On 8 April 2025, the Monetary Authority of Singapore (“MAS”) published a Consultation Paper on the Proposed Amendments to Anti-Money Laundering and Countering the Financing of Terrorism Notices for Financial Institutions and Variable Capital Companies. In this consultation, the MAS proposes streamlined amendments across all financial institutions that predominantly implement best practices that were communicated previously. Clearly, the amendments result in higher requirements for the financial institutions’ anti-money laundering (“AML”) and countering the financing of terrorism (“CFT”) measures. The consultation period ends on 8 May 2025. The MAS expects the amendments to take effect from 30 June 2025. 

In this article, we outline the proposed amendments.

Inclusion of Proliferation Financing

To better align AML/CFT regulations in Singapore with the revised FATF standards, the MAS proposes to explicitly state that money laundering (“ML”) includes proliferation financing (“PF”). Therefore, financial institutions must identify, assess, understand and mitigate their PF risks and, thus,include adequate measures to counter PFin their AML/CFT frameworks. Most financial institutions are expected to already include PF in their AML/CFT frameworks. The existing AML guidelines already include information, including red flags, regarding PF.

Expansion of Trust Relevant Parties

The MAS proposes to amend the definition of trust relevant parties in its Notice on Prevention of Money Laundering and Countering the Financing of Terrorism – Trust Companies (“TCA-N03”) and to reference this definition in its AML/CFT notices applicable to other types of financial institutions, for example, the Notice on Prevention of Money Laundering and Countering the Financing of Terrorism – Capital Markets Intermediaries (“SFA04-N02”).

[1] An “object of power” is proposed to mean “a person who

    • Is a member of a class of possible beneficiaries under the trust; and
    • Is reasonably expected to benefit from the trust, whether or not because
      • The person is referred to as a potential beneficiary by the settlor of the trust in a document relating to the trust such as the letter of wishes; or
      • The class of possible beneficiaries has narrowed for any reason.”

 

The MAS proposes that a financial institution must, in addition to the information prescribed for the existing trust relevant parties, obtain information on the identity of the protector, the identity of the class of beneficiaries and object of power, and of any other natural person(s) exercising ultimate effective control over a trust related party. This included information on beneficial owners of a legal person or a legal arrangement that is a trust relevant party. 

Clarification of Timelines for Filing of Suspicious Transaction Reports 

The MAS proposes to reduce the number of days to submit a suspicious transaction report (“STR”) from 15 business days of the case being referred by the relevant employee of the financial institution to 5 business days after suspicion was first established, in the case of sanctions, 1 business day after suspicion was first established. 

In addition, in the proposed amendments to the AML Guidelines, the MAS is promoting a risk-based monitoring to identify and prioritise the review of concerns of higher ML/TF risk. These concerns should be promptly reviewed and escalated for mitigating measures where required. 

Amendments to the Notices and Guidelines 

In this section, we highlight pertinent proposed changes to the notices and guidelines on AML/CFT, in particular the Notice on Prevention of Money Laundering and Countering the Financing of Terrorism – Capital Markets Intermediaries (SFA04-N02) and the Guidelines to MAS Notice SFA04-N02 on Prevention of Money Laundering and the Financing of Terrorism (Guidelines to SFA04-N02). Please note that we do not list all proposed amendments to the notices and guidelines. 

Identification of Beneficial Owners 

Instead of requiring financial institutions to take reasonable measures to verify the identities of the beneficial owners, the MAS proposes that financial institutions must obtain specified information on the beneficial owners that is similar to the information required from the customers.² 

[2] You may note that the MAS is also proposing a list of information required from beneficial owners that are a legal person or legal arrangement.

Guidance to Identify Fraudulent or Tampered Data, Documents or Information 

The MAS proposes that financial institutions must provide their staff with adequate guidance on how to identify indicators of fraudulent or tampered data, documents or information. Indicators include 

  • significant discrepancies in a customer’s representations that are found when these representations are checked against independent sources of information, such as corporate data reports; 
  • accounting errors, or anomalies in financial statements that are not in line with the financial institution’s understanding of the customer’s profile; and 
  • lack of sign-off by relevant certifying parties such as an auditor or notary public. 

If any indicators are detected, the matter should be escalated and appropriate ML/TF risk mitigation measures applied. 

Sharing of Information on Customers 

To ensure the holistic monitoring of customer accounts, the MAS proposes that financial institutions have processes to share information on customers and their related accounts within and across business units. The information shared should minimally include the information to identify the customer and the source of wealth. 

Enhancements in Screening 

The MAS proposes that financial institutions screen against pertinent search engines, in addition to commercial databases. Financial institutions should conduct screening in the native language(s) of the person screened and on pertinent search engines used in countries or jurisdictions closely associated with the person screened. 

Higher-risk Shell Companies 

The MAS provides examples of characteristics displayed by higher-risk shell companies. These include: 

  • Unclear economic purpose for requiring an account relationship in Singapore; 
  • Unclear economic purpose for linking a common individual/address to multiple companies; 
  • Unrelated third parties are added to operate an account after the account opening; 
  • Unusual change of corporate structure/beneficial owner after the account opening; 
  • Suspicious transactions which are not in line with the financial institution’s understanding of the customer; or  
  • Superficial corporate websites that are inconsistent with the scale of the business. 

Examples are provided for most cases. 

Clarification on the Establishment and Corroboration of the Source of Wealth 

The MAS proposes changes to reflect its latest guidance on the establishment and corroboration of the source of wealth, including a risk-based approach. 

Reflecting a risk-based approach, the MAS indicates that financial institutions should obtain source of wealth information to the extent practicable about the entire body of wealth that the customer and beneficial owner would be expected to have, and how the customer and beneficial owner acquired the wealth. Accordingly, the MAS expects financial institutions to establish the seed moneythat generated subsequent wealth. Where a material source of wealth of the customer or beneficial owner is a gift or other asset received from third parties, financial institutions should obtain information to establish the legitimacy and plausibility of the gift or other asset. This should include establishing the relationship between the third party and the customer or beneficial owner, verifying the transaction(s) effecting such gift or other asset against reliable and independent sources of information, and assessing the plausibility of the third party’s source of wealth. 

Financial institutions should take a risk-based approach and focus on corroboration of sources of wealth and sources of funds that are more material or present a higher risk for ML/TF. 

Financial institutions should ensure that sources of wealth and sources of funds are established through appropriate and reasonable means, to the extent practicable, using reliable and independent sources of information. Examples of appropriate and reasonable means include credible public sources. Where independent sources of information are not available, financial institutions should exercise prudence in the use of non-independent sources of information, such as customer representations, assumptions and benchmarks, to ensure adequate rigour of assessment. This should include the performance of additional checks against alternative information sources. Moreover, the financial institutions basis for using such information should be documented and reviewed periodically. 

Where a financial institution is unable to corroborate any more material source of wealth or source of funds that presents a higher risk for ML/TF, it should assess whether the residual risks associated with not corroborating this source of wealth or source of funds is acceptable and whether additional risk mitigation measures should be applied in the absence of corroboration. 

Finally, the MAS proposes to classify all offering of personalised wealth management services, financial advisory services and financial products to high-net-worth individuals as higher-risk business. As a result, financial institutions are expected to independently corroborate these customers sources of wealth and screen operating companies and individual benefactors contributing to the customer’s and beneficial owner’s wealth. 

Participation in Tax Amnesty as Indicator of Higher Risk 

The MAS proposes adding participation in a tax amnesty programme to its list of examples of suspicious transactions (situations) in the section on tax crime-related transactions and requests financial institutions to file an STR when a customer has indicated that it has participated in a tax amnesty programme. 

 

How We Can Help 

Ingenia Consultants Pte. Ltd. provides regulatory support services for financial institutions, including compliance and internal audit. We assist in the review and enhancement of AML/CFT frameworks, carry out customer due diligence, and review such efforts by financial institutions to provide their senior management and board of directors assurance through our internal audits. 

For more information on our compliance and internal audit services and capabilities, please contact: 

Rolf Haudenschild

Co-founder 

Ingenia Consultants Pte. Ltd. 

rolf.haudenschild@ingenia-consultants.com 

The International Internal Audit Standards Board released the new Global Internal Audit Standards (the new “IIA Standards”) on 9 January 2024, and the internal audit functions were required to adopt the new Standards by 9January 2025 

Based on the new IIA Standards, the Institute of Internal Auditors (IIA) has introduced several key changes that can impact the selection of consulting firms a company, such as a financial institution, engages to carry out its internal audit as an outsourced service provider 

  • Stricter independence of the internal audit services (the new “Organizational Independent Standard”) 
  • Greater emphasis on risk-based auditing (the new “Engagement Risk Assessment Standards”) 
  • Higher expectations for internal audit quality and objectivity 
  • More focus on environmental, social and governance (“ESG”), and cybersecurity audits 
  • Adoption of technology and data analytics 

Enhanced Internal Audit Standards 

Organisational Independence 

Under the new Organizational Independence Standard, internal audit service providers are expected to follow stricter independence requirements when providing internal audit and consulting services for the same client. The chief audit executive is required to be qualified and report directly to the board of directors (the “Board”) and the function is positioned at a level within the organization that enables the internal audit function to discharge its service and responsibilities without interference.  

Risk-based Audit 

The new Engagement Risk Assessment Standards reinforce a risk-based approach, requiring internal audits to focus on high-risk areas. Consulting firms that perform internal audits based on regulation or SOX requirements may need to adjust audit methodologies or approaches to align with these new expectations. Internal auditors need to consult with their clients to identify high-risk areas and assess the inherent risk, including alignment with the company’s risk appetite and industry best practices. 

Competency 

The new Competency Standard requires internal auditors to possess or obtain the relevant industry knowledge and auditing standards to perform their responsibilities successfully. For example, to conduct internal audits in the financial sector, the internal audit staff should have the knowledge about applicable regulations and business models, experience to understand the operations of the financial institutions and applicable industry practices, and the skills and abilities to conduct the test of design and test of execution of the financial institution in accordance with the IIA Standards and clearly communicate the findings to the financial institution’s Board and senior management. 

Focus on ESG and Cybersecurity 

The chief audit executive should seek inputs from the Board on the governance and risk management concerns related to non-financial matters such as strategic initiatives, cyber security, health and safety, sustainability, business resilience and reputation and address them as part of the proposed internal audit plan.  

Use of Technology and Data Analytics 

As part of their due professional care, internal auditors are required to consider the efficient use of techniques, tools, and technology and the extent and timeliness of work to achieve the engagement objective. For this purpose, internal auditors may use data analysis software and technologies. 

How We Can Help 

Ingenia Consultants Pte. Ltd. is well-positioned to provide an independent and objective assurance review in accordance with the new IIA Standard. 

Ingenia Consultants Pte. Ltd. is a corporate member of the Institute of Internal Auditors (IIA). Our internal audit team is headed by a certified public accountant (“CPA”) and led by a certified internal auditor (“CIA”). To ensure the independence of our internal audit, in particular, from our regulatory compliance services, we maintain an independent internal audit business unit with separate staff and a separate system dedicated to internal audit. 

At the outset of our internal audit engagements, we work with our clients (their board of directors or senior management) to identify high-risk areas, assess the inherent risk and align our internal audit with the risk appetite determined by the board of directors and industry best practices. To strengthen this process, we also leverage anonymised industry data from our extensive work over several years. 

For more information on our internal audit services and capabilities, please contact: 

Kew Yip Han 

Manager 

Ingenia Consultants Pte. Ltd. 

yiphan.kew@ingenia-consultants.com 

The Monetary Authority of Singapore (“MAS”) released its 2024 Proliferation Financing (“PF”) National Risk Assessment (“NRA”) and Counter-PF Strategy on 30 October 2024. This provides an in-depth analysis of Singapore’s exposure to PF risks and outlines a comprehensive framework to mitigate them. As PF threats grow more complex, the MAS emphasises the importance of financial institutions (“FIs”) enhancing their compliance measures to align them with regulatory expectations and evolving risks. 

The assessment identifies several key threats to Singapore’s financial system. A major concern is the misuse of legal entities to obscure the origins and movement of funds, as proliferators often rely on complex corporate structures to conceal illicit financial flows. Additionally, ship-to-ship transfers present another challenge, facilitating the evasion of sanctions and export controls. The trade in dual-use goods—items with both civilian and military applications—poses a heightened risk, as these goods may be diverted for unauthorized purposes. Moreover, luxury goods exports are increasingly exploited as part of PF networks, while virtual assets pose anonymity risks that make them vulnerable to misuse by sanctioned entities. 

The report further highlights that both financial and non-financial sectors are exposed to PF risks. The financial sector, including banks, digital payment token service providers, remittance agents, and maritime insurers, faces heightened risks due to the nature of its operations, which involve international transactions and potential exposure to illicit actors. Similarly, the sector of designated non-financial professions and businesses (“DNFPBs”), including corporate service providers, dealers in precious metals and stones, and legal professionals, is identified as being at risk due to its role in facilitating business transactions, managing client funds, and establishing corporate structures that could be misused for PF purposes. 

In response to these risks, the MAS has developed a counter-PF strategy focused on strengthening Singapore’s defences. The strategy emphasizes raising awareness and building capabilities by engaging financial institutions and businesses to ensure a deeper understanding of PF risks and regulatory expectations. Enhanced compliance measures, including stricter due diligence, improved transaction monitoring, and more effective screening processes to detect and prevent PF-related activities, are essential components of this strategy. The regulatory framework will also have to undergo continuous risk assessments and adaptations to remain responsive to emerging threats in the global financial landscape. 

The implications of this assessment and strategy for financial institutions are significant. FIs must enhance their risk assessment frameworks by integrating the MAS’ findings into their internal risk models. Strengthening due diligence measures, particularly for high-risk sectors and jurisdictions, is critical to mitigating PF exposure. Institutions may also invest in advanced transaction monitoring systems capable of detecting unusual activities, such as transactions involving dual-use goods or entities with opaque ownership structures. Compliance with sanctions regimes remains a critical priority, requiring regular updates to sanctions lists to prevent dealings with designated persons or entities. Furthermore, targeted training programs should be implemented to equip financial sector employees with the knowledge necessary to identify and report suspicious activities effectively. 

The 2024 assessment introduces several key updates and enhancements to Singapore’s approach to countering PF. The scope of PF threats has expanded to include the misuse of virtual assets and the exploitation of luxury goods exports, reflecting the evolving tactics of proliferators. Additionally, emerging high-risk sectors, such as digital payment token providers and maritime insurers, have been identified as areas requiring greater compliance scrutiny. The refined counter-PF strategy places a renewed focus on awareness, control measures, and continuous monitoring to ensure Singapore’s financial system remains resilient against PF threats. 

These developments underscore the MAS’ proactive approach to addressing the dynamic challenges posed by PF. By continually refining regulatory frameworks and strengthening institutional defences, Singapore reinforces its commitment to maintaining a robust and secure financial ecosystem, ensuring it remains well-equipped to combat both existing and emerging risks associated with PF activities. 

How We Can Help 

We at Ingenia Consultants Pte. Ltd. support our clients in navigating their anti-money laundering requirements, including proliferation finance. We specialize in helping our clients comply with these regulatory obligations, by developing appropriate policies and procedures. For any further information, please contact: 

Phoebe Mok

Senior Manager 

Ingenia Consultants Pte. Ltd. 

phoebe.mok@ingenia-consultants.com  

Financial institutions operating in Singapore, such as holders of a capital market services (“CMS”) licence and payment service providers (“PSPs”), are required to comply with anti-money laundering (“AML”) and countering the financing of terrorism (“CFT”) regulations. One of the key obligations is the timely filing of suspicious transaction reports (“STRs”) with the Suspicious Transaction Reporting Office (STRO), a division of the Commercial Affairs Department (CAD) of the Singapore Police Force
(SPF).

This article provides an overview of the legal requirements, indicators of suspicious transactions, and the process for filing an STR to help financial institutions remain compliant.

Legal and Regulatory Framework

The following key regulations govern the obligation to file an STR:

  • Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992 (“CDSA”)
  • Terrorism (Suppression of Financing) Act 2002 (“TSOFA”)
  • Notices and guidelines by the Monetary Authority of Singapore (MAS), namely
    • MAS Notice SFA04-N02 for CMS license holders, or
    • MAS Notice PSN01 or PSN02 for payment service providers

Under these laws and regulations, financial institutions must promptly file an STR when they have reasonable grounds to suspect that a transaction is connected to criminal conduct, money laundering (“ML”), or terrorism financing (“TF”). At the latest, they are to submit the STR within 15 business days from their discovery of the suspicious transaction (para. 13-1 Guidelines to SFA04-02 for CMS licence holders and para. 18-1 Guidelines to PSN01 or para. 16-1 Guidelines to PSN02 for PSPs)

STRs filed by Financial Institutions in Singapore

As per information published by the Singapore Police Force (“SPF”)1, the number of STRs filed increased significantly in the past years.

Year     Number of STR Filed    % Increase
2020    33,882
2021    45,897                               35%
2022    49,846                               9%

By far most STRs were submitted by banks. In 2021, they submitted 60% of all STRs, and in 2022, 58%.

Indicators of Suspicious Transactions

All financial institutions should identify red flags common to their type of business and, more specifically, to their company’s specific business. They should list these red flags in their procedures and include them in the AML/CFT training of their staff.

While not exhaustive, the following are common red flags that may warrant an STR filing:

  • Transactions involving unusually large amounts with no clear economic purpose;
  • Request by a customer for investment management services where the source of funds is unclear or not consistent with the customer’s apparent standing;
  • An account operated in the name of an offshore company with structured movement of funds;
  • Cross-border transactions involving the acquisition or disposal of high-value assets that cannot be clearly identified as bona fide transactions;
  • Transactions linked to high-risk jurisdictions identified by the Financial Action Task Force (FATF);
  • Customers unwilling to provide information on the source of funds or the purpose of transactions;
  • The customer uses intermediaries that are not subject to adequate AML/CFT laws;
  • A customer relationship with a payment service provider in which a customer has a large number of accounts with the same payment service provider and frequently transfers between different accounts;
  • Concentration of payments where multiple senders transfer money to a single individual’s account;
  • Frequent changes to the customer’s address or authorized signatories;
  • Customers are in a hurry to complete the transaction, with promises to provide the supporting information later;
  • Funds or digital payment tokens (“DPT”, commonly referred to as cryptocurrencies) used by a customer to settle his obligations are from a source that appears to have no explicit or direct links to the customer;
  • Frequent changes in the customer’s identification information, such as home address, IP address, or linked bank accounts/wallet addresses.

Refer to the MAS’ AML Guidelines applicable to your type of business for further examples of red flags that are specific to your type of business (Guidelines to SFA04-N02 for holders of a CMS licence, e.g. for fund management or dealing in capital markets products, Guidelines to PSN01 for PSPs offering fiat payment services such as domestic or cross-border money transfer service, merchant acquisition service, or account issuance service, or Guidelines to PSN02 for PSPs providing digital payment token, i.e. cryptocurrency, service).

Filing an STR: Step-by-Step Process

Identify and Assess the Suspicious Transaction

  • Staff carrying out various tasks may identify suspicious transactions either at the time of onboarding or throughout a customer’s relationship life cycle. Suspicious transactions and other new information indicating an ML/TF risk can also be identified through automated monitoring systems. These systems continuously monitor/screen the customers and analyse transaction patterns, customer behaviour, and predefined rules. The systems help flag information and anomalies that could be potential red flags compared to the customer’s profile, prompting further investigation by compliance teams.
  • The staff who identifies the suspicious transaction should escalate their suspicion to their compliance team or money laundering reporting officer (“MLRO”), as indicated in your AML/CFT policies and procedures.
  • Once escalated to the compliance team or MLRO, they will conduct internal investigations and review the transaction in question.

Complete the STR Form and Submit it to STRO

  • The MLRO or a compliance officer may access the STR form via the STRO Online Notices and Reporting (“SONAR”) system and electronically submit the completed STR form.
  • In the STR form, you must provide details such as transaction amounts, counterparties, account details, and the basis of suspicion, and supporting documents (e.g., transaction records and emails) should be attached where relevant.

Maintain Confidentiality

The fact that an STR has been filed must not be disclosed to the customer. Tipping-off is an offence under the CDSA and TSOFA. Even internally, this information should only be on a need-to-know basis.

Ongoing Monitoring and Internal Reporting

  • Even after the submission, you must continue monitoring the account for further suspicious activity, possibly even conducting enhanced monitoring.
  • Moreover, you should consider additional control measures and implement them, as appropriate.
  • Don’t forget to maintain proper internal records of the STR submission and any follow-up actions.

Compliance Best Practices

The filing of STRs is part of your comprehensive AML/CFT framework. It must be properly embedded and connected within your entire framework to effectively detect suspicious transactions (and adverse information) and ensure their proper filing through STRs.

  • Establish a robust AML/CFT framework, including internal policies and training programs.
  • Ensure all employees are aware of their obligations and are trained in identifying suspicious transactions.
  • Regularly review transaction monitoring systems to enhance detection capabilities and fine tune to keep them relevant.
  • Maintain a log of cases where an STR was filed and circumstances where it was decided not to file an STR with a rationale for the decision.
  • File the STR as soon as investigations are completed, and the facts have been established. At the latest, you should file the STR within 15 business days after the discovery of the suspicious transaction.
  • Cooperate fully with regulatory authorities and provide additional information when required.

Conclusion

Filing STRs is a critical compliance requirement under Singapore’s AML/CFT regulations. Capital Market Services license holders and Payment Service Providers must establish strong internal controls to detect and report suspicious transactions in a timely and accurate manner. Failure to comply may result in regulatory penalties and reputational damage. Staying vigilant and adhering to legal obligations will help financial institutions contribute to Singapore’s efforts in combating financial crimes.

How We Can Help

We at Ingenia Consultants Pte. Ltd. support our clients in navigating their anti-money laundering requirements, including the filing of STRs. We specialize in helping our clients comply with these regulatory obligations, by developing appropriate policies and procedures. For any further information, please contact:

Vijay Bharadwaj

Director

Ingenia Consultants Pte. Ltd.

vijay.bharadwaj@ingenia-consultants.com

The Payment Services Act 2019 (PS Act) of Singapore is a comprehensive regulatory framework that governs payment service providers to enhance the safety, security, and efficiency of payment systems. One of the critical areas under the PS Act is the safeguarding of customer money, which ensures that customers’ funds are protected from misuse and insolvency risks.

Key Safeguarding Requirements

Under the PS Act, payment service providers (PSPs) offering services, such as e-money issuance, or money transfer, are required to safeguard customer funds. The relevant provisions and requirements include:

1. Segregation of Client Money

Section 23 of the PS Act stipulates that licensees must ensure customer money is segregated from their operational funds. This means maintaining separate bank accounts designated solely for holding customer funds to prevent commingling with the company’s assets. This separation protects customer money in the event of the PSP’s insolvency.

2. Safeguarding Arrangements

A major payment institution must ensure that money received from, or on account of, a customer for domestic or cross-border money transfer services or on account of merchant acquisition is
safeguarded if it continues to hold at the end of the business day.
Similarly, a major payment institution must safeguard customer’s funds, at all times, received in exchange for issuing e-money except where these funds are received for:

  • Payments made to reduce a customer’s debt to the institution,
  • Refunds or repayments made by the institution to the customer,
  • Funds used to pay service fees or charges imposed by the institution,
  • Payments made to a recipient as per customer instructions (whether received or not) or
  • Money paid to another person who is legally entitled to it.

This safeguarding can be done in one of the following manners:

  1. by an undertaking, from a safeguarding institution, such as a bank licensed in Singapore, to be fully liable to the customer for the relevant money;
  2. by a guarantee given by a safeguarding institution for the amount of the relevant money;
  3. by depositing the relevant money in a trust account maintained with a safeguarding institution.

3. Timely Safeguarding

PSPs are required to safeguard customer money within a specified period, usually by the end of the next business day after receiving the funds. This ensures that customers’ funds are protected from misuse and insolvency risks.

4. Regular Reconciliation

PSPs must reconcile their records of customer funds daily. This process involves verifying that the amounts held in safeguarding accounts match the total funds owed to customers. Discrepancies must be resolved immediately to maintain compliance.

5. Reporting and Auditing

PSPs must regularly report to the Monetary Authority of Singapore (MAS) on their safeguarding arrangements. They are also subject to periodic audits to ensure compliance with safeguarding obligations.

Consequences of Non-Compliance

Non-compliance with safeguarding requirements can lead to severe penalties, including fines, suspension of the PSP’s license, or other regulatory actions by MAS. PSPs must establish robust
internal controls and governance frameworks to ensure adherence to these regulations.

Why Safeguarding Matters

The safeguarding of customer money is vital for maintaining trust and confidence in payment services. It mitigates risks associated with insolvency and misuse of funds, providing customers with assurance that their money is secure.

How We Can Help

We at Ingenia Consultants Pte. Ltd. support our clients in navigating the safeguarding requirements under the PS Act. We specialize in helping PSPs comply with regulatory obligations, including setting up appropriate safeguarding mechanisms.

For any further information, please contact:
Vijay Bharadwaj
Director
Ingenia Consultants Pte. Ltd.
vijay.bharadwaj@ingenia-consultants.com

Licenced fund management companies restricted to servicing qualified investors, namely accredited investors and institutional investors, (“A/I LFMCs”) are generally required to submit quarterly and annual returns to the Monetary Authority of Singapore (“MAS”) to confirm their compliance with capital requirements and provide information for supervisory and statistical purposes.
Every quarter, they must submit the following forms (reg. 27 SF(FMR)R and sec. 3(1) and 5 of the Statistics Act 1973):

  • Form 1
  • Form 2
  • Quarterly Income & Expenditure Statement For Compilation Of Value-Added Of Financial Sector (Financial Institutions Excluding Insurance Companies) (“QIE Form”)

Form 1 and Form 2 must be submitted within 14 days after the end of the quarter end (reg. 27(6) SF(FMR)R). The QIE Form must be submitted within 15 days after the end of every quarter (para. 2 ED S 01/88 dated 18 July 2018). The latest forms can and should be downloaded from MASNET.

Every year, A/I LFMCs must submit the following forms and document (sec. 107(1) SFA, reg. 27(8)-(9) SF(FMR)R):

  • Financial statements
  • Form 1
  • Form 2
  • Form 3
  • Form 4
  • Form 5
  • Form 6

All of these documents must be submitted within 5 months after the end of the financial year (sec.107(1)(a) SFA).

A/I LFMCs are expected to submit all forms within the stipulated timelines. Missing submissions and missed deadlines contributed to several enforcement actions by the MAS.[1]

If the A/I LFMC is unable to submit the forms within the stipulated timelines, it should notify its MAS officer-in-charge ahead of the deadline, providing reasons for its inability.

Quarterly Returns

The quarterly returns are based on the management accounts of the A/I LFMC. As the timeline for the submission of the quarterly returns is quite short, the A/I LFMC should clearly convey to its accounting team that the management accounts must be quickly prepared after the end of the calendar quarter, in particular, where the A/I LFMC is engaging an outsourced accountant. It is also important to note that the preparation of the quarterly returns requires the balance sheet as of the end of each month to calculate the average aggregated assets in Form 2.

Form 1

To a large extent, Form 1 is a restatement of the Company’s balance sheet whereby the exposure to the different types of activities under the Securities and Futures Act 2001 is emphasised.

Tips

Contrary to Form 1, the “Unappropriated profit or loss” in Form 1 is the sum of the retained earnings and the current financial year’s profit or loss.

Form 2

Form 2 focuses on the A/I LFMC’s capital requirements: the base capital, financial resources, the total risk requirement, and adjusted assets. A/I LFMCs may note that the section on aggregate indebtedness does not apply to them (reg. 15 SF(FMR)R).

Tips

For the calculation of the base capital, the A/I LFMC must pay particular attention to the statement of its profit or loss. For the calculation of the base capital, the “Unappropriated profit or loss” is the A/I LFMC’s last audited profit or loss, its retained earnings. The current financial year’s loss must be deducted from the base capital whereas the current financial year’s profit must not be added for the base capital calculation but is taken into account for the calculation of the financial resources. It is important to remember that the “unappropriated profit or loss” changes and only changes after the A/I LFMC’s financial audit is completed.

An A/I LFMC also does not need to calculate the counterparty risk requirement, the position risk requirement, the large exposure risk requirement or the underwriting risk requirement as long as its average adjusted assets do not exceed the lower of SGD 10m or five times its financial resources (para. 3.3.1(a) read in conjunction with 3.3.3 SFA04-N13).

In many cases, an A/I LFMC’s operational risk capital is simply SGD 100,000. Until the A/I LFMC has an average gross income of SGD 2m for the three immediately preceding years, the A/I LFMC’s operational risk requirement is SGD 100,000 (para. 4.1.2 SFA04-N13).

QIE Form

The QIE Form is based on the A/I LFMC’s profit and loss statement for the full quarter. It examines the A/I LFMC’s income and expenses for statistical purposes. The first section collects data on the investments and their depreciation. The second section analyses the income and expenses, including employment.

To properly complete the QIE Form, the A/I LFMC must report business transactions with Singapore residents and firms under “In Singapore” and transactions with persons and firms outside Singapore under “Outside Singapore”. The A/I LFMC may need to organise its accounting to extract the figures with this segregation.

Salaries are also reported “In Singapore” and “Outside Singapore”. At the same time, a distinction is made between “Singapore resident employees”, these are Singapore citizens and Singapore permanent residents, and other staff, “Non-Singapore resident employees”. The same distinction is also made for total employment figures as at the end of the quarter. The A/I LFMC may need to inquire with its human resources department to make these distinct amounts available.

Tips

In the transfer of its accounts into the QIE Form, the A/I LFMC should pay particular attention to accounts with a negative figure. The QIE Form (generally) does not allow for negative income or expenses. As a result, a negative income may need to be reported as an expense and vice-versa.

In the QIE Form, values must be stated to the nearest Singapore dollar. This may lead to slight discrepancies when multiple numbers that were individually rounded are added up to a sum, namely the profit/loss before tax. Where the A/I LFMC encounters an error message for a field that is a sum, it is worth examining it for an error due to the rounding of the individual components.

Annual Returns

The annual returns are based on the audited financial statements of the A/I LFMC.

Form 1 and Form 2

The A/I LFMC must submit Form 1 and Form 2 as part of its quarterly returns and as part of its annual returns. Although the forms for the quarterly and the annual returns request the same data, different templates need to be used. Importantly, the figures in the annual submissions must be based on the audited financial statements. Thus, they may differ from the figures submitted for the quarter end that coincides with the financial year-end.

Form 3

Form 3 examines the income of the A/I LFMC based on the types of financial services activities.

Tips

Many activities will not apply to the A/I LFMC because the same form applies to all holders of a capital markets services (“CMS”) licence.

Form 4

In Form 4, the A/I LFMC must catalogue its assets under management, namely based on types of investors and activity.

Tips

For the distinction between “Institutional clients” and “Individual clients”, “Institutional clients” is not equivalent to institutional investors as defined in section 4A(1)(c) of the Securities and Futures Act 2001. This distinction in Form 4 rather reflects the distinction as per the market practice of whether the A/I LFMC’s customer is an individual or an institution.

Where an A/I LFMC is also exempt from the requirement to hold a financial adviser’s licence, the A/I LFMC should also note that the distinction between funds under “discretionary management” and “under advisory service” does not reflect the distinction between the two regulated activities of fund management and financial advice. Funds “under advisory service” means the value of assets for which the A/I LFMC acts as an advisor without the authority to make investment decisions. This targets funds where the primary fund manager engages the A/I LFMC as an advisor/sub-advisor for a fund.

Form 5 and Form 6

Form 5 and Form 6 must be completed by the A/I LFMC’s external auditor. In Form 5, the auditor confirms that it has audited the A/I LFMC’s accounts. However, the auditor also confirms that nothing has come to its attention that causes it to believe that the A/I LFMC has not complied with all conditions and restrictions applicable to the A/I LFMC under its licence, i.e. under applicable regulations and as imposed in its licence. Due to this confirmation, various external auditors insist on a comprehensive review of the A/I LFMC’s internal controls, not just the A/I LFMC’s accounts. In Form 6, the auditor confirms that the A/I LFMC’s financial statements have been properly drawn up. 

Financial Statements

The financial statements that the A/I LFMC submits as part of its annual returns must be true and fair financial statements made up to the last day of its financial year in accordance with the Companies Act 1967 (reg. 27(8) SF(FMR)R) and must include the management letter (if any). These will be the company’s audited financial statements.

Ingenia Consultants Pte. Ltd. supports financial institutions in their compliance, including the preparation of quarterly and annual returns for fund management companies. This support is included in our outsourced compliance services or can be engaged separately.

For any further information, please contact:

Maurice Yap
Senior Manager
Ingenia Consultants Pte. Ltd.
maurice.yap@ingenia-consultants.com

 

[1] For example, “MAS Takes Enforcement Actions Against China Capital Impetus Asset Management, its Executive Director and Former CEO for Breaches of the Securities and Futures (Licensing and Conduct of Business) Regulations” of 31 July 2024, “MAS Reprimands RVP One Pte. Ltd. and its Chief Executive Officer for Breaches of the Securities and Futures (Licensing and Conduct of Business) Regulations” of 30 July 2024.

In today’s dynamic business environment, managing risks effectively is critical to ensuring operational resilience, complying with regulatory requirements, and achieving organisational objectives. The risk control self-assessment (“RCSA”) process is a vital tool that empowers organisations to proactively identify, evaluate, and mitigate risks.

What is the RCSA process?

The RCSA is a structured and collaborative approach to assess risks and controls within the operations.

The process involves engaging various stakeholders to:

1. Identify Risks: Understand potential threats to achieving organisational objectives.
2. Assess Risks: Evaluate the likelihood and impact of identified risks.
3. Review Controls: Assess the effectiveness of current risk controls.
4. Mitigate Risks: Design and implement action plans to address gaps or improve existing controls.

Benefits of RCSA

The awareness of the risks it is exposed to and the RCSA process, in particular, provide several benefits
to the company.

1. Proactive Risk Management: The RCSA helps organisations identify and address risks before they materialise.
2. Enhanced Control Environment: The RCSA ensures controls are aligned with identified risks.
3. Informed Decision-making and Resource Allocation: The RCSA process provides leadership with actionable insights on risk exposure and helps allocate resources based on business needs.
4. Improved Compliance: The RCSA demonstrates due diligence in meeting regulatory and governance requirements, namely where the company applies a risk-based approach.
5. Collaboration and Awareness: The RCSA fosters a risk-aware culture across all levels of the organisation.

Key steps in the RCSA process

The RCSA process commonly follows the steps below to identify and assess the inherent risks and the existing controls, determine the residual risks based on these two factors and, finally, plan for required actions, if any.

1. Risk Identification

The relevant stakeholders identify the inherent risks that the company and its operations are exposed to. You can leverage tools like process maps, past incident reports, and risk libraries for a comprehensive view.

2. Inherent Risk Assessment

The identified inherent risks are rated based on two criteria: likelihood (frequency) and impact (severity). The risk rating is applied based on a risk matrix.

3. Control Evaluation

Existing controls are listed for each identified risk and evaluated for their adequacy, effectiveness, and efficiency. For this purpose, findings from recent quality assurance and internal and external audits should be considered.

4. Determination of Residual Risk

The residual risk of each inherent risk is determined by the rating of the inherent risk and the strength of the respective controls in accordance with a pre-defined matrix. Residual risks in the same category may be consolidated to obtain an easier understanding of the company’s risk exposure.

5. Action Planning

Where necessary, corrective action is developed, namely in case of inadequate controls or where the residual risk exceeds the company’s risk. Deadlines for the action items are determined, and ownership for their implementation is assigned.

6. Monitoring and Reporting

The progress of mitigation efforts is continuously tracked to ensure their timely implementation and, thus, enhanced risk mitigation. Findings are documented, and the reports are shared with key stakeholders for transparency and accountability.

Tailoring the RCSA Process for Your Business

Every organisation is unique, requiring a customised specific RCSA. Tailoring the RCSA to your business ensures that risk identification and mitigation strategies align with the organisation’s unique objectives, industry, and operational context. This customisation enhances the relevance, efficiency, and effectiveness of your risk management efforts.

We at Ingenia Consultants Pte. Ltd. support our clients in setting up enterprise-wide risk management frameworks commensurate with the nature, size and complexity of their operations. Namely, we help with the RCSA process and document it.

Industry-specific risk libraries: We provide guidance to your company in identifying and assessing applicable risks leveraging our expertise across various sub-sectors of the financial industry, such as fund management, external asset management, payment services and digital asset services.

Stakeholder engagement: We facilitate workshops and meetings to align teams with RCSA objectives.

Periodic reviews: We establish a process and assist your company in reviewing your risks and refining the RCSA process based on evolving risks.

 

For any further information, please contact:
Vijay Bharadwaj
Director
Ingenia Consultants Pte. Ltd.
vijay.bharadwaj@ingenia-consultants.com

On 30 October 2024, the Monetary Authority of Singapore (“MAS”) issued an information paper on “AML/CFT Supervisory Expectations from Recent Inspections”. This information paper sets out the MAS’ expectations and good practices noted in recent anti-money laundering (“AML”) and countering the financing of terrorism (“CFT”) inspections conducted across a range of financial institutions (“FIs”), including banks, payment service providers, capital markets services licensees, licensed trust companies and direct life insurers. The information paper encourages financial institutions to benchmark themselves against the practices and supervisory expectations set out in the information paper in a risk-based and proportionate manner and conduct a gap analysis, taking into account the risk profile of their business activities and customers. A separate circular by the MAS emphasises this expectation that financial institutions conduct a gap analysis.

Assessment of Customer Risk

FIs should have a good understanding of their customers’ profiles in order to inform their money laundering (“ML”) and terrorism financing (“TF”) risk assessment of the customer at onboarding and ongoing monitoring of business relations. As part of their inquiries into the customer, FIs should, among other precautions, take reasonable measures to obtain and verify information on their customers’ current and previous nationalities and identities, particularly for higher-risk customers. The FI should then consider all the customer’s current and previous nationalities and identities when assessing potential adverse news screening alerts, including searches in the native languages of countries associated with the customer, and assessing the ML/TF risk. The FI should assess the ML/TF risk, taking into consideration factors such as citizenship and residency by investment (“CBI”/”RBI”) schemes that are assessed to be of higher risk[1], frequent changes in nationalities or key identifiers of the customer, material discrepancies in information or adverse news. However, the MAS also indicates that customers can hold multiple nationalities for legitimate reasons, including via CBI/RBI schemes.

Identification of Material Red Flags

FIs should exercise vigilance in identifying material red flags in documents obtained from customers as part of their customer due diligence (“CDD”) process. Where there are doubts about the legitimacy of documents or representations obtained from or made by the customer, e.g. because of significant discrepancy to publicly available information, accounting anomalies, or lack of official sign-off, further follow-up actions, such as conducting an additional inquiry and independent due diligence on the customer or taking additional risk mitigation measures, such as exiting the business relationship or filing of a suspicious transaction report (“STR”), should be triggered.

FIs should provide clear guidance for their staff on their responsibilities to identify material red flags in documents or representations obtained from or made by customers, including examples and their escalation. The FIs should periodically review their guidance and are encouraged to leverage technology to enhance their detection of potentially fraudulent or tampered documents.

Source of Wealth Establishment

Establishing the source of wealth (“SOW”) is essential to ensure the legitimacy of the customer’s SOW and inform the FI’s ongoing monitoring of business relations with customers. Therefore, FIs should apply rigour in assessing the plausibility of customers’ SOW and avoid overreliance on customers’ representations. For PEPs, private banking and wealth management businesses, the MAS expects FIs’ SOW establishment measures to encompass obtaining (i) a base set of SOW information, including details on seed money where relevant, and (ii) additional documents and information to independently corroborate the SOW of the customer. For other higher-risk categories of customers, FIs should also establish customers’ SOW by (i) obtaining a base set of SOW information, including details on seed money where relevant, and (ii) assessing whether any ML/TF risk concerns warrant and can be addressed by further corroborative checks. Where FIs are unable to establish a SOW that is of higher risk or a significant portion of a customer’s wealth, closer senior management oversight and enhanced monitoring are needed.

The MAS further re-emphasises the principles in its Circular on “Establishing the Sources of Wealth of Customers”, issued on 26 July 2024.

  • Materiality
    • Obtain information on the customer’s entire body of wealth.
    • Focus on corroborating the more material or higher-risk SOW, e.g. SOW from higher-risk countries or higher-risk industries.
    • Assess whether the residual risk of uncorroborated wealth is acceptable or whether additional risk mitigation measures are necessary.
  • Prudence: Use more reliable corroborative evidence.

For example, the relationship between the donor and the recipient of a gift should be established, e.g., with a birth certificate; for business ownership, audited financial statements should be obtained, or unaudited financial statements should be triangulated with independent sources.

  • Relevance: Exercise reasonable judgment in determining which documents or information are critical for SOW corroboration, e.g., documents from many years ago may no longer be easily available and not be of high relevance to the customer’s SOW.

Risk Mitigation Measures

FIs are expected to put in place timely and appropriate risk mitigation measures when a suspicious transaction report (“STR”) is filed or where there are reasonable grounds for suspicion that could warrant an STR to be filed on an account. Hereby, FIs should ensure that the risk mitigation measures taken are adequate to address the risk concerns and not solely rely on enhanced monitoring of the account. These measures are to ensure that FIs are not exposed to risks of facilitation of ML/TF activities while deciding whether to retain or close the accounts.

Senior management of FIs also needs to exercise close oversight of business relations with customers with suspicions of ML/TF. Clear guidance on escalation should be given, adequate resources should be available for account reviews, and senior management should be regularly updated.

Holistic Monitoring of Accounts

Holistic monitoring across business units is important for FIs to better understand the risks associated with customers and their related accounts, identify potential ML/TF risks and take any risk mitigationmeasures if required. For this purpose, FIs should share information on customers and their related accounts across different business units, particularly for higher-risk customers.

 

Ingenia Consultants Pte. Ltd. is supporting financial institutions in their compliance, including anti-money laundering (“AML”) and countering the financing of terrorism (“CFT”). Moreover, our internal audit services provide the board of directors and senior management with assurance regarding these obligations. Reach out to us to learn more about our regulatory support.

For any further information, please contact:

Rolf Haudenschild

Co-founder

Ingenia Consultants Pte. Ltd.

rolf.haudenschild@ingenia-consultants.com


[1] For instance, OECD has also published a list of potentially higher risk CBI/RBI schemes.

The Monetary Authority of Singapore’s recent circular, issued on 25 October 2024, sets supervisory expectations on anti-scam measures for Major Payment Institutions (“MPIs”) issuing e-wallets, which provide personal payment accounts, i.e., accounts for individuals in Singapore containing e-money.

Effective 15 December 2023, the stock cap for e-wallets has been raised to SGD 20,000 (from SGD 5,000), and the flow cap to SGD 100,000 (from SGD 30,000). MPIs that have already increased the cap are expected to already have the additional requirement (or should otherwise implement them immediately). MPIs wishing to adopt these higher caps must implement specific anti-scam measures beforehand. For MPIs not adopting the higher caps, MAS recommends progressive implementation of these measures to enhance anti-scam resilience.

Below we list a summary of the key requirements of these anti-scam measures that MPIs need to put in place.

Governance and Accountability

➢ Board of directors and senior management oversight: The board of directors and senior management oversee the implementation of anti-scam measures and must ensure that a framework for responding to scams is in place.
➢ A separate unit to assess scam-related disputes independently

Preventive Measures

➢ Restrictions on sending clickable links, QR codes, or phone numbers through SMS, unless specific criteria are met
➢ 12-hour cooling-off period for e-wallet access on new devices
➢ Additional verification for high-risk activities or transfers above SGD 1,000, with warnings about associated risks

Detective Measures

➢ Real-time outgoing transaction alerts and a default transaction threshold set to SGD 0 to detect potential fraud early
➢ Notifications for high-risk activities and new device logins, with user reminders to verify these actions

Remedial Measures

➢ Continuous reporting channels for users to report unauthorised transactions
➢ “Kill switch” allowing users to block their e-wallet if they suspect unauthorised access

 

At Ingenia Consultants Pte. Ltd., we support our clients in drafting policies and procedures and designing controls to comply with regulatory requirements.
For any further information, please contact:

Vijay Bharadwaj
Director
Ingenia Consultants Pte. Ltd.
vijay.bharadwaj@ingenia-consultants.com