If your organisation handles personal data or sits under Bank Negara Malaysia’s supervision, recent regulatory changes have significantly reshaped your compliance obligations. The amended Personal Data Protection Act (PDPA), and Bank Negara Malaysia’s revised Risk Management in Technology (RMiT) policy require organisations to demonstrates that data protection and technology risk are being actively managed.

For IT, risk, and compliance professionals, the raises a practical question. Which skills and certification match what these frameworks now demand?

| What Changed Under the Amended PDPA

Malaysia’s Personal Data Protection (Amendment) Act 2024 came into force in stages during 2025, introducing several significant changes to Malaysia’s personal data protection framework.

One of the key changes the requirement to appoint a Data Protection Officer (DPO). From 1 June 2025, organisations meeting the applicable criteria are required to appoint a DPO to oversee and support compliance with the PDPA.

A few details matter here for anyone considering the DPO role, or hiring for it:

The requirement applies to organisations processing data of over 20,000 individuals, sensitive or financial data of over 10,000 individuals, or conducting regular and systematic monitoring.

Source

The appointed DPO must be physically present in Malaysia for at least 180 days a year, or easily contactable by local authorities, and proficient in both Bahasa Malaysia and English.

Source

Organisations must notify the Commissioner within 21 days of appointing a DPO, using the official registration portal.

Source

Penalties have also increased. The maximum penalty for contravening the PDPA’s Data Protection Principles has increased to RM1 Million and imprisonment for up to three years. the amended framework also introduced mandatory data breach notification requirements, strengthening organisations’ responsibilities when personal data breaches occur.

| What Changed Under BNM’s Revised RMiT

If PDPA governs how personal data is handled, RMiT addresses how financial institutions manage technology and cyber risk more broadly.

Bank Negara Malaysia issued a revised Risk Management in Technology policy on 28 November 2025 strengthening requirements around technology and cyber risk management, operational resilience, digital service security and the secure adoption of new or advanced technologies.

Some of the more consequential changes worth knowing:

Institutions were given 90 days from the issuance date to submit a gap analysis and action plan to BNM, a tight runway for anyone still building out their compliance documentation.

Source

The revised RMiT strengthens emerging technology requirements through risk assessments, governance and oversight, and regular monitoring in production.

Source

RMiT also introduces time-bound resilience requirements for key digital services, including early-warning mechanisms and stand-in processing arrangements to be implemented by 30 September 2027.

Source

Even organisations outside BNM’s direct supervision are affected indirectly. The broader regulatory direction, spanning PDPA, RMiT, and national AI governance guidelines, is pushing the entire market toward the same standard of accountable, well-documented AI and data governance, whether or not a company is a licensed financial institution.

| Why This Creates Real Demand for Specific ISACA Skills

Compliance teams now need a specific combination of skills that most generalist IT roles were never built to cover. Understanding data flows and privacy by design. Assessing and documenting technology risk in a format regulator accept. Governing AI systems with the same rigour as any other critical technology.

This is where several ISACA certifications align with the capabilities organisations may need to support PDPA and RMiT compliance.

CDPSE (Certified Data Privacy Solutions Engineer) is the most direct fit for the technical side of PDPA compliance, since it validates the ability to build privacy governance and data lifecycle practices directly into systems, rather than bolting them on afterward.

CRISC (Certified in Risk and Information Systems Control) aligns closely with RMiT’s risk assessment and documentation demands, particularly the new gap analysis and ongoing monitoring obligations for emerging technology.

CGEIT (Certified in the Governance of Enterprise IT) is relevant for leaders responsible for board-level technology governance and oversight, areas where RMiT places explicit responsibilities.

AAIA, AAISM, and AAIR, ISACA’s advanced certifications for experienced professionals in AI audit, security management, and risk, increasingly relevant as Malaysia strengthens guidance on AI governance and responsible use.

CISM (Certified Information Security Manager) remains a strong option for professionals overseeing the security programme that both frameworks assume is already in place.

| Building a Compliance Ready Team, Not Just a Compliant Policy

A written policy satisfies an auditor for about as long as it takes them to ask who actually implements it. Both frameworks are increasing the importance of clearly, defined accountability, documented responsibilities and demonstrable capabilities.

Practical starting points for organisations working through this now:

Map current DPO or risk owner responsibilities against the ISACA certifications above, rather than assuming one generalist qualification covers everything.

For teams focused on privacy engineering or technology risk, CDPSE and CRISC are logical starting points because their domains align closely with these areas.

The revised RMiT strengthens emerging technology requirements through risk assessments, governance and oversight, and regular monitoring in production.

Malaysia’s regulators have made their expectations increasingly specific over the past 18 months, from board level accountability to documented AI risk assessments. Meeting them with a generic compliance checklist is no longer realistic. Building teams with relevant privacy, risk, governance, security and AI capabilities can help organisations respond more effectively to these evolving requirements.

| A Quick Way to Think About Timing

Not every certification needs to be tackled at once, and trying to do so usually stalls progress rather than speeding it up. A more workable approach is to sequence certifications against your organisation’s actual regulatory calendar.

DPO appointment

CDPSE

For organizations appointing their first DPO, CDPSE provides relevant skills in areas such as data lifecycle management and privacy by design.

Post gap analysis

CRISC and CGEIT

For financial institutions already past the 90-day RMiT gap analysis deadline, CRISC and CGEIT become more urgent, since ongoing monitoring and board reporting are now continuous obligations rather than one-time submissions.

Prepare Ahead

Malaysia’s regulatory landscape continues to evolve as organisations adopt AI and other emerging technologies. For financial institutions, the revised RMiT places greater emphasis on the governance, risk assessment, and ongoing monitoring of emerging technologies.

Building AI governance capabilities through relevant pathways such as AAIA, AAISM, or AAIR can help experienced professionals strengthen their expertise in AI audit, security management, and risk.

The Bigger Picture

Compliance in Malaysia’s current regulatory environment is no longer a once-a-year exercise handled by legal alone. It is an ongoing, cross functional responsibility that increasingly depends on the specific expertise a certification is designed to prove.

Choosing the right one, and choosing it early, is turning out to be one of the more practical decisions a compliance or IT risk professional can make this year.

| A Quick Way to Think About Timing

With DPO appointments and RMiT gap analyses now carrying legal weight, waiting until the next audit to build these skills is a risk few organisations can afford. Trainocate Malaysia’s ISACA certification pathways cover the credentials discussed in this article, including CDPSE for privacy engineering, CRISC for IT risk, CGEIT for enterprise IT governance, and AAIA, AAISM, and AAIR for advanced AI audit, security management, and risk capabilities.

Explore the full learning paths and find the certification that matches your organisation’s compliance calendar.