Payment Services Licenses

Published on: 9 Jul, 2025

The Monetary Authority of Singapore (MAS) issues Payment Services Act (PS Act) licenses for persons conducting payment services in Singapore, unless exempted.

 

There are three types of licenses under the PS Act:

  • Money-Changing (MC) licence
  • Standard Payment Institution (SPI) licence
  • Major Payment Institution (MPI) licence

An applicant should choose the license type that accommodates its business needs over a reasonable timeframe. A licensee must apply for a variation or change of license in Form 2 if it intends to add or remove any payment service, or change its license type. Approval must be obtained prior to commencing business of any new payment service or under the new license type. For instance, an MC licensee needs to apply to change its licence to an SPI or MPI licence to conduct any additional payment service.

 

Payment Services Covered by the PS Act The PS Act’s First Schedule outlines seven types of payment services:

  • Account Issuance Service (Activity A): This involves issuing a payment account or services related to operating a payment account, such as an e-wallet or a non-bank issued credit card.
  • Domestic Money Transfer Service (Activity B): This covers providing local funds transfer services in Singapore, including payment gateway services and payment kiosk services.
  • Cross-border Money Transfer Service (Activity C): This involves providing inbound or outbound remittance services in Singapore, as well as facilitating remittance between entities in different countries even if monies are not accepted or received in Singapore.
  • Merchant Acquisition Service (Activity D): This is where a service provider processes payment transactions from a merchant and processes payment receipts on behalf of the merchant, often including point-of-sale terminal or online payment gateway services.
  • E-money Issuance Service (Activity E): This entails issuing e-money for user payments to merchants or transfers to other individuals.
  • Digital Payment Token Service (Activity F): This involves buying or selling digital payment tokens (DPTs, commonly known as cryptocurrencies), providing a platform for DPT exchange, transmitting or arranging DPT transmission, offering custodian wallet services for DPTs, or actively facilitating DPT buying or selling without possessing monies or DPTs.
  • Money-Changing Service (Activity G): This specifically covers buying or selling foreign currency notes.

 

Admission Criteria and Ongoing Requirements for Licensees Applicants must meet specific criteria and demonstrate ongoing compliance with the PS Act obligations. These include:

  • Governance and Ownership Requirements: The applicant must comply with the governance and ownership structure detailed in Appendix 1 of the guidelines and be registered with ACRA. For a Money-Changing Licence, a sole-proprietor must be a Singapore citizen with at least 1 year of relevant experience, and for partnerships/LLPs, the majority of partners should be Singapore citizens, each with at least 1 year of relevant experience. For SPI/MPI licences, director requirements are specified for Singapore-incorporated companies.
  • Fit and Proper: The applicant must satisfy MAS that its sole-proprietor, partners, directors, CEO, shareholders, and employees are fit and proper. The entity and its related group should not have an adverse reputation, especially concerning financial crime.
  • Competency of Key Individuals: Sole-proprietors, partners, executive directors, and the CEO must have sufficient experience in the payment services industry or related financial services, including understanding Singapore’s regulatory framework.
  • Base Capital: SPI applicants require S$100,000, while MPI applicants need S$250,000.
  • Security (for MPIs): MPI applicants must provide security before commencing business, which can be a cash deposit with MAS or a bank guarantee. The security amount is S$100,000 if monthly transaction values do not exceed S$6 million for any one payment service, and S$200,000 in all other cases.
  • Compliance Arrangements: The applicant must have effective compliance arrangements and adequate resources commensurate with its business. This may include an independent compliance function and a suitably qualified compliance officer at the management level. For DPT services, an in-house local compliance officer is generally required due to higher risk and complexity.
  • Technology Risk Management: If providing online financial services, a penetration test must be completed before the license is granted, with all high-risk findings remediated and validated. Licensees offering DPT services must comply with the Notice on Technology Risk Management (FSM-N13) from November 6, 2024. All other licensees should refer to the Guidelines on Risk Management Practices – Technology Risk.
  • Audit Arrangements: Plans for adequate independent audit arrangements are necessary to regularly assess procedures, controls, and compliance. Annually, a licensee must appoint an auditor to audit accounts, transactions, and compliance, with a report submitted to MAS in Form 4.
  • Legal Opinion: New SPI or MPI applicants must submit a legal opinion from a law firm experienced in the PS Act, summarising the business model and assessing whether proposed services are regulated. This is also required for existing licensees adding DPT services. MAS may request a second legal opinion if needed.
  • External Auditor’s Independent Assessment (for new DPT service applicants): These applicants must appoint a qualified independent External Auditor to assess AML/CFT and Consumer Protection policies, procedures, and controls. The report is due with the application form.
  • Letter of Responsibility and/or Undertaking: MAS may require these from majority shareholders, parent companies, or related companies.
  • Other Factors: MAS considers track record and financial condition of the applicant and its holding company, whether the public interest will be served, and the commitment of the holding company to Singapore operations.

 

Ongoing compliance obligations also include Anti-Money Laundering and Countering the Financing of Terrorism (AML/CFT) requirements, periodic regulatory returns, and cyber hygiene measures. Businesses registered under the GST InvoiceNow Requirement must obtain a Peppol ID to transmit invoice data to IRAS.