How to Run a Compliance Gap Analysis for a Precious Stones and Metals Dealer in Singapore
Before you read this. This is our own reading of the instruments as they stood on 18 August 2026: the Acts, the Regulations, the Notices and the Guidelines, with the amendments in force on that date. Compliance material dates quickly, and a notice can be revised without any of the commentary around it changing. Check the current text before acting on anything here. Where our reading and the regulator’s text differ, the regulator’s text governs.
In November 2024 a dealer was fined for failing to perform customer due diligence on more than S$313,000 of sales, of which more than S$140,000 was later traced back to victims of a malware scam. Two of the dealer’s own employees had processed the payments despite suspecting money laundering.
The fine landed on the business, but under the dealer regime the exposure does not stop there. An owner or director involved in running the business who knew, or ought reasonably to have known, that such a failure was happening and did not take all reasonable steps to stop it commits the same offence as the business. Not knowing is not a defence. The defence that exists is having taken all reasonable steps, and that is precisely the evidence a compliance gap analysis is built to produce.
None of the November case was a failure of the rules on paper. It was a failure of the rules to run at the counter, which is a different problem and a more common one. The most reliable way to find that kind of gap, and to show that you looked, is to run the inspection on yourself before the regulator does. That structured self-inspection is a compliance gap analysis, and this guide explains what one is, what it covers for a dealer, and what good looks like.
What a compliance gap analysis is, and what it is for
A gap analysis is a diagnostic. It compares how your business actually operates against the specific rules that govern it, and it finds the places where the framework is fraying before those weaknesses turn into a breach. It is a proactive exercise, not a reactive one, and that is the whole point: the gap you find in a review is cheap, and the gap a regulator finds in an inspection is not.
It is worth separating this from a formal independent audit. An audit tends to look at historical adherence for reporting purposes. A gap review is a forward-looking support exercise that produces a roadmap for remediation. The focus is on the practical application of the rules, so a team is not just holding a manual but actively mitigating risk in a way that matches what the regulator expects to see.
The objective of a regulatory health check
The goal is a clear baseline. You look at your existing policies and procedures and test them against the reality of daily operations, because there is often a gap between the written rule and what staff actually do at the counter. A health check surfaces those discrepancies and confirms the framework still fits the business as it changes. If a dealer has shifted its customer mix or started accepting new payment forms, the controls have to move with it to stay effective.
When to run a gap review
Waiting for a notice of inspection is usually too late to make meaningful change. A review is most useful at a few specific points:
-
Business change. A new customer segment, a new product line, a new payment channel, or a move into higher-value transactions.
-
Regulatory updates. An amendment to the PSPM Act 2019, the PMLTFPF Regulations 2019, or the Guidelines for Regulated Dealers. The move to version 5.1 of the Guidelines on 12 May 2026 is a recent example of a change that warrants a look at whether your controls still match the current text.
-
Structural change. A change in ownership, a new compliance officer, or a change in internal reporting lines.
-
Before an anticipated inspection. Running the review while there is still room to fix things, rather than during a live inquiry.
Regular reviews stop compliance debt from accumulating quietly until it becomes unmanageable under inspection pressure. Finding the issues early is what lets a firm walk into an engagement from a position of steadiness rather than scramble.
Which rules actually govern a dealer
Singapore splits AML and CFT supervision between two regulators: the Monetary Authority of Singapore over financial institutions, and the Ministry of Law over precious stones and precious metals dealers. This guide is about the dealer, so it works to the Ministry of Law regime and the instruments that sit under it, not the financial-sector rulebook, and importing rules from the financial-sector regime that do not apply to a dealer is one of the more common ways a framework goes wrong.
The PSPM regime for dealers
The legal foundation is the Precious Stones and Precious Metals (Prevention of Money Laundering, Terrorism Financing and Proliferation Financing) Act 2019, with the operational detail in the PMLTFPF Regulations 2019, and the regulator’s expectations set out in the Guidelines for Regulated Dealers. The current version of those Guidelines is version 5.1, dated 12 May 2026. The one substantive change version 5.1 made from the version before it was to clarify the definition of cash equivalent, which matters because that definition sits at the centre of the main reporting trigger.
Clarity on the order of these instruments helps. The Act is the law and the Regulations made under it are binding. The Guidelines describe what the regulator expects to see in practice, and while they are not themselves law, failing to meet them tends to produce findings. The job of a framework is to translate all of it into everyday workflows rather than leave it as high-level text.
Mapping the current controls against the rulebook
Mapping controls is a methodical exercise, and it means looking past the literal text of a manual to how rules are applied in real time. This is usually where operational friction surfaces. You document every existing compliance process as it actually runs, not as an idealised version, and then compare your internal thresholds against the regulatory triggers to see where they have drifted apart.
Testing the CDD and transaction triggers
The most familiar trigger for a dealer is the designated transaction: one where cash or a cash equivalent exceeding S$20,000 is received as payment. The threshold attaches to the payment, not to the sale, so a S$50,000 sale settled by an ordinary bank transfer is not a designated transaction, because a bank transfer is neither cash nor a cash equivalent. A cash equivalent is a narrow, closed category: a defined list of specified payment forms set out in Regulation 3(1), not an open description to reason your way into. That definition is the one the current Guidelines clarified, so the reliable way to classify a payment is to check it against the list as it now reads, rather than judge it by the character of the payment.
The dangerous mistake is treating S$20,000 as the only trigger. Customer due diligence is also required where the dealer has reason to suspect money laundering, terrorism financing or proliferation financing, with no threshold at all, where it doubts the veracity of earlier due diligence, and in the prescribed circumstances covering gold and digital payment token payments. A dealer who reads the rule as “nothing to do under S$20,000” has inverted it, and that inversion is exactly the shape of the failure this guide opened with: the missing due diligence, the absent screening, and staff who saw something and had no working pathway to act on it. Every one of those is a gap a review is built to catch before it becomes an enforcement fact, and none of them turns on the size of the individual sale.
Evaluating the AML and CFT programme
A programme is more than transaction monitoring. The risk assessment should be the foundation of the framework, reflecting the specific risks in the dealer’s customer base, its products and its delivery channels, rather than a generic template. A review looks at whether that assessment captures the real inherent risks and the real effectiveness of the controls, and whether it has kept up with how the business actually operates now. It also tests the training records, because it is not enough to have a policy: staff have to demonstrate the behaviour the regulator expects, including a clear understanding of how to disclose suspicion under the Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act. Interviewing staff across functions is how you verify the written rules are being translated into practice on the floor.
Building a remediation roadmap
Finding a gap is only half the exercise. The value lies in the structured remediation that follows. Findings are categorised by their impact on regulatory standing, ownership is assigned to specific functions, timelines are set, and the work is documented. A remediation roadmap also does something for the firm beyond fixing the gap: kept as a clear log of every step taken, it demonstrates to a regulator that when the firm finds a weakness, it fixes it, which is the difference between a culture of continuous improvement and one of reactive panic.
Prioritising the high-risk findings
Not all gaps are equal. The ones that create immediate exposure come first. Missing customer due diligence records on designated transactions are high priority, as is any failure in sanctions screening, which carries no monetary threshold and applies before dealing with any customer regardless of the deal size. A risk assessment that is outdated or missing is a foundational problem, because the rest of the framework rests on it. And for a dealer, gaps in the semi-annual return filed through the Ministry of Law’s myPal system have to be closed to stay in good standing.
Integrating the changes into daily operations
Updating the manual is the first step, not the last. A manual on a shelf changes nothing until the new controls are woven into daily behaviour, and that is what targeted training is for: it gives staff the logic behind a new process, not just the instruction. That is the shift from compliance as a checkbox to compliance as an operational standard, where staff are actively managing risk rather than following rules they do not understand. It is also the specific thing that would have changed the outcome in the case above, where the people processing the payments already suspected something was wrong.
Bringing it together
A resilient framework is not a template. It is a matter of aligning daily operations with the specific instruments that govern a dealer, identifying the real inherent risks, and applying the customer due diligence triggers correctly rather than treating the S$20,000 threshold as the whole of the obligation. A gap analysis is how a dealer moves from hoping the framework holds to knowing where it does not, and closing those gaps before an inspection rather than during one.
If you would like a practitioner view of where your framework stands, you can book a scoping call with Azentiq Nexus Consulting to talk it through.
Disclaimer
This article is published by Azentiq Nexus Consulting LLP. It is general information about regulatory obligations. It is not legal advice, and it is not compliance advice for your particular circumstances.
Azentiq Nexus Consulting LLP is a compliance consultancy. We are not a law firm and we do not advise on law. We are not licensed by the Monetary Authority of Singapore and we are not registered with the Ministry of Law. We advise regulated firms; we are not one.
Regulations, thresholds and published guidance change. This article reflects our understanding at the time it was written and may not reflect the current position. Always check the current text published by the relevant regulator, and take advice on your own facts before acting.
Reading this article does not create a client relationship.
Frequently asked questions
- What is a compliance gap analysis for a precious metals dealer?
- It is a structured review that compares a dealer's current controls and procedures against the specific requirements of the PSPM Act 2019, the PMLTFPF Regulations 2019 and the Guidelines for Regulated Dealers. It identifies where internal processes fall short before they surface in an inspection, and it produces a remediation roadmap the firm's own team can act on.
- How is a gap analysis different from an audit?
- A gap analysis is a forward-looking support exercise focused on identifying operational weaknesses and providing a path to fix them. An audit is typically an independent assurance exercise that verifies historical adherence for reporting purposes. A gap review is practitioner-led and designed to strengthen the framework, not to certify it.
- What are the customer due diligence triggers for a dealer under the PSPM regime?
- The familiar one is a designated transaction, meaning cash or a cash equivalent exceeding S$20,000 received as payment, under the PMLTFPF Regulations 2019. It is not the only trigger. Due diligence is also required where the dealer suspects money laundering, terrorism financing or proliferation financing, with no threshold at all, where it doubts earlier due diligence, and in the prescribed circumstances covering gold and digital payment token payments. Sanctions screening carries no threshold either and applies to every customer.
- What counts as a cash equivalent?
- A cash equivalent is a narrow, closed category defined in Regulation 3(1) of the PMLTFPF Regulations 2019: a specific list of payment forms rather than an open class. The current Guidelines for Regulated Dealers, version 5.1 dated 12 May 2026, clarified this definition, so check a payment against the list as it now reads rather than reasoning from what the payment looks like. What matters operationally is that the S$20,000 test counts cash and those listed cash equivalents, and a payment outside the list, such as an ordinary bank transfer, does not start the designated-transaction machinery.
- How often should a dealer run a gap review?
- At least once a year is a sensible baseline, and sooner whenever there is a significant change in the business or in the instruments that govern it. Regular reviews keep the framework aligned with the current rules and stop compliance debt building up unnoticed between inspections.
- What are the most common gaps found in a dealer's framework?
- Risk assessments that are generic or out of date, incomplete customer due diligence records on designated transactions, thin evidence of staff training, and gaps in the semi-annual return filed through myPal. Most gaps are the distance between a documented policy and the actual behaviour at the counter.
- Does Azentiq Nexus Consulting provide legal advice?
- No. It does not provide legal advice, formal legal opinions, or contract drafting. It is a support function for a firm's internal compliance team, focused on operational programme design, remediation and staff training, not a replacement for legal counsel.
- Can Azentiq Nexus Consulting act as a dealer's compliance officer?
- No. The Ministry of Law expects that person to sit inside the registered dealer, as an employee or owner. The firm appoints its own compliance officer, and what is on offer here is advisory support, health checks and gap reviews for that person.
Scale With Trust
Weekly compliance briefings for regulated firms in Singapore. Every Friday. No spam.
By subscribing, you agree to receive emails from Azentiq Nexus Consulting.