Skip to content

Evidence request lists

Singapore Payment Services Act (PSA) - Digital Payment Token Regulation

Evidence request list. 10 controls, 10 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

AML/CFT

SGPSA-2
AML/CFT Risk Assessment and Customer Due Diligence

Per PSA + MAS Notice PSN02: AML/CFT. Requirements include (a) Enterprise-Wide AML and CFT Risk Assessment + (b) Customer Due Diligence on DPT Customers + (c) Enhanced Due Diligence for Higher Risk Customers + (d) ongoing monitoring + (e) Politically Exposed Persons + (f) transaction monitoring.

Artefacts an auditor will ask for
  • SG PSA evidence for SGPSA-2
Where this commonly fails
  • Travel Rule + EDD partial

Consumer Protection

SGPSA-5
Customer Protection, Disclosures, Marketing Restrictions

Per PSA + MAS Guidelines on Provision of DPT Services to the Public: customer protection. Requirements include (a) risk disclosures + (b) marketing restrictions to public + (c) suitability assessment + (d) handling of customer assets + segregation.

Artefacts an auditor will ask for
  • SG PSA evidence for SGPSA-5
Where this commonly fails
  • Travel Rule + EDD partial

Cybersecurity

SGPSA-4
Cybersecurity and Technology Risk for DPT Service Providers

Per PSA + MAS Notices: cybersecurity for DPT. Align with MAS TRM Guidelines + Cyber Hygiene Notice + Incident Reporting.

Artefacts an auditor will ask for
  • SG PSA evidence for SGPSA-4
Where this commonly fails
  • Travel Rule + EDD partial

Licensing

SGPSA-1
Licensing for Digital Payment Token Services

Per Singapore Payment Services Act 2019 (PSA) + 2021 amendments: DPT licensing. Requirements include (a) Licensing for Digital Payment Token Services + (b) Fit and Proper Assessment of Key Personnel + (c) capital requirements + (d) cooperate with MAS.

Artefacts an auditor will ask for
  • SG PSA evidence for SGPSA-1
Where this commonly fails
  • Travel Rule + EDD partial

MAS Notice PSN02: AML and CFT for Digital Payment Token Services

PSN02-1
Customer due diligence

DPT providers must conduct customer identification, verification, and ongoing monitoring.

Artefacts an auditor will ask for
  • CDD procedure
  • customer onboarding records
  • risk rating documentation
  • ongoing monitoring records
Where this commonly fails
  • weak CDD
  • no risk rating
  • missing ongoing monitoring
PSN02-2
Suspicious transaction reporting

Providers must report suspicious transactions to the Suspicious Transaction Reporting Office.

Artefacts an auditor will ask for
  • STR procedure
  • STO filing records
  • transaction monitoring outputs
  • training documentation
Where this commonly fails
  • weak monitoring
  • delayed STR filing
  • missing training
PSN02-3
Record-keeping requirements

DPT providers must maintain transaction records and customer identification records for five years.

Artefacts an auditor will ask for
  • record retention schedule
  • customer file inventory
  • transaction record storage
  • audit access procedures
Where this commonly fails
  • weak retention
  • missing inventory
  • no audit access
PSN02-4
Sanctions screening

Providers must screen customers and transactions against designated sanctions lists.

Artefacts an auditor will ask for
  • sanctions screening procedure
  • screening tool configurations
  • match disposition records
  • review logs
Where this commonly fails
  • weak screening
  • no disposition records
  • missing review
PSN02-5
Internal policies and training

Providers must establish AML/CFT policies, procedures, and conduct regular staff training.

Artefacts an auditor will ask for
  • AML CFT policy
  • training curriculum
  • completion records
  • executive sign-off
Where this commonly fails
  • weak policy
  • no training
  • missing sign-off

Travel Rule

SGPSA-3
Travel Rule and Wire Transfer Information

Per PSA + FATF Travel Rule: information sharing for DPT transfers. Requirements include (a) originator + beneficiary information for transfers above threshold + (b) implement Travel Rule compliance + (c) maintain transaction records.

Artefacts an auditor will ask for
  • SG PSA evidence for SGPSA-3
Where this commonly fails
  • Travel Rule + EDD partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Singapore Payment Services Act (PSA) - Digital Payment Token Regulation framework page.