← Back to Home News · SG

MAS Signals Harder Line on Digital Token Monitoring

Make RegTech.com preferred on Google
MAS Signals Harder Line on Digital Token Monitoring
MAS tightens AML/CFT supervisory expectations for Singapore's digital payment token service providers.
AI Summary
  • The Monetary Authority of Singapore has set out, in unusually concrete terms, where crypto firms are falling short on financial-crime controls. Its July 2026 information paper on AML/CFT supervisory expectations for Digital Payment Token Service Providers catalogues the execution failures MAS found in practice, from missing senior-management sign-off to weak source-of-wealth checks, and makes clear that a licence and a compliance tech stack are not, on their own, evidence of a working control environment.

The information paper, published on 13 July 2026, sets out the Monetary Authority of Singapore's supervisory expectations for how Digital Payment Token Service Providers (DPTSPs) run their anti-money laundering, counter-terrorist-financing and counter-proliferation-financing (AML/CFT/CPF) controls. Drawing on supervisory inspections and anonymised case studies, it reads less as fresh rulemaking than as a stocktake of where firms' controls break down once they meet real customers and real transactions.

A recurring theme is that the weaknesses MAS found are rarely isolated technology failures. They tend to be structural, the product of teams working in isolation: technology functions listing tokens without compliance vetting, or compliance teams making decisions without the wider customer context. MAS's expectation is that AML/CFT obligations are built into product and onboarding processes from the outset rather than bolted on afterwards.

The main gaps MAS flagged

MAS expects DPTSPs to run an enterprise-wide gap analysis under the oversight of the board and senior management. Two of the execution failures it highlights sit within enhanced customer due diligence (ECDD).

Senior management sign-off

In some cases, MAS found, DPTSPs established or continued relationships with higher-risk customers without the senior-management approval their own frameworks required, and in some instances executives approved those relationships despite clear gaps in the customer's risk profile. The regulator's point is that documented senior oversight of higher-risk clients and of remediation is not administrative housekeeping: accountability for the effectiveness of AML/CFT controls is non-delegable, and the control culture is set at board level or not at all.

Source of wealth and source of funds

In Case Study D, MAS describes a firm that established the existence of a customer's wealth, for example through bank statements, without understanding or documenting the activities that generated it. Firms also failed to set baseline source-of-wealth estimates for higher-risk customers at onboarding. MAS expects corroboration to go beyond a bank balance, drawing on both on-chain transaction history and off-chain documentation, and testing whether the funds are plausible against what the firm knows about the customer.

Vendor tools and the Travel Rule

The paper is also pointed about compliance technology. MAS warns firms against relying on vendor default configurations, noting that firms fail inspections by applying generic thresholds and risk parameters without tailoring them to their own business model, transaction volumes and risk appetite. Many tools marketed as end-to-end remain fragmented in practice across on-chain analytics, off-chain screening and governance, risk and compliance workflows, leaving gaps that firms must close with customisation and human judgement.

Those gaps are most visible in value transfers. Singapore enforces the FATF Travel Rule through MAS Notice PSN02, but global adoption is uneven. The FATF's 2026 targeted update (its seventh, published on 16 July 2026) put the share of surveyed jurisdictions with Travel Rule legislation in force at 83%, a rise from the 73% recorded a year earlier. The practical consequence is that a Singapore firm's compliance depends partly on its counterparties' regulatory maturity and its vendor's coverage. Transfers involving unhosted wallets or unregulated VASPs are where enhanced due diligence and independent verification need to be strongest, not treated as edge cases.

The expertise gap

MAS also identifies a split in expertise: blockchain specialists who lack grounding in money-laundering and terrorist-financing risk, and compliance officers who lack the technical background to follow on-chain flows. Closing that gap points to practical steps rather than generic training: giving product, risk and compliance committees both technical and AML expertise when they vet new token listings; tailoring training to each function, so technical staff learn to spot layering techniques and compliance staff build blockchain-forensics skills; and keeping closer channels between firms and supervisors so enforcement trends translate quickly into day-to-day procedures.

For firms navigating licensing or expansion, MAS's message is that a firm's AML/CFT posture is not a back-office matter but a measure of its institutional integrity. The test the paper implicitly sets is not whether a firm has controls on paper, but whether it could show a supervisor today that those controls are understood, documented, governed and actually working. In a closely scrutinised market, that evidence, rather than the technology or the licence itself, is what earns trust.

Sources

  • MAS, AML/CFT Supervisory Expectations for Digital Payment Token Service Providers (13 July 2026): mas.gov.sg
  • MAS Notice PSN02, Prevention of Money Laundering and Countering the Financing of Terrorism, Digital Payment Token Service: mas.gov.sg
  • FATF, Targeted Update on Implementation of the FATF Standards on Virtual Assets and VASPs (16 July 2026): fatf-gafi.org
Link copied to clipboard
AI Bot
AI Bot
Hi! I'm the RegTech.com assistant. How can I help you today?
Ask me anything — top trending news, latest regulatory changes in the EU, or simply search for topics.