MAS AML / CFT for licensed entities — Eligibility and requirements checklist

Published on: 27 Jul, 2026

MAS AML / CFT for licensed entities — Eligibility and requirements checklist

Raffles Corporate Services works with a panel of corporate and employment law firms; this article is general information, not legal advice.

MAS AML / CFT for licensed entities is the set of anti-money-laundering and countering-the-financing-of-terrorism obligations that every MAS-regulated firm must operationalise. In practice it means a risk-based programme covering customer due diligence, ongoing monitoring, screening, suspicious transaction reporting and record-keeping, owned at board level and evidenced to a supervisor on demand.

What MAS AML / CFT for licensed entities requires

The regime is built on the relevant MAS Notices on the prevention of money laundering and financing of terrorism, issued to each licensed population — fund managers, capital markets services holders, payment institutions, banks and insurers. The common backbone is a documented enterprise-wide risk assessment, customer due diligence proportionate to risk, screening against sanctions and politically-exposed-person lists, transaction monitoring, and prompt reporting of suspicious activity. A named compliance officer and independent audit complete the picture.

Who must comply

All MAS licensees and registered entities carrying on a regulated activity are in scope, from a single-strategy fund manager to a multi-service payments firm. The obligations scale with risk: a firm onboarding high-net-worth clients across multiple jurisdictions faces deeper due diligence than one serving a narrow domestic base. New applicants should expect MAS to review the AML / CFT programme as part of the licensing assessment.

Eligibility and requirements checklist

  • A board-approved AML / CFT policy and enterprise-wide risk assessment, refreshed at least annually.
  • An appointed AML / CFT compliance officer with sufficient seniority and independence.
  • Customer due diligence procedures, including identification and verification of beneficial owners.
  • Enhanced due diligence triggers for high-risk clients and politically exposed persons.
  • Automated sanctions and adverse-media screening at onboarding and on an ongoing basis.
  • Transaction monitoring rules calibrated to your client and product risk.
  • A suspicious transaction reporting process linked to the Suspicious Transaction Reporting Office.
  • Record retention for at least 5 years after a transaction or the end of a relationship.
  • Staff training on a recurring schedule, with attendance records.
  • Independent audit or assurance of the programme.

Cost, timeline and thresholds — the numbers

Building a defensible programme usually takes 2 to 4 months for a new licensee. First-year costs commonly run S$20,000 to S$50,000 for policy design, screening tooling and independent review, with screening subscriptions from S$3,000 per year. MAS Notices require records to be kept for a minimum of 5 years. Customer due diligence is mandatory before establishing a business relationship, and enhanced measures apply above risk thresholds you define in your risk assessment. Suspicious transaction reports must be filed without undue delay once suspicion is formed.

Statutory anchors

Section 39 of the Corruption, Drug Trafficking and Other Serious Crimes Act 1992 establishes the duty to report suspicious transactions and makes failure to report an offence, which is why your reporting workflow must be robust. Section 27B of the Monetary Authority of Singapore Act 1970 empowers MAS to issue the binding AML / CFT Notices that set out customer due diligence and record-keeping standards. Neither obligation can be delegated away to a service provider.

Common mistakes and gotchas

The classic error is a generic, off-the-shelf policy that does not reflect the firm’s actual clients and products, which a supervisor spots quickly. Others include weak beneficial-ownership tracing, screening only at onboarding rather than continuously, and treating the compliance officer role as a part-time formality. Firms serving international clients frequently underestimate cross-border complexity — before onboarding, it is worth checking whether the client’s chosen structure even fits, for example by reading when a Singapore VCC is the wrong vehicle. Banking friction is another surprise; our guide to Singapore bank account opening across DBS, OCBC, UOB, Wise and Aspire explains what banks now ask of licensed applicants.

How the process runs step by step

Begin with the enterprise-wide risk assessment, because it drives every downstream control. Draft policies and procedures, appoint and empower the compliance officer, implement screening and monitoring, and train staff. Then commission an independent review and capture the findings in board papers. Timelines and benchmarks for the operational side are covered in our companion piece on MAS AML / CFT for licensed entities — timeline and processing benchmarks.

FAQs

Do I need a full-time compliance officer? Not always. Smaller firms can appoint a suitably senior person with a defined mandate, but the role must be genuine, independent and resourced, not a title in name only.

How long must AML records be kept? The MAS Notices require retention for at least 5 years after the transaction or the end of the business relationship, and longer if a matter is under investigation.

When must a suspicious transaction be reported? As soon as suspicion is formed, without undue delay, to the Suspicious Transaction Reporting Office. Tipping off the customer is an offence.

Can I outsource AML screening? You can use vendors for screening and monitoring, but accountability, decision-making on alerts and reporting stay with the licensed entity.

Calibrating customer due diligence to real risk

A credible programme distinguishes between low-risk and high-risk relationships rather than applying one blunt standard. Simplified measures may suit low-risk domestic clients, while enhanced due diligence, senior sign-off and closer monitoring apply to politically exposed persons, complex ownership chains and higher-risk jurisdictions. The Monetary Authority of Singapore expects the depth of due diligence to track the risk you have documented, so your enterprise-wide risk assessment must genuinely drive onboarding decisions.

Ongoing monitoring and screening

Onboarding is only the start. Transactions should be monitored against rules calibrated to client and product risk, and screening against sanctions and adverse-media lists should run continuously, not just at account opening. Periodic reviews refresh customer information at a frequency set by risk rating. Alerts must be investigated, decisions recorded, and genuine suspicions escalated promptly. The Acts underpinning these duties are published on Singapore Statutes Online, the authoritative source for the legislation cited here.

Independent assurance and governance

MAS looks for a compliance function with real authority and an independent audit that tests whether the programme works in practice. The compliance officer should report to the board or a board committee, not only to the business line whose activity they police. An annual independent review, with findings tracked to closure, gives the board the assurance it needs and gives a supervisor confidence that the framework is more than paperwork.

Need help with this? Call, SMS or WhatsApp +65 8501 7133, or email [email protected]. Raffles Corporate Services works with a panel of corporate and employment law firms; this article is general information, not legal advice.