
In July 2026, the Monetary Authority of Singapore (MAS) published an information paper on AML/CFT Supervisory Expectations for Digital Payment Token Service Providers (DPTSPs) that offered financial institutions (FI) dealing in digital payment tokens (DPTs) a detailed map of where controls typically break down. The case studies are specific to DPTSPs, but the underlying lessons are universal:
- Policies that are not granular enough to guide staff
- Undocumented risk assessments
- Screening that runs on stale cycles
- Blockchain analytics used narrowly rather than as part of a holistic risk view
For compliance officers, this paper sets out MAS’ expectations. The findings need to be translated into repeatable, auditable steps across the financial crime compliance (FCC) risk management lifecycle: risk identification, risk assessment, risk monitoring, risk reporting and risk governance. This is where blockchain analytics progresses from a “nice to have” to a discretionary add-on to a structural component of the control environment.
Why the scrutiny on the DPT sector
MAS was clear that DPTs carry heightened money laundering and terrorism financing (ML/TF) risk because of their pseudonymous and cross-border nature. But the same pressure point exists wherever an FI touches virtual assets, including correspondent banking relationships with virtual asset service providers (VASPs), custody arrangements, institutional trading desks or fiat on/off-ramp services.
The MAS paper repeatedly makes the point that on-chain visibility must be fused with off-chain information. Neither is sufficient alone. That fusion has to happen somewhere in the compliance operating model, and its natural home is the five-stage risk lifecycle that most FIs already use to manage financial crime risk.
1. Risk identification: knowing what you don’t yet know
The starting point of the lifecycle is identifying where ML/TF risk can enter the institution. MAS’ observations on new product risk assessments are instructive here: DPTSPs generally had risk indicators in place but they frequently lacked granularity on how those indicators should be assessed, which information sources to use and which functions (business, compliance, technology risk) should be involved.
Practical steps for compliance officers:
- Maintain a live inventory of DPT exposure points (new token listings, new counterparty VASPs, new payment corridors and new customer segments) and require a documented ML/TF risk assessment before each is activated, not after.
- Build risk-identification criteria that go beyond generic “high-risk jurisdiction” indicators to token-specific and counterparty-specific factors: association with exposure to illicit or high-risk entities such as mixers, darknet markets or sanctioned wallets; issuer governance and ownership concentration; and technological or smart-contract vulnerabilities that could be exploited for illicit flows. Most cryptoasset risks map to categories that institutions already address: customer/counterparty, geographic and product/service risk. On-chain behavioral risk is the one dimension with no direct equivalent in traditional finance. For more details, refer to Elliptic's Typologies Report.
- Use blockchain analytics at the earliest stage to pre-screen a prospective token, wallet or counterparty VASP before commercial onboarding, rather than treating analytics for post-onboarding monitoring.
- Document the reasoning behind thresholds (market capitalization, trading volume, liquidity) used to admit or reject a product or counterparty, so the criteria can be reviewed and defended later. This is a gap MAS’ own case studies flagged explicitly.
2. Risk assessment: building a holistic customer and product risk profile
Once a risk is identified, it must be assessed, both at onboarding and periodically thereafter. MAS’ case studies on enhanced customer due diligence (ECDD) show a recurring weakness: institutions relying solely on customer declarations for source of wealth (SOW) and source of funds (SOF), without independent corroboration and without considering the customer’s historical or beneficial-owner nationality when it touched a higher-risk jurisdiction.
If SOW/SOF is accepted at face value without independent corroboration or regard for higher-risk nationality links, the institution loses its ability to detect misrepresented wealth or concealed risk, exposing it to regulatory censure for inadequate ECDD.
Practical steps for compliance officers:
- Treat blockchain analytics as one input among several, not the sole basis for a risk rating. On-chain data should be triangulated with bank statements, employment records and other off-chain evidence to corroborate SOW/SOF, particularly where incoming funds are DPTs.
- For customers whose wealth derives from virtual asset activity, require supporting documentation on the nature, timing and counterparties of prior transactions, not just their existence.
- Assess jurisdiction risk dynamically, considering a customer’s current and prior nationalities, residency history and the origin of funds, rather than defaulting to current nationality alone.
- Where a customer arrives from a platform with weak historical AML/CFT controls (a scenario increasingly relevant as clients migrate between regulatory regimes), be prudent by requiring wallet-level behavioral analysis to reconstruct the transaction history that the originating platform failed to maintain.
- Ensure risk assessments are signed off by an identified compliance or control function, with senior management or Board approval properly evidenced. Undocumented approvals were a specific finding in MAS’s case studies.
3. Risk monitoring: moving from static screening to continuous, on-chain-aware surveillance
MAS was clear that ongoing monitoring must consider both DPT and fiat transactions together, and that sound compliance practice requires blockchain analytics solutions to be used alongside, rather than in place of, off-chain transaction and customer data monitoring.
Several case studies illustrate the consequence of narrow monitoring practices: transaction parameters that failed to detect rapid DPT-in, fiat-out patterns; alerts cleared on the basis of transaction size alone, without deeper on-chain context such as timestamps or intermediary wallet counterparties; and annual, rather than continuous, sanctions re-screening that left a six-month blind spot/gap in coverage after a customer became sanctioned.
Practical steps for compliance officers:
- Calibrate transaction monitoring thresholds and scenarios to the institution’s own customer base, product mix and risk appetite, rather than default vendor or group-wide settings, and review them periodically for continued relevance.
- Integrate blockchain analytics outputs (wallet risk scores, exposure to mixers, darknet markets and high-risk exchanges) directly into the transaction monitoring workflow, rather than running them as a parallel, disconnected process.
- When an alert involves on-chain exposure, obtain additional context (transaction timestamps, intermediary wallet hops, counterparty attribution) before clearing it, rather than closing the alert on transaction value alone.
- Move sanctions and politically exposed person (PEP) screening of customers, beneficial owners and value-transfer counterparties to continuous or near-real-time cycles rather than static onboarding-plus-annual reviews.
- Apply enhanced, on-chain-informed risk mitigation (such as proof-of-wallet-ownership checks, transaction limits or additional counterparty due diligence) consistently to transfers involving unhosted wallets or unregulated VASPs, regardless of whether a specific transaction has already been flagged as high-risk.
4. Risk reporting: making the invisible visible to decision-makers
A control environment is only as strong as the information it surfaces to those who must act on it. MAS’ emphasis on documentation (of risk assessments, deviations from policy, Board approvals and quality assurance findings) points to a broader reporting gap: Many of the weaknesses identified were not failures of intent but failures of evidence.
Practical steps for compliance officers:
- Establish periodic reporting to senior management and the Board that consolidates blockchain analytics findings (aggregate wallet exposure trends, sanctions nexus incidents, illicit/high-risk exposure volumes) alongside traditional AML/CFT metrics such as suspicious activity report (SAR) filings and alert closure rates.
- Report on the quality of alert handling, not just alert volumes, including sampling results from quality assurance reviews of how analytics-driven alerts were investigated and closed.
- Escalate and report materially significant gaps promptly, including deficiencies identified in outsourced service providers or Travel Rule solution coverage, rather than waiting for periodic cycles.
- Maintain an auditable record connecting each material risk decision (a listing approval, an ECDD sign-off, an alert closure) to the underlying analytics and off-chain evidence considered, so the institution can reconstruct its reasoning for regulators on demand.
5. Risk governance: closing the loop
Governance is the thread that ties the other four stages together. MAS repeatedly found that even where a control existed on paper, it broke down through inconsistent execution, undocumented approvals or a lack of the right expertise in the room.
Practical steps for compliance officers:
- Ensure Board and senior management oversight extends to root-cause analysis of identified gaps, not just remediation tracking. MAS explicitly expects close oversight of gap assessments.
- Build committees responsible for product approval, ECDD escalation and Travel Rule solution selection with a balanced mix of technical DPT, AML/CFT and compliance expertise, addressing MAS’s finding that technical staff often lack ML/TF risk awareness while compliance staff often lack sectoral depth.
- Conduct due diligence on Partners and outsourced Service Providers before onboarding and periodically thereafter, and retain ultimate responsibility for AML/CFT outcomes even where functions are outsourced.
- Deliver tailored, role-specific training so that technical, compliance and business staff share a common baseline understanding of blockchain technology, DPT-specific typologies and regulatory expectations.
- Periodically benchmark the institution’s frameworks against updated supervisory guidance and incorporate lessons learned back into policies and procedures. This turns each MAS observation into a permanent uplift rather than a one-off fix.
The bottom line
MAS’s information paper sets out in granular detail where AML/CFT controls for DPT-related activity most commonly fail. The essence is that institutions fail not because they lack solutions, but because those solutions are not consistently embedded across the full risk management lifecycle. Blockchain analytics is powerful, but its value is only realized when it is woven into risk identification, deepened by rigorous assessment, operationalized through continuous monitoring, made visible through disciplined reporting and anchored by strong governance. Compliance officers who treat these five stages as a connected system, rather than five separate checklists, will be better placed to withstand both the ML/TF risks of digital assets and the supervisory scrutiny that inevitably follows them.
At Elliptic, we work closely with regulators, financial institutions and digital asset firms across the Asia-Pacific region. If your team is working through what MAS’ information paper can mean for your business, talk to our team today.


