The Monetary Authority of Singapore (MAS) has published its information paper, AML/CFT Supervisory Expectations for Digital Payment Token Service Providers (DPTSPs), outlining critical systemic deficiencies in how digital asset firms execute anti-money laundering, countering the financing of terrorism, and countering proliferation financing (AML/CFT/CPF) controls.
Interpreting this update requires integrating three core strategic pillars: compliance-by-design, the elimination of operational silos, and the realignment of compliance alongside legal marketing. The deficiencies highlighted by MAS are rarely isolated software failures; they are structural breakdowns caused by departments operating in isolation.
When technology teams list tokens without granular compliance vetting, or compliance officers reject customers without cross-referencing broader corporate metrics, the entity operates in a silo. True compliance-by-design requires legal obligations to be hardcoded into product architecture and brand communications from day one, transforming regulatory adherence from a backend checkpoint into a foundational operational asset.
Deep Dive: Dissecting the Regulatory Gaps
MAS requires DPTSPs to conduct an immediate enterprise-level gap analysis under the strict oversight of the Board and senior management. Drawing from the case studies highlighted in the paper exposes severe execution failures within two core areas of Enhanced Customer Due Diligence (ECDD):
1. Breakdown of Senior Management Governance
The MAS Observation: Multiple DPTSPs routinely onboard higher-risk customers, including Politically Exposed Persons (PEPs), without securing mandatory senior management sign-off. In distinct cases, senior executives approved relationships despite glaring holes in the customer's risk profile.
The Structural Gap: When senior executives fail to document approval pathways for higher-risk clients, it signals a deeper cultural deficit. MAS is reminding the ecosystem that close, documented oversight of gap analyses and remediation measures is not administrative housekeeping. It is an explicit declaration that accountability for the effectiveness of compliance is entirely non-delegable. The control culture is set in the boardroom, or it is not set at all.
2. Failure to Verify Source of Wealth (SOW) and Source of Funds (SOF)
The MAS Observation: As demonstrated in Case Study D, DPTSP D conflated wealth with its provenance. Staff accepted bank statements showing a balance but failed to understand or document the underlying economic activities that generated those funds. Furthermore, firms failed to establish baseline SOW estimates for higher-risk clients upon onboarding.
The Structural Gap: Corroborating wealth derived from virtual assets requires parsing both on-chain transactions and off-chain documentation. A proper framework mandates that staff look beyond the immediate bank deposit to verify historical trading activity, corporate earnings, or token liquidation history, and assess the plausibility of the funds against the client's known profile.
The Software Dilemma: The Counterparty Bottleneck
Are current compliance software solutions a comprehensive, all-in-one remedy?
Most currently available solutions are built for yesterday's regulatory requirements. Furthermore, software architectures are frequently designed as siloed modules with a view to future cross-selling. When licensed entities rush to achieve compliance readiness, they often make the mistake of procuring disparate tools from various vendors, not based on a comprehensive vendor analysis, but simply because peer firms use them. While many vendors market "end-to-end" capabilities, the actual technology stack remains fragmented across on-chain telemetry, off-chain screening, and core governance, risk, and compliance (GRC) workflow engines.
Can current software support the updated MAS DPTSP demands?
Legacy systems built in the pre-generative and pre-agentic AI era will increasingly struggle to keep pace with evolving market demands. This dynamic is especially pronounced as the convergence of Web2 and Web3 ecosystems creates highly complex infrastructure requirements, necessitating architectural flexibility and operational autonomy rather than vendor-locked frameworks defined by costly change requests. Current compliance systems can only support these fluid modern demands if they are extensively customised and heavily augmented by human judgement.
MAS explicitly warns against relying blindly on vendor default configurations. Firms routinely fail inspections by adopting generic thresholds, rules, and risk parameters without tailoring them to their specific business models, transaction volumes, and risk appetite.
This software fragmentation becomes glaringly obvious during value transfers. As MAS highlights, while Notice PSN02 enforces the FATF Travel Rule locally, global adoption remains highly asymmetrical. Per the 2025 FATF Targeted Update, only 73% of assessed jurisdictions have passed implementing legislation.
The uncomfortable operational reality is that a Singapore firm's compliance is structurally bottlenecked by its chosen vendor's technical coverage and the regulatory maturity of its global counterparties. Interactions with unhosted wallets or unregulated VASPs cannot be treated as backend edge cases to be tolerated; they are the environments where enhanced measures, counterparty due diligence, and independent human verification must be strongest.
Resolving the Expertise Deficit: The Role of Compliance Firms
The MAS paper identifies a profound split in staff expertise: technical blockchain experts frequently lack basic money laundering and terrorist financing (ML/TF) risk awareness, while traditional compliance officers lack the technical capacity to understand complex digital asset structures and on-chain flow. To bridge this integration gap, compliance entities must shift away from static training modules toward applied operational education:
Balanced Committee Frameworks: Advanced firms must mandate that product approval, risk, and compliance committees maintain an equal representation of technical blockchain engineers and seasoned AML/legal practitioners to vet new token listings before deployment.
Granular, Capability-Based Training: Training programmes must be tailored strictly to specific corporate functions. Technical teams must be trained to identify exploitation vectors that enable layering, while compliance analysts must be upskilled in blockchain forensics, timestamping, and data lineage parsing.
Public-Private Informational Feedback Loops: Specialised industry networks must facilitate deeper dialogue between private compliance leads and public-sector authorities. Translating real-world enforcement trends into clear, plain-English operating procedures ensures that fast-moving policy updates are immediately absorbed into a firm's day-to-day workflow.
For firms navigating licensing or expansion under the current regime, this information paper must be approached as a supervisory mirror. A firm's AML/CFT posture is not a back-office matter; it is an active reflection of its institutional integrity and operational judgment.
The critical question this paper poses to the sector is not simply: "Do we have the required controls in place?"
The better, more urgent question is: "Could we provide evidence to a supervisor, right now, that those controls are fully understood, granularly documented, properly governed, and actively working?"
In this highly scrutinised landscape, trust is not built by the technology a firm deploys or the licence it holds. It is built entirely by the demonstrable governance behind both.
Read more here.