Free · No call required

The 18-point checklist for a
Malaysian financial-services
website that earns trust.

Statutory disclosures, PDPA compliance, and the trust signals a corporate client actually looks for before they'll pick up the phone. Go through your own site against it — privately, no login, no form.

18 checks, 4 categories Written for insurance, reinsurance & financial services Takes about 10 minutes
A

Statutory & regulatory disclosure

The baseline facts a Malaysian corporate client checks before they'll take a firm seriously as a counterparty — not marketing, just proof the entity behind the site is real and accountable.

01
SSM registration number displayed
A visible Companies Commission of Malaysia number lets a visitor verify the entity exists independently, in seconds, without asking anyone.
02
Sector licence number shown, if one applies
BNM registration, a Labuan FSA licence, or an SC capital-markets licence — whichever governs the firm — displayed plainly, not left for a visitor to hunt down elsewhere.
03
Full registered address available
Not just a city name in the footer — a real, checkable business address. A firm handling real risk or real money should be locatable.
04
A named Data Protection Officer or PDPA contact
Since the 2024 Amendment, regulated-sector firms must have someone accountable for data protection. If the site can't say who that is, a careful visitor notices the gap.
B

PDPA & data protection

Every one of these has a real legal basis under the Personal Data Protection Act 2010, as amended in 2024 — this isn't a style preference, it's what the law actually asks a site to do.

05
Every data-collecting form has its own notice
Not a link buried in the footer — a plain-language line next to the submit button explaining what's collected and why, right where the decision to submit is being made.
06
Consent is opt-in, never pre-ticked
A pre-ticked consent box is a compliance failure, not a convenience — PDPA's notice-and-choice principle requires a genuine, active choice.
07
A Privacy Policy reflecting the 2024 Amendment
DPO contact, the 72-hour breach-notification duty, the data-portability right, and any cross-border transfer disclosure — the 2010 baseline alone is now out of date.
08
A stated data-retention period
"How long do you keep what I give you" is a real, reasonable question — the answer should already be on the page, not something a visitor has to ask.
09
Analytics and cookies disclosed
If the site runs Google Analytics or any tracking script, the Privacy Policy should say so plainly — silence here reads as either unaware or evasive, neither is a good look.
C

Credibility & trust signals

The part that's judged before a single word of copy is read closely — whether the firm behind the screen looks like it has genuinely thought about what it does, and why that matters to the person looking.

10
Real, named leadership — not an empty team section
A "Board of Directors" or "Our Team" heading with no names under it is worse than not having the section at all — it announces the gap instead of hiding it.
11
Visible evidence the site is actively maintained
A current copyright year, a dated news item, a recent case study — anything that tells a visitor someone is still looking after this, not just the year it launched.
12
Specific claims, not filler language
"Comprehensive solutions across a diverse range of products" tells a risk manager nothing and quietly suggests the firm can't — or won't — talk plainly about its own work.
13
A clear answer to "why this firm, not the other three"
A corporate buyer usually has several tabs open. If the site won't say what's different, the silence answers the question for them — and not in the firm's favour.
14
Verifiable proof, not just adjectives
Years in business, a licence number, a named client reference, a specific heritage detail — proof a careful visitor can actually check, not a paragraph of "trusted" and "leading."
D

Technical trust

Small, quiet things that shape a first impression before anyone reads a sentence — and are usually the easiest of the eighteen to actually fix.

15
Working HTTPS, no browser security warning
A "not secure" warning on a financial-services site undoes every other item on this list in the same second it appears.
16
No broken images or dead links on the homepage
A missing logo, a broken team photo, a link to nowhere — small individually, but each one is a moment a careful visitor notices something wasn't checked.
17
Loads in a few seconds, not longer
A slow first load costs trust before a single word of the pitch is read — patience is not something a corporate visitor extends to a vendor's own website.
18
Renders properly on a phone
A broken mobile layout undercuts everything above it — plenty of the people checking a firm out before a meeting are doing it from their phone, in the taxi on the way there.

Reading your own score

15–18 checked — the site is genuinely in good order. Any gaps left are worth closing on principle, not urgency.
9–14 checked — the fundamentals are there but there are real, specific gaps a careful visitor would notice. Usually fixable without a full rebuild.
Under 9 checked — the site is quietly working against the firm, not for it. Worth a proper look before the next big pitch or renewal season.

Where the rules get sector-specific

The list above is the general standard. Three sets of Malaysian rules go further for particular firms. We've written each one up the same way — quoting the instrument, naming the paragraph, and saying plainly what it does not require.

If a few of these came up short

Send me the site. I'll tell you what I see, for free.

No pitch attached — just an honest read of where your site stands against this list, from someone who's gone through the sector's sites one by one. If it turns into a conversation about fixing it, that's your call, not mine.

Get in touch →