This browser is not actively supported anymore. For the best passle experience, we strongly recommend you upgrade your browser.
| 1 minute read

Singapore: MAS cracks down on unauthorized bank data access

The Monetary Authority of Singapore (MAS) has issued Prohibition Orders (POs) against three individuals under the Financial Services and Markets Act 2022 (FSMA) due to their unauthorised access to customer information. This enforcement action demonstrates the MAS’ willingness to issue prohibition orders under its expanded enforcement powers (which came into force in 31 July 2024), and serves as a reminder to firms of the importance of protecting customer information.

Details of charges

Mr Liong, formerly a collections officer at DBS Bank, misused his access to the bank’s Customer Information System to perform unauthorised searches on the bank’s customers. Specifically, he accessed information about customers he encountered online, obtained personal details of friends and relatives, and retrieved information at the request of Mr Muthaliyar (a former colleague) and Mr Ang (a friend).

MAS found that all three individuals no longer met the fit and proper criteria for persons carrying on regulated activities, and so MAS issued each of them with POs (of between three and six years).

MAS’ powers to issue POs

The PO regime under FSMA commenced on 31 July 2024. It allows MAS to prohibit individuals from carrying out regulated activities, taking part in the management of a financial institution or becoming a substantial shareholder of financial institutions. MAS’ powers are wide-ranging, and these enforcement cases demonstrate MAS’ willingness to act firmly in response to any type of misconduct.

Why this matters

This case highlights MAS’ focus on protecting customer information and enforcing high standards of conduct within financial institutions. The outcome serves as a reminder that organisations should:

  • reinforce staff training on the handling of sensitive information;
  • regularly review and update compliance frameworks and controls to prevent unauthorised data access and ensure any unauthorised data access is picked up by second and third levels of defence; and
  • ensure that internal policies and procedures align with MAS’ expectations and regulatory requirements.

Tags

asia, enforcement