The Regulatory Framework
The AML/CFT landscape in Singapore is shaped by three principal layers.
Primary legislation establishes the legal obligations. The Corruption, Drug Trafficking and Other Serious Crimes Act (CDSA) is the cornerstone, creating offences for money laundering and imposing reporting obligations on financial institutions and designated non-financial businesses and professions. The Payment Services Act (PSA) extends these obligations to payment service providers, bringing digital payment services, money-changing, and remittance businesses within the regulatory perimeter.
MAS AML/CFT Guidelines set out the regulator’s detailed expectations for how regulated institutions should implement a compliance programme. These guidelines are issued under the Monetary Authority of Singapore Act and reflect Singapore’s commitment to the FATF 40 Recommendations. They are not legislation in themselves, but MAS expects regulated institutions to treat them as operational standards that will inform supervisory assessment.
The risk-based approach is the organising principle. MAS requires institutions to identify, assess, and understand the ML/TF risks they face, and to apply resources and controls proportionate to those risks. This approach is flexible by design; institutions are not required to apply uniform controls across all customers, but they must be able to demonstrate that their controls are calibrated to the risks they have identified.
MAS also distinguishes between a Programme-Based Approach and a Risk-Based Approach . The Programme-Based Approach, once the standard model, required institutions to implement a fixed set of compliance procedures. The Risk-Based Approach, now the dominant framework, requires institutions to conduct risk assessments and tailor their controls accordingly. Institutions that have not yet completed a documented risk assessment should treat this as a priority action.
Who Is Regulated
MAS supervision extends across a broad range of entities.
Banks and finance companies are subject to the full suite of AML/CFT obligations and represent the most mature segment of the compliance landscape.
Payment service providers licensed under the PSA include digital payment token services, money-changing services, and domestic money transfer services. MAS brought these entities within the AML/CFT framework through amendments to the PSA, reflecting the growing ML/TF risk associated with digital payment services.
Capital markets entities licensed by MAS, including holders of capital markets services licences, are subject to AML/CFT obligations under the Securities and Futures Act and MAS AML/CFT Guidelines.
Other entities within scope include trust companies, insurance companies with certain product exposures, and motor vehicle dealers where cash transactions exceed defined thresholds.
If your organisation holds a licence from MAS or is otherwise subject to the PSA, AML/CFT obligations apply. The specific controls will be calibrated to your business model, but the foundational obligations are consistent across the regulated population.
Customer Due Diligence Obligations
Customer due diligence (CDD) is the operational foundation of any AML/CFT programme. MAS AML/CFT Guidelines require institutions to understand the customer and, where applicable, the beneficial owner before establishing a business relationship.
Standard CDD applies to all customers. It requires collection of identifying information, verification of that information against reliable documents or data, understanding the nature and purpose of the business relationship, and ongoing scrutiny of transactions conducted through the account.
Enhanced due diligence (EDD) applies where the risk is higher. MAS identifies several risk triggers, including complex or unusually large transactions, transactions with no apparent economic or visible lawful purpose, relationships with politically exposed persons (PEPs), and relationships involving jurisdictions with higher ML/TF risk. In EDD situations, institutions must implement additional measures such as obtaining senior management approval, gathering additional information on the customer’s source of funds and wealth, and conducting more frequent reviews of the business relationship.
Simplified CDD may apply where the assessed risk is lower and where MAS AML/CFT Guidelines conditions are met. Simplified measures are not a reduction in vigilance; they are a proportional response to lower risk. Institutions must still monitor transactions and must be prepared to apply full CDD if circumstances change.
Timing of CDD is specified in the guidelines. Verification of identity must be completed before establishing a business relationship. Where this is not reasonably possible, such as in certain securities transactions, delayed verification may be applied subject to conditions including transaction limitations and risk mitigation measures. The default position is verification first; any exceptions must be documented and justified.
Ongoing Monitoring
CDD is not a one-time event. MAS requires institutions to conduct ongoing monitoring of customer relationships throughout the lifecycle of the engagement.
Transaction monitoring is a core obligation. Institutions must scrutinise transactions to ensure they are consistent with the customer’s known profile, the nature of the business relationship, and the information collected during onboarding. Transactions that deviate from expected patterns require escalation.
Account reviews should be conducted at a frequency determined by the assessed risk level of the customer. High-risk customers require more frequent review. Reviews should confirm that the information held remains accurate and current, and that the risk rating assigned at onboarding remains appropriate.
Periodic review triggers extend beyond scheduled reviews. Material changes to a customer’s circumstances, large or unusual transactions without clear economic purpose, and adverse information emerging through screening or media monitoring are all triggers for immediate review.
The expectation is that monitoring is ongoing and systematic , not reactive or ad hoc. Institutions must be able to demonstrate that their monitoring processes are operating effectively and that reviews are conducted on time.
PEP Screening and Enhanced Obligations
Politically exposed persons present elevated ML/TF risk due to the nature of their positions and their potential exposure to corruption, embezzlement, and illicit financial flows. MAS AML/CFT Guidelines impose specific obligations on institutions in relation to PEPs.
MAS defines a PEP to include foreign PEPs (individuals holding prominent public functions in a foreign jurisdiction), domestic PEPs (individuals holding prominent public functions in Singapore), and persons who are or have been entrusted with a prominent function by an international organisation. Family members and close associates of all categories are treated as PEPs for these purposes.
Singapore’s own political leadership, senior civil servants, members of the Executive, and officials in roles such as the Attorney-General’s chambers or the Singapore Armed Forces are examples of domestic PEPs that compliance teams should have in scope.
Obligations for PEP relationships include identifying the customer and beneficial owner as a PEP, obtaining senior management approval before establishing or continuing the relationship, taking reasonable measures to establish the source of wealth and source of funds, and conducting enhanced and ongoing monitoring throughout the relationship.
Screening for PEP status must occur at onboarding and must be refreshed on an ongoing basis. A customer who is not a PEP at the time of onboarding may acquire PEP status later; the compliance programme must detect this change and trigger the enhanced obligations accordingly.
MemberCheck supports Singapore institutions with real-time PEP screening against domestic and foreign PEP lists, adverse media monitoring to surface reputational risk, and configurable matching that allows compliance teams to calibrate sensitivity according to their risk appetite and regulatory expectations.
Technology Risk Management and System Expectations
MAS Technology Risk Management Guidelines set out expectations for the technology infrastructure supporting AML/CFT compliance. These guidelines have become increasingly relevant as compliance programmes have digitised.
System availability and resilience are expected to meet defined standards. Compliance processes that depend on technology must have appropriate redundancy, and institutions must have business continuity plans in place.
Data integrity and security are non-negotiable. Customer due diligence records, transaction data, and screening results represent sensitive personal and commercial information. Institutions must implement controls consistent with MAS expectations on data protection and technology security.
Screening system performance is within scope. The effectiveness of automated screening against PEP, sanctions, and adverse media databases must be measurable. Institutions should be able to demonstrate that their systems are returning accurate results, that matches are being reviewed by qualified personnel, and that false positive rates are being managed.
FraudShield addresses the transaction monitoring component of these expectations, providing configurable rules-based monitoring aligned to the types of patterns that compliance teams in Singapore institutions need to detect.
Suspicious Transaction Reporting
When an institution identifies a transaction or activity that raises suspicion of money laundering or terrorism financing, it has a legal obligation to report.
Reporting to CAD is the obligation. The Commercial Affairs Department of the Singapore Police Force is the competent authority for receiving suspicious transaction reports (STRs). The obligation arises when an institution knows, suspects, or has reasonable grounds to suspect that funds or property are connected to money laundering, terrorism financing, or other serious offences under the CDSA.
Tipping off is a criminal offence. An institution, or any officer or employee of an institution, must not disclose to the customer or any third party that an STR has been or may be submitted. The prohibition on tipping off applies even if the suspicion is not confirmed and no report is ultimately made.
Timing matters. An STR should be submitted promptly once a suspicion is formed. Delays in reporting can themselves constitute a breach of obligations.
The threshold for reporting is not a high one. Institutions should err on the side of reporting where there is reasonable suspicion. MAS and CAD do not penalise good-faith reports that do not result in prosecution.
Virtual Asset Service Providers Under the PSA
The PSA, as amended, brings virtual asset service providers (VASPs) within the regulatory perimeter. Entities providing digital payment token services in Singapore are required to be licensed by MAS and are subject to AML/CFT obligations.
VASP obligations include customer due diligence requirements equivalent to those applicable to other payment service providers, screening against FATF sanctions lists, and compliance with the Travel Rule for relevant transfers. MAS has issued specific guidance on the application of AML/CFT requirements to VASPs, reflecting the elevated ML/TF risk profile of digital asset transactions.
Travel Rule compliance requires VASPs to collect, transmit, and receive originator and beneficiary information for virtual asset transfers. This obligation applies to transfers above the applicable threshold and reflects Singapore’s commitment to implementing the FATF Travel Rule.
The intersection of PSA obligations and broader AML/CFT requirements means that VASPs operating in Singapore must maintain compliance programmes that are at least as rigorous as those expected of traditional payment service providers, with additional considerations specific to the digital asset context.
How MemberCheck Supports Your Singapore Compliance Programme
MemberCheck is designed to support compliance teams at Singapore institutions in meeting the operational demands of MAS AML/CFT Guidelines.
PEP screening against domestic, foreign, and international PEP databases ensures that institutions can identify politically exposed persons at onboarding and throughout the customer lifecycle. Configurable matching allows teams to calibrate sensitivity according to their risk appetite and the specific expectations of MAS supervisors.
Sanctions screening against FATF sanctions lists, OFAC, UN, EU, and other relevant lists provides the foundation for the screening obligations applicable to payment service providers and other regulated entities.
Adverse media screening surfaces negative information about customers and beneficial owners that may indicate elevated risk or require further investigation. This supports the ongoing monitoring obligation and the PEP due diligence requirement to gather information on source of wealth and source of funds.
Configurable matching and workflow allows compliance teams to define their own screening parameters, escalation pathways, and review processes. MemberCheck is not a black box; it is a configurable platform that adapts to your risk framework and operational processes.
Ongoing monitoring is supported through automated re-screening against updated lists and configurable alerts when new information emerges that may affect a customer’s risk profile.
How FraudShield Supports Transaction Monitoring
FraudShield provides the transaction monitoring capability that MAS expects institutions to maintain. Configurable rules-based monitoring allows compliance teams to define the transaction patterns they need to detect, calibrated to their customer base and risk profile.
Real-time and batch monitoring options support institutions with different transaction volumes and monitoring requirements. Rules can be configured to detect large transactions, unusual transaction patterns, structuring behaviour, and other indicators consistent with the red flag indicators identified in MAS AML/CFT Guidelines.
Alert management and case workflow support the investigation process, ensuring that flagged transactions are reviewed by qualified personnel and that decisions are documented.
Reporting and audit trail capabilities support the obligation to demonstrate effective monitoring to MAS supervisors during examinations.
Moving From Compliance to Capability
Meeting the minimum requirements of MAS AML/CFT Guidelines is the starting point, not the destination. Institutions that treat AML/CFT compliance as a checkbox exercise expose themselves to regulatory risk, reputational damage, and financial crime.
The institutions that perform best under MAS supervision are those that treat compliance as a capability : integrated into business processes, supported by appropriate technology, staffed by qualified personnel, and subject to continuous improvement based on operational experience and supervisory feedback.
Understanding your risk profile, implementing proportionate controls, maintaining documentary evidence of compliance activity, and responding promptly when issues arise are the hallmarks of a mature compliance programme.
MemberCheck and FraudShield are built to support this maturity journey, providing the screening, monitoring, and workflow infrastructure that compliance teams need to move from reactive compliance to proactive financial crime prevention.
Singapore MAS AML/CFT Requirements: A Compliance Guide for FIs
Understand your obligations under the MAS AML/CFT Guidelines. This guide covers CDD, PEP screening, transaction monitoring, and STR reporting for Singapore financial institutions.
Speak to our teamThis article was accurate at the time of publication in August 2026 and is intended for general informational purposes only. It does not constitute legal, regulatory or compliance advice. Organisations should seek qualified professional guidance in relation to their specific obligations.

