Must establish clear cybersecurity operations responsibilities covering each phase of the cyber-attack lifecycle. Direct Align directly: hold clear cybersecurity-operations responsibilities across the attack lifecycle for IIMMPACT's own environment.
11.9 S Must ensure continuous, proactive monitoring: establish a Security Operations Centre, cover all critical systems and supporting infrastructure, and conduct regular vulnerability assessment and penetration testing per Appendix 5. Direct Align directly: run proactive monitoring, a SOC capability, and regular VAPT over IIMMPACT's own critical systems and supporting infrastructure.
11.10 S Must establish a process to collect, analyse, and evaluate cyber threat intelligence, including monitoring of social media and the dark web. Direct Align directly: operate a threat-intelligence process for IIMMPACT's own environment.
11.11 S Must establish an appropriate response process to investigate flagged anomalous activities based on their complexity. Direct Align directly: hold a response process to investigate flagged anomalies in IIMMPACT's own systems.
11.12 S Must establish comprehensive cyber crisis management policies integrated with business continuity and disaster recovery planning, and a stakeholder communication plan. Direct Align directly: maintain cyber crisis-management policies integrated with IIMMPACT's own continuity planning.
11.13 S Must establish a Cyber Incident Response Plan covering preparedness, detection and analysis, containment and eradication, recovery, and post-incident review. Direct Align directly: hold a Cyber Incident Response Plan covering IIMMPACT's own environment end to end.
11.14 S Cyber Emergency Response Team members must be conversant with the incident response plan and contactable at all times. Direct Align directly: keep IIMMPACT's own response team conversant with the plan and contactable.
11.15 S Must establish a secure out-of-band communication infrastructure for crisis coordination. Direct Align directly: maintain out-of-band communication for IIMMPACT's own crisis coordination.
11.16 S Must conduct an annual cyber drill exercise testing the incident response plan and out-of-band communication, involving the board, senior management, and relevant third party service providers, with results reported to the board. Indirect Align by being drill-ready: participate in an FI's annual cyber drill where IIMMPACT is a relevant third party to that FI's critical services.
11.17 S Must review loss provision and cyber insurance adequacy against extreme adverse scenarios, with specified governance considerations for any cyber insurance policy. Not applicable FI's own insurance and loss provision. IIMMPACT holds its own cover separately.
11.18 S Must notify BNM of cyber incidents in line with the Operational Risk Reporting, Business Continuity Management, and Merchant Acquiring Services policy documents. Indirect Align by supporting the FI's BNM notification duty: disclose incidents to affected FIs promptly and with enough detail for them to notify BNM.
11.19 S Must share cyber threat intelligence with the industry through relevant platforms, subject to applicable data protection law. Direct Align directly: participate in threat-intelligence sharing where relevant to IIMMPACT's own environment.
11.20 S Must collaborate with relevant stakeholders and authorities in combating cyber threats. Direct Align directly: collaborate with relevant stakeholders and authorities on cyber threats affecting IIMMPACT.

Part B, Section 12: Digital Services

0 direct8 indirect1 n/a
Para.TypeRMiT requirement (intent)MappingIIMMPACT alignment approach
12.1 S Must expand the CRF for digital services: minimum security controls per delivery channel (Appendices 2 to 4 and 11), proper user or device authentication and transaction authorization, and strong physical and logical controls. Indirect Align by carrying the security controls the FI's digital-service channel requires through the IIMMPACT-processed step.
12.2 S Where the paragraph 12.1 to 12.9 controls are not yet implemented, must document alternative measures and assume liability for resulting fraud. Indirect Align by not being the weak link: ensure the IIMMPACT-processed step does not force the FI into the alternative-measures liability position.
12.3 S Must enhance the CRF for digital fraud: extend threat identification to mobile devices and access points, adopt layered controls, maintain continuous surveillance, establish customer incident handling, coordinate across business functions, conduct senior management review, and report outcomes to the board. Not applicable to designated payment system operators and intermediary remittance institutions. Indirect Align by supporting the FI's digital-fraud controls on the IIMMPACT-processed transaction path.
12.4 S Must update fraud detection capabilities and rules in a timely manner upon new modus operandi, per the Appendix 11 Fraud Detection Standards. Indirect Align by feeding the FI's fraud detection: make IIMMPACT-processed transaction data available for the FI's fraud analytics.
12.5 S Must mitigate digital service delivery risk: secure communication channels, advance customer notice of new controls, and practical call-authenticity verification methods. Indirect Align by using secure channels and supporting customer-notice requirements on the IIMMPACT-processed path.
12.6 S Must give customers activation and deactivation control over payment cards for card-not-present and overseas transactions, without reducing institutional liability. Indirect Align where the IIMMPACT-processed transaction is card-based: support card activation and control features.
12.7 S Must maintain ongoing customer fraud awareness programs: modus operandi updates, security measure explanations, real-time risk alerts, and interactive simulations. Not applicable FI's own customer-awareness programme.
12.8 S Must provide convenient fraud reporting, account suspension, and reactivation channels: a self-service kill switch, an adequately resourced contact centre, and timely restoration after validation. Indirect Align by supporting the FI's fraud response: enable suspension and reactivation on the IIMMPACT-processed path.
12.9 S Must implement additional post-incident measures: heightened account monitoring, customer notification, and credential or instrument reissuance. Indirect Align by supporting post-incident measures on the IIMMPACT-processed path.

Part B, Section 13: Technology Audits

0 direct1 indirect3 n/a
Para.TypeRMiT requirement (intent)MappingIIMMPACT alignment approach
13.1 S Technology audit scope, frequency, and intensity must be proportionate to system complexity and criticality. Not applicable FI's own audit-scope proportionality.
13.2 S Must establish an annual technology audit plan covering critical services, third party service providers, external system interfaces, delayed or terminated projects, and post-implementation reviews. Indirect Align by being audit-ready: support the FI's technology audit where IIMMPACT integrations fall within its audit plan.
13.3 S Internal audit must have dedicated, professionally certified technology audit resources with sound subject-matter knowledge. Not applicable to non-NCII eligible e-money issuers, non-bank merchant acquirers, and intermediary remittance institutions. Not applicable FI's own internal-audit staffing and certification.
13.4 G Technology audit resources may advise during the planning and development phase of major products or systems, subject to independence safeguards for later post-implementation reviews. Not applicable FI's own audit-resource advisory role.

Part B, Section 14: External Party Assurance

0 direct2 indirect0 n/a
Para.TypeRMiT requirement (intent)MappingIIMMPACT alignment approach
14.1 S Must appoint a technically competent external party to conduct a Data Centre Resilience and Risk Assessment (DCRA) at least once every three years or on material infrastructure change; the designated board committee must deliberate the outcome. Indirect Align by supplying assurance: where IIMMPACT hosts or carries an FI critical system, provide an independent data-centre resilience assessment the FI can rely on, as this paragraph permits.
14.2 S Must appoint a technically competent external party to conduct a Network Resilience Assessment (NRA) on the same cadence; the designated board committee must deliberate the outcome. Indirect Align by supplying assurance: same, for network resilience.

Part B, Section 15: Security Awareness and Education

1 direct1 indirect1 n/a
Para.TypeRMiT requirement (intent)MappingIIMMPACT alignment approach
15.1 S Must provide regular, at least annual, cybersecurity awareness education for all staff, measured for effectiveness, extended to third party service providers where appropriate. Indirect Align by participating: take part in an FI's security-awareness programme where the FI judges it appropriate, and run IIMMPACT's own internal awareness in parallel.
15.2 S Must provide continuous training for staff in technology operations, cybersecurity, and risk management to ensure competency and certification. Direct Align directly: train IIMMPACT's own technology, security, and risk staff to competence and certification.
15.3 S Must provide board members with regular training on technology developments. Not applicable FI's own board training.

Part C, Section 16: Notification for Technology-Related Applications

0 direct4 indirect3 n/a
Para.TypeRMiT requirement (intent)MappingIIMMPACT alignment approach
16.1 S Must notify BNM before introducing new or enhanced digital services. Indirect Align by supporting the FI's notification duty when an IIMMPACT integration is the triggering enhancement: supply technical description and risk input.
16.2 S A first-time digital service offering requires notification including risk assessment, security arrangements, terms and conditions, client charter, privacy policy, and any finalized outsourcing or partnership arrangements. Indirect Align by supporting first-time-offering notification content the FI must submit.
16.3 S Enhancements meeting the Appendix 6 criteria qualify for simplified notification: description of the enhancement plus its risk assessment. Indirect Align by supporting the FI's assessment of simplified-notification eligibility (see Appendix 6).
16.4 S Enhancements not qualifying for simplified notification require independent external assurance (Appendix 7 Part A) and a CISO, senior management, or board-level confirmation (Appendix 7 Part B) before notifying BNM. Indirect Align by being review-ready where a full external assurance is required for an IIMMPACT integration.
16.5 S The independent external assurance party must be competent with a good track record, addressing Appendix 7 Parts C and D. Not applicable Governs the competence of the FI's chosen assurance party.
16.6 S Must provide relevant documents for BNM review when requested. Not applicable FI's own document-provision duty to BNM.
16.7 G May offer or implement the digital service immediately upon compliant notification. Not applicable Guidance on the FI's own timing.

Part C, Section 17: Consultation and Notification for Cloud Services and Emerging Technology

0 direct3 indirect2 n/a
Para.TypeRMiT requirement (intent)MappingIIMMPACT alignment approach
17.1 S Must consult BNM before first-time adoption of public cloud or emerging technology for critical systems: risk assessment per 10.50 and Appendix 10 (cloud) or Appendix 9 (emerging technology), a readiness confirmation per Appendix 7 Part B, and a third party pre-implementation review. Indirect Align where IIMMPACT's platform is characterised as cloud/emerging tech for an FI critical system: supply the risk information the FI needs to consult BNM.
17.2 S Must notify BNM for subsequent public cloud or emerging technology adoption, subject to prior first-time consultation, an enhanced risk management framework, independent assurance, and confirmed incident response sufficiency. Indirect Align by supporting subsequent-adoption notification on the same basis.
17.3 G No notification is required for non-material enhancements to existing cloud or emerging technology adoption. Not applicable Guidance; no notification for non-material change.
17.4 S BNM may direct consultation, notification, or guidance compliance at its discretion; the institution must comply promptly. Not applicable BNM's discretionary direction to the FI.
17.5 S The cloud and emerging technology adoption roadmap must be included in the annual outsourcing plan; supporting risk assessment documentation must be available to BNM on request. Indirect Align by supporting inclusion in the FI's annual outsourcing plan where relevant.

Part C, Section 18: Assessment and Gap Analysis

0 direct0 indirect2 n/a
Para.TypeRMiT requirement (intent)MappingIIMMPACT alignment approach
18.1 S Must perform a gap analysis against this policy document and submit an action plan to BNM within 90 days of issuance, maintaining continuous compliance tracking against revised requirements thereafter. Not applicable FI's own gap analysis and BNM submission. This very document is IIMMPACT's good-faith analogue: a voluntary self-mapping rather than a required filing.
18.2 S The self-assessment, gap analysis, and action plan must be submitted to the applicable BNM supervisory department. Not applicable FI's own submission routing.
Source: BNM/RH/PD 028-98, issued 28 November 202589 of 121 provisions relevant to IIMMPACT