← All Articles

What the DBS Outages Teach Boards About Technology Risk

14 min readGovernance & RiskSharePDF

Listen to this article

What the DBS Outages Teach Boards About Technology Risk

0:00
Jump to a section

Executive Summary

DBS is the region’s reference case for digital transformation, and in 2025 it reported about S$1 billion in economic value from data and AI. Between November 2021 and October 2023 it also suffered a series of digital outages serious enough that the Monetary Authority of Singapore twice raised its operational-risk capital requirement, to about S$1.6 billion in total, and then imposed a six-month pause on non-essential IT changes and new business ventures. MAS found shortcomings in four areas: system resilience, incident management, change management, and technology risk governance and oversight. DBS’s own annual report linked part of the problem to its modernisation, saying the move from a mainframe to cloud-native microservices had created a more complex infrastructure requiring additional rigour. For boards moving fast on AI and agents, the episode is a map of where oversight has to be in place before the speed arrives.

S$930m

additional regulatory capital from a 1.5 times operational-risk multiplier after the November 2021 outage, MAS, February 2022

S$1.6bn

total additional capital once MAS raised the multiplier to 1.8 times after the March 2023 disruption, MAS, May 2023

5

disruptions to DBS banking services in eight months, as MAS told Parliament in November 2023

6 months

pause on non-essential IT changes and new business ventures, from 1 November 2023 to 30 April 2024, MAS

Core conclusions

  • The failures sat in operations and governance. MAS’s four findings were resilience, incident management, change management and technology risk oversight, and none of them is solved by better software alone.
  • Modernisation raises operational risk before it lowers it. DBS said so itself: the shift to microservices made the estate more complex and needed more operational rigour and oversight.
  • Board oversight of technology risk has to be built ahead of the change programme. At DBS the dedicated board committee, the risk reporting line and the resilience budget came after the regulator acted. AI agents raise the same question on a shorter clock.

DBS spent fifteen years becoming a bank that runs like a technology company. It took its engineering back in-house, moved almost everything onto its own cloud, reorganised into 33 platforms and, by 2025, reported about S$1 billion in economic value from data and AI. I have written up that journey in full in the DBS Bank case study. This post covers the part of it that boards talk about less: the two years in which the same bank became the subject of some of the sharpest regulatory action MAS has taken on technology risk.

The outages and the regulator’s actions

The sequence matters, because each MAS action built on the one before.

DateWhat happenedMAS response
23 to 25 November 2021Digital banking services down for about two daysFebruary 2022: 1.5 times multiplier on operational-risk RWA, about S$930 million in additional capital. MAS noted deficiencies in incident management and recovery procedures
29 March 2023Digital services disrupted againSame day: MAS called it “unacceptable, coming a year after a similar incident”. May 2023: multiplier raised to 1.8 times, about S$1.6 billion in total additional capital
14 October 2023Data centre cooling failure; DBS could not fail over because of a network misconfigurationUp to 810,000 attempts to access digital banking failed and about 2.5 million payment and ATM transactions could not be completed
1 November 2023MAS counts five disruptions in eight monthsSix-month pause on non-essential IT changes; no new business ventures; no reduction of branches or ATMs
30 April 2024Pause reviewedNot extended. The 1.8 times multiplier stays until DBS shows it can maintain service availability

Sources: MAS media releases of 7 February 2022, 29 March 2023, 5 May 2023, 1 November 2023 and 30 April 2024; MAS oral reply to a parliamentary question, 6 November 2023.

Setbacks, 2021 to 2024

Two and a half years of outages, and the capital MAS added for them.

Nov 2021Digital banking down for about two days.
Feb 2022MAS applies a 1.5× multiplier to operational-risk RWA. About S$930m of extra capital.
Mar 2023Digital services disrupted again.
May 2023Multiplier raised to 1.8×. About S$1.6bn of extra capital.
Oct 2023Data-centre cooling fails; no failover. About 2.5 million payment and ATM transactions not completed.
Nov 2023Six-month pause on non-essential IT changes. Board sets up a technology risk committee.
Apr 2024Pause ends. The 1.8× multiplier stays until DBS shows it can keep services available.
OutageRegulator's action

Sources: MAS media releases of 7 February 2022, 5 May 2023, 1 November 2023 and 30 April 2024; MAS parliamentary reply, 6 November 2023; DBS, 1 November 2023. MAS counted five disruptions in the eight months to November 2023; the major ones are shown.

The capital figure is the one boards should dwell on. MAS noted in 2022 that the S$930 million was four times the amount it had required for a similar DBS disruption in 2010, when the multiplier was 1.2 times and the add-on about S$230 million. The regulator was signalling that the tolerance for repeat technology failure at a systemically important bank had fallen sharply.

The regulator’s four findings

When MAS imposed the pause, it named the areas where it had found shortcomings: system resilience; incident management; change management; and technology risk governance and oversight. It also said the planned structural fixes would take up to 24 months.

The four areas where MAS found shortcomings at DBS in 2023: system resilience, incident management, change management, and technology risk governance and oversight
Only the first finding is mostly an engineering matter. The other three are about how change is approved, how failure is handled and who at the top is watching.

Read the list as a board would. System resilience is partly engineering. Incident management, change management and governance are management disciplines: who is allowed to change what, how a failure is escalated and recovered, and whether the board sees technology risk with the same clarity it sees credit risk. A bank with thousands of in-house engineers and tens of thousands of code releases a month had a strong engineering bench. The gaps MAS named were in the controls around it.

Complexity came with the modernisation

DBS’s 2023 annual report was candid about one cause. “The shift from a monolithic mainframe to a cloud-native, microservices-based approach,” the technology statement said, “created a more complex infrastructure requiring additional operational rigour and oversight.”

That sentence deserves a place in every transformation business case. Breaking a monolith into hundreds of services makes change faster and cheaper, which is why DBS did it. It also multiplies the number of moving parts, dependencies and failure paths, and it pushes more of the reliability burden onto change control and incident response. The October 2023 failure is a clean example: a physical cooling fault at a data centre became a customer-facing outage because a network configuration meant the failover did not work. No single engineer made a large mistake. The system as configured could not absorb an ordinary fault.

Boards approving a modernisation programme usually see the benefits case and a delivery risk register. Few see an explicit statement that operational risk will rise during the transition, by how much, and what additional controls will carry it.

How DBS restructured oversight

DBS’s response is as instructive as the failures. By May 2023 it had convened a Special Board Committee to oversee a full review by an independent external expert. On 1 November 2023, the day MAS imposed the pause, the board apologised publicly and set out a roadmap:

  • A new board committee dedicated to technology risk, reporting through the Board Risk Management Committee.
  • Technology risk management moved under the Chief Risk Officer.
  • Technology and operations split into two units, with a new acting Chief Information Officer.
  • A special budget of SGD 80 million for resilience.
  • A target of no more than an average of 1.5 hours a month of unscheduled downtime for three key services, with recovery within three hours, improving to two hours or less within 24 months.

The 2023 annual report adds a Technology Risk Management Uplift programme chaired by the CEO. In February 2024 DBS cut senior management’s 2023 variable pay by 21 per cent and the CEO’s by 30 per cent, SGD 4.14 million. Eugene Huang was appointed CIO from May 2024, and by 2025 the annual report describes a Board Technology Committee monitoring resilience, security and architecture milestones.

Every item on that list is sensible. The board question is timing. Each came after the regulator had acted, and most of them could have been decided in 2018, when the bank reorganised around platforms and committed to cloud-native engineering.

The same questions apply to AI agents

The AI programme at DBS ran through the same period. The bank reported S$370 million of AI economic value for 2023 and about S$1 billion for 2025, and in 2026 it is deploying agents. CEO Tan Su Shan describes the control layer this way: “We can see all the agents, the agent registry… accountability, observability, traceability and evaluations of the agents.”

That is the right list, and it maps directly onto MAS’s four findings. An agent registry is change management for software that acts. Observability and traceability are incident management. Evaluations are resilience testing for model behaviour. Accountability is governance and oversight. The difference is speed. A model or prompt change can alter the behaviour of thousands of automated decisions overnight, and an agent with tool access can act on production systems faster than a human change board can meet. The lesson from 2021 to 2023 is that the oversight has to be designed and running before the autonomy is granted.

Six questions for the board

Before approving the next phase of an AI or modernisation programme, I would want the board to have written answers to these:

  1. Which of our critical services would be unavailable if one data centre or one cloud region failed today, and when did we last prove the failover works?
  2. How is a change to a model, a prompt or an agent’s permissions approved, tested and rolled back, and who signs it?
  3. Which board committee owns technology risk, how often does it meet, and does its chair have the background to challenge the CIO?
  4. Does technology risk report to the Chief Risk Officer, with the same independence as credit and market risk?
  5. What unscheduled downtime and recovery time do we tolerate for each critical service, and are those numbers on the board dashboard?
  6. What operational risk does the transformation add during the transition, and which named controls carry it?

The free technology risk board pack expands these into twenty questions across the four MAS findings and AI change, and prints a pack with the evidence to request and the MAS, PRA, DORA, APRA or HKMA rule behind each gap.

Free tool

How Far Is Your Organisation From DBS?

Score your organisation on the nine capabilities DBS built before its AI paid off, and see which gap to close first.

→

Evidence & Methodology

Almost everything factual here comes from the regulator or from DBS itself, which makes the record unusually solid. The conclusions about timing and about AI agents are mine, and I have marked them.

ClaimSourceGrade
1.5 times multiplier and about S$930m (2022); 1.8 times and about S$1.6bn in total (2023); 2010 comparison of 1.2 times and about S$230mMAS media releases, 7 February 2022 and 5 May 2023Measured, regulator record
Five disruptions in eight months; 810,000 failed access attempts and 2.5 million transactions not completed on 14 October 2023; failover blocked by network misconfigurationMAS oral reply to a parliamentary question, 6 November 2023Measured, regulator record
Six-month pause, four areas of shortcoming, up to 24 months for structural changes; pause not extended in April 2024 with the multiplier retainedMAS media releases, 1 November 2023 and 30 April 2024Measured, regulator record
Board committee, CRO reporting line, tech and ops split, SGD 80m budget, downtime targets; 21% and 30% pay cutsDBS press release, 1 November 2023; DBS 4Q23 press statement, 7 February 2024Reported by DBS
Mainframe-to-microservices shift created a more complex infrastructureDBS Annual Report 2023, technology statementReported by DBS
Oversight should have been built before the change programme; the same logic applies to AI agentsMy reading of the sequence, from governance and assurance work with regulated firmsMy call

If your board is approving a modernisation or AI programme and wants the oversight designed before the speed arrives, the six questions above are where I usually start. My consulting work covers technology and AI risk governance for boards of regulated firms and public agencies.

Was this useful?

Read next
Terence Kok
Before You Go

I have admired what DBS built for a long time, and I still do. That is why this episode is worth studying. A bank with one of the strongest engineering benches in the region, a CEO who put digital on every scorecard and a board that funded it, still ended up with its regulator freezing change for six months. If it can happen there, the question for every other board is whether its oversight of technology risk is keeping pace with its own ambitions. Most of the boards I work with have not asked it in writing yet.

Terence Kok