MAS AML / CFT for licensed entities — Costs and fees breakdown
MAS AML / CFT for licensed entities is the anti-money-laundering and countering-the-financing-of-terrorism regime that every MAS-regulated financial institution must implement, covering customer due diligence, ongoing monitoring, suspicious transaction reporting and audit. This guide sets out the practical costs, advisory fees and timelines to budget for in 2026.
Raffles Corporate Services works with a panel of corporate and employment law firms; this article is general information, not legal advice.
What the AML / CFT regime requires
MAS AML / CFT for licensed entities is built on the relevant MAS Notices to each class of institution (for example the Notice to capital markets intermediaries and to payment service providers) and the supporting Guidelines. The pillars are risk assessment, customer due diligence (CDD) including beneficial ownership identification, enhanced due diligence for higher-risk customers and politically exposed persons, ongoing transaction monitoring, screening against sanctions and watchlists, suspicious transaction reporting to the Suspicious Transaction Reporting Office, and independent audit.
For a related perspective across the Raffles group, see our guide on Vcc act 2018 section 107 tax treatment for umbrella.
Who must comply
All MAS licence holders – banks, CMS licensees, fund managers, payment institutions under the Payment Services Act 2019, insurers and trust companies – are caught. The depth of controls scales with money-laundering and terrorism-financing risk: a cross-border remittance operator faces a materially heavier monitoring burden than a single-strategy fund manager dealing only with accredited investors.
You may also find our note on Singapore pte ltd company registration for foreigners costs and useful for the wider context.
MAS AML / CFT for licensed entities – core obligations
Each institution must appoint an AML/CFT compliance officer, maintain an enterprise-wide risk assessment, keep records for at least five years, and file suspicious transaction reports. Section 39 of the Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992 establishes the obligation to report suspicion of proceeds of crime, and failure to report is itself an offence. MAS Notices additionally require screening at onboarding and on an ongoing basis.
Refer to the primary sources for the current position: Monetary Authority of Singapore; Singapore Statutes Online.
Cost and timeline breakdown
Costs split between one-off programme build and recurring operating spend (screening tools, name-screening subscriptions, independent audit). Indicative 2026 ranges for a small-to-mid licensed entity are below.
| Item | Indicative fee (S$) | Timeline |
|---|---|---|
| Enterprise-wide AML/CFT risk assessment | S$6,000 – S$15,000 | 2 – 4 weeks |
| Policy suite (CDD/EDD/screening/STR) | S$5,000 – S$12,000 | 2 – 3 weeks |
| Name-screening / monitoring tool | S$3,000 – S$30,000 p.a. | Subscription |
| Staff training programme | S$1,500 – S$5,000 | 1 – 2 weeks |
| Independent AML audit | S$8,000 – S$25,000 | 3 – 6 weeks |
Step-by-step implementation
Sequence: appoint the AML/CFT compliance officer; complete the enterprise risk assessment; write CDD, EDD and screening policies; deploy or subscribe to a name-screening and transaction-monitoring solution; train staff and document the training; remediate any thin legacy files; and commission the first independent AML audit.
For the procedural walkthrough, read our companion article on Mas aml cft for licensed entities step by step.
Common mistakes and gotchas
Recurring weaknesses include screening only at onboarding rather than continuously, treating beneficial ownership as a tick-box, monitoring rules that generate unmanageable false positives, and no independent audit. MAS enforcement actions consistently cite inadequate CDD and late or absent suspicious transaction reports as the most serious failings.
The risk-based approach in practice
MAS expects a risk-based approach: institutions must understand their own money-laundering and terrorism-financing exposure and calibrate controls accordingly. Lower-risk relationships may use simplified due diligence, while higher-risk customers – politically exposed persons, complex ownership structures, or customers in higher-risk jurisdictions – require enhanced due diligence, senior-management approval to onboard, and closer ongoing monitoring. The enterprise-wide risk assessment is the foundation that justifies every control decision, so it should be evidenced and refreshed at least annually.
Beneficial-ownership identification is a recurring area of supervisory attention. Institutions must look through layered ownership to identify the natural persons who ultimately own or control a customer, and document the verification steps taken.
Screening, monitoring and record-keeping
Name screening should run at onboarding and on an ongoing basis against sanctions lists, including those administered under the United Nations Act and MAS regulations, and against adverse-media and PEP databases. Transaction monitoring should be tuned to the institution’s products and customer base so that alerts are meaningful rather than overwhelming. Every CDD record, transaction record and internal escalation must be retained for at least five years and be retrievable for MAS and law-enforcement requests.
Where a suspicion of criminal proceeds arises, a Suspicious Transaction Report is filed with the Suspicious Transaction Reporting Office, and the institution must avoid tipping off the customer.
Building a cost-effective AML programme
For a small licensed entity, the most cost-effective path is a proportionate policy suite, a subscription screening tool sized to transaction volume, a named compliance officer with board access, and an annual independent review. Outsourcing the periodic independent audit to an external specialist is common and usually cheaper than maintaining an in-house second line. The recurring cost is dominated by the screening and monitoring subscription and the independent audit, while the one-off cost is the initial risk assessment, policy build and tooling implementation.
Onboarding workflow that satisfies MAS expectations
A defensible onboarding workflow runs in a fixed sequence: identify and verify the customer and any beneficial owners, screen against sanctions, PEP and adverse-media sources, risk-rate the relationship, apply enhanced due diligence and obtain senior-management approval where the rating is high, and record the rationale. Source-of-wealth and source-of-funds enquiries are central for higher-risk customers and should be evidenced, not merely asserted. Re-screening and periodic review then keep the file current, with review frequency driven by the risk rating.
Embedding this workflow in a checklist or onboarding system reduces the risk of inconsistent files, which is one of the most common supervisory findings.
Governance, training and the compliance officer’s role
The AML/CFT compliance officer should have genuine seniority, independence and direct access to the board, with authority to delay or decline onboarding and to escalate suspicious activity. Annual training tailored to each role – front office, operations and management – keeps awareness current and should be documented with attendance and assessment records. The board should receive periodic AML/CFT reporting covering the risk assessment, alert and report volumes, and audit findings, so that accountability sits at the top of the institution rather than solely with the compliance function.
MAS AML / CFT for licensed entities: key considerations
In summary, MAS AML / CFT for licensed entities is the anti-money-laundering and countering-the-financing-of-terrorism regime that every MAS-regulated financial institution must implement, covering customer due diligence, ongoing monitoring, suspicious transaction reporting and audit. The figures above are indicative for 2026 and should be confirmed against your specific circumstances and the latest official guidance before you commit.
FAQs
Who can be the AML/CFT compliance officer?
A suitably senior and independent person with the authority and resources to act. In a small firm this is often a director, but the role must have genuine standing and direct access to the board.
How long must AML records be kept?
At least five years from the end of the business relationship or the date of the transaction, in line with the MAS Notices.
Is an independent AML audit mandatory?
MAS expects regulated institutions to subject their AML/CFT framework to independent review on a risk-based, periodic basis; for most licensed entities this is effectively an annual or biennial requirement.
What is enhanced due diligence?
Additional measures for higher-risk customers – such as obtaining source-of-wealth and source-of-funds information, senior-management approval, and closer ongoing monitoring – over and above standard customer due diligence.
What is tipping off?
Alerting a customer that a suspicious transaction report has been or may be filed. It is an offence and AML procedures must be designed to prevent it.
Need help with this? Call, SMS or WhatsApp +65 8501 7133, or email [email protected]. Raffles Corporate Services works with a panel of corporate and employment law firms; this article is general information, not legal advice.