Singapore Payment Services Act (PSA) - Digital Payment Token Regulation
Evidence request list. 10 controls, 10 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
AML/CFT
Per PSA + MAS Notice PSN02: AML/CFT. Requirements include (a) Enterprise-Wide AML and CFT Risk Assessment + (b) Customer Due Diligence on DPT Customers + (c) Enhanced Due Diligence for Higher Risk Customers + (d) ongoing monitoring + (e) Politically Exposed Persons + (f) transaction monitoring.
- SG PSA evidence for SGPSA-2
- Travel Rule + EDD partial
Consumer Protection
Per PSA + MAS Guidelines on Provision of DPT Services to the Public: customer protection. Requirements include (a) risk disclosures + (b) marketing restrictions to public + (c) suitability assessment + (d) handling of customer assets + segregation.
- SG PSA evidence for SGPSA-5
- Travel Rule + EDD partial
Cybersecurity
Per PSA + MAS Notices: cybersecurity for DPT. Align with MAS TRM Guidelines + Cyber Hygiene Notice + Incident Reporting.
- SG PSA evidence for SGPSA-4
- Travel Rule + EDD partial
Licensing
Per Singapore Payment Services Act 2019 (PSA) + 2021 amendments: DPT licensing. Requirements include (a) Licensing for Digital Payment Token Services + (b) Fit and Proper Assessment of Key Personnel + (c) capital requirements + (d) cooperate with MAS.
- SG PSA evidence for SGPSA-1
- Travel Rule + EDD partial
MAS Notice PSN02: AML and CFT for Digital Payment Token Services
DPT providers must conduct customer identification, verification, and ongoing monitoring.
- CDD procedure
- customer onboarding records
- risk rating documentation
- ongoing monitoring records
- weak CDD
- no risk rating
- missing ongoing monitoring
Providers must report suspicious transactions to the Suspicious Transaction Reporting Office.
- STR procedure
- STO filing records
- transaction monitoring outputs
- training documentation
- weak monitoring
- delayed STR filing
- missing training
DPT providers must maintain transaction records and customer identification records for five years.
- record retention schedule
- customer file inventory
- transaction record storage
- audit access procedures
- weak retention
- missing inventory
- no audit access
Providers must screen customers and transactions against designated sanctions lists.
- sanctions screening procedure
- screening tool configurations
- match disposition records
- review logs
- weak screening
- no disposition records
- missing review
Providers must establish AML/CFT policies, procedures, and conduct regular staff training.
- AML CFT policy
- training curriculum
- completion records
- executive sign-off
- weak policy
- no training
- missing sign-off
Travel Rule
Per PSA + FATF Travel Rule: information sharing for DPT transfers. Requirements include (a) originator + beneficiary information for transfers above threshold + (b) implement Travel Rule compliance + (c) maintain transaction records.
- SG PSA evidence for SGPSA-3
- Travel Rule + EDD partial
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Singapore Payment Services Act (PSA) - Digital Payment Token Regulation framework page.