Why now
The obligations already exist.
If you are building or operating data centres in Singapore, Malaysia, or anywhere serving regulated customers in this region, these frameworks already apply to you:
ABS OSPAR
Annual, and it is your budget
Control Objective II(b) requires that data centre and controlled areas are physically secured against internal and external threats. It names a Threat and Vulnerability Risk Assessment explicitly. It binds the service provider, not the bank — on an annual cycle.
MAS TRM
Your customers must assess you
Singapore financial institutions must conduct a TVRA on the data centres they use, covering physical and environmental threats and the political and economic climate. Your regulated customers will run this assessment whether you commission it or they do.
BNM RMiT
Malaysia, every three years, and it must be external
Malaysian financial institutions must appoint an external service provider for data centre resilience assessment at least every three years. It cannot be done in-house.
Cybersecurity Act & Code of Practice
OT on a statutory clock
Critical information infrastructure owners face operational technology penetration testing on a twenty-four month cadence. An updated code of practice lands H2 2026, and vendor obligations are addressed in it.
Digital Infrastructure Bill
The one to prepare for now
Public consultation closed July 2026. Licensing is proposed at three megawatts of critical IT load. Physical security is named explicitly, with incident notification extended to non-cyber disruptions.
If any of this is on your roadmap and you do not yet know how you would evidence it, that is the conversation to have.