RMiT does not require in-country hosting. What it does require, for any critical system on public cloud, is a set of documents and controls that a Region change leaves exactly where they were.
On 20 January 2026 BNM imposed a RM1 million administrative monetary penalty on Bank Kerjasama Rakyat Malaysia Berhad, after an external threat actor gained unauthorised access to its IT infrastructure. The failures cited were cybersecurity controls and incident response under the RMiT and MCIPD policy documents. Data location was not among them. BNM has not published a technical root cause, so none is assumed here.
Same workload, two different questions. The second one is what gets examined.
Location of cloud infrastructure appears in paragraph 10.50(c) as a risk to assess, alongside geo-political and legal risk. Offshore hosting is treated as a jurisdiction risk to manage, not a prohibition. Region-locking may be a sound choice for your own risk position. It is not the regulator's demand.
Each produces a dated document. In practice these get asked for before anything about the architecture does.
Required before your first public cloud adoption of a critical system. Skip it and every later workload stays on the consultation route instead of the faster notification route under 17.2.
If you depart from any Appendix 10 measure, you must be able to show BNM your alternative is at least as effective. Write that comparison now, not when it is asked for.
Your gap analysis and action plan against this revision were due to BNM within 90 days of 28 November 2025. The action plan then has to show movement against its own milestones.
RMiT does not use the term Tier-1. Its term is critical system, defined at paragraph 5.2. If your internal tiering does not map to that definition, fix the mapping first.
Key storage and crypto computation must sit in an HSM, a TEE, or similarly secured devices, commensurate with risk. Separately, you must retain ownership, control and management of cloud-hosted data including key management.
Activity in critical systems must be logged, retained at least three years, and reviewed regularly. Anomalies must be flagged for prompt investigation.
For critical systems with a reasonable expectation of immediate service: cumulative unplanned downtime on the customer or counterparty interface of not more than 4 hours on a rolling 12 months, and a maximum tolerable downtime of 120 minutes per incident.
Runs in your browser. Nothing is recorded or sent. Answer for the evidence that exists today, not what is on the roadmap.
Was BNM consulted before your first public cloud adoption of a critical system, with Appendix 7 Parts A, B and C complete?
Do you hold a current written mapping with a justification for every measure you have departed from?
Was the gap analysis against the 28 November 2025 revision submitted, and is the action plan tracked to milestones?
Can you show on paper who holds and manages the keys protecting critical-system data, and how control is retained?
Retained three years, and the engineering identities recorded cannot alter or delete them?
Can the incident register produce 120 minutes per incident and 4 hours cumulative on a rolling 12 months?
For each one, BNM asks for a document rather than an explanation. Answer all six to see where yours are missing.
Bank Negara Malaysia, issued 28 November 2025. Ref BNM/RH/PD 028-98. Cited: 5.2, 10.7, 10.20, 10.21, 10.22, 10.32, 10.50, 10.51, 10.52, 10.57, 11.18, 17.1, 17.2, 17.5, 18.1, Appendix 7, Appendix 10.
Open the policy document →Bank Negara Malaysia, issued 31 October 2025, superseding the 3 April 2023 document. Cited here only for customer information handling and permitted disclosure.
RM1 million administrative monetary penalty imposed 20 January 2026 under the RMiT and MCIPD policy documents. Settled 26 January 2026. No technical root cause published.
The November 2025 revision renumbered parts of section 10. Cryptography and HSM moved from 10.19 to 10.22. Cloud data control moved from 10.53 to 10.52. A document citing 10.19 for cryptography is citing the superseded edition.