MAS vs IFSCA — side by side
Same customer, two rulebooks. Below is the operational delta between Singapore (MAS) and GIFT City (IFSCA) as Omnified encodes it — the differences that make a "one API across both" actually save months.
This rulebook is a structured operational interpretation of public regulatory guidance to help configure Omnified. Verify every threshold, list, and requirement with qualified compliance counsel before relying on it. Thresholds and lists change — see version notes.
| Dimension | MAS (Singapore) | IFSCA (GIFT City) |
|---|---|---|
| Primary source | MAS Notice 626 (+ PSN01/PSN02, SFA04-N02, Notice 314) | IFSCA AML/CFT & KYC Guidelines (+ PMLA alignment) |
| Regulated-entity coverage | Bank, merchant bank, finance company, PSP, DPT, capital-markets intermediary, FMC, insurer | IBU, FME, capital-markets intermediary, IIO, finance company, PSP, fintech sandbox |
| Individual identity evidence | Full name + unique ID + DOB + nationality + residential address. Singpass/MyInfo qualifies as government-verified. | Full name + DOB + nationality + residential address. Passport is the default rail for non-residents; DigiLocker/Aadhaar/CKYC + PAN for India-linked. |
| Non-face-to-face rules | Government-verified digital ID (Singpass/MyInfo) OR video-KYC + liveness. | V-CIP with prescribed conditions: live, geotagged, trained officer, recording retained. |
| BO threshold — companies | ≥25% ownership OR control (cascade test). | ≥10% (PMLA-aligned) OR control (cascade test) — recent PMLA amendments changed this; see version notes. |
| BO threshold — partnerships | ≥25% or control. | ≥10% of capital/profits or control. |
| BO — trusts | Settlor, trustees, protector (if any), beneficiaries or class thereof, any ultimate controller. | Same structural coverage — settlor, trustees, beneficiaries, ultimate controller. |
| EDD triggers | Foreign PEP (always); domestic/international-org PEP on risk; FATF high-risk country; NFTF without safeguards; firm-rated high risk. | Same categories. PEP + SoW/SoF + senior-management approval + enhanced monitoring required. |
| Simplified CDD | Allowed with documented low-risk rationale; forbidden where ML/TF suspicion exists. | Same — suspicion disqualifies simplified CDD. |
| Screening lists | UN + MAS-designated + firm lists. PEP + adverse media per policy. | UN + MHA India (§51-A) + firm lists. PEP + adverse media for standard/enhanced tiers. |
| Ongoing monitoring cadence | Risk-based; higher-risk more frequent (firm-defined). | Seed values: high-risk annual, medium-risk every 2 years [counsel-verify against firm policy]. |
| Retention | ≥5 years post-relationship / occasional transaction. | ≥5 years post-relationship / occasional transaction. |
| Third-party reliance | Regulated + supervised third party, documentation available without delay. | Group reliance for IBUs/FMEs/CMIs/IIOs — equivalent standards + documentation available on request. |
| Designated personnel | MLRO / compliance function per firm policy. | Principal Officer + Designated Director must be intimated to IFSCA. |
| Sector-specific baseline | DPT (PSN02) treated as highest-risk profile — simplified CDD not appropriate. | Fintech sandbox entities operate under time-boxed conditions; base AML applies. |
Why this matters
The regulators agree on the shape of AML/CFT — identify, verify, screen, monitor, retain — but they disagree on the details: which identity rails count, what thresholds trigger enhanced diligence, which lists you must screen against, and how you may accept a non-face-to-face customer. A single hard-coded flow can't serve both.
Omnified splits the two: one API for verification and orchestration, two rulebooks that evaluate the same normalised payload against the applicable jurisdiction. Change a threshold in rulebook data (say the PMLA BO threshold moves) and the next validation run applies the new value — no deploy required, and prior runs still cite the version they used.