Docs · Rulebooks

MAS vs IFSCA — side by side

Same customer, two rulebooks. Below is the operational delta between Singapore (MAS) and GIFT City (IFSCA) as Omnified encodes it — the differences that make a "one API across both" actually save months.

Operational interpretation — not legal advice

This rulebook is a structured operational interpretation of public regulatory guidance to help configure Omnified. Verify every threshold, list, and requirement with qualified compliance counsel before relying on it. Thresholds and lists change — see version notes.

DimensionMAS (Singapore)IFSCA (GIFT City)
Primary sourceMAS Notice 626 (+ PSN01/PSN02, SFA04-N02, Notice 314)IFSCA AML/CFT & KYC Guidelines (+ PMLA alignment)
Regulated-entity coverageBank, merchant bank, finance company, PSP, DPT, capital-markets intermediary, FMC, insurerIBU, FME, capital-markets intermediary, IIO, finance company, PSP, fintech sandbox
Individual identity evidenceFull name + unique ID + DOB + nationality + residential address. Singpass/MyInfo qualifies as government-verified.Full name + DOB + nationality + residential address. Passport is the default rail for non-residents; DigiLocker/Aadhaar/CKYC + PAN for India-linked.
Non-face-to-face rulesGovernment-verified digital ID (Singpass/MyInfo) OR video-KYC + liveness.V-CIP with prescribed conditions: live, geotagged, trained officer, recording retained.
BO threshold — companies≥25% ownership OR control (cascade test).≥10% (PMLA-aligned) OR control (cascade test) — recent PMLA amendments changed this; see version notes.
BO threshold — partnerships≥25% or control.≥10% of capital/profits or control.
BO — trustsSettlor, trustees, protector (if any), beneficiaries or class thereof, any ultimate controller.Same structural coverage — settlor, trustees, beneficiaries, ultimate controller.
EDD triggersForeign PEP (always); domestic/international-org PEP on risk; FATF high-risk country; NFTF without safeguards; firm-rated high risk.Same categories. PEP + SoW/SoF + senior-management approval + enhanced monitoring required.
Simplified CDDAllowed with documented low-risk rationale; forbidden where ML/TF suspicion exists.Same — suspicion disqualifies simplified CDD.
Screening listsUN + MAS-designated + firm lists. PEP + adverse media per policy.UN + MHA India (§51-A) + firm lists. PEP + adverse media for standard/enhanced tiers.
Ongoing monitoring cadenceRisk-based; higher-risk more frequent (firm-defined).Seed values: high-risk annual, medium-risk every 2 years [counsel-verify against firm policy].
Retention≥5 years post-relationship / occasional transaction.≥5 years post-relationship / occasional transaction.
Third-party relianceRegulated + supervised third party, documentation available without delay.Group reliance for IBUs/FMEs/CMIs/IIOs — equivalent standards + documentation available on request.
Designated personnelMLRO / compliance function per firm policy.Principal Officer + Designated Director must be intimated to IFSCA.
Sector-specific baselineDPT (PSN02) treated as highest-risk profile — simplified CDD not appropriate.Fintech sandbox entities operate under time-boxed conditions; base AML applies.

Why this matters

The regulators agree on the shape of AML/CFT — identify, verify, screen, monitor, retain — but they disagree on the details: which identity rails count, what thresholds trigger enhanced diligence, which lists you must screen against, and how you may accept a non-face-to-face customer. A single hard-coded flow can't serve both.

Omnified splits the two: one API for verification and orchestration, two rulebooks that evaluate the same normalised payload against the applicable jurisdiction. Change a threshold in rulebook data (say the PMLA BO threshold moves) and the next validation run applies the new value — no deploy required, and prior runs still cite the version they used.