If you are serious about obtaining a MAS crypto licence in Singapore, there is one regulatory standard MAS crypto licensing requirements in Singapore which you cannot afford to misunderstand, underestimate, or treat as a formality:

PSN02.

You may have come across it while researching:

  • MAS crypto licence requirements
  • DPT licence Singapore
  • AML requirements for crypto companies
  • MAS compliance frameworks

But what many founders don’t realise—until they are deep into the application process—is this:

PSN02 is not just a guideline.
It is one of the core frameworks MAS uses to determine whether your crypto business is ready for approval.

And if your business does not meet PSN02 expectations:

Your application will not move forward smoothly—no matter how strong everything else looks.

What Is PSN02 and Why Does It Matters So Much?

PSN02 refers to:

MAS Notice PSN02 — Prevention of Money Laundering and Countering the Financing of Terrorism (AML/CFT) for Digital Payment Token Service Providers

In Simple Terms

It is the rulebook that defines:

How crypto businesses must manage financial crime risk in Singapore.

Why MAS Prioritises PSN02

Crypto businesses inherently introduce:

  • Cross-border fund movement
  • Pseudonymous transactions
  • High-speed execution

From MAS’s perspective, this creates:

Elevated risk of money laundering, terrorist financing, and illicit activity.

So MAS Asks:

“Can this business detect, prevent, and manage financial crime risk effectively?”

And PSN02 is how MAS answers that question.

Key Insight

If your business does not meet PSN02 standards,
you are not ready for a MAS licence—regardless of anything else.

PSN02 Is Not a Policy—It’s a System

One of the biggest mistakes applicants make is treating PSN02 as:

  • A document to prepare
  • A checklist to complete
  • A compliance box to tick

MAS does not see it that way.

MAS expects PSN02 to be:

An operational system embedded into your business.

This Means:

  • Your AML framework must work in real time
  • Your controls must be implemented—not theoretical
  • Your team must understand how to apply them

Key Insight

PSN02 compliance is not about what you write.
It is about what your business actually does.

The Core Components of PSN02 Compliance

Let’s break down what MAS actually expects under PSN02.

1. Risk-Based Approach (The Foundation of Everything)

At the heart of PSN02 is one principle:

Not all risks are equal.

MAS expects your business to:

  • Identify risks
  • Assess risks
  • Mitigate risks

This Applies To:

  • Customers
  • Transactions
  • Geographies
  • Products

What This Looks Like in Practice

Low-Risk Customer
  • Simplified monitoring
  • Standard onboarding
High-Risk Customer
  • Enhanced due diligence
  • Ongoing monitoring
  • Additional verification

Key Insight

MAS expects dynamic risk management—not static compliance.

2. Customer Due Diligence (CDD)

This is the starting point of your AML framework.

You Must Be Able To:

  • Identify your customer
  • Verify their identity
  • Understand their profile

This Includes:

  • Government-issued ID verification
  • Beneficial ownership identification
  • Understanding source of funds (where applicable)

MAS Expectation

Not:

“We collect documents”

But:

“We understand who our customers are and the risks they present.”

3. Enhanced Due Diligence (EDD)

Some customers require more scrutiny.

PSN02 Requires You To:

  • Identify high-risk customers
  • Apply enhanced controls
  • Monitor them more closely

Examples of High-Risk Profiles

  • Politically Exposed Persons (PEPs)
  • High-risk jurisdictions
  • Complex ownership structures

Key Insight

A one-size-fits-all approach to onboarding is a red flag for MAS.

4. Ongoing Monitoring (Where Compliance Becomes Real)

This is where many applications fail.

Why?

Because monitoring is:

The most operationally demanding part of PSN02.

MAS Expects You To:

  • Monitor transactions continuously
  • Detect suspicious patterns
  • Investigate anomalies

This Requires:

  • Automated tools
  • Defined thresholds
  • Escalation procedures

What MAS Does NOT Accept

  • Manual-only systems
  • Reactive monitoring
  • Generic frameworks

Key Insight

Monitoring is not optional—it is the engine of your AML system.

5. Suspicious Transaction Reporting (STR)

When suspicious activity is identified:

You must act.

PSN02 Requires:

  • Timely reporting of suspicious transactions
  • Internal escalation processes
  • Documentation of decisions

What MAS Looks For

  • Clear procedures
  • Trained personnel
  • Evidence of implementation

6. Sanctions Screening

You must ensure your platform is not used by:

  • Sanctioned individuals
  • Restricted entities

This Includes:

  • Screening at onboarding
  • Continuous monitoring
  • Updating sanctions lists

Key Insight

Sanctions compliance is non-negotiable.

7. Travel Rule Compliance

This is a major focus area for crypto firms.

PSN02 Requires You To:

  • Collect sender and recipient information
  • Transmit this information with transactions
  • Ensure traceability

Why This Matters

Because:

It reduces anonymity in crypto transactions.

Common Challenge

  • Integrating Travel Rule solutions
  • Ensuring interoperability

Key Insight

Travel Rule compliance is now a baseline expectation—not an advanced feature.

8. Record-Keeping

You must maintain:

  • Customer records
  • Transaction records
  • Compliance actions

MAS Requires:

  • Accuracy
  • Accessibility
  • Retention for regulatory review

9. Independent Audit & Testing

Your AML framework must be:

Tested and validated.

This Includes:

  • Internal reviews
  • External audits
  • Ongoing assessments

Why MAS Requires This

Because:

Self-declared compliance is not enough.

Where Most Firms Fail PSN02

There are mandatory licensing requirements for DPT service providers despite understanding the requirements, many firms fail at implementation.

Common Failures

  • Copy-paste AML policies
  • No real monitoring tools
  • Lack of risk-based approach
  • Poor understanding of fund flows
  • Weak Travel Rule implementation

MAS Reaction

“This business cannot manage financial crime risk.”

The PSN02–Fund Flow Connection

One of the most important—and often overlooked—connections is between: PSN02 compliance, Fund flow clarity and how MAS fund flow diagrams work.

Why This Matters

Because:

  • AML controls depend on understanding flows
  • Risk points exist within flows
  • Monitoring must align with flows

If Fund Flows Are Unclear

Your AML framework becomes:

Theoretical—not operational.

Key Insight

You cannot build PSN02 compliance without understanding how money moves through your system.

PSN02 and MAS Licensing Approval

At the end of the day, PSN02 plays a central role in approval decisions for which you need to know about MAS crypto licence application process and documentation.

MAS Is Asking:

  • Can this business prevent financial crime?
  • Are controls effective in practice?
  • Is the system robust and scalable?

If the Answer Is Yes

Your application progresses.

If the Answer Is Unclear

Expect:

  • Queries
  • Delays
  • Increased scrutiny

If the Answer Is No

Approval becomes unlikely.

How to Approach PSN02 Strategically

Instead of asking:

“How do we comply with PSN02?”

Ask:

“How do we build a system that manages risk effectively?”

This Means:

  • Investing in real tools
  • Designing practical processes
  • Training your team
  • Aligning everything with your business model

Key Insight

PSN02 is not a hurdle—it is a framework for building a credible business.

How CRYPTOVERSE Can Help

PSN02 compliance is one of the most complex—and most critical—parts of obtaining a MAS crypto licence and that’s where our MAS licensing advisory services can help you.

That’s where CRYPTOVERSE comes in.

We help clients:

  • Design AML/CFT frameworks aligned with PSN02
  • Map fund flows to identify risk points
  • Implement monitoring and compliance systems
  • Prepare documentation that reflects real operations

Our approach ensures that your business does not just:

Understand PSN02—but meet it in practice.

Final Thought

At the end of the day, PSN02 is not just a regulatory requirement.

It is:

MAS’s way of determining whether your business can be trusted.

Because in Singapore:

  • Trust is earned through systems
  • Systems are proven through execution
  • And execution is measured through frameworks like PSN02

So the real question is not:

“Do we comply with PSN02?”

The real question is:

“Can our business operate in a way that prevents financial crime—consistently, reliably, and at scale?”

Because that is what MAS is ultimately deciding.

FAQs

1. What is PSN02?

PSN02 is MAS Notice PSN02, the AML/CFT framework that Digital Payment Token service providers in Singapore must comply with. It sets out how crypto businesses must detect, prevent, and manage financial crime risk.

2. Is PSN02 just a document I need to submit with my MAS application?

No. MAS expects PSN02 to be an operational system embedded into your business, not paperwork. Controls must be actually implemented and used, not just written down.

3. What’s the difference between Customer Due Diligence and Enhanced Due Diligence under PSN02?

CDD is standard identity verification and risk profiling for all customers. EDD applies additional scrutiny — closer monitoring and verification — for higher-risk customers like PEPs or those in high-risk jurisdictions.

4. Why do many crypto firms fail PSN02 compliance?

Common failures include copy-paste AML policies, lack of real monitoring tools, no risk-based approach, and weak Travel Rule implementation. MAS wants evidence the system actually works, not just documentation that it exists.

5. How does PSN02 compliance affect MAS licence approval?

 It’s central to the decision. If MAS can’t confirm your business can effectively prevent financial crime, expect queries and delays at best, or a stalled application at worst — regardless of how strong the rest of your application is.