Digital Payment Token (DPT) service providers are required to have robust anti-money laundering and countering the financing of terrorism (AML/CFT) controls in place.
DPTs can be abused for illicit purposes due to their pseudonymous nature, and the potential use to facilitate fast and cross-border transactions.
DPT service providers are important gatekeepers in the financial system and are required to apply for a license under paragraph 5 of the Payment Services Act (PSA). DPT service providers are also required to have robust AML/CFT controls to identify and verify their customers, and detect and deter the flow of illicit funds on an ongoing basis.
More details on the AML/CFT requirements applicable to DPT service providers can be found under MAS Notice PSN02 (issued on 5 December 2019) and Guidelines to MAS Notice PSN02 (issued on 16 March 2020).
In March 2021, MAS published a guidance paper on “Strengthening AML/CFT Controls of Digital Payment Token Service Providers” to enhance industry awareness to the ML/TF risks in the DPT sector, and provide guidance to help DPT service providers implement effective AML/CFT controls.
In that guidance paper, MAS highlighted its supervisory expectations on the key AML/CFT considerations relating to new DPT products, enhanced customer due diligence (ECDD) and value transfers, which are aligned with international developments and standards.
This content leverages on the key highlights from the MAS’ guidance paper to help DPT service providers understand existing AML/CFT requirements.
Under paragraph 2 of the PSA, “digital payment token” means any digital representation of value (other than an excluded digital representation of value) that:
More details on the types of regulated DPT activities can be found under the First Schedule of the PSA.
Entities that:
are required to be licensed as DPT service providers, and comply with MAS’ AML/CFT laws and regulations.
FATF, the global AML/CFT inter-governmental body, revised the FATF Standards to require countries to regulate VASPs to mitigate ML/TF risks. VASPs include entities known locally as DPT Service Providers.
In particular, FATF amended Recommendation 15 to scope in virtual assets (VA) and VASPs in October 2018 and provided additional guidance in June 2019. FATF continues to monitor the VASP sector via two 12-month reviews, and has urged members to continue to make progress in implementing the revised FATF standards in their domestic regimes.
DPT service providers must abide by the AML/CFT requirements in MAS Notice PSN02. Some key AML/CFT requirements include:
Additional information on MAS’ expectations relating to:
These three areas are highlighted in bold in the following diagram for your reference.
Licensees should refer to MAS Notice PSN02, and the accompanying Guidelines to the Notice, for the full set of AML/CFT requirements and MAS’ supervisory expectations. Licensees should also ensure that they monitor for, and take note of additional AML/CFT guidance that MAS may release from time to time.
DPT service providers should have a formalised approach to identify and assess the ML/TF risks involved, before offering new products (including listing of new DPTs on their platform). In particular, DPT service providers should ensure that the:
As part of Enhanced Customer Due Diligence (ECDD) measures, DPT service providers should:
DPT service providers should monitor business relations with customers on an ongoing basis, and ensure that transactions are consistent with knowledge of the customer, its business and risk profile, and source of funds. In particular, DPT service providers need to pay attention to all complex, unusually large or unusual patterns of transactions undertaken, that have no apparent or visible economic or lawful purpose.
This review should include consideration of the following factors:
AML/CFT requirements are imposed on DPT service providers to mitigate the ML/TF risks arising from the anonymity, speed and cross-border nature of transactions that they facilitate. In Singapore, MAS has implemented AML/CFT requirements that are aligned with the revised FATF standards.
DPT service providers should ensure that their existing AML/CFT controls meet the requirements of MAS Notice PSN02 and the accompanying guidelines. Regular reviews of internal controls should be performed to keep pace with regulatory developments.
Refer to the following links on MAS’ AML/CFT Notice and Guidelines that all DPT service providers are required to comply with.
Check out the following links for MAS’ guidance paper on AML/CFT controls for the DPT sector, and for the FATF’s report on VA ML/TF red flag indicators.