The Payment Services Act in Singapore: A Licensing and Compliance Guide

MAS Licensing Azentiq Nexus Consulting 7 min read

A payment firm that watches its monthly volume climb toward S$3 million usually knows a licensing change is coming, but the change is less mechanical than it looks, and the detail that decides it is easy to read the wrong way. This guide works through what the Payment Services Act regulates, how the licence tiers are actually set, and the AML and CFT duties that come with a licence, with particular care on the two thresholds that firms most often misjudge.

What the Act is, and how it regulates

The Payment Services Act 2019 consolidated Singapore’s payment oversight, merging the Money-changing and Remittance Businesses Act and the Payment Systems (Oversight) Act into one framework under the Monetary Authority of Singapore. The point was not only tidiness. It gave firms a single, clearer perimeter while letting the regulator keep pace with cross-border transfers and digital payment tokens, with consumer protection and system stability as the standing aims.

Regulation tied to the service, not the entity

The framework is activity-based, which means a firm’s obligations follow the payment services it actually provides rather than what kind of company it is. It is modular: a firm offering domestic transfers that later starts issuing e-money adds that service to its profile rather than starting a fresh licence. The effect is that the regulatory load stays proportionate to the risk, so a small money-changer is not held to the same requirements as a large digital token platform.

The instruments to know

The Act is the foundation for the licence, but it is not where the anti-money-laundering duties live. The Payment Services Regulations 2019 carry the operational detail under the Act. The AML and CFT obligations come through MAS Notices PSN01 and PSN02, and those are issued not under the Payment Services Act but under the Financial Services and Markets Act 2022, even though they bind holders of a payment services licence. Both were revised on 30 June 2025. So the licence comes from one Act and the money-laundering duties from another, and a compliance officer who reads the Payment Services Act and its Regulations and stops there has missed the instruments that actually carry the AML obligations.

The licensing framework and the two thresholds

Under the Act a firm has to match its licence to the payment services it provides, so the first task is to work out which of the seven regulated payment services it performs.

The seven payment services

The seven fall into three natural groups: account issuance and domestic money transfer; cross-border money transfer and merchant acquisition; and e-money issuance, digital payment token services and money-changing. Identifying which apply is the foundation of everything that follows, because the whole obligation set is keyed to the service.

Standard and Major Payment Institutions, and how the volume is measured

Licensing has three classes. Money-changing is its own restricted licence for currency exchange. For the rest, the line between a Standard Payment Institution and a Major Payment Institution is set by volume, and the way that volume is measured is the part that catches firms out. A Standard Payment Institution stays below S$3 million in monthly transactions for any single payment service, and below a S$5 million daily e-money float. But both figures are averages over a calendar year, not flat monthly or daily caps. So a single spike, one S$3.5 million month, does not cross the line if the yearly average stays under it, and a firm that upgrades on the strength of one busy month may be taking on a licence it does not need.

Crossing either yearly average moves a firm to a Major Payment Institution licence, which brings a higher base capital, S$250,000 against S$100,000 for a Standard Payment Institution, held on an ongoing basis rather than only at application, and a security deposit. The transition is a genuine piece of work with the regulator, and getting the category right early is what avoids either an unnecessary upgrade or an unintentional breach.

The deposit is where the detail bites, and a warning belongs on its S$6 million before the figure itself: it is not the same S$6 million as the one in the Act’s licensing test, and it does not work the same way. The deposit is S$100,000 where a payment service processes up to S$6 million a month and S$200,000 above that, and three things about that figure are easy to get wrong. It is an average, not a flat figure. It is averaged over the current calendar year, the year in progress, rather than over a calendar year the way the two licensing thresholds are, so it moves as the year’s volume accumulates and can be crossed late in the year on the back of a heavy month. And it is measured for each payment service the firm provides, so a firm running three services is measured three times, not once on its total.

There is a trap worth stating plainly. In the Act, S$6 million is a combined figure across two or more payment services; in the Regulations, for the deposit, the same S$6 million is per service. Same number, opposite aggregation, twenty pages apart, and nothing on the page warns a reader who has learned the first that the second runs the other way.

The AML and CFT obligations

The duties that translate the Act into daily practice come mainly through the Notices. Providers of specified payment services work to PSN01; digital payment token providers work to PSN02. A point worth holding clearly is that these are a different world from the precious stones and metals regime, where customer due diligence turns on the S$20,000 dealer threshold. A MAS payment institution has its own due-diligence triggers under PSN01 and PSN02, and sanctions screening in both regimes carries no monetary threshold at all: it is owed on every customer, whatever the size of the transaction.

Beyond screening, a firm has to run real customer due diligence and ongoing monitoring, which depends on genuinely knowing who its customers are and where their money comes from. This is not a set-and-forget control, and the firms that come through inspections best are the ones that treat it as a core function rather than an administrative afterthought.

The enterprise-wide risk assessment

A compliance framework starts with an enterprise-wide risk assessment. It is where a firm identifies its exposure to money laundering and terrorism financing across the four factors that matter: its customers, the countries it operates in, its products, and its delivery channels. Non-face-to-face onboarding, for instance, carries more risk than in-person verification, and documenting that is what lets a firm justify why some controls are heavier than others. Done properly, the assessment is the thing that shows a regulator the controls are reasoned rather than generic.

Staying compliant after the licence

A licence is the start of the obligation, not the end of it. The heavier ongoing duties are the regulatory returns a firm files with MAS, which are one of the main ways the regulator watches transaction volumes and firm health, so late or inaccurate submissions draw exactly the attention a firm does not want. A compliance calendar that keeps every return on time is unglamorous, and it matters more than it looks.

Internal audits and health checks are the safety net underneath that. They let a firm find and fix a gap before an inspection does, and they are where a support function that brings a practitioner view of what a regulator expects earns its place, without displacing the in-house team’s ownership.

Inspection readiness and training

MAS can inspect at any time, and it expects to see a living compliance culture where the written policy is matched by what people actually do. Record-keeping carries a lot of the weight, because a control you cannot evidence is one the regulator may treat as never performed. Training runs alongside: the Guidelines expect all relevant staff to be trained on AML and CFT, not just the compliance team, so that a front-line person can recognise a red flag in the moment, with training at hiring and at regular intervals after. Management carries its own duty to understand its oversight responsibilities and to resource the function properly.

Bringing it together

The Payment Services Act is modular by design, and its difficulty is in the detail: which of the seven payment services you provide, how the SPI and MPI thresholds are actually measured, and the discipline of ongoing reporting. Get the licence category right against the yearly-average thresholds, keep the AML and CFT programme matched to your real risks, and treat the returns as obligations rather than administration, and the framework becomes navigable rather than fraught.

If you would like a practitioner view of where your framework stands, or of which licence tier fits your scale, you can book a scoping call with Azentiq Nexus Consulting to talk it through.

Disclaimer

This article is published by Azentiq Nexus Consulting LLP. It is general information about regulatory obligations. It is not legal advice, and it is not compliance advice for your particular circumstances.

Azentiq Nexus Consulting LLP is a compliance consultancy. We are not a law firm and we do not advise on law. We are not licensed by the Monetary Authority of Singapore and we are not registered with the Ministry of Law. We advise regulated firms; we are not one.

Regulations, thresholds and published guidance change. This article reflects our understanding at the time it was written and may not reflect the current position. Always check the current text published by the relevant regulator, and take advice on your own facts before acting.

Reading this article does not create a client relationship.

Frequently asked questions

What are the main objectives of the Payment Services Act?
Consumer protection and the stability of the financial system, delivered through a single framework that merged older payment laws. The activity-based design keeps the regulatory load proportionate to the risk of the specific payment services a firm provides, and it lets the regulator address newer risks in digital payment tokens and cross-border transfers.
Who needs a licence under the Payment Services Act?
Any firm providing regulated payment services in Singapore. The seven services are account issuance, domestic money transfer, cross-border money transfer, merchant acquisition, e-money issuance, digital payment token services, and money-changing. The framework catches both traditional providers and newer fintech entrants that move funds or exchange tokens.
What is the difference between a Standard and a Major Payment Institution?
It is set by volume, and the volume is measured as an average over a calendar year, not as a flat cap. A Standard Payment Institution stays below S$3 million in monthly transactions for any single payment service, and below a S$5 million daily e-money float, both averaged across the year. Crossing either average moves a firm to a Major Payment Institution licence, with a higher base capital of S$250,000 held on an ongoing basis and a larger security deposit. A single high month does not cross the line if the yearly average stays under it.
How does the Act regulate digital payment token services?
A digital payment token provider needs a Standard or Major Payment Institution licence and works to MAS Notice PSN02 for its AML and CFT duties. The regulator's focus is on whether the firm has real systems to identify and manage the money-laundering and terrorism-financing risks that come with digital assets.
What are the AML and CFT requirements for payment service providers?
Customer due diligence and ongoing monitoring under PSN01 or PSN02, an enterprise-wide risk assessment, and regular staff training. Sanctions screening carries no monetary threshold and is owed on every customer. The aim is a programme matched to the firm's actual risk profile rather than a generic manual.
How often should a payment institution run a compliance health check?
The Guidelines do not fix a frequency, but at least once a year is a sensible baseline, and sooner when transaction volumes rise or a new service launches. Regular reviews find gaps before the regulator does and keep the programme aligned with the current versions of the MAS Notices.
Can a firm provide payment services while its licence application is pending?
No. Providing regulated payment services without MAS authorisation is a breach of the Act, and most transitional arrangements have expired, so a new entrant waits for formal approval before starting. The waiting period is best used to build and test the internal compliance systems so the firm is ready the day the licence is granted.