← Regulations / Singapore / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Singapore

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Singapore with a local entity, subject to AML obligations and high licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
High
Last updated
2026-07-13

AML Obligations

  • DPT service providers must comply with MAS AML/CFT Notices PSN01 and PSN02 (amendments effective July 2025)
  • Customer due diligence (CDD) at onboarding and ongoing transaction monitoring required under PSN01/PSN02
  • Suspicious transaction reporting (STR) to MAS and Commercial Affairs Department
  • Travel Rule compliance for DPT transfers (receiving/sending DPTs)
  • The white-label SaaS provider (as the licensed DPT service provider) bears primary AML/CFT responsibility, though client obligations may be contractually allocated
  • No specific transaction thresholds stated in cited facts; standard MAS CDD thresholds likely apply (SGD 5,000 for occasional transactions under PSN01)

Key Restrictions

  • Must hold a Major Payment Institution (MPI) license with SGD 250,000 base capital (~$185K USD), or an SPI license with SGD 100,000 base capital (subject to SGD 3M single/SGD 6M aggregate monthly transaction limits)
  • Must have a Singapore-incorporated entity and resident presence
  • Customer assets must be held in a statutory trust (mandatory since 2024) — segregation is mandatory
  • Security deposits of SGD 100K–200K are required
  • Two-year track record for major roles (CEO, directors) is typically required
  • Marketing to the general public for crypto services is prohibited (MAS guidelines Jan 2022) — no incentive programs, no ATMs in public areas
  • If the wallet holds security tokens (SFA-covered assets), a separate Capital Markets Services (CMS) license for custodial services may be required under the Securities and Futures Act
  • MAS Technology Risk Management Guidelines (2021) apply — cybersecurity, data protection, operational resilience requirements

Key Risks

  • Very low approval rate for MPI licenses (only ~20-30 out of 170+ applications granted) — high regulatory gatekeeping risk
  • Regulatory ambiguity between PSA (DPT services) and SFA (custody of security tokens) — if underlying assets are security tokens, dual licensing may be required
  • MAS actively discourages retail crypto speculation; enforcement risk for perceived retail-facing marketing
  • No explicit proof-of-reserves or insurance requirements cited in the facts, but expectation management around asset safeguarding is high
  • White-label SaaS model creates ambiguity: the SaaS provider is the licensed entity bearing full AML/CFT liability, but may have limited control over the white-label client's end-user KYC/AML practices

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

licensing 40% confidence

MAS — All DPT service regulation, PSA licensing, AML/CFT, stablecoin framework, TRM guidelines

licensing 40% confidence

Payment Services Act 2019 (2019) — DPT service licensing — MPI/SPI licenses

licensing 40% confidence

Securities and Futures Act (2001) — Security tokens, CMS licensing

licensing 90% confidence

MAS AML/CFT Notices (PSN01, PSN02) — AML/CFT requirements for DPT service providers; amendments effective July 2025

licensing 80% confidence

MAS Technology Risk Management Guidelines (2021) — Cybersecurity, data protection, operational resilience

licensing 80% confidence

VASP: Major Payment Institution (MPI) license for DPT services. SGD 250,000 base capital (~$185K USD). 170+ applications received, only ~20-30 full MPI licenses granted. SPI option: SGD 100,000 base capital with transaction limits (SGD 3M single/SGD 6M aggregate). Must have Singapore entity, resident director, local compliance officer, physical office.

licensing 80% confidence

CUSTODY: Included under DPT MPI license. Customer asset segregation mandatory (statutory trust since 2024). Security deposits (SGD 100K-200K) required.

licensing 20% confidence

This is the cornerstone legislation for cryptocurrency regulation in Singapore. It regulates entities that provide services related to "Digital Payment Tokens" (DPTs), which is MAS's term for cryptocurrencies like Bitcoin and Ethereum.

licensing 20% confidence

Dealing in DPTs (e.g., buying and selling on behalf of customers).

licensing 20% confidence

Facilitating the exchange of DPTs (e.g., operating a DPT exchange).

licensing 20% confidence

Receiving or sending DPTs (e.g., cross-border DPT transfers).

licensing 20% confidence

This act applies to digital tokens that qualify as "capital markets products" (i.e., security tokens). If a digital token represents an equity, a debt instrument, a collective investment scheme, or a derivative, it falls under the SFA.

licensing 20% confidence

Providing custodial services for security tokens.

licensing 20% confidence

MAS AML/CFT Notices (e.g., PSN01, PSN02 for Payment Services):

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet / SaaS operators can serve Singapore residents under an MPI license (with SGD 250K capital, mandatory segregated statutory trust for customer assets, SGD 100K–200K security deposit, and full AML/CFT compliance under MAS Notices PSN01/PSN02), but the operator must be a Singapore-incorporated entity, faces a very low license approval rate, and must avoid marketing to the general public; if custody involves security tokens, additional CMS licensing under the SFA may apply.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?