A practical breakdown of Singapore's crypto regulatory framework — PSA licences, the DTSP regime, stablecoin rules, AML/CFT obligations, and what MAS expects from founders in 2026.

Singapore is among the strongest options on most shortlists for crypto founders seeking a well-recognised, institutionally credible licence. The Monetary Authority of Singapore (MAS) has spent years building a framework that is detailed, consistent, and enforced — which is precisely why operating in or from Singapore without understanding that framework creates serious legal risk.

The rules have changed substantially since the Payment Services Act (PSA) first came into force in 2019. Two rounds of PSA amendments, the FSMA Part 9 DTSP regime from 30 June 2025, and the September 2026 consultation on stablecoin legislation have widened the perimeter. What once applied only to domestic crypto services now covers Singapore-based businesses serving clients anywhere in the world. What once applied only to domestic crypto services now covers Singapore-based businesses serving clients anywhere in the world.

This article breaks down every layer of Singapore’s crypto regulatory framework that founders, legal counsel, and compliance officers need to understand in 2026 — from token classification and licence selection through AML obligations, consumer protection rules, and what MAS has signalled is coming next.

Regulatory Reference Guide

Singapore Crypto Regulation
Every Rule Founders Must Know

PSA licences • DTSP regime • Stablecoin rules • AML/CFT obligations • What MAS expects

MAS Regulates Activities, Not Companies.
Start with Your Token Type.

DPT

Digital Payment Token

Value not pegged to fiat. BTC, ETH are clearest examples.

Governed by PSA
E-Money

Stablecoin / E-Money

Pegged to fiat (SGD or G10). USDT-type tokens fall here.

PSA + SCS Framework
Security

Security Token

Equity, profit-sharing, or title to a real-world asset.

Governed by SFA

Misclassification is not a paperwork error. Treating a security token as a DPT constitutes an unlicensed business activity under Singapore law.


Three Licensing Frameworks.
Which Track Is Your Business On?

PSA
SPI or MPI Licence

DPT services to customers in Singapore — exchanges, OTC desks, custody, buying & selling crypto.

FSMA Part 9
DTSP Licence

Singapore-based entities serving only overseas clients. In force from 30 June 2025.

SFA
CMS Licence

Dealing in or advising on security tokens. Independent of PSA — a DPT licence does not cover this.

If your platform deals with more than one token type, more than one regime may apply simultaneously.


SPI vs MPI: Choosing the Right Tier

Key Thresholds at a Glance
Standard PISPI
Monthly DPT Volume
Up to:
– SGD 3M (per service)
– SGD 6M (all services)
Min. Base Capital
SGD 100,000
Customer Fund Safeguarding
Not Required
Security Deposit
Not Required
Annual Licence Fee
SGD 5,000
Major PIMPI
Monthly DPT Volume
Exceeds:
– SGD 3M (per service)
– SGD 6M (all services)
Min. Base Capital
SGD 250,000
Customer Fund Safeguarding
Mandatory
Minimum Security Deposit
SGD 100,000 – 200,000
Annual Licence Fee
SGD 5,000

Both tiers carry the same AML obligations under MAS Notice PSN02. The SPI does not offer a lighter compliance burden. Typical MAS review is 6–12 months after a complete filing. End-to-end, from preparation to licence, is usually 9–12 months.


The Rule That Closed the Loophole

FSMA Part 9 — DTSP Licence

From 30 June 2025, any Singapore-incorporated entity providing digital token services solely to overseas clients must hold a DTSP licence. Serving only foreign customers no longer keeps a Singapore business outside the regulatory perimeter.

Penalty: Up to SGD 250,000 and/or 3 years’ imprisonment

MAS Single-Currency Stablecoin (SCS) Requirements

To earn “MAS-Regulated Stablecoin” status, issuers must meet:
💰
Reserve Assets

100% par value maintained, monthly independent checks, annual audits. Segregated from issuer funds.

🏢
Min. Capital

SGD 1 million or 50% of annual operating expenses — whichever is higher.

Redemption

Holders redeem at par value within 5 business days.

📋
Disclosure

Whitepaper covering stabilisation mechanism, holder rights, and reserve audit results.

📄
Licence Required

Must hold a Major Payment Institution (MPI) licence.


MAS Notice PSN02 — Core Obligations for All DPT Providers

CDD
Customer Due Diligence

Mandatory for all customers. Enhanced CDD in higher-risk cases. Ongoing monitoring required.

STR
Suspicious Tx Reporting

File STRs with the Suspicious Transaction Reporting Office (STRO).

5 YRS
Record Retention

All CDD docs and transaction records retained for a minimum of five years.

RBA
Risk-Based Approach

Written ML/TF risk assessment reflecting the specific risks of your business model.

FATF Travel Rule

Collect, verify & transmit originator and beneficiary info for all DPT transfers above SGD 1,500. For transfers below threshold, ordering VASP must still submit info to beneficiary VASP. A generic or template-based AML programme is one of the most common reasons MAS raises multiple query rounds.


Key Retail Customer Obligations

  • Asset Segregation: Customer assets held under statutory trust, separated from provider funds.

  • Lending & Staking Restrictions: Prohibited for retail customers. Available to institutional & accredited investors only.

  • Risk Awareness Assessment: Retail investors must pass a mandatory assessment before trading on licensed platforms.

  • Risk Disclosures: Clear disclosures on risks of holding digital assets, including insolvency risk.

  • Conflict of Interest Controls: Updated MAS guidelines (effective June 2025) introduced expanded COI measures for all retail-facing DPT providers.


Four Key Developments on the Horizon

📜
Stablecoin Legislation

Consultation P015-2026 (1 September 2026) sets out the draft PS Act amendments for the SCS Framework, including a proposed ban on interest or yield on MAS-regulated stablecoins and limited recognition of certain foreign-issued tokens.

🏭
Tokenised Bills Pilot

Trial of tokenised MAS bills settled via wholesale CBDC — shifting from experimentation to real-world deployment of tokenised financial infrastructure.

📊
OECD CARF Adoption

Singapore expected to adopt CARF — requiring licensed exchanges to report cross-border crypto holdings to tax authorities.

🔒
Licensing Enforcement

MAS continues tightening oversight. The DTSP regime is in force and MAS has the tools to act against non-compliant operators.

★  5 Key Takeaways for Founders
  • Token classification determines everything. MAS assesses what a token does, not what it is called. Misclassification = unlicensed activity.
  • The DTSP loophole is closed. Singapore-incorporated businesses serving only overseas clients have needed a FSMA Part 9 licence since 30 June 2025.
  • AML is not optional. MAS Notice PSN02 applies to all DPT providers regardless of licence tier — there is no reduced standard for smaller operators.
  • Licence for where you are going. Crossing volume thresholds without upgrading from SPI to MPI is a compliance breach. Plan for scale from day one.
  • Compliance is a design decision. Founders who build substance, AML programmes, and controls before applying move through the MAS process significantly faster.

How MAS Classifies Crypto Activities

Singapore does not issue a generic “crypto licence.” MAS regulates activities, not companies, and the applicable legal framework depends on the nature of the token and the service being provided.

Token classification determines everything — which statute applies, which licence is required, and what ongoing obligations attach. MAS does not look at what a token is called. It assesses the token’s features and the rights it confers on holders.

The three primary token categories under Singapore law are:

  • Digital Payment Token (DPT): A digital representation of value not pegged to any fiat currency — Bitcoin and Ether are the clearest examples. DPT services are regulated under the PSA.
  • E-Money / Stablecoin: A digital token pegged to a fiat currency. Most stablecoins (e.g., USDT) fall here. Tokens pegged to the Singapore dollar or a G10 currency may qualify as MAS-regulated stablecoins under specific reserve conditions.
  • Security Token: A digital representation of ownership rights such as equity, profit sharing, or title to a real-world asset. These are treated as capital markets products and regulated under the Securities and Futures Act (SFA).

If your platform deals with more than one token category, more than one regulatory regime may apply simultaneously. Misclassifying a token — treating a security token as a DPT, for example — is not a paperwork error. It is an unlicensed business activity.

The Three Licensing Tracks

In 2026, a Singapore-based crypto business will generally fall under one of three licensing frameworks depending on what it does and who it serves.

Payment Services Act (PSA) — SPI or MPI licence: Applies to any business providing DPT services to customers in Singapore. This covers exchanges, OTC desks, custody services, and platforms facilitating the buying, selling, or exchange of crypto assets for Singapore-based clients.

Financial Services and Markets Act (FSMA) Part 9 — DTSP licence: Applies from 30 June 2025 to Singapore-incorporated entities or individuals operating from Singapore who provide digital token services exclusively to customers outside Singapore. This regime closed a long-standing loophole that allowed Singapore-based operators to serve only offshore clients without a licence.

Securities and Futures Act (SFA): Applies where a token constitutes a capital markets product. Dealing in or advising on security tokens requires a Capital Markets Services (CMS) licence. The SFA operates independently of the PSA and FSMA, and a DPT service licence does not cover security token activities.

The practical starting point for any founder is: who are your customers and what are you doing for them? The answer to those two questions determines which track — or combination of tracks — your business sits on. Our team regularly works with founders at this exact stage through our Jurisdiction Advisory service to map activities to the right framework before any application begins.

SPI vs MPI: Choosing the Right Licence Tier

Within the PSA framework, crypto businesses providing DPT services must hold either a Standard Payment Institution (SPI) or Major Payment Institution (MPI) licence. The threshold that determines which tier applies is transaction volume.

Feature Standard Payment Institution (SPI) Major Payment Institution (MPI)
Monthly DPT transaction volume Up to SGD 3 million (single service) Exceeds SGD 3 million
Average daily float Up to SGD 5 million Exceeds SGD 5 million
Minimum base capital SGD 100,000 SGD 250,000
Customer fund safeguarding Not required Mandatory
Technology risk guidelines Basic Full MAS TRM Guidelines
Annual licence fee SGD 5,000 SGD 5,000
Security deposit Not required At least SGD 100,000

Both licence tiers require company registration with ACRA, a permanent place of business in Singapore, at least one executive director who is a Singapore citizen or Permanent Resident, or one executive director on an Employment Pass plus one other director who is a Singapore citizen or Permanent Resident. The executive director is expected to be resident in Singapore.

AML/CFT controls need to be in line with MAS requirements. Both are also subject to the same AML obligations under MAS Notice PSN02 — the SPI does not offer a lighter compliance burden in that regard.

The choice between SPI and MPI is not purely about current transaction volumes. MAS expects applicants to licence for where their business is going, not just where it is today. A business that launches as an SPI but crosses the volume threshold without upgrading its licence is in breach. Most institutional or exchange-model businesses targeting any meaningful scale will require an MPI from the outset.

MAS review typically takes 6–12 months from a complete submission. Preparation before filing usually adds 2–3 months. Crypto and DPT files can run longer if MAS issues multiple query rounds. Our Crypto & VASP Licensing practice covers SPI and MPI applications end to end, including application preparation, AML programme design, and post-approval compliance support.

The DTSP Regime: The Rule That Closed the Loophole

Before June 2025, a common structuring approach was to incorporate in Singapore while directing all commercial activity at overseas clients — on the basis that serving only foreign customers kept the business outside the PSA’s scope. That approach no longer works.

From 30 June 2025, any individual, partnership, or Singapore-incorporated company providing digital token services solely to clients outside Singapore must hold a DTSP licence under Part 9 of the FSMA. This applies to services relating to Digital Payment Tokens and tokens that are capital markets products. Operating without the required DTSP licence carries penalties of up to SGD 250,000 and/or three years’ imprisonment.

The DTSP regime does not replace the PSA for businesses serving Singapore customers — it sits alongside it. If your business serves both Singapore-based and overseas clients, the PSA licence (SPI or MPI) covers both directions of service. The DTSP licence is specifically for businesses whose client base is entirely offshore.

MAS has made clear that it will not issue DTSP licences freely. The bar is high, and the regulator has signalled it will generally not license businesses that present elevated risk without demonstrable substance in Singapore. This reinforces that the DTSP regime is not a light-touch alternative to the PSA — it reflects the same regulatory expectations, applied to a different service scope.

Stablecoin Regulation in Singapore

Singapore’s approach to stablecoins operates on two levels. Under the PSA, all stablecoins are currently treated as DPTs for non-issuance activities — meaning exchanges, custodians, and transfer services dealing in stablecoins require the same SPI or MPI licence as any other DPT service provider.

For issuers, MAS finalised a dedicated Single-Currency Stablecoin (SCS) Framework in August 2023. The framework applies specifically to stablecoins pegged to the Singapore dollar or any G10 currency that are issued in Singapore. Stablecoins pegged to non-G10 currencies or multi-currency baskets fall outside this framework and remain governed as standard DPTs.

To be recognised and labelled as an “MAS-regulated stablecoin,” issuers must meet the following requirements:

  • Reserve assets: Maintained at 100% of the par value of outstanding coins in circulation, with monthly independent checks and annual audits. Assets must be segregated from the issuer’s own funds.
  • Capital: Minimum base capital of SGD 1 million, or 50% of annual operating expenses, whichever is higher.
  • Redemption: Holders must be able to redeem stablecoins at par value within five business days.
  • Disclosure: A whitepaper covering the value-stabilising mechanism, holder rights, and reserve audit results.
  • Licence: Issuers must hold a Major Payment Institution (MPI) licence.

On 1 September 2026, MAS published consultation P015-2026 on Payment Services Act amendments to give the SCS Framework statutory force. The consultation closes on 16 October 2026. No commencement date has been announced.

The BLOOM initiative, launched in October 2025, supports trials with tokenised bank liabilities and regulated stablecoins for settlement. Founders planning stablecoin issuance should treat the SCS Framework as the operative standard now, and monitor for legislative updates through 2026.

Any issuer or entity that misrepresents a token as an “MAS-regulated stablecoin” without meeting the requirements may face financial penalties or imprisonment, and will be placed on MAS’s Investor Alert List.

AML/CFT Obligations and the Travel Rule

AML/CFT compliance is not an optional component of a Singapore crypto licence — it is the primary lens through which MAS evaluates applications and monitors ongoing operations. MAS Notice PSN02 establishes the AML/CFT requirements that apply to all DPT service providers, regardless of whether they hold an SPI or MPI licence.

The core obligations under Notice PSN02 include:

  • Customer Due Diligence (CDD): Mandatory for all customers, with enhanced CDD in higher-risk cases. This includes collecting and verifying identity information, understanding the nature and purpose of the business relationship, and performing ongoing monitoring.
  • Suspicious Transaction Reporting: Licensed DPT providers must file Suspicious Transaction Reports (STRs) with the Suspicious Transaction Reporting Office (STRO).
  • Record Retention: All CDD documentation and transaction records must be retained for a minimum of five years.
  • Risk-Based Approach: Providers must assess jurisdictional and counterparty risk and apply proportionate controls. MAS expects a written ML/TF risk assessment that reflects the specific risks of the business model.

Singapore implemented the FATF Travel Rule through MAS Notice PSN02, requiring DPT service providers to collect, verify, and transmit originator and beneficiary information for all DPT transfers above SGD 1,500. For transfers below this threshold, the ordering VASP must still submit originator and beneficiary information to the beneficiary VASP. Originator information includes the customer’s full legal name, account number or wallet address, and physical address or national identification number.

MAS has acknowledged a practical challenge — the “sunrise issue” — where counterparty VASPs in other jurisdictions may not yet be Travel Rule compliant. MAS has issued guidance permitting a risk-based approach during the transition period, but this does not exempt Singapore-licensed providers from their own obligations. A thin or template-based AML programme is one of the most common reasons MAS raises multiple rounds of queries during the application process. Our AML & Compliance practice assists clients in building programmes that meet MAS’s expectations from day one.

Consumer Protection Rules for Retail Customers

Singapore draws a clear distinction between retail customers and accredited investors in how DPT service providers may conduct business. Greater obligations apply when the counterparty is a retail customer, reflecting MAS’s view that retail participants have less access to professional advice and fewer resources to absorb losses.

The key consumer protection obligations for DPT service providers dealing with retail customers include:

  • Asset segregation: Customer assets must be held under a statutory trust, separated from the provider’s own assets. This is mandatory and applies to both DPT tokens and customer fiat holdings.
  • Lending and staking restrictions: DPT service providers are prohibited from facilitating lending or staking of DPT tokens on behalf of retail customers. These services may continue to be offered to institutional and accredited investors.
  • Risk disclosures: Providers must give clear disclosures to retail customers on the risks of holding digital assets with the provider, including insolvency risk.
  • Risk Awareness Assessment: Retail investors must pass a mandatory Risk Awareness Assessment before trading cryptocurrencies on licensed platforms.
  • Conflict of interest controls: Updated MAS guidelines effective June 2025 introduced expanded conflict of interest measures and additional business conduct requirements that apply to all retail-facing DPT service providers.

The accredited investor (AI) opt-in regime allows eligible customers — individuals with net personal assets exceeding SGD 2 million, among other qualifying criteria — to consent to be treated as accredited investors, which removes certain retail-level protections in exchange for access to a broader range of services. The AI opt-in process has specific procedural requirements and was updated in June 2025. Providers that handle the opt-in process incorrectly expose themselves to regulatory risk even where the underlying customer genuinely qualifies.

What to Expect in 2026

Singapore’s regulatory posture in 2026 is best described as consolidation and formalisation. The broad framework is in place. What is happening now is the legislative and operational filling-in of remaining gaps.

The key developments to monitor in 2026 are:

  • Stablecoin legislation: MAS confirmed at the Singapore FinTech Festival in November 2025 that draft legislation for stablecoins will be published in 2026. The legislation is expected to give formal statutory effect to the existing SCS Framework, potentially with additional requirements where stablecoins become systemically significant.
  • Tokenised government bills pilot: Singapore will trial tokenised MAS bills settled via wholesale central bank digital currency (CBDC) in 2026, building on successful interbank lending trials in 2025 involving DBS, OCBC, and UOB. This is the shift from experimentation to real-world deployment of tokenised financial infrastructure.
  • OECD Crypto-Asset Reporting Framework (CARF): Singapore is expected to adopt CARF, which will require licensed exchanges to report cross-border crypto holdings to tax authorities. This has direct implications for client onboarding, data collection, and reporting infrastructure.
  • Continued licensing enforcement: MAS has signalled it will continue tightening oversight of businesses operating without appropriate licences. The DTSP regime is now in force and MAS has tools to act against non-compliant operators.

None of these developments reduce the regulatory burden for crypto businesses in Singapore. They extend and formalise it. Founders who engage with the framework early — and build compliance infrastructure before it is demanded — will be better positioned than those who treat regulation as a final-stage concern.

Practical Considerations Before You Apply

A Singapore MAS licence carries genuine institutional weight. It is recognised by banks, institutional counterparties, and regulators across Asia, the Gulf, and Europe in a way that lighter-touch licences from offshore jurisdictions are not. That recognition comes at a cost — the framework is demanding, and MAS’s approval process is thorough.

Several factors consistently determine whether an application proceeds smoothly or stalls:

  • Corporate substance: MAS expects a real presence in Singapore. A registered address and nominee directors are not sufficient. At least one executive director must be a Singapore citizen or Permanent Resident, and there must be a physical place of business.
  • Compliance officer quality: The compliance officer must have relevant Singapore experience. A compliance officer without familiarity with MAS’s expectations is one of the most common reasons applications attract extended scrutiny.
  • AML programme depth: A thin ML/TF risk assessment — particularly one that does not reflect the specific risks of the applicant’s business model — is routinely flagged by MAS. Generic templates do not pass.
  • Technology risk controls: MPI applicants must demonstrate controls that meet MAS’s Technology Risk Management (TRM) Guidelines. Understating technology risk controls is a common application failure point.
  • No pre-licence marketing: Marketing or onboarding customers before approval is a serious compliance breach. The licence must be in hand before any regulated activity begins.

Founders who are evaluating Singapore alongside other jurisdictions should also consider that the MAS licence does not substitute for licences in other markets. It does not provide passporting rights into the EU under MiCA, and it does not replace a VASP registration or CASP licence for businesses targeting European customers. If your market is global, jurisdiction selection is a multi-licence conversation, not a single-jurisdiction decision.

For businesses at the assessment stage, our Jurisdiction Advisory service provides a structured comparison across Singapore, UAE (VARA/ADGM), Hong Kong, Lithuania, and other active crypto licensing jurisdictions. For those who have already decided on Singapore, our Crypto & VASP Licensing team handles the full application process — from ACRA incorporation and AML programme design through MAS submission, banking setup via our Banking & EMI / PSP service, and long-term compliance support via AML & Compliance.

Singapore’s crypto regulatory framework in 2026 is comprehensive, consistently enforced, and actively expanding. The PSA governs domestic DPT services. The FSMA DTSP regime now captures businesses serving overseas clients from Singapore. Stablecoin issuers face specific reserve, capital, redemption and disclosure requirements under the SCS Framework. The statutory pathway is now under consultation, not yet in force. And AML/CFT obligations under MAS Notice PSN02 apply across the board, with no reduced standard for smaller operators.

The framework rewards founders who treat compliance as a design decision rather than a late-stage concern. Businesses that enter the MAS process with complete corporate substance, a credible AML programme, and a compliance infrastructure that matches their business model move through the process significantly faster than those who build these elements under pressure.

Understanding the rules is the starting point. Applying them correctly to your specific business model, token type, and client base is where execution matters.

Talk to a Specialist

GSS Legal has assisted clients through MAS applications, DTSP licence assessments, stablecoin compliance reviews, and cross-jurisdiction licence strategies across Singapore, UAE, Hong Kong, and the EU. If you are evaluating Singapore or preparing an application, book a consultation to discuss your specific structure.

Book a Consultation

Chia sẻ