If you sell software, IT support, payroll processing or another service to a bank, an insurer or a payment firm in Singapore, the rules your client follows when it outsources to you changed on 11 December 2024. MAS now marks the Guidelines on Outsourcing it issued on 27 July 2016 as cancelled, and states that they were "in effect until 10 December 2024" (MAS, Guidelines on Outsourcing).

The Answer in 60 Seconds

MAS split the old guidelines in two. Banks and merchant banks now answer to binding Notices, MAS Notice 658 for banks and MAS Notice 1121 for merchant banks, issued under section 47A of the Banking Act 1970, together with new Guidelines on Outsourcing (Banks). Every other financial institution, insurers and insurance brokers included, follows the old text "amended and renamed" as the Guidelines on Outsourcing (Financial Institutions other than Banks), covered in our guide to the non-bank guidelines.

The obligations sit on the bank, and they reach you through its contract. For a material ongoing service, Notice 658 lists terms the bank "must" put into the agreement: confidentiality, a right for MAS or its auditor to audit your books, systems and premises, records on request, deletion of customer information at exit, and the bank's right to terminate. Cloud and software-as-a-service, IT hosting, helpdesk and payroll services are treated as outsourced services by default.

On insurance, the guidelines ask the financial institution to evaluate your "insurance coverage" during due diligence, and to set out the indemnities and the party liable for losses from a security breach in the contract. None of the outsourcing instruments (Notices 658 and 1121, the two sets of Guidelines, or MAS's FAQs on them) sets a minimum limit, a line of cover or an insurer rating. A figure of that kind in your contract comes from your client, not from MAS.

The Sourced Detail

What happened to the 2016 guidelines

The old set was a single document for every MAS-regulated institution: guidance, in MAS's own words, "on sound practices on risk management of outsourcing arrangements" (Guidelines on Outsourcing, 27 July 2016, last revised 5 October 2018). On 11 December 2023 MAS published its response to the consultation, together with the new Notices and Guidelines. Most of the new regime took effect on 11 December 2024, but not all at once: the Notice 658 contract terms start as each existing agreement is next extended (MAS Notice 658, para 14.2).

What replaced it depends on who your client is. For banks and merchant banks it was replaced: MAS said banks "should refer to the Guidelines for Banks from 11 December 2024", and two older secrecy notices on outsourcing, Notice 634 for banks and Notice 1108 for merchant banks, were cancelled from the same day (MAS, Response to Feedback, 11 December 2023; MAS Notice 634; MAS Notice 1108). For everyone else it was renamed: MAS's circular to insurers says the existing guidelines "have been amended and renamed as "Guidelines on Outsourcing (Financial Institutions other than Banks)"" (MAS Circular ID 19/23).

The bank regime: section 47A, Notice 658 and Notice 1121

The legal base is section 47A of the Banking Act 1970. Before obtaining any relevant service from any person, a bank "must" take the steps MAS specifies to evaluate that person, and "enter into a contract with the person that satisfies requirements specified by the Authority by written notice to the bank" (s47A(4)). A bank that contravenes section 47A(2) or (4), or a requirement of a notice made under subsection (6) or (7), is liable on conviction to a fine not exceeding S$250,000 and, for a continuing offence, a further fine not exceeding S$25,000 for every day or part of a day it continues after conviction (s47A(11)). The fine sits on the bank; what reaches you is the contract.

Notice 658 is that written notice for banks. It is dated 11 December 2023, "applies to all banks in Singapore", and, other than its contract-term paragraphs 7.1 and 12.8, takes effect on 11 December 2024 (MAS Notice 658, paras 1.1 and 14.1). For a contract signed before 11 December 2023, the mandatory terms apply from the date the bank next extends it or 11 December 2024, whichever is later (para 14.2). Notice 1121 applies the same regime to merchant banks; MAS said its requirements "will mirror" Notice 658 (MAS Notice 1121; Response to Feedback, footnote 1).

Which services count

The net is wide. A "relevant service" is any service a bank obtains, other than from its own employees, directors or officers (Banking Act 1970, s47A(12)). A service is "ongoing" when it runs for more than 12 months, or when renewals take its cumulative duration past 12 months, and it is "material" when a leak of the information you hold, unauthorised access to your systems, or your failure to deliver would materially affect the bank (MAS Notice 658, para 2.1).

Annex C of Notice 658 lists services that count as outsourced by default: "Public cloud services including, but not limited to, software-as-a-service, platform-as-a-service and infrastructure-as-a-service", hosting and maintenance of information systems, IT helpdesks, data centre operations, data archival and destruction, "payroll processing, benefits and compensation administration and recruitment", corporate secretariat services, electronic signature services and ATM maintenance (MAS Notice 658, Annex C).

Some services fall outside. Annex B excludes training and technical support on off-the-shelf software by the vendor that developed it, "advisory services, including services provided under a retainer arrangement", and expert assessments where the bank lacks the expertise. Annex D exempts services not performed for banking business where the provider has no access to the bank's confidential or customer information, and gives "cleaning, gardening and pantry services" as examples (MAS Notice 658, Annexes B and D).

What the bank must do, and what it will ask of you

A register. The bank records every ongoing outsourced service, and every one that involves disclosing customer information, in a register it "must" submit to MAS "semi-annually and at any time upon request" (MAS Notice 658, paras 3.1 and 3.2).

Due diligence, then again within 24 months. Before a material ongoing service starts, the bank checks your risk management framework, your "reputation and track record in providing similar relevant services" and your "financial strength and resources", and repeats those checks "no later than 24 months" after the service begins (paras 5.1 and 5.2). A short track record is not a bar: MAS said the test "should not preclude Banks from engaging service providers that are startups" (MAS, Response to Feedback, revised March 2025, para 5.10).

Contract terms the bank must include. For a material ongoing service, the agreement must contain terms that achieve the effect of, among others: confidentiality of customer information; a requirement "that the Authority, or an auditor appointed by the Authority, be allowed to audit the books, systems and premises of the service provider"; records and information provided on request; deletion or destruction of customer information at the end; and the bank's right to terminate on reasonable notice, if MAS directs it, if you or your sub-contractor fail to safeguard customer information, or if your ability to safeguard it has demonstrably deteriorated (MAS Notice 658, para 7.1). MAS narrowed the termination grounds to these four after service providers said the draft terms "could be easily triggered by Banks" (Response to Feedback, revised March 2025, paras 11.2 and 11.5).

An independent audit every three years. The bank "must conduct independent audits" on each material ongoing service "at least once every three years" (MAS Notice 658, para 9.1). A certification audit by independent auditors counts; a self-attestation does not (Guidelines on Outsourcing (Banks), para 3.9.8).

Sub-contractors. The bank's prior approval is expected before any part of a material service is sub-contracted, and you tell the bank when you engage a sub-contractor: "MAS expects the notification to take place no later than 30 days" (Guidelines on Outsourcing (Banks), paras 3.5.1 and 3.5.4). Where the sub-contracting involves disclosing customer information, the bank needs "the consent in writing of the customer" (MAS Notice 658, para 6.1).

Where the data sits. The test is access, not a postcode. A bank "should not enter into outsourcing arrangements with service providers in jurisdictions where prompt access to information by MAS ... may be impeded by legal or administrative restrictions" (Guidelines on Outsourcing (Banks), para 3.10.2(b)). None of these outsourcing instruments requires data to be hosted in Singapore.

Business continuity and incidents. The bank verifies that you have "satisfactory business continuity plans", expects you to test them, and writes into the contract "the type of events and the circumstances under which the service provider should report to the Bank" (paras 3.7.2 and 3.4.2(g)). The instruments set no fixed number of hours for that report; any deadline is a term of your contract.

Your staff. Employees working on the service are assessed against "the Bank's hiring policies for the role they are performing" (para 3.3.4).

Insurance: what the instruments say, and what they do not

The guidelines put "insurance coverage" on the list of information the financial institution evaluates about a service provider, as item (h) in the bank set and the non-bank set alike (Guidelines on Outsourcing (Banks), para 3.3.3; Guidelines on Outsourcing (FIs other than Banks), para 5.4.3).

They also shape the liability clauses your insurance sits behind. The contract should specify "the indemnities, remedies and recourse of the respective parties", address "the party liable for losses in the event of a breach of security or confidentiality", and make the service provider "contractually liable for the performance and risk management practices of its sub-contractor" (Guidelines on Outsourcing (Banks), paras 3.4.2(h), 3.6.2(a) and 3.5.1).

That is the whole of it. Notice 658 and Notice 1121 carry no insurance, indemnity or liability requirement, and none of the outsourcing instruments (Notices 658 and 1121, the two sets of Guidelines, or MAS's FAQs on them) names a line of cover, a minimum limit, an insurer rating or a certificate of insurance. When a bank's contract asks for a cyber limit or a professional indemnity limit, the number does not come from these MAS instruments; it is a term between you and your client.

If your client is not a bank

Insurers, insurance brokers, payment institutions, capital markets firms and financial advisers follow the Guidelines on Outsourcing (Financial Institutions other than Banks), effective 11 December 2024 and last revised on 24 January 2025 (MAS). They remain guidelines rather than a notice, the register goes to MAS "at least annually or upon request" (para 4.1.1), and MAS "has removed the expectation for institutions to notify MAS before making any material outsourcing commitment" (MAS FAQ on the Guidelines on Outsourcing, Q1). The detail is in our guide to the non-bank guidelines.

Common Mistakes

  1. Treating the 2016 guidelines as current. MAS lists them as cancelled and "in effect until 10 December 2024"; a questionnaire or policy that still cites them is out of date (MAS).

  2. Reading a limit in your contract as a MAS rule. The instruments ask the institution to evaluate your insurance coverage; the limit, the lines of cover and any rating come from your client (Guidelines on Outsourcing (Banks), para 3.3.3).

  3. Assuming the data has to live in Singapore. The test is whether MAS can get prompt access to the information, not where the server is (Guidelines on Outsourcing (Banks), para 3.10.2(b)).

  4. Sub-contracting without telling the bank. MAS expects the notice no later than 30 days after the engagement, and a material service needs the bank's prior approval (Guidelines on Outsourcing (Banks), paras 3.5.1 and 3.5.4).

  5. Thinking only IT vendors are caught. Payroll processing, benefits and compensation administration, recruitment, corporate secretariat and electronic signature services are on Annex C's list alongside cloud and hosting (MAS Notice 658, Annex C).

  6. Offering a self-attestation where the bank needs an audit. A certification audit by independent auditors can be relied on; a self-attestation cannot (Guidelines on Outsourcing (Banks), para 3.9.8).

What This Means for Your Business

Sort your financial-sector clients first. A bank or merchant bank works under Notice 658 or 1121 and, if your service is a material ongoing one, will put the paragraph 7.1 terms into your contract; an insurer, broker or payment firm works under the non-bank guidelines, which set expectations rather than mandatory terms.

Then read three parts of the contract together: the audit and access clause, the indemnity and liability clause, and the insurance schedule. The first tells you who can inspect your books, systems and premises; the second tells you what losses you carry after a security breach or a sub-contractor's failure; the third is the cover your client wants to see behind them. Take all three to a licensed adviser and check your policies against them before you sign, not at renewal.

Keep two records ready: a list of the sub-contractors on each financial-sector service, with the date you told the client about each one, and your latest independent certification report, because a certification audit by independent auditors can be relied on to meet the bank's audit expectations (Guidelines on Outsourcing (Banks), para 3.9.8).

Questions to Ask Your Adviser

  1. Does my professional indemnity or technology errors and omissions policy respond to the indemnity this bank's contract asks me to give?
  2. Does my cyber policy cover the losses the contract makes me liable for after a breach of security or confidentiality, including the client's losses?
  3. Does my cover extend to work done by sub-contractors I engage on a financial-sector service?
  4. Is the territory and data-location wording in my policies consistent with where I host this client's data?
  5. What evidence of cover can my insurer issue for the client's due diligence, and how quickly at each renewal?

Related Information

Published 5 May 2026. Source verified 14 September 2026.