• Sep 30, 2026
  • 11 min read

Singapore's AML and KYC Compliance Guide for 2026

A complete 2026 guide to AML and KYC compliance in Singapore: MAS rules, beneficial ownership updates, penalties, and FATF evaluation results.

Singapore is one of the world's leading financial hubs, ranked 4th in the Global Financial Centres Index. Its banking system holds more than S$4 trillion (over US$3 trillion) in assets, and financial services make up around 14% of GDP.

The same qualities that draw legitimate business to Singapore, such as deep capital markets, strong banks, and easy cross-border payments, also make it a target for money launderers. That risk became very public in 2023, when police arrested ten foreign nationals of Fujianese origin in a series of raids. The group, known as the "Fujian Gang," moved more than S$ 3 billion (about US$ 2.2 billion) in illicit funds through the country. All ten pleaded guilty in 2024.

Singapore has since tightened its anti-money laundering (AML) framework on several fronts. Parliament passed new AML legislation in 2024, and beneficial ownership rules for companies and LLPs were overhauled. In June 2025, the Monetary Authority of Singapore (MAS) issued revised AML/CFT notices that made proliferation financing risk assessment mandatory. MAS also penalized nine financial institutions over their links to the Fujian Gang case, its second-largest cumulative enforcement penalty on record.

In May 2026, the Financial Action Task Force (FATF) published its mutual evaluation of Singapore, giving the country its best result to date. 

Who must comply with AML and KYC rules in Singapore

AML compliance requirements in Singapore apply to financial institutions as well as certain designated non-financial businesses and professions, including but not limited to: 

  • Banks
  • Casinos
  • Money-changing service providers 
  • Insurance companies
  • Capital markets intermediaries, including certain securities and brokerage businesses  
  • Lawyers and accountants
  • Financial advisers
  • Real estate agents
  • Dealers of precious metals
  • Payment service providers
  • Domestic money transfer services
  • Cross-border money transfer services
  • Account issuance services
  • Merchant acquisition services
  • E‑money issuance services
  • Digital payment token services
  • Trust companies
  • Corporate service providers

Suggested read: AML Odyssey: How Growing Businesses Find Their Way to Ithaca

Singapore's key AML and KYC regulators

Several agencies share supervisory responsibility for AML regulations in Singapore:

Core AML and KYC laws in Singapore

The main AML regulation in Singapore is the Corruption, Drug Trafficking and Other Serious Crimes Act 1992 (CDSA). The Act criminalizes money laundering and sets out confiscation, reporting, and other obligations relating to proceeds of crime and suspicious transactions. 

In November 2024, Singapore enacted the Anti-Money Laundering and Other Matters Act. Certain provisions of the Act came into force on November 14, 2024, with the remaining provisions to be commenced later. The Act strengthens Singapore’s framework for investigating and prosecuting money laundering offenses, addresses seized or restrained property linked to suspected criminal activity, and aligns the AML/CFT framework for casino operators with FATF standards.

Additional legislation addresses specific aspects of AML and KYC. The Financial Services and Markets Act 2022 (FSM Act) underpins MAS's cross-sector powers, information sharing, and sanctions implementation. The Companies and Limited Liability Partnerships (Miscellaneous Amendments) Act 2024 (CLLPMA), effective June 16, 2025, overhauled rules for beneficial ownership transparency. Finally, the Corporate Service Providers Act 2024 raises licensing and due diligence standards for corporate service providers.

The National Anti-Money Laundering Strategy, published in October 2024, outlines Singapore's approach to addressing money laundering risks. It focuses on prevention, detection, and enforcement through a robust legal framework, as well as international cooperation.

Some other important AML regulations include: 

To learn more about each of these regulations, you can download our compliance guidelines here.

MAS's 2025 AML and CFT rule updates

On June 30, 2025, MAS published its response to feedback on its proposed amendments to AML/CFT notices and guidelines following a public consultation that ran from April 8 to May 8, 2025. This response set out amendments that took effect from July 1, 2025, including:

  • Mandatory proliferation financing (PF) risk assessments. Companies should bring anti-proliferation financing obligations into the scope of anti-money laundering rules.
  • Tighter STR timelines. Institutions should generally file a Suspicious Transaction Report within five business days of establishing suspicion. For cases involving sanctioned parties or those acting on their behalf, STRs should be filed as soon as possible and no later than one business day after suspicion was first established. MAS clarified that “establishment of suspicion” means the point at which the institution concludes, based on the available information, circumstances, and its investigations, that an STR should be filed; it does not prescribe a fixed timeframe for completing the underlying investigation. 
  • Broader trust due diligence. Notice TCA-N03 amendments expanded "trust relevant parties," requiring due diligence to include protectors, class-based beneficiaries, "objects of power," and controllers of legal arrangements.
  • A practical concession on addresses. Where ML/TF risk is not high, and a beneficial owner's residential address cannot be obtained despite reasonable efforts, a business address may now be recorded instead, with the assessment documented.
  • Source of wealth due diligence. MAS clarified that institutions should understand a customer’s overall source of wealth while applying a reasonable, risk-proportionate approach to corroboration, focusing particularly on material or higher-risk sources of wealth.

Proliferation financing: A new compliance duty

The July 2025 amendments formally folded proliferation financing, or ‘PF’ (i.e., financing linked to weapons of mass destruction), into the scope of money laundering risk under MAS's Notices. This brings Singapore in line with revised FATF standards. Financial institutions must now factor PF into their ML/TF risk assessments, either as a standalone exercise or integrated into existing frameworks.

Beneficial ownership transparency rules for companies

Singapore significantly tightened beneficial ownership rules through the CLLPMA. Since June 16, 2025, companies, foreign companies, and LLPs must maintain up to three registers, each with a private version and a central version filed with ACRA. These beneficial ownership registers are:

  • Register of Registrable Controllers (RORC). Covering beneficial owners, required since 2017, centrally filed since 2020, and now maintained from the date of incorporation.
  • Register of Nominee Directors (ROND). Now filed with ACRA under the CLLPMA.
  • Register of Nominee Shareholders (RONS). A private register since 2022, now also filed with ACRA's Central RONS.

Existing companies had until December 31, 2025, to submit nominee director and shareholder information to ACRA.

How Singapore businesses meet AML compliance requirements

 Regulated businesses in Singapore must establish AML/CFT controls in accordance with the legislation, regulatory notices, and sector-specific requirements applicable to their activities. The precise obligations differ by sector, but commonly include:

  • Establishing risk-based internal AML policies and procedures, scaled to  the size and complexity of their business
  • Communicating policies to all new employees and explaining any updates to them to existing employees at least on an annual basis
  • Training staff to identify and escalate suspicious activity, and to understand the consequences of non-compliance
  • Conducting a business risk assessment to identify the overall ML/FT risk the business is exposed to, including the risk factors to be considered
  • Appointing a compliance officer and clearly specifying their roles and responsibilities in managing the AML compliance program
  • Reporting suspicious transactions to STRO
  • Conducting Customer Due Diligence (CDD) to verify the identities of their customers, including beneficial owners
  • Maintaining appropriate records and conducting ongoing monitoring of business relationships and transactions 
  • Applying enhanced due diligence where higher ML/TF/PF risks are identified
  • Screening customers and connected parties against applicable sanctions and other risk indicators, where required under the relevant framework

Suggested read: The APAC Sentinel: Effective Transaction Monitoring Tactics

Understanding the difference between KYC and AML

KYC and AML are often used interchangeably, but they aren't the same thing: KYC is one part of an AML program, not a substitute for it.

AspectKYC (Know Your Customer)AML (Anti-Money Laundering)
ScopeA specific process within AML focused on verifying customer identities and understanding customer risk.A broad framework of laws, policies, and procedures to fight money laundering, terrorism financing, proliferation financing, and related financial crime risks. 
ProcessInvolves identity verification, due diligence, and ongoing monitoring of customers.Includes KYC, transaction monitoring, suspicious transaction reporting, and regulatory compliance.
Purpose Helps businesses identify and verify customers, understand who they are dealing with, and assess associated financial crime risks.Prevents and detects money laundering, terrorism financing, and other financial crimes by enforcing strict compliance measures.
Regulatory requirementMandatory for financial institutions and regulated businesses.Implemented through applicable laws, regulations, notices, and sector-specific requirements, including those issued by MAS and other Singapore regulators. 

How to perform KYC in Singapore

Financial institutions and other MAS-regulated entities must comply with the KYC and customer due diligence requirements applicable to them under the relevant MAS AML/CFT Notices and Guidelines. The precise requirements vary by institution type and regulated activity. 

Outsourcing AML controls to third parties

Financial institutions may outsource certain AML/CFT functions or rely on third parties in circumstances permitted under the applicable MAS requirements, but these arrangements do not transfer the institution’s regulatory responsibility. Institutions should conduct appropriate due diligence and maintain oversight of outsourced service providers, including assessing whether their controls and performance are adequate.

Automating transaction monitoring

Financial institutions with larger customer volumes are expected to implement automated systems that can handle increased CDD requests and a wide variety of customer transactions.  

Financial institutions should periodically test and update their transaction monitoring rules to ensure they can identify suspicious transactions and behaviors. Adjusting transaction monitoring rules helps financial institutions reduce false positives and false negatives.

Value transfers and digital tokens

A value transfer refers to “any transaction carried out on behalf of a value transfer originator through a financial institution to make one or more digital tokens available.”

Banks and digital payment token (DPT) service providers are subject to specific AML/CFT/CPF requirements when conducting digital-token value transfers. For banks, MAS Notice 626 sets out these requirements; for DPT service providers, MAS Notice PS-N02 sets out the relevant requirements.

These requirements include identifying and, where required, verifying the originator, obtaining and retaining prescribed information about the transfer, and ensuring that required originator and beneficiary information accompanies the transfer. 

How to conduct Customer Due Diligence

Regulated entities must establish proper Customer Due Diligence procedures, which involve collecting and verifying customer information during onboarding. CDD includes identification, verification, and ongoing monitoring of information provided by customers. 

Companies should also check customers against sanctions lists (e.g., OFAC, UN, HMT, EU, DFAT), Politically Exposed Persons (PEP) lists, and adverse media. Enhanced Due Diligence must be applied to high-risk customers, non-face-to-face clients, or those from high-risk jurisdictions.

Managing Politically Exposed Person relationships

Financial institutions should obtain senior management approval to establish or continue business relations with PEPs and identify their sources of wealth and funds, including beneficial owners of any related entities. Additionally, they must conduct enhanced transaction monitoring and report any unusual or suspicious activity without informing the customer.

Recordkeeping requirements for financial institutions

Financial institutions must keep records of customers and transactions (including value transfers and digital tokens) for at least five years after the end of the business relationship or the final transaction. Dealers of precious stones have to keep such records for the same amount of time when transactions exceed S$20,000 (approximately $15,000).

AML duties for virtual asset and token providers

Digital payment token (DPT) service providers (more commonly known internationally as ‘Virtual Asset Service Providers’ or ‘VASPs’) are regulated under the Payment Services Act 2019 and MAS Notice PSN02 (as revised on June 30, 2025). 

Required controls cover risk assessment (including PF), CDD (including identity verification), reliance on third parties, value transfers and related originator/beneficiary information requirements, recordkeeping, suspicious transaction reporting, and internal policies and training. 

MAS has also published a dedicated information paper on AML/CFT supervisory expectations for DPT providers. The paper supplements existing AML/CFT/CPF requirements and should be read together with PS-N02 and its accompanying Guidelines 

The 2026 FATF evaluation noted that Singapore has become one of the world's most significant VASP hubs since its last assessment, with a robust licensing framework helping to restrict criminals’ ability to hold beneficial ownership or control of financial institutions and VASPs.

How to report suspicious transactions in Singapore

The Suspicious Transaction Reporting Office (STRO) is Singapore's Financial Intelligence Unit (FIU) and receives and analyzes AML/CFT reports. There are three main categories of reports received by STRO: 

  • Suspicious Transaction Reports
  • Cash Transaction Reports
  • Cross-Border Cash Movement Reports  

If a regulated entity identifies suspicious activity – such as discovering that a client has a history of drug-related offenses, appears in adverse media, or has conducted an unusual transaction without a clear purpose – it must promptly submit a Suspicious Transaction Report (STR) to the STRO. This report should include all transactions related to the customer in question. The subject of the report must not be informed, as doing so would be considered a “tipping-off” offense. 

Casinos are subject to a separate CTR regime. They must report cash transactions involving cash in or cash out of S$10,000 or more in a gaming day where the casino knows that they are entered into by or on behalf of the same patron.

Financial institutions should conduct extensive ongoing monitoring of suspicious clients by analyzing transactions and requesting additional information and/or documents. 

If a financial institution decides to maintain a business relationship with a suspicious client, it should ensure appropriate measures are taken to mitigate the risks. These measures include subjecting accounts to increased scrutiny, obtaining senior management approval before executing further transactions, and more.

Penalties for breaching AML and KYC rules in Singapore

According to The Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992 (CDSA), the following AML penalties apply to those convicted of money laundering activities:

  • For individuals: a fine of up to S$500,000 (approximately $375,000) or up to 10 years' imprisonment
  • For companies: a fine of up to S$1,000,000 (approximately $750,000) or double the amount of goods acquired through illegal activity, whichever is higher

For companies that fail to comply with AML regulations (e.g., failing to report suspicious activities on time), the following penalties may apply:

  • Official warnings
  • Reprimands
  • Prohibition orders
  • Removal of management from their positions
  • License termination
  • Monetary penalties

The maximum monetary penalty for financial institutions failing to meet AML obligations is S$1,000,000 (approximately $750,000).

High-profile money laundering incidents continue to shape Singapore's AML policy and lead to substantial penalties. For example, in 2025, MAS imposed S$27.45 million in penalties on nine financial institutions for AML/CFT breaches linked to the Fujian Gang case. 

Reports published in January 2026 also highlighted a massive 579% rise in Singapore’s AML/CFT fines during 2025. 

Common obstacles to AML and KYC compliance

Businesses in Singapore face several challenges when implementing effective AML and KYC measures:

  • Ever-evolving regulatory framework. The Monetary Authority of Singapore continually updates AML/CFT regulations to address new threats. Keeping up with these changes requires significant resources to remain compliant.
  • Complexities of transaction monitoring. Developing systems that can detect suspicious activity without generating many false positives is complex and requires sophisticated technology.
  • Resource constraints. Small and medium-sized enterprises often struggle with limited resources, making it difficult to implement comprehensive AML/KYC programs.
  • Navigating complicated corporate structures. Businesses often have to deal with vehicles such as offshore shell companies, which can make it much harder to track the ultimate source of funds.
  • Cross-border operations. Businesses that operate internationally face the challenges of aligning Singapore’s strict AML measures with changing regulations in other jurisdictions. 

Singapore's 2026 FATF mutual evaluation results

On May 6, 2026, the Financial Action Task Force and the Asia/Pacific Group on Money Laundering published their joint mutual evaluation of Singapore, based on a July 2025 on-site assessment. 

The result was Singapore's best-ever outcome, placing it in FATF’s lightest monitoring category of ‘Regular Follow-up’. This was a significant improvement from the ‘Enhanced Follow-up’ status Singapore had held since its 2016 assessment. The upgrade is particularly notable given that Singapore was among the first countries evaluated under FATF's tougher fifth-round methodology, adopted in 2022, which raises the bar for demonstrated effectiveness.

Of eleven "Immediate Outcomes," Singapore scored Substantial on seven and Moderate on four, with none rated High or Low. The evaluation found Singapore employs a dynamic approach to identifying ML/TF risk, has a robust licensing framework preventing criminals from holding beneficial ownership of financial institutions or VASPs, and maintains a comprehensive international cooperation regime.

However, the report did identify some areas for further improvement. It highlighted that Singapore's system "must be sharper in producing demonstrable and consistent risk-based results." The report also flagged incomplete cross-sector supervisory coordination, a need to develop PF risk awareness outside traditionally regulated sectors, and room for better risk mitigation around foreign legal persons.

The future of Singapore's AML and KYC rules: A 2027 outlook

Here's what to expect from Singapore's AML and KYC regime in 2027:

  • FATF roadmap implementation is expected to continue, with further action on beneficial ownership verification, more complex investigations, and reviewed sentencing guidelines.
  • MAS penalty caps may rise, following MAS's flagged review of its framework "for proportionality and deterrence."
  • Stronger beneficial ownership enforcement is expected to be fully rolled out under the Companies and LLPs (Amendments) Act 2025, which has been in effect since April 2026 and brings higher penalties and expanded ACRA powers.
  • Government-backed digital identity is likely to see greater adoption. Singapore's Singpass infrastructure is expected to play an increasingly important role in KYC and identity verification, allowing businesses to verify users through a trusted, government-backed system. Sumsub integrates with Singpass as part of its Non-Doc Verification product to provide document-free onboarding for Singaporean residents.
  • Outsourced AML functions are likely to face deeper scrutiny, with examiners asking whether institutions can independently verify vendor performance in real time, rather than simply whether they used a reputable vendor.
  • AI-driven compliance tools are expected to keep growing, with uses such as real-time monitoring, behavioral analysis, deepfake detection, liveness checks, and faster identity verification.
  • Digital assets are likely to remain a sustained focus, reflecting Singapore's status as a major VASP hub, with continued refinement of DPT rules and closer attention to PF risk.

FAQ: AML and KYC compliance in Singapore

  • What is AML and KYC compliance in Singapore?

    AML compliance covers the laws, regulations, and controls that financial institutions and designated non-financial businesses must implement to detect, prevent, and report money laundering, terrorism financing, and proliferation financing. KYC compliance supports AML compliance by verifying customer identities, understanding beneficial ownership, assessing risk, and monitoring relationships on an ongoing basis.

  • What is the difference between KYC and AML?

    AML (anti-money laundering) is the overall framework for managing money laundering risks, while KYC (Know Your Customer) is a specific process within AML frameworks that focuses on verifying a customer's identity and risk level.

  • How often should businesses update KYC information in Singapore?

    Businesses should update KYC information periodically, with the frequency determined by the customer's risk profile. For instance, higher-risk customers require more frequent reviews.

  • What are the penalties for AML non-compliance in Singapore?

    Non-compliance can result in AML penalties including large fines, revocation of business licenses, and other legal actions. For example, financial institutions that fail to follow MAS’s AML policies risk penalties of up to S$1 million per offense.

  • Can businesses use third-party KYC providers in Singapore?

    Yes, businesses can engage third-party providers for KYC processes, but they remain responsible for ensuring compliance with regulatory standards.

  • What are the red flags for suspicious transactions under AML laws?

    Indicators include unusual transaction patterns, inconsistencies in customer information, and activities that don't align with a customer's known profile.

  • How does MAS monitor and enforce AML & KYC compliance?

    MAS oversees compliance through regular audits, enforcement actions, and penalties for various violations.