KYC Requirements in Singapore: MAS CDD Rules for Banks and Payment Companies
MAS CDD Rules for Banks and Payment Companies
Singapore’s know your customer requirements combine binding regulatory notices with supporting guidelines, circulars and supervisory guidance issued by the Monetary Authority of Singapore. The applicable notice depends on the institution and the services it provides. Banks are principally governed by MAS Notice 626, while merchant banks and payment service providers are subject to separate instruments.
This guide explains when customer due diligence is required, what standard and enhanced measures involve, how beneficial ownership should be established, and how MyInfo and other digital verification methods can support compliant onboarding. It also covers ongoing monitoring, record keeping and suspicious transaction reporting.
Institutions should always check the current version of the applicable MAS notice and guidelines.

The Singapore Regulatory Framework
MAS uses sector-specific AML and CFT notices. Although the frameworks share common principles, their scope and transaction thresholds are not interchangeable.
- MAS Notice 626 applies to banks in Singapore, including locally incorporated banks and Singapore branches of foreign banks.
- MAS Notice 1014 applies to merchant banks.
- MAS Notice PSN01 applies to licensed payment service providers and exempt persons that provide specified payment services or specified products covered by that notice.
- MAS Notice PSN02 applies to digital payment token service providers.
PSN01 and PSN02 are divided by the service being provided, not simply by whether the firm holds a standard payment institution or major payment institution licence. A payment institution may need to comply with PSN01, PSN02 or both, depending on its regulated activities.
For a closer look at the bank framework, see our MAS Notice 626 guide.
When Customer Due Diligence Is Required
Under MAS Notice 626, a bank must perform CDD in the following circumstances:
- When establishing business relations with a customer.
- When undertaking an occasional non-digital-token transaction exceeding S$20,000 for a customer that has not established business relations, including transactions that appear to be linked.
- When undertaking any digital-token transaction for a customer that has not established business relations.
- When undertaking a wire transfer exceeding S$1,500 for a customer that has not established business relations.
- When there is knowledge or suspicion of money laundering or terrorism financing, regardless of an exemption or transaction value.
- When the bank has doubts about the veracity or adequacy of customer information obtained previously.
Payment service providers must use the triggers and thresholds in the notice that applies to their services. For example, PSN01 contains payment-service-specific thresholds and exemptions that should not be imported into a bank’s Notice 626 policy.
A bank should ordinarily identify and verify the customer before establishing the relationship or carrying out the relevant transaction. Limited delayed verification may be permitted where it is essential not to interrupt normal business, the ML and TF risks are effectively managed, and verification is completed as soon as reasonably practicable. This exception should be governed by documented controls rather than treated as a routine onboarding practice.
If required CDD cannot be completed, the institution should not open the account, commence the relationship or perform the transaction. For an existing relationship, it should consider termination and whether an STR is required.
What Standard Customer Due Diligence Covers
Standard CDD is the baseline for customers who do not qualify for simplified measures and do not require enhanced measures. The process should establish who the customer is, who controls the customer, why the relationship is being opened and whether subsequent activity is consistent with that understanding.
For an individual, the required identifying information generally includes the customer’s full name, unique identification number, residential address, date of birth and nationality. The institution must verify the customer’s identity using reliable, independent source data, documents or information.
For a legal person or legal arrangement, CDD also covers its legal name, registration or identification details, legal form, governing powers, registered office and principal place of business where different. The institution must identify connected parties, verify persons acting on the customer’s behalf and confirm their authority.
CDD must also include:
- Identifying and taking reasonable measures to verify beneficial owners.
- Understanding and, where appropriate, obtaining information on the purpose and intended nature of the business relationship.
- Screening and risk assessment appropriate to the customer, product, geography and delivery channel.
- Ongoing monitoring and keeping customer information relevant and up to date.
For a general explanation of the process, see What is Customer Due Diligence.
Simplified Due Diligence
Simplified due diligence may be used only where the institution has assessed the relationship or transaction as presenting a low risk of money laundering and terrorism financing and the applicable notice permits simplified measures. The basis for the decision should be documented.
Certain government bodies, regulated financial institutions and listed entities may be subject to specific exemptions or reduced beneficial-ownership measures under the applicable rules. These provisions should not be described as automatic blanket SDD. The institution must still understand the customer and the relationship, conduct appropriate monitoring and reconsider the treatment if the risk changes.
Simplified measures must not be applied where the institution knows or suspects money laundering or terrorism financing, or where specific higher-risk circumstances require enhanced measures.
Enhanced Due Diligence
An institution must apply enhanced measures where the customer, relationship or transaction presents higher ML or TF risk. The additional measures should respond to the risk identified rather than consist only of collecting more documents.
Politically Exposed Persons
For a foreign politically exposed person, and relevant family members and close associates, a bank must obtain senior management approval before establishing or continuing business relations, take appropriate and reasonable measures to establish source of wealth and source of funds, and conduct enhanced ongoing monitoring.
Domestic PEPs and persons entrusted with prominent functions by an international organisation are treated on a risk-sensitive basis. Where the relationship is assessed as higher risk, the enhanced measures applicable to foreign PEPs should be applied. This distinction is important: senior management approval and source-of-wealth measures should not be presented as automatic requirements for every domestic PEP regardless of risk.
Correspondent Banking
Before establishing a cross-border correspondent banking relationship, a bank must gather sufficient information about the respondent institution, understand its business and reputation, assess the quality of its AML and CFT controls, and obtain senior management approval. It must also establish the respective responsibilities of each institution and apply the additional requirements relevant to payable-through accounts.
Higher Risk Countries and Jurisdictions
Jurisdiction risk should reflect MAS requirements, FATF public statements and the institution’s own risk assessment. A connection to a jurisdiction under increased monitoring is an important risk factor, but it does not automatically require the same response in every case. Institutions should apply enhanced measures or countermeasures where required and use proportionate controls for other elevated jurisdiction risks.
Complex and Unusual Transactions
Banks must pay particular attention to transactions that are unusually large, complex, lack an apparent economic or lawful purpose, or are inconsistent with what is known about the customer. They should examine the background and purpose, document their findings and determine whether the activity changes the customer’s risk or gives rise to suspicion.
Beneficial Ownership Verification
Beneficial ownership is based on ultimate ownership and control, not only the name recorded in a company register. A bank must identify the natural persons who ultimately own or control the customer and take reasonable measures to verify their identities.
An ownership interest of more than 25 percent is commonly used as an indicator when assessing ownership of a legal person. It is not a safe harbour. A person with a smaller interest may still be a beneficial owner if that person exercises control through voting arrangements, appointment rights, contractual influence or other means.
If no natural person can be identified through ownership, the institution should consider control through other means. Only after taking reasonable steps and finding no such person should it use the relevant senior managing official as the fallback identification point. The steps taken and the conclusion reached should be recorded.
For layered structures, the institution must look through intermediate companies and nominees to identify the ultimate natural persons. A Bizfile profile or shareholder register may support the analysis, but it does not by itself establish ultimate beneficial ownership in every case.
For a trust, the relevant parties include the settlor, trustees, protector where applicable, beneficiaries or class of beneficiaries, and any other natural person exercising ultimate effective control. The corporate ownership percentage should not be applied as the sole test for a trust.

Digital Onboarding and eKYC
MAS does not prescribe one technology stack for digital onboarding. Institutions may use digital identity services, document verification, biometrics and other controls where the resulting process meets the same identification, verification, risk-assessment and record-keeping requirements that apply to other channels.
Using MyInfo
MyInfo allows customers to share verified government-held personal data with participating organisations through Singpass. It can reduce manual entry and support verification using reliable, independent source data. The institution should retain sufficient evidence to show what information was obtained, when it was obtained and how it was used in the CDD process.
MyInfo can support identity verification, but it does not complete every part of KYC. The institution must still establish the purpose and intended nature of the relationship, assess customer risk, perform relevant screening, identify beneficial owners where applicable and obtain additional source-of-funds or source-of-wealth information when the customer’s risk or circumstances require it.
Singpass Face Verification
Singpass Face Verification is a facial-biometric authentication service that can support onboarding and authentication journeys. It may provide additional assurance that the person completing the journey is connected to the asserted identity. However, Face Verification is not necessarily part of every MyInfo transaction and the combination should not be described as a complete CDD package on its own.
Foreign Nationals and Customers Without Singpass
Some foreign nationals have valid Singpass accounts and MyInfo profiles and can use supported services. Customers without access require another verification pathway. Depending on the customer and risk, this may combine passport or identity-document verification with database checks, authenticity controls, facial comparison, liveness measures or human review.
A live video interaction may form part of a remote verification process, but institutions should not treat video KYC as a separate regulatory safe harbour. The control design, evidence retained and escalation process should be proportionate to impersonation, forged-document and non-face-to-face risks.
How Digital Banks Apply the Same Rules
MAS awarded four licences under Singapore’s digital bank framework. GXS Bank and MariBank received digital full bank licences, while ANEXT Bank and Green Link Digital Bank received digital wholesale bank licences. Trust Bank has a digital proposition but is licensed as a full bank rather than as one of the four digital-bank licence awardees.
Digital banks are subject to the same substantive AML and CFT requirements as other banks under Notice 626. Their onboarding evidence may be generated through digital systems rather than physical documents, but they must still establish the customer’s identity, assess risk, identify beneficial owners where relevant, understand the relationship and monitor activity.
The exact customer journeys and vendors used by individual banks can change. Institutions should avoid assuming that every digital bank uses the same combination of MyInfo, Face Verification, document capture or video review.
Source of Wealth and Source of Funds
Source of funds describes the origin of the money involved in a relationship or transaction. Source of wealth describes how a customer or beneficial owner accumulated their overall wealth. The depth of enquiry and corroboration should reflect the customer’s risk, the materiality of the wealth or funds and the circumstances of the relationship.
MAS’s July 2024 circular on establishing customers’ sources of wealth provided further guidance to financial institutions in the wealth-management sector. It emphasised appropriate, reasonable and risk-proportionate measures, including independent corroboration using documentary evidence or reliable public sources. It also confirmed that institutions should avoid a one-size-fits-all approach.
The circular did not create a universal June 2025 source-of-wealth requirement for every bank customer. Source-of-wealth measures already formed part of the enhanced requirements for relevant PEPs and higher-risk wealth relationships. Later industry best-practices material should be described as guidance on implementation, not as a new blanket mandate.
Ongoing Monitoring and Customer Reviews
CDD continues throughout the business relationship. A bank must scrutinise transactions to ensure that they are consistent with its knowledge of the customer, the customer’s business and risk profile, and, where appropriate, the source of funds.
Customer information should be kept relevant and up to date, particularly for higher-risk customers. Institutions commonly use scheduled reviews supplemented by event-driven reviews. Relevant triggers can include a change in beneficial ownership, unusual activity, new adverse information, a material change in expected behaviour or a connection to a higher-risk person or jurisdiction.
Transaction monitoring is one part of this obligation. See our guide to transaction monitoring in Singapore for more detail.
Record Keeping
Banks must retain CDD information, account files and relevant business correspondence for at least five years after the business relationship ends. Records relating to an occasional transaction must generally be kept for at least five years after the transaction. Transaction records must be sufficient to reconstruct individual transactions and should be retrievable promptly when required by MAS or another competent authority.
For digital onboarding, the retained evidence should be sufficient to demonstrate the verification method and outcome. Depending on the process, this may include data-retrieval records, authentication results, document images, system decisions, exception handling and evidence of human review. The record should reflect the controls actually used rather than a generic checklist.
Suspicious Transaction Reporting
Suspicious Transaction Reports are filed with the Suspicious Transaction Reporting Office within the Singapore Police Force. The obligation is based on knowledge or reasonable grounds for suspicion, not on a minimum transaction value. An STR may therefore be required for a small, attempted or rejected transaction.
A report should be filed as soon as reasonably practicable after suspicion is formed. Internal investigation can help explain the activity, but it should not be used to delay a required report. Institutions should document the indicators considered, the decision reached and the timing of escalation and filing.
Singapore law also contains tipping-off restrictions. Staff should follow approved internal procedures and avoid disclosures that could prejudice an investigation or reveal protected reporting information.
Singapore does not impose a universal S$20,000 cash transaction reporting requirement on banks and payment institutions. Separate CTR regimes apply to specified sectors and transactions, including regulated precious-stone and precious-metal dealers, pawnbrokers and casinos. These sector-specific rules should not be presented as part of the general Notice 626 KYC framework.
Where KYC Controls Commonly Break Down
Even where a policy reflects the applicable notice, implementation can fail when the evidence does not support the institution’s decision. Compliance teams should test whether their files and systems demonstrate the following:
- The correct MAS notice and threshold were applied to the institution, service and transaction.
- Ownership was traced through intermediate companies and nominees to the relevant natural persons.
- EDD information was assessed and affected the risk decision, rather than merely being collected.
- PEP definitions cover relevant family members and close associates and distinguish foreign PEPs from risk-based treatment of domestic and international-organisation PEPs.
- Customer profiles and beneficial-ownership records are updated when risk-relevant events occur.
- Digital onboarding records show the data, verification method, outcome, exceptions and approvals used in the decision.
- Suspicion is escalated and reported promptly, with a clear audit trail.
Frequently Asked Questions
Which MAS notice governs KYC for Singapore banks
MAS Notice 626 applies to banks. Merchant banks are covered by Notice 1014. Payment service providers must assess whether PSN01, PSN02 or both apply to the services they provide.
What is the occasional transaction threshold under Notice 626
For a customer without established business relations, Notice 626 requires CDD for a non-digital-token transaction exceeding S$20,000 and for a wire transfer exceeding S$1,500. Any digital-token transaction is also a CDD trigger. CDD is required regardless of value where there is suspicion or doubt about previously obtained customer information.
Does MyInfo satisfy all KYC requirements
No. MyInfo can provide verified government-held data and support identity verification, but the institution must still complete the other applicable elements of CDD, including risk assessment, relationship-purpose information, screening, beneficial-ownership work and any risk-based source-of-funds or source-of-wealth enquiries.
Can foreign nationals use MyInfo
Some can. A foreign national with a valid Singpass account may have a MyInfo profile and be able to use supported services. Customers without eligible access require an alternative verification pathway.
Can a bank use video for remote identity verification
A live video interaction may be one control within a risk-based remote verification process. It should not be described as an automatic safe harbour or a complete KYC method. The bank remains responsible for the reliability of the evidence, management of impersonation and document-fraud risks, and completion of all other CDD requirements.
Did MAS introduce a new source of wealth mandate in June 2025
No universal June 2025 mandate applies to every bank customer. MAS issued further source-of-wealth guidance for the wealth-management sector in July 2024, while source-of-wealth measures already applied in relevant PEP and higher-risk circumstances. Later best-practices material helps institutions implement those expectations on a risk-proportionate basis.
How long must KYC records be retained
CDD records for a business relationship must generally be retained for at least five years after the relationship ends. Records for occasional transactions must generally be retained for at least five years after the transaction. Other legal, regulatory or investigative requirements may require longer retention in a particular case.
Experience the most intelligent AML and fraud prevention platform
Experience the most intelligent AML and fraud prevention platform
Experience the most intelligent AML and fraud prevention platform
Top AML Scenarios in ASEAN

The Role of AML Software in Compliance

The Role of AML Software in Compliance





