Bank Negara RMiT Extends Binding Tech-Risk Rules To AI | TLY

AI Regulation Tracker  /  Financial services

Bank Negara Malaysia Brings AI Deployments Inside Binding Technology-Risk Rules

The revised Risk Management in Technology policy took effect on November 28, 2025. It sharpens board accountability and governance of emerging technology, including AI and machine learning, and puts every regulated AI deployment inside the same binding cyber, cloud, and control regime Bank Negara enforces on licensed financial institutions.

The Leveraged Years AI Regulation News

Malaysia did not write a standalone AI statute for its banks. It did something quieter that reaches just as far. On November 28, 2025, Bank Negara Malaysia brought a revised Risk Management in Technology policy into effect, and that policy is where every regulated AI deployment in a Malaysian financial institution now has to live. RMiT has been the central bank's technology-risk rulebook for years. The revision sharpens it and makes clear that emerging technology, artificial intelligence included, is governed inside the same binding framework as everything else a licensed institution runs.

This is the distinction that matters for anyone reading regulatory headlines. A consultation asks for views. A policy document tells you what to do. RMiT is the second kind. It is issued to institutions licensed by Bank Negara, and they have to comply. So when the revised RMiT tightens the governance of emerging technology and lifts the expectations on cloud, cybersecurity, cryptographic controls, and resilience, those are obligations with supervisory teeth behind them, not suggestions a firm can weigh and set aside.

How does RMiT treat AI and machine learning?

RMiT does not carve AI out as a special category with its own separate rulebook. It folds AI and machine learning into its emerging-technology governance, which is arguably the more demanding approach. An institution deploying a new technology, including an AI or machine-learning system, is expected to run a structured risk assessment, put adequate controls in place, and monitor the system on an ongoing basis both before and during production use. That means an AI model that touches a regulated function cannot be spun up outside the technology-risk process. It has to be assessed, controlled, and watched like any other piece of critical technology, with the added attention that comes from models whose behavior can drift as they learn from live data.

The revision also raises the surrounding controls that AI systems depend on. Enhanced cloud governance matters because most serious AI runs on cloud infrastructure. Stronger cybersecurity and cryptographic requirements matter because an AI pipeline is only as safe as the data and access controls around it. Bank Negara's structure here treats the model and its environment as one risk surface rather than pretending the clever part can be governed separately from the plumbing.

Who stays accountable when a vendor is involved?

The institution does. RMiT operates on a shared-responsibility model with cloud and technology service providers, but shared responsibility is not transferred responsibility. A licensed financial institution that buys an AI capability from a third party remains accountable to Bank Negara for how that capability is governed, controlled, and monitored. This is the point US vendors and their clients most often get wrong. Selling or buying a model does not move the regulatory duty to the vendor. The regulated firm has to be able to show the central bank that it understands the system, controls it, and can answer for its behavior, whoever built it.

Why a US professional should track this

Two audiences should care. First, US financial groups with Malaysian licensed subsidiaries. Their Malaysian entities are inside RMiT, which means their AI and machine-learning projects there are already subject to structured risk assessment, control, and monitoring duties, and were expected to file a gap analysis and action plan with Bank Negara within 90 days of the November 28, 2025 effective date. Second, US technology and AI vendors selling into Malaysian financial institutions. You are now part of a shared-responsibility perimeter that a prudential regulator supervises, and your clients will push RMiT-shaped control, documentation, and audit expectations onto you through their contracts. For CPAs and finance leaders more broadly, RMiT is a clean example of a pattern worth internalizing. Regulators increasingly govern AI not through AI-specific laws but by extending existing technology-risk and operational-resilience rules to cover it, and those extensions are binding from day one.

Questions professionals are asking

Is RMiT binding or just guidance?

Binding. RMiT is a policy document that financial institutions licensed by Bank Negara Malaysia must comply with. It is not a consultation or a voluntary framework. Non-compliance is a supervisory and enforcement matter, which is why the AI and emerging-technology obligations in the November 28, 2025 revision carry real weight for regulated firms.

Does RMiT have a separate AI rulebook?

No. RMiT folds AI and machine learning into its governance of emerging technology rather than creating a separate AI code. An institution deploying an AI or machine-learning system must run a structured risk assessment, apply adequate controls, and monitor the system before and during production use, inside the same technology-risk framework that covers its other critical systems.

Who is accountable when a cloud or AI vendor is used?

The regulated institution. RMiT uses a shared-responsibility model with service providers, but responsibility is shared, not transferred. A licensed financial institution remains accountable to Bank Negara for governing, controlling, and monitoring an AI capability even when a third party built or hosts it, and must be able to demonstrate that control on request.

What did institutions have to do after November 28, 2025?

Institutions were required to submit a gap analysis and action plan to Bank Negara within 90 days of the November 28, 2025 issuance, alongside meeting the enhanced cloud, cybersecurity, cryptographic, and emerging-technology requirements. US groups with Malaysian licensed subsidiaries should confirm their entities completed that step.

RELATED BRIEFINGS

Browse the full AI Regulation News tracker

Informational analysis for working professionals, not legal advice. Confirm how RMiT applies to your institution with qualified Malaysian financial-services counsel.