Twenty questions your board should answer on technology risk.
In 2023 MAS found DBS short in four areas: system resilience, incident management, change management, and technology risk governance and oversight. Answer for your own organisation, add AI and agent change, and print a board pack with the evidence to request and the rule behind each gap.

The regulator's capital add-on and six-month freeze on change cost DBS more than any single outage did. The same four findings would apply to most banks and many regulated firms. Answer honestly: "Don't know" counts as a gap, because a board that cannot answer the question cannot show a regulator that it governs the risk.What happened at DBS →
- Governance and oversight. Who at board level owns technology risk, what appetite they set, and what they see.
- System resilience. Which services matter most, how fast they must come back, and whether that has been proven.
- Change management. How changes are approved and rolled back, and when the pace of change should slow.
- Incident management. How fast the regulator, management and customers hear about a failure, and what follows.
- AI and agent change. Models, prompts and agents change faster than systems; the same controls have to reach them.
Each answer, its points and where it lands in the pack
5 areas of 4 questions, 20 in all: 40 points available. The score is the share of those points, by area and overall.
Points, lists and tier bands as this tool computes them. Don't know scores the same as No, because a board that cannot answer the question cannot show a regulator that it governs the risk.
About 8 minutes. Nothing is sent anywhere.
Governance and oversight
Who at board level owns technology risk, what appetite they set, and what they see.
System resilience
Which services matter most, how fast they must come back, and whether that has been proven.
Change management
How changes are approved and rolled back, and when the pace of change should slow.
Incident management
How fast the regulator, management and customers hear about a failure, and what follows.
AI and agent change
Models, prompts and agents change faster than systems; the same controls have to reach them.
Technology risk board pack
–%
| Area | Score | Bar |
|---|---|---|
| Governance and oversight | – | |
| System resilience | – | |
| Change management | – | |
| Incident management | – | |
| AI and agent change | – |
For context: what the same findings cost DBS
MAS applied an operational-risk capital multiplier of 1.5 times after the November 2021 outage, about S$930 million, and raised it to 1.8 times in 2023, about S$1.6 billion in total. From November 2023 it paused DBS's non-essential IT changes and new business ventures for six months, citing shortcomings in system resilience, incident management, change management, and technology risk governance and oversight. Senior management's 2023 variable pay was cut by 21 per cent and the chief executive's by 30 per cent. Sources in the case study →
This pack is a self-assessment built from your answers. It does not constitute an audit, a regulatory opinion or legal advice. References were checked against the regulators' published texts on 23 September 2026; the EU references were read from reproductions of the Official Journal, MAS's AI risk management guidelines were still a consultation draft, and rules change, so confirm each reference with your compliance function before relying on it. Your answers stay in this browser and are neither sent to Terence Kok nor reviewed by anyone.
The rules behind each question.
| Jurisdiction | Instruments cited |
|---|---|
| Singapore (MAS) | MAS Technology Risk Management Guidelines (January 2021); MAS Notice FSM-N05 on Technology Risk Management (in force 10 May 2024, replacing Notice 644); MAS Guidelines on Business Continuity Management (June 2022). For AI: consultation paper P017-2025 on AI risk management (proposed, not final at 23 September 2026) and the December 2024 information paper on AI model risk management. |
| United Kingdom (PRA) | PRA SS1/21 Operational resilience (firms within impact tolerance by 31 March 2025); SS2/21 Outsourcing and third-party risk; SS1/23 Model risk management (applies to banks with internal model approval); new incident and third-party reporting rules in PS7/26 and SS1/26, which apply from 18 March 2027. Until then, Fundamental Rule 7 governs notification. |
| European Union (DORA) | Digital Operational Resilience Act, Regulation (EU) 2022/2554 (applies from 17 January 2025); Delegated Regulation (EU) 2025/301 on incident reporting timelines; EU AI Act, Regulation (EU) 2024/1689, whose Annex III high-risk obligations apply from 2 December 2027 after the 2026 digital omnibus. Read from reproductions of the Official Journal text. |
| Australia (APRA) | APRA CPS 230 Operational Risk Management (July 2026 text; first in force 1 July 2025); CPS 234 Information Security. |
| Hong Kong (HKMA) | HKMA Supervisory Policy Manual OR-2 Operational Resilience (May 2022); TM-G-1 General Principles for Technology Risk Management (2003); TM-G-2 Business Continuity Planning (May 2022); HKMA circular of 22 June 2010 on incident notification. |
| International (Basel) | Basel Committee Principles for Operational Resilience (d516) and Revisions to the Principles for the Sound Management of Operational Risk (d515), both March 2021. A baseline where no local rule applies. |
For AI questions the pack also cites the relevant ISO/IEC 42001:2023 Annex A control by number and title. For board oversight of AI more broadly, use the Board AI Oversight Checklist; for sizing agent risk, the Agent Risk Assessment Matrix.

When MAS froze change at DBS, the four findings it named were not exotic. Most boards I sit in front of could not answer the questions behind them with evidence on the table: which services come back within four hours, when failover was last proven, who decides to slow change, how fast the regulator hears. This pack turns those findings into twenty questions and a paper you can table at the next risk committee, with the rule behind each one so the conversation starts from the requirement rather than from opinion.

