Guidelines to MAS Notice SFA 04-N02 on Prevention of Money Laundering and Countering the Financing of Terrorism — Capital Markets Intermediaries¶
Overview¶
The MAS Guidelines to MAS Notice SFA 04-N02 provide detailed, practical guidance on how capital markets intermediaries (CMIs) — holders of a CMS licence under the SFA and persons exempted from the licence requirement under paragraphs 3(1)(d), 3A(1)(d), 7(1)(b) of the Second Schedule to SF(LCB)R — should implement the AML/CFT requirements set out in MAS Notice SFA 04-N02. These guidelines adopt a risk-based approach (RBA), allowing institutions to allocate resources proportionate to the ML/TF risks they face.
The guidelines are issued in support of MAS Notice SFA 04-N02, which is itself issued under section 16 of the Financial Services and Markets Act 2022, and should be read in conjunction with that Notice. The Notice and these Guidelines together apply to the same CMI population.
Risk-Based Approach (RBA)¶
Principles¶
The risk-based approach is the cornerstone of effective AML/CFT compliance. It requires CMS licence holders to:
- Identify the ML/TF risks they face (customers, products, delivery channels, geographies)
- Assess the nature and level of those risks
- Apply measures to manage and mitigate the identified risks
- Monitor and review the effectiveness of the measures on an ongoing basis
Enterprise-Wide Risk Assessment (EWRA)¶
CMS licence holders should conduct a comprehensive EWRA that considers:
- Customer risk factors: Type of customer, nature of business, reputation, country of origin
- Product/service risk factors: Complexity, value, ease of use for ML/TF, cross-border nature
- Delivery channel risk factors: Non-face-to-face onboarding, third-party reliance
- Geographical risk factors: Countries subject to sanctions, FATF grey/black lists, high corruption indices
The EWRA should be documented, reviewed at least annually, and approved by senior management.
Customer Identification and Verification¶
Natural Persons — Acceptable Documents¶
For Singapore citizens and permanent residents:
- NRIC (National Registration Identity Card)
- Valid passport
For foreigners:
- Valid passport
- Employment Pass, S Pass, or Work Permit (with passport)
- Dependent's Pass or Long-Term Visit Pass (with passport)
Verification Methods¶
- Document-based verification: Original or certified true copy of unexpired government-issued photo ID
- Electronic verification: Using reliable, independent electronic data sources (e.g., MyInfo, credit bureau data)
- Video verification: Live video call with real-time document verification (subject to MAS conditions)
Non-Face-to-Face Onboarding¶
When establishing a business relationship without a face-to-face meeting, CMS licence holders should apply at least one of the following additional measures:
- Certifying copies of documents by a suitable certifier
- Requiring the first payment through an account in the customer's name at a regulated financial institution
- Using electronic verification with multiple independent data sources
- Conducting a video call with real-time identity verification
Beneficial Ownership¶
Determination of Beneficial Owners¶
A beneficial owner is any natural person who:
- Owns 25% or more of the shares or voting rights in a legal person
- Exercises ultimate effective control over the legal person, regardless of ownership percentage
- Is the settlor, trustee, protector, or beneficiary of a legal arrangement (trust)
Control Structure — Layered Ownership¶
When ownership is held through intermediate entities:
- Trace through each layer of ownership to identify ultimate beneficial owners
- Where no natural person meets the 25% threshold, identify the natural person(s) exercising control through other means (e.g., board control, management agreements)
- Where no beneficial owner can be identified, identify and verify the identity of the most senior managing official
Politically Exposed Persons (PEPs)¶
Categories of PEPs¶
- Foreign PEPs: Individuals entrusted with prominent public functions by a foreign country (heads of state, senior politicians, senior government officials, senior judicial officials, senior military officials, senior executives of state-owned enterprises)
- Domestic PEPs: Individuals entrusted with similar prominent public functions in Singapore
- International organisation PEPs: Individuals in senior positions at international organisations (e.g., UN, World Bank)
- Family members and close associates of PEPs
PEP Screening¶
CMS licence holders should:
- Screen all new and existing customers against commercially available PEP databases
- Update PEP screening at least annually for existing customers
- Consider a risk-based period (typically 12-24 months) after a person ceases to be a PEP
PEP Risk Management¶
Where a customer or beneficial owner is identified as a PEP:
- Obtain senior management approval to establish or continue the relationship
- Establish the source of wealth (total assets) and source of funds (origin of specific funds)
- Apply enhanced ongoing monitoring
- Document the rationale for accepting or continuing the relationship
Correspondent Relationships¶
Due Diligence on Correspondent Institutions¶
Before establishing a correspondent banking or securities relationship, CMS licence holders should:
- Gather sufficient information to understand the respondent institution's business, reputation, and quality of supervision
- Assess the respondent's AML/CFT controls
- Obtain senior management approval
- Document the AML/CFT responsibilities of each institution
Prohibitions¶
CMS licence holders must NOT:
- Enter into or continue correspondent relationships with shell banks
- Permit accounts to be used by shell banks
- Enter into relationships with institutions that permit their accounts to be used by shell banks
Transaction Monitoring¶
Monitoring Programme Requirements¶
CMS licence holders should implement transaction monitoring that:
- Is calibrated to the institution's risk profile, customer base, and product range
- Includes both automated systems and manual review processes
- Generates alerts for transactions that are unusual, complex, or have no apparent economic purpose
- Covers both individual transactions and patterns of transactions over time
Red Flag Indicators¶
The guidelines identify specific red flag indicators for the capital markets sector:
- Transactions inconsistent with the customer's stated investment objectives or financial profile
- Frequent transfers between accounts with no apparent business rationale
- Transactions involving jurisdictions with weak AML/CFT frameworks
- Reluctance to provide information or providing inconsistent information
- Use of multiple accounts, nominees, or corporate structures without clear business purpose
- Sudden unexplained changes in transaction patterns or volumes
- Requests to execute transactions in a manner designed to avoid reporting thresholds
Ongoing Monitoring of Business Relationships¶
Trigger Events for CDD Review¶
CDD information should be reviewed and updated upon:
- A significant transaction outside normal patterns
- A material change in the customer's business or ownership structure
- A change in the customer's risk profile
- A suspicion of ML/TF activity
- A regulatory or law enforcement inquiry
Documentation¶
CMS licence holders should maintain records of:
- Each periodic CDD review and its findings
- Any changes to the customer's risk rating and the rationale
- Actions taken in response to identified risks (enhanced monitoring, relationship exit, STR filing)
Employee Training¶
Training Programme Requirements¶
CMS licence holders must ensure that all relevant employees receive training that covers:
- ML/TF risks relevant to the institution's business
- Legal obligations under the CDSA, TSOFA, and MAS regulations
- Internal AML/CFT policies, procedures, and controls
- Customer identification and verification procedures
- Recognising and reporting suspicious transactions
- Tipping-off prohibitions and consequences
Training Frequency¶
- New employees: Before commencing duties involving customers or transactions
- Existing employees: At least annually, with updates when there are significant regulatory changes
- Senior management: Specific training on their AML/CFT oversight responsibilities
Independent Audit¶
CMS licence holders should establish an independent audit function (internal or external) that:
- Tests the effectiveness of the AML/CFT programme at least annually
- Covers all aspects: policies, procedures, controls, monitoring, training, record keeping
- Reports findings directly to senior management and the board
- Tracks remediation of identified deficiencies
Reliance on Third Parties¶
CMS licence holders may rely on third parties (e.g., introducing brokers) for CDD, provided:
- The third party is a regulated financial institution subject to AML/CFT requirements consistent with FATF standards
- The CMS licence holder obtains the CDD data immediately from the third party
- The CMS licence holder remains ultimately responsible for CDD compliance
- The arrangement is documented in a written agreement
Key Regulatory References¶
- MAS Guidelines to Notice SFA 04-N02 (effective 1 July 2025)
- MAS Notice SFA 04-N02 — Prevention of Money Laundering and Countering the Financing of Terrorism — Capital Markets Intermediaries (in-KB at
06-aml-cft/mas-notice-sfa-04-n02-aml-cft.md) - Securities and Futures Act 2001 (SFA) — the Act under which CMS licences are issued (no longer the statutory basis for the AML regime)
- Financial Services and Markets Act 2022, section 16 — statutory basis for the parent Notice SFA 04-N02
- FATF Guidance on the Risk-Based Approach for the Securities Sector (2018)
- Singapore National Money Laundering and Terrorism Financing Risk Assessment (2024)
Relevance to Regnify¶
For CMS licence holders using Regnify:
- Representative onboarding should incorporate CDD checks as part of the Form 3A submission workflow
- Risk assessment of representatives can be integrated into the Fit and Proper evaluation module
- Record keeping requirements (5-year retention) align with Regnify's audit trail and document storage capabilities
- Training records for representatives can be tracked as part of ongoing compliance monitoring