Let’s talk

Insights for your business.

MAS AML / CFT for licensed entities , Common mistakes and rejection reasons

Singapore waterfront and business district

MAS AML / CFT for licensed entities means the anti-money-laundering and countering-the-financing-of-terrorism controls MAS requires banks, capital markets services holders, payment institutions and other licensed entities to build into onboarding, monitoring and reporting — gaps here are the single most common reason a licence application stalls or an inspection escalates.

Raffles Corporate Services works with a panel of corporate and employment law firms; this article is general information, not legal advice.

What MAS AML / CFT for licensed entities covers

Every MAS-licensed entity — whether under the Banking Act 1970, the Securities and Futures Act 2001, the Financial Advisers Act 2001, the Trust Companies Act 2005 or the Payment Services Act — is subject to a sector-specific MAS Notice on the Prevention of Money Laundering and Countering the Financing of Terrorism. These Notices give effect, at the regulatory level, to Singapore’s underlying AML/CFT legislation, principally the Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992 and the Terrorism (Suppression of Financing) Act 2002. In practice, the Notice requires customer due diligence (CDD) at onboarding, enhanced due diligence (EDD) for higher-risk customers and politically exposed persons, ongoing transaction monitoring, screening against sanctions and terrorism financing lists, and suspicious transaction reporting to the Suspicious Transaction Reporting Office (STRO). None of this is optional or scalable away for a small licensee — the Notice applies from the date the licence is granted, regardless of headcount or transaction volume.

The Notices have also converged in recent years around a common expectation: that AML/CFT is treated as a first-line business function, not a second-line compliance overlay bolted on after the product is built. That means front-office and onboarding staff are expected to understand red flags well enough to escalate proactively, rather than relying entirely on a compliance team reviewing alerts after the fact. MAS also expects licensees to keep pace with typology guidance it issues periodically — on trade-based money laundering, on the misuse of shell companies, and on emerging risks in digital payment tokens — and to be able to show that the risk assessment has actually been updated to reflect that guidance, not just acknowledged it.

Who this applies to

The AML/CFT Notices apply to every class of MAS licensee that deals with customer funds or customer relationships: banks, merchant banks, capital markets services licence holders (fund managers and broker-dealers), financial advisers, insurers and insurance intermediaries, trust companies, remittance agents and payment institutions. It is not limited to entities handling cash — a fund manager that never touches client money directly is still subject to CDD and STR obligations in respect of its investors, and a payment institution processing purely digital transactions has, if anything, a heavier monitoring burden because of the speed and volume of transactions. Newly licensed fintechs are a particular risk area: many build a customer-facing product first and treat AML/CFT as a compliance add-on, when MAS expects the monitoring architecture to be designed in from the start.

Eligibility and requirements

There is no separate AML/CFT licence — the requirements are conditions of the underlying MAS licence and are assessed both at application and on an ongoing basis. To meet the standard, a licensed entity generally needs: a board-approved AML/CFT policy tailored to its actual business (not a generic template); a documented enterprise-wide risk assessment (EWRA) that identifies its customer, geographic, product and delivery-channel risk; CDD and EDD procedures that are actually followed, with evidence; a transaction monitoring system or manual process proportionate to transaction volume; a designated AML/CFT compliance officer with the authority and access to escalate; and periodic independent testing of the AML/CFT programme, typically via internal audit. MAS routinely asks for the EWRA and the compliance officer’s reporting line as part of a new licence application, and gaps here are a common cause of a first-round query.

Evidence MAS typically asks to see, roughly in order of frequency at inspection: the enterprise-wide risk assessment itself, with a visible methodology rather than a bare risk rating; the board or risk-committee minute approving the AML/CFT policy; a sample of onboarding files showing CDD (and EDD where triggered) was actually completed before the relationship went live; the compliance officer’s job description and reporting line, showing genuine authority to escalate or block; screening logs showing sanctions and PEP checks at onboarding and periodically thereafter; and the independent testing report from the most recent cycle, together with evidence that findings were remediated. A programme that exists only as a policy document, with no EWRA, no onboarding evidence and no independent testing behind it, is treated by MAS as effectively theoretical.

Cost and timeline

Building a proportionate AML/CFT programme — policy, EWRA, CDD/EDD procedures and a monitoring approach — typically costs S$12,000 to S$40,000 in professional fees for a small-to-mid-sized licensed entity, rising toward S$60,000 or more where a dedicated transaction monitoring system needs to be licensed and configured. Ongoing costs for ongoing screening subscriptions, periodic EWRA refreshes and independent testing typically run S$10,000 to S$25,000 per year. On timeline, drafting and board-adopting the policy and EWRA typically takes 6 to 8 weeks; building or configuring a monitoring system adds a further 4 to 10 weeks depending on whether it is a manual process or a licensed software solution; and MAS’s review of AML/CFT documentation submitted with a licence application typically adds 4 to 8 weeks to the overall approval timeline, with an additional 3 to 6 weeks if the first submission is incomplete.

Step-by-step process

1. Complete an enterprise-wide risk assessment covering customer type, geography, products and delivery channels before drafting the policy — MAS expects the policy to follow from the risk assessment, not the reverse. 2. Draft a board-approved AML/CFT policy that names the compliance officer, sets CDD and EDD triggers, and sets escalation and reporting lines. 3. Build or licence a screening and monitoring capability proportionate to expected transaction volume, including sanctions and PEP screening at onboarding and on an ongoing basis. 4. Document CDD procedures with clear evidence requirements (identity verification, source of wealth for higher-risk customers, beneficial ownership identification). 5. Train staff who handle onboarding and monitoring, and keep training records. 6. Test the suspicious transaction reporting pathway internally so that a genuine STR can reach STRO without delay. 7. Commission independent testing of the whole programme on a rolling basis (annually is standard) and remediate findings before the next cycle, keeping the paper trail.

Where the licensed entity is structured through a regulated fund vehicle, the beneficial ownership and legal-personality analysis often needs to align with the vehicle’s own constitutional position — see our related guide on the VCC Act 2018 — Section 17 legal personality — eligibility and requirements checklist for how a Variable Capital Company’s legal personality affects CDD and beneficial-ownership analysis for its sub-funds.

How MAS reviews AML/CFT at licensing and at inspection

At licensing stage, MAS reviewers typically cross-check the AML/CFT policy against the business plan submitted for the licence — a payment institution proposing to serve high-risk corridors with a policy that has no EDD provisions for those corridors, for example, will usually generate a query before the application progresses further. At inspection, examiners generally start from a sample of customer files rather than the policy document itself: they pick a handful of onboarding files, often weighted toward higher-risk customers, and trace the CDD, screening and (where relevant) EDD evidence for each one. Where the sampled files do not show what the policy says should have happened, the inspection typically widens to a larger file sample rather than stopping at the original few, because the examiner can no longer rely on the licensee’s self-assessment of its own compliance.

Board and senior management engagement is tested in a similar way to the policy itself: MAS does not expect directors to perform CDD personally, but it does expect them to be able to describe, without prompting, the licensee’s two or three highest AML/CFT risk areas and what management is doing about them. A board pack that discusses AML/CFT only as a single line item once a year, with no discussion of the EWRA’s actual conclusions, is a recurring theme in post-inspection findings letters.

Common mistakes and rejection reasons

The most common reason an AML/CFT submission is queried, or an inspection finding is raised, is a policy that reads well but does not match what onboarding staff actually do — CDD checklists that are not followed for lower-value customers, EDD triggers that exist on paper but are never actually applied to PEPs, or a risk assessment that was drafted once at licensing and never refreshed as the customer base changed. Other recurring issues: a compliance officer named on paper who has no real authority to block onboarding or freeze a relationship; screening that covers sanctions lists but omits PEP or adverse media screening; monitoring alerts that are generated but not actually reviewed within a reasonable time; and no STR filed in years despite an obviously higher-risk customer base, which examiners treat as a sign the monitoring system is not working rather than a sign of a clean book. Beneficial ownership analysis is a particular weak point — failing to look through nominee or corporate shareholders to the individuals who ultimately control a customer is one of the most frequently cited findings in MAS inspection reports, and the underlying register obligations are closely related to the Register of Registrable Controllers (RORC) requirements that apply to the corporate customer itself.

A further cluster of findings relates to governance rather than technique: AML/CFT policies inherited wholesale from a regional or group parent that reference thresholds, systems or reporting lines the Singapore entity does not actually have; risk assessments that were completed once at incorporation and never revisited even after the customer book shifted toward higher-risk jurisdictions; and independent testing that is commissioned from a firm with no real AML/CFT expertise, producing a report that reads as a formality rather than a genuine challenge. Examiners are quick to spot template language, and a programme that visibly does not match the licensee’s actual customer base and transaction profile tends to widen the scope of the wider review rather than being treated as an isolated gap.

Numerical specifics at a glance

FAQs

Does MAS AML / CFT for licensed entities apply to a fund manager that never touches client money?
Yes — CDD, EDD and STR obligations attach to the customer relationship (including fund investors), not to whether the licensee physically holds client funds.

How often should the enterprise-wide risk assessment be refreshed?
MAS expects the EWRA to be a living document, refreshed at least annually and whenever the customer base, products or geographic footprint changes materially.

What counts as enhanced due diligence?
EDD typically means additional identity verification, source of wealth and source of funds enquiry, senior management sign-off on onboarding, and more frequent ongoing monitoring — applied to higher-risk customers, PEPs and higher-risk jurisdictions.

Can a small payment institution outsource its transaction monitoring?
Yes, but the licensee remains responsible for the outcome and must be able to demonstrate that the outsourced monitoring is properly calibrated and reviewed — outsourcing does not transfer regulatory accountability.

What happens if a suspicious transaction is not reported?
A failure to file an STR where one was warranted is treated as a serious standalone compliance failure and is a common trigger for a full AML/CFT inspection, independent of any underlying criminal conduct by the customer.

Does the compliance officer need to be a separate full-time role?
Not necessarily for a small licensee, but the individual must have sufficient seniority, independence from the business lines they oversee, and enough time and authority to actually perform the role — a nominal appointment with no real capacity is a recurring inspection finding.

Related guides

See also our companion guide on MAS AML / CFT for licensed entities — Documents required and templates for the specific policy, EWRA and CDD templates MAS expects to see.

For the regulatory basis of these obligations, see MAS’s own Anti-Money Laundering and Countering the Financing of Terrorism page. The Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992 and the Terrorism (Suppression of Financing) Act 2002 form the statutory basis for Singapore’s AML/CFT regime, which MAS gives effect to through sector-specific Notices issued under the Banking Act 1970, the Securities and Futures Act 2001, the Financial Advisers Act 2001 and the Trust Companies Act 2005; see the Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992 and the Terrorism (Suppression of Financing) Act 2002 on the Singapore Statutes Online portal.

Need help with this? Call, SMS or WhatsApp +65 8501 7133, or email [email protected]. Raffles Corporate Services works with a panel of corporate and employment law firms; this article is general information, not legal advice.

Submit a Comment

Your email address will not be published. Required fields are marked *

Real people. Right here in Singapore.

Let’s get to work.

Hop on Raffles Corporate Services