MAS DPTSP AML/CFT expectations have come into sharper focus following a new Information Paper from the Monetary Authority of Singapore.
In July 2026, the Monetary Authority of Singapore (MAS) published its Information Paper, AML/CFT Supervisory Expectations for Digital Payment Token Service Providers (DPTSPs) (The Paper). The Paper sets out MAS’ observations and supervisory expectations for DPTSPs in implementing Anti-Money Laundering (AML), Countering the Financing of Terrorism (CFT) and Countering Proliferation Financing (CPF) controls across seven key areas, namely:
a. Assessment of Risks Arising from New Products
b. Enhanced Customer Due Diligence Measures on Higher Risk Customers
c. Value Transfer Requirements
d. Ongoing Monitoring
e. Screening
f. Due Diligence on Partners and Outsourced Providers
g. Training and Staff Expertise
The Paper does not create a new regulatory regime. It supplements existing AML/CFT/CPF requirements and should be read together with MAS Notice PSN02 and the accompanying Guidelines. More importantly, it reveals MAS’ supervisory focus. Although DPTSPs generally understand their obligations, MAS continues to identify gaps in implementation, execution, documentation, and oversight.
The recurring message is clear. For DPTSPs, effective AML/CFT/CPF compliance is not just about having policies, tools and committees in place. DPTSPs must be able to demonstrate how they exercise risk-based judgement, who is accountable for key decisions, and how controls operate in practice.
1. MAS DPTSP AML/CFT: Assessment of Risks Arising from New Products
Before listing a new Digital Payment Token (DPT), firms should perform a documented, risk-based assessment. The assessment should go beyond the standard indicators in the Guidelines to MAS Notice PSN02. DPTSPs should assess four additional areas:
-
- Direct ML/TF risk: The token’s association with higher-risk persons, entities, or jurisdictions.
-
- Track record: The credibility of the token’s creators, its governance, and any adverse news.
-
- Market and economic indicators: Trading volume, liquidity, and built-in inflationary/deflationary mechanisms that could signal manipulation or fraud.
-
- Technology and cybersecurity risk: Vulnerabilities in the token’s smart contract or underlying blockchain.
MAS notes that not all of these factors contribute directly to ML/TF risk. However, each represents a potential vulnerability that illicit actors could exploit to facilitate ML/TF activities. DPTSPs should therefore assess these interconnected risks holistically.
Where firms fell short:
-
- Broad risk indicators existed, but no guidance on how staff should assess them or which information sources to use.
-
- No documentation of which functions (business, compliance, technology risk) should sign-off.
-
- Listing thresholds (e.g. minimum market capitalisation, average daily volume) set with no written rationale, making them impossible to review or explain later.
-
- Listing decisions said to involve senior management and Board approval, but no paper trail proving either the approval or any underlying risk assessment had been conducted.
What DPTSPs need to do next:
-
- Capture risk factors that are relevant, assessable and practically applicable.
-
- Name the functions required to sign off each listing decision, and document their input.
-
- Record the rationale behind every quantitative threshold used in listing criteria.
-
- Keep an auditable record of every risk assessment and approval, including deviations from policy and the justification for them.
2. Enhanced due diligence for Higher-Risk Customers
For Politically Exposed Persons (PEPs) and other higher-risk customers, firms should obtain senior management approval to onboard or continue the relationship, establish a genuine understanding of the Source of Wealth (SOW) and Source of Funds (SOF), obtain independent supporting evidence to corroborate them, and apply enhanced ongoing monitoring. Where incoming funds are tokens, blockchain analytics should complement off-chain information, not replace it. This is in line with MAS’s broader supervisory message to the financial industry: firms are expected to independently corroborate SOF and SOW.
Where firms fell short:
-
- Mixing up SOF and SOW: One firm confirmed a customer’s wealth existed (via bank statements) but never established how it was generated, treating proof of funds as equivalent to understanding the customer’s SOW.
-
- Relying on the customer’s own SOF declaration without independent verification
-
- Proceeding to onboard customers with expected account activity well above their known income.
-
- Assessing jurisdiction risk using only a customer’s current nationality, missing that the customer previously held nationality of, and derived wealth from, a higher-risk jurisdiction.
What DPTSPs need to do next:
-
- Require independent corroborating evidence for SOW/SOF and not just customer declarations alone – particularly for higher-risk customers.
-
- Build a base set of SOW information (e.g. estimated overall wealth) into onboarding for every higher-risk customer, including beneficial owners
-
- Assess jurisdiction risk using relevant nationality, residency, and SOW links, including previous nationality or historical links to higher-risk jurisdictions where relevant.
-
- Ensure declared account activity is consistent with the customer’s known income and SOW, especially before approving higher-risk relationships.
3. Strengthening Value Transfer and Travel Rule Compliance
A portion of the Paper focuses heavily on FATF’s Travel Rule for crypto transfers. MAS Notice PSN02 implements the FATF Travel Rule, requiring originating DPTSPs to transmit originator and beneficiary information to receiving DPTSPs concurrently with a value transfer. Globally, implementation remains patchy; the 2025 FATF Targeted Update found roughly three-quarters of assessed jurisdictions had passed implementing legislation, but genuine global coverage hasn’t been achieved, leaving gaps that illicit actors can exploit
MAS sets out six factors that firms should weigh when choosing a Travel Rule solution:
-
- Coverage of token types and Virtual Asset Service Provider (VASP) network
-
- Interoperability with other compliance tools
-
- VASP due diligence rigour applied to network members
-
- Counterparty identification robustness, including non-network VASPs
-
- Immediacy of data transmission
-
- Data security safeguards
Where firms fell short:
-
- The Travel Rule solution covered only a small proportion of its actual transfers, because the solution didn’t support certain tokens or the counterparty wasn’t in its network.
-
- For transfers outside that coverage, the firm only applied risk mitigation when its analytics tool flagged high-risk entities, rather than treating every non-compliant transfer and every transfer to an unhosted wallet as requiring mitigation by default.
-
- Sole reliance on the Travel Rule vendor to identify and verify counterparties, rather than independently confirming wallet ownership.
What DPTSPs need to do next:
-
- Map exactly what proportion of value transfers your Travel Rule solution actually covers, and build compensating controls for the rest.
-
- Apply enhanced risk mitigation to all transfers to/from unhosted wallets or unregulated VASPs, regardless of what analytics tools flag.
-
- Independently verify counterparty/beneficiary wallet ownership rather than relying solely on the solution provider.
-
- Never send Travel Rule data to unverified email addresses, and refresh counterparty due diligence periodically, not just at onboarding.
4. Enhancing Ongoing Transaction Monitoring
MAS DPTSP AML/CFT expectations require DPTSPs to monitor customer relationships continuously. They should assess token and fiat transactions together using parameters tailored to their own business rather than default vendor or group settings. MAS is reminding firms that not every suspicious activity can be detected simply by tracing blockchain transactions. Blockchain analytics tools are valuable, but they are not a substitute for proper AML transaction monitoring and risk assessment. This reflects MAS’ broader supervisory approach throughout the Paper; technology is an important enabler, but firms remain responsible for applying a risk-based assessment.
Where firms fell short:
-
- One firm had no parameters to detect rapid token inflows followed by fast fiat outflows. It also failed to investigate transactions that did not match the customer’s stated account purpose.
-
- Another firm’s compliance team noticed customers depositing tokens worth far more than their declared income. The team also knew that some whitelisted wallets had indirect exposure to sanctioned entities. However, it concluded the risk was “acceptable” because the transaction amounts were small. It did not pursue further on-chain analysis that could have identified layering.
What DPTSPs need to do next:
-
- Set and periodically review your own parameters and thresholds; don’t inherit default or group settings unreviewed.
-
- Give staff clear, documented procedures for escalating or dismissing alerts, and run quality assurance over that process.
-
- Treat a low transaction amount as one input, not a reason to close an alert; pursue additional on-chain detail (timestamps, intermediary wallets) before concluding risk is acceptable.
-
- Follow up directly with customers on unusually large or inconsistent transactions rather than relying on tooling alone.
5. Strengthening Customer Screening
Screening is described as a “fundamental” preventative control. The Paper highlights the importance of understanding the underlying data sources your screening vendor relies on, rather than taking the tool’s existence on faith.
Where firms fell short:
-
- A firm screened customers at onboarding and annually thereafter, plus screened wallets continuously via analytics, but a customer sanctioned six months after onboarding could go undetected for another six months under that cycle.
-
- Another firm never engaged its screening vendor to understand what its database actually covered, including adverse media; a gap that meant a customer subsequently charged with corruption was never flagged.
What DPTSPs need to do next:
-
- Move beyond annual re-screening cycles for customers and relevant parties; Screen customers and relevant parties at a daily/weekly frequency, commensurate with ever-changing sanctions and ML/TF risk.
-
- Actively engage screening vendors to understand database coverage, including adverse media sources, and assess whether it’s adequate
-
- Screen all relevant parties (including value transfer originators and beneficiaries), not just direct customers.
6. Outsourcing Without Losing Oversight
Many DPTSPs rely on liquidity providers, intra-group entities or external service providers for parts of their MAS DPTSP AML/CFT function. Outsourcing AML/CFT functions does not transfer regulatory responsibility. The DPTSP remains fully accountable for compliance and must maintain appropriate governance, actively oversee its service providers, and regularly monitor their performance against clear and measurable service standards.
What DPTSPs need to do next:
-
- Conduct comprehensive due diligence on partners and service providers before onboarding, and periodically thereafter, covering capability, probity, ownership structure, and AML/CFT/CPF control robustness.
-
- Maintain active governance and management oversight over any outsourced AML/CFT function, rather than delegating without effective oversight. .
-
- Set clear, measurable KPIs for service providers, and run regular quality assurance reviews and onsite visits where relevant.
7. Strengthening Staff Training and Expertise
As part of MAS DPTSP AML/CFT expectations, MAS observed that technical blockchain specialists at some firms had weak ML/TF risk awareness, while compliance staff at others lacked the sector-specific experience to understand DPT-related risks properly. Training should be tailored to staff roles, with employees having a foundational understanding of blockchain technology, cryptocurrencies, and the associated ML/TF risks.
What DPTSPs need to do next:
-
- Build a tailored training programme giving all relevant staff a baseline understanding of blockchain technology, crypto-specific ML/TF risk, and regulatory developments.
-
- Calibrate scope and frequency of training to each role’s actual responsibilities and risk exposure.
-
- Ensure committees overseeing new product and listing decisions have balanced representation of technical, AML/CFT, and compliance expertise, not one perspective dominating the other.
MAS DPTSP AML/CFT: What this means going forward
The Paper shows that the next phase of MAS DPTSP AML/CFT maturity for DPTSPs is about execution. Firms must be able to demonstrate that their controls are not only documented, but applied consistently, reviewed periodically, supported by appropriate expertise and evidenced through clear governance records.
For DPTSPs preparing for supervisory engagement, the key diagnostic question is not simply whether a control exists. It is whether the firm can identify who exercised the control, what information was considered, how judgement was applied, where the decision was documented, and whether the outcome was tested against the firm’s stated risk appetite.
Where the answer is unclear, the firm may carry the same underlying weakness MAS has identified across the sector: controls that exist in form but are not yet sufficiently embedded in practice
MAS DPTSP AML/CFT: How Curia Regis Can Support
As MAS DPTSP AML/CFT expectations continue to evolve, DPTSPs require more than periodic compliance reviews—they need practical, risk-based solutions embedded into their day-to-day operations. Curia Regis supports firms by:
-
- Conducting independent compliance assessments to evaluate the effectiveness of AML/CFT/CPF frameworks and identify regulatory control gaps.
-
- Strengthening governance and risk management through governance reviews, enterprise-wide risk assessments, and practical compliance advisory.
-
- Enhancing policies, procedures, and customer due diligence (CDD/EDD) processes to align with MAS regulatory expectations and industry best practices.
Providing compliance training and regulatory remediation support to help firms address supervisory findings, strengthen internal capabilities, and build a more resilient, effective, and sustainable compliance programme while remaining focused on their business objectives.
Ensure your operational response is seamless. You can reach us here or email admin@curiaregis.com to get in touch.
