Custodial wallet / SaaS in Singapore
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Singapore with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- DPT service providers must comply with MAS AML/CFT Notices PSN01 and PSN02 (amendments effective July 2025)
- Customer due diligence (CDD) at onboarding and ongoing transaction monitoring required under PSN01/PSN02
- Suspicious transaction reporting (STR) to MAS and Commercial Affairs Department
- Travel Rule compliance for DPT transfers (receiving/sending DPTs)
- The white-label SaaS provider (as the licensed DPT service provider) bears primary AML/CFT responsibility, though client obligations may be contractually allocated
- No specific transaction thresholds stated in cited facts; standard MAS CDD thresholds likely apply (SGD 5,000 for occasional transactions under PSN01)
Key Restrictions
- Must hold a Major Payment Institution (MPI) license with SGD 250,000 base capital (~$185K USD), or an SPI license with SGD 100,000 base capital (subject to SGD 3M single/SGD 6M aggregate monthly transaction limits)
- Must have a Singapore-incorporated entity and resident presence
- Customer assets must be held in a statutory trust (mandatory since 2024) — segregation is mandatory
- Security deposits of SGD 100K–200K are required
- Two-year track record for major roles (CEO, directors) is typically required
- Marketing to the general public for crypto services is prohibited (MAS guidelines Jan 2022) — no incentive programs, no ATMs in public areas
- If the wallet holds security tokens (SFA-covered assets), a separate Capital Markets Services (CMS) license for custodial services may be required under the Securities and Futures Act
- MAS Technology Risk Management Guidelines (2021) apply — cybersecurity, data protection, operational resilience requirements
Key Risks
- Very low approval rate for MPI licenses (only ~20-30 out of 170+ applications granted) — high regulatory gatekeeping risk
- Regulatory ambiguity between PSA (DPT services) and SFA (custody of security tokens) — if underlying assets are security tokens, dual licensing may be required
- MAS actively discourages retail crypto speculation; enforcement risk for perceived retail-facing marketing
- No explicit proof-of-reserves or insurance requirements cited in the facts, but expectation management around asset safeguarding is high
- White-label SaaS model creates ambiguity: the SaaS provider is the licensed entity bearing full AML/CFT liability, but may have limited control over the white-label client's end-user KYC/AML practices
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
MAS — All DPT service regulation, PSA licensing, AML/CFT, stablecoin framework, TRM guidelines
Payment Services Act 2019 (2019) — DPT service licensing — MPI/SPI licenses
Securities and Futures Act (2001) — Security tokens, CMS licensing
MAS AML/CFT Notices (PSN01, PSN02) — AML/CFT requirements for DPT service providers; amendments effective July 2025
MAS Technology Risk Management Guidelines (2021) — Cybersecurity, data protection, operational resilience
VASP: Major Payment Institution (MPI) license for DPT services. SGD 250,000 base capital (~$185K USD). 170+ applications received, only ~20-30 full MPI licenses granted. SPI option: SGD 100,000 base capital with transaction limits (SGD 3M single/SGD 6M aggregate). Must have Singapore entity, resident director, local compliance officer, physical office.
CUSTODY: Included under DPT MPI license. Customer asset segregation mandatory (statutory trust since 2024). Security deposits (SGD 100K-200K) required.
This is the cornerstone legislation for cryptocurrency regulation in Singapore. It regulates entities that provide services related to "Digital Payment Tokens" (DPTs), which is MAS's term for cryptocurrencies like Bitcoin and Ethereum.
Dealing in DPTs (e.g., buying and selling on behalf of customers).
Facilitating the exchange of DPTs (e.g., operating a DPT exchange).
Receiving or sending DPTs (e.g., cross-border DPT transfers).
This act applies to digital tokens that qualify as "capital markets products" (i.e., security tokens). If a digital token represents an equity, a debt instrument, a collective investment scheme, or a derivative, it falls under the SFA.
Providing custodial services for security tokens.
MAS AML/CFT Notices (e.g., PSN01, PSN02 for Payment Services):
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — custodial wallet / SaaS operators can serve Singapore residents under an MPI license (with SGD 250K capital, mandatory segregated statutory trust for customer assets, SGD 100K–200K security deposit, and full AML/CFT compliance under MAS Notices PSN01/PSN02), but the operator must be a Singapore-incorporated entity, faces a very low license approval rate, and must avoid marketing to the general public; if custody involves security tokens, additional CMS licensing under the SFA may apply.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?