Singapore Payment Services Act (PSA) - Digital Payment Token Regulation
Singapore's Payment Services Act (PSA, 2019, amended 2024) establishes a comprehensive licensing framework for payment services including digital payment token (DPT) services. Administered by the Monetary Authority of Singapore (MAS). Key requirements include: Major Payment Institution (MPI) licence for large-scale DPT services, Standard Payment Institution (SPI) licence for smaller operations, user protection requirements, AML/CFT compliance, technology risk management (MAS TRM Guidelines), and cyber hygiene. MAS has also issued PS-N02 (Notice on Prevention of Money Laundering and Countering the Financing of Terrorism for DPT Services) and Guidelines on Provision of Digital Payment Token Services to the Public.
Singapore Payment Services Act (PSA) - Digital Payment Token Regulation is a compliance framework from Singapore (MAS) with 6 domains and 10 controls that map to 10 other frameworks. The largest domains are MAS Notice PSN02: AML and CFT for Digital Payment Token Services (5 controls), AML/CFT (1 controls), Consumer Protection (1 controls). Every control below carries what it requires and what an assessor expects to see.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (6)
AML/CFT
| Code | Title |
|---|---|
| SGPSA-2 | AML/CFT Risk Assessment and Customer Due Diligence |
Consumer Protection
| Code | Title |
|---|---|
| SGPSA-5 | Customer Protection, Disclosures, Marketing Restrictions |
Cybersecurity
| Code | Title |
|---|---|
| SGPSA-4 | Cybersecurity and Technology Risk for DPT Service Providers |
Licensing
| Code | Title |
|---|---|
| SGPSA-1 | Licensing for Digital Payment Token Services |
MAS Notice PSN02: AML and CFT for Digital Payment Token Services
| Code | Title |
|---|---|
| PSN02-1 | Customer due diligence |
| PSN02-2 | Suspicious transaction reporting |
| PSN02-3 | Record-keeping requirements |
| PSN02-4 | Sanctions screening |
| PSN02-5 | Internal policies and training |
Travel Rule
| Code | Title |
|---|---|
| SGPSA-3 | Travel Rule and Wire Transfer Information |
Your Compliance Coverage
If you comply with Singapore Payment Services Act (PSA) - Digital Payment Token Regulation, you already cover:
French Sapin II Law (Law No. 2016-1691)
10%
1 controls mapped
Compare →US Automated Commercial Environment (ACE) - CBP Trade Data Requirements
10%
1 controls mapped
Compare →Uganda Data Protection and Privacy Act (2019)
10%
1 controls mapped
Compare →+ 7 more: UAE Virtual Asset Regulatory Authority (VARA) Regulations (10%), US OFAC Sanctions Compliance Framework (10%)
See all 10 mapped frameworks ↓Maps to 10 other frameworks
What is Singapore Payment Services Act (PSA) - Digital Payment Token Regulation and who does it apply to?
Singapore Payment Services Act (PSA) - Digital Payment Token Regulation is a compliance framework from Singapore (MAS) with 6 domains and 10 controls. Singapore's Payment Services Act (PSA, 2019, amended 2024) establishes a comprehensive licensing framework for payment services including digital payment token (DPT) services. Administered by the Monetary Authority of Singapore (MAS). Key requirements include: Major Payment Institution (MPI) licence for large-scale DPT services, Standard Payment Institution (SPI) licence for smaller operations, user protection requirements, AML/CFT compliance, technology risk management (MAS TRM Guidelines), and cyber hygiene. MAS has also issued PS-N02 (Notice on Prevention of Money Laundering and Countering the Financing of Terrorism for DPT Services) and Guidelines on Provision of Digital Payment Token Services to the Public. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
What does Singapore Payment Services Act (PSA) - Digital Payment Token Regulation actually require?
Singapore Payment Services Act (PSA) - Digital Payment Token Regulation has 10 controls organised across 6 domains. The largest domains are MAS Notice PSN02: AML and CFT for Digital Payment Token Services (5 controls), AML/CFT (1 controls), Consumer Protection (1 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
If I already comply with another framework, how much of Singapore Payment Services Act (PSA) - Digital Payment Token Regulation do I already cover?
Singapore Payment Services Act (PSA) - Digital Payment Token Regulation maps to 10 other compliance frameworks. The top mapping partners are French Sapin II Law (Law No. 2016-1691) (10% coverage), US Automated Commercial Environment (ACE) - CBP Trade Data Requirements (10% coverage), Uganda Data Protection and Privacy Act (2019) (10% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I implement Singapore Payment Services Act (PSA) - Digital Payment Token Regulation?
Start your Singapore Payment Services Act (PSA) - Digital Payment Token Regulation compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Singapore Payment Services Act (PSA) - Digital Payment Token Regulation requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 10 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 686 frameworks.
Get Started Free →Free forever — no credit card required