Docs · Rulebooks
Singapore · MAS
v1.0.0Effective 1/1/2024 · Last reviewed 1/1/2024

MAS AML/CFT rulebook (Singapore)

Omnified's Singapore rulebook models the MAS AML/CFT framework across the entity types that MAS regulates — banks, merchant banks, finance companies, payment service providers, digital-payment-token services, capital-markets intermediaries, fund managers, and insurers. It is one operational reading of the Notices and Guidelines below; verify every threshold with counsel.

Operational interpretation — not legal advice

This rulebook is a structured operational interpretation of public regulatory guidance to help configure Omnified. Verify every threshold, list, and requirement with qualified compliance counsel before relying on it. Thresholds and lists change — see version notes.

Entity-type matrix

Which MAS profile applies to which regulated entity:

Entity typePrimary sourceNotes
Bank / merchant bankMAS Notice 626Full AML/CFT profile
Finance companyMAS Notice 824Mirrors Notice 626 with sector deltas
Payment service providerMAS PSN01SVF/MPI account issuers
Digital payment token serviceMAS PSN02Highest-risk baseline; simplified CDD not appropriate
Capital markets intermediaryMAS SFA04-N02Broker-dealers, custodians
Licensed fund management companyMAS SFA04-N02 + GuidelinesIncludes VCCs
Direct insurerMAS Notice 314Life & composite

Requirements by category

Identification

SG-CDD-001MAS Notice 626 §6 — Customer Due Diligence (Identification of Individuals)verify with counsel

Collect full name, unique ID number, date of birth, nationality, and residential address for every individual customer.

Evidence: id_documentaddress_proof
SG-CDD-003MAS Notice 626 §7 — CDD for Legal Personsverify with counsel

Collect entity name, registration number, legal form, registered address, and directors for every corporate/partnership/trust customer.

Evidence: certificate_of_incorporationregister_of_directors

Verification

SG-CDD-002MAS Notice 626 §6 — Verification from reliable independent sourcesverify with counsel

Verify identity from reliable, independent sources. Singpass/MyInfo qualifies as a government-verified source for Singapore residents.

Evidence: verification_report

Beneficial ownership

SG-BO-001MAS Notice 626 §7.2 — Identification of Beneficial Ownersverify with counsel

Identify beneficial owners — natural persons who ultimately own or control ≥25% of the legal person, applying a cascading control test if no individual meets the threshold.

Evidence: bo_registerownership_chart

Enhanced dd

SG-EDD-001MAS Notice 626 §8 — Politically Exposed Persons & Enhanced CDDverify with counsel

Apply Enhanced CDD to foreign PEPs (always), and to domestic/international-organisation PEPs on a risk basis. EDD requires senior-management approval, source-of-wealth/source-of-funds establishment, and enhanced ongoing monitoring.

Evidence: sow_documentationsof_documentationsenior_approval_memo
SG-EDD-002MAS AML/CFT Guidelines — FATF High-Risk Jurisdictionsverify with counsel

Mandatory EDD when the customer is from a FATF-identified higher-risk jurisdiction. Apply enhanced screening and ongoing monitoring.

Evidence: country_risk_assessment

Risk tier

SG-SCDD-001MAS Notice 626 §6.42 — Simplified CDDverify with counsel

Simplified CDD is only permissible where a documented low-risk rationale exists and no suspicion of ML/TF is present. Any suspicion flag automatically disqualifies simplified CDD.

Evidence: low_risk_rationale_memo
SG-DPT-001MAS PSN02 — DPT Services AML/CFTverify with counsel

Digital payment token (DPT) service providers must treat customer relationships at an elevated risk baseline. Simplified CDD is not appropriate for DPT flows.

Evidence: risk_assessment

Screening

SG-SCR-001MAS Notice 626 §6.36-6.41 — Screeningverify with counsel

Screen every customer at onboarding, on trigger events, and periodically against UN Security Council sanctions and MAS-designated lists. Add firm-maintained lists per policy.

Evidence: screening_report
SG-SCR-002MAS Notice 626 §8.2 — PEP Screeningverify with counsel

PEP and adverse-media screening at onboarding and on trigger events per the firm's risk-based policy.

Evidence: pep_screening_report

Non face to face

SG-NFTF-001MAS AML/CFT Guidelines — Non-Face-to-Face Businessverify with counsel

Non-face-to-face onboarding requires additional measures such as video-KYC with liveness, or reliance on a government-verified digital ID.

Evidence: video_kyc_recordingliveness_score

Ongoing monitoring

SG-OM-001MAS Notice 626 §6.29-6.35 — Ongoing Monitoringverify with counsel

Conduct ongoing monitoring of business relationships, including transaction monitoring, sanctions rescreening, and periodic review of customer information.

Evidence: monitoring_policy
SG-STR-001CDSA §39 & MAS Notice 626 §5 — STR Obligationverify with counsel

Where suspicion of ML/TF arises, a Suspicious Transaction Report must be filed with the Suspicious Transaction Reporting Office (STRO). Omnified flags suspicion indicators; filing remains the client's responsibility.

Evidence: str_filing_channel

Record keeping

SG-RK-001MAS Notice 626 §11 — Record Keepingverify with counsel

Retain CDD records, transaction records, and STR-related material for at least 5 years after the business relationship ends or the occasional transaction is completed.

Evidence: retention_policy

Reliance

SG-REL-001MAS Notice 626 §9 — Reliance on Third Partiesverify with counsel

Reliance on a third party for CDD is permitted only where the third party is regulated, supervised for AML/CFT, and agrees to provide underlying documentation on request without delay.

Evidence: reliance_agreementthird_party_regulator_evidence

Scenario library

a) Singapore resident individual — retail fintech, clean profile

Problem
A local resident opens an e-money wallet with a licensed PSP. No sanctions hits, no PEP signal, clean adverse-media, typical income.
Requirements
SG-CDD-001SG-CDD-002SG-SCR-001SG-OM-001SG-RK-001
Omnified routes
Singpass/MyInfo pull → sanctions + PEP screen → standard CDD. Simplified CDD only if the PSP has a documented low-risk rationale on file.
Expected outcome
compliant — Singpass covers identity + verification; sanctions/PEP screen returns clean; ongoing monitoring wired.

b) Foreign PEP opening a private-wealth account

Problem
A former minister of a foreign state, now a private client, wants to open an account with a Singapore bank.
Requirements
SG-CDD-001SG-CDD-002SG-EDD-001SG-SCR-002SG-OM-001
Omnified routes
EDD chain triggered: senior-management approval routed, SoW/SoF collection required before activation, enhanced monitoring switched on.
Expected outcome
gaps_found until SoW/SoF and senior-approval memo are recorded. Not_met findings surface exactly what's missing.

c) Corporate customer with layered ownership

Problem
A Singapore-incorporated holding company owned 60% by a foreign parent, which is itself owned 40/40/20 by three individuals.
Requirements
SG-CDD-003SG-BO-001
Omnified routes
BO cascade: 60% × 40% = 24% (below the 25% threshold). Engine walks the chain and, finding no individual ≥25%, falls back to the control test (board control / senior-management).
Expected outcome
compliant only when a control-test individual is identified and documented, otherwise not_met with the ownership chart flagged as missing evidence.

d) Non-face-to-face DPT customer

Problem
A remote-onboarding request from a customer for a DPT wallet issued by a Singapore-licensed DPT service provider.
Requirements
SG-DPT-001SG-NFTF-001SG-SCR-001SG-EDD-002 (if country-risk fires)
Omnified routes
DPT baseline forbids simplified CDD. Non-face-to-face requires Singpass/MyInfo OR video-KYC + liveness. Country-risk lookup may escalate to EDD.
Expected outcome
compliant if a government-verified digital ID or video-KYC + liveness bundle is present; otherwise not_met on SG-NFTF-001.

e) Customer from a FATF high-risk jurisdiction

Problem
A prospective account holder ordinarily resident in a FATF-listed country.
Requirements
SG-CDD-001SG-CDD-002SG-EDD-002SG-SCR-001
Omnified routes
Mandatory EDD is triggered by the country flag: enhanced monitoring on, expanded screening (sanctions + PEP + adverse media).
Expected outcome
not_met on SG-EDD-002 until enhanced monitoring is configured and adverse-media screening runs.

f) Existing customer — suspicion trigger requires re-CDD

Problem
Transaction monitoring flags a plausible ML pattern on an existing customer previously onboarded under simplified CDD.
Requirements
SG-SCDD-001SG-STR-001SG-EDD-001 (on rerun)
Omnified routes
Suspicion flag makes simplified CDD impossible — engine returns blocked on SG-SCDD-001 and requires re-CDD + STR channel.
Expected outcome
blocked — client must uplift to standard/enhanced CDD and route through STR filing channel.

CDD decision tree


  ┌─ any suspicion of ML/TF? ──── yes ──▶ standard/enhanced CDD + STR channel (simplified impossible)
  │                                no
  │
  ├─ customer is PEP? ─────────── yes ──▶ ENHANCED CDD (senior approval + SoW/SoF + enhanced monitoring)
  │                                no
  │
  ├─ FATF high-risk country? ─── yes ──▶ ENHANCED CDD + expanded screening
  │                                no
  │
  ├─ non-face-to-face channel? ─ yes ──▶ Singpass/MyInfo OR video-KYC + liveness
  │                                no
  │
  ├─ DPT service? ─────────────── yes ──▶ elevated baseline, simplified CDD not appropriate
  │                                no
  │
  └─ documented low-risk rationale + simple product ──▶ SIMPLIFIED CDD
     otherwise ────────────────────────────────────────▶ STANDARD CDD
      
Changelog
v1.0.0 — Initial baseline modeled on MAS Notice 626 (banks) with cross-references to PSN01/PSN02 (PSPs, DPT), SFA04-N02 (capital markets), and MAS AML/CFT guidelines. Every threshold is data — see machine_rule.params on each requirement.