MAS Information Paper on AML/CFT Supervisory Expectations for Digital Payment Token Service Providers

Background

On 13 July 2026, MAS published an information paper setting out its supervisory expectations for digital payment token service providers (“DPTSPs”) across seven areas: new product (including token listing) risk assessment, enhanced customer due diligence (“ECDD”), value transfer requirements, ongoing monitoring, screening, due diligence on partners and outsourced providers, and training. The paper summarizes findings from MAS’ inspections and licensing engagements, and supplements Notice PSN02 and its Guidelines. It also continues a clear direction from the March 2021 guidance on strengthening DPTSP controls and the April 2022 name screening paper, signalling that MAS’ supervisory focus has shifted from whether frameworks exist to how well they are executed.   

MAS Expectations

  1. Token Listing and New Product Risk Assessment: DPTSPs must formally assess ML/TF risks before offering or listing any digital payment tokens (“DPT”) — covering the token’s association with higher-risk persons or jurisdictions, its track record and holding concentration, market manipulation indicators, and smart contract vulnerabilities. Critically, the assessment does not end at listing: adverse news for the DPTs must be monitored on an ongoing basis, and both the assessment criteria and any deviations from them must be documented with reasons.

  2. Enhanced Customer Due Diligence: For PEPs and higher-risk customers, MAS expects senior management approval, established source of wealth (“SOW”) and source of funds (“SOF”), and enhanced monitoring. Where funds arrive as DPTs, blockchain analytics should corroborate off-chain evidence. MAS found firms accepting customers’ own declarations as sufficient SOW/SOF evidence, and approving relationships despite obvious due diligence gaps.
     
  3. Value Transfers Requirements (Travel Rule): Originator and beneficiary information must be transmitted securely and concurrently with each transfer. MAS sets out six factors for evaluating Travel Rule solutions — coverage, interoperability, VASP due diligence, counterparty identification, immediacy of transmission, and data security — and expects firms to mitigate their chosen solution’s gaps rather than accept them. Enhanced risk mitigation applies to all transfers involving unhosted wallets, not merely those flagged by analytics tools, and firms should refrain from transfers where counterparty VASP risks cannot be managed. 

  4. Ongoing Monitoring: Monitoring must span both DPT and fiat legs of customer activity, with parameters calibrated to the firm’s own business model rather than vendor or group defaults, periodically reviewed, and supported by clear alert-handling procedures and quality assurance. Blockchain analytics alone is insufficient — one firm cleared sanctions-exposure alerts simply because transaction values were small, without examining timing or intermediary counterparties. DPTSPs must implement and regularly update risk-based, context-aware transaction monitoring parameters — rather than blindly adopting default or group settings —while also providing staff with clear alert-handling procedures and conducting quality assurance to identify and fix process weaknesses. 

  5. Screening: Screening must extend beyond customers to all relevant parties, including value transfer originators and beneficiaries, on a timely and ongoing basis. Annual re-screening leaves a window in which a customer sanctioned mid-cycle could transact undetected for months. Firms must also understand their screening vendors’ underlying databases — one  firm’s vendor gap caused a customer’s corruption charge to go entirely undetected. 

  6. Partners and Outsourced Providers: Due diligence on liquidity partners and outsourced AML functions is required at onboarding and periodically thereafter, with measurable KPIs, quality assurance reviews, control mechanisms, and onsite visits. Outsourcing the function does not outsource the responsibility for AML/CFT/CPF compliance with the regulations.  

  7. Training and Expertise: Training must be calibrated to role and risk — technical staff need AML/CFT/CPF awareness, compliance staff need baseline blockchain literacy, and key committees need balanced representation of both.  

What’s Next?

MAS expects DPTSPs to perform an enterprise-level gap analysis against the paper, ensuring the effectiveness of the AML/CFT/CPF controls. Board and senior management need to own the AML/CFT/CPF frameworks, integrate key findings into their policies and procedures and disseminate them to staff to strengthen organization-wide awareness of money laundering and terrorism financing risks. 

How Can We Help?

Capital Governance can assist financial institutions in 

  1. Reviewing Governance Framework: Conduct a gap analysis and designing standard operating procedures for AML/CFT/CPF frameworks and controls. 

  2. Refreshing P&Ps: Proposing tailored structural improvements and policy enhancements to ensure your AML/CFT/CPF controls and service provider due diligence can be documented to match the newly implemented MAS expectations. 
  3. AML/CFT/CPF Training: Training your team on basic understanding on the AML risks of blockchain and regulatory expectations.  

And more …