MAS AML / CFT for licensed entities — Documents required and templates

Published on: 11 Aug, 2026

MAS AML / CFT for licensed entities — Documents required and templates

Raffles Corporate Services works with a panel of corporate and employment law firms; this article is general information, not legal advice.

MAS AML / CFT for licensed entities is the framework of customer due diligence, screening, monitoring and reporting a financial institution operates to prevent money laundering and terrorism financing. Wealth managers and fintechs should hold a board-approved AML/CFT policy, a documented enterprise-wide risk assessment and a screening and suspicious-transaction reporting process before onboarding clients.

What MAS AML / CFT for licensed entities requires

The obligations flow from the Corruption, Drug Trafficking and Other Serious Crimes Act 1992 and the relevant MAS Notices on the prevention of money laundering and countering the financing of terrorism, which differ by licence type. The common architecture is: an enterprise-wide risk assessment, customer due diligence proportionate to risk, ongoing monitoring of transactions, screening against sanctions and politically exposed person lists, and the filing of suspicious transaction reports with the Suspicious Transaction Reporting Office. See the Monetary Authority of Singapore for the notice that applies to your licence.

Section 39 of the Corruption, Drug Trafficking and Other Serious Crimes Act 1992 establishes the obligation to report suspicion of criminal proceeds, and the reporting duty is not discharged by internal escalation alone.

Who this applies to

Banks, capital markets licensees, fund managers, payment institutions, insurers and trust companies all fall within the regime, with notices tailored to each. A single-family office relying on a Section 13O or 13U exemption is not licensed in the same way, but the fund manager it appoints is, and the family office is expected to cooperate with that manager’s onboarding. Fintechs holding a payment licence face particularly close scrutiny of transaction monitoring. Our fund-vehicle explainer on VCC Act 2018 — Section 24 variable capital and share redemption — Eligibility and requirements checklist shows how redemptions interact with source-of-funds checks.

Documents and templates you should hold

Keep the board-approved AML/CFT policy; the enterprise-wide risk assessment with a documented methodology; customer risk-rating templates; a CDD checklist covering identity, beneficial ownership and source of wealth; a sanctions and PEP screening procedure with the tool of record; a transaction-monitoring rule set; an STR decision log; and training records for all staff. Retain records for at least five years after the relationship ends, as the notices require. Where distributions are made to underlying investors, keep those board resolutions consistent, as our Declaring Dividends in Singapore: What Directors Need to Know (2026) guide illustrates.

Cost and timeline benchmarks

A proportionate AML/CFT programme for a small licensee typically costs S$10,000 to S$30,000 to design and document, with screening tools adding S$3,000 to S$20,000 a year depending on volume. Expect four to ten weeks to complete the enterprise-wide risk assessment, write the policy and configure screening. An independent AML audit, which larger licensees run periodically, adds S$8,000 to S$25,000.

Step-by-step: building the programme

Begin with the enterprise-wide risk assessment so every later control is risk-based. Draft the policy and appoint a money-laundering reporting officer. Build the CDD workflow with beneficial-ownership identification down to the 25 percent threshold used in practice. Configure sanctions and PEP screening at onboarding and on an ongoing basis. Set transaction-monitoring rules and a clear STR escalation path. Train staff and schedule refreshers. Our MAS insurance broker and intermediary licensing — Documents required and templates guide covers the migration considerations for licensees changing regimes.

Common mistakes

Weak spots include a generic risk assessment copied from a template, screening that runs only at onboarding, beneficial-ownership records that stop at the first corporate layer, and an STR process that escalates internally but never files. Under-resourcing the reporting officer role is a recurring supervisory concern.

Risk-based due diligence in practice

A risk-based approach means the depth of due diligence rises with the assessed risk of the customer. A locally resident salaried client with a simple profile sits at one end; a complex offshore structure with layered ownership and exposure to higher-risk jurisdictions sits at the other and attracts enhanced due diligence, senior sign-off and closer ongoing monitoring. Source of wealth and source of funds are distinct questions: the former explains how the client accumulated their assets, the latter explains the origin of the specific monies entering the relationship, and files that conflate the two are a common finding.

Politically exposed persons are not prohibited customers, but they require senior management approval to onboard, enhanced scrutiny of source of wealth, and closer transaction monitoring, with the same discipline applied to close associates and family members.

Transaction monitoring and reporting discipline

Monitoring rules should map to the enterprise-wide risk assessment rather than to a generic template, and alerts must be worked and documented, not merely generated. The audit trail should show who reviewed an alert, what they concluded and why. Where suspicion crystallises, the report to the Suspicious Transaction Reporting Office should be timely and the internal decision recorded, including decisions not to file, so the reasoning can be reconstructed later. Tipping off the customer that a report has been made is itself an offence, so staff training must cover the confidentiality of the reporting process.

Fees, timelines and thresholds at a glance

  • Programme design and documentation: S$10,000 to S$30,000
  • Screening tools per year: S$3,000 to S$20,000
  • Independent AML audit: S$8,000 to S$25,000
  • Record-retention period: at least 5 years after relationship ends
  • Time to stand up the programme: 4 to 10 weeks

FAQs

Who must file a suspicious transaction report?
Any person who knows or has reasonable grounds to suspect that property represents proceeds of crime, under Section 39 of the Corruption, Drug Trafficking and Other Serious Crimes Act 1992. Internal escalation alone does not discharge the duty.

How far must beneficial ownership be traced?
To the natural persons who ultimately own or control the customer, commonly applying a 25 percent ownership threshold as a starting point, with a control test where ownership is diffuse.

Is ongoing screening required or just onboarding screening?
Ongoing. Sanctions and PEP screening must be repeated on a risk-based cadence, not only at account opening.

How long must records be kept?
At least five years after the business relationship ends, as required by the MAS notices.

Related guides across the Raffles group

Authoritative sources: the Monetary Authority of Singapore; Singapore Statutes Online.

Need help with this? Call, SMS or WhatsApp +65 8501 7133, or email [email protected]. Raffles Corporate Services works with a panel of corporate and employment law firms; this article is general information, not legal advice.