MAS AML/CFT rulebook (Singapore)
Omnified's Singapore rulebook models the MAS AML/CFT framework across the entity types that MAS regulates — banks, merchant banks, finance companies, payment service providers, digital-payment-token services, capital-markets intermediaries, fund managers, and insurers. It is one operational reading of the Notices and Guidelines below; verify every threshold with counsel.
This rulebook is a structured operational interpretation of public regulatory guidance to help configure Omnified. Verify every threshold, list, and requirement with qualified compliance counsel before relying on it. Thresholds and lists change — see version notes.
Entity-type matrix
Which MAS profile applies to which regulated entity:
| Entity type | Primary source | Notes |
|---|---|---|
| Bank / merchant bank | MAS Notice 626 | Full AML/CFT profile |
| Finance company | MAS Notice 824 | Mirrors Notice 626 with sector deltas |
| Payment service provider | MAS PSN01 | SVF/MPI account issuers |
| Digital payment token service | MAS PSN02 | Highest-risk baseline; simplified CDD not appropriate |
| Capital markets intermediary | MAS SFA04-N02 | Broker-dealers, custodians |
| Licensed fund management company | MAS SFA04-N02 + Guidelines | Includes VCCs |
| Direct insurer | MAS Notice 314 | Life & composite |
Requirements by category
Identification
Collect full name, unique ID number, date of birth, nationality, and residential address for every individual customer.
Collect entity name, registration number, legal form, registered address, and directors for every corporate/partnership/trust customer.
Verification
Verify identity from reliable, independent sources. Singpass/MyInfo qualifies as a government-verified source for Singapore residents.
Beneficial ownership
Identify beneficial owners — natural persons who ultimately own or control ≥25% of the legal person, applying a cascading control test if no individual meets the threshold.
Enhanced dd
Apply Enhanced CDD to foreign PEPs (always), and to domestic/international-organisation PEPs on a risk basis. EDD requires senior-management approval, source-of-wealth/source-of-funds establishment, and enhanced ongoing monitoring.
Mandatory EDD when the customer is from a FATF-identified higher-risk jurisdiction. Apply enhanced screening and ongoing monitoring.
Risk tier
Simplified CDD is only permissible where a documented low-risk rationale exists and no suspicion of ML/TF is present. Any suspicion flag automatically disqualifies simplified CDD.
Digital payment token (DPT) service providers must treat customer relationships at an elevated risk baseline. Simplified CDD is not appropriate for DPT flows.
Screening
Screen every customer at onboarding, on trigger events, and periodically against UN Security Council sanctions and MAS-designated lists. Add firm-maintained lists per policy.
PEP and adverse-media screening at onboarding and on trigger events per the firm's risk-based policy.
Non face to face
Non-face-to-face onboarding requires additional measures such as video-KYC with liveness, or reliance on a government-verified digital ID.
Ongoing monitoring
Conduct ongoing monitoring of business relationships, including transaction monitoring, sanctions rescreening, and periodic review of customer information.
Where suspicion of ML/TF arises, a Suspicious Transaction Report must be filed with the Suspicious Transaction Reporting Office (STRO). Omnified flags suspicion indicators; filing remains the client's responsibility.
Record keeping
Retain CDD records, transaction records, and STR-related material for at least 5 years after the business relationship ends or the occasional transaction is completed.
Reliance
Reliance on a third party for CDD is permitted only where the third party is regulated, supervised for AML/CFT, and agrees to provide underlying documentation on request without delay.
Scenario library
a) Singapore resident individual — retail fintech, clean profile
- Problem
- A local resident opens an e-money wallet with a licensed PSP. No sanctions hits, no PEP signal, clean adverse-media, typical income.
- Requirements
SG-CDD-001SG-CDD-002SG-SCR-001SG-OM-001SG-RK-001- Omnified routes
- Singpass/MyInfo pull → sanctions + PEP screen → standard CDD. Simplified CDD only if the PSP has a documented low-risk rationale on file.
- Expected outcome
- compliant — Singpass covers identity + verification; sanctions/PEP screen returns clean; ongoing monitoring wired.
b) Foreign PEP opening a private-wealth account
- Problem
- A former minister of a foreign state, now a private client, wants to open an account with a Singapore bank.
- Requirements
SG-CDD-001SG-CDD-002SG-EDD-001SG-SCR-002SG-OM-001- Omnified routes
- EDD chain triggered: senior-management approval routed, SoW/SoF collection required before activation, enhanced monitoring switched on.
- Expected outcome
- gaps_found until SoW/SoF and senior-approval memo are recorded. Not_met findings surface exactly what's missing.
c) Corporate customer with layered ownership
- Problem
- A Singapore-incorporated holding company owned 60% by a foreign parent, which is itself owned 40/40/20 by three individuals.
- Requirements
SG-CDD-003SG-BO-001- Omnified routes
- BO cascade: 60% × 40% = 24% (below the 25% threshold). Engine walks the chain and, finding no individual ≥25%, falls back to the control test (board control / senior-management).
- Expected outcome
- compliant only when a control-test individual is identified and documented, otherwise not_met with the ownership chart flagged as missing evidence.
d) Non-face-to-face DPT customer
- Problem
- A remote-onboarding request from a customer for a DPT wallet issued by a Singapore-licensed DPT service provider.
- Requirements
SG-DPT-001SG-NFTF-001SG-SCR-001SG-EDD-002 (if country-risk fires)- Omnified routes
- DPT baseline forbids simplified CDD. Non-face-to-face requires Singpass/MyInfo OR video-KYC + liveness. Country-risk lookup may escalate to EDD.
- Expected outcome
- compliant if a government-verified digital ID or video-KYC + liveness bundle is present; otherwise not_met on SG-NFTF-001.
e) Customer from a FATF high-risk jurisdiction
- Problem
- A prospective account holder ordinarily resident in a FATF-listed country.
- Requirements
SG-CDD-001SG-CDD-002SG-EDD-002SG-SCR-001- Omnified routes
- Mandatory EDD is triggered by the country flag: enhanced monitoring on, expanded screening (sanctions + PEP + adverse media).
- Expected outcome
- not_met on SG-EDD-002 until enhanced monitoring is configured and adverse-media screening runs.
f) Existing customer — suspicion trigger requires re-CDD
- Problem
- Transaction monitoring flags a plausible ML pattern on an existing customer previously onboarded under simplified CDD.
- Requirements
SG-SCDD-001SG-STR-001SG-EDD-001 (on rerun)- Omnified routes
- Suspicion flag makes simplified CDD impossible — engine returns blocked on SG-SCDD-001 and requires re-CDD + STR channel.
- Expected outcome
- blocked — client must uplift to standard/enhanced CDD and route through STR filing channel.
CDD decision tree
┌─ any suspicion of ML/TF? ──── yes ──▶ standard/enhanced CDD + STR channel (simplified impossible)
│ no
│
├─ customer is PEP? ─────────── yes ──▶ ENHANCED CDD (senior approval + SoW/SoF + enhanced monitoring)
│ no
│
├─ FATF high-risk country? ─── yes ──▶ ENHANCED CDD + expanded screening
│ no
│
├─ non-face-to-face channel? ─ yes ──▶ Singpass/MyInfo OR video-KYC + liveness
│ no
│
├─ DPT service? ─────────────── yes ──▶ elevated baseline, simplified CDD not appropriate
│ no
│
└─ documented low-risk rationale + simple product ──▶ SIMPLIFIED CDD
otherwise ────────────────────────────────────────▶ STANDARD CDD