AML Laws and Regulations for Securities Depository in Singapore
In a Nutshell
The securities depository is the Central Depository, the entity that holds, in book entry form, the securities traded on the Singapore Exchange. It is defined under section 81SF of the Securities and Futures Act 2001, and section 81SI of the Act deems it a bare trustee for all securities deposited with it, so it sits at the apex of the securities holding chain rather than dealing directly with most investors.”
The guideline it follows is MAS Notice SFA 03AA N01 and its Guidelines. They set the risk based approach, customer due diligence, reliance on the brokers and banks in the chain, enhanced measures for politically exposed persons, record keeping and suspicious transaction reporting. Because investors reach the depository through brokers, much of the front line due diligence is done by those firms.
Singapore’s 2024 assessment places the securities depository in the lower money laundering risk band. The threat is moderate, since securities markets can be misused internationally, but the vulnerability is very limited, because the depository does not trade or move funds directly and every account holder is identified at onboarding.
Around this core sit the criminal and sanctions statutes, the national risk assessments, the Securities and Futures Act that defines the depository, and the FATF standards, including the guidance written for the securities sector.
AML Laws and Regulations for the Securities Depository in Singapore
The securities depository sits at the centre of the market, holding everyone’s shares in book entry form, yet it rarely meets the investors behind those holdings, and that shapes its anti money laundering duties. This guide sets out the laws and regulations that apply to the securities depository in Singapore, from the criminal statutes that make money laundering an offence to the detailed Guidelines the Monetary Authority of Singapore (MAS) enforces on the securities depository.
The framework is best read in layers. The criminal and sanctions laws sit at the base. Above them is the instrument the depository works with, MAS Notice SFA 03AA N01, together with its Guidelines. Alongside these run Singapore’s national risk assessments, the Securities and Futures Act that defines the depository, and the FATF standards behind the whole regime. Each instrument below is explained through the lens of the depository, not in the abstract.
Because the depository holds securities rather than moving funds directly, its money laundering exposure differs from that of institutions involved in payments or cash transactions. Its risks can instead arise from securities holdings or transactions involving persons whose identity, ownership or control has not been properly established. This makes the controls applied by brokers and banks that onboard investors, together with the depository’s own applicable checks, central to the framework.
Singapore's Securities Depository at a Glance
The Central Depository holds, as a bare trustee in book entry form, all the securities traded on the Singapore Exchange, so every investor who trades on the Exchange holds through a depository account (Money Laundering National Risk Assessment 2024, chapter 7.17).
Investors reach the depository through a broker and a bank, which are themselves MAS regulated, and the depository does not engage in direct trading or funds transactions with account holders (ML NRA 2024, chapter 7.17).
Risk rating: the sector is assessed in the lower money laundering risk band, with a moderate threat but very limited vulnerability, because the depository neither trades nor moves funds directly (ML NRA 2024, chapter 7.17).
Core AML Laws and Regulations for Securities Depository in Singapore
These laws and sanctions regulations form the statutory foundation of Singapore’s AML, CFT and CPF framework. They impose obligations that apply according to their respective provisions, while the sector specific requirements applicable to the depository are supplemented by MAS notices and guidelines.
The Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992
The CDSA establishes Singapore’s principal money laundering offences and provides for the confiscation of criminal proceeds. Section 45 requires a person who knows or has reasonable grounds to suspect that property represents the proceeds of, was used in connection with, or is intended to be used in connection with drug dealing or criminal conduct to disclose that knowledge or suspicion to a Suspicious Transaction Reporting Officer as soon as is reasonably practicable.
The Terrorism (Suppression of Financing) Act 2002
The TSOFA criminalises various forms of terrorism financing and dealings involving property connected with terrorism. Where its disclosure and prohibition requirements apply, the depository must take the prescribed action and make the required disclosures. In practice, sanctions screening of account holders and relevant connected parties is an important control for identifying persons or property subject to terrorism related restrictions.
The United Nations Act 2001
The United Nations Act 2001 provides the legislative basis for giving effect to certain United Nations Security Council decisions through regulations made under the Act. For a financial institution regulated by MAS, the applicable sanctions obligations may be implemented through the relevant MAS regulations and other applicable requirements made under Singapore law.
The Financial Services and Markets (Sanctions and Freezing of Assets of Persons, Democratic People's Republic of Korea) Regulations 2023
These regulations establish Singapore’s sanctions and asset freezing requirements relating to designated persons connected with the DPRK. Where the regulations apply to the depository, it must comply with the applicable prohibitions, asset freezing requirements and reporting obligations, including those relating to designated persons and specified transactions or services.
The Financial Services and Markets (Sanctions and Freezing of Assets of Persons, Iran) Regulations 2023
The Iran regulations establish sanctions and asset freezing requirements relating to designated persons and specified activities covered by the regulations. Where applicable, the depository must comply with the relevant asset freezing, prohibition and reporting requirements. Screening account holders and relevant connected parties against applicable sanctions lists is an important control for identifying designated persons and mitigating sanctions and proliferation financing risks.
Overarching AML Laws and Regulations Applicable to the Securities Depository in Singapore
These instruments support the depository’s practical implementation of its AML, CFT and CPF obligations, including suspicious transaction reporting and the identification of terrorism financing and other financial crime risks.
Getting Started with SONAR, for STR Filers (2025)
SONAR is the STRO Online Notices and Reporting platform used for the electronic submission of disclosures under section 45 of the CDSA. The platform supports the reporting process, including registration, user management and electronic submission. A depository subject to the reporting obligation can use SONAR to submit the required disclosure and maintain appropriate records of its submission.
Form Guide for the STR Form (Version 12 August 2025)
This guide provides instructions for completing the suspicious transaction report form, including the information required about the reporting entity and the basis for the suspicion. For the depository’s compliance team, it can be used as a reference when preparing a complete and properly supported suspicious transaction report.
Terrorism Financing Indicators
This STRO reference identifies indicators that may signal terrorism financing, including due diligence concerns, unusual transactions and activity without an apparent economic or lawful purpose. For the depository, these indicators can support the identification and escalation of potentially suspicious activity and help inform the decision on whether a report is required.
National Risk Assessments Applicable to the Securities Depository in Singapore
Singapore publishes national assessments covering money laundering, terrorism financing and proliferation financing risks. The depository should consider the relevant findings when assessing and managing its own risks. For the securities depository sector, the 2024 money laundering risk assessment places the sector in the lower risk band, identifying a moderate threat but very limited vulnerability.
Money Laundering National Risk Assessment Singapore 2024
The national money laundering assessment gives the securities depository its own section and places it in the lower risk band. It records a moderate threat, because international typologies show laundering through securities markets, but very limited vulnerability, because the depository does not trade or move funds directly and every account holder is identified through the relevant onboarding channels. The depository should carry these findings into its sector risk assessment.
Terrorism Financing National Risk Assessment 2024
The terrorism financing assessment focuses primarily on sectors and channels such as banking, remittance and payments. For the depository, its findings remain relevant when assessing terrorism financing risks, particularly risks involving third parties, opaque ownership or control and other findings identified in the national risk assessment.
Proliferation Financing National Risk Assessment and Counter PF Strategy 2024
This assessment identifies risks including sanctions evasion and the misuse of legal persons in proliferation financing. For the depository, the exposure may arise indirectly through corporate account holders or structures with opaque ownership or control. Beneficial ownership checks and sanctions screening are therefore important controls for managing relevant proliferation financing risks.
Environmental Crimes Money Laundering National Risk Assessment (May 2024)
An assessment of how the proceeds of environmental crime, from the illegal wildlife trade to illegal logging, move through the system. It rates banks and remittance agents as the high risk sectors. For the securities depository, the relevance is more limited and may arise where a corporate account holder has wealth or assets linked to environmental crime.
Money Laundering and Terrorism Financing Risk Assessment of Legal Persons (2024)
This assessment rates companies as high risk for misuse and finds them generating an outsized share of suspicious transaction reports. It bears on the depository whose account holders include companies and investment vehicles. The assessment therefore supports greater attention to ownership and control structures and to identifying the natural persons who ultimately own or control a legal person where required.
Virtual Assets (Digital Payment Tokens) Risk Assessment (2024)
This assessment weighs Singapore’s exposure to virtual asset activity. Its bearing on the depository is narrow, since it holds listed securities rather than digital payment tokens. However, its findings may be relevant when assessing the risk associated with an account holder or transaction that has a connection to virtual asset activity.
Securities Depository ML/TF Risk Snapshot
Money laundering: lower risk band, with a moderate threat from securities market typologies but very limited vulnerability, because the depository neither trades nor moves funds directly (ML NRA 2024, chapter 7.17).
How the risk is contained: investors are onboarded and verified by MAS regulated brokers and banks, and every account holder is identified at the point of onboarding (ML NRA 2024, chapter 7.17).
Proliferation and terrorism financing: largely indirect, through a corporate account holder with opaque ownership (PF and TF NRAs 2024).
Supervision: MAS subjects the depository to on site inspection and off site supervision and has not observed critical weaknesses in its controls (ML NRA 2024, chapter 7.17).
Sector Specific Guidance Applicable to the Securities Depository in Singapore
This is the core of the depository’s obligations. MAS supervises the depository and issues the notice and guidance it must follow. The material divides into common instruments that apply across financial institutions and the specific instruments written for the depository, led by MAS Notice SFA 03AA N01 and its Guidelines.
Common Guidelines for Securities Depository
These MAS instruments apply across financial institutions and shape how the depository designs its controls. They do not displace Notice SFA 03AA N01; they explain MAS’s supervisory expectations on themes such as source of wealth, transaction monitoring, misuse of legal persons, sanctions and audit.
The Financial Services and Markets Act 2022
The FSM Act 2022 is the statute through which MAS supervises and enforces AML/CFT across the financial sector, and Section 16 is a power under which Notice SFA 03AA N01 is made. It authorises the sanctions regulations the depository screens against and confers MAS’s inspection and direction powers. Failure to comply with applicable AML/CFT requirements made under the FSMA is an offence and may attract a fine of up to S$1 million, with further penalties for continuing offences.
Circular AMLD 01/2018: Use of MyInfo and CDD for Non Face to Face Business Relations
This circular recognises the Government’s MyInfo service as a reliable, independent source of a customer’s basic identity data. Where the depository opens an account directly and without face to face contact, it can verify a MyInfo user from that data instead of collecting documents afresh, subject to the circular’s safeguards against the impersonation risk that arises where MyInfo is not used.
Circular AMLD 01/2022: Non Face to Face Customer Due Diligence Measures
This circular sets MAS’s expectations for onboarding without face to face contact, which is the norm where the depository opens an account directly. It cautions that a video or selfie check alone can fall short, urges a second independent channel for higher risk customers, and expects the onboarding technology to be assessed by the firm and signed off by its board and senior management.
Circular AMLD 02/2023: ML/TF Risks in the Wealth Management Sector
This circular reaches the depository only at the edges, where an account is held by a high net worth investor or a vehicle with layered ownership. Even so, its themes still apply: firmer board oversight, a fresh look at due diligence and quality assurance, tracing past holding vehicles to the real beneficial owners, and reading a customer who walks away rather than answer questions as grounds to weigh a report.
Circular AMLD 08/2024: Establishing the Sources of Wealth of Customers
This circular describes how a firm should pin down a customer’s source of wealth before the relationship begins. For the depository, it matters for a directly held account for a high value or higher risk holder: the depository should take reasonable steps to establish the source of wealth, corroborate it under the tests of materiality, prudence and relevance, and escalate what it cannot substantiate.
Circular AMLD 05/2026: Risk Proportionate Source of Wealth Establishment
A 2026 circular that rebalances how much source of wealth work is warranted. MAS wants the effort to be effective, efficient and proportionate to risk, so ordinary account holders are not burdened. Where the circular is applicable to the depository’s circumstances, its risk proportionate approach supports calibrating source of wealth measures according to the customer’s risk, materiality and relevance rather than applying a blanket approach.
Circular AMLD 11/2023: Ensuring Effective Detection of Sanctions Related Risks
MAS expects firms to spot and manage sanctions risk, including unilateral sanctions from other jurisdictions. Setting the risk appetite is a board task, and the circular describes a backward looking review once a party is designated. For the depository, the practical effect is disciplined screening of account holders and connected parties, and a review of accounts when a name is listed.
Circular AMLD 12/2024: Audit of AML/CFT Policies, Procedures and Controls
This circular deals with the independent audit that serves as a firm’s third line of defence. The depository must run an audit function that tests whether its AML/CFT controls actually work, staff it with the right expertise, give priority to higher risk areas such as directly held accounts and reliance arrangements, and benchmark against industry best practice.
Strengthening AML/CFT Controls on Misuse of Legal Persons and Complex Structures (August 2023)
Grounded in inspection work, this MAS paper portrays firms that allowed concerning flows through trusts, foundations and layered corporate structures. Its case studies lay bare failures to identify the true beneficial owner. The depository holding accounts for companies and investment vehicles should measure itself against it and be sure it can trace the natural persons behind a corporate account holder.
AML/CFT Supervisory Expectations from Recent Inspections (October 2024)
Taken from its recent inspections, this paper organises MAS’s expectations into five themes: treating multiple nationalities and investment migration ties as risk factors, spotting document red flags, checking whether a customer’s source of wealth holds up, supporting a report or an exit with genuine mitigation, and passing customer information between business lines. Each bears on how the depository onboards and reviews a directly held account.
Best Practices in Relation to Risks in Wealth Management (May 2025)
An industry paper for firms with wealthy customers, pulling together case studies on private investment companies, trusts and remote onboarding. Its reach into the depository is limited to the occasional high value or complex account holder, but where a bank or adviser sits alongside, the depository must still meet its own due diligence duties where it deals with the holder directly.
Effective Practices to Detect and Mitigate the Risk from Misuse of Legal Persons (June 2019)
This MAS paper is about safeguarding against shell and front companies across a relationship. It offers multi layered risk assessment, red flag lists, network link analysis and staff training, and it points out that a lone red flag rarely settles a case. The depository holding accounts for corporate investors should weigh several signals together before it acts.
Guidance for Effective AML/CFT Transaction Monitoring Controls (September 2018)
This paper assembles the transaction monitoring expectations MAS has drawn from its inspections. The depository sees securities movements rather than cash flows, so the guidance is applied proportionately, but its themes, tuning what to look for, keeping data clean and recording how alerts are handled, still shape how it monitors account activity.
Guidance to Capital Markets Intermediaries on Enhancing AML/CFT Frameworks and Controls (January 2019)
Written for capital markets intermediaries, this MAS guidance on governance, risk awareness and execution is directly relevant to the depository as a piece of market infrastructure in the capital markets. It sets out board accountability, the three lines of defence and how a firm should resource its AML/CFT programme, all of which the depository is expected to reflect.
Guidelines on Risk Management Practices, Internal Controls (July 2024)
A prudential guideline setting out what MAS expects of a firm’s control environment and its business process controls. It touches customer due diligence only lightly and defers to the AML/CFT notices for the detail, so for the depository it supplies the internal controls scaffolding, from segregation of duties to management reporting, around which the AML/CFT programme is built rather than a source of AML duties itself.
Guidelines on Provision of Digital Advisory Services (October 2018)
A conduct guideline that governs digital and robo advisory services. Its bearing on the depository is remote, since it does not advise investors, but it is retained for completeness as part of the common MAS material, and its reminder on remote channel controls informs any direct digital onboarding the depository carries out.
Sound Practices to Counter Proliferation Financing (August 2018)
Informed by MAS’s thematic reviews, this paper deals with proliferation financing linked to DPRK and Iran sanctions evasion. It describes how firms should reinforce controls, keep watch over higher risk customers and counterparties, and spot typologies such as shell companies run by nominee directors. It reaches the depository whose corporate account holders may carry links to higher risk jurisdictions.
Strengthening Financial Institutions' CFT Controls (May 2023)
Based on an industry survey, this MAS information paper focuses on countering the financing of terrorism. It restates the duty to freeze and report designated party assets and sets expectations for screening, escalation and prompt, good quality reporting, each of which the depository applies to its account holders and their connected parties.
Specific Guidelines for Securities Depository
These are the instruments written for the depository. Two of them, MAS Notice SFA 03AA N01 and its Guidelines, are the guidelines the depository lives by, so they are covered in full below. One further notice applies only where the depository also carries on precious stones dealing.
MAS Notice SFA 03AA N01 on Prevention of Money Laundering and Countering the Financing of Terrorism
Notice SFA 03AA N01 is the principal binding AML/CFT notice for the securities depository. It is issued under section 16 of the Financial Services and Markets Act 2022 and applies to the Depository as defined under section 81SF of the Securities and Futures Act 2001. It takes effect on 1 July 2025.
The Notice provides that money laundering includes proliferation financing. Distinctively, business relations mean the opening or maintenance of an account by the depository directly, and not through a depository agent or a financial institution listed in Appendix 2 to the Notice, which is what channels the duty to the accounts the depository handles itself.
After the underlying principles, the Notice requires the depository to identify, assess and understand its money laundering, terrorism financing and proliferation financing risk across its account holders, the countries they operate in, and its products, services and channels, and to apply a risk based approach with senior management approved policies and enhanced measures where risk is higher. It must assess new products, practices and technologies before launch.
Customer due diligence is the core. The depository may not keep anonymous or fictitious name accounts, and it must perform customer due diligence when it establishes business relations directly, when it suspects money laundering or terrorism financing, or when it doubts information it holds. It must identify and verify the account holder from reliable, independent sources, identify any person acting for the customer, identify the connected parties of a corporate account holder, and identify and verify beneficial owners through cascading steps of ownership, then control, then senior management.
The Notice then scales the work to risk. Simplified due diligence is available only where risk is demonstrably low, including in defined dealings with the financial institutions listed in the Appendix.
Enhanced due diligence is required for politically exposed persons, calling for senior approval, establishment of source of wealth and source of funds and closer monitoring, and for other higher risk situations, including account holders connected to including account holders connected to jurisdictions identified by the FATF as having strategic deficiencies in their AML/CFT regimes.
Reliance is central to this sector: the depository may rely on an Appendix 2 institution, or a foreign financial institution supervised for AML/CFT compliance consistent with FATF standards, for elements of due diligence, because investors commonly access the securities market through brokers and other financial institutions.
Where an account is opened through a depository agent rather than directly with the depository, it falls outside the Notice’s definition of ‘business relations’ altogether, so the depository’s CDD duty does not extend to it in the first place. Where the depository does rely on a third party, it keeps responsibility for its own obligations. A separate chapter governs correspondent accounts; there is no wire transfer chapter, because the depository holds securities rather than remitting funds.
The remaining paragraphs complete the framework. The depository must keep records for at least five years. The Notice also provides for restrictions on certain personal data access and correction rights where necessary to protect AML/CFT controls and prevent tipping off.
Suspicions must be reported to the Suspicious Transaction Reporting Office through a single internal reference point, mindful of the tipping off offence in section 57 of the CDSA, and the depository must maintain internal policies, an AML/CFT compliance officer, an independent audit function, screening procedures for hiring, and regular training.
Guidelines to MAS Notice SFA 03AA N01 (the primary guidance for the depository)
The Guidelines to Notice SFA 03AA N01 are the primary guidance the depository works with, and they are given the fullest treatment here. They are dated July 2025, and their chapters mirror the paragraphs of the Notice, so the depository can read each obligation beside its explanation. They are guidance and not binding rules, yet MAS makes clear that how far a firm observes them can feed into its overall view of the firm, including how well its board and senior management exercise oversight, so in practice they are the benchmark the depository is measured against.
The Guidelines open with the sector’s risk profile, which is distinctive: the depository sits at the top of the holding chain, holding securities as a bare trustee, but it does not trade or move funds, and it deals with most investors only through the brokers and banks that onboard them. The Guidelines confirm that proliferation financing is treated as part of money laundering throughout, and they set out the accountability model, with the board and senior management answerable for AML/CFT effectiveness, supported by the three lines of defence.
On the risk-based approach, the depository must assess its money laundering and terrorism financing risk on an enterprise wide basis, considering its account holder types, the products it supports and its channels, and including any overseas operations where it is part of a group. The enterprise wide assessment must be approved by senior management, should combine qualitative and quantitative analysis, must incorporate the findings of Singapore’s national risk assessments, and should be refreshed when a material change occurs, such as a new type of account or a change in how investors are onboarded.
The customer due diligence chapter is the longest, and it is written around the depository’s place in the chain. It explains identification and verification of an account holder the depository deals with directly, how to treat a person acting for the customer, connected parties and beneficial owners. They explain the identification of beneficial owners, including the commonly applied more-than-25% ownership threshold, while requiring the depository to follow the prescribed ownership and control analysis where ownership is indirect or more complex.
Crucially, it works through reliance: how the depository may depend on an Appendix 2 institution, or a suitably supervised foreign financial institution, that has done the frontline due diligence, what it must satisfy itself of before relying, and why responsibility still rests with the depository.
The enhanced due diligence chapter sets out who counts as a politically exposed person under the FATF standard, and it separates two ideas often run together, source of wealth and source of funds: source of wealth is where the account holder’s whole body of wealth came from, while source of funds is the origin of the assets in the account. The depository should corroborate this in proportion to risk and apply enhanced due diligence where a PEP, a complex structure or a high risk jurisdiction warrants it, with senior approval and closer monitoring. Screening guidance requires account holders and connected parties to be screened and sanctions hits to be frozen or escalated without delay.
The remaining chapters complete the picture. The correspondent accounts chapter sets out the added checks for such relationships; record keeping, suspicious transaction reporting.
The Guidelines state that an STR filing should not exceed five business days after suspicion is first established, except in exceptional or extraordinary circumstances, with a shorter one-business-day expectation for cases involving sanctioned parties.
The chapters on the compliance officer, audit and training complete the operational detail. The PF provisions require the depository to incorporate PF risks into its ML risk assessment and to maintain appropriate controls, including screening against relevant United Nations Security Council designation lists and freezing without delay where required. Throughout, the Guidelines recognise that the depository’s controls are built on identification at onboarding and appropriate reliance, while still requiring ongoing monitoring of business relations and securities activity that may indicate unexplained or suspicious conduct.
A recurring theme is the treatment of the financial institutions listed in the Notice’s Appendix. Dealings with those institutions attract simplified due diligence, because they are themselves regulated for AML/CFT, and the Guidelines explain how the depository should document that treatment and keep it under review rather than apply it mechanically.
On ongoing monitoring, the Guidelines expect the depository to keep its due diligence information current and to watch for a change in the control of an account holder or for a transfer of securities that does not fit the account, escalating what it cannot explain. Read together, the chapters turn a short notice into a practical programme built around identification, reliance and monitoring, in which each control has a defined owner and a place in the depository’s wider governance.
Who Performs Customer Due Diligence in the Securities Holding Chain
Most investors reach the depository through a broker and a bank, so much of the frontline due diligence is done before an account reaches it. The table below shows who checks whom, and where the depository’s own duty bites.
Where the account sits | Who performs the customer due diligence |
Held through a broker (a depository agent) | The broker dealer identifies and verifies the investor at onboarding, so most retail account holders are checked by the broker |
Held through an Appendix 2 institution | The bank or other listed financial institution, itself MAS regulated, performs the due diligence, and the depository may rely on it |
Opened directly with the depository | The depository performs the required customer due diligence itself, the situation MAS Notice SFA 03AA N01 mainly governs |
Settlement of the money | Handled by banks, not the depository, so the depository does not run direct funds transactions with account holders |
Obligations responsibility | Even where it relies on another institution, the depository remains responsible for meeting its own obligations |
Allied Laws Applicable to the Securities Depository in Singapore
These statutes are not primarily AML instruments, but each supports the regime: some define and govern the depository, others give investigators their powers, and others create the predicate offences, and proliferation controls the depository screens against.
The Securities and Futures Act 2001
The statute that defines and governs the depository. Section 81SF sets out what the Depository is, and the Act frames the securities market and the settlement system the depository underpins. It is this definition that brings the depository within Notice SFA 03AA N01 and MAS supervision.
The Companies Act 1967
Singapore’s general company law statute. What matters for AML is its register of registrable controllers regime, mirrored in a central ACRA register, which the depository relies on and verifies when it identifies the controllers of a corporate account holder.
The Monetary Authority of Singapore Act 1970
The Act constituting MAS as Singapore’s central bank and unified financial regulator. It is where MAS draws the authority to supervise the depository and to issue the AML/CFT notices, Notice SFA 03AA N01 among them, that the sector must follow.
The Prevention of Corruption Act 1960
Singapore’s principal anti corruption law. Because corruption is a predicate offence for money laundering, the proceeds of offences under it are part of what the depository looks for in checks on a directly held account, and its presumption on unexplained assets reinforces scrutiny where an account holder’s means cannot be explained.
The Criminal Procedure Code 2010
The procedural code conferring on investigators their powers of production, search and seizure. Served with a production order, or an order relating to an account or the securities in it, the depository must comply, preserve its records and avoid tipping off, which is how an AML investigation reaches into a holding.
The Strategic Goods (Control) Act 2002
Governs the transfer and brokering of strategic and dual use goods, the proliferation financing nexus the depository screens for. Its brokering controls fall away only where a person’s sole role is to provide financing or a financial service, which signals exposure where a corporate account holder’s business touches such trade.
The Biological Agents and Toxins Act 2005
A weapon of mass destruction predicate law barring the nonpeaceful use, production, acquisition or transfer of scheduled biological agents and toxins. For the depository, it is one of the offences its proliferation financing screening watches for, engaged where an account holder connects to prohibited biological weapon activity.
The Chemical Weapons (Prohibition) Act 2000
Singapore’s statute implementing the Chemical Weapons Convention, making it an offence to use, develop, acquire or transfer chemical weapons, on one’s own or through an intermediary. It sits behind the proliferation financing checks the depository runs on its account holders.
Miscellaneous Laws and Regulations Applicable to the Securities Depository in Singapore
These national strategies, committee reports and typologies set the direction of Singapore’s regime and the public private partnership the depository operates within. They carry no binding force, but they direct how MAS supervises and supply many of the typologies the depository builds into its screening.
National Anti Money Laundering Strategy 2024
Singapore’s national AML blueprint, built on the pillars of Prevent, Detect and Enforce. The depository sits within the Prevent pillar, where MAS commits to risk based supervision and to the beneficial ownership transparency the depository relies on for due diligence on a corporate account holder.
National Strategy for Countering the Financing of Terrorism 2024
Updated in 2024 with the terrorism financing risk assessment, this strategy spans five fronts: coordinated risk identification, sound legal and sanctions frameworks, an effective regulatory regime, resolute enforcement and cross border partnership. It signals the direction the depository’s terrorism financing controls should take.
National Asset Recovery Strategy 2024
Singapore’s strategy for locating, seizing and recovering the proceeds of crime, citing billions recovered of late. The depository is a partner in it mainly through its reporting and its cooperation with production orders, since securities held in an account can be the subject of restraint.
Singapore Law Enforcement Strategy to Combat Money Laundering (October 2024)
A joint strategy of Singapore’s money laundering investigation agencies that sets out focus areas and key actions and depends on information moving both ways with financial institutions. It frames the enforcement backdrop the depository supports through its reporting on suspicious accounts and transfers.
Inter Ministerial Committee on Anti Money Laundering Report (October 2024)
The review carried out following a large money laundering case, recommending measures on the misuse of corporate structures, the duties of gatekeepers and improved information sharing. Its themes reach the depository whose account holders include companies and investment vehicles, and it marks the firmer supervisory stance the wider sector now sits under.
Legal Persons: Misuse Typologies and Best Practices (2018)
A typologies paper on the ways companies and partnerships are misused, giving the depository the red flags for beneficial ownership and corporate account holder checks. It is useful where a company or an investment vehicle holds securities through a directly held account.
International Standards Applicable to the Securities Depository in Singapore
Singapore’s regime is built to meet the FATF standards, and Notice SFA 03AA N01 tracks them, including the guidance written for the securities sector. These instruments are the least sector specific of all, yet they explain why the domestic rules look the way they do and hand the depository the typologies and methods supervisors expect it to track.
The FATF Recommendations (updated June 2026)
The 40 Recommendations are the global AML/CFT and counterproliferation standard behind every obligation on the depository, from customer due diligence and beneficial ownership to reliance on third parties, politically exposed persons and suspicious transaction reporting.
Guidance for a Risk Based Approach: Securities Sector (October 2018)
The FATF’s risk based approach guidance written for the securities sector, the most directly applicable international paper here. It works through the sector’s risks, including the layered chain of intermediaries between an investor and the market, and it underpins the reliance model and the proportionate approach Notice SFA 03AA N01 takes.
Methodology for Assessing Technical Compliance and Effectiveness (updated June 2026)
The measure the FATF applies to assess technical compliance with the Recommendations and how well a country’s system works in practice. It sets the benchmark by which Singapore, and by extension its market infrastructure, are measured, and it informs MAS’s supervisory expectations.
Mutual Evaluation Report of Singapore (May 2026)
The 2026 mutual evaluation by the FATF and the Asia/Pacific Group assesses how well Singapore’s regime works in practice. It frames supervisory expectations across the financial sector, including the proportionate expectations placed on market infrastructure such as the depository.
FATF Guidance on Politically Exposed Persons (Recommendations 12 and 22, 2013)
Explains how a firm should pick out politically exposed persons and apply enhanced due diligence to them: senior approval, establishing source of wealth and funds, and closer ongoing monitoring, which the depository applies to a PEP account holder.
Guidance on Beneficial Ownership of Legal Persons (March 2023)
Guidance issued under the revised Recommendation 24 on how to obtain and verify beneficial ownership information, shaping how the depository pins down the beneficial owners of a corporate account holder.
Best Practices on Beneficial Ownership for Legal Persons (October 2019)
A collection of country best practices for keeping beneficial ownership information adequate, accurate and up to date, backing the depository’s use of registries and multiple sources when it identifies the controllers of a corporate account holder.
Risk Based Approach: Beneficial Ownership and Transparency of Legal Arrangements (March 2024)
Guidance focused on Recommendation 25 and trusts and similar arrangements, helping the depository assess and mitigate risk where a trust or similar structure holds securities through an account.
Concealment of Beneficial Ownership (July 2018)
A joint FATF and Egmont Group typologies report on how criminals hide beneficial ownership through intermediaries and structures, giving the depository the red flags to detect concealment behind a corporate account holder.
FATF Guidance on Counter Proliferation Financing (February 2018)
Guidance on carrying out the financial provisions of Security Council resolutions against weapons of mass destruction proliferation, under which the depository must screen and freeze without delay in line with Recommendation 7.
Guidance on Proliferation Financing Risk Assessment and Mitigation (June 2021)
Explains how a firm should assess and mitigate proliferation financing risk following the amendments to Recommendations 1 and 2 that folded it into the sector wide risk assessment duty.
Guidance on Digital Identity (March 2020)
Helps the depository judge whether a digital identity system is reliable and independent enough for customer due diligence under a risk based approach, a question that arises where it opens an account directly online.
Artificial Intelligence and Deepfakes: Impacts on ML/TF/PF
A forward looking FATF scan of how artificial intelligence and deepfakes threaten preventive systems, for example, synthetic identities defeating the remote onboarding of an account holder, alongside AI’s uses in screening and monitoring.
Summary of the Key Instruments
The table below distils the instruments the securities depository relies on most, what type each is, whom it binds, and the core obligation it places on the depository. A brief reference to keep at hand, not a replacement for the fuller sections above.
Instrument | Type | Binds | Core obligation for the depository |
CDSA 1992 | Statute | Everyone | Report suspected criminal proceeds; do not tip off |
TSOFA 2002 | Statute | Everyone | Do not deal in terrorist property; screen and report |
FSM sanctions regulations (DPRK, Iran) | Regulations | All FIs | Freeze designated persons’ assets without delay |
MAS Notice SFA 03AA N01 | Notice (binding) | The Depository | Risk based CDD, reliance, records, STR |
Guidelines to Notice SFA 03AA N01 | Guidelines | The Depository | Primary guidance; how to meet the Notice |
Securities and Futures Act 2001 (s 81SF) | Statute | The Depository | Defines and governs the depository |
FATF Recommendations | Standard | Countries/FIs | The global standard behind the domestic rules |
Conclusion
For the securities depository in Singapore, the anti money laundering framework is real but shaped by its unusual place in the market. The criminal statutes make laundering and terrorism financing offences and require suspicions to be reported; the sanctions regulations require designated parties to be screened out; and Notice SFA 03AA N01 with its Guidelines turns all of this into a working system of risk based due diligence, sound reliance on the brokers and banks in the chain, enhanced measures for higher risk account holders, and suspicious transaction reporting. Because the depository holds securities rather than moving money, its controls rest on who holds each account and on the strength of the checks done before an account reaches it.
The instruments interlock. The depository’s enterprise wide risk assessment draws on the national risk assessments; its due diligence and reliance flow from Notice SFA 03AA N01 and its Guidelines; its very definition comes from the Securities and Futures Act; and its sanctions and proliferation controls draw on the FSM Act sanctions regulations and the FATF standards, including the securities sector guidance. Seeing how the pieces connect is what lets a piece of market infrastructure show that its low residual risk is the product of design, not of chance.
Frequently Asked Questions
MAS Notice SFA 03AA N01 is the anti money laundering and countering the financing of terrorism notice for the Depository, issued under section 16 of the Financial Services and Markets Act 2022 and applying to the Depository as defined under section 81SF of the Securities and Futures Act 2001. It is read together with the Guidelines to Notice SFA 03AA N01, which explain each obligation in turn.
It is the Central Depository, which holds in book entry form, as a bare trustee, the securities traded on the Singapore Exchange. Anyone who trades on the Exchange holds their securities through a depository account, opened alongside a trading account with a broker, so the depository sits at the apex of the securities holding chain.
Not directly. Most investors are onboarded and verified by the brokers and banks through which they hold, and Notice SFA 03AA N01 lets the depository rely on that front line due diligence. The depository performs full customer due diligence itself where it opens an account directly, and it remains responsible for its own obligations even when it relies on another institution.
Singapore’s 2024 assessment rates the sector lower risk. The threat is moderate, because securities markets can be misused internationally, but the vulnerability is very limited: the depository does not trade or move funds directly, every account holder is identified at onboarding, and settlement of money is handled by banks. Its low residual risk is a product of its structure and controls.
No. Notice SFA 03AA N01 has no wire transfer chapter, because the depository holds securities rather than remitting funds; the movement of money on a trade is handled by banks. The Notice does include a correspondent accounts chapter, and the depository’s core duties are customer due diligence, reliance, records and reporting.
Whenever it has reasonable grounds to suspect money laundering or terrorism financing. The report goes to the Suspicious Transaction Reporting Office, generally within five business days of forming the suspicion, and within one business day where sanctions are engaged, and the depository must not tip off the account holder. Our guide to STR red flags explains common triggers.
About the Author
Pathik Shah
FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)
Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.

