Search Ocorian

young asian professional business woman using laptop in outdoor coffee shop or sidewalk cafe

Singapore business continuity management: is your three-year audit due?

03 September, 2026

Financial institutions should audit their overall business continuity management (BCM) framework and business continuity plans for critical business services at least every three years. For firms that completed their first audit by the June 2024 implementation deadline, the next audit cycle is approaching and should be planned now.

The Monetary Authority of Singapore (MAS) issued its revised business continuity management (BCM) guidelines in June 2022. Financial institutions were expected to establish a BCM audit plan within 12 months of issuance and complete their first BCM audit within 24 months. The recurring audit obligation is as important: the overall BCM framework and the business continuity plans for critical business services should be audited at least once every three years.
 

The three-year BCM audit cycle

The three-year requirement is a minimum frequency, not a sector-wide calendar deadline. Each institution should check the completion date and scope of its previous audit and schedule the next review so that no more than three years elapse between audits. For those who completed the audit ahead of the regulatory deadline, the next BCM audit will be due soon.

An earlier audit may be appropriate where there have been material changes to the business, critical services, operating model, technology environment or third-party arrangements. Firms should also consider whether significant incidents, repeated test failures or overdue remediation warrant independent review before the end of the normal cycle.
 

What should the BCM audit cover?

The audit should provide independent assurance over both the design and effectiveness of the BCM framework. Its scope should be commensurate with the nature, size, risk profile and complexity of the institution, while giving appropriate attention to each critical business service.
 

Independence and competence matter

The audit should be undertaken by a qualified party that is independent of the activities being reviewed and has appropriate BCM knowledge. Depending on the institution’s governance and resources, this may be an internal auditor, an external auditor, or another suitably qualified independent function. The chosen reviewer should be free from responsibility for designing or operating the controls within scope.
 

Preparing now for your next BCM audit

Firms approaching the end of their first three-year cycle should avoid treating audit preparation as a document-gathering exercise. The strongest evidence will show that BCM is embedded, regularly tested and improved over time. Key actions include:

  • Confirm the date, scope and coverage of the last independent BCM audit;

  • Update the audit plan and secure an appropriately independent and experienced reviewer;

  • Revalidate the inventory of critical business services, functions and accountable owners;

  • Confirm that dependency maps reflect current systems, third parties, locations and key personnel;

  • Review recent exercises and incidents for evidence that service recovery time objectives can be achieved;

  • Close, or formally risk-accept and escalate, outstanding findings from audits and tests; and

  • Allow sufficient time for management responses, remediation planning and reporting to the board or relevant governing body.


Board and senior management oversight

Responsibility for effective BCM remains with the board and senior management. Audit results, material weaknesses and remediation progress should be visible to the appropriate governing body and supported by clear ownership and target dates.

A timely audit provides more than regulatory assurance. It can identify concentration risk, outdated assumptions and operational dependencies before they become points of failure during a disruption.

How Ocorian can help

Building on the extensive support we have provided to our clients since the update of the BCM guidelines, Ocorian is well suited to help you prepare for your next  BCM audit cycle or conduct your BCM audit.

To find out how we can support your organisation, please contact us.

About the authors

Ching Soon Yeoh is a principal consultant at Ocorian with over 20 years of experience in the asset management industry supporting asset managers and financial services firms. He specialises in regulatory compliance, governance, AML/CFT and operational risk management, helping clients navigate Singapore’s complex regulatory requirements.

Billie Jo Dixon is the practice lead for Ocorian’s regulatory & compliance team in Singapore. She has over twenty years’ experience in financial services and is a respected expert in regulatory compliance. She helps firms decide if they need to be licensed in Singapore and guides them through the MAS licensing process and all aspects of being a licensed business.