Expanding into Singapore's fintech ecosystem raises immediate questions about regulatory requirements. The Monetary Authority of Singapore (MAS) maintains one of Asia's most structured licensing frameworks, and determining which license category applies to your business model is rarely straightforward. For founders at pre-Series A to Series B stage, and compliance officers scaling established operations, the difference between a Standard Payment Institution (SPI) and Major Payment Institution (MPI) license—or whether you need a Capital Markets Services License (CMSL) at all—can determine months of preparation work and significant capital allocation.
This guide maps the regulatory landscape as it stands in 2026, following amendments to the Payment Services Act (PSA) and recent MAS guidance on digital asset service providers. We address the questions we hear most frequently from clients: Which license do you actually need? What does the application process require? And what ongoing obligations will your compliance team manage once approved?
Understanding the Licensing Framework: Where Your Business Model Fits
Singapore's regulatory approach categorizes fintech activities by risk profile and systemic impact. The Payment Services Act 2019, as amended in 2024 to include digital payment token service providers, remains the primary legislation governing payment and remittance businesses. Capital markets activities fall under the Securities and Futures Act. Understanding where your business sits within this framework is the essential first step.
Standard Payment Institution (SPI) vs. Major Payment Institution (MPI)
The distinction between SPI and MPI licenses hinges on transaction volume thresholds and the scope of payment services offered. An SPI license applies to businesses with monthly payment flows below S$3 million for any single payment service, or S$6 million aggregate across multiple services. This threshold captures most early-stage fintechs processing domestic payments, e-wallet services, and limited merchant acquiring.
Cross the threshold, or offer more complex services such as cross-border money transfer, digital payment token services, or merchant acquiring without transaction caps, and MAS requires an MPI license. The MPI framework carries more stringent capital requirements (base capital of S$250,000 versus S$100,000 for SPI), mandatory safeguarding arrangements for customer funds, and enhanced compliance obligations.
Important: The 2024 PSA amendments introduced additional obligations for digital payment token service providers, including segregation of customer assets and enhanced disclosure requirements. If your business facilitates cryptocurrency transactions or tokenized payment solutions, these provisions apply regardless of SPI or MPI classification.
Capital Markets Services License (CMSL)
Wealthtech, robo-advisory, and peer-to-peer lending platforms typically require CMSL coverage. The license authorizes regulated activities including dealing in securities, fund management, and providing financial advisory services. For fintechs offering investment products, portfolio management, or automated advisory services, CMSL compliance is non-negotiable.
The CMSL application process is notably more extensive than payment institution licensing. MAS evaluates not only financial resources and operational infrastructure but also the investment methodology, risk management frameworks, and the track record of key individuals. Capital requirements vary by activity—fund managers typically need base capital between S$250,000 and S$1 million depending on investor type and strategy complexity.
When Exemptions Apply
Not every fintech activity requires full licensing. MAS provides specific exemptions that may apply to your business model:
- Small payment institution exemption: Businesses below S$1 million monthly transaction volume may operate under exemption with reduced compliance obligations, provided they notify MAS and meet conduct requirements.
- Technology service provider exemption: Pure technology providers that do not handle customer funds or execute transactions may fall outside PSA scope, though this determination requires careful legal analysis.
- Closed-loop payment exemption: Payment facilities limited to a specific merchant ecosystem and non-transferable outside that system may qualify for exemption.
- Financial adviser exemption: Limited advice on certain exempt investment products, or advice provided through licensed platforms, may not require standalone CMSL coverage.
Critical note: Exemption determinations are fact-specific. MAS expects businesses to seek legal confirmation of exempt status before commencing operations. Operating under an assumed exemption that MAS later disputes can result in enforcement action.
License Selection Decision Tree
Use this framework to identify your likely licensing path. Each question builds on the previous to narrow your regulatory requirements:
Step 1: Identify Your Core Activity
- Do you handle customer funds (accept, hold, transfer)? → Payment Services Act likely applies
- Do you manage investments or provide investment advice? → CMSL likely required
- Do you lend your own capital? → Moneylenders Act may apply
- Do you facilitate lending between third parties? → CMSL or exemption analysis required
Step 2: Assess Transaction Volume (Payment Services)
- Projected monthly volume below S$1 million → Small payment institution exemption possible
- Volume between S$1–3 million per service → SPI license required
- Volume above S$3 million per service, or S$6 million aggregate → MPI license required
- Cross-border money transfer regardless of volume → MPI license typically required
Step 3: Evaluate Digital Asset Involvement
- Facilitating digital payment token exchange → DPT service provider obligations apply
- Token custody services → Enhanced safeguarding requirements under 2024 amendments
- Non-transferable loyalty points or in-game currencies → May fall outside DPT scope
Step 4: Determine CMSL Sub-Category (If Applicable)
- Robo-advisory or discretionary portfolio management → Licensed fund management
- Execution-only brokerage → Dealing in securities or exchange-traded products
- Financial advisory → Financial adviser license or appointed representative status
This decision tree provides a starting framework, but regulatory classification often requires nuanced analysis. Hybrid models—such as payment platforms that also offer investment features—may trigger multiple licensing requirements. Early engagement with MAS through the FinTech Regulatory Sandbox can provide clarity on classification before committing to full application costs.
The MAS Licensing Journey: Timeline and Process
Understanding the timeline from initial concept to operational license helps founders plan runway and resource allocation realistically. The process typically unfolds across three phases, with total duration ranging from six to eighteen months depending on complexity.
Phase 1: Sandbox Entry or Pre-Application Consultation
MAS offers two pathways for early-stage engagement. The FinTech Regulatory Sandbox allows businesses to test innovative solutions in a live environment with relaxed regulatory requirements for a defined period (typically 6–12 months). Sandbox entry requires demonstration of genuine innovation, clear risk mitigation plans, and defined exit criteria. For businesses not requiring sandbox testing, MAS provides pre-application consultation to confirm license categorization and discuss specific concerns.
We recommend this phase for all first-time applicants. The insights gained from MAS feedback can prevent costly missteps in the full application and demonstrate regulatory engagement that supports later approval.
Phase 2: Full Application Submission
The formal application requires comprehensive documentation across several domains:
| Document Category | Key Requirements |
|---|---|
| Business Plan | Detailed revenue model, target market, 3-year financial projections, funding sources |
| Governance Structure | Organizational chart, reporting lines, board composition, segregation of duties |
| Compliance Framework | AML/CFT policies, transaction monitoring procedures, sanctions screening protocols |
| Technology & Security | IT infrastructure diagram, cybersecurity policies, outsourcing arrangements, business continuity plan |
| Key Individual Profiles | Detailed CVs, qualification certificates, fit-and-proper declarations |
MAS assessment timelines vary by license type. SPI applications typically receive response within 3–4 months; MPI and CMSL applications may take 6–9 months. MAS may issue clarification requests during review, each adding 2–4 weeks to the timeline.
Phase 3: Post-Approval Compliance Obligations
License approval marks the beginning of ongoing regulatory obligations, not the end of compliance work. MAS conducts regular supervisory reviews, and licensed institutions must maintain compliance frameworks continuously. Key post-approval requirements include:
- Annual attestations: Submission of audited financial statements, compliance attestations, and updated business plans
- Material change notification: Prior approval required for changes to shareholders above threshold, key appointments, or business model modifications
- Compliance officer appointment: Licensed payment institutions must appoint a compliance officer with direct board reporting line
- Regular MAS reporting: Quarterly or annual statistical returns depending on license type
Technology Risk Management: MAS Expectations
Technology risk management has moved from supporting documentation to core licensing assessment criteria. MAS Technology Risk Management Guidelines, updated in 2025, establish clear expectations for fintech infrastructure resilience.
Cybersecurity Requirements
All licensed fintechs must implement multi-layered security controls aligned with MAS TRM guidelines. This includes encryption of sensitive data both in transit and at rest, multi-factor authentication for system access, regular vulnerability assessments, and incident response protocols with defined escalation paths to MAS. The 2025 guidelines specifically emphasize zero-trust architecture and require documented security posture assessments for cloud deployments.
Outsourcing and Third-Party Risk
Fintechs relying on cloud infrastructure, payment processors, or technology vendors must maintain robust outsourcing governance. MAS requires material outsourcing arrangements to be documented with clear service level agreements, audit rights, and exit provisions. The licensed institution—not the vendor—remains responsible for regulatory compliance. For cloud deployments processing customer data or financial transactions, MAS expects detailed data residency assessments and sub-processing notifications.
Business Continuity Planning
Payment institutions and CMSL holders must demonstrate operational resilience through documented business continuity plans. MAS expects recovery time objectives (RTOs) of four hours or less for critical payment systems, with comprehensive disaster recovery testing conducted at least annually. The 2025 guidelines introduced additional requirements for scenario-based resilience testing, including simulation of critical vendor failures and cyber incident recovery.
Director and Senior Management Requirements
MAS places significant weight on the experience and integrity of individuals directing licensed institutions. The fit-and-proper criteria extend beyond academic qualifications to include relevant industry experience, track record of regulatory compliance, and personal integrity.
Local Resident Director Requirements
A critical—and often underestimated—requirement is the appointment of at least one executive director ordinarily resident in Singapore. This individual serves as the primary regulatory contact and must demonstrate substantial involvement in day-to-day operations. For foreign founders, this typically means either relocating a co-founder to Singapore or appointing a qualified local executive with sufficient authority and equity alignment to satisfy MAS concerns about commitment to local oversight.
Important distinction: The resident director must be an executive with decision-making authority, not a nominee or non-executive appointee. MAS has rejected applications where the local director lacked demonstrable operational control or held only nominal responsibilities.
Key Appointment Requirements
MPI and CMSL licenses require approved appointments for specific roles:
- Chief Executive Officer: Ultimate responsibility for regulatory compliance and business conduct
- Compliance Officer: Independent oversight of AML/CFT and regulatory compliance programs
- Technology Risk Officer: For institutions with significant technology operations, responsibility for IT risk management
- Money Laundering Reporting Officer (MLRO): Specific appointment for suspicious transaction reporting and AML oversight
Each appointment requires MAS notification or prior approval, with detailed CVs and fit-and-proper declarations submitted. Changes to these positions must be reported within 14 days, with MAS retaining authority to object to appointments that do not meet standards.
Ongoing Reporting and Compliance Obligations
License approval initiates a continuous compliance relationship with MAS. Understanding ongoing obligations helps compliance teams allocate resources appropriately and avoid supervisory scrutiny.
Transaction Reporting Thresholds
Payment institutions must maintain systems capable of generating transaction reports by volume and value, segmented by payment service type. MAS may request this data for supervisory purposes or market analysis. MPI license holders face additional requirements for daily transaction monitoring and periodic reconciliation of customer funds held in segregation.
Suspicious Transaction Reporting (STR)
All licensed fintechs must implement transaction monitoring systems to detect potentially suspicious activity. Where suspicion of money laundering or terrorist financing arises, institutions must file Suspicious Transaction Reports with the Suspicious Transaction Reporting Office (STRO) within 15 days. MAS expects documented policies for identifying suspicious activity, staff training programs, and regular calibration of monitoring systems.
Annual Attestations and Audits
Licensed institutions must submit annual audited financial statements prepared in accordance with Singapore Financial Reporting Standards. Additionally, MPI and CMSL holders must provide compliance attestations confirming adherence to regulatory requirements, board oversight effectiveness, and adequacy of risk management frameworks. These submissions are typically due within four months of financial year-end.
Final Considerations: Planning Your Regulatory Strategy
Singapore's fintech licensing framework rewards preparation and transparency. The regulatory burden is substantial—there is no minimizing the capital requirements, compliance obligations, and ongoing reporting that licensed institutions must manage. However, the clarity of MAS requirements, combined with Singapore's reputation for regulatory consistency, creates a predictable environment for businesses that approach licensing methodically.
For founders planning Q3 or Q4 incorporation, we recommend beginning structure discussions 12–14 weeks before target launch dates. This timeline accommodates pre-application consultation, document preparation, and the application review period. For established fintechs expanding product lines, early engagement with MAS on classification questions can prevent operational disruption.
For companies navigating the intersection of business financing requirements and regulatory licensing, integrated planning across funding and compliance timelines is essential. The capital requirements for MPI and CMSL licenses—base capital plus operational buffers—should be factored into fundraising plans from the outset.
If your expansion timeline involves MAS licensing in the coming quarters, we recommend scheduling a preliminary assessment to map your specific business model against current regulatory requirements. The framework continues to evolve, particularly in digital asset services, and early clarity on your compliance pathway supports more accurate resource planning and investor communication.
"Regulatory compliance in Singapore is not a checkbox exercise—it is an ongoing operational framework that requires dedicated resources, experienced leadership, and genuine commitment to risk management. The businesses that thrive are those that integrate compliance into their operational DNA from day one."
Key regulatory references for this article: Payment Services Act 2019 (as amended 2024), MAS Technology Risk Management Guidelines (2025), MAS Guidelines on Fit and Proper Criteria, MAS Notices on Prevention of Money Laundering and Countering the Financing of Terrorism.




