Proposed: technology cybersecurity
Is this legally binding?
Consultation. Proposed, not final. Read it, plan for it, and do not treat it as settled.
Proposed and not final. Nothing here can be enforced against you yet.
PROPOSED expectation (Guidelines para 4.16): secured deployment environments, tight access control, and controls over third-party components; MAS technology risk management requirements and guidance apply. Not final - at consultation stage.
From the source
“An FI should ensure that the AI system is secure, well-governed, and supported by appropriate controls to manage technology and cybersecurity risks.”
Consultation Paper P017-2025 / proposed Guidelines (see summary for paragraph)
What this connects to
2 relations. Official relations are the ones the source documents state; anything marked GAGE analysis is our reading, not an agency's.
Cites2
- SectionProposed Guidelines Section 4: key AI life cycle controlsConsultation
Proposed expectation within this section of the draft Guidelines
- InstrumentConsultation Paper on Proposed Guidelines on Artificial Intelligence Risk Management for Financial Institutions (P017-2025)Consultation
Proposed expectation in P017-2025 (not final)
Verified against the official source on 2026-08-17. GAGE is not affiliated with or endorsed by any agency named here, and nothing on this page is legal advice. How this is built and checked.