Remediating MAS Inspection Findings: A 2026 Guide
Where this comes from. Azentiq Nexus Consulting is not licensed by the Monetary Authority of Singapore, and this is not regulatory guidance. We are a compliance consultancy. Our remediation work has been with dealers regulated by the Ministry of Law rather than with MAS-regulated firms, and we say so because the difference matters. What carries across is the craft of closing a finding: the diagnosis, the sequencing, the evidence. Anything specific to how MAS operates is cited to MAS so you can read it yourself. Where this article reflects practitioner experience rather than a published position, it says so.
A letter of findings has landed on your desk, and the real question is what happens next. Before the checklist, one thing worth knowing. On 12 August 2026, MAS published its own paper on how firms should approach this, which at the time of writing we could not find written up anywhere else. It is the Information Paper on Culture Capabilities for Effective Remediation and Sustainable Change, it runs to 27 pages, and where this guide leans on it we cite the paragraph so you can read it yourself.
One caveat up front, because it changes what the paper can and cannot tell you. It is about culture: the behavioural drivers behind repeated control failures, not a general manual for closing findings. So we use it for what it covers, and for everything else we tell you plainly that it is experience rather than a MAS position.
What a letter of findings is, and the hierarchy behind it
MAS inspection findings are formal observations issued when a firm is assessed as falling short of a regulatory standard or Guideline, usually after a thematic or onsite inspection. Compliance findings of this kind, in our experience, most often surface two things: gaps in anti-money-laundering and countering-the-financing-of-terrorism controls, and a divergence between what the manual says and what the desk actually does. That second one matters more than it looks, because it is read as a sign that the framework is not really being followed.
The stakes are real. Left unaddressed, findings can lead to MAS enforcement action, from composition fines and public reprimands to conditions on a licence, and in serious cases worse. That is the reason to treat remediation as a proper piece of risk management rather than a checklist to clear.
To respond well, it helps to be precise about the instrument. Acts and Regulations, such as the Payment Services Act 2019 or the Securities and Futures Act 2001, carry mandatory requirements: the things a firm must do. Guidelines and Notices set out what the regulator expects to see in practice. Guidelines are not themselves law, but they are the benchmark MAS uses to assess conduct, so a remediation plan should answer the specific instrument the finding cites, not a general sense of good practice.
The findings that tend to repeat
In our experience advising regulated firms, most findings are systemic rather than one-off slips, and a few themes come up again and again: enterprise-wide risk assessments that no longer match the business, customer due diligence that stops short of the true beneficial owner in a layered structure, and transaction-monitoring thresholds calibrated so loosely they drown the team in false positives or so tightly they miss the real thing. Naming the theme is the first step, because the fix for a theme is different from the fix for a single file.
Start with root cause, and for culture, start with the paper
Remediation fails when a firm treats the symptom and not the cause. Retrieving one missing document from one client file closes that file; it does nothing to stop the next one. The useful question is why the gap was there at all. In our experience the answer is usually one of a short list: a training gap, a system that does not do what people assume it does, or a policy that stopped matching the business a while ago. That diagnosis is experience, not a MAS rule, and we flag it as such.
Where the paper is directly on point is culture. It puts a culture root cause analysis at the very start of remediation. In its words, “the process of remediation starts with a robust and evidence-based culture root cause analysis” (Capability 2, paragraph 3.1), and it is explicit that this goes beyond examining deficiencies in governance structures, control systems, policies and procedures, to the behavioural patterns and culture drivers underneath them. So when the same kind of finding keeps returning, the paper’s own framing is that the driver is likely behavioural, and that a fix aimed only at the control will not hold.
Where the drift actually lives
Documentation-practice divergence, the manual saying one thing while staff do another, is the clearest example of that behavioural driver in daily life. In our experience the fix is rarely to discipline the staff who deviated; it is usually to rewrite the procedure so it matches how the work is actually done and remains compliant, so the manual becomes something people use rather than a document nobody opens. That is experience. The paper’s contribution is the reason it matters: if the behaviour and the written rule keep parting ways, that is a culture signal, not a paperwork problem.
Tactical fixes and systemic change
This next part is mostly experience, so we will label it as such. Remediation runs on two tracks at once. Tactical fixes deal with the specific errors the inspection named: completing the missing due-diligence records on the high-risk accounts, clearing the backlog of monitoring alerts. They show immediate progress and they buy time. Systemic change is the slower work of making sure those errors cannot recur, which usually means redesigning the process that produced them rather than patching the output.
The trap we have watched firms fall into is stopping at the first track. If you only fix the files, you have not fixed the firm, and the same theme returns at the next inspection. The tactical work protects your standing in the short term; the systemic work is what actually closes the finding.
A remediation checklist that holds up
A structured response keeps anything from slipping, and the days right after the exit interview are when a team is sharpest on the detail. The timeline itself is set by the letter of findings, so we have left specific durations out of this: the letter is the authority on how long you have, not a rule of thumb. Everything below is process we have used, not a MAS requirement.
Phase one, categorise and plan. Sort the findings by risk and by the instrument each one engages, such as the Payment Services Act 2019 or the Securities and Futures Act 2001. Give every finding a named owner, because a finding without an owner is the one that slips. Then draft a remediation roadmap with milestones that line up with the regulator’s timeline.
Phase two, execute and verify. Update the policies and procedures so they address the root cause you diagnosed, not just the surface error in a handful of files. Train the staff who have to live with the change. Then run an internal compliance health check to confirm the change works in practice before you report it as done.
Phase three, report and close. Prepare a formal response setting out what you did and the evidence for each finding. Keep the dialogue with your MAS officer open and professional throughout. And schedule a follow-up review, because a fix that quietly decays is a finding waiting to be reopened.
Independent validation, and here the paper is not vague
When it comes to checking that a culture change has actually worked, the paper drops the hedging that this kind of guidance usually carries. Paragraph 5.3 says, in full: “Validation should be performed by an independent function or an external party.” Not may, not in serious cases: should, and by someone independent. The paper pairs this with a worked example, Good Practice 4D, of a firm that brought in independent reviewers at two different stages of its culture change programme, one to test whether the programme was well designed and a later one to test whether it was working in practice.
The reason this belongs in a remediation guide is that validation is the step firms most often mark as done when it is only self-assessed. If the person confirming the change worked is the person who ran the change, that is not validation in the sense the paper means. This is also, in fairness, where we should say what we do not do: Azentiq Nexus Consulting does not provide independent audit or assurance services, which is precisely why that validation sits with someone other than us.
The board’s role, stated honestly
It is tempting to write that MAS requires the board to be notified of inspection findings. We are not going to, because we could not find it said that way in the paper, and this is the kind of claim a reader checks. What the paper does say is about leadership of the culture change. Paragraph 1.9 puts the Board and senior management in the role of “setting the direction to drive the culture change” and steering the firm through the work that follows. Paragraph 2.8 describes regular reporting to the Board and senior management, and is candid that it may include “delays and challenges” rather than only progress.
So the sourced version of the point is narrower and, we think, more useful than the version the draft reached for. The board should own the direction of a remediation that turns on behaviour, and it should see the difficulties honestly rather than a sanitised status update. That the board should also be told when findings land is sound practice and our own view, and we offer it as that, not as a MAS instruction.
How Azentiq Nexus Consulting helps
We work as a support function for an in-house compliance team, not a replacement for it. On a remediation that is our practitioner perspective on what a regulator expects to see, help diagnosing where operational reality has drifted from the written procedure, and support drafting the response and training the people who have to run the new process. We do not provide independent audit or assurance services, so where a finding calls for independent validation, that is a job for someone other than us, and we will say so.
If a letter of findings has landed and you would like a practitioner view of how to approach it, you can book a scoping call with Azentiq Nexus Consulting to talk it through.
Disclaimer
This article is published by Azentiq Nexus Consulting LLP. It is general information about regulatory obligations. It is not legal advice, and it is not compliance advice for your particular circumstances.
Azentiq Nexus Consulting LLP is a compliance consultancy. We are not a law firm and we do not advise on law. We are not licensed by the Monetary Authority of Singapore and we are not registered with the Ministry of Law. We advise regulated firms; we are not one.
Regulations, thresholds and published guidance change. This article reflects our understanding at the time it was written and may not reflect the current position. Always check the current text published by the relevant regulator, and take advice on your own facts before acting.
Reading this article does not create a client relationship.
Frequently asked questions
- How long do we have to remediate MAS inspection findings?
- The timeline is set in the letter of findings itself, and it varies with the nature and seriousness of the gaps, so there is no reliable rule-of-thumb figure to quote. Urgent issues, particularly around AML or CFT risk, usually need immediate tactical fixes regardless of the wider deadline. The practical move is to build a roadmap against the date the letter gives you rather than a number from an article.
- What happens if we cannot meet the deadline?
- Unexplained failure to meet a deadline invites more supervisory scrutiny, so the sensible course is to manage the timeline actively and keep it documented. In our experience, telling the regulator early and with a clear operational reason when a date is at risk is far better received than silence followed by a miss. That is our advice from practice, not a MAS-published requirement.
- Do we need an external firm to verify our remediation?
- For culture change specifically, the MAS paper is clear: paragraph 5.3 says validation should be performed by an independent function or an external party. More broadly, whether an independent review is expected depends on the seriousness of the findings and what the regulator asks for, so the letter and your supervisor are the guide. Azentiq Nexus Consulting does not provide independent audit or assurance services; we support the in-house team and its preparation for any such review.
- Should we tell our board about the findings?
- Yes, in our view the board and senior management should be informed and should take ultimate responsibility for the response. On the sourced point, the MAS paper puts the Board and senior management in charge of setting the direction for culture change (paragraph 1.9) and expects reporting to them that can include delays and challenges (paragraph 2.8). Telling the board when findings first land is our own recommendation from practice rather than a requirement we can cite.
- How does MAS check that we have actually fixed the gaps?
- We cannot point you to a published line on exactly how MAS verifies a remediation, so treat what follows as our expectation from practice, not a MAS process. We would expect it to start with a review of the formal submission and to be able to extend to a follow-up look at the evidence. What you can act on without any of that is the preparation: have the proof that the change is embedded ready to be looked at, updated policies, training records, and results from internal testing, with an audit trail behind each claim of completion.
- What is the difference between a regular and a thematic inspection?
- MAS's PSN02 describes its on-site inspections as including "regular and thematic inspections to test FIs' effectiveness in key areas". It does not define a regular inspection, so we will not put words in its mouth. A thematic inspection is the one it draws by contrast: a focus on a specific area, applied to firms selected by risk rather than the whole industry, with the guidance giving the example of virtual asset service providers pulled into thematic inspections where they are identified as higher risk. Either kind can produce formal findings that need a structured response.
- How often should we run a compliance health check?
- At least once a year is a sensible baseline, and sooner after a significant change such as a new product line. Finding the gaps yourself, before an inspection does, is the cheapest version of all of this, because you fix them without a deadline and a letter attached.
Scale With Trust
Weekly compliance briefings for regulated firms in Singapore. Every Friday. No spam.
By subscribing, you agree to receive emails from Azentiq Nexus Consulting.