Back to Frameworks

Singapore Payment Services Act (PSA) - Digital Payment Token Regulation

Singapore (MAS)
v2019 (amended 2024)
6 domains
10 controls

Singapore's Payment Services Act (PSA, 2019, amended 2024) establishes a comprehensive licensing framework for payment services including digital payment token (DPT) services. Administered by the Monetary Authority of Singapore (MAS). Key requirements include: Major Payment Institution (MPI) licence for large-scale DPT services, Standard Payment Institution (SPI) licence for smaller operations, user protection requirements, AML/CFT compliance, technology risk management (MAS TRM Guidelines), and cyber hygiene. MAS has also issued PS-N02 (Notice on Prevention of Money Laundering and Countering the Financing of Terrorism for DPT Services) and Guidelines on Provision of Digital Payment Token Services to the Public.

Verified

Singapore Payment Services Act (PSA) - Digital Payment Token Regulation is a compliance framework from Singapore (MAS) with 6 domains and 10 controls that map to 10 other frameworks. The largest domains are MAS Notice PSN02: AML and CFT for Digital Payment Token Services (5 controls), AML/CFT (1 controls), Consumer Protection (1 controls). Every control below carries what it requires and what an assessor expects to see.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (6)

AML/CFT

1 controls
Controls in the AML/CFT domain of Singapore Payment Services Act (PSA) - Digital Payment Token Regulation1 controls
CodeTitle
SGPSA-2AML/CFT Risk Assessment and Customer Due Diligence

Consumer Protection

1 controls
Controls in the Consumer Protection domain of Singapore Payment Services Act (PSA) - Digital Payment Token Regulation1 controls
CodeTitle
SGPSA-5Customer Protection, Disclosures, Marketing Restrictions

Cybersecurity

1 controls
Controls in the Cybersecurity domain of Singapore Payment Services Act (PSA) - Digital Payment Token Regulation1 controls
CodeTitle
SGPSA-4Cybersecurity and Technology Risk for DPT Service Providers

Licensing

1 controls
Controls in the Licensing domain of Singapore Payment Services Act (PSA) - Digital Payment Token Regulation1 controls
CodeTitle
SGPSA-1Licensing for Digital Payment Token Services

MAS Notice PSN02: AML and CFT for Digital Payment Token Services

5 controls
Controls in the MAS Notice PSN02: AML and CFT for Digital Payment Token Services domain of Singapore Payment Services Act (PSA) - Digital Payment Token Regulation5 controls
CodeTitle
PSN02-1Customer due diligence
PSN02-2Suspicious transaction reporting
PSN02-3Record-keeping requirements
PSN02-4Sanctions screening
PSN02-5Internal policies and training

Travel Rule

1 controls
Controls in the Travel Rule domain of Singapore Payment Services Act (PSA) - Digital Payment Token Regulation1 controls
CodeTitle
SGPSA-3Travel Rule and Wire Transfer Information

Your Compliance Coverage

If you comply with Singapore Payment Services Act (PSA) - Digital Payment Token Regulation, you already cover:

Maps to 10 other frameworks

10 total controls
French Sapin II Law (Law No. 2016-1691)
1 source controls mapped|1 target controls covered
10%
US Automated Commercial Environment (ACE) - CBP Trade Data Requirements
1 source controls mapped|1 target controls covered
10%
Uganda Data Protection and Privacy Act (2019)
1 source controls mapped|1 target controls covered
10%
UAE Virtual Asset Regulatory Authority (VARA) Regulations
1 source controls mapped|1 target controls covered
10%
US OFAC Sanctions Compliance Framework
1 source controls mapped|4 target controls covered
10%
US ITAR and EAR - Export Control and Data Security
1 source controls mapped|1 target controls covered
10%
ISO/IEC 29147:2018
1 source controls mapped|1 target controls covered
10%
IAIS Insurance Core Principles (ICPs)
1 source controls mapped|1 target controls covered
10%
Sweden Data Protection Act (Dataskyddslag, 2018:218)
1 source controls mapped|1 target controls covered
10%
NIST SP 800-53 Rev 5
1 source controls mapped|1 target controls covered
10%

What is Singapore Payment Services Act (PSA) - Digital Payment Token Regulation and who does it apply to?

Singapore Payment Services Act (PSA) - Digital Payment Token Regulation is a compliance framework from Singapore (MAS) with 6 domains and 10 controls. Singapore's Payment Services Act (PSA, 2019, amended 2024) establishes a comprehensive licensing framework for payment services including digital payment token (DPT) services. Administered by the Monetary Authority of Singapore (MAS). Key requirements include: Major Payment Institution (MPI) licence for large-scale DPT services, Standard Payment Institution (SPI) licence for smaller operations, user protection requirements, AML/CFT compliance, technology risk management (MAS TRM Guidelines), and cyber hygiene. MAS has also issued PS-N02 (Notice on Prevention of Money Laundering and Countering the Financing of Terrorism for DPT Services) and Guidelines on Provision of Digital Payment Token Services to the Public. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

What does Singapore Payment Services Act (PSA) - Digital Payment Token Regulation actually require?

Singapore Payment Services Act (PSA) - Digital Payment Token Regulation has 10 controls organised across 6 domains. The largest domains are MAS Notice PSN02: AML and CFT for Digital Payment Token Services (5 controls), AML/CFT (1 controls), Consumer Protection (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

If I already comply with another framework, how much of Singapore Payment Services Act (PSA) - Digital Payment Token Regulation do I already cover?

Singapore Payment Services Act (PSA) - Digital Payment Token Regulation maps to 10 other compliance frameworks. The top mapping partners are French Sapin II Law (Law No. 2016-1691) (10% coverage), US Automated Commercial Environment (ACE) - CBP Trade Data Requirements (10% coverage), Uganda Data Protection and Privacy Act (2019) (10% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I implement Singapore Payment Services Act (PSA) - Digital Payment Token Regulation?

Start your Singapore Payment Services Act (PSA) - Digital Payment Token Regulation compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Singapore Payment Services Act (PSA) - Digital Payment Token Regulation requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 10 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.

Get Started Free →

Free forever — no credit card required