Key Takeaways
Monetary Authority of Singapore Tightens Policy

- All Singapore PSPs must now submit annual audit reports to MAS within six months of their financial year-end
- External auditors must immediately report serious breaches, not wait for annual submissions
- New licensees face mandatory end-to-end reviews of AML/CFT controls one year after launch
Singapore's Monetary Authority (MAS) has released new audit guidelines for payment service providers, requiring licensed firms to submit annual Independent Assurance Reports and flag serious breaches immediately. The rules, outlined in PS-G04, apply to all holders of a payment service licence under the Payment Services Act 2019.
The move targets a payments sector that processed S$77 billion in retail e-payments in 2023 and has grown roughly 30% year-over-year. With over 1,200 payment service licensees operating in Singapore, MAS is standardizing how external auditors examine risk management, regulatory compliance, and customer fund safeguards.
What the PS-G04 guidelines require
PSPs must appoint a qualified external auditor each year and submit a complete audit package to MAS within six months after their financial year-end. That package includes audited financial statements, an Independent Assurance Report prepared under Singapore Standard on Assurance Engagements (SSAE) 3000 (Revised), and any findings on regulatory compliance and risk controls.
MAS explicitly prohibits splitting audit work across multiple firms. One auditor handles everything: accounts, the Independent Assurance Report, and all observations. The regulator will use these findings to assess whether a PSP has proactively identified and fixed control gaps.
Auditors must also produce a management letter covering the licensee's accounts, transactions, systems, controls, policies, and procedures. This goes beyond the formal report and gives MAS a fuller picture of operational health.
Immediate breach reporting now mandatory
The guidelines create a dual reporting obligation. External auditors cannot wait for the annual Form 4 submission to flag serious problems. They must report immediately when customer funds are not properly segregated, base capital falls below minimums, regulated activities run without a licence, or leadership changes occur without MAS approval.
PSPs carry the same obligation. If a firm discovers a serious breach or systemic weakness, it must notify MAS directly, even if the auditor has already reported the issue. Failing to do so invites supervisory action.
This creates real teeth. A PSP that spots a problem and stays quiet, hoping the auditor will handle disclosure, now faces explicit regulatory risk.
Minimum audit coverage areas
MAS expects audits to scale with a PSP's risk profile and complexity, but sets a floor. Every annual audit must cover money laundering and terrorism financing risks, potential loss of customer funds, and technology vulnerabilities. Mandatory review areas include safeguarding customer funds and assets, regulatory reporting accuracy, base capital compliance, exempted products, and remediation of prior audit findings.
PSPs must hand auditors substantial background material: business models, customer profiles, licensed and exempted services, licensing conditions, regulatory breaches, outstanding control deficiencies, and enterprise-wide risk assessments.
New licensees face stricter first-year reviews
Firms that just received a licence, or existing PSPs that begin offering newly licensed payment services, face additional scrutiny. MAS expects auditors to perform an end-to-end review one year after operations commence. That review focuses on anti-money laundering and countering the financing of terrorism (AML/CFT) controls and technology risk management.
The review must assess both the adequacy of the PSP's risk management systems and their operating effectiveness. In other words, it's not enough to have policies on paper. Auditors must verify they work in practice.
Why this matters for regional fintech
Singapore has positioned itself as Southeast Asia's fintech hub. Global players like Stripe and Wise operate there alongside crypto exchanges and local digital wallets. The Payment Services Act 2019 created a unified licensing framework that attracted this concentration.
Stronger audit requirements raise the cost of doing business, but they also signal to regulators elsewhere that Singapore takes compliance seriously. For PSPs operating across multiple jurisdictions, meeting Singapore's standards may simplify conversations with other regulators.
The flip side: smaller PSPs with thin margins now face higher compliance costs. Auditing to SSAE 3000 standards is not cheap. Firms that previously treated compliance as a checkbox exercise will need to invest in internal controls or risk negative audit findings that trigger MAS scrutiny.
Logicity's Take
MAS is betting that standardized, rigorous audits will catch problems before they become headlines. For fintech finance teams, the immediate task is ensuring your external auditor understands the full scope of PS-G04 and can deliver a single unified report. If your current audit relationship involves multiple firms or informal processes, start conversations now. Compliance teams may also want to evaluate audit management tools; platforms like [Airtable](https://logicity.in/r/airtable), [ClickUp](https://logicity.in/r/clickup), or [Notion](https://logicity.in/r/notion) can help track remediation items and evidence collection, though dedicated GRC software may be warranted for larger operations.
Disclosure
Some links in this post are affiliate links — Logicity earns a commission if you sign up, at no extra cost to you. We only link products we have used or actively recommend.
Frequently Asked Questions
Which firms do the MAS PS-G04 guidelines apply to?
All holders of a payment service licence under Singapore's Payment Services Act 2019, including money-changing licensees.
How long do PSPs have to submit their annual audit report?
Six months after the end of their financial year.
Can a PSP use multiple auditors for different parts of the annual audit?
No. MAS requires one auditor to handle the accounts, Independent Assurance Report, and all findings.
What breaches must be reported immediately under PS-G04?
Customer funds not properly segregated, base capital below minimums, unlicensed regulated activities, and unapproved changes to controllers, board members, or CEOs.
Are newly licensed PSPs subject to additional audit requirements?
Yes. Auditors must perform an end-to-end review of AML/CFT controls and tech risk management one year after the PSP begins operations.
Context on the scale of fintech investment flowing into regulated markets
How emerging payment infrastructure intersects with regulatory requirements
Need Help Implementing This?
If your PSP needs to restructure its audit process or build internal controls to meet PS-G04 requirements, reach out to Logicity's fintech compliance network. We connect teams with experienced regulatory consultants and audit specialists.
Source: Crowdfund Insider
Huma Shazia
Senior AI & Tech Writer
Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.






