Singapore Payment Services Act (PSA) — Digital Payment Token Regulation
Singapore's Payment Services Act (PSA, 2019, amended 2024) establishes a comprehensive licensing framework for payment services including digital payment token (DPT) services. Administered by the Monetary Authority of Singapore (MAS). Key requirements include: Major Payment Institution (MPI) licence for large-scale DPT services, Standard Payment Institution (SPI) licence for smaller operations, user protection requirements, AML/CFT compliance, technology risk management (MAS TRM Guidelines), and cyber hygiene. MAS has also issued PS-N02 (Notice on Prevention of Money Laundering and Countering the Financing of Terrorism for DPT Services) and Guidelines on Provision of Digital Payment Token Services to the Public.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (15)
AML and CFT
| Code | Title |
|---|---|
| PSA-DPT-03 | Enterprise-Wide AML and CFT Risk Assessment |
| PSA-DPT-04 | Customer Due Diligence on DPT Customers |
| PSA-DPT-05 | Enhanced Due Diligence for Higher Risk Customers |
| PSA-DPT-06 | Travel Rule for DPT Transfers |
| PSA-DPT-07 | Transaction Monitoring and Suspicious Reporting |
| PSA-DPT-08 | Sanctions and Targeted Financial Sanctions Screening |
Assurance
| Code | Title |
|---|---|
| PSA-DPT-21 | Independent Audit of PSA Compliance |
Conduct and consumer protection
| Code | Title |
|---|---|
| PSA-DPT-15 | Risk-Disclosure to Retail Customers |
| PSA-DPT-16 | Restrictions on Public Promotion of DPT Services |
| PSA-DPT-17 | Customer Suitability and Access Safeguards |
| PSA-DPT-18 | Complaints Handling |
Customer asset protection
| Code | Title |
|---|---|
| PSA-DPT-09 | Safeguarding of Customer Assets |
| PSA-DPT-10 | Custody Controls for DPT Wallets |
DPT Licensing
Digital payment token service regulation
Governance
| Code | Title |
|---|---|
| PSA-DPT-02 | Fit and Proper Assessment of Key Personnel |
Licensing and authorisation
| Code | Title |
|---|---|
| PSA-DPT-01 | Licensing for Digital Payment Token Services |
Operational and technology risk
| Code | Title |
|---|---|
| PSA-DPT-11 | Technology Risk Management |
| PSA-DPT-12 | Cyber Hygiene Controls |
| PSA-DPT-13 | Business Continuity and Incident Response |
Outsourcing
| Code | Title |
|---|---|
| PSA-DPT-14 | Outsourcing and Third-Party Risk Management |
Part 1 — Preliminary
| Code | Title |
|---|---|
| MHR-1 | Objects and Definitions |
| MHR-2 | Application and Scope |
| OSA-1 | Objects and Definitions |
| OSA-2 | Scope of Application |
| POFMA-1.1 | Definitions and Interpretation (Sections 2-3) |
| POFMA-1.2 | Application and Scope (Section 4) |
| Sec. 1 | Short Title and Commencement |
| Sec. 2 | Interpretation |
| Sec. 3 | Scope and Application |
| Sec. 6 | Establishment of the Commission |
Part 2 — Licensing of Payment Service Providers
| Code | Title |
|---|---|
| Sec. 11 | Deemed Consent |
| Sec. 5 | Functions and Duties of Authority |
| Sec. 6 | Establishment of the Commission |
| Sec. 7 | Responsibilities of Organisation |
| Sec. 8 | Functions of the Commission |
Part 3 — Conduct of Business
| Code | Title |
|---|---|
| Sec. 23 | Storage Limitation |
| Sec. 24 | Integrity and Confidentiality |
| Sec. 25 | Interpretation |
| Sec. 26 | Notifiable Data Breaches |
| Sec. 27 | Duty to Conduct Assessment |
Part 4 — Directions, Inspections and Investigations
| Code | Title |
|---|---|
| Sec. 31 | Unauthorised Disclosure |
| Sec. 35 | Security of Processing |
| Sec. 37 | Financial Penalties |
| Sec. 40 | Right to Object |
Part 5 — DPT-Specific Consumer Protections
| Code | Title |
|---|---|
| Sec. 54 | Risk disclosure requirements |
| Sec. 55 | Data Breach Notification |
| Sec. 56 | Complaints Mechanism |
| Sec. 57 | Business conduct standards |
| Sec. 58 | Administrative Offences |
Recordkeeping and reporting
| Code | Title |
|---|---|
| PSA-DPT-19 | Recordkeeping for DPT Services |
| PSA-DPT-20 | Regulatory Reporting and Notifications |
Your Compliance Coverage
If you comply with Singapore Payment Services Act (PSA) — Digital Payment Token Regulation, you already cover:
Australia Consumer Data Right — Banking (CDR)
29%
14 controls mapped
Compare →EU Network Code on Cybersecurity for the Electricity Sector
29%
14 controls mapped
Compare →African Union Malabo Convention
29%
14 controls mapped
Compare →+ 603 more: MiFID II / MiFIR (29%), Chile Personal Data Protection Law (Law No. 21.719) (29%)
See all 606 mapped frameworks ↓Maps to 606 other frameworks
Frequently Asked Questions
What is Singapore Payment Services Act (PSA) — Digital Payment Token Regulation?
Singapore Payment Services Act (PSA) — Digital Payment Token Regulation is a compliance framework from Singapore (MAS) with 15 domains and 50 controls. Singapore's Payment Services Act (PSA, 2019, amended 2024) establishes a comprehensive licensing framework for payment services including digital payment token (DPT) services. Administered by the Monetary Authority of Singapore (MAS). Key requirements include: Major Payment Institution (MPI) licence for large-scale DPT services, Standard Payment Institution (SPI) licence for smaller operations, user protection requirements, AML/CFT compliance, technology risk management (MAS TRM Guidelines), and cyber hygiene. MAS has also issued PS-N02 (Notice on Prevention of Money Laundering and Countering the Financing of Terrorism for DPT Services) and Guidelines on Provision of Digital Payment Token Services to the Public. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Singapore Payment Services Act (PSA) — Digital Payment Token Regulation have?
Singapore Payment Services Act (PSA) — Digital Payment Token Regulation has 50 controls organised across 15 domains. The largest domains are Part 1 — Preliminary (10 controls), AML and CFT (6 controls), Part 2 — Licensing of Payment Service Providers (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Singapore Payment Services Act (PSA) — Digital Payment Token Regulation map to?
Singapore Payment Services Act (PSA) — Digital Payment Token Regulation maps to 606 other compliance frameworks. The top mapping partners are Australia Consumer Data Right — Banking (CDR) (29% coverage), EU Network Code on Cybersecurity for the Electricity Sector (29% coverage), African Union Malabo Convention (29% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Singapore Payment Services Act (PSA) — Digital Payment Token Regulation compliance?
Start your Singapore Payment Services Act (PSA) — Digital Payment Token Regulation compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Singapore Payment Services Act (PSA) — Digital Payment Token Regulation requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 50 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required