Digital Payment Token (DPT) service providers are required to have robust anti-money laundering and countering the financing of terrorism (AML/CFT) controls in place.
DPTs can be abused for illicit purposes due to their pseudonymous nature, and the potential use to facilitate fast and cross-border transactions.
DPT service providers are important gatekeepers in the financial system and are required to apply for a license under paragraph 5 of the Payment Services Act (PSA). DPT service providers are also required to have robust AML/CFT controls to identify and verify their customers, and detect and deter the flow of illicit funds on an ongoing basis.
More details on the AML/CFT requirements applicable to DPT service providers can be found under MAS Notice PSN02 (issued on 5 December 2019) and Guidelines to MAS Notice PSN02 (issued on 16 March 2020).
In March 2021, MAS published a guidance paper on “Strengthening AML/CFT Controls of Digital Payment Token Service Providers” to enhance industry awareness to the ML/TF risks in the DPT sector, and provide guidance to help DPT service providers implement effective AML/CFT controls.
In that guidance paper, MAS highlighted its supervisory expectations on the key AML/CFT considerations relating to new DPT products, enhanced customer due diligence (ECDD) and value transfers, which are aligned with international developments and standards.
This content leverages on the key highlights from the MAS’ guidance paper to help DPT service providers understand existing AML/CFT requirements.
Under paragraph 2 of the PSA, “digital payment token” means any digital representation of value (other than an excluded digital representation of value) that:
- is expressed as a unit;
- is not denominated in any currency, and is not pegged by its issuer to any currency;
- is, or is intended to be, a medium of exchange accepted by the public, or a section of the public, as payment for goods or services or for the discharge of a debt;
- can be transferred, stored or traded electronically; and
- satisfies such other characteristics as MAS may prescribe.
More details on the types of regulated DPT activities can be found under the First Schedule of the PSA.
Entities that:
- deal in DPTs;
- facilitate the exchange of DPTs;
- facilitate the transmission of DPTs; and/or
- provide custodian wallet services,
are required to be licensed as DPT service providers, and comply with MAS’ AML/CFT laws and regulations.
The Financial Action Task Force (FATF) revised its AML/CFT standards to impose AML/CFT requirements on Virtual Asset Service Provider (VASPs).
FATF, the global AML/CFT inter-governmental body, revised the FATF Standards to require countries to regulate VASPs to mitigate ML/TF risks. VASPs include entities known locally as DPT Service Providers.
In particular, FATF amended Recommendation 15 to scope in virtual assets (VA) and VASPs in October 2018 and provided additional guidance in June 2019. FATF continues to monitor the VASP sector via two 12-month reviews, and has urged members to continue to make progress in implementing the revised FATF standards in their domestic regimes.
Overview of MAS’ AML/CFT requirements for DPT sector
DPT service providers must abide by the AML/CFT requirements in MAS Notice PSN02. Some key AML/CFT requirements include:
- Taking appropriate steps to identify, assess and understand the licensee’s ML/TF risks;
- Developing and implementing policies, procedures and controls – including those in relation to the conduct of Customer Due Diligence (CDD), transaction monitoring, value transfers, screening, suspicious transaction reporting and record keeping – to enable the licensee to effectively manage and mitigate their ML/TF risks;
- Monitoring the implementation of those policies, procedures and controls, and enhancing them as necessary; and
- Performing enhanced measures where there are higher ML/TF risks to effectively manage and mitigate them.
Additional information on MAS’ expectations relating to:
- new products;
- Enhanced Customer Due Diligence (ECDD); and
- ongoing monitoring will be elaborated in this module.
These three areas are highlighted in bold in the following diagram for your reference.
Licensees should refer to MAS Notice PSN02, and the accompanying Guidelines to the Notice, for the full set of AML/CFT requirements and MAS’ supervisory expectations. Licensees should also ensure that they monitor for, and take note of additional AML/CFT guidance that MAS may release from time to time.
What should an assessment of ML/TF risks of new products entail?
DPT service providers should have a formalised approach to identify and assess the ML/TF risks involved, before offering new products (including listing of new DPTs on their platform). In particular, DPT service providers should ensure that the:
- ML/TF assessment for each product should be documented, and subjected to senior management’s approval
- ML/TF risk assessment for new products should include both quantitative and qualitative considerations, and could include the following factors (which are non-exhaustive):
- whether the product has characteristics that promote anonymity, obfuscate transactions or undermine the payment service provider’s ability to perform AML/CFT measures effectively;
- whether the product is known to be used by criminals for illicit purposes;
- whether the volatility and liquidity of the product render it susceptible to market manipulation and fraud; and
- whether the product has been developed and/or issued by reputable entities for lawful and legitimate purposes.
What types of ECDD measures should be considered for Politically Exposed Persons (PEPs) and higher risk customers?
As part of Enhanced Customer Due Diligence (ECDD) measures, DPT service providers should:
- Obtain approval from senior management to establish or continue business relations;
- Establish the sources of wealth and funds of customers/beneficial owners – In establishing source of funds (where incoming funds are DPTs), the insights from distributed ledger analytics and/or other surveillance tools can be used to augment other sources of information; and
- Conduct enhanced monitoring of the business relations of the customer – e.g. subjecting the customer to a higher frequency of periodic review.
What type of ongoing monitoring approach should be considered?
DPT service providers should monitor business relations with customers on an ongoing basis, and ensure that transactions are consistent with knowledge of the customer, its business and risk profile, and source of funds. In particular, DPT service providers need to pay attention to all complex, unusually large or unusual patterns of transactions undertaken, that have no apparent or visible economic or lawful purpose.
DPT service providers should also conduct regular review of their AML/CFT policies, procedures and controls.
This review should include consideration of the following factors:
Conclusion
AML/CFT requirements are imposed on DPT service providers to mitigate the ML/TF risks arising from the anonymity, speed and cross-border nature of transactions that they facilitate. In Singapore, MAS has implemented AML/CFT requirements that are aligned with the revised FATF standards.
DPT service providers should ensure that their existing AML/CFT controls meet the requirements of MAS Notice PSN02 and the accompanying guidelines. Regular reviews of internal controls should be performed to keep pace with regulatory developments.
Refer to the following links on MAS’ AML/CFT Notice and Guidelines that all DPT service providers are required to comply with.
- MAS Notice PSN02 Prevention of Money Laundering and Countering the Financing of Terrorism – Digital Payment Token Service
- Guidelines to Notice PSN02 on Prevention of Money Laundering and Countering the Financing of Terrorism - Digital Payment Token Service.
Check out the following links for MAS’ guidance paper on AML/CFT controls for the DPT sector, and for the FATF’s report on VA ML/TF red flag indicators.
- Strengthening AML/CFT Controls of Digital Payment Token Service Providers
- Report on Red Flag Indicators of Money Laundering and Terrorist Financing (ML/TF) for Virtual Asset



