Tuesday, August 11, 2026
21.8 C
Los Angeles

İstanbul Court Jails Üsküdar Mayor Sinem Dedetaş in Expanding Corruption Probe

An İstanbul court has ordered the pretrial...

Former TV Star-Turned-Mayor Detained as Turkey Intensifies Crackdown on Opposition

Turkish authorities have detained Erdal Besikcioglu, the...

California Man Sentenced in Connection With Cross-Country Money Laundering Conspiracy

Baltimore, Maryland – A federal judge sentenced a...

Singapore Tightens AML/CFT Expectations for Digital Payment Token Service Providers

Due DiligenceSingapore Tightens AML/CFT Expectations for Digital Payment Token Service Providers

Singapore’s monetary and financial regulator has set out detailed supervisory expectations for digital payment token service providers (DPTSPs), signalling a continued push toward stronger anti-money laundering and countering the financing of terrorism controls across the country’s rapidly evolving digital asset sector.

The Monetary Authority of Singapore (MAS) has issued an information paper outlining how DPTSPs are expected to implement their anti-money laundering, countering the financing of terrorism and countering proliferation financing (AML/CFT/CPF) frameworks in key areas.

The paper does not replace existing regulatory requirements. Instead, it supplements the existing AML/CFT/CPF regime and is intended to provide greater clarity on the standards MAS expects regulated digital payment token businesses to meet.

The expectations are to be read alongside MAS Notice PS-N02, which sets out AML/CFT requirements applicable to digital payment token service providers, as well as the accompanying guidelines.

The move comes as regulators globally continue to strengthen oversight of virtual assets, recognising that digital payment token businesses can face significant financial crime risks because of the speed, cross-border nature and complexity of digital asset transactions.

From compliance requirements to supervisory expectations

For digital asset businesses, the distinction between regulatory requirements and supervisory expectations is important.

While MAS’s existing notices establish mandatory obligations, the new information paper provides greater insight into how the regulator assesses the effectiveness of the controls implemented by DPTSPs.

That means firms are not expected merely to have AML/CFT policies documented on paper. Their systems and processes must be capable of identifying, assessing and managing financial crime risks in practice.

This reflects a broader shift in financial crime compliance, where regulators are increasingly examining whether firms’ controls are genuinely effective rather than simply whether the required policies and procedures exist.

For DPTSPs, this places greater emphasis on the quality of risk assessments, customer due diligence, transaction monitoring, screening, escalation procedures and governance surrounding financial crime controls.

Digital assets present a distinct risk environment

Digital payment tokens operate in an environment that differs significantly from traditional financial products.

Transactions can move across jurisdictions rapidly, counterparties can be difficult to identify, and the underlying ownership or control of digital assets may not always be immediately apparent.

The use of blockchain technology can provide transparency into transactions, but transaction visibility does not necessarily translate into visibility of the individuals or entities behind those transactions.

This creates challenges for firms attempting to establish who their customers are, understand the source and destination of funds, identify beneficial ownership and determine whether transactions are consistent with a customer’s expected activity.

DPTSPs therefore need to take a risk-based approach that accounts for the specific characteristics of their businesses, customers, products, delivery channels and geographic exposure.

Customer due diligence remains at the centre

One of the most important pillars of an effective AML/CFT framework is customer due diligence.

For DPTSPs, customer identification cannot be treated as a one-time onboarding exercise. As customer relationships evolve, firms need mechanisms to ensure that information remains accurate and that changes in customer behaviour or risk are identified.

This becomes particularly important where customers have complex ownership structures, operate across multiple jurisdictions or engage in higher-risk activities.

An effective compliance programme should enable firms to develop a meaningful understanding of their customers rather than relying solely on basic identification information.

For higher-risk customers, enhanced due diligence becomes critical.

This can involve obtaining additional information about the customer’s business and activities, understanding the source of funds and source of wealth where appropriate, establishing the rationale for transactions and applying enhanced monitoring.

The objective is to ensure that the level of scrutiny applied is proportionate to the risks identified.

Risk assessment must reflect the realities of the business

MAS’s supervisory approach also reinforces the importance of risk-based AML/CFT frameworks.

A DPTSP’s risk assessment should reflect the nature and scale of its business rather than functioning as a generic compliance document.

The risk profile of a firm can be influenced by multiple factors, including the types of digital payment token services it provides, the jurisdictions in which it operates, customer profiles, transaction patterns, delivery channels and exposure to higher-risk counterparties.

A risk assessment that fails to account for these factors may give a misleading picture of the firm’s actual exposure.

As a result, firms need to periodically reassess their risks and ensure that their controls evolve as their business changes.

This is particularly relevant to digital asset businesses, where products, technologies and transaction models can develop considerably faster than traditional financial services.

Screening and ongoing monitoring gain greater importance

Effective financial crime controls also depend on the ability to identify customers and transactions associated with sanctions, politically exposed persons, adverse information and other relevant risk indicators.

For DPTSPs, screening needs to be supported by appropriate processes for resolving potential matches and determining whether a customer or transaction presents a genuine risk.

Poor-quality screening can create two problems.

An overly broad approach may generate large numbers of false positives, overwhelming compliance teams and making it difficult to identify genuine risks. An overly narrow approach, meanwhile, can result in potentially significant risks being missed.

The challenge is therefore not simply to screen more names or transactions, but to establish controls capable of producing reliable and actionable results.

Transaction monitoring is similarly important.

Digital asset firms need to understand what constitutes unusual or potentially suspicious behaviour within the context of their specific business models. Monitoring systems that rely exclusively on generic thresholds may struggle to detect sophisticated or evolving typologies.

Technology does not eliminate the need for human oversight

The digital nature of DPT services makes technology an important component of AML/CFT compliance.

Automated screening, transaction monitoring, blockchain analytics, customer risk scoring and data analytics can allow firms to process large volumes of information and identify potentially suspicious activity more efficiently.

However, technology alone does not constitute an effective AML/CFT programme.

Alerts still need to be investigated. Potential matches need to be assessed. Risk decisions need to be documented. Escalations need to reach the appropriate personnel.

This places considerable importance on the quality of the data being used by compliance systems and on the ability of investigators to connect information from multiple sources.

For firms operating across jurisdictions, this can be particularly challenging because relevant information may be fragmented across corporate records, regulatory databases, sanctions lists, court records, media reports and other public and proprietary sources.

Governance and accountability are critical

The effectiveness of an AML/CFT framework ultimately depends on governance.

Senior management and the board have an important role in ensuring that financial crime risks receive appropriate attention and that compliance functions have adequate resources, authority and independence.

For DPTSPs, this means AML/CFT cannot be treated exclusively as an operational responsibility delegated to a compliance team.

The firm’s overall governance structure should support effective oversight of financial crime risks and ensure that significant issues are escalated appropriately.

The quality of internal controls, policies, procedures, training, testing and independent review also becomes important in demonstrating whether the framework works as intended.

A more demanding compliance environment for digital assets

MAS’s information paper is part of a wider regulatory trend in which digital asset businesses are increasingly being brought within established financial crime control frameworks.

The regulatory direction is clear: operating in the digital asset sector does not reduce the need for robust AML/CFT controls.

If anything, the characteristics of digital assets can require firms to develop more sophisticated approaches to customer and transaction risk.

For DPTSPs, this means compliance programmes will increasingly need to combine traditional financial crime controls with technology capable of addressing the unique characteristics of digital asset activity.

The challenge will be to build systems that are not only capable of identifying risks but also explainable, auditable and responsive to changing financial crime typologies.

Implications for DPT service providers

For digital payment token service providers operating in Singapore, MAS’s supervisory expectations provide an important signal about the direction of regulatory scrutiny.

Firms should expect greater attention to the effectiveness of their AML/CFT/CPF frameworks and should be able to demonstrate how their controls operate in practice.

That includes having a clear understanding of their customer and business risks, maintaining appropriate customer information, applying enhanced measures where risks warrant them, monitoring transactions effectively, conducting appropriate screening and ensuring that suspicious activity can be identified and escalated.

Equally important is the ability to demonstrate why particular compliance decisions were made.

As regulators become increasingly focused on effectiveness, auditability and outcomes, maintaining a policy document alone is unlikely to be sufficient.

The broader message

Singapore has positioned itself as a major financial and technology hub while taking a cautious approach to the risks associated with digital assets.

The latest supervisory expectations reinforce that approach.

For DPTSPs, the message is straightforward: innovation in financial services must be accompanied by strong safeguards against financial crime.

As digital asset markets become more interconnected with the broader financial system, regulators are likely to place increasing emphasis on whether firms can identify bad actors, understand the provenance and movement of funds, detect suspicious activity and respond appropriately when risks emerge.

For compliance teams, this represents a shift from viewing AML/CFT as a collection of regulatory obligations toward treating financial crime risk management as a continuous, data-driven and operational discipline.

For digital asset businesses seeking to operate sustainably in regulated markets, that distinction could become increasingly important.

By FCCT Editorial Team

Disclaimer: The views expressed in this article are independent views solely of the author(s) expressed in their private capacity.

Check out our other content

Ad


Check out other tags:

Most Popular Articles