Get a demo
Insights & research

How to build MAS' AML/CFT expectations into your controls

A person smiling in a yellow jacket against a light background.

By June Lau

A digital interface with glowing icons, including a gear symbol, representing various technology and data-related concepts in a grid layout.

In July 2026, the Monetary Authority of Singapore (MAS) published an information paper on AML/CFT Supervisory Expectations for Digital Payment Token Service Providers (DPTSPs) that offered financial institutions (FI) dealing in digital payment tokens (DPTs) a detailed map of where controls typically break down. The case studies are specific to DPTSPs, but the underlying lessons are universal: 

  • Policies that are not granular enough to guide staff
  • Undocumented risk assessments
  • Screening that runs on stale cycles
  • Blockchain analytics used narrowly rather than as part of a holistic risk view

For compliance officers, this paper sets out MAS’ expectations. The findings need to be translated into repeatable, auditable steps across the financial crime compliance (FCC) risk management lifecycle: risk identification, risk assessment, risk monitoring, risk reporting and risk governance. This is where blockchain analytics progresses from a “nice to have” to a discretionary add-on to a structural component of the control environment.

Why the scrutiny on the DPT sector

MAS was clear that DPTs carry heightened money laundering and terrorism financing (ML/TF) risk because of their pseudonymous and cross-border nature. But the same pressure point exists wherever an FI touches virtual assets, including correspondent banking relationships with virtual asset service providers (VASPs), custody arrangements, institutional trading desks or fiat on/off-ramp services. 

The MAS paper repeatedly makes the point that on-chain visibility must be fused with off-chain information. Neither is sufficient alone. That fusion has to happen somewhere in the compliance operating model, and its natural home is the five-stage risk lifecycle that most FIs already use to manage financial crime risk.

1. Risk identification: knowing what you don’t yet know

The starting point of the lifecycle is identifying where ML/TF risk can enter the institution. MAS’ observations on new product risk assessments are instructive here: DPTSPs generally had risk indicators in place but they frequently lacked granularity on how those indicators should be assessed, which information sources to use and which functions (business, compliance, technology risk) should be involved.

Practical steps for compliance officers:

  • Maintain a live inventory of DPT exposure points (new token listings, new counterparty VASPs, new payment corridors and new customer segments) and require a documented ML/TF risk assessment before each is activated, not after.
  • Build risk-identification criteria that go beyond generic “high-risk jurisdiction” indicators to token-specific and counterparty-specific factors: association with exposure to illicit or high-risk entities such as mixers, darknet markets or sanctioned wallets; issuer governance and ownership concentration; and technological or smart-contract vulnerabilities that could be exploited for illicit flows. Most cryptoasset risks map to categories that institutions already address: customer/counterparty, geographic and product/service risk. On-chain behavioral risk is the one dimension with no direct equivalent in traditional finance. For more details, refer to Elliptic's Typologies Report.
  • Use blockchain analytics at the earliest stage to pre-screen a prospective token, wallet or counterparty VASP before commercial onboarding, rather than treating analytics for post-onboarding monitoring.
  • Document the reasoning behind thresholds (market capitalization, trading volume, liquidity) used to admit or reject a product or counterparty, so the criteria can be reviewed and defended later. This is a gap MAS’ own case studies flagged explicitly.

2. Risk assessment: building a holistic customer and product risk profile

Once a risk is identified, it must be assessed, both at onboarding and periodically thereafter. MAS’ case studies on enhanced customer due diligence (ECDD) show a recurring weakness: institutions relying solely on customer declarations for source of wealth (SOW) and source of funds (SOF), without independent corroboration and without considering the customer’s historical or beneficial-owner nationality when it touched a higher-risk jurisdiction. 

If SOW/SOF is accepted at face value without independent corroboration or regard for higher-risk nationality links, the institution loses its ability to detect misrepresented wealth or concealed risk, exposing it to regulatory censure for inadequate ECDD.

Practical steps for compliance officers:

  • Treat blockchain analytics as one input among several, not the sole basis for a risk rating. On-chain data should be triangulated with bank statements, employment records and other off-chain evidence to corroborate SOW/SOF, particularly where incoming funds are DPTs.
  • For customers whose wealth derives from virtual asset activity, require supporting documentation on the nature, timing and counterparties of prior transactions, not just their existence.
  • Assess jurisdiction risk dynamically, considering a customer’s current and prior nationalities, residency history and the origin of funds, rather than defaulting to current nationality alone.
  • Where a customer arrives from a platform with weak historical AML/CFT controls (a scenario increasingly relevant as clients migrate between regulatory regimes), be prudent by requiring wallet-level behavioral analysis to reconstruct the transaction history that the originating platform failed to maintain.
  • Ensure risk assessments are signed off by an identified compliance or control function, with senior management or Board approval properly evidenced. Undocumented approvals were a specific finding in MAS’s case studies.

3. Risk monitoring: moving from static screening to continuous, on-chain-aware surveillance

MAS was clear that ongoing monitoring must consider both DPT and fiat transactions together, and that sound compliance practice requires blockchain analytics solutions to be used alongside, rather than in place of, off-chain transaction and customer data monitoring. 

Several case studies illustrate the consequence of narrow monitoring practices: transaction parameters that failed to detect rapid DPT-in, fiat-out patterns; alerts cleared on the basis of transaction size alone, without deeper on-chain context such as timestamps or intermediary wallet counterparties; and annual, rather than continuous, sanctions re-screening that left a six-month blind spot/gap in coverage after a customer became sanctioned.

Practical steps for compliance officers:

  • Calibrate transaction monitoring thresholds and scenarios to the institution’s own customer base, product mix and risk appetite, rather than default vendor or group-wide settings, and review them periodically for continued relevance.
  • Integrate blockchain analytics outputs (wallet risk scores, exposure to mixers, darknet markets and high-risk exchanges) directly into the transaction monitoring workflow, rather than running them as a parallel, disconnected process.
  • When an alert involves on-chain exposure, obtain additional context (transaction timestamps, intermediary wallet hops, counterparty attribution) before clearing it, rather than closing the alert on transaction value alone.
  • Move sanctions and politically exposed person (PEP) screening of customers, beneficial owners and value-transfer counterparties to continuous or near-real-time cycles rather than static onboarding-plus-annual reviews.
  • Apply enhanced, on-chain-informed risk mitigation (such as proof-of-wallet-ownership checks, transaction limits or additional counterparty due diligence) consistently to transfers involving unhosted wallets or unregulated VASPs, regardless of whether a specific transaction has already been flagged as high-risk.

4. Risk reporting: making the invisible visible to decision-makers

A control environment is only as strong as the information it surfaces to those who must act on it. MAS’ emphasis on documentation (of risk assessments, deviations from policy, Board approvals and quality assurance findings) points to a broader reporting gap: Many of the weaknesses identified were not failures of intent but failures of evidence.

Practical steps for compliance officers:

  • Establish periodic reporting to senior management and the Board that consolidates blockchain analytics findings (aggregate wallet exposure trends, sanctions nexus incidents, illicit/high-risk exposure volumes) alongside traditional AML/CFT metrics such as suspicious activity report (SAR) filings and alert closure rates.
  • Report on the quality of alert handling, not just alert volumes, including sampling results from quality assurance reviews of how analytics-driven alerts were investigated and closed.
  • Escalate and report materially significant gaps promptly, including deficiencies identified in outsourced service providers or Travel Rule solution coverage, rather than waiting for periodic cycles.
  • Maintain an auditable record connecting each material risk decision (a listing approval, an ECDD sign-off, an alert closure) to the underlying analytics and off-chain evidence considered, so the institution can reconstruct its reasoning for regulators on demand.

5. Risk governance: closing the loop

Governance is the thread that ties the other four stages together. MAS repeatedly found that even where a control existed on paper, it broke down through inconsistent execution, undocumented approvals or a lack of the right expertise in the room.

Practical steps for compliance officers:

  • Ensure Board and senior management oversight extends to root-cause analysis of identified gaps, not just remediation tracking. MAS explicitly expects close oversight of gap assessments.
  • Build committees responsible for product approval, ECDD escalation and Travel Rule solution selection with a balanced mix of technical DPT, AML/CFT and compliance expertise, addressing MAS’s finding that technical staff often lack ML/TF risk awareness while compliance staff often lack sectoral depth.
  • Conduct due diligence on Partners and outsourced Service Providers before onboarding and periodically thereafter, and retain ultimate responsibility for AML/CFT outcomes even where functions are outsourced.
  • Deliver tailored, role-specific training so that technical, compliance and business staff share a common baseline understanding of blockchain technology, DPT-specific typologies and regulatory expectations.
  • Periodically benchmark the institution’s frameworks against updated supervisory guidance and incorporate lessons learned back into policies and procedures. This turns each MAS observation into a permanent uplift rather than a one-off fix.

The bottom line

MAS’s information paper sets out in granular detail where AML/CFT controls for DPT-related activity most commonly fail. The essence is that institutions fail not because they lack solutions, but because those solutions are not consistently embedded across the full risk management lifecycle. Blockchain analytics is powerful, but its value is only realized when it is woven into risk identification, deepened by rigorous assessment, operationalized through continuous monitoring, made visible through disciplined reporting and anchored by strong governance. Compliance officers who treat these five stages as a connected system, rather than five separate checklists, will be better placed to withstand both the ML/TF risks of digital assets and the supervisory scrutiny that inevitably follows them. 

At Elliptic, we work closely with regulators, financial institutions and digital asset firms across the Asia-Pacific region. If your team is working through what MAS’ information paper can mean for your business, talk to our team today.

FAQs

What is the CLARITY Act?
The CLARITY Act is proposed US legislation aimed at clarifying how cryptoassets are regulated, including the split of oversight between agencies. Elliptic's post covers its progress through the Senate Banking Committee.
Why does its progress matter?
Movement through committee signals momentum toward a clearer US market structure framework, which affects how crypto firms are regulated and supervised.
What should firms take from this?
Track the bill's scope and likely obligations so compliance programmes can prepare, while noting that the detail can change as it moves through the legislative process.
What is the GENIUS Act?
The GENIUS Act is US legislation establishing a federal framework for payment stablecoins, including requirements for permitted stablecoin issuers. Elliptic's post covers its passage in the Senate.
Who does the GENIUS Act affect?
It primarily affects stablecoin issuers and the banks and firms that handle stablecoins, by setting standards for which stablecoins are permitted under federal law.

Dive deeper

All insights
JUNE 2025 CRYPTO REGULATORY AFFAIRS ELLIPTIC

Crypto regulatory affairs: Singapore’s June 30 deadline for digital token service providers approaches

Image features a professional headshot with a neutral background, emphasizing the subject's face and upper body.

By David Carlisle

Vice President of Policy and Regulatory Affairs

Singapore sets the global standard: MAS issues guidance on crypto wealth due diligence

Liat Shetret

Crypto regulatory affairs: US Operation Economic Outcast looks to squeeze Iran’s crypto activity

David Carlisle

How to get ready for Hong Kong's next wave of virtual asset licensing

June Lau