MAS AML / CFT for licensed entities — Complete 2026 guide

Published on: 3 Jun, 2026

MAS AML / CFT for licensed entities — Complete 2026 guide

MAS AML / CFT for licensed entities is the framework that every Singapore-licensed financial institution must implement to prevent money laundering, terrorist financing and proliferation financing. It sits across a stack of MAS Notices — 626 for banks, SFA 04-N02 for capital markets services holders, PSN01 and PSN02 for payment institutions — and an overarching set of Guidelines on Risk Management Practices. This 2026 guide explains what is expected, the cost and timeline of building a compliant programme, and the most common audit findings.

Raffles Corporate Services works with a panel of corporate and employment law firms; this article is general information, not legal advice.

What MAS AML / CFT covers

MAS AML / CFT obligations rest on five core duties: identifying and verifying customers (CDD), monitoring ongoing transactions, screening against sanctions and PEP lists, reporting suspicious transactions to the Suspicious Transaction Reporting Office (STRO), and maintaining records for at least five years. Each licence class has a dedicated MAS Notice setting out detailed expectations, and the Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992 (CDSA) creates the underlying criminal offence for failing to report.

The Terrorism (Suppression of Financing) Act 2002 reinforces these duties, with Section 8 of the Terrorism (Suppression of Financing) Act 2002 making it an offence to fail to disclose information that may assist in preventing terrorist financing.

Who is in scope

Every MAS-licensed or registered entity is in scope: banks, finance companies, merchant banks, insurers, capital markets services licensees, registered fund managers, payment service providers, trust companies, and external asset managers operating under exemption. The 2024 Single Family Office (SFO) framework extended AML expectations to the manager of the family office where it advises 13O / 13U funds — a point many family offices missed in their first compliance build.

For sponsors using a Variable Capital Company structure, the manager (not the VCC) is the regulated entity for AML purposes. The companion guide at VCC Act 2018 — Part 13 inward and outward redomiciliation — Complete 2026 guide covers the VCC framework in full; the AML uplift sits on top of it.

The risk-based approach

MAS expects firms to implement a risk-based approach (RBA). Each customer, product, geography and channel is scored, and the depth of CDD scales with the score. A retail Singapore citizen buying a unit trust through a face-to-face branch sits at the low end; a non-resident corporate structured through three layers of offshore vehicles purchasing a complex derivative sits at the high end. Enhanced Due Diligence (EDD) is mandatory for politically exposed persons, customers from higher-risk jurisdictions on FATF lists, and any customer whose risk score crosses the firm’s documented threshold.

Cost and timeline for the AML programme

For a new boutique licensee, a defensible AML / CFT programme costs S$60,000 to S$150,000 in year one. The major lines are roughly S$15,000 to S$30,000 for a risk assessment and policy suite, S$25,000 to S$60,000 for screening and transaction monitoring tooling, S$10,000 to S$25,000 for an independent compliance review, and ongoing S$30,000 to S$80,000 per annum for a dedicated MLRO or outsourced compliance officer. Larger firms with cross-border customer books regularly spend 10–20 times this.

Timeline: 10 weeks to a board-approved policy suite, six months to a tested first line of defence, and one full annual cycle (12 months) before internal audit can give a clean assurance opinion.

Step-by-step: building the AML / CFT framework

Step one is the Enterprise-Wide Risk Assessment (EWRA). It maps customers, products, channels and geographies onto a risk matrix and is refreshed at least annually. Step two is the policy suite — AML / CFT policy, sanctions policy, CDD procedures, EDD procedures, STR procedures, training policy. Step three is tooling: a name screening engine running daily against the UN Security Council Consolidated List, OFAC SDN, EU Restrictive Measures and any commercial PEP database; and a transaction monitoring system with rules calibrated to the firm’s products. Step four is appointment of the Money Laundering Reporting Officer (MLRO), who must have direct reporting access to the board.

Firms onboarding in Singapore should also review Understanding Drag-Along Rights in Singapore Shareholder Agreements (2026) for the underlying corporate structure, and our existing analysis at MAS streamlined fund manager framework 2026 — Complete 2026 guide for related MAS framework changes.

Common mistakes

The most common deficiencies MAS finds at inspection are: stale risk assessments (more than 12 months old), CDD files missing source-of-wealth evidence for high-risk customers, screening rules that have not been recalibrated since go-live, ongoing monitoring rules that have generated thousands of unactioned alerts, training that is generic e-learning with no role-specific content, and an MLRO who lacks board access. Each of these can result in supervisory action or a financial penalty.

Sanctions screening — the non-negotiable

Sanctions screening is the one area where there is no risk-based reduction. Every customer, beneficial owner and counterparty must be screened against sanctions lists at onboarding and on each list update. Singapore implements UN Security Council sanctions via the United Nations Act 2001 and various subsidiary regulations. Failure to screen, or sanctioned hits not properly cleared and documented, is a strict-liability area in supervisory practice.

STR filing — the practitioner reality

Suspicious Transaction Reports are filed with STRO via the SONAR portal. The filing standard is “knowledge or reasonable grounds to suspect”, which is lower than evidence-based confidence. Firms that under-file face supervisory criticism, but over-filing trivial alerts dilutes the regime. A good programme has clear escalation tiers, a documented MLRO sign-off, and a “no tipping off” protocol that prevents staff from informing the customer.

FAQs

Can CDD be outsourced? Yes — to another financial institution subject to equivalent AML standards — but ultimate responsibility remains with the licensee. The outsourcing arrangement must be documented and reviewed.

What is “source of wealth” vs “source of funds”? Source of funds is the immediate origin of the money in the transaction; source of wealth is the overall economic activity that built the customer’s net worth. EDD typically requires both.

How often should we screen existing customers? Daily for sanctions list updates; periodic refresh of full CDD on a risk-based cycle (typically 12 months for high risk, 36 months for medium, 60 months for low).

Is there a de minimis for STR filing? No. The duty is triggered by knowledge or reasonable suspicion, regardless of transaction value.

What about virtual asset service providers? VASPs licensed under the Payment Services Act 2019 face additional travel rule and crypto-specific obligations under PSN02.

Authoritative references

Need help with this? Call, SMS or WhatsApp +65 8501 7133, or email [email protected]. Raffles Corporate Services works with a panel of corporate and employment law firms; this article is general information, not legal advice.