Skip to article
HSJGlobal

SINGAPORE DIGITAL TOKEN REGULATION

Singapore DPT Service Provider Licence: Requirements & Risks

Treat the DPT licence as one part of a provable customer-asset, AML/CFT and operational-risk system.

A Singapore DPT service provider needs more than a company and a token product: it needs a verified Payment Services Act scope, an appropriate MAS route and controls that can manage AML/CFT, customer assets, technology and outsourced dependencies. It suits a team that can document how the product actually moves or controls value; it does not suit a launch that calls itself ‘crypto technology’ while accepting customer instructions or assets before its regulatory perimeter is clear.

The major risk is not only whether a licence application is filed, but whether the business can stop, investigate, record and recover from a suspicious or failed transaction. Start by mapping every customer, token, wallet, fiat, instruction and provider flow, then build the corporate and control evidence around that map.

Key takeaways

  • DPT classification follows the real function , so token labels, brand names and user-interface wording cannot replace an activity map.
  • Company records and regulatory evidence must agree , particularly for controllers, ownership, funding and decision authority.
  • PSN02 requires operational AML/CFT readiness , not a policy copied from another jurisdiction without local ownership and testing.
  • Key management and providers are core risks , because an outsourced wallet or cloud service does not remove the applicant’s responsibility.
  • Public claims must be proven by live controls , so a claim-to-control matrix should gate marketing and feature releases.

In this article

Define the DPT product before selecting a licence route

A digital payment token (DPT) business should not begin with the phrase ‘crypto exchange’. Under Singapore’s Payment Services Act (PS Act), the legal analysis turns on the services the company will actually provide. A product may include token transfer, exchange, custody-like functions, customer wallets, fiat payment flows, merchant functions, referrals, technology provision or activities that fall outside the DPT perimeter and into another regulatory regime. Each component must be mapped before a licence route is selected.

MAS’s current payment-services licensing framework identifies DPT service as a payment-service activity, and the MAS Financial Institutions Directory shows regulated DPT-service activity under major payment institutions. That public directory is useful for verification of existing firms, but it is not a self-assessment tool and does not determine the correct licence for a new product. The proposed business, transaction flow, token features, customer geography and client relationship must be assessed against the current law and MAS guidance.

A token label does not settle the regulatory perimeter; the actual function, control and value flow do. For example, adding custody, executing a transfer, converting token value, accepting fiat, operating a marketplace or promoting a retail product can create different risks and regulatory questions. Build a product-function inventory before a website, mobile app, merchant agreement or customer waitlist describes a service that is not yet supported.

Product question Why it changes the analysis Record to prepare
Who controls token access or transaction signing? Identifies custody, operational and customer-asset exposure Key-management and authority map
Does the firm exchange, transfer or arrange token value? May determine the relevant payment-service activity End-to-end asset, fiat and instruction flow
Who are the customers and counterparties? Shapes AML/CFT, sanctions and distribution risk Onboarding and country-risk criteria
What is said to the public? Marketing can create conduct and risk-disclosure issues Approved claims and customer communications register

Map the DPT service perimeter

Review the token, wallet, fiat and customer flows before your entity or public product description locks in the wrong regulatory scope.

Build the entity and ownership records for regulatory scrutiny

A Singapore company is commonly used as the operating vehicle, but incorporation is only the corporate foundation. The ACRA filing must accurately show position holders, shareholders, controllers, registered office, share capital, constitution and activity. These facts are also central to a DPT licence application, banking due diligence, provider onboarding and AML/CFT assessment. A UEN does not allow the company to provide DPT services.

Start the corporate record from verified ownership documents, not from a simplified investor presentation. Where there are foreign corporate shareholders, trusts, multiple founders or nominee arrangements, reconcile legal ownership, beneficial ownership, controller details, board authority and funding evidence before filing. The practical document sequence for corporate-shareholder incorporation records is a useful parallel for ensuring that ACRA and regulatory information derive from the same reliable source pack.

Use the ordinary Singapore company formation requirements to establish the company law baseline, then layer the DPT-specific application and operational evidence on top. ACRA’s current rules on directors, company secretaries, registered office and registers remain applicable even when the company’s principal business is technology-led or cross-border.

The governance model needs named senior responsibility for token operations, AML/CFT, technology, customer assets, incidents, complaints and outsourcing. A resident director or corporate service provider cannot take those operational decisions by virtue of a filing role. Directors should be able to identify the product perimeter, major asset and cyber risks, and the trigger that requires escalation to MAS, banks, customers or law enforcement.

DPT risk and recovery path A DPT service must connect product scope, AML/CFT, customer-asset controls and public communications before launch. Map token and value flow Confirm MAS route Test AML/CFT controls Prove key and wallet controls Approve public claims Launch only verified features
A DPT service must connect product scope, AML/CFT, customer-asset controls and public communications before launch.

Use current MAS licensing and AML/CFT sources, not historic crypto summaries

MAS’s payment-service-provider licensing guidance is the current starting point for eligibility and application procedure under the PS Act. Its payment-services application page also publishes official application and annual fees by service and licence type. These official items should be checked on the filing date; a price quoted in an old blog, a provider package or another firm’s licence history is not evidence that the same route applies to a new DPT business.

DPT service providers also have a dedicated AML/CFT framework. MAS Notice PSN02 addresses prevention of money laundering and countering the financing of terrorism for DPT service, and MAS has issued guidance to that Notice. MAS also published AML/CFT supervisory expectations for DPT service providers in July 2026. Those materials should be read against the actual customer risk, token exposure, transaction pattern, sanctions screening, travel-rule and suspicious-transaction workflow of the proposed business.

Compliance readiness must be demonstrable before token activity is live, not reconstructed after a suspicious transaction. The business needs a risk assessment that explains customer segments, countries, token types, product channels, fraud vectors, blockchain analytics or monitoring tools, escalation limits and the people authorised to decide when an account or transaction is restricted. A policy copied from a foreign group is not enough if local controls, systems and accountable owners are missing.

  1. Confirm the exact regulated services and any adjacent activity that may require a separate legal analysis.
  2. Prepare ownership, governance, business plan, technology, financial and provider evidence from one controlled source of truth.
  3. Design customer due diligence, screening, monitoring, investigation, record-keeping and reporting workflows for the intended risk profile.
  4. Test the public-facing product and marketing material against the licence status, customer segment and risk-disclosure position.

Stress-test customer-asset controls

Identify who controls keys, access, monitoring, recovery and outsourced providers before a live DPT transaction creates an untested exposure.

Customer assets, key management and outsourcing are core risks

A DPT business can fail even when its licence application reads well if it cannot explain who controls private keys, how authority is split, how customer entitlements are recorded, what happens when a transaction is irreversible, how wallets are reconciled and how compromise is detected. Treat those questions as legal, operational, customer-protection and technology risks at once. The answer may differ between a hosted wallet, an exchange, an execution-only product and a business that never controls customer assets.

Outsourcing must be mapped with the same precision. Cloud hosting, wallet infrastructure, key-management technology, blockchain analytics, KYC, sanctions screening, liquidity providers, fiat ramps, customer support and affiliates can each be critical. A written contract should make clear the provider’s role, data access, service levels, security expectations, audit/information rights, subcontracting restrictions, incident notices, exit support and business-continuity responsibilities.

Do not assume a group brand or vendor certification proves local readiness. The Singapore applicant needs to know what its own directors and staff can monitor, override, suspend, reconcile and evidence. If a parent company or foreign affiliate controls a critical function, the governance model must state how the Singapore entity receives information, exercises oversight and protects customers when there is a conflict or system failure.

The difficult question is not whether a provider exists, but whether the applicant can control and recover the critical service it relies on. Use scenario tests for wallet compromise, abnormal withdrawal patterns, chain disruption, sanctions alerts, vendor outage, incorrect pricing, inaccessible customer assets and disputed transactions.

Public communications and retail risk need their own controls

DPT products can be complex, volatile and difficult for customers to understand. MAS has published Guidelines on Provision of Digital Payment Token Services to the Public. A business should check the current guidance before offering, advertising or otherwise presenting a DPT service to the public, particularly where customers may interpret product design, incentives, return statements or interface language as a recommendation or safety assurance.

Create a controlled communications inventory: landing pages, app-store copy, influencer scripts, referral programmes, onboarding screens, risk acknowledgements, campaign emails, transaction confirmations and support templates. For each item, identify the intended customer, the service actually authorised, the responsible approver, the legal/risk review date and the event that requires it to be withdrawn or revised.

Claim or feature Risk to test Control before release
‘Secure custody’ statement Could overstate protection or ownership model Evidence of actual custody, segregation, access and recovery controls
Yield, rewards or token promotion Could alter product, conduct or marketing analysis Current legal scope and approved risk wording
Instant transfer promise May conflict with screening or exception handling Transaction-monitoring and hold/escalation workflow
Global availability May ignore country, sanctions or customer restrictions Country gating and onboarding controls

This claim-to-control matrix is the page’s information gain asset. It exposes a common failure: a product team writes an attractive promise before the legal entity, licence position and control environment can substantiate it. The matrix forces the business to either prove the promise, narrow it or defer it.

Build a risk-led launch register rather than a licence checklist

A DPT launch should be split into independently verified gates: correct entity and ownership records; confirmed regulatory perimeter and MAS route; applicant-ready governance and financial plan; tested AML/CFT and sanctions controls; customer-asset or wallet controls where relevant; outsourced-provider oversight; approved public communication; and controlled operational release. A completed company filing or submitted application is only one gate.

For each gate, record the exact evidence, owner, reviewer, condition, expiry/review date and escalation path. A simple red/amber/green status without supporting records is not enough for a high-risk DPT product because the product and control model can change quickly. Treat every material product, token, jurisdiction, investor, liquidity, custody or group-control change as a re-opening of the relevant gates.

Launch gate Minimum evidence Example stop trigger
Regulatory scope Product and token-function map; MAS route analysis New activity is added without assessment
AML/CFT Risk assessment, screening and escalation testing Monitoring cannot identify or investigate an abnormal flow
Customer assets Key, wallet, reconciliation and recovery controls No proven owner for a loss or access incident
Public communications Approved claims, target audience and risk wording Campaign promises a feature outside the live control scope

This structure also makes timing more honest. Company formation, MAS review, banking, vendor onboarding, system testing and document completion have different dependencies. A responsible plan specifies them rather than promising a single date for a regulated DPT service to be ‘ready’.

Budget, timing and licence-status verification need independent checks

A DPT project budget should distinguish official MAS application and annual charges from company formation, legal analysis, AML/CFT implementation, blockchain analytics, KYC/sanctions tools, wallet or custody technology, security testing, incident response, insurance, staff, audit/accounting, banks, liquidity and outsourced-provider costs. A low incorporation quotation cannot be used as a total cost estimate for a business that expects to control or facilitate customer token activity.

There is no responsible single approval timetable. The entity filing, MAS assessment, completion of ownership evidence, technology and AML/CFT build, provider contracts, bank/ramp onboarding and public-communications review have different blockers. A launch plan should identify the dependency for every date and state what feature will remain disabled if that dependency is not complete.

Before relying on a counterparty’s claimed DPT status, check the MAS Financial Institutions Directory and the counterparty’s official contact details. The directory itself warns about impersonation and notes that an institution can hold multiple licences. Verification of another firm’s licence does not establish your own eligibility, but it can prevent a commercial or customer-protection decision from being based on an unverified claim.

For the applicant’s own status, keep a board-approved record that distinguishes incorporation, application submitted, requests for information, formal licence status, activated services and customer release. This avoids overstating the company’s position to investors, vendors or the public while work remains outstanding.

Launch a DPT service only when the regulated activity and recovery controls are both clear

The right DPT route begins with the real product and value flow, builds a transparent entity and ownership structure, tests the current MAS licensing and AML/CFT framework, and proves the critical customer-asset, technology and outsourcing controls before public launch. A licence application should be the output of that work, not a substitute for it.

Stop and reassess when a new token, wallet model, payment rail, liquidity provider, target country, customer segment, marketing promise or group-control arrangement changes the risk profile. The same change can affect the licence scope, customer disclosures, AML/CFT controls and incident-recovery plan.

The final board-level test is whether a director can explain a failed or suspicious customer transaction from detection through restriction, investigation, communications, records and recovery. If the answer is ‘the vendor handles it’, the business has not yet demonstrated full control of the DPT service it proposes to offer.

Create a defensible DPT launch plan

Sequence the entity, MAS, AML/CFT, technology and customer-communication workstreams around verifiable launch gates.

Frequently asked questions

Is every crypto-related company a DPT service provider?

No. The legal result depends on the actual functions performed, such as control, transfer, exchange, custody-like activity, customer relationship and value flow. A technology label alone does not decide the PS Act analysis.

Does a DPT licence application allow a product to launch while review is pending?

A submitted application is not the same as an approved or otherwise valid regulatory position. The business should not offer a live regulated service merely because it has incorporated or filed documents.

Can wallet or key management be fully outsourced?

A provider can perform critical functions, but the Singapore applicant must retain oversight, access to information, failure escalation and a credible recovery model for the service it offers.

What is MAS Notice PSN02 relevant to?

PSN02 is MAS’s AML/CFT notice for DPT service. It should be applied to the provider’s actual customer, transaction, token and risk profile, together with current MAS guidance.

When should public DPT marketing be reviewed again?

Review it whenever the service, token, custody model, returns/rewards claim, customer group, country, risk wording or control model changes. Marketing should not get ahead of the live regulated scope.

On this page
Chat with an Expert