Regulation 1
Citation
These Regulations are the Electronic Transactions (Certification Authority) Regulations 2010.
/akn/sg/act/sub_leg/2010/ETA-RG1
The full official text, structured for quick navigation. Copy any provision or jump straight to a section.
Quick answer
Electronic Transactions (Certification Authority) Regulations 2010 is Singapore Subsidiary Legislation, cited as Subsidiary Legislation ETA-RG1 2010, currently marked in force and first recorded in 2010.
Part 1
Citation
These Regulations are the Electronic Transactions (Certification Authority) Regulations 2010.
Definitions
In these Regulations —“accreditation” means accreditation granted under these Regulations;“accredited certification authority” means a certification authority that is accredited under these Regulations;“accreditation mark” means an accreditation mark as set out in the Schedule;“subscriber identity verification method” means the method used to verify and authenticate the identity of a subscriber;“trusted person” means any person who has —
direct responsibilities for the day‑to‑day operations, security and performance of those business activities that are regulated under the Act or these Regulations in respect of a certification authority; or
duties directly involving the issuance, renewal, suspension, revocation of certificates (including the identification of any person requesting a certificate from an accredited certification authority), creation of private keys or administration of a certification authority’s computing facilities.
“accredited certification authority” means a certification authority that is accredited under these Regulations;
“accreditation mark” means an accreditation mark as set out in the Schedule;
“subscriber identity verification method” means the method used to verify and authenticate the identity of a subscriber;
“trusted person” means any person who has —
direct responsibilities for the day‑to‑day operations, security and performance of those business activities that are regulated under the Act or these Regulations in respect of a certification authority; or
duties directly involving the issuance, renewal, suspension, revocation of certificates (including the identification of any person requesting a certificate from an accredited certification authority), creation of private keys or administration of a certification authority’s computing facilities.
Part 2
Application to be accredited certification authority
Every application to be an accredited certification authority must be made in the form and manner that the Controller may determine and must be supported by —
the certification practice statement of the certification authority;
an audit report prepared in accordance with regulations 23 and 34 for compliance with the Compliance Audit Checklist published on the Controller’s Internet website; and
any information that the Controller may require.
Upon submitting an application for accreditation, the applicant must pay to the Controller an application fee of $1,000.
The Controller must, in the form that the Controller may determine, notify the applicant as to whether the application is successful.
Upon notification that the application is successful, the applicant must pay to the Controller an accreditation fee of $1,000 and, subject to regulation 5, the Controller must grant accreditation to the applicant as an accredited certification authority upon the payment.
The accreditation is subject to any conditions or restrictions that the Controller may determine.
The accreditation is valid for 2 years unless cancelled or suspended under the Act or these Regulations.
The Controller must not refund any fee paid under this regulation if the application is unsuccessful, withdrawn or discontinued, or if the accreditation is cancelled or suspended.
Renewal of accreditation
Regulation 3 (with the exception of paragraph (2)) applies, with the necessary modifications, to an application for renewal of accreditation under this regulation as it applies to an application for accreditation under regulation 3.
The Controller may allow applications for renewal of accreditation to be submitted in the form of electronic records subject to any requirements that the Controller may impose.
If an accredited certification authority intends to renew its accreditation, the certification authority must submit an application for the renewal of its accreditation not later than 3 months before the expiry of its accreditation.
If an application for renewal is made later than the time prescribed in paragraph (3), the application is deemed to be an application under regulation 3 and the application fee prescribed in regulation 3(2) is payable.
If the certification authority does not intend to renew its accreditation, the certification authority must —
inform the Controller in writing not later than 3 months before the expiry of the accreditation;
inform all its subscribers in writing not later than 2 months before the expiry of the accreditation; and
advertise such intention in such daily newspapers and in such manner as the Controller may determine, not later than 2 months before the expiry of the accreditation.
Part 3
Refusal to grant or renew accreditation
The Controller may refuse to grant or renew an accreditation if —
the applicant has not complied with any requirement in the Act or these Regulations;
the applicant has not provided the Controller with any information relating to it or any person employed by or associated with it for the purposes of its business, and to any circumstances likely to affect its method of conducting business, that the Controller may require;
the applicant or its substantial shareholder is in the course of being wound up or liquidated;
a receiver or a receiver and manager has been appointed to the applicant or its substantial shareholder;
the applicant or its substantial shareholder has, whether in Singapore or elsewhere, entered into a compromise or scheme of arrangement with its creditors, being a compromise or scheme of arrangement that is still in operation;
the applicant or its substantial shareholder or any trusted person has been convicted, whether in Singapore or elsewhere, of an offence the conviction for which involved a finding that it, he or she acted fraudulently or dishonestly, or has been convicted of an offence under the Act or these Regulations;
the Controller is not satisfied as to the qualifications or experience of the trusted person who is to perform duties in connection with the accreditation of the applicant;
the applicant fails to satisfy the Controller that it is a fit and proper person to be accredited or that all its trusted persons and substantial shareholders are fit and proper persons;
the Controller has reason to believe that the applicant may not be able to act in the best interest of its subscribers, customers or participants having regard to the reputation, character, financial integrity and reliability of the applicant or any of its substantial shareholders or trusted persons;
the Controller is not satisfied as to the financial standing of the applicant or its substantial shareholder;
the Controller is not satisfied as to the record of past performance or expertise of the applicant or its trusted person having regard to the nature of the business which the applicant may carry on in connection with the accreditation;
there are other circumstances which are likely to lead to the improper conduct of business by, or reflect discredit on the method of conducting the business of, the applicant or its substantial shareholder or any of the trusted persons; or
the Controller is of the opinion that it is in the interest of the public to do so.
In paragraph (1), “substantial shareholder”, in relation to an applicant which is a company, has the meaning given by the Companies Act 1967.
Cancellation or suspension of accreditation
An accreditation is deemed to be cancelled if the certification authority is wound up.
The Controller may cancel or suspend the accreditation of a certification authority —
on any ground on which the Controller may refuse to grant an accreditation under regulation 5;
if any information furnished in support of the application for the accreditation was false, misleading or inaccurate;
if the certification authority fails to undergo or pass an audit required under regulation 34;
if the certification authority fails to comply with a direction of the Controller made under section 23 of the Act;
if the certification authority is being or will be wound up;
if the certification authority has entered into any composition or arrangement with its creditors; (g)if the certification authority fails to carry on business for which it was accredited;
if the Controller has reason to believe that the certification authority or its trusted person has not performed its, his or her duties efficiently, honestly or fairly; or
if the certification authority fails to comply with any condition or restriction applicable in respect of the accreditation.
The Controller may cancel the accreditation of a certification authority at the request of that certification authority.
The Controller must not cancel the accreditation under paragraph (2) without first giving the certification authority an opportunity of being heard.
Inquiry into allegations of misconduct, etc.
The Controller may inquire into any allegation that a certification authority, or an officer or employee of a certification authority, is or has been guilty of any misconduct or is no longer fit to continue to remain accredited by reason of any other circumstances which have led, or are likely to lead, to the improper conduct of business by it or to reflect discredit on the method of conducting business.
If, after inquiring into an allegation under paragraph (1), the Controller is of the opinion that the allegation is proved, the Controller may if he or she thinks fit —
cancel the accreditation of the certification authority;
suspend the accreditation of the certification authority for any period, or until the happening of any event, that the Controller may determine; or
reprimand the certification authority.
The Controller must, at the hearing of an inquiry into an allegation under paragraph (1) against a certification authority, give the certification authority an opportunity of being heard.
Where the Controller is satisfied, after making an inquiry into an allegation under paragraph (1), that the allegation has been made in bad faith or that it is otherwise frivolous or vexatious, the Controller may, by written order, require the person who made the allegation to pay any costs and expenses involved in the inquiry.
The Controller may issue directions to the certification authority for compliance under section 23 of the Act as a result of making the inquiry.
For the purposes of this regulation, “misconduct” means —
any failure to comply with the requirements of the Act or these Regulations or the certification practice statement of the certification authority concerned; and
any act or omission relating to the conduct of business of the certification authority concerned which is or is likely to be prejudicial to public interest.
Effect of cancellation or suspension of accreditation
A certification authority whose accreditation is cancelled or suspended under regulation 6 or 7 is deemed, for the purposes of the Act and these Regulations, not to be accredited from the date that the Controller cancels or suspends the accreditation, as the case may be.
The cancellation or suspension of the accreditation of a certification authority does not operate so as to —
avoid or affect any agreement, transaction or arrangement entered into by the certification authority, whether the agreement, transaction or arrangement was entered into before or after the cancellation or suspension of the accreditation; or
affect any right, obligation or liability arising under any such agreement, transaction or arrangement.
Appeal to Minister
Where the Controller —
refuses to grant or renew an accreditation under regulation 5;
cancels or suspends an accreditation under regulation 6; or
cancels or suspends an accreditation, or reprimands a certification authority, under regulation 7,any person who is aggrieved by the decision of the Controller may, within 14 days after the person is notified of the decision, appeal to the Minister and the decision of the Minister is final.
If an appeal is made against a decision made by the Controller, the Controller may, if he or she thinks fit, defer the execution of the decision until the appeal has been decided by the Minister or the appeal is withdrawn.
In considering whether to defer the execution of the decision, the Controller must have regard to whether the deferment is prejudicial to the interests of any subscriber of the certification authority or any other party who may be adversely affected.
If an appeal is made to the Minister, a copy of the appeal must be lodged with the Controller.
Part 4
Business structure
An applicant for accreditation must be a company operating in Singapore at the time of the application and throughout the period when it is an accredited certification authority.
Personnel
An applicant for accreditation must, at the time of the application and throughout the period when the applicant is an accredited certification authority, take reasonable measures to ensure that every trusted person —
is a fit and proper person to carry out the duties assigned to him or her;
is not an undischarged bankrupt in Singapore or elsewhere, and has not made any composition or arrangement with his or her creditors; and
has not been convicted, whether in Singapore or elsewhere, of —
an offence the conviction for which involved a finding that he or she acted fraudulently or dishonestly; or
an offence under the Act or these Regulations.
Despite paragraph (1)(c), the Controller may allow the applicant or accredited certification authority to have a trusted person who has been convicted of an offence mentioned in that paragraph, if the Controller is satisfied that —
the trusted person is now a fit and proper person to carry out his or her duties; and (b)10 years have elapsed from —
the date of conviction; or
the date of release from imprisonment if he or she was sentenced to a term of imprisonment,whichever is the later.
Every trusted person must —
have a good knowledge of the Act and these Regulations;
be trained in the certification authority’s certification practice statement; and
possess the relevant technical qualifications, expertise and experience to effectively carry out his or her duties.
Certification practice statement
An accredited certification authority must have and comply with a certification practice statement approved by the Controller.
Part 5
Trustworthy record keeping and archival
An accredited certification authority may keep its records in the form of paper documents or electronic records or any other form approved by the Controller.
The records must be indexed, stored, preserved and reproduced so as to be accurate, complete, legible and accessible to the Controller, an auditor or an authorised officer.
Trustworthy transaction logs
Every accredited certification authority must make and keep in a trustworthy manner the records relating to —
activities in issuance, renewal, suspension and revocation of certificates, including the process of identification of any person requesting a certificate from an accredited certification authority;
the process of generating subscribers’ (where applicable) or the accredited certification authority’s own key pairs;
the administration of an accredited certification authority’s computing facilities; and
any critical related activity of an accredited certification authority that may be determined by the Controller.
Every accredited certification authority must archive all certificates issued by it and maintain mechanisms to access the certificates for at least 7 years.
Every accredited certification authority must retain all records required to be kept under paragraph (1) and all logs of the creation of the archive of certificates mentioned in paragraph (2) for at least 7 years.
Types of certificates
Subject to the approval of the Controller, an accredited certification authority may issue certificates of the following different levels of assurance:
certificates which are considered as trustworthy certificates for the purposes of paragraph 3(b)(i) of the Third Schedule to the Act;
certificates which are not considered as trustworthy certificates for the purposes of paragraph 3(b)(i) of the Third Schedule to the Act.
The accredited certification authority must associate a distinct certification practice statement approved by the Controller for each type of certificate issued.
The accredited certification authority must draw the attention of subscribers and relying parties to the effect of using and relying on certificates that are not considered trustworthy certificates for the purposes of paragraph 3(b)(i) of the Third Schedule to the Act.
Issuance of certificates
In addition to the requirements specified in paragraph 14 of the Third Schedule to the Act, every accredited certification authority must comply with the requirements in this regulation in relation to the issuance of certificates.
The certificate must contain or incorporate by reference information that is sufficient to locate or identify one or more repositories in which notification of the suspension or revocation of the certificate will be listed if the certificate is suspended or revoked.
The practices and procedures set forth in the certification practice statement of an accredited certification authority must contain conditions with standards higher than those conditions specified in paragraph 14(2) of the Third Schedule to the Act.
The subscriber identity verification method employed for issuance of certificates must be specified in the certification practice statement and is subject to the approval of the Controller during the application for accreditation.
Where a certificate is issued to a person (called in this regulation the new certificate) on the basis of another valid certificate held by the same person (called in this regulation the originating certificate) and subsequently the originating certificate has been suspended or revoked, the certification authority that issued the new certificate must conduct investigations to determine whether it is necessary to suspend or revoke the new certificate.
The accredited certification authority must provide a reasonable opportunity for the subscriber to verify the contents of the certificate before it is accepted.
If the subscriber accepts the issued certificate, the accredited certification authority must publish a signed copy of the certificate in a repository mentioned in paragraph (2).
Despite paragraph (7), the accredited certification authority may contractually agree with the subscriber not to publish the certificate.
If the subscriber does not accept the certificate, the accredited certification authority must not publish it.
Once the certificate has been issued by the accredited certification authority and accepted by the subscriber, the accredited certification authority must notify the subscriber within a reasonable time of any fact known to the accredited certification authority that significantly affects the validity or reliability of the certificate.
The date and time of all transactions in relation to the issuance of a certificate must be logged and kept in a trustworthy manner.
Renewal of certificates
Regulation 16 applies to the renewal of certificates as it applies to the issuance of certificates.
The subscriber identity verification method must be that specified in the certification practice statement as approved by the Controller.
The date and time of all transactions in relation to the renewal of a certificate must be logged and kept in a trustworthy manner.
Suspension of certificates
This regulation applies only to every accredited certification authority which allows subscribers to request for suspension of certificates.
Every accredited certification authority may provide for immediate revocation instead of suspension if the subscriber has agreed in writing.
Upon receiving a request for suspension of a certificate under paragraph 16 of the Third Schedule to the Act, the accredited certification authority must ensure that the certificate is suspended and notice of the suspension published in the repository in accordance with paragraph 19 of the Third Schedule to the Act.
An accredited certification authority may suspend a certificate that it has issued if the accredited certification authority has reasonable grounds to believe that the certificate is unreliable, regardless of whether the subscriber consents to the suspension; but the accredited certification authority must complete its investigation into the reliability of the certificate and decide within a reasonable time whether to reinstate the certificate or to revoke the certificate in accordance with paragraph 17 or 18 of the Third Schedule to the Act.
It is the responsibility of any person relying on a certificate to check whether a certificate has been suspended.
An accredited certification authority must suspend a certificate after receiving a valid request for suspension (in accordance with paragraph 16 of the Third Schedule to the Act); but if the accredited certification authority considers that revocation is justified in the light of all the evidence available to it, the certificate must be revoked in accordance with paragraph 17 or 18 of the Third Schedule to the Act.
An accredited certification authority must check with the subscriber or his or her authorised agent whether the certificate should be revoked and whether to reinstate the certificate after suspension.
An accredited certification authority must terminate a suspension initiated by request if the accredited certification authority discovers and confirms that the request for suspension was made without authorisation by the subscriber or his or her authorised agent.
If the suspension of a certificate leads to a revocation of the certificate, the requirements for revocation apply.
The date and time of all transactions in relation to the suspension of certificates must be logged and kept in a trustworthy manner.
An accredited certification authority must maintain facilities to receive and act upon requests for suspension at all times of the day and on all days of every year.
Revocation of certificates
In order to confirm the identity of the subscriber or authorised agent making a request for revocation under paragraph 17(a) of the Third Schedule to the Act, the accredited certification authority must use the subscriber identity verification method specified in the certification practice statement for this purpose.
An accredited certification authority must, after receiving a request for revocation, verify the request, revoke the certificate and publish notification of it under paragraph 20 of the Third Schedule to the Act.
An accredited certification authority must maintain facilities to receive and act upon requests for revocation at all times of the day and on all days of every year.
An accredited certification authority must give notice to the subscriber immediately upon the revocation of a certificate.
The date and time of all transactions in relation to the revocation of certificates must be logged and kept in a trustworthy manner.
Expiry date of certificates
A certificate must state the date on which it expires.
Maintenance of certification practice statement
Every accredited certification authority must use the Internet draft of the Internet X.509 Public Key Infrastructure Certificate Policy and Certification Practices Framework, adopted by the Internet Engineering Task Force and reproduced by the Controller on its Internet website, as a guide for the preparation of its certification practice statement.
Any change to the certification practice statement during the term of the accreditation requires the prior approval of the Controller.
Every accredited certification authority must highlight to its subscribers any limitation of their liabilities and, in particular, it must draw the subscribers’ attention to the implication of reliance limits on their certificates.
The subscriber identity verification method for the issuance, renewal, suspension and revocation of a certificate must be specified in the certification practice statement.
A copy of the latest version of the certification practice statement, together with its effective date, must be filed with the Controller and published on the certification authority’s Internet website accessible to members of the public.
After the effective date, the latest version filed with the Controller will be the prevailing version for a particular certificate.
Every accredited certification authority must log all changes to the certification practice statement together with the effective date of each change.
An accredited certification authority must keep in a trustworthy manner a copy of each version of the certification practice statement, together with the date it came into effect and the date it ceased to have effect.
Secure digital signatures
The technical implementation of the requirements in paragraph 3 of the Third Schedule to the Act must be such as to ensure that it is computationally infeasible for any person, other than the person to whom the signature correlates, to have created a digital signature which is verified by reference to the public key listed in that person’s certificate.
The signature on its own should be such as to —
ensure that the name or other unique identifiable notation of the person to whom the signature correlates be incorporated as part of the signature and cannot be replaced or forged; and
readily present such indicia of identity to a person intending to rely on the signature.
The technical implementation should ensure that —
the steps taken towards the creation of the signature must be under the direction of the person to whom the signature correlates; and
no other person can reproduce the sequence of steps to create the signature and thereby create a valid signature without the involvement or the knowledge of the person to whom the signature correlates.
The technical implementation should indicate to a relying party of a signature whether the document or record that the signature purports to sign has been modified in any way and this indication should be revealed in the process of verifying the signature.
Compliance Audit Checklist
Every accredited certification authority must ensure that in the performance of its services it materially satisfies the Compliance Audit Checklist determined by the Controller and published on the Controller’s Internet website.
An auditor, when determining whether a departure from the Compliance Audit Checklist is material, must exercise reasonable professional judgment as to whether a condition that does not strictly comply with the Compliance Audit Checklist is or is not material, taking into consideration the circumstances and the system as a whole.
Without limiting the situations which the auditor may consider to be material, the following incidents of non‑compliance are to be considered to be material:
any non‑compliance relating to the validity of a certificate;
the performance of the functions of a trusted person by a person who is not suitably qualified;
the use by an accredited certification authority of any system other than a trustworthy system.
The Compliance Audit Checklist must be interpreted in a manner that is reasonable in relation to the context in which a system is used and is consistent with law.
Despite an auditor’s assessment of whether a departure from the Compliance Audit Checklist is material, the Controller may make his or her own assessment and reach a conclusion for the purpose of paragraph (1) which is at variance with that of the auditor.
Every accredited certification authority must provide every subscriber with a trustworthy system to generate his or her key pair.
Every accredited certification authority must provide the mechanism to generate and verify digital signatures in a trustworthy manner and the mechanism provided must also indicate the validity of the signature.
If the digital signature is not valid, the mechanism provided should indicate if the invalidity is due to the integrity of the document or the signature and the mechanism provided must also indicate the status of the certificate.
For mechanisms provided by third parties other than the accredited certification authority, the resulting signature is considered secure only if the accredited certification authority endorses the implementation of such mechanisms in conjunction with its certificate.
Every accredited certification authority is responsible for the storage of keys (including the subscriber’s key and the accredited certification authority’s own key) in a trustworthy manner.
The Controller may publish on its Internet website further details of the Compliance Audit Checklist for compliance by every accredited certification authority.
Incident handling
An accredited certification authority must implement an incident management plan that must provide at the least for management of the following incidents: (a)compromise of key;
penetration of certification authority system and network;
unavailability of infrastructure;
fraudulent registration and generation of certificates, certificate suspension and revocation information.
If any incident mentioned in paragraph (1) occurs, it must be reported to the Controller within 24 hours.
Confidentiality
Every accredited certification authority and its authorised agent must keep all subscriber‑specific information confidential.
Paragraph (1) does not apply to —
any disclosure of subscriber‑specific information made —
with the permission of the subscriber;
for the purposes of the administration or enforcement of section 23 or 24 or Part 6 of the Act;
for any prosecution under any written law; or
in compliance with an order of court or the requirement of any written law; or
any subscriber‑specific information which —
is contained in the certificate, or is otherwise provided by the subscriber to the accredited certification authority, for public disclosure; or
relates to the fact that the certificate has been suspended or revoked.
Change in management
An accredited certification authority must notify the Controller within 5 days of any changes in —
the appointment of any person as a member of its board of directors, its chairperson or its chief executive, or their equivalent; or
any persons with a controlling interest in the certification authority.
For the purposes of paragraph (1)(b), a person has a controlling interest in a certification authority if —
that person has an interest in the voting shares of the certification authority and exercises control over the certification authority; or
that person has an interest in the voting shares of the certification authority of an aggregate of at least 30% of the total votes attached to all voting shares in the certification authority, unless that person does not exercise control over the certification authority.
The notification required in relation to paragraph (1)(b) must be in the form that the Controller may require and must include the following information:
the name of the person with a controlling interest;
the percentage of the voting shares in the certification authority acquired by that person.
Part 6
Availability of general purpose repository
A general purpose repository must be available at all times of the day and on all days of every year.
A general purpose repository must ensure that the total aggregate period of any down time in any period of one month does not exceed 0.3% of the period.
Any down time, whether scheduled or unscheduled, must not exceed 30 minutes duration at any one time.
Specific purpose repository
Subject to the approval of the Controller, a repository may be dedicated for a specific purpose for which specific hours of operation may be acceptable.
Part 7
Use of accreditation mark
Any person who, not being an accredited certification authority, uses an accreditation mark or a colourable imitation of an accreditation mark shall be guilty of an offence and shall be liable on conviction to a fine not exceeding $50,000 or to imprisonment for a term not exceeding 12 months or to both.
Part 8
Application to public agencies
For the purposes of paragraph 3(b)(iii) of the Third Schedule to the Act, a public agency that is approved by the Minister under that paragraph to act as a certification authority must comply with the provisions of the following Parts as if it were an accredited certification authority:
Part 3 (with the exception of regulations 5, 6, 8 and 9);
Part 4 (with the exception of regulation 10);
Part 5 (with the exception of regulation 26);
Part 6;
Part 7 (with the exception of regulation 29);
Part 8;
Part 9 (with the exception of regulations 35 and 36).
The provisions mentioned in paragraph (1) apply, with the necessary modifications and any other modifications that the Controller may determine, to a public agency mentioned in that paragraph.
Part 9
Waiver
Any accredited certification authority that wishes to apply for a waiver of any of the requirements specified in these Regulations may apply in writing to the Controller at the time when it submits an application for accreditation.
The application must be supported by reasons for the application and include any supporting documents that the Controller may require.
Disclosure
The accredited certification authority must submit half‑yearly progress and financial reports to the Controller.
The half‑yearly progress reports must include information on —
the number of subscribers;
the number of certificates issued, suspended, revoked, expired and renewed;
system performance including system up and down time and any extraordinary incidents;
changes in the organisational structure of the certification authority; (e)changes since the preceding progress report was submitted or since the application for the accreditation; and
changes in the particulars of any trusted person since the last submission to the Controller, including the name, identification number, residential address, designation, function and date of employment of the trusted person.
The accredited certification authority has a continuing obligation to disclose to the Controller any changes in the information submitted.
All current versions of the accredited certification authority’s applicable certification practice statements together with their effective dates must be published in the accredited certification authority’s Internet website.
Discontinuation of operations of accredited certification authority
If an accredited certification authority intends to discontinue its operations, the accredited certification authority may arrange for its subscribers to re‑subscribe to another accredited certification authority.
The accredited certification authority must make arrangements for its records and certificates to be archived in a trustworthy manner.
If the records are transferred to another accredited certification authority, the transfer must be done in a trustworthy manner.
An accredited certification authority must —
give to the Controller written notice of its intention to discontinue its operations not later than 3 months before the discontinuation;
give to its subscribers written notice of its intention to discontinue its operations not later than 2 months before the discontinuation; and
advertise, in such daily newspapers and in such manner as the Controller may determine, its intention to discontinue its operations not later than 2 months before the discontinuation.
Audit
The Controller may, by written notice, require an accredited certification authority to undergo and pass an audit.
The audit mentioned in paragraph (1) must be —
conducted in accordance with the auditing requirements specified in this regulation; and
completed within the time that the Controller may, by written notice, specify.
The audit must be conducted by a qualified independent audit team approved by the Controller for this purpose comprising a person who is a Certified Public Accountant and a person who is a Certified Information Systems Auditor and either of whom must possess sufficient knowledge of digital signatures and certificates.
The firm or company to which the audit team belongs must be independent of the certification authority being audited and must not be a software or hardware vendor that is providing or has provided services or is supplying or has supplied equipment to the certification authority.
Auditing fees must be borne by the certification authority.
A copy of the audit report must be submitted to the Controller within 4 weeks of the completion of an audit.
Penalties
Any person who, without any reasonable excuse, fails to comply with regulation 13(2), 14, 16(2) or (11), 17(3), 18(10), 19(5), 21(7) or (8) or 25(1) shall be guilty of an offence and shall be liable on conviction to a fine not exceeding $5,000 and, in the case of a second or subsequent conviction, to a fine not exceeding $10,000.
Composition of offences
Any offence under section 23(2) of the Act or under these Regulations may be compounded by the Controller under section 36 of the Act.