
If your organisation handles personal data or sits under Bank Negara Malaysia’s supervision, recent regulatory changes have significantly reshaped your compliance obligations. The amended Personal Data Protection Act (PDPA), and Bank Negara Malaysia’s revised Risk Management in Technology (RMiT) policy require organisations to demonstrates that data protection and technology risk are being actively managed.
For IT, risk, and compliance professionals, the raises a practical question. Which skills and certification match what these frameworks now demand?
| What Changed Under the Amended PDPA
Malaysia’s Personal Data Protection (Amendment) Act 2024 came into force in stages during 2025, introducing several significant changes to Malaysia’s personal data protection framework.
One of the key changes the requirement to appoint a Data Protection Officer (DPO). From 1 June 2025, organisations meeting the applicable criteria are required to appoint a DPO to oversee and support compliance with the PDPA.
A few details matter here for anyone considering the DPO role, or hiring for it:
Penalties have also increased. The maximum penalty for contravening the PDPA’s Data Protection Principles has increased to RM1 Million and imprisonment for up to three years. the amended framework also introduced mandatory data breach notification requirements, strengthening organisations’ responsibilities when personal data breaches occur.
| What Changed Under BNM’s Revised RMiT
If PDPA governs how personal data is handled, RMiT addresses how financial institutions manage technology and cyber risk more broadly.
Bank Negara Malaysia issued a revised Risk Management in Technology policy on 28 November 2025 strengthening requirements around technology and cyber risk management, operational resilience, digital service security and the secure adoption of new or advanced technologies.
Some of the more consequential changes worth knowing:
Even organisations outside BNM’s direct supervision are affected indirectly. The broader regulatory direction, spanning PDPA, RMiT, and national AI governance guidelines, is pushing the entire market toward the same standard of accountable, well-documented AI and data governance, whether or not a company is a licensed financial institution.
| Why This Creates Real Demand for Specific ISACA Skills
Compliance teams now need a specific combination of skills that most generalist IT roles were never built to cover. Understanding data flows and privacy by design. Assessing and documenting technology risk in a format regulator accept. Governing AI systems with the same rigour as any other critical technology.
This is where several ISACA certifications align with the capabilities organisations may need to support PDPA and RMiT compliance.
| Building a Compliance Ready Team, Not Just a Compliant Policy
A written policy satisfies an auditor for about as long as it takes them to ask who actually implements it. Both frameworks are increasing the importance of clearly, defined accountability, documented responsibilities and demonstrable capabilities.
Practical starting points for organisations working through this now:
Malaysia’s regulators have made their expectations increasingly specific over the past 18 months, from board level accountability to documented AI risk assessments. Meeting them with a generic compliance checklist is no longer realistic. Building teams with relevant privacy, risk, governance, security and AI capabilities can help organisations respond more effectively to these evolving requirements.




















