Let’s talk

Insights for your business.

MAS AML/CFT for Licensed Entities: Frequently Asked Questions

MAS AML / CFT for licensed entities refers to the anti-money laundering and countering the financing of terrorism obligations that the Monetary Authority of Singapore imposes on banks, capital markets services licence holders, fund managers and other regulated financial institutions. This FAQ works through the questions compliance officers and directors most often ask when building or reviewing an AML/CFT programme.

Almost every licensed entity in Singapore, whether a bank, a licensed fund management company, a payment institution or a trust company, eventually has to answer the same practical questions: which notice actually applies to us, what does “risk-based” mean in practice, how often does the risk assessment need refreshing, and what happens when a transaction monitoring alert cannot be resolved cleanly. This article is organised as a reference FAQ rather than a walkthrough of what goes wrong (we cover that angle separately), so that a compliance officer, MLRO or director can find a direct answer to a specific question without re-reading an entire policy manual.

What does MAS AML/CFT actually require, at a framework level?

At its core, the MAS AML/CFT framework requires a licensed entity to know its customers, assess and understand the money laundering and terrorism financing risks it faces, and put in place controls proportionate to those risks. The detailed requirements are set out in entity-specific MAS notices rather than in a single overarching statute. For banks, the relevant instrument is MAS Notice 626 on Prevention of Money Laundering and Countering the Financing of Terrorism (last revised 28 March 2024), which sets out requirements on customer due diligence, reliance on third parties, correspondent banking, record keeping and suspicious transaction reporting. Other licence classes are subject to their own equivalent notices (for example, capital markets services licence holders and fund managers are subject to notices issued under the Securities and Futures Act framework), which mirror the same broad architecture even though the notice numbers differ.

Sitting above these entity-specific notices is Singapore’s broader financial regulatory architecture, including the Financial Services and Markets Act 2022, which consolidates MAS’s cross-sectoral powers over financial institutions and designated persons. The Act does not replace the entity-specific AML/CFT notices; it works alongside them as part of MAS’s overall supervisory toolkit.

Who counts as a “licensed entity” for this purpose?

The obligations apply to entities holding a licence, registration or exemption administered by MAS: banks and merchant banks, finance companies, licensed and registered fund managers, capital markets services licence holders, payment institutions licensed under the Payment Services Act 2019, insurers and insurance intermediaries, and trust companies. A common misconception is that smaller registered fund managers or exempt entities are somehow outside scope because they are not “fully licensed” in the way a bank is. In practice, registration and many forms of exemption still come with AML/CFT obligations attached, calibrated to the size and risk profile of the entity rather than waived altogether.

What does a risk-based approach mean in day-to-day terms?

A risk-based approach means the intensity of due diligence and ongoing monitoring should scale with the assessed risk of the customer, product, delivery channel and jurisdiction involved, rather than applying one uniform standard to every relationship. A licensed entity is expected to conduct an enterprise-wide risk assessment covering these four dimensions, and then calibrate its customer due diligence tiers (standard, simplified, enhanced) accordingly. A politically exposed person, a customer from a higher-risk jurisdiction, or a complex ownership structure will typically trigger enhanced due diligence, including closer scrutiny of source of wealth and source of funds, more senior sign-off, and more frequent periodic review. A long-standing local retail customer transacting through normal channels will typically sit at standard or simplified due diligence.

The enterprise-wide risk assessment itself is not a one-off document. It is generally expected to be refreshed periodically, commonly annually for higher-risk entities and at least every two to three years for lower-risk ones, and whenever a material change occurs, such as launching a new product line, entering a new jurisdiction, or a material shift in customer base.

How much does building an AML/CFT programme cost, and how long does it take?

There is no MAS licensing fee attached specifically to AML/CFT compliance; the cost lies in building and maintaining the programme itself. For a small to mid-sized licensed fund manager or payment institution building an AML/CFT framework from scratch, a typical engagement covering an enterprise-wide risk assessment, customer due diligence policy, transaction monitoring procedures and a compliance manual runs from around S$8,000 to S$22,000, depending on business complexity, and takes approximately 6 to 10 weeks from kick-off to a board-approved policy suite. Ongoing costs, including ongoing customer due diligence refreshes, transaction monitoring system fees (where a dedicated system is used rather than manual review) and annual independent AML/CFT audits, are typically budgeted as a recurring compliance cost rather than a one-off project. An independent audit of the AML/CFT programme, which many licence classes are expected to commission periodically, commonly takes 3 to 5 weeks from fieldwork to final report for a firm of moderate size.

These figures are indicative planning estimates only; actual cost and timeline depend heavily on transaction volumes, customer base and whether a firm already has a functioning compliance function to build on.

What are the key ongoing obligations once the programme is live?

Once a programme is in place, the recurring obligations generally include: conducting customer due diligence at onboarding and on a periodic basis thereafter, calibrated to risk rating; screening customers and, where relevant, beneficial owners against sanctions and PEP lists at onboarding and on an ongoing basis; monitoring transactions for patterns inconsistent with the customer’s expected profile; filing suspicious transaction reports with the Suspicious Transaction Reporting Office where the statutory suspicion threshold is met; maintaining records of customer identification and transaction data for the retention period set out in the applicable notice; and providing AML/CFT training to relevant staff, typically refreshed annually. Senior management is expected to receive periodic reporting on the effectiveness of the programme, not simply a confirmation that policies exist.

What triggers a suspicious transaction report, and who decides?

A suspicious transaction report is triggered when an employee, having applied the relevant customer due diligence and having considered the context of the transaction, forms a suspicion that funds may be connected to criminal conduct, regardless of the transaction amount. There is no minimum dollar threshold below which suspicion can be disregarded; a S$500 transaction can be just as reportable as a S$5,000,000 one if the surrounding facts are suspicious. The decision to file typically sits with the MLRO or a designated compliance officer, not with the frontline relationship manager who first noticed the pattern, precisely so that the assessment is made independently of any commercial relationship with the customer. Internal escalation procedures should make clear how quickly a frontline concern needs to reach the MLRO, since delay in escalation is one of the more common findings raised in supervisory reviews.

Common mistakes worth knowing about before they happen

A handful of issues recur across licence classes: risk assessments that were completed once at licensing and never refreshed; due diligence files that record a customer’s stated occupation and income but never reconcile it against the actual transaction volumes flowing through the account; and reliance on a group entity’s KYC without verifying that the group entity’s standards actually meet the Singapore notice’s requirements. None of these are exotic problems, and all are readily fixable once flagged, which is exactly the ground covered in more procedural depth in our companion article on MAS AML/CFT for licensed entities: common mistakes and rejection reasons, which takes a mistakes-first approach rather than the FAQ format used here.

What should the compliance function actually look like day to day?

Boards and founders often ask what a functioning AML/CFT compliance function looks like in practice, as opposed to on paper. At a minimum, most licensed entities need: a designated MLRO with sufficient seniority and independence to challenge business decisions; a documented enterprise-wide risk assessment refreshed on the cycle described above; onboarding procedures that actually capture and verify beneficial ownership, not just the name of the immediate account holder; a transaction monitoring process, whether automated or manual, with documented alert-clearing procedures; a record-keeping system that can produce a complete customer file on request, typically within the retention period set by the applicable notice (commonly five years from the end of the business relationship); and an annual or periodic independent review of the whole programme, whether by internal audit, external audit, or a qualified external compliance consultant.

Smaller entities frequently combine the MLRO role with another compliance or operations function, which is generally acceptable provided the individual has enough seniority and time allocated to the role that AML/CFT does not become an afterthought squeezed between other duties. What examiners and institutional counterparties look for is evidence that the MLRO actually reviews alerts and escalations, rather than a title on an organisation chart with no supporting activity log.

What happens during a MAS inspection focused on AML/CFT?

A MAS thematic or full-scope inspection touching AML/CFT typically starts with a request for the enterprise-wide risk assessment, the AML/CFT policy manual, a sample of customer due diligence files (often skewed towards higher-risk customers), transaction monitoring alert logs, and any suspicious transaction reports filed in the review period. Inspectors then test whether the documented policy was actually followed in practice: does the file for a politically exposed person actually show enhanced due diligence was performed, or does it just tick a box marked “PEP: yes” with no further detail? Was source of wealth documentation collected and does it plausibly match the transaction volumes seen on the account? Common findings include due diligence files that are internally inconsistent, risk assessments that have not been updated to reflect a change in business (a new product line, a new customer segment, entry into a higher-risk jurisdiction), and gaps between what the training records say staff were taught and what frontline staff can actually demonstrate they understand when asked.

Where findings are identified, MAS typically issues a set of remediation actions with a timeline, rather than moving straight to enforcement, except in cases involving serious or wilful non-compliance. The remediation period is usually where the real cost of a weak programme becomes visible, since fixing historical files retroactively is far more expensive than building the controls correctly the first time.

How does this connect to fund structures and onboarding more broadly?

AML/CFT obligations do not sit in isolation from the rest of a fund manager’s or licensed entity’s operational surveillance and onboarding architecture. A manager that has just tightened its AML/CFT transaction monitoring, for instance, will often find the same underlying data and alerting infrastructure is relevant when it needs to investigate a trade surveillance alert for a VCC, since both processes depend on having clean, well-tagged transaction data to work from. Similarly, the customer due diligence file built during AML/CFT onboarding overlaps significantly with the documentation a Singapore-incorporated entity needs when it is first set up. Our guide on Singapore Pte Ltd company registration for foreigners: common mistakes and rejection reasons is a useful companion for founders who are setting up the underlying corporate vehicle at the same time as building out their compliance function.

FAQs

Is there a single “AML/CFT Act” in Singapore that applies to all licensed entities?
Not in the sense of one consolidated statute. The detailed AML/CFT requirements sit in entity-specific MAS notices (such as Notice 626 for banks), issued under the relevant sectoral legislation for each licence class, with the Financial Services and Markets Act 2022 providing part of the overarching regulatory architecture MAS operates under.

Does a registered fund management company need the same AML/CFT programme as a bank?
The underlying principles (risk-based due diligence, screening, monitoring, reporting) are the same, but the scale and sophistication of the programme should be proportionate to the size, complexity and risk profile of the entity. A small RFMC with a handful of accredited investor clients will have a lighter programme than a retail bank, but it cannot have no programme at all.

How often should customer due diligence be refreshed for existing clients?
This depends on the customer’s risk rating. Higher-risk customers are typically reviewed annually, while lower-risk customers may be reviewed on a longer cycle, commonly every two to three years, or immediately upon a material change in circumstances.

Can AML/CFT compliance be fully outsourced to a third party?
Day-to-day tasks such as screening and monitoring can be outsourced or supported by a vendor, but ultimate responsibility for the adequacy of the AML/CFT programme remains with the licensed entity’s board and senior management; outsourcing the task does not outsource the accountability.

What is the practical difference between simplified and enhanced due diligence?
Simplified due diligence applies to lower-risk relationships and involves a lighter verification and monitoring standard, while enhanced due diligence applies to higher-risk relationships (PEPs, higher-risk jurisdictions, complex structures) and requires additional steps such as senior management approval, deeper source of wealth verification, and more frequent ongoing monitoring.

Related reading

For the mistakes-first companion to this FAQ, see MAS AML/CFT for licensed entities: common mistakes and rejection reasons. For fund managers building out trade surveillance capability alongside AML/CFT monitoring, see investigating a trade surveillance alert for a VCC. For founders setting up the underlying corporate vehicle, see Singapore Pte Ltd company registration for foreigners: common mistakes and rejection reasons. The relevant MAS notices are published on the Monetary Authority of Singapore website, and the underlying legislation can be traced on Singapore Statutes Online.

Need help with this? Call, SMS or WhatsApp +65 8501 7133, or email [email protected]. Raffles Corporate Services works with a panel of corporate and employment law firms; this article is general information, not legal advice.

Submit a Comment

Your email address will not be published. Required fields are marked *

Real people. Right here in Singapore.

Let’s get to work.

Hop on Raffles Corporate Services