News

Back
MAS Publishes AML/CFT Supervisory Expectations for DPTSPs
July 20, 20268 min read

MAS Publishes AML/CFT Supervisory Expectations for DPTSPs

The Monetary Authority of Singapore (MAS) has published an Information Paper on AML/CFT Supervisory Expectations for Digital Payment Token Service Providers (DPTSPs or Virtual Assets Service Providers/VASPs), setting out its observations from recent inspections and its supervisory expectations for anti-money laundering, countering the financing of terrorism, and countering proliferation financing (AML/CFT/CPF) controls. The paper supplements existing requirements under MAS Notice PSN02 and its accompanying Guidelines, and DPTSPs are expected to benchmark themselves against it in a risk-based and proportionate manner. 

MAS organises its expectations across seven areas: (1) assessment of risks arising from new products, including the listing of new digital payment tokens (DPTs); (2) enhanced customer due diligence (ECDD) on higher-risk customers; (3) value transfer requirements, i.e. the Travel Rule; (4) ongoing monitoring; (5) screening; (6) due diligence on partners and outsourced AML/CFT service providers; and (7) training and staff expertise. Throughout, MAS is candid about the gaps its inspections uncovered, from thin documentation of new-product risk assessments to incomplete Travel Rule coverage, publishing 10 case studies that illustrate exactly where licensees fell short.

We focus below on the Travel Rule expectations, since this is where a DPTSP's choice of compliance infrastructure matters most, and where VerifyVASP has been building since its founding, and independently proving a solution designed to fully meet this bar.

The Travel Rule, and MAS' "Guiding Factors for Evaluation of a Travel Rule Solution"

MAS Notice PSN02 implements the FATF Travel Rule domestically: when a DPT value transfer is made between DPTSPs, the originating DPTSP must transmit originator and beneficiary information to the beneficiary DPTSP concurrently or simultaneously with the transfer, in a secure manner. MAS notes that, per the 2025 FATF Targeted Update on Virtual Assets, 73% of respondent jurisdictions (85 of 117, excluding those that prohibit or plan to prohibit VASPs) have now passed Travel Rule legislation — yet MAS is explicit that considerable implementation gaps remain globally, and that VAs and VASPs remain vulnerable to misuse.

Importantly, MAS sets out the Guiding Factors for Evaluation of Travel Rule Solution framework that DPTSPs must apply when selecting compliance infrastructure. A comprehensive evaluation should minimally consider:

●    Coverage — the DPT types and network of VASPs the solution covers;

●    Interoperability — how the solution interfaces with other Travel Rule tools, and its limitations in sending/receiving data to/from counterparty VASPs;

●    VASP due diligence measures — the rigour applied before a VASP is onboarded to the solution's network;

●    Counterparty VASP identification and due diligence — the robustness of entity verification and contact validation, both for network members and for counterparties outside the network. Among others, DPTSPs should not solely rely on the Travel Rule solution for the identification and verification of the counterparty/beneficiary VASP;

●    Immediate transmission of data — the solution's technical ability to transmit value transfer information simultaneously or concurrently with the transfer itself; and

●    Data security and protection — the safeguards protecting value transfer information from unauthorised disclosure.

MAS' case studies show what happens when these factors are treated as a checklist rather than an operating discipline (checkbox versus objective-based compliance). In one case (Case Study F), a DPTSP's Travel Rule solution covered only a small proportion of its actual value transfers, leaving the majority without originator/beneficiary information because the solution did not support the DPT in question or because the counterparty DPTSP sat outside its network. MAS also explicitly states that DPTSPs cannot outsource judgment of counterparty/beneficiary VASP identification entirely to their solution provider: they must independently confirm the beneficiary wallet owner, avoid sending Travel Rule data to unverified email addresses, and take their own risk mitigation measures when transacting with unhosted wallets or unregulated counterparties.

MAS footnotes that DPTSPs can also refer to the 2024 FATF's Targeted Update on Implementation of the FATF Standards on VAs and VASPs, which sets out guiding questions for evaluating Travel Rule solution providers. This is not a new or hypothetical exercise for VerifyVASP. We already answered these questions and had the answers independently audited.

Robust Adherence to the FATF Requirements

Back in 2023, when FATF first published this same category of guiding questions for Travel Rule solution providers (Box 2.2 of its Targeted Update), VerifyVASP took the position that any solution's response to these questions is only meaningful if it can be validated against real production traffic. So we answered every one of FATF's guiding questions and had our responses independently reviewed by a Big Four audit firm; the review found no inconsistencies between our production implementation and our stated answers.

To our knowledge, VerifyVASP remains the only Travel Rule solution to have had its FATF guiding-question responses assessed by an independent Big Four auditor, rather than simply asserted in a sales deck. As MAS now points Singapore's DPTSPs to this exact same framework of guiding questions when selecting a Travel Rule solution, that independent assurance is the best proof.

How Our Verified Network Architecture Maps to MAS' Six Guiding Factors

We set out our full architecture in What is a Verified Network. Here is a direct mapping against MAS' six factors:

Coverage. Our Verified Network is asset-agnostic and now supports 150+ member VASPs, including many of the world’s largest VASPs where majority of transactions are with, across 30+ jurisdictions, having processed over USD 550 billion in verified Travel Rule-compliant value as of June 2026, across more than 20 million verifications.

Interoperability. We have proven interoperably flows, representing about 16% of our Travel Rule traffic and will be expanding this through our acquisition of Sygna Inc, the dominant Travel Rule Solution in Japan. We are also architected for international data standards, a key building block for interoperability by basing our messages on IVMS101 and ISO20022. We are members of the ISO 20022 API Standards Evaluation Group, the Payments Standards Evaluation Group, and the Technical Support Group, contributing directly to the emerging global standard for Travel Rule data exchange rather than operating a closed silo.

VASP due diligence measures. Every member VASP is verified at the legal-entity level — not merely by service name or brand — through KYB processes modelled after FATF Recommendation 10 (Customer Due Diligence) for corporates, and a due diligence questionnaire adapted from the Wolfsberg Counterparty Due-Diligence Questionnaire for virtual assets, which is verified for factuality. This is the origin of our name: VerifyVASP verifies the VASP, not just the transactions.

Counterparty VASP identification and due diligence. The information profile, collated and verified at onboarding is then shared once permissions are obtained to counterparty VASPs requesting to conduct due diligence processes. We are also the only LEI Validation Agent for the virtual asset industry in partnership with the Global Legal Entity Identifier Foundation (GLEIF), offering members obtain unique legal entity identifiers for counterparty verification.

At the transactional level, beneficiary VASP, beneficiary, originating VASP and originator are each verified pre-transaction, immediately and securely with exact-match accuracy where both parties are Travel Rule-obliged; where a counterparty is higher-risk (unregulated or non-obliged), our architecture shifts to SHA hash-matching rather than exposing naked personal data, so DPTSPs are never forced to choose between connectivity and data protection.

Where a counterparty VASP is unregulated, unlicensed, or otherwise cannot be verified, MAS’ information paper calls for enhanced risk mitigation measures for such value transfers, and specifically cites permitting and verifying only first-party transfers as one such measure, a measure FATF also flags directly. Our VerifyName solution was purpose-built for exactly this scenario: it confirms, on an immediate and secure basis, that a declared beneficiary or originator name matches the counterparty’s own records for first-party transfers. This also risk-mitigates a data protection concern that is easy to overlook: where a counterparty VASP cannot be accessed or shown to adequately safeguard sensitive customer information, VerifyName avoids exposing that data to an unverifiable third party in the first place, rather than relying on the counterparty’s own controls after the fact and risking data loss. For self-hosted (unhosted) wallets, VerifyWallet provides the complementary control: it verifies that the customer genuinely controls the destination or source wallet through cryptographic signing, so DPTSPs can confidently limit these higher-risk transfers to a verified first-party only. 

Immediate transmission of data. Data is not merely "sent”, but verified in real time, with beneficiary verification averaging 0.168 seconds. Every verification generates an auto-generated Verification Statement, giving DPTSPs a transaction-level audit trail for internal and external audit — something MAS' case studies suggest is often missing when Travel Rule compliance is reduced to message delivery alone. 

Data security and protection. Personally identifiable information (PII) is encrypted end-to-end within a decentralised architecture and is never decrypted nor stored by VerifyVASP, even in encrypted form; local data residency is available where required. Our Privacy Policy suffices for Singapore’s PDPA compliance, but for GDPR context and jurisdictions considered in their adequacy list, a master data processing agreement may be required to ensure data protection obligations are extended to counterparty VASPs.

Tech Risk and Data Protection: Independently Assured

MAS' information paper sits alongside its Technology Risk Management (TRM) Guidelines, and the same logic that applies to DPTSPs applies to the vendors they rely on: a Travel Rule solution is typically a material service provider handling sensitive PII, and its own controls need to be independently assured. We addressed this directly by completing a SOC 2 Type II audit of the Verified Network, and by having our architecture separately audited against the FATF's own list of requirements for Travel Rule solutions.

We have now renewed our SOC 2 Type II assessment for a fourth consecutive year, most recently covering the period 1 February 2025 to 31 January 2026, evaluating the design and operating effectiveness of our controls against the AICPA Trust Services Criteria of security, availability, and processing integrity. This is precisely the kind of independent, ongoing assurance that MAS' TRM expectations are designed to elicit from material service providers — and we maintain a zero-incident record since our founding in 2019, across a period in which the wider Web3 industry has seen a steady drumbeat of high-profile hacks and data leaks.

Built for FATF, MAS and International Jurisdictions

MAS' information paper does not exist in isolation, it operationalises Singapore's implementation of the FATF Standards, and the value transfer requirements in MAS Notice PSN02 are Singapore's domestic expression of FATF Recommendation 16. Here is a summary of markers which demonstrate that VerifyVASP was built for FATF alignment from the outset, which is why we are able to meet MAS' expectations as a natural consequence rather than a retrofit:

●      Independent Big Four assessment of our responses to FATF's Travel Rule solution provider guiding questions (2023), referenced above.

●      SOC 2 Type II audit, renewed annually since our first assessment, now in its fourth consecutive year.

●      Only GLEIF-accredited LEI Validation Agent for the virtual asset industry, supporting unique legal entity identification in line with EU and UK Travel Rule requirements and FATF's emphasis on legal-entity-level counterparty due diligence.

●      Active standards participation through the ISO 20022 Payments and Technical Support Standards Evaluation Groups, working toward interoperable, FATF-aligned Travel Rule messaging globally.

●      Scale validated in production, not in a lab: over USD 500 billion processed, 20 million-plus verifications, and 150+ member VASPs across 30+ jurisdictions, giving our FATF-alignment claims a production track record that MAS' inspections suggest is rare in this industry.

●      Zero-incident record since 2019, underpinning both our AML/CFT assurances and our technology risk management posture under frameworks like Singapore's TRM Guidelines and the EU's DORA.

The Takeaway for DPTSPs

MAS has made clear that DPTSPs cannot simply adopt a Travel Rule solution and consider the value transfer requirement discharged. They must evaluate solutions against coverage, interoperability, VASP and counterparty due diligence, immediate transmission, and data security, and be able to demonstrate that evaluation with evidence, not representations. VerifyVASP has been building since 2019 a Verified Network designed around exactly this framework, and has consistently sought independent, third-party validation, rather than asking DPTSPs to take our compliance on faith or pure marketing claims.

If you would like to discuss how VerifyVASP can help your current or upcoming DPTSP meet MAS' AML/CFT/CPF supervisory expectations, or would like access to our FATF guiding-question assessment or SOC 2 Type II report, please get in touch with our team.