2026-07-16
Added · Updated
Payment service providers must appoint an external auditor annually and submit audited financial statements, an Independent Assurance Report, and a management letter via Form 4 within six months of the financial year end. The audit scope must cover safeguarding of customer monies, accuracy of regulatory reporting, base capital compliance, and remediation of prior findings, with specific end-to-end reviews required for Anti-Money Laundering/Countering the Financing of Terrorism and Technology risks for new licensees or new services one year after commencement. External auditors are mandated to immediately report serious breaches, such as failure to segregate customer funds or significant capital reductions, to the Monetary Authority of Singapore, while licensees retain independent obligations to notify the Authority of such incidents.
01 Guidelines on Audit of Payment Service Providers Guidelines PS-G04 16 July 2026
2 Guidelines on Audit of Payment Service Providers CONTENTS 1 Introduction 3 2 Annual Audit Requirement 3 3 Information to be provided to the Auditors 6 4 Baseline Expectations for Audit of PSPs 7 5 Mandatory End-to-End Review for New Licensees and Licensees with Newly Licensed Payment Services 8
3 Guidelines on Audit of Payment Service Providers Guideline No : PS-G04 Issue Date : 16 July 2026 Guidelines on Audit of Payment Service Providers (PSPs) 1 Introduction 1.1 The Guidelines on the Audit of Payment Service Providers (the “Guidelines”) is issued pursuant to section 37 of the Payment Services Act 2019 (“PS Act”), read with Regulation 20 of the Payment Services Regulations 2019 (“PS Regs”), and apply to all holders of a payment service licence (payment service providers or “PSPs”). The Guidelines set out MAS’ expectations on the annual audit requirements, scope and mandatory coverage areas for all PSPs. 1.2 The extent and degree to which a PSP implements the Guidelines should be commensurate with the level of risk and complexity of its business model, as well the products and services offered. 1.3 The Guidelines provide general guidance and are not intended to be comprehensive nor replace or override any legislative provisions. They should be read in conjunction with the provisions of the PS Act, PS Regs and other relevant legislation, written directions, notices, codes and guidelines issued by MAS. 2 Annual Audit Requirement 2.1 Pursuant to section 37 of the PS Act as read with Regulation 20 of the PS Regs, a PSP must, on an annual basis, appoint an auditor and ensure that a report of the audit is submitted to the Authority in Form 4 within 6 months after the financial year end, via the online portals in Table 1 below. For avoidance of doubt, the requirement applies to all holders of a payment service licence, including sole proprietors who hold a money-changing licence. 2.2 The PSP should ensure that it appoints an appropriate and suitably qualified external auditor in advance of the stipulated Form 4 submission timeline, to allow sufficient time for the auditor to complete the annual audit. PSPs should not be engaging separate auditors for different parts of the annual audit. The same appointed auditor should cover, and be responsible for a) the annual audit of the licensees’ accounts, b) the submission of the Independent Assurance Report, and c) the submission of any findings and observations noted in the course of the annual audit.
4 Guidelines on Audit of Payment Service Providers Table 1 – Form 4 Submission Requirements Form 4 portals Submissions a) Form 4 - Submission of Financial Statements i) Audited accounts of the PSP b) Form 4 - Auditor's Report for a Licensed PSP ii) Independent Assurance Report, and iii) Findings and observations noted from the audit of transactions in relation to the payment services provided by the PSP, in particular, in respect of the PSP’s observance of regulatory requirements, as well as adequacy of risk management and controls Audited Accounts of the PSP 2.3 Reasonable assurance should be obtained from the external auditor that the financial statements as a whole are free from material misstatement, whether due to fraud or error. Independent Assurance Report 2.4 The Independent Assurance Report (“the Report”) must be prepared based on the Audit Guidance Statement 1 (AGS1), Appendix 3B, in accordance with the Singapore Standard on Assurance Engagements (SSAE) 3000 (Revised). 2.5 The Report is based on limited assurance as to whether a) the financial data contained in PSN04 has been prepared, in all material aspects, in accordance with the PS Act and PS Regs, and b) there has been any contravention of the conditions, restrictions, obligations and other requirements provided under the PS Act and PS Regs.
5 Guidelines on Audit of Payment Service Providers Findings and Observations 2.6 As part of the annual audit requirement, a copy of the management letter from the external auditor (“management letter”), including any findings, observations and recommendations noted from the audit of the licensee’s accounts, transactions, systems and controls, as well as policies and procedures in accordance with regulatory requirements, should be submitted in Form 4. External auditors should clearly set out the audit coverage areas in the management letter and specify the areas or control processes where sample testing has been conducted to assess effectiveness of controls. 2.7 MAS will consider the findings and observations in the management letter as part of our assessment of the licensee’s control framework. MAS will also take into account factors such as whether the licensee had self-identified control gaps for improvement, management’s receptiveness towards issues raised and willingness and proactiveness to remediate these findings. 2.8 Section 37(9)1 of the PS Actsets out the various matters that external auditors must immediately report to the Authority, rather than only in the Form 4 submission. • Examples of serious breaches that should be immediately reported to MAS include, but are not limited to, instances where customers’ monies are not properly segregated or safeguarded, base capital falling below the minimum requirement, conducting regulated activities without the licence to do so, and changes in controllers, Board of Directors or CEO without having obtained the prior approval of MAS. • Systemic and severe gaps in risk management systems and controls should also be immediately reported. 1 These matters include: • Serious breaches or non-compliance with our requirements • Criminal offences involving fraud or dishonesty; • Significant losses that reduced the capital of the licensee by at least 50%; • Irregularities which materially impacted licensee’s accounts or caused major disruption to the payment service(s) provided; • The auditor is unable to confirm that the claims of creditors of the licensee are still covered by the assets of the licensee.
6 Guidelines on Audit of Payment Service Providers 2.9 The external auditors’ duty to immediately report the matters set out in paragraph 2.8 to MAS does not replace the licensee’s own responsibility to notify MAS. As part of its obligations as a licensed entity, MAS expects a PSP to notify MAS immediately upon the discovery of any serious breach, or any systemic and severe gap in its risk management systems and controls. This expectation applies regardless of whether the matter has also been, or will be, reported by the external auditor. Where a PSP fails to notify MAS on an immediate basis, MAS will take requisite supervisory actions against the PSP. 2.9 Section 37(10) of the PS Act provides for auditors to provide such information to the Authority without breaching of any duty to the PSP if disclosure is made in good faith, and the auditor is not liable for any loss arising out of the disclosure or any act or omission in consequence of the disclosure. 2.10 If MAS is not satisfied with the performance of any duty by the auditor of a PSP, MAS may, under section 37(7) of the PS Act, direct the licensee to remove the auditor and appoint another auditor, at any time. 3 Information to be provided to the Auditors 3.1 To enable the appointed external auditors to discharge their duties under section 37(4) of the PS Act2 , PSPs should provide their auditors with the necessary information on a timely basis. Such information includes, but is not limited to: (a) The PSP’s business model, profile of customers and jurisdictions served; (b) The regulated products and services offered by the PSP, including the payment services conducted at each stage of the transaction process; (c) The exempted products and services offered by the PSP and the controls in place to ensure that the PSP continues to meet the exemption criteria; (d) Licensing conditions and any regulatory directions issued to the PSP; (e) Regulatory breaches, fines and any other regulatory/supervisory actions taken against the PSP; 2 Section 37(4) of the PS Act provides “The duties of an auditor appointed under subsection (1) or (2) are as follows: (a) to carry out, for the year in respect of which the auditor is appointed, an audit of the accounts of the licensee; (b) to carry out an audit of the transactions in relation to the payment services provided by the licensee, in particular, in respect of the licensee’s observance of the provisions of this Act and any of the requirements imposed under any other written law administered by the Authority;”
7 Guidelines on Audit of Payment Service Providers (f) Outstanding findings in relation to control deficiencies and non-compliance with applicable requirements arising from prior and current years’ internal audit reports, external audit reports, and inspections conducted; and (g) Any other information required by the external auditors such as the latest Enterprise-Wide Risk Assessment conducted by the PSP, relevant committee meeting minutes and latest gap analysis performed against existing requirements. 4 Baseline Expectations for Audit of PSPs Baseline Expectations 4.1 All PSPs are expected to have robust risk management systems and controls to identify, assess, and mitigate the inherent risks arising from their business activities. PSPs should also have the necessary policies and processes in place to ensure compliance with applicable regulations on an ongoing basis. 4.2 The annual audit scope and coverage of licensee’s systems, risk management and controls should be commensurate with the level of risk and complexity of the business activities. Annual audits of PSPs should at minimum cover the key risks for payment services, namely – Money Laundering and Terrorism Financing (“ML/TF”) risks, loss of customer monies, and technology risks. Other risk areas that could be covered include, but are not limited to, outsourcing risk management and oversight, regulatory reporting, and operational risk. 4.3 For example, areas assessed by the auditor to be of higher inherent risk (e.g. provision of cross border money transfer services, digital payment token services, significant outsourcing arrangements) should be included within the audit scope on an annual basis. New products, services and markets, or implementation of new systems and processes are also key areas that should be audited on a timely basis. For areas that have been assessed by auditors to pose lower inherent risk, auditors could be reviewing and performing sample testing on a rotational basis (e.g. once every 2-3 years). In assessing the audit coverage areas, auditors should take into account: (a) the PSP’s business model; including any new products or services implemented; (b) Emerging risk areas such as new money laundering techniques and typologies; and (c) Any applicable regulations, written directions, notices, guidelines, circulars, information papers issued by MAS.
8 Guidelines on Audit of Payment Service Providers Mandatory Annual Audit Areas for all Licensees 4.4 MAS expects the following mandatory audit areas to be covered during audits on an annual basis. PSPs should provide the appointed auditors with updated and relevant information on a timely basis to facilitate the audit for these mandatory areas: (a) Safeguarding of relevant monies and customer assets in accordance with the safeguarding requirements3 ; (b) Accuracy and completeness of the reported figures in PSN04; (c) Compliance with base capital requirements4 ; (d) Where PSPs are offering exempted products5 pursuant to PSN01, whether the exempted products and services offered continue to meet the exemption criteria; and (e) Remediation of findings from prior external audits and MAS inspections. 5 Mandatory End-to-End Review for New Licensees and Licensees with Newly Licensed Payment Services 5.1 In addition to the mandatory annual audit areas highlighted in Para 4 above, newly licensed PSPs are expected to ensure that auditors perform an end-to-end review ofthe adequacy and operating effectiveness of its risk management systems and controls for the following key risk areas, one year after the commencement of its operations6 : (a) Anti Money Laundering and Terrorism Financing Risk; and (b) Technology Risk. 5.2 Licensed PSPs that have started offering newly licensed payment services should also ensure that the same end-to-end review as set out in Para 5.1 above is performed for the new payment service(s), one year after the commencement of its new payment service(s). 3 Safeguarding requirements in Section 21A/23 of the PS Act (including the relevant Regulations), as well as relevant guidelines, such as PSG03 – Guidelines on the Provision of Consumer Protection Safeguards by Digital Payment Token Service Providers. 4 Regulation 2(2) of the PS Regulations – Base Capital 5 As defined in PSN01 6 For example, if PSP A with a financial year end (FYE) of 31 December 2026 commenced its operations on 1 September 2026, PSP A is expected to ensure the end-to-end review is performed as part of the annual audit for the following year ending 31 December 2027 (i.e. Form 4 due 30 June 2028).
9 Guidelines on Audit of Payment Service Providers (a) Anti-Money Laundering and Countering the Financing of Terrorism (“AML/CFT”) 5.3 Taking into consideration the business model, products, services, funds flows and delivery channels of the PSP, auditors are expected to perform an end-to-end review of the PSP’s AML/CFT risk management and controls, so as to: (a) identify any gaps in the risk management and controls of the PSP to mitigate ML/TF risks and enable compliance with applicable ML/TF regulatory requirements7 ; and (b) assess operating effectiveness of the AML/CFT risk management and controls through sample testing. All findings, observations and recommendations noted from (a) and (b) should be included as part of the management letter and submitted to MAS as part of Form 4. 5.4 The coverage and sampling of the AML/CFT end-to-end review should be commensurate with the level of ML/TF risks, as well as the size and complexity of the PSP’s business. The end-to-end review should cover the following areas8 : • Enterprise-Wide ML/TF Risk Assessment • Compliance arrangements • Customer Due Diligence Process • Name Screening Process • Ongoing Monitoring Process • Wire transfer/ Value transfer Arrangements • Record Keeping Process • Suspicious Transaction Reporting Process • Governance and management oversight of ML/TF risks 7 The regulatory requirements include, but not limited to MAS Notice PS-N01, MAS Notice PS-N02, Guidelines to MAS Notice PSN01 on Prevention of Money Laundering and Countering the Financing of Terrorism, Guidelines to MAS Notice PSN02 on Prevention of Money Laundering and Countering the Financing of Terrorism, Targeted Financial Sanctions under Financial Services and Markets Regulations and Terrorism (Suppression of Financing) Act 2002, MAS Notice SNR-N01 Financial Measures in Relation to Russia, and MAS Notice SNR-N03 Financial Measures in Relation to Violent Israeli Settlers. 8 Appendix C of the AML Audit Peer Group (AAPG) best practice paper includes examples of what to look out for in the end-toend review.
10 Guidelines on Audit of Payment Service Providers 5.5 For subsequent audits, external auditors should review AML/CFT controls on an annual basis. A risk-based approach may be adopted to decide on the scope of coverage of the relevant AML/CFT focus areas for such reviews. For instance, higher inherent risk areas identified or areas where inadequacies/breaches were previously noted should be reviewed and tested on an annual basis, while lower inherent risk areas may be covered on a rotational basis. External auditors should also consider a risk-targeted approach when selecting samples for review, focusing on more higher risk samples rather than on a random basis. (b) Technology Risk 5.6 Auditors are also expected to perform an end-to-end review of the PSP’s technology risk management and internal controls, so as to: (a) identify any gaps in the PSP’s IT operations, functions and processes to mitigate technology risks and enable compliance with applicable Technology & Cyber Security requirements9 ; and (b) assess operating effectiveness of the technology risk management and controls through sample testing. All findings, observations and recommendations noted from (a) and (b) should be included as part of the management letter and submitted to MAS as part of Form 4. 5.7 The coverage of the end-to-end Technology Risk review should be commensurate with the level of technology risks, as well as the complexity of systems and technologies supporting the payment services offered. For example, some PSPs, such as those offering online financial services may face higher inherent technology risks due to the complexity of their IT systems or nature of their products, service and delivery channels, necessitating requirements for a high level of reliability, availability and recoverability of critical IT systems. Therefore, the extent of coverage for such PSPs is expected to be more extensive than for PSPs that do not offer any online financial services. 9 The regulatory requirements include, but not limited to MAS Notice FSM-N13, MAS Notice FSM-N14 and Guidelines on Risk Management Practices – Technology Risk.
11 Guidelines on Audit of Payment Service Providers 5.8 The end-to-end review should include the following areas10 (where relevant): • Cyber Hygiene Practices11 • Tech Risk Governance and Oversight • Technology Risk Management Framework • IT Project Management/Security By Design • Software Application Development and Management • IT Services Management • IT Resilience • Access Control • Cyber Security Operations • Cryptography • Online Financial Services • Data and Infrastructure Security 5.9 For subsequent audits, a risk-based approach may be adopted to determine the scope and frequency of coverage of the relevant technology risk areas. For instance, higher inherent risk areas identified or areas where inadequacies/breaches were previously noted should be reviewed and tested on an annual basis, while lower risk areas may be audited on a rotational basis. External auditors should also consider a risk-targeted approach when selecting samples for review, focusing on more higher risk samples rather than on a random basis. 10 Further details can be found in the Guidelines on Risk Management Practices – Technology Risk. 11 As set out in MAS Notice FSM-N14