MAS Notice PSN01: AML/CFT Requirements for Payment Service Providers
MAS Notice PSN01 is the principal AML/CFT obligation for payment service providers licensed in Singapore. It is the payments-sector counterpart to Notice 626, which governs banks — similar in architecture, materially different in its thresholds and in who it captures. This guide walks through the scope, the customer due diligence and enhanced due diligence requirements, the wire transfer rules, and the points where payments programmes most often come apart under supervision.
Payments firms in Singapore often arrive at AML/CFT compliance through a bank-shaped lens, because most of the available written guidance is bank-shaped. That is a reasonable starting point and a poor finishing one. MAS Notice 626 and Notice PSN01 share an architecture — both descend from the same FATF Recommendations — but they diverge in the places that matter operationally: which entities are captured, which transactions trigger due diligence, and what a firm without traditional accounts is expected to do when a customer never establishes a relationship at all.
This guide sets out what PSN01 requires and where payments programmes tend to fail. It describes obligations in force at the time of writing; the text a compliance team works to should always be the current consolidated Notice published on the MAS website, together with the accompanying Guidelines, rather than a remembered earlier edition.
Who Notice PSN01 Applies To
PSN01 applies to two groups: holders of a licence under the Payment Services Act 2019 that carry on a business of providing a specified payment service, and persons exempt under section 13(1) of that Act where they offer a specified product. The Notice refers to both collectively as payment service providers.
"Specified payment service" is defined narrowly and it is worth committing to memory, because it determines whether this Notice governs you at all:
- Account issuance service — including e-money and payment accounts.
- Domestic money transfer service.
- Cross-border money transfer service — inbound and outbound remittance.
- Money-changing service.
The Notice also carves out a narrow exemption at paragraph 3.2 for genuinely low-value, low-risk products — broadly, account issuance products that permit no cash withdrawal, cap cash refunds at S$100 absent identification, and cannot hold more than S$1,000. The conditions are cumulative and strictly drawn. Treat the exemption as unavailable unless you have tested the product against every limb and documented the conclusion.
Where PSN01 Sits in the Legal Framework
PSN01 is issued under section 16 of the Financial Services and Markets Act 2022. This is a detail worth stating precisely, because it is frequently reported as a Payment Services Act notice. The PS Act determines who must be licensed and for what; the FSM Act is the instrument under which MAS issues the AML/CFT Notice that binds those licensees. Both statutes are engaged, and the Notice itself refers to PS Act licence classes throughout.
Two further distinctions matter in practice:
- The Notice is binding; the Guidelines are not. MAS publishes accompanying Guidelines to Notice PSN01 that explain how it expects the requirements to be applied. They do not have the force of law, and MAS will nonetheless assess a programme against them. Treating them as optional reading is a recognisable way to fail an inspection.
- Reporting obligations sit elsewhere. The duty to report suspicion arises under the Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act and the Terrorism (Suppression of Financing) Act 2002. PSN01 requires the internal machinery that makes those statutory obligations operable.
For the wider Singapore picture and how the regimes interlock, see our overview of MAS AML/CFT regulation.
Risk Assessment and the Risk-Based Approach
Paragraph 5 requires every payment service provider to identify, assess and understand its money laundering and terrorism financing risks across four dimensions: its customers; the countries or jurisdictions its customers are from or in; the jurisdictions the firm itself operates in; and its own products, services, transactions and delivery channels.
The obligation is explicit that these steps include documenting the assessment, considering all relevant risk factors before concluding on overall risk, and keeping the assessment current. An undocumented risk assessment is not a risk assessment for these purposes.
The delivery-channel limb deserves more attention than payments firms usually give it. A remittance business operating through agents, a wallet onboarding entirely remotely, and an acquirer onboarding merchants through a reseller carry materially different exposures, and a single generic assessment will not survive contact with a supervisor. Our enterprise-wide risk assessment guide sets out a defensible structure, and customer risk assessment covers the customer-level scoring that follows from it.
Customer Due Diligence and the S$5,000 Trigger
CDD under PSN01 follows the familiar shape — identify the customer, verify identity from reliable independent sources, identify and take reasonable measures to verify any beneficial owner, understand the purpose and intended nature of the relationship, and conduct ongoing monitoring.
What differs from the banking regime is when it bites. Payments firms routinely serve customers who never open an account, and the Notice addresses this directly. CDD is required where, among other triggers, the firm undertakes any transaction exceeding S$5,000 for a customer who has not otherwise established business relations — the occasional-transaction threshold — and wherever there is a suspicion of money laundering or terrorism financing, regardless of amount or any threshold or exemption that would otherwise apply.
Money-changing carries its own calibration. A "specified money-changing transaction" is one not exceeding S$20,000 where the money is funded from an identifiable source, or not exceeding S$5,000 in any other case. Whether funds come from an identifiable source is therefore a determination with direct consequences, and it should be recorded rather than assumed.
Paragraph 8 permits simplified CDD in lower-risk circumstances, and paragraph 7 requires ongoing review so that customer information does not silently go stale. Simplified measures are a calibration of CDD, not an exemption from it, and the basis for applying them has to be documented.
Enhanced Due Diligence and Politically Exposed Persons
Paragraph 9 governs enhanced due diligence. Its PEP provisions are stricter than the FATF baseline and are frequently under-implemented in payments firms.
PSN01 defines a politically exposed person as a domestic PEP, a foreign PEP, or an international organisation PEP, and defines "prominent public functions" to include heads of state and government, government ministers, senior civil or public servants, senior judicial or military officials, senior executives of state-owned corporations, senior political party officials, members of the legislature and senior management of international organisations.
Where a customer or any beneficial owner is a PEP — or a family member or close associate of one — the firm must, in addition to ordinary CDD:
- obtain senior management approval to establish or continue the relationship, or to undertake the transaction where no account is opened;
- establish by appropriate and reasonable means the source of wealth and source of funds of the customer and any beneficial owner; and
- conduct enhanced ongoing monitoring, increasing the degree and nature of monitoring to determine whether the relationship or its transactions appear unusual or suspicious.
Paragraph 9 also treats jurisdictional exposure as a higher-risk circumstance, requiring firms to treat business relations and transactions involving customers from or in jurisdictions for which FATF has called for countermeasures as presenting high risk. See when EDD is required and how to apply it for the operational detail, and PEP screening for how the determination is made at scale.
Wire Transfers: the S$1,500 Threshold
Paragraph 15 is where payments firms carry obligations banks rarely think about in the same terms, and it is the most commonly mis-built part of a PSN01 programme.
The Notice distinguishes cross-border wire transfers below or equal to S$1,500 from those exceeding S$1,500, and sets different information requirements for each. In both cases the ordering institution must include originator and beneficiary information with the message or payment instruction; above the threshold the requirements are fuller and the verification expectations higher. Firms acting as beneficiary institution or as intermediary have their own obligations, including ensuring information is not stripped in transit and that transfers remain traceable.
Three practical points:
- Role determines duty. The same firm may be ordering institution on one leg and beneficiary institution on another. Controls built only for the outbound case leave the inbound case uncovered.
- Threshold logic must be currency-aware. The figure is expressed in Singapore dollars; a transfer denominated in another currency still has to be assessed against it.
- Missing information is an event, not a nuisance. Incoming transfers lacking required information need a defined path — query, reject, or accept with justification — and that path has to be evidenced.
Firms that also move virtual assets will recognise the shape of this from FATF Recommendation 16, and should be careful not to assume one implementation satisfies the other.
Cash, Foreign Exchange and Bearer Instruments
Paragraphs 10 and 11 impose obligations that have no close analogue in the banking notice.
For foreign currency exchange, where the value of an FX transaction is equal to or exceeds S$20,000 (or its foreign currency equivalent), the CDD, simplified CDD and EDD paragraphs apply to it. The Notice further requires firms to inquire, so far as possible, into the background and purpose of every such transaction and to document the findings so they are available to the relevant authorities.
Paragraph 11 restricts the payment of cash at or above S$20,000 in defined circumstances, permits payment by crossed cheque subject to conditions, and requires linked transactions to be aggregated where the firm suspects they have been split to evade the restriction.
These provisions tend to be handled by front-line staff under time pressure rather than by the compliance function, which is exactly why they should be enforced by system controls and not by training alone. A limit that depends on a cashier remembering it is not a control.
Third Parties, Correspondents and Agents
Paragraphs 12 to 14 deal with the parts of the operation a firm does not perform itself.
- Reliance on third parties (12). Reliance is permitted within limits, but the obligation remains with the relying firm. Information must be obtainable without delay and the underlying records must be available on request.
- Correspondent accounts (13). Cross-border correspondent relationships attract additional due diligence on the respondent, its controls and its supervision.
- Agency arrangements (14). Agents performing customer-facing functions remain the principal’s responsibility. For remittance businesses operating through agent networks, this is often the single largest practical exposure in the programme.
The common failure across all three is the assumption that outsourcing the activity outsources the obligation. It does not, and the evidence a supervisor asks for — what the agent did, when, on what basis — is exactly what a loosely governed agent network cannot produce.
Suspicious Transaction Reporting, Records and Governance
Paragraph 18 requires a single internal reference point to whom all staff are instructed to promptly refer transactions suspected of being connected with money laundering or terrorism financing, for possible referral to the Suspicious Transaction Reporting Office — STRO, part of the Commercial Affairs Department of the Singapore Police Force — and records to be kept of all such internal referrals, including those not escalated externally.
That last point is regularly missed. The decision not to file is as much a decision as the decision to file, and it has to be recorded with its reasoning. Our guide to SAR/STR filing covers the internal process in depth, and SAR/STR reporting covers the case management side.
Paragraph 16 sets record-keeping obligations, paragraph 17 addresses personal data, and paragraph 19 requires internal policies, procedures and controls proportionate to the firm’s risks and size, independent audit, and staff training. Firms incorporated in Singapore must additionally develop a group AML/CFT policy and extend it to branches and subsidiaries across the financial group, with defined treatment where a host jurisdiction’s requirements differ.
The compliance officer function and the training obligation are covered further in the MLRO role and personal liability and AML training programme requirements.
Where PSN01 Programmes Fail
The recurring weaknesses in payments programmes are different from those in banks, and they cluster around the places where the payments model diverges from the banking model:
- Treating PSN01 as Notice 626 with different numbers. The occasional-transaction trigger, the wire transfer thresholds and the FX and cash provisions have no direct banking equivalent, and a lifted bank programme simply does not contain them.
- Thresholds implemented per transaction, never in aggregate. The single most predictable evasion, and the one a supervisor will test first.
- PEP screening scoped to customers only. The obligation extends to beneficial owners, persons appointed to act, connected parties, and to family members and close associates.
- Agent networks governed by contract alone. A contractual obligation with no assurance activity behind it produces no evidence.
- Wire transfer controls built for one direction. Outbound covered, inbound unexamined, intermediary role unconsidered.
- Monitoring calibrated to volume rather than to risk. High-volume, low-value payments businesses generate alert counts that overwhelm small teams, which produces rushed closures and late STRs.
None of these are documentation gaps. Each is a practice failure that survives comfortably in a programme that reads well on paper, which is precisely why they are found during inspection rather than during policy review.
AML/CFT Built for Payment Service Providers
One Constellation supports PSN01 compliance with risk-based CDD and threshold logic that aggregates linked transactions, PEP and sanctions screening extending to beneficial owners and close associates, wire transfer controls covering both directions, and STR-ready case management.
