Executive Summary
DBS is the region’s reference case for digital transformation, and in 2025 it reported about S$1 billion in economic value from data and AI. Between November 2021 and October 2023 it also suffered a series of digital outages serious enough that the Monetary Authority of Singapore twice raised its operational-risk capital requirement, to about S$1.6 billion in total, and then imposed a six-month pause on non-essential IT changes and new business ventures. MAS found shortcomings in four areas: system resilience, incident management, change management, and technology risk governance and oversight. DBS’s own annual report linked part of the problem to its modernisation, saying the move from a mainframe to cloud-native microservices had created a more complex infrastructure requiring additional rigour. For boards moving fast on AI and agents, the episode is a map of where oversight has to be in place before the speed arrives.
S$930m
additional regulatory capital from a 1.5 times operational-risk multiplier after the November 2021 outage, MAS, February 2022
S$1.6bn
total additional capital once MAS raised the multiplier to 1.8 times after the March 2023 disruption, MAS, May 2023
5
disruptions to DBS banking services in eight months, as MAS told Parliament in November 2023
6 months
pause on non-essential IT changes and new business ventures, from 1 November 2023 to 30 April 2024, MAS
Core conclusions
- The failures sat in operations and governance. MAS’s four findings were resilience, incident management, change management and technology risk oversight, and none of them is solved by better software alone.
- Modernisation raises operational risk before it lowers it. DBS said so itself: the shift to microservices made the estate more complex and needed more operational rigour and oversight.
- Board oversight of technology risk has to be built ahead of the change programme. At DBS the dedicated board committee, the risk reporting line and the resilience budget came after the regulator acted. AI agents raise the same question on a shorter clock.
The argument, in ten slides
Save it, or send it to whoever chairs your risk committee.










DBS spent fifteen years becoming a bank that runs like a technology company. It took its engineering back in-house, moved almost everything onto its own cloud, reorganised into 33 platforms and, by 2025, reported about S$1 billion in economic value from data and AI. I have written up that journey in full in the DBS Bank case study. This post covers the part of it that boards talk about less: the two years in which the same bank became the subject of some of the sharpest regulatory action MAS has taken on technology risk.
The outages and the regulator’s actions
The sequence matters, because each MAS action built on the one before.
| Date | What happened | MAS response |
|---|---|---|
| 23 to 25 November 2021 | Digital banking services down for about two days | February 2022: 1.5 times multiplier on operational-risk RWA, about S$930 million in additional capital. MAS noted deficiencies in incident management and recovery procedures |
| 29 March 2023 | Digital services disrupted again | Same day: MAS called it “unacceptable, coming a year after a similar incident”. May 2023: multiplier raised to 1.8 times, about S$1.6 billion in total additional capital |
| 14 October 2023 | Data centre cooling failure; DBS could not fail over because of a network misconfiguration | Up to 810,000 attempts to access digital banking failed and about 2.5 million payment and ATM transactions could not be completed |
| 1 November 2023 | MAS counts five disruptions in eight months | Six-month pause on non-essential IT changes; no new business ventures; no reduction of branches or ATMs |
| 30 April 2024 | Pause reviewed | Not extended. The 1.8 times multiplier stays until DBS shows it can maintain service availability |
Sources: MAS media releases of 7 February 2022, 29 March 2023, 5 May 2023, 1 November 2023 and 30 April 2024; MAS oral reply to a parliamentary question, 6 November 2023.
Two and a half years of outages, and the capital MAS added for them.
Sources: MAS media releases of 7 February 2022, 5 May 2023, 1 November 2023 and 30 April 2024; MAS parliamentary reply, 6 November 2023; DBS, 1 November 2023. MAS counted five disruptions in the eight months to November 2023; the major ones are shown.
The capital figure is the one boards should dwell on. MAS noted in 2022 that the S$930 million was four times the amount it had required for a similar DBS disruption in 2010, when the multiplier was 1.2 times and the add-on about S$230 million. The regulator was signalling that the tolerance for repeat technology failure at a systemically important bank had fallen sharply.
The regulator’s four findings
When MAS imposed the pause, it named the areas where it had found shortcomings: system resilience; incident management; change management; and technology risk governance and oversight. It also said the planned structural fixes would take up to 24 months.

Read the list as a board would. System resilience is partly engineering. Incident management, change management and governance are management disciplines: who is allowed to change what, how a failure is escalated and recovered, and whether the board sees technology risk with the same clarity it sees credit risk. A bank with thousands of in-house engineers and tens of thousands of code releases a month had a strong engineering bench. The gaps MAS named were in the controls around it.
Complexity came with the modernisation
DBS’s 2023 annual report was candid about one cause. “The shift from a monolithic mainframe to a cloud-native, microservices-based approach,” the technology statement said, “created a more complex infrastructure requiring additional operational rigour and oversight.”
That sentence deserves a place in every transformation business case. Breaking a monolith into hundreds of services makes change faster and cheaper, which is why DBS did it. It also multiplies the number of moving parts, dependencies and failure paths, and it pushes more of the reliability burden onto change control and incident response. The October 2023 failure is a clean example: a physical cooling fault at a data centre became a customer-facing outage because a network configuration meant the failover did not work. No single engineer made a large mistake. The system as configured could not absorb an ordinary fault.
Boards approving a modernisation programme usually see the benefits case and a delivery risk register. Few see an explicit statement that operational risk will rise during the transition, by how much, and what additional controls will carry it.
How DBS restructured oversight
DBS’s response is as instructive as the failures. By May 2023 it had convened a Special Board Committee to oversee a full review by an independent external expert. On 1 November 2023, the day MAS imposed the pause, the board apologised publicly and set out a roadmap:
- A new board committee dedicated to technology risk, reporting through the Board Risk Management Committee.
- Technology risk management moved under the Chief Risk Officer.
- Technology and operations split into two units, with a new acting Chief Information Officer.
- A special budget of SGD 80 million for resilience.
- A target of no more than an average of 1.5 hours a month of unscheduled downtime for three key services, with recovery within three hours, improving to two hours or less within 24 months.
The 2023 annual report adds a Technology Risk Management Uplift programme chaired by the CEO. In February 2024 DBS cut senior management’s 2023 variable pay by 21 per cent and the CEO’s by 30 per cent, SGD 4.14 million. Eugene Huang was appointed CIO from May 2024, and by 2025 the annual report describes a Board Technology Committee monitoring resilience, security and architecture milestones.
Every item on that list is sensible. The board question is timing. Each came after the regulator had acted, and most of them could have been decided in 2018, when the bank reorganised around platforms and committed to cloud-native engineering.
The same questions apply to AI agents
The AI programme at DBS ran through the same period. The bank reported S$370 million of AI economic value for 2023 and about S$1 billion for 2025, and in 2026 it is deploying agents. CEO Tan Su Shan describes the control layer this way: “We can see all the agents, the agent registry… accountability, observability, traceability and evaluations of the agents.”
That is the right list, and it maps directly onto MAS’s four findings. An agent registry is change management for software that acts. Observability and traceability are incident management. Evaluations are resilience testing for model behaviour. Accountability is governance and oversight. The difference is speed. A model or prompt change can alter the behaviour of thousands of automated decisions overnight, and an agent with tool access can act on production systems faster than a human change board can meet. The lesson from 2021 to 2023 is that the oversight has to be designed and running before the autonomy is granted.
Six questions for the board
Before approving the next phase of an AI or modernisation programme, I would want the board to have written answers to these:
- Which of our critical services would be unavailable if one data centre or one cloud region failed today, and when did we last prove the failover works?
- How is a change to a model, a prompt or an agent’s permissions approved, tested and rolled back, and who signs it?
- Which board committee owns technology risk, how often does it meet, and does its chair have the background to challenge the CIO?
- Does technology risk report to the Chief Risk Officer, with the same independence as credit and market risk?
- What unscheduled downtime and recovery time do we tolerate for each critical service, and are those numbers on the board dashboard?
- What operational risk does the transformation add during the transition, and which named controls carry it?
The free technology risk board pack expands these into twenty questions across the four MAS findings and AI change, and prints a pack with the evidence to request and the MAS, PRA, DORA, APRA or HKMA rule behind each gap.
Free tool
How Far Is Your Organisation From DBS?
Score your organisation on the nine capabilities DBS built before its AI paid off, and see which gap to close first.
Evidence & Methodology
Almost everything factual here comes from the regulator or from DBS itself, which makes the record unusually solid. The conclusions about timing and about AI agents are mine, and I have marked them.
| Claim | Source | Grade |
|---|---|---|
| 1.5 times multiplier and about S$930m (2022); 1.8 times and about S$1.6bn in total (2023); 2010 comparison of 1.2 times and about S$230m | MAS media releases, 7 February 2022 and 5 May 2023 | Measured, regulator record |
| Five disruptions in eight months; 810,000 failed access attempts and 2.5 million transactions not completed on 14 October 2023; failover blocked by network misconfiguration | MAS oral reply to a parliamentary question, 6 November 2023 | Measured, regulator record |
| Six-month pause, four areas of shortcoming, up to 24 months for structural changes; pause not extended in April 2024 with the multiplier retained | MAS media releases, 1 November 2023 and 30 April 2024 | Measured, regulator record |
| Board committee, CRO reporting line, tech and ops split, SGD 80m budget, downtime targets; 21% and 30% pay cuts | DBS press release, 1 November 2023; DBS 4Q23 press statement, 7 February 2024 | Reported by DBS |
| Mainframe-to-microservices shift created a more complex infrastructure | DBS Annual Report 2023, technology statement | Reported by DBS |
| Oversight should have been built before the change programme; the same logic applies to AI agents | My reading of the sequence, from governance and assurance work with regulated firms | My call |
Sources
- Monetary Authority of Singapore. (2022). MAS imposes additional capital requirement on DBS Bank.
- Monetary Authority of Singapore. (2023). MAS statement on disruption of DBS’ digital banking services.
- Monetary Authority of Singapore. (2023). MAS imposes further additional capital requirement on DBS Bank for disruption of banking services.
- Monetary Authority of Singapore. (2023). Oral reply to parliamentary question on banking services disruption of DBS and Citibank.
- Monetary Authority of Singapore. (2023). MAS imposes six-month pause on DBS’ non-essential activities.
- DBS Group. (2023). DBS apologises for series of digital disruptions, lays out comprehensive roadmap to improve technology resiliency.
- DBS Group. (2024). Annual Report 2023: CIO statement.
- DBS Group. (2024). Fourth quarter 2023 press statement.
- Monetary Authority of Singapore. (2024). MAS will not extend six-month pause on DBS’ non-essential activities.
- DBS Group. (2024). DBS appoints veteran technologist Eugene Huang as Chief Information Officer.
- DBS Group. (2026). CEO Tan Su Shan on how agentic AI is transforming the bank.

AI Can Triage. It Can't Be Accountable. Most Enterprises Have the Order Backwards.
The accountability principle behind question 2: a named person approves every change to what an agent is allowed to do.

Why Autonomy Readiness Should Cap Your Agentic AI Score
Why the controls in place, and not the capability of the model, should decide how much an agent may do on its own.

An AI Management System Is Not a Policy Binder. It's the Machine ISO 42001 Actually Audits.
The management system a board can point to when a regulator asks how AI change is governed.

How Financial Institutions Should Use AI to Keep Up With Regulatory Change
What the proposed MAS AI risk management guidelines ask of the institutions they cover.
If your board is approving a modernisation or AI programme and wants the oversight designed before the speed arrives, the six questions above are where I usually start. My consulting work covers technology and AI risk governance for boards of regulated firms and public agencies.
