AML Laws and Regulations for Digital Payment Token Service Providers in Singapore

Table of Contents

In a Nutshell

Digital payment token (DPT) service providers are licensed under the Payment Services Act 2019 to provide regulated DPT services. From 30 June 2025, a separate digital token service provider licensing regime under part 9 of the Financial Services and Markets Act 2022 (FSMA) applies to certain Singapore based businesses providing services outside Singapore.

For DPT service providers, the main rulebook is MAS Notice PS N02 and its Guidelines, covering risk assessment, customer due diligence, beneficial ownership, enhanced measures for politically exposed persons and high-risk customers, the travel rule for token value transfers, record keeping and suspicious transaction reporting. The FSMA regime has corresponding requirements under the applicable MAS notice FSM N27.

The sector presents significant risks because digital assets can move rapidly across borders, involve pseudonymous addresses and reach unregulated or offshore counterparties. Singapore 2024 national risk assessments identify DPT service providers as a significant risk ML, TF, PF risk area, with TF risk assessed at medium high.

The framework sits alongside Singapore’s Aml, CFT and sanctions laws, the Payment services Act, FSMA, MAS notices and guidelines, national risk assessment, and FATF standards. This guide explains each layer and its practical requirements.

AML Laws and Regulations for Digital Payment Token Service Providers in Singapore

A digital payment token service provider handles value that can leave Singapore, change hands and settle on a public blockchain faster than most controls can react, and that speed is exactly what makes the sector attractive to anyone trying to hide where funds came from. This guide sets out the laws and regulations that apply to licensed providers of digital payment token services in Singapore, from the criminal statutes that make money laundering an offence to the detailed rulebook the Monetary Authority of Singapore (MAS) enforces.

The framework is best read in layers. The criminal and sanctions laws sit at the base. Above them is the instrument providers work with every day, MAS Notice PS N02, together with its Guidelines, and, for a firm licensed under the Financial Services and Markets Act, the parallel Notice FSM N27. Alongside these run Singapore’s national risk assessments, the Payment Services Act that licenses the sector, and the FATF standards that shape the whole regime. Each instrument below is described for what it means to licensed providers, not in the abstract.

Because tokens can be bought with cash like onramps and then moved and split across wallets, the sector is used both to place and to layer illicit funds, a wider exposure than most financial businesses face. That single fact drives much of what follows, from how providers assess risk to how they apply the travel rule when tokens leave their platform.

Singapore's digital payment token sector at a glance

As at the 2024 Virtual Assets Risk Assessment there were 19 licensed digital payment token service providers in Singapore, alongside 13 licensed entities offering digital capital markets products (Virtual Assets Risk Assessment 2024).

The value of transactions in which tokens were bought, sold or exchanged for fiat through a Singapore provider in 2023 was about S$73 billion, roughly 0.023% of the turnover on the Singapore Exchange (Virtual Assets Risk Assessment 2024).

Risk ratings: money laundering medium-high, and terrorism financing raised from medium-low to medium-high in the 2024 assessment, driven by anonymity, speed and cross-border reach (ML NRA 2024; TF NRA 2024).

Core AML Laws and Regulations for Digital Token Service Providers in Singapore

These statutes and sanctions regulations designate money laundering, terrorism financing, and proliferation financing as offences and require every digital payment token service provider to detect and report them. They bind by their own force, with the MAS rulebook layered above them.

The Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992

The CDSA establishes Singapore’s core money laundering offences and provides for the confiscation of criminal proceeds. For token providers, section 45 is particularly important: where there are reasonable grounds to suspect that tokens and fiat are proceeds of criminal conduct, the provider must file a suspicious transaction report with the Suspicious Transaction Reporting Office (STRO). Section 57 criminalises tipping off, meaning staff must not disclose information that could prejudice an investigation or alert a customer to a report.

The Terrorism (Suppression of Financing) Act 2002

The TSOFA criminalises the collection of property for terrorism and dealings in terrorist property. For token providers, this means they must not deal with tokens or other property they know or have reasonable grounds to believe are owned or controlled by terrorists and must report relevant information to the authorities. In practice, these obligations are supported by targeted financial sanctions screening of customers, beneficial owners and relevant counterparties, with funds or assets subject to confirmed designation frozen without delay.

The United Nations Act 2001

This Act lets the Minister make regulations giving effect to United Nations Security Council sanctions, and it is the enabling authority behind Singapore’s country measures. For licensed token providers, those measures now run through MAS regulations, because the Act steps back where a financial institution is subject to MAS directions or regulations, so the providers look to the MAS sanctions regime rather than to this Act directly.

The Financial Services and Markets (Sanctions and Freezing of Assets of Persons, Democratic People's Republic of Korea) Regulations 2023

Made by MAS under the Financial Services and Markets Act 2022, these regulations bring United Nations sanctions on North Korea into force and bind every financial institution, so licensed token providers and their overseas branches are covered. The firm must freeze designated persons’ assets without delay, must not deal in or facilitate transactions involving them, and must report to MAS. State-sponsored theft of tokens makes this a live, not theoretical, exposure.

The Financial Services and Markets (Sanctions and Freezing of Assets of Persons, Iran) Regulations 2023

Issued by MAS under the FSM Act 2022, the Iran regulations implement Security Council Resolution 2231. Token providers must freeze designated persons’ funds and economic resources and must not provide services that could support proliferation financing, subject to narrow exemptions that require a MAS determination. In day-to-day terms, the duty is continuous screening of customers and of the wallet addresses they transact with.

Overarching AML Laws and Regulations Applicable to Digital Payment Token Service Providers in Singapore

These instruments cut across the whole regime and give providers the practical means to discharge their reporting duties and to recognise terrorism financing when it surfaces in a token transaction.

Getting Started with SONAR, for STR Filers (2025)

SONAR is the STRO’s electronic platform for submitting suspicious transaction reports. The accompanying guide explains the filing process, including registration, user access and report submission. It provides the practical mechanism through which token providers discharge their section 45 CDSA reporting obligations and maintain evidence of their filings.  

Form Guide for the STR Form (Version 12 August 2025)

A field-by-field guide to the current suspicious transaction report form, explaining how to complete each section, from the reporting institution’s details to the grounds for suspicion. It also requires a unique internal reference number for each report. For token providers, the guide helps compliance officers submit accurate and complete reports, including relevant wallet addresses, transaction details and other supporting information.  

Terrorism Financing Indicators

This indicator group potential terrorism financing red flags into areas such as due diligence anomalies, unusual movement of funds, and transactions lacking an apparent economic purpose. They help token providers identify terrorism financing typologies, including small cross-border transfers and online appeals for token solicitation, and support the assessment of whether a terrorism financing report should be filed.

National Risk Assessments Applicable to Digital Payment Token Service Providers in Singapore

Singapore publishes formal assessments of where its money laundering, terrorism financing and proliferation financing risks lie, and MAS Notice PS N02 and FSM N27 require providers to feed their findings into their own enterprise-wide risk assessment. For this sector, the assessments are pointed: they name digital payment token service providers among the higher-risk sectors and explain why.

Money Laundering National Risk Assessment Singapore 2024

The national money laundering assessment places digital payment token service providers among the medium-high risk sectors, alongside banks and cross-border payment firms. It documents how scam and stolen Identity proceeds are moved through token accounts and out to overseas wallets, and providers are expected to read these findings straight into their own sector risk assessment and monitoring rules.

Terrorism Financing National Risk Assessment 2024

The terrorism financing assessment deliberately raised digital payment token service providers from medium-low to medium-high, citing the anonymity, speed and cross-border nature of token transfers and the risk of dealing with unregulated overseas providers. Token providers must apply the assessment’s typologies, especially small online solicitations and rapid layering across wallets, when it screens customers and monitor transactions.

Proliferation Financing National Risk Assessment and Counter PF Strategy 2024

This assessment identifies sanctions evasion, misuse of legal persons and dual-use trade as the main proliferation channels, and it flags state-linked theft and laundering of tokens as a growing concern. For token providers, the exposure is direct, because designated actors use tokens to move value, which is why sanctions screening and freezing without delay carry the counter-proliferation load.

Environmental Crimes Money Laundering National Risk Assessment (May 2024)

A thematic assessment of how the proceeds of environmental crime, such as illegal wildlife trade and illegal logging, are laundered. It rates banks and remittance agents as the high-risk sectors, but it still reaches token providers whose customers convert such proceeds into tokens, because digital rails can move and integrate value once it has entered the financial system.

Money Laundering and Terrorism Financing Risk Assessment of Legal Persons (2024)

This assessment rates companies as high risk for misuse and shows they generate a disproportionate share of suspicious transaction reports. It is relevant to token providers whose corporate customers may be shell companies used to open accounts and cash out tokens, and it reinforces the duty to look through a corporate customer to the natural persons who own or control it.

Virtual Assets (Digital Payment Tokens) Risk Assessment (2024)

The assessment is written specifically for this sector. It sets out the threats, vulnerabilities and controls for digital payment token service providers, records the 19 licensed providers and the roughly S$73 billion in fiat token turnover in 2023, and concludes that the sector carries high money laundering, terrorism financing and proliferation financing risk. It is the single most important risk document for a provider’s enterprise-wide assessment.

Digital payment token sector ML/TF risk snapshot

Money laundering: medium-high, driven by pseudonymous settlement, near-instant cross-border transfers and the use of token accounts to move scam and stolen-identity proceeds (ML NRA 2024; Virtual Assets Risk Assessment 2024).

Terrorism financing: raised from medium-low to medium-high in 2024, given anonymity, speed and the risk of dealing with unregulated overseas providers (TF NRA 2024).

Proliferation financing: direct exposure, because state-linked actors use tokens for sanctions evasion and to launder stolen tokens (PF NRA 2024).

Key vulnerability: transfers to and from wallets that no institution controls, and dealings with providers licensed to a lower standard abroad (Virtual Assets Risk Assessment 2024).

Sector-Specific Guidance Applicable to Digital Payment Token Service Providers in Singapore

This is the core of providers’ obligations. MAS supervises digital payment token service providers and issues the notices and guidance they must follow. The material divides into common instruments that apply across financial institutions and the specific instruments written for the token sector, led by MAS Notice PS N02 and its Guidelines.

Common Guidelines for Digital Payment Token Service Providers

These MAS instruments apply across financial institutions and shape how providers design their controls. They do not replace Notice PS N02; they explain MAS’s supervisory expectations on topics such as the source of wealth, transaction monitoring, the misuse of legal persons, sanctions, and audit.

The Financial Services and Markets Act 2022

The FSM Act 2022 is the law through which MAS carries out AML/CFT/CPF supervision and enforcement across the financial sector. It supplies the section 16 power under which Notice FSM N27 is issued; it authorises the sanctions regulations token providers screen against; and it gives MAS its inspection and direction powers. Because a breach of an AML/CFT/CPF requirement can draw a penalty of up to SGD1 million, the Act carries the enforcement weight that stands behind the notices.

Circular AMLD 01/2018: Use of MyInfo and CDD for Non Face to Face Business Relations

This circular confirms that the Government’s MyInfo service counts as a reliable and independent source for verifying a customer’s core identity data. Token providers onboarding a MyInfo user can lean on that data rather than gathering documents separately, and the circular lays down safeguards for the remote onboarding the sector runs on, including steps to manage impersonation risk where MyInfo is not used.

Circular AMLD 01/2022: Non Face to Face Customer Due Diligence Measures

This circular develops MAS’s expectations for onboarding natural and legal persons without face-to-face contact, which for token providers is the norm rather than the exception. It warns that video or selfie checks alone may be insufficient, recommends a second-channel check for high-risk accounts, and requires any onboarding technology to be assessed by the firm and signed off by its board and senior management.

Circular AMLD 02/2023: ML/TF Risks in the Wealth Management Sector

Addressed to firms serving wealthy clients, this circular is relevant to token providers that offer custody or trading to high net worth or institutional token holders. It calls for stronger board oversight, due diligence review and quality assurance, for looking through trusts and holding structures to the ultimate beneficial owners, and it treats a customer who withdraws rather than answering questions as a reason to consider a report.

Circular AMLD 08/2024: Establishing the Sources of Wealth of Customers

This circular sets out how a firm should establish a customer’s source of wealth before it opens the relationship. It expects providers to use reasonable means to establish that source of wealth and to corroborate it independently against documents or reliable sources, working to the principles of materiality, prudence and relevance, and to escalate anything it cannot corroborate to senior management. For token providers, it bites hardest on large or unexplained funding of token purchases.

Circular AMLD 05/2026: Risk Proportionate Source of Wealth Establishment

This circular calibrates the source of wealth expectations. MAS stresses that the work should be effective, efficient and proportionate to risk, so that legitimate customers are not burdened. Token providers are told to concentrate corroboration on material or high-risk wealth, to avoid repeated or unreasonable requests on ordinary retail customers, and to escalate real red flags rather than hold everyone to one uniform standard.

Circular AMLD 11/2023: Ensuring Effective Detection of Sanctions Related Risks

MAS requires firms to detect and manage sanctions risk, including unilateral sanctions imposed by other jurisdictions that bear on cross-border token flows. The board must set the risk appetite, and the circular describes a lookback review of transactions after a designation, so providers can catch value that moved through wallets and counterparties before a name was listed.

Circular AMLD 12/2024: Audit of AML/CFT Policies, Procedures and Controls

This circular deals with the independent audit that makes up providers’ third line of defence. Token providers must run an audit function that tests the effectiveness of its AML/CFT/CPF controls at regular intervals, staff it with people who understand both AML and blockchain analytics, give priority to high-risk areas such as the travel rule and unhosted wallet handling, and measure itself against industry best practice.

Strengthening AML/CFT Controls on Misuse of Legal Persons and Complex Structures (August 2023)

An MAS information paper from inspections that found firms letting concerning flows pass through trusts, foundations and layered corporate structures. Through case studies, it shows failures to identify true beneficial owners and to connect source of wealth concerns. Token providers whose corporate customers may be shell companies used to cash out tokens should benchmark themselves against it and remediate under senior management oversight.

AML/CFT Supervisory Expectations from Recent Inspections (October 2024)

Drawn from recent inspections, this paper groups MAS’s expectations into five areas: treating multiple nationalities and investment migration links as risk factors, spotting document red flags, testing whether a customer’s source of wealth is plausible, taking genuine mitigating action after a report or an exit, and sharing customer information across business units. For token providers, each theme lands squarely on remote onboarding and periodic account review.

Best Practices in Relation to Risks in Wealth Management (May 2025)

An industry paper for firms serving wealthy clients, consolidating case studies on private investment companies, sanctions and geopolitical events, remote onboarding and investment migration clients. It is relevant to token providers serving high net worth or institutional customers, and it confirms that where an intermediary sits between the firm and the end customer, the firm must still satisfy its due diligence obligations on that end customer.

Effective Practices to Detect and Mitigate the Risk from Misuse of Legal Persons (June 2019)

An MAS paper on defending against shell and front companies across the customer lifecycle. It sets out multi-factor risk assessment, red-flag lists, network link analysis and staff training, and stresses that a single red flag is rarely conclusive. Token providers onboarding corporate customers should weigh several factors together, blending company registry checks with on-chain analysis, before acting.

Guidance for Effective AML/CFT Transaction Monitoring Controls (September 2018)

This paper collects MAS’s inspection-based expectations for transaction monitoring. It runs through the risk-based calibration of parameters and thresholds, back testing, data integrity, alert handling, documentation, and how outsourced first-level alert review should be treated. For token providers watching both on-platform activity and on-chain flows, it cautions against closing alerts on generic grounds without confirming the risk is genuinely addressed.

Guidance to Capital Markets Intermediaries on Enhancing AML/CFT Frameworks and Controls (January 2019)

Written for capital markets intermediaries rather than for token providers, this MAS guidance on governance, risk awareness and execution binds digital payment token service providers directly only where the same group also holds a capital markets services licence, for example because it deals in digital capital markets products. For other providers, it is persuasive good practice on board accountability and the three lines of defence.

Guidelines on Risk Management Practices, Internal Controls (July 2024)

This prudential guideline states MAS’s expectations for a firm’s control environment and its business process controls. It touches on customer due diligence only at a high level and leaves the detail to the AML/CFT/CPF notices and guidelines, so for token providers it establishes the internal controls scaffolding, from segregation of duties to management information, around which the AML/CFT/CPF programme is arranged rather than a source of AML obligations in itself.

Guidelines on Provision of Digital Advisory Services (October 2018)

A conduct guideline for digital or robo-advisory services, which is a capital markets activity rather than token services. It is in scope for token providers only where the same entity also offers automated investment advice. Its AML/CFT/CPF relevance is narrow: the reminder that any non-face-to-face channel needs adequate ML/TF/PF controls and must manage the impersonation risks of remote onboarding.

Sound Practices to Counter Proliferation Financing (August 2018)

An MAS paper, from thematic reviews, on countering proliferation financing tied to DPRK and Iran sanctions evasion. It works through control uplift, closer monitoring of high-risk customers and counterparties, and typologies such as shell companies with nominee directors. It matters to token providers because state-linked actors use tokens to evade sanctions, so the paper’s controls carry straight over to wallet and counterparty screening.

Strengthening Financial Institutions' CFT Controls (May 2023)

An MAS information paper drawing on an industry survey about countering the financing of terrorism. It restates the duty to freeze, and report designated persons’ assets and sets expectations on screening, data analytics, escalation and the timely, quality filing of reports, all of which token providers apply to their customers and to the wallet addresses they send to and receive from.

Specific Guidelines for Digital Payment Token Service Providers

These are the instruments written for the token sector. Two of them, MAS Notice PS N02 and its Guidelines, are the rulebook a provider lives by, so they are covered in full below, and Notice FSM N27 extends the same discipline to the FSM Act licensees. The remaining instruments apply to a provider according to the licence it holds and the activity it carries on.

MAS Notice PS N02 on Prevention of Money Laundering and Countering the Financing of Terrorism, Digital Payment Token Service

Notice PS N02 is the binding AML/CFT/CPF rulebook for the sector. It applies to every payment service provider that carries on a digital payment token service under the Payment Services Act 2019, whether by dealing in tokens, running an exchange, transferring tokens, providing custody, or arranging or actively facilitating token transfers. The current version is dated 2 April 2024 and was last revised on 1 July 2025, and throughout the Notice, money laundering is defined to include the financing of proliferation.

The Notice first fixes its own vocabulary, and this is where the sector shows its hand. It defines a value transfer as any token transaction carried out on behalf of an originator to make tokens available to a beneficiary, and it names the ordering, intermediary and beneficiary institutions in a transfer chain. It then requires providers to identify, assess and understand their money laundering and terrorism financing risk across their customers, the countries they and their customers deal with, their tokens and services, and their delivery channels. The providers are obligated to apply a risk-based approach with senior management-approved policies and enhanced measures where risk is high. New products, new technologies and new delivery mechanisms must be risk-assessed before launch, with particular attention to features that favour anonymity.

Customer due diligence is the core. Service providers may not keep anonymous or fictitious name accounts, and they must perform customer due diligence when they establish business relations, when they undertake any token transaction or value transfer for a customer, when they suspect money laundering or terrorism financing, or when they doubt the veracity of information they hold. Unlike the cash-based sectors, there is no de minimis that switches the duty off for token transactions. The provider must identify and verify the customer from reliable, independent sources; identify any person acting for the customer and confirm that person’s authority; identify connected parties of a legal person; and identify and verify beneficial owners through cascading steps of ownership, then control, then senior management.

The Notice then requires ongoing monitoring of every relationship: providers must scrutinise transactions and token flows against their knowledge of the customer, pay special attention to complex, unusually large or unusual patterns without apparent purpose, keep due diligence information current, and screen customers, connected parties, beneficial owners and every value transfer originator and beneficiary against sanctions and other lists. The provider may apply simplified due diligence only where risk is demonstrably low, and never where the FATF has called for countermeasures or where a suspicion has arisen. Enhanced due diligence is mandatory for politically exposed persons, requiring senior management approval, establishment of source of wealth and source of funds, and enhanced monitoring, and for other high-risk situations the provider identifies.

The later paragraphs carry the sector’s signature obligation, the travel rule. For every token value transfer, the ordering institution must obtain and hold required originator and beneficiary information and transmit it to the beneficiary institution immediately and securely; for transfers of SGD1,500 or less, it must include at least the names and account or reference numbers of both parties, and for transfers above SGD1,500 it must also identify and verify the originator. A provider may rely on a qualifying third party for elements of due diligence but never for ongoing monitoring, and it remains responsible for its own obligations. It must keep records for at least five years, must report suspicions to the Suspicious Transaction Reporting Office through a single internal reference point, mindful of the tipping-off offence in section 57 of the CDSA, and must maintain adequate internal policies, a group policy across its branches and subsidiaries, an AML/CFT/CPF compliance officer at management level, an independent audit function and regular training.

Guidelines to MAS Notice PS N02 (the primary guidance for token providers)

The Guidelines to Notice PS N02 are the primary guidance digital payment token service providers work with, and they are given the fullest treatment here. They are dated 2 April 2024 and were last revised on 1 July 2025, and their chapters mirror the paragraphs of the Notice, so providers can read each obligation next to its explanation. They are guidance rather than binding rules, but MAS states that the degree to which a firm observes them may affect its overall assessment of the firm, including the quality of its board and senior management oversight, so in practice they set the standard providers are measured against.

The Guidelines open with the sector’s risk profile, and it is deliberately blunt. Tokens settle pseudonymously and move across borders almost instantly; they can be exchanged for other tokens or fiat in seconds, and they can reach wallets and providers that sit outside any regulator’s reach. That combination means token providers can be exposed at the placement stage, when cash, like on ramps, converts illicit funds into tokens, as well as at the layering stage, when value is split and hopped across chains. On accountability, the Guidelines confirm that ultimate responsibility rests with the board and senior management, describe the three lines of defence, and expect the control framework to be resourced by people who understand both financial crime and blockchain analytics.

On the risk-based approach, providers must assess their money laundering and terrorism financing risk not only for individual customers but on an enterprise-wide basis, consolidating across products, tokens, channels and geographies, and including their overseas branches and subsidiaries where it is Singapore-incorporated. The enterprise-wide assessment must be approved by senior management, should combine qualitative and quantitative analysis, must take in the findings of Singapore’s national risk assessments and the Virtual Assets Risk Assessment, and should be refreshed when a material trigger occurs, such as listing a new token, opening a new corridor or adopting a new custody model.

The customer due diligence chapter is the longest, and it works through the token-specific problems the Notice only names. It explains verification from reliable and independent sources for remote onboarding, where the customer is seldom in the room, and it sets the widely used benchmark that a beneficial owner is generally a natural person who owns more than 25% of an entity, while making clear that anyone who controls the customer through other means is a beneficial owner regardless of any percentage. It addresses custody directly: where a provider holds tokens for a customer in a hosted wallet, the provider controls the wallet and must know who the customer is, and where a customer asks to transfer to or from a wallet the provider does not control, an unhosted or self-hosted wallet, the provider should take reasonable measures to establish who controls that wallet, for example by requiring the customer to demonstrate control through a specified test transfer or signature. On timing, verification should generally be completed before or during the establishment of business relations, with relations suspended and, if necessary, terminated where it cannot be completed and any tokens returned to source.

The travel rule chapter is where these Guidelines differ most from those for other sectors, and it repays close reading. It explains that the ordering institution must obtain, hold and transmit the required originator and beneficiary information immediately, meaning at the same time as or before the transfer, and securely, meaning protected against interception or alteration. It works through the S$1,500 threshold in the Notice, the treatment of batch transfers, and the position where the counterparty is not another regulated institution. For a transfer to or from an unhosted wallet, or a party that is not an ordering or beneficiary institution, the travel rule’s transmission mechanism does not fit, so the Guidelines require enhanced measures instead: identifying any third-party originator or beneficiary, establishing wallet control, screening against sanctions and watchlists, and applying enhanced monitoring. They address the sunrise problem, where a counterparty in a less regulated jurisdiction cannot send or receive travel rule data, and they require a provider to adopt policies to hold, return or reject an incoming transfer that lacks the required information rather than simply releasing it.

Screening guidance requires all identified parties, and every value transfer originator and beneficiary, to be screened regardless of assessed risk; sanctions hits to be frozen without delay; and a report to be filed no later than one business day after suspicion is established in sanctions cases, with fuzzy matching calibrated to the firm’s risk and a second person check on sanctions alerts. The enhanced due diligence chapter defines politically exposed persons in line with the FATF standard and draws the important distinction between source of wealth and source of funds: source of wealth is the origin of the customer’s entire body of wealth and how it was acquired, while source of funds is the origin of the particular money or tokens involved in the relationship. A provider should corroborate this information against reliable, independent sources, focus on material or high-risk wealth, and, where it cannot corroborate, assess the residual risk and apply mitigation such as senior management approval and enhanced due diligence on the relationships that warrant it.

The remaining chapters complete the picture, covering reliance as distinct from outsourcing, record-keeping, suspicious transaction reporting, where the general standard is no later than five business days after suspicion is established, the compliance officer, audit and training, together with a proliferation financing chapter and worked examples of customer due diligence information and suspicious token transactions.

MAS Notice FSM N27 on Prevention of Money Laundering and Countering the Financing of Terrorism, Licensed Digital Token Service Providers

Notice FSM N27 is the second binding rulebook for the sector, and providers need to know which of the two it falls under. It is issued under section 16 of the Financial Services and Markets Act 2022 and applies to a holder of a digital token service provider licence granted under section 138 of that Act. That licence was created for a specific gap: a business that is based in or incorporated in Singapore and provides digital token services only to customers outside Singapore. Such a business is not carrying on a payment service to persons in Singapore, so it falls outside the Payment Services Act, but Singapore did not want it to operate from here without AML/CFT/CPF supervision. The Notice took effect on 30 June 2025.

In substance, FSM N27 mirrors Notice PS N02. It imposes the same enterprise-wide risk assessment, the same customer due diligence and beneficial ownership requirements, the same enhanced due diligence for politically exposed persons and other high-risk situations, the same travel rule for token value transfers, and the same record-keeping, suspicious transaction reporting and internal control duties, and it extends them to the licensee’s branches and subsidiaries wherever located. It also carries transitional provisions for a pre-licence customer, a person the business already served before it obtained its section 138 licence, requiring due diligence to be brought up to standard within a period the Authority sets. The practical point for providers is that being outward-facing and unlicensed under the Payment Services Act is not an escape from Singapore’s AML/CFT/CPF regime; the obligations follow the Singapore nexus.

Guidelines to MAS Notice FSM N27

Companion guidance to Notice FSM N27, dated 30 June 2025 and last revised 1 July 2025. Because FSM N27 mirrors Notice PS N02, these Guidelines mirror the Guidelines to PS N02, chapter for chapter, from the risk-based approach and customer due diligence to the travel rule, enhanced due diligence and proliferation financing. They set MAS’s supervisory expectations for the outward-facing licensees and providers that hold a section 138 licence; read them exactly as a Payment Services Act provider reads the Guidelines to PS N02.

Guidance on Strengthening AML/CFT Controls of Digital Payment Token Service Providers (March 2021)

The earliest sector-specific paper, issued soon after DPT services were first licensed. Drawing on the FATF standards and early supervisory experience, it sets out sound practices across governance, risk assessment, customer due diligence, transaction monitoring using blockchain analytics, the handling of value transfers and the management of counterparty and wallet risk. It remains a useful maturity benchmark, and providers should read it as the practical companion to the later Notice PS N02 and its Guidelines rather than as a superseded document.

Two regimes at a glance

Which notice binds a provider depends on the licence it holds. The table below sets the two regimes side by side.

Feature

Notice PS N02 (Payment Services Act regime)

Notice FSM N27 (FSM Act DTSP regime)

Governing licence

Digital payment token service licence under the Payment Services Act 2019

Digital token service provider licence under section 138 of the FSM Act 2022

Who it covers

A provider carrying on a token service in or from Singapore, including to customers in Singapore

A Singapore-based business providing token services only to customers outside Singapore

In force

Dated 2 April 2024, last revised 1 July 2025

Took effect 30 June 2025

AML/CFT content

Full risk-based CDD, EDD, travel rule, records, reporting, audit and training

Mirrors PS N02, applied to the licensee’s outward-facing business and overseas branches

Travel rule

Applies to token value transfers, with the S$1,500 information split

Applies on the same terms to the licensee’s value transfers

Primary guidance

Guidelines to Notice PS N02

Guidelines to Notice FSM N27

 

Allied Laws Applicable to Digital Payment Token Service Providers in Singapore

These statutes are not primarily AML instruments, but each supports the regime: some license and govern token providers, others give investigators their powers, and others create the predicate offences and proliferation controls providers screen against.

The Payment Services Act 2019

The statute that constitutes most of the sector. It defines digital payment tokens and digital payment token services. It requires a person carrying on such a service in Singapore to hold a licence, which is what brings the firm within the scope of Notice PS N02. It also supplies the powers MAS uses to impose ongoing conduct and consumer access requirements on the sector.

The Payment Services Regulations 2019

The Securities and Futures Act reaches token providers where a token is also a capital markets product, a digital capital markets product in MAS’s terms, so the firm may need a capital markets services licence and fall under the capital markets AML notice for that activity. It marks the boundary between the payments and securities regimes that a token business can straddle.

The Guidelines on Licensing for Digital Token Service Providers

These licensing guidelines explain how MAS approaches applications for the section 138 FSM Act licence and the standards it expects of applicants. MAS has stated it will grant this licence only in extremely limited circumstances, because a Singapore-based business serving customers wholly abroad presents money laundering risk that is hard to supervise at a distance. The guidelines are not an AML notice, but they frame the gateway to the FSM N27 regime and signal the high bar a would be outward facing provider must clear before it can operate from Singapore.

The Securities and Futures Act 2001

The Securities and Futures Act reaches token providers where a token is also a capital markets product, a digital capital markets product in MAS’s terms, so the firm may need a capital markets services licence and fall under the capital markets AML notice for that activity. It marks the boundary between the payments and securities regimes that a token business can straddle.

The Companies Act 1967

The general company law statute. For AML purposes, its load-bearing feature is the register of registrable controllers’ regime, backed by a central register at ACRA, which underpins the beneficial ownership information providers rely on and verify when they conduct due diligence on corporate customers and look through to the natural persons who control them.

The Monetary Authority of Singapore Act 1970

The statute that constitutes MAS as the central bank and integrated financial regulator. It is the source of MAS’s authority to supervise digital payment token service providers and to issue the AML/CFT/CPF notices, PS N02 and FSM N27, that providers must follow.

The Prevention of Corruption Act 1960

Singapore’s principal anti-corruption statute. Corruption is a predicate offence for money laundering, so proceeds of offences under this Act are among what providers screen for in politically exposed person and source of funds checks, and its presumption on unexplained assets supports scrutiny of a customer whose wealth cannot be explained.

The Criminal Procedure Code 2010

The procedural code that arms investigators with production, search and seizure powers. Providers served with a production order, or an order not to deal with property in an account, must comply, preserve records and avoid tipping off, which is how AML enforcement reaches into a token account or a hosted wallet.

The Strategic Goods (Control) Act 2002

Governs the transfer and brokering of strategic and dual-use goods, the proliferation financing nexus token providers screen for. Its brokering controls drop away only where a person’s sole role is to provide financing or a financial service, which flags exposure once providers do more than simply fund a deal.

The Biological Agents and Toxins Act 2005

This Act bans the non-peaceful use, production, acquisition and transfer of listed biological agents and toxins, one of the weapons of mass destruction. For token providers, it anchors the proliferation financing screening applied when a customer or a wallet counterparty could be tied to prohibited biological weapons activity.

The Chemical Weapons (Prohibition) Act 2000

Carrying Singapore’s Chemical Weapons Convention obligations into domestic law, this Act criminalises the use, development, acquisition and transfer of chemical weapons, including transfers made indirectly. It sits behind the proliferation financing controls token providers run when screening their customers and the wallets they deal with.

Miscellaneous Laws and Regulations Applicable to Digital Payment Token Service Providers in Singapore

These national strategies, committee reports and typologies set the direction of Singapore’s regime and the public-private partnership a provider operates within. They are not binding rules, yet they steer supervision and feed the typologies providers screen for.

National Anti Money Laundering Strategy 2024

Singapore’s national AML blueprint, built on the pillars of Prevent, Detect and Enforce. Token providers sit within the Prevent pillar, where MAS commits to risk-based supervision of financial institutions, including the newer token sector, and to beneficial ownership transparency, which providers rely on for due diligence.

National Strategy for Countering the Financing of Terrorism 2024

Updated in 2024 alongside Singapore’s terrorism financing risk assessment, which identified the token sector as presenting increased risk, the strategy sets out five key priorities: coordinated risk identification, a strong legal and sanctions framework, effective regulation, robust enforcement, and international cooperation. It provides the strategic direction for strengthening terrorism financing controls across the financial sector, including token providers.

National Asset Recovery Strategy 2024

Singapore’s strategy to detect, deprive and deliver on the proceeds of crime, noting billions seized in recent years. Token providers are an operational partner, since balances and hosted wallets can be the subject of production orders and restraint, and swift cooperation, including preserving on-chain evidence, is expected.

Singapore Law Enforcement Strategy to Combat Money Laundering (October 2024)

The joint strategy of Singapore’s money laundering investigation agencies, which sets focus areas and key actions and leans on public-private information flows with financial institutions. It frames the enforcement environment that token providers support through their reporting, which increasingly includes wallet-level intelligence.

Inter Ministerial Committee on Anti Money Laundering Report (October 2024)

Produced after a major money laundering case, this review recommends measures on the misuse of corporate structures, the role of gatekeepers and information sharing. Its themes bear on token providers whose corporate customers can be shell companies, and it signals the tighter supervisory posture the sector now operates under.

Legal Persons: Misuse Typologies and Best Practices (2018)

An industry typologies paper on how companies and partnerships are misused, supplying the red flags providers use in beneficial ownership and corporate account screening. It is useful for token businesses that onboard holding companies and special purpose vehicles seeking to trade or cash out tokens.

International Standards Applicable to Digital Payment Token Service Providers in Singapore

Singapore’s regime is built to meet the FATF standards, and Notice PS N02 tracks them closely, including the travel rule for virtual assets. These instruments are the least sector-specific of all, yet they explain why the domestic rules look the way they do and hand a provider the typologies and methods supervisors expect it to track.

The FATF Recommendations (updated June 2026)

The Recommendations provide the global standards underpinning AML, CFT and CPF obligations for digital token service providers. Recommendation 15 and its interpretive note specifically address the providers, including requirements for risk-based controls and the travel rule. These standards are reflected in Singapore’s MAS Notice PS N02, which sets out the corresponding AML, CFT and CPF requirements for providers.

Mutual Evaluation Report of Singapore (May 2026)

This 2026 evaluation by the FATF and the Asia/Pacific Group gauges how well Singapore’s regime performs in practice. It frames supervisory expectations across the financial sector, including how Singapore licenses and supervises its digital payment token service providers for money laundering risk.

Methodology for Assessing Technical Compliance and Effectiveness (updated June 2026)

The framework that the FATF applies to measure technical compliance with the Recommendations and the effectiveness of a country’s system is used in practice. It defines the yardstick by which Singapore, and by extension its Digital Token Service Providers, are measured, and it informs MAS’s supervisory expectations.

FATF Guidance on Politically Exposed Persons (Recommendations 12 and 22, 2013)

Explains how a provider identifies politically exposed persons and applies enhanced due diligence: senior management approval, establishing source of wealth and funds, and enhanced ongoing monitoring of the relationship.

Guidance on Beneficial Ownership of Legal Persons (March 2023)

Guidance following the revised Recommendation 24 explains how providers should obtain and verify beneficial ownership information, including how to identify the beneficial owners of corporate customers and distinguish legal ownership from beneficial ownership.

Best Practices on Beneficial Ownership for Legal Persons (October 2019)

Best practices for adequate, accurate and timely beneficial ownership information, supporting a provider’s use of registries and multiple sources when it onboards corporate customers and looks through to their controllers.

Concealment of Beneficial Ownership (July 2018)

A joint FATF and Egmont Group typologies report on how criminals hide beneficial ownership through intermediaries and structures, giving insurers the red flags to detect concealment behind a corporate policyholder or beneficiary.

Risk Based Approach: Beneficial Ownership and Transparency of Legal Arrangements (March 2024)

Guidance focused on Recommendation 25, trusts and similar arrangements, helping insurers assess and mitigate risk where a trust owns a policy or is named as a beneficiary.

FATF Guidance on Counter Proliferation Financing (February 2018)

Guidance on implementing the financial provisions of Security Council resolutions against weapons of mass destruction proliferation, requiring providers to screen and freeze without delay under Recommendation 7, which is acute where tokens are used for sanctions evasion.

Guidance on Proliferation Financing Risk Assessment and Mitigation (June 2021)

Sets out how a provider assesses and mitigates proliferation financing risk following the amended Recommendations 1 and 2, which extended risk-assessment duties to proliferation financing across the digital token service providers.

Guidance on Digital Identity (March 2020)

Helps a provider decide whether a digital identity system is reliable and independent enough for customer due diligence under a risk-based approach, which is central to the remote onboarding almost every token provider relies on.

Artificial Intelligence and Deepfakes: Impacts on ML/TF/PF

A forward-looking FATF scan of how artificial intelligence and deepfakes threaten preventive systems, for example, synthetic identities and deepfake selfies defeating remote onboarding, alongside AI’s uses in transaction monitoring and on-chain analysis.

Summary of Key Instruments

The table below distils the instruments a digital payment token service provider relies on most, what type each is, whom it binds, and the core obligation it places on a provider. Use it as a quick reference rather than a replacement for the fuller sections above.

Instrument

Type

Who it binds

Core obligation for a provider

CDSA 1992

Statute

All persons and providers

Report suspicions (STR), do not tip off, keep records

Terrorism (Suppression of Financing) Act 2002

Statute

All persons and providers

Freeze terrorist property; inform the authorities

FSM Sanctions Regulations (DPRK, Iran) 2023

Regulations

All financial institutions

Freeze designated persons’ assets; report to MAS

MAS Notice PS N02

Notice (PS Act)

PS Act DPT service licensees

Risk-based CDD, EDD, travel rule, monitoring, STR, records

Guidelines to PS N02

Guidelines

All token providers

How to meet the Notice; observance affects MAS assessment

MAS Notice FSM N27

Notice (FSM Act s16)

Section 138 DTSP licensees

Mirrors PS N02 for outward-facing token businesses

Payment Services Act 2019

Statute

Token service providers

Licensing of digital payment token services

MAS Act 1970

Statute

MAS and providers

Source of MAS supervisory authority

ML, TF and PF NRAs 2024

Risk assessments

Whole system

Feed the provider’s enterprise-wide risk assessment

FATF Recommendations

International standard

Global baseline

Underpin the domestic rules, including the travel rule

 

Conclusion

Singapore’s AML, CFT and CPF framework for digital payment token service providers is an interconnected system rather than a set of standalone requirements. The underlying legislation establishes the offences, reporting and sanctions obligations, while MAS Notice PS N02 and its Guidelines, and MAS Notice FSM N27 where applicable, translate these obligations into practical controls covering risk assessment, CDD, EDD, beneficial ownership, ongoing monitoring, travel rule compliance and suspicious transaction reporting.  

Given the cross-border, pseudonymous and technology-driven nature of digital payment token activities, providers must apply these requirements through controls that address blockchain, unhosted-wallet, sanctions, proliferation financing and unregulated counterparty risks. Ultimately, effective compliance depends on understanding how the standards fit together and converting them into a coherent risk-based control framework.

Frequently Asked Questions

MAS Notice PS N02 sets out the AML/ CFT requirements for payment service providers that provide digital payment token services under the Payment Services Act 2019. It should be read together with the Guidelines to Notice PS N02, which explain how the requirements should be applied in practice. A separate notice applies to entities conducting digital token activities under the Financial Services and Markets Act 2022. MAS Notice FSM N27 applies to holders of a digital token service provider licence under that Act.

Notice PS N02 binds a provider licensed under the Payment Services Act to provide a digital payment token service, which includes serving customers in Singapore. Notice FSM N27 binds a holder of a section 138 FSM Act licence, a Singapore-based business that provides digital token services only to customers outside Singapore. The AML/CFT obligations are essentially the same; the difference is which licence the firm holds.

Under Notice PS N02, for a token value transfer, the ordering provider must obtain, hold and transmit required information about the originator and the beneficiary to the beneficiary institution immediately and securely. For transfers of S$1,500 or less, it must include at least both parties’ names and account numbers, and for transfers above S$1,500 it must also identify and verify the originator.

Where a transfer is to or from a wallet that no institution controls, the travel rule’s transmission mechanic does not fit, so the Guidelines to Notice PS N02 require enhanced measures instead: establishing control of the wallet, for example, through a test transfer or signature, identifying any third party, screening against sanctions designated lists, and applying enhanced monitoring proportionate to the risk.

Whenever it has reasonable grounds to suspect money laundering or terrorism financing. It is filed with the Suspicious Transaction Reporting Office, as a rule within five business days of forming the suspicion, and within one business day in sanctions cases. Our guide to STR red flags explains common triggers.

Singapore’s 2024 assessments rate digital payment token service providers medium-high for money laundering, and the terrorism financing assessment raised the sector from medium-low to medium-high, citing anonymity, speed and cross-border reach. The sector also carries direct proliferation financing exposure because state-linked actors use tokens to evade sanctions.

Yes. A Singapore-based business that provides digital token services only to customers abroad needs a section 138 FSM Act licence and is bound by Notice FSM N27, which mirrors Notice PS N02. MAS has said it will grant that licence only in extremely limited circumstances, precisely because such a business is harder to supervise.

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.