2025-06-30

Added · Updated

Notice TCA-N03 Prevention of Money Laundering and Countering the Financing of Terrorism - Trust Companies

This Notice applies to all licensed trust companies and private trust companies exempted from licensing, taking effect on 1 July 2025. It requires these entities to implement risk-based approaches for assessing and mitigating money laundering and terrorism financing risks, including specific protocols for new products and technologies. The document mandates comprehensive customer due diligence measures, prohibiting anonymous dealings and requiring the identification and verification of trust relevant parties, connected parties, and effective controllers using reliable independent sources. It also establishes obligations to file suspicious transaction reports and disclose trustee status to financial institutions, designated non-financial businesses and professions, and variable capital companies.

Monetary Authority of Singapore logo

Singapore

Monetary Authority of Singapore

Click to view thumbnail

1 MAS Notice TCA-N03 30 June 2025 NOTICE TO TRUST COMPANIES FINANCIAL SERVICES AND MARKETS ACT 2022 PREVENTION OF MONEY LAUNDERING AND COUNTERING THE FINANCING OF TERRORISM – TRUST COMPANIES 1 INTRODUCTION 1.1 This Notice is issued under section 16 of the Financial Services and Markets Act 2022 (“FSM Act”) and applies to all trust companies licensed under section 5 of the Trust Companies Act 2005 (“TCA”) and all private trust companies exempted from licensing under section 15 of the TCA (referred to as “trust companies” in this Notice). 1.2 This Notice shall take effect from 1 July 2025. 2 DEFINITIONS 2.1 For the purposes of this Notice – “AML/CFT” means anti-money laundering1 and countering the financing of terrorism; “Authority” means the Monetary Authority of Singapore; “business contact” means any contact (including the undertaking of any transactions) between the trust company and the trust relevant party in the course of the provision of trust business services by the trust company; “CDD measures” or “customer due diligence measures” means the measures required by paragraph 6; “CDSA” means the Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992; “connected party” – (a) in relation to a legal person (other than a partnership), means any director or any natural person having executive authority in the legal person; 1 In this Notice, money laundering includes proliferation financing, and all references in this Notice to money laundering (including money laundering risks) shall be construed accordingly.

2 (b) in relation to a legal person that is a partnership, means any partner or manager2 ; and (c) in relation to a legal arrangement, means any natural person having executive authority in the legal arrangement; “DNFBP” or “designated non-financial businesses and professions” means any of the following: (a) a casino as defined in section 2(1) of the Casino Control Act 2006 or any casino operating outside of Singapore; (b) an estate agent as defined in section 3(1) of the Estate Agents Act 2010 or any estate agent operating outside of Singapore; (c) a regulated dealer as defined in section 2 of the Precious Stones and Precious Metals (Prevention of Money Laundering and Terrorism) Act 2019 or any dealer in precious metals, precious stones or precious products outside of Singapore; (d) a legal practitioner as defined in section 70A(2) of the Legal Profession Act 1966 or any legal practitioner outside of Singapore; (e) a notary public as defined in section 2 of the Notaries Public Act 1959 or any notary public outside of Singapore; (f) an accountant in public practice3 and any professional firm4 , providing any service described in paragraph 4 of the section “Scope” in the Ethics Pronouncement5 issued by the Council of the Institute of Singapore Chartered Accountants or any equivalent accountant and professional firm outside of Singapore; (g) a trust and company service provider. (h) a developer as defined in section 2 of the Sale of Commercial Properties Act 1979; (i) a housing developer as defined in section 2 of the Housing Developers (Control and Licensing) Act 1965; or (j) a pawnbroker as defined in section 3(1) of the Pawnbrokers Act 2015; “effective controller”, in relation to a trust relevant party, means – 2 In the case of a limited liability partnership or a limited partnership. 3 Accountants in public practice in Singapore includes public accountants as defined in section 2(1) of the Accountants Act 2004. 4 Professional firms include accounting corporations, accounting firms and accounting LLPs approved under s17, 18 and 18A of the Accountants Act 2004 respectively. 5 EP 200 on Anti-Money Laundering and Countering the Financing of Terrorism – Requirements and Guidelines for Professional Accountants in Singapore, issued on 29 October 2014, last updated on 1 June 2023 and as may be updated from time to time

3 (a) the natural person who ultimately owns or controls the trust relevant party; or (b) the natural person on whose behalf business contact is established or maintained, and includes any person who exercises ultimate effective control over the trust relevant party; “FATF” means the Financial Action Task Force; “financial group”, means a group that consists of a legal person or legal arrangement exercising control and coordinating functions over the rest of the group, and its branches and subsidiaries that are financial institutions as defined in section 2 of the FSM Act or the equivalent financial institutions outside Singapore; “government entity” means a government of a country or jurisdiction, a ministry within such a government, or an agency specially established by such a government through written law; “legal arrangement” means a trust or other similar arrangement; “legal person” means an entity other than a natural person that can establish a permanent relationship as a trust relevant party with a financial institution or otherwise own property; “object of a power” means a person who – (a) is a member of a class of possible beneficiaries under the trust; and (b) is reasonably expected to benefit from the trust, whether or not because – (i) the person is referred to as a potential beneficiary by the settlor of the trust in a document relating to the trust such as a letter of wishes; or (ii) the class of possible beneficiaries has narrowed for any reason. “officer” means any director or any member of the committee of management of the trust company; “partnership” means a partnership, a limited partnership within the meaning of the Limited Partnerships Act 2008 or a limited liability partnership within the meaning of the Limited Liability Partnerships Act 2005; “personal data” has the same meaning as defined in section 2(1) of the Personal Data Protection Act 2012; “reasonable measures” means appropriate measures which are commensurate with the level of money laundering or terrorism financing risks; “SFA” means the Securities and Futures Act 2001;

4 “STR” means suspicious transaction report; “STRO” means the Suspicious Transaction Reporting Office, Commercial Affairs Department of the Singapore Police Force; “trust and company service provider” means any of the following persons: (a) a corporate service provider as defined in section 2(1) of the Corporate Service Providers Act 2024 or its equivalent in a foreign jurisdiction; (b) an equivalent in a foreign jurisdiction of a company that carries on any trust business as specified in the First Schedule to the TCA; “trust business” has the same meaning as defined in section 2 of the TCA; “trust companies” means trust companies licensed under section 5 of the TCA and private trust companies exempted from licensing under section 15 of the TCA; “trust relevant party”, in relation to a legal arrangement, means any of the following: (a) the settlor; (b) the trustee; (c) the protector; (d) the beneficiary, class of beneficiaries or object of a power; or (e) any other persons with the power under the legal arrangement instrument or by law to do any of the following: (i) dispose of the property under the legal arrangement; (ii) invest the property under the legal arrangement other than as a trust manager of the legal arrangement; (iii) direct, make or approve distributions of the property under the legal arrangement; (iv) vary or terminate the legal arrangement; (v) add or remove a person as a beneficiary or object of a power under the legal arrangement; or (vi) add a person to, or remove a person from, a class of beneficiaries under the legal arrangement. “TSOFA” means the Terrorism (Suppression of Financing) Act 2002; and

5 “variable capital company” means a body corporate incorporated as such under the Variable Capital Companies Act 2018. 2.2 The expressions used in this Notice shall, except where defined in this Notice or where the context otherwise requires, have the same meanings as in the TCA. 3 UNDERLYING PRINCIPLES 3.1 This Notice is based on the following principles, which shall serve as a guide for all trust companies in the conduct of their operations and business activities: (a) A trust company shall exercise due diligence when dealing with trust relevant parties, natural persons appointed to act on the trust relevant party’s behalf, connected parties of the trust relevant party, effective controllers of the trust relevant party. (b) A trust company shall conduct its business in conformity with high ethical standards, and guard against establishing or maintaining any business contact, that is or may be connected with, or facilitates or may facilitate money laundering or terrorism financing. (c) A trust company shall, to the fullest extent possible, assist and cooperate with the relevant law enforcement authorities in Singapore to prevent money laundering and terrorism financing. (d) Where a trust company establishes any contact (including the undertaking of any transaction) with another financial institution in Singapore or elsewhere, relating to the provision of any trust business services by the trust company to a trust relevant party, the trust company shall disclose to the financial institution that it is acting as a trustee. (e) Where a trust company establishes any contact (including the undertaking of any transaction) with a DNFBP in Singapore or elsewhere, relating to the provision of any trust business services by the trust company to a trust relevant party, the trust company shall disclose to the DNFBP that it is acting as a trustee. (f) Where a trust company establishes any contact (including the undertaking of any transaction) with a variable capital company in Singapore or elsewhere, relating to the provision of any trust business services by the trust company to a trust relevant party, the trust company shall disclose to the variable capital company that it is acting as a trustee. 4 ASSESSING RISKS AND APPLYING A RISK-BASED APPROACH Risk Assessment

6 4.1 A trust company shall take appropriate steps to identify, assess and understand, its money laundering and terrorism financing risks6 in relation to – (a) its trust relevant parties; (b) the countries or jurisdictions its trust relevant parties are from or in; (c) the countries or jurisdictions the trust company has operations in; and (d) the products, services, transactions and delivery channels of the trust company. 4.2 The appropriate steps referred to in paragraph 4.1 shall include - (a) documenting the trust company’s risk assessments; (b) considering all the relevant risk factors before determining the level of overall risk and the appropriate type and extent of mitigation to be applied; (c) keeping the trust company’s risk assessments up-to-date; and (d) having appropriate mechanisms to provide its risk assessment information to the Authority. Risk Mitigation 4.3 A trust company shall - (a) develop and implement policies, procedures and controls, which are approved by senior management, to enable the trust company to effectively manage and mitigate the risks that have been identified by the trust company or notified to it by the Authority or other relevant authorities in Singapore; (b) monitor the implementation of those policies, procedures and controls, and enhance them if necessary; (c) perform enhanced measures where higher risks are identified, to effectively manage and mitigate those higher risks; and (d) ensure that the performance of measures or enhanced measures to effectively manage and mitigate the identified risks addresses the risk assessment and guidance from the Authority or other relevant authorities in Singapore. 5 NEW PRODUCTS, PRACTICES AND TECHNOLOGIES 6 For the avoidance of doubt, money laundering risks include proliferation financing risks.

7 5.1 A trust company shall identify and assess the money laundering and terrorism financing risks that may arise in relation to - (a) the development of new products and new business practices, including new delivery mechanisms; and (b) the use of new or developing technologies for both new and existing products. 5.2 A trust company shall undertake the risk assessments, prior to the launch or use of such products, practices and technologies (to the extent such use is permitted by this Notice), and shall take appropriate measures to manage and mitigate the risks. 5.3 A trust company shall, in complying with the requirements of paragraphs 5.1 and 5.2, pay special attention to any - (a) new products and new business practices, including new delivery mechanisms; and (b) new or developing technologies, that favour anonymity. 6 CUSTOMER DUE DILIGENCE (“CDD”) Anonymous Dealings or Fictitious Names 6.1 No trust company shall establish or maintain business contact with any trust relevant party on an anonymous basis or where the trust relevant party uses a fictitious name. Where There Are Reasonable Grounds for Suspicion prior to the Establishment of Business Contact 6.2 Prior to a trust company establishing business contact, where the trust company has any reasonable grounds to suspect that the assets or funds of a trust relevant party are proceeds of drug dealing or criminal conduct as defined in the CDSA, or are property related to the facilitation or carrying out of any terrorism financing offence as defined in the TSOFA, the trust company shall - (a) not establish business contact with the trust relevant party; and (b) file an STR7 , and extend a copy to the Authority upon request. When CDD is to be Performed 7 Please note in particular section 57 of the CDSA on tipping-off.

8 6.3 A trust company shall perform the measures as required by paragraphs 6, 7 and 8 when – (a) the trust company establishes business contact with any trust relevant party; (b) there is a suspicion of money laundering or terrorism financing, notwithstanding that the trust company would not otherwise be required by this Notice to perform the measures as required by paragraphs 6, 7 and 8; or (c) the trust company has doubts about the veracity or adequacy of any information previously obtained. (I) Identification of Trust Relevant Party and Obtaining Information relating to the Legal Arrangement 6.4 A trust company shall identify each trust relevant party with whom the trust company establishes business contact as follows: (a) in respect of the settlor, trustee and protector of the legal arrangement, before the legal arrangement is constituted; provided that where the settlor has constituted the legal arrangement before establishing business contact with the trust company, the trust company shall identify the settlor, trustee and protector of the legal arrangement before the provision of any trust business services; (b) in respect of each beneficiary (including each beneficiary in a class of beneficiaries) and object of a power of the legal arrangement, as soon as reasonably practicable after the beneficiary or object of a power, as the case may be, becomes identifiable, and in any case before making a distribution to that beneficiary or object of a power, as the case may be, or when that beneficiary or object of a power, as the case may be, intends to exercise vested rights; and (c) in respect of any other trust relevant party, as soon as reasonably practicable after the trust company first comes into business contact with that trust relevant party. 6.5 For the purposes of paragraph 6.4, a trust company shall obtain at least the following information: (a) where the trust relevant party is a natural person, his or her – (i) full name, including any aliases; (ii) unique identification number (such as an identity card number, birth certificate number or passport number); (iii) residential address (iv) date of birth;

9 (v) nationality; and (b) where the trust relevant party is a legal person or legal arrangement – (i) its full name; (ii) its incorporation number, business registration number or tax identification number or its equivalent; (iii) its registered or business address, and if different, its principal place of business; (iv) its date of constitution, incorporation or registration; (v) its place of incorporation or registration; (vi) a copy of the trust deed (or its equivalent)(if any); (vii) the purpose for which the legal person or legal arrangement was set up; (viii) the place from where the legal person or legal arrangement is administered; and (ix) the legal form, constitution, and powers that regulate and bind the legal person or legal arrangements. (c) Notwithstanding paragraphs 6.4 and 6.5, where the trust company has assessed that the money-laundering and terrorism financing risks in relation to a charitable or statutory permitted non-charitable trust are not high, the trust company does not need to identify the beneficiaries of the trust, but it shall document the results of the assessment. 6.6 A trust company shall obtain the following information in relation to a legal arrangement: (a) its full name; (b) its unique identifier such as tax identification number or its equivalent; (c) a copy of the trust deed (or its equivalent); (d) purpose for which the legal arrangement was set up; and (e) place from where the legal arrangement is administered. 6.7 Where the trust relevant party is a legal person or legal arrangement, the trust company shall identify the connected parties of the trust relevant party, by obtaining at least the following information of each connected party: (a) full name, including any aliases; and

10 (b) unique identification number (such as an identity card number, birth certificate number or passport number of the connected party). 6.7A Where the trust company – (a) has assessed that the money laundering and terrorism financing risks in relation to the trust relevant party are not high; and (b) is unable to obtain the unique identification number of the connected party after taking reasonable measures, the trust company may obtain the date of birth and nationality of the connected party, in lieu of the unique identification number. 6.7B The trust company shall document the results of the assessment in paragraph 6.7(A)(a) and all the measures taken under paragraph 6.7(A)(b). (II) Verification of Identity of Trust Relevant Party and information relating to the Legal Arrangement 6.8 A trust company shall verify the identity of each trust relevant party with whom the trust company establishes business contact as follows – (a) in respect of the settlor, trustee and protector of the legal arrangement, before the legal arrangement is constituted; provided that where the settlor has constituted the legal arrangement before establishing business contact with the trust company, the trust company shall verify the identities of the settlor, trustee and protector of the legal arrangement before the provision of any trust business services; (b) in respect of each beneficiary (including each beneficiary in a class of beneficiaries) and object of a power of the legal arrangement, as soon as reasonably practicable after the beneficiary or object of a power, as the case may be, becomes identifiable, and in any case before making a distribution to that beneficiary or object of a power, as the case may be, or when that beneficiary or object of a power, as the case may be, intends to exercise vested rights; and (c) in respect of any other trust relevant party, as soon as reasonably practicable after the trust company first comes into business contact with that trust relevant party. 6.9 A trust company shall verify the identity of the trust relevant party and the information obtained relating to the legal arrangement using reliable, independent source data, documents or information. Where the trust relevant party is a legal person or legal arrangement, a trust company shall verify the legal form, proof of existence, constitution and powers that regulate and bind the trust relevant party, using reliable, independent source data, documents or information.

11 (III) Identification and Verification of Identity of Natural Person Appointed to Act on a Trust Relevant Party’s Behalf 6.10 Where a trust relevant party appoints one or more natural persons to act on the trust relevant party’s behalf in establishing business contact with a trust company, the trust company shall - (a) identify each natural person who acts or is appointed to act on behalf of the trust relevant party by obtaining at least the following information of such natural person: (i) full name, including any aliases; (ii) unique identification number (such as an identity card number, birth certificate number or passport number); (iii) residential address; (iv) date of birth; (v) nationality; and (b) verify the identity of each natural person8 using reliable, independent source data, documents or information. 6.11 A trust company shall verify the due authority of each natural person appointed to act on behalf of the trust relevant party by:- (a) obtaining the appropriate documentary evidence authorising the appointment of such natural person by the trust relevant party to act on the customer’s behalf; and (b) verifying that such natural person is the person authorised to act on the trust relevant party’s behalf, through methods which include obtaining the person’s specimen signature or electronic means of verification. 6.11A Where the trust company – (a) has assessed that the money laundering and terrorism financing risks of the trust relevant party are not high; and (b) is unable to obtain the residential address of the natural person who acts or is appointed to act on behalf of the trust relevant party after taking reasonable measures, 8 For the avoidance of doubt, the identity of a natural person appointed by a trust relevant party to act on the latter’s behalf shall be verified at such time that the identity of the trust relevant party is required to be verified under paragraph 6.8.

12 the trust company may obtain the business address of this natural person, in lieu of the residential address. 6.11B Where the trust company has obtained the business address of the natural person referred to in paragraph 6.11A, the trust company shall take reasonable measures to verify the business address using reliable, independent source data, documents or information. 6.11C The trust company shall document the results of the assessment in paragraph 6.11A(a) and all the measures taken under paragraph 6.11A(b). 6.12 Where the trust relevant party is a Singapore Government entity, the trust company shall only be required to obtain such information as may be required to confirm that the trust relevant party is a Singapore Government entity as asserted. (IV) Identification and Verification of Identity of Effective Controller 6.13 Subject to paragraph 6.16, a trust company shall inquire if there exists any effective controller in relation to a trust relevant party. 6.14 Where there is one or more effective controllers in relation to a trust relevant party, the trust company shall identify the effective controllers before the trust is constituted (provided that where the settlor has constituted the trust before establishing business contact with the trust company, the trust company shall identify the effective controllers before the provision of any trust business services). For the purposes of identifying the effective controllers, the trust company shall – (a) for trust relevant parties that are legal persons - (i) identify the natural persons (whether acting alone or together) who ultimately own the trust relevant party; (ii) to the extent that there is doubt under subparagraph (i) as to whether the natural persons who ultimately own the trust relevant party are the effective controllers or where no natural persons ultimately own the trust relevant party, identify the natural persons (if any) who ultimately control the trust relevant party or have ultimate effective control of the trust relevant party; and (iii) where no natural persons are identified under subparagraphs (i) or (ii), identify the natural persons having executive authority in the trust relevant party, or in equivalent or similar positions; (b) for trust relevant parties that are legal arrangements - (i) for trusts, identify the trust relevant parties, any natural person exercising ultimate ownership, ultimate control or ultimate effective control (including through a chain of control or ownership) over the trust relevant parties or

13 the trust, and any legal person or legal arrangement along such chain of control or ownership; and (ii) for other types of legal arrangements, identify persons in equivalent or similar positions, as those described under subparagraph (i). 6.14A For the purposes of paragraph 6.14, a trust company shall obtain at least the following information: (a) where the person identified under paragraph 6.14 is a natural person, his or her – (i) full name, including any aliases; (ii) unique identification number (such as an identity card number, birth certificate number or passport number); (iii) residential address; (iv) date of birth; and (v) nationality. (b) where the person identified under paragraph 6.14 is a legal person or legal arrangement – (i) its full name; (ii) its incorporation number, business registration number or tax identification number or its equivalent; (iii) its registered or business address, and if different, its principal place of business; (iv) its date of constitution, incorporation or registration; (v) its place of incorporation or registration; (vi) a copy of the trust deed (or its equivalent)(if any); (vii) the purpose for which the legal person or legal arrangement was set up; (viii) the place from where the legal person or legal arrangement is administered; and (ix) the legal form, constitution and powers that regulate and bind the legal person or legal arrangement. 6.14B A trust company shall take reasonable steps to verify the identity of each person identified under paragraph 6.14 as follows –

14 (a) before the trust is constituted (provided that where the settlor has constituted the trust before establishing business contact with the trust company, the trust company shall verify the identity of the person identified under paragraph 6.14 before the provision of any trust business services); and (b) using reliable, independent source data, documents or information. For each person identified under paragraph 6.14 that is a legal person or legal arrangement, a trust company shall verify the legal form, proof of existence, constitution and powers that regulate and bind the legal person or legal arrangement, using reliable, independent source data, documents or information. 6.14C Where the trust company – (a) has assessed that the money laundering and terrorism financing risks in relation to the customer are not high; and (b) is unable to obtain the unique identification number and/or residential address of the person identified under paragraph 6.14 after taking reasonable measures, the trust company may obtain the date of birth and nationality of the person identified under paragraph 6.14, in lieu of the unique identification number, and the business address of the person identified under paragraph 6.14, in lieu of the residential address. 6.14D The trust company shall document the results of the assessment in paragraph 6.14C(a) and all the measures taken under paragraph 6.14C(b). 6.15 Where the trust relevant party is not a natural person, the trust company shall understand the nature of the trust relevant party’s business and its ownership and control structure. 6.16 A trust company shall not be required to inquire if there exists any effective controller in relation to a trust relevant party that is - (a) an entity listed and traded on the Singapore Exchange; (b) an entity listed on a stock exchange outside of Singapore that is subject to - (i) regulatory disclosure requirements; and (ii) requirements relating to adequate transparency in respect of its effective controllers (imposed through stock exchange rules, law or other enforceable means); (c) a financial institution set out in Appendix 1; (d) a financial institution incorporated or established outside Singapore that is subject to and supervised for compliance with AML/CFT requirements consistent with standards set by the FATF; or

15 (e) an investment vehicle where the managers are financial institutions - (i) set out in Appendix 1; or (ii) incorporated or established outside Singapore but are subject to and supervised for compliance with AML/CFT requirements consistent with standards set by the FATF, unless the trust company has doubts about the veracity of the CDD information, or suspects that the trust relevant party or business contact with the trust relevant party, may be connected with money laundering or terrorism financing. 6.17 For the purposes of paragraphs 6.16(d) and 6.16(e)(ii), a trust company shall document the basis for its determination that the requirements in those paragraphs have been duly met. (V) Information on the Purpose and Intended Nature of Business Contact 6.18 A trust company shall, when processing the application to establish business contact, understand and as appropriate, obtain from the trust relevant party information as to the purpose and intended nature of business contact. (VI) Ongoing Monitoring 6.19 A trust company shall monitor on an ongoing basis, its business contact with trust relevant parties. 6.20 A trust company shall, within the scope of establishing or maintaining business contact with a trust relevant party, scrutinise transactions undertaken to ensure that the transactions are consistent with the trust company’s knowledge of the trust relevant party, its business and risk profile and where appropriate, the source of funds. 6.21 A trust company shall pay special attention to all complex, unusually large or unusual patterns of transactions, undertaken in the course of business contact, that have no apparent or visible economic or lawful purpose. 6.22 For the purposes of ongoing monitoring, a trust company shall put in place and implement adequate systems and processes, commensurate with the size and complexity of the trust company, to - (a) monitor its business contact with trust relevant parties; and (b) detect and report suspicious, complex, unusually large or unusual patterns of transactions. 6.23 A trust company shall, to the extent possible, inquire into the background and purpose of the transactions in paragraph 6.21 and document its findings with a view to making this information available to the relevant authorities should the need arise.

16 6.24 A trust company shall ensure that CDD data, documents and information obtained in respect of the legal arrangement, trust relevant parties, natural persons appointed to act on behalf of the trust relevant parties, connected parties of the trust relevant parties, effective controllers of a trust relevant party, are relevant and kept up-to-date by undertaking reviews of existing CDD data, documents and information, particularly for higher risk categories of trust relevant parties. 6.25 Where there are any reasonable grounds for suspicion that existing business contact with a trust relevant party are connected with money laundering or terrorism financing, and where the trust company considers it appropriate to continue business contact with the trust relevant party - (a) the trust company shall substantiate and document the reasons for continuing business contact with the trust relevant party; and (b) the trust relevant party’s business contact with the trust company shall be subject to commensurate risk mitigation measures, including enhanced ongoing monitoring. 6.26 Where the trust company assesses the trust relevant party or the business contact with the trust relevant party referred to in paragraph 6.25 to be of higher risk, the trust company shall perform enhanced CDD measures, which shall include obtaining the approval of the trust company’s senior management to continue business contact with the trust relevant party. CDD Measures for Non-Face-to-Face Business Contact 6.27 A trust company shall develop policies and procedures to address any specific risks associated with non-face-to-face business contact with a trust relevant party. 6.28 A trust company shall implement the policies and procedures referred to in paragraph 6.27 when establishing business contact with a trust relevant party and when conducting ongoing due diligence. 6.29 Where there is no face-to-face contact, the trust company shall perform CDD measures that are at least as robust as those that would be required to be performed if there was face-to-face contact. Reliance by Acquiring Trust Company on Measures Already Performed 6.30 When a trust company (“acquiring trust company”) acquires, either in whole or in part, the business of another financial institution (whether in Singapore or elsewhere), the acquiring trust company shall perform the measures as required by paragraphs 6, 7 and 8, on the trust relevant parties acquired with the business at the time of acquisition except where the acquiring trust company has –

17 (a) acquired at the same time all corresponding records of the trust relevant parties (including CDD information) and has no doubt or concerns about the veracity or adequacy of the information so acquired; and (b) conducted due diligence enquiries that have not raised any doubt on the part of the acquiring trust company as to the adequacy of AML/CFT measures previously adopted in relation to the business or part thereof now acquired by the acquiring trust company, and document such enquiries. Where Measures are Not Completed 6.31 Where the trust company is unable to complete the measures as required by paragraphs 6, 7 and 8, it shall not commence or continue business contact with any trust relevant party. The trust company shall consider if the circumstances are suspicious so as to warrant the filing of an STR. 6.32 For the purposes of paragraph 6.31, completion of the measures means the situation where the trust company has obtained, screened and verified all necessary CDD information required under paragraphs 6, 7 and 8, and where the trust company has received satisfactory responses to all inquiries in relation to such necessary CDD information. Existing Trust Relevant Parties 6.33 Where there is any subsequent revision to this Notice resulting in a change in the measures as required under paragraphs 6, 7 and 8, a trust company shall perform the measures as required by paragraphs 6, 7 and 8 in relation to its existing trust relevant parties, based on its own assessment of materiality and risk, taking into account any previous measures applied, the time when the measures were last applied to such existing trust relevant parties and the adequacy of data, documents or information obtained. Screening 6.34 A trust company shall screen a trust relevant party, natural persons appointed to act on behalf of the trust relevant party, connected parties of the trust relevant party, effective controllers of a trust relevant party against relevant money laundering and terrorism financing information sources, as well as lists and information provided by the Authority or other relevant authorities in Singapore for the purposes of determining if there are any money laundering or terrorism financing risks in relation to the trust relevant party. 6.35 A trust company shall screen the persons referred to in paragraph 6.34 - (a) in respect of the settlor, trustee and protector of the legal arrangement, before the legal arrangement is constituted; provided that where the settlor has constituted the legal arrangement before establishing business contact with the trust company, the trust company shall screen the settlor, trustee and protector of the legal arrangement before the provision of any trust business services;

18 (b) in respect of each beneficiary (including each beneficiary in a class of beneficiaries) and object of a power, if any, of the legal arrangement, as soon as reasonably practicable after the beneficiary or object of a power, as the case may be, becomes identifiable, and in any case before making a distribution to that beneficiary or object of a power, as the case may be, or when that beneficiary or object of a power, as the case may be, intends to exercise vested rights; (c) in respect of any other trust relevant party, as soon as reasonably practicable after the trust company first comes into business contact with that trust relevant party; (d) on a periodic basis after the trust company establishes business contact with the trust relevant party; and (e) when there are any changes or updates to - (i) the lists and information provided by the Authority or other relevant authorities in Singapore to the trust company; or (ii) the natural persons appointed to act on behalf of a trust relevant party, connected parties of a trust relevant party, effective controllers of a trust relevant party. 6.36 The results of screening and assessment by the trust company shall be documented. 7 SIMPLIFIED CUSTOMER DUE DILIGENCE 7.1 Subject to paragraph 7.4, a trust company may perform simplified CDD measures in relation to a trust relevant party, any natural person appointed to act on behalf of the trust relevant party and any effective controller of a trust relevant party (other than any effective controller that the trust company is exempted from making inquiries about under paragraph 6.16) if it is satisfied that the risks of money laundering and terrorism financing are low. 7.2 The assessment of low risks shall be supported by an adequate analysis of risks by the trust company. 7.3 The simplified CDD measures shall be commensurate with the level of risk, based on the risk factors identified by the trust company. 7.4 A trust company shall not perform simplified CDD measures – (a) where a trust relevant party and any effective controller of a trust relevant party is from or in a country or jurisdiction in relation to which the FATF has called for countermeasures;

19 (b) where a trust relevant party and any effective controller of a trust relevant party is from or in a country or jurisdiction known to have inadequate AML/CFT measures, as determined by the trust company for itself, or notified to trust companies generally by the Authority, or other foreign regulatory authorities; or (c) where the trust company suspects that money laundering or terrorism financing is involved. 7.5 Subject to paragraphs 7.2, 7.3 and 7.4, a trust company may perform simplified CDD measures in relation to a trust relevant party that is a financial institution set out in Appendix 2. 7.6 Where the trust company performs simplified CDD measures in relation to a trust relevant party, any natural person appointed to act on behalf of the trust relevant party and any effective controller of a trust relevant party, it shall document - (a) the details of its risk assessment; and (b) the nature of the simplified CDD measures. 7.7 For avoidance of doubt, the term “CDD measures” in paragraph 7 means the measures required by paragraph 6. 8 ENHANCED CUSTOMER DUE DILIGENCE Politically Exposed Persons 8.1 For the purposes of paragraph 8 - “close associate” means a natural person who is closely connected to a politically exposed person, either socially or professionally; “domestic politically exposed person” means a natural person who is or has been entrusted domestically with prominent public functions; “family member” means a parent, step-parent, child, step-child, adopted child, spouse, sibling, step-sibling and adopted sibling of the politically exposed person; “foreign politically exposed person” means a natural person who is or has been entrusted with prominent public functions in a foreign country or jurisdiction; “international organisation” means an entity established by formal political agreements between member countries or jurisdictions that have the status of international treaties, whose existence is recognised by law in member countries or jurisdictions and which is not treated as a resident institutional unit of the country or jurisdiction in which it is located;

20 “international organisation politically exposed person” means a natural person who is or has been entrusted with prominent public functions in an international organisation; “politically exposed person” means a domestic politically exposed person, foreign politically exposed person or international organisation politically exposed person; and “prominent public functions” includes the roles held by a head of state, a head of government, government ministers, senior civil or public servants, senior judicial or military officials, senior executives of state owned corporations, senior political party officials, members of the legislature and senior management of international organisations. 8.2 A trust company shall implement appropriate internal risk management systems, policies, procedures and controls to determine if a trust relevant party, any natural person appointed to act on behalf of the trust relevant party, any connected party of the trust relevant party, or any effective controller of the trust relevant party is a politically exposed person, or a family member or close associate of a politically exposed person. 8.3 A trust company shall, in addition to performing CDD measures (specified in paragraph 6), perform at least the following enhanced CDD measures where a trust relevant party, or any effective controller of the trust relevant party is determined by the trust company to be a politically exposed person, or a family member or close associate of a politically exposed person under paragraph 8.2: (a) obtain approval from the trust company’s senior management to establish or continue business contact with the trust relevant party; (b) establish, by appropriate and reasonable means, the source of wealth and source of funds of the trust relevant party, or any effective controller of the trust relevant party; and (c) conduct, during the course of business contact with the trust relevant party, enhanced monitoring of business contact with the trust relevant party. In particular, the trust company shall increase the degree and nature of monitoring of the business contact with, and transactions undertaken in the course of business contact with, the trust relevant party, in order to determine whether they appear unusual or suspicious. 8.4 A trust company may adopt a risk-based approach in determining whether to perform enhanced CDD measures or the extent of enhanced CDD measures to be performed for

(a) domestic politically exposed persons, their family members and close associates; (b) international organisation politically exposed persons, their family members and close associates; or

21 (c) politically exposed persons who have stepped down from their prominent public functions, taking into consideration the level of influence such persons may continue to exercise after stepping down from their prominent public functions, their family members and close associates, except in cases where their business contact with the trust company present a higher risk for money laundering or terrorism financing. Other Higher Risk Categories 8.5 A trust company shall implement appropriate internal risk management systems, policies, procedures and controls to determine if business contact with any trust relevant party presents a higher risk for money laundering or terrorism financing. 8.6 For the purposes of paragraph 8.5, circumstances where a trust relevant party presents or may present a higher risk for money laundering or terrorism financing include but are not limited to the following: (a) where a trust relevant party, or any effective controller of the trust relevant party is from or in a country or jurisdiction in relation to which the FATF has called for countermeasures, the trust company shall treat any business contact with such trust relevant party as presenting a higher risk for money laundering or terrorism financing; (b) where a trust relevant party, or any effective controller of the trust relevant party is from or in a country or jurisdiction known to have inadequate AML/CFT measures, as determined by the trust company for itself, or notified to trust companies generally by the Authority or other foreign regulatory authorities, the trust company shall assess whether any such trust relevant party presents a higher risk for money laundering or terrorism financing; and (c) where a trust relevant party is a legal person for which the trust company is not able to establish if it has any – (i) ongoing, apparent or visible operation or business activity; (ii) economic or business purpose for its corporate structure or arrangement; or (iii) substantive financial activity in its interactions with the trust company, the trust company shall assess whether any such trust relevant party presents a higher risk for money laundering or terrorism financing. 8.7 A trust company shall perform the appropriate enhanced CDD measures in paragraph 8.3 for business contact with any trust relevant party - (a) who the trust company determines under paragraph 8.5; or

22 (b) the Authority or other relevant authorities in Singapore notify to the trust company, as presenting a higher risk for money laundering or terrorism financing. 8.8 A trust company shall, in taking enhanced CDD measures to manage and mitigate any higher risks that have been identified by the trust company, or notified to it by the Authority or other relevant authorities in Singapore, ensure that the enhanced CDD measures take into account the requirements of any laws, regulations or directions administered by the Authority, including but not limited to the regulations or directions issued by the Authority under section 192 read with section 15(1)(b) of the FSM Act, and section 15(1)(a) of the FSM Act, respectively. 9 RELIANCE ON THIRD PARTIES 9.1 For the purposes of paragraph 9 - “third party” means – (a) a financial institution set out in Appendix 2; (b) a financial institution which is subject to and supervised by a foreign authority for compliance with AML/CFT requirements consistent with standards set by the FATF (other than a Foreign FI); (c) in relation to a trust company incorporated in Singapore, its branches, subsidiaries, parent entity, the branches and subsidiaries of the parent entity, and other related corporations (other than an Entity X); or (d) in relation to a trust company incorporated outside Singapore, its head office, its parent entity, the branches and subsidiaries of the head office, the branches and subsidiaries of the parent entity, and other related corporations (other than an Entity X); “Foreign FI” means a financial institution which – (a) is subject to and supervised by a foreign authority for compliance with AML/CFT requirements consistent with standards set by the FATF; (b) holds a licence equivalent to a payment services licence under the Payment Services Act 2019 or a digital token service provider licence under the FSM Act; and (c) does not hold any other financial services licence other than the licence mentioned in subparagraph (b); and

23 “Entity X” means an entity which – (a) holds a payment services licence under the Payment Services Act 2019 or a digital token service provider licence under the FSM Act, or equivalent licences; and (b) does not hold any other financial services licence other than the licence mentioned in subparagraph (a). 9.2 Subject to paragraph 9.3, a trust company may rely on a third party to perform the measures as required by paragraphs 6, 7 and 8 if the following requirements are met: (a) the trust company is satisfied that the third party it intends to rely upon is subject to and supervised for compliance with AML/CFT requirements consistent with standards set by the FATF, and has adequate AML/CFT measures in place to comply with those requirements; (b) the trust company takes appropriate steps to identify, assess and understand the money laundering and terrorism financing risks particular to the countries or jurisdictions that the third party operates in; (c) the third party is not one which trust companies have been specifically precluded by the Authority from relying upon; and (d) the third party is able and willing to provide, without delay, upon the trust company’s request, any data, documents or information obtained by the third party with respect to the measures applied on the trust relevant party, which the trust company would be required or would want to obtain. 9.3 No trust company shall rely on a third party to conduct ongoing monitoring of business contact with trust relevant parties. 9.4 Where a trust company relies on a third party to perform the measures as required by paragraphs 6, 7 and 8, it shall - (a) document the basis for its satisfaction that the requirements in paragraphs 9.2(a) and (b) have been met, except where the third party is a financial institution set out in Appendix 2; and (b) immediately obtain from the third party the CDD information which the third party had obtained. 9.5 For the avoidance of doubt, notwithstanding the reliance upon a third party, the trust company shall remain responsible for its AML/CFT obligations in this Notice. 10 RECORD KEEPING

24 10.1 A trust company shall, in relation to all data, documents and information that the trust company is required to obtain or produce to meet the requirements under this Notice, prepare, maintain and retain records of such data, documents and information. 10.2 A trust company shall perform the measures as required by paragraph 10.1 such that - (a) all requirements imposed by law (including this Notice) are met; (b) any individual transaction undertaken by the trust company in the course of business contact can be reconstructed (including the amount and type of currency involved) so as to provide, if necessary, evidence for prosecution of criminal activity; (c) the Authority or other relevant authorities in Singapore and the internal and external auditors of the trust company are able to review the trust company’s business contact, records and CDD information and assess the level of compliance with this Notice; and (d) the trust company can satisfy, within a reasonable time or any more specific time period imposed by law or by the requesting authority, any enquiry or order from the relevant authorities in Singapore for information. 10.3 Subject to paragraph 10.5 and any other requirements imposed by law, a trust company shall, for the purposes of record retention under paragraphs 10.1 and 10.2, and when setting its record retention policies, comply with the following record retention periods: (a) for CDD information relating to the business contact and transactions undertaken in the course of business contact, as well as account files, business correspondence and results of any analysis undertaken, a period of at least 5 years following the termination of such business contact or completion of such transactions; and (b) for data, documents and information relating to a transaction undertaken in the course of business contact, including any information needed to explain and reconstruct the transaction, a period of at least 5 years following the completion of the transaction. 10.4 A trust company may retain data, documents and information as originals or copies, in paper or electronic form or on microfilm, provided that they are admissible as evidence in a Singapore court of law. 10.5 A trust company shall retain records of data, documents and information on all its business contact with a trust relevant party pertaining to a matter which is under investigation or which has been the subject of an STR, in accordance with any request or order from STRO or other relevant authorities in Singapore. 11 PERSONAL DATA

25 11.1 For the purposes of paragraph 11, “individual” means a natural person, whether living or deceased. 11.2 Subject to paragraph 11.3 and for the purposes of complying with this Notice, a trust company shall not be required to provide an individual trust relevant party, an individual appointed to act on behalf of a trust relevant party, an individual connected party of a trust relevant party, or an individual effective controller of a trust relevant party, with - (a) any access to personal data about the individual that is in the possession or under the control of the trust company; (b) any information about the ways in which the personal data of the individual under subparagraph (a) has been or may have been used or disclosed by the trust company; and (c) any right to correct an error or omission of the personal data about the individual that is in the possession or under the control of the trust company. 11.3 A trust company shall, as soon as reasonably practicable, upon the request of an individual trust relevant party, an individual appointed to act on behalf of a trust relevant party, an individual connected party of a trust relevant party, or an individual effective controller of a trust relevant party, provide the requesting individual with the right to - (a) access the following types of personal data of that individual, that is in the possession or under the control of the trust company: (i) the individual’s full name, including any alias; (ii) the individual’s unique identification number (such as an identity card number, birth certificate number or passport number); (iii) the individual’s residential address; (iv) the individual’s date of birth; (v) the individual’s nationality; (vi) subject to sections 21(2) and (3) read with the Fifth Schedule to the Personal Data Protection Act 2012, any other personal data of the respective individual provided by that individual to the trust company; and (b) subject to section 22(7) read with the Sixth Schedule to the Personal Data Protection Act 2012, correct an error or omission in relation to the types of personal data set out in subparagraphs (a)(i) to (vi), provided the trust company is satisfied that there are reasonable grounds for such request. 11.4 For the purposes of complying with this Notice, a trust company may, whether directly or through a third party, collect, use and disclose personal data of an individual trust relevant party, an individual appointed to act on behalf of a trust relevant party, an individual

26 connected party of a trust relevant party, or an individual effective controller of a trust relevant party, without the respective individual’s consent. 12 SUSPICIOUS TRANSACTIONS REPORTING 12.1 A trust company shall keep in mind the provisions in the CDSA9 and in the TSOFA that provide for the reporting to the authorities of transactions suspected of being connected with money laundering or terrorism financing and implement appropriate internal policies, procedures and controls for meeting its obligations under the law, including the following: (a) establish a single reference point within the organisation to whom all employees and officers are instructed to promptly refer all transactions suspected of being connected with money laundering or terrorism financing, for possible referral to STRO via STRs; and (b) keep records of all transactions referred to STRO, together with all internal findings and analysis done in relation to them. 12.2 A trust company shall promptly submit reports on suspicious transactions (including attempted transactions), regardless of the amount of the transaction, to STRO, and extend a copy to the Authority upon request. 12.3 A trust company shall consider if the circumstances are suspicious so as to warrant the filing of an STR and document the basis for its determination, including where – (a) the trust company is for any reason unable to complete the measures as required by paragraphs 6, 7 and 8; or (b) the trust relevant party is reluctant, unable or unwilling to provide any information requested by the trust company, or decides to withdraw a pending application to establish business contact or to terminate existing business contact. 12.4 Where a trust company forms a suspicion of money laundering or terrorism financing, and reasonably believes that performing any of the measures as required by paragraphs 6, 7 or 8 will tip-off a trust relevant party, a natural person appointed to act on behalf of the trust relevant party, a connected party of the trust relevant party, or an effective controller of a trust relevant party, the trust company may stop performing those measures. The trust company shall document the basis for its assessment and file an STR. 13 INTERNAL POLICIES, COMPLIANCE, AUDIT AND TRAINING 13.1 A trust company shall develop and implement adequate internal policies, procedures and controls, taking into consideration its money laundering and terrorism financing risks and 9 Please note in particular section 57 of the CDSA on tipping-off.

27 the size of its business, to help prevent money laundering and terrorism financing and communicate these to its employees. 13.2 The policies, procedures and controls shall meet all the requirements of this Notice. Group Policy 13.3 For the purposes of paragraphs 13.4 to 13.9, a reference to a “trust company” means a trust company incorporated in Singapore. 13.4 A trust company shall develop a group policy on AML/CFT to meet all the requirements of this Notice and extend this to all of its branches and subsidiaries in its financial group. 13.5 Where a trust company has a branch or subsidiary in a host country or jurisdiction - (a) in relation to which the FATF has called for countermeasures; or (b) known to have inadequate AML/CFT measures, as determined by the trust company for itself, or notified to trust companies generally by the Authority or other foreign regulatory authorities, the trust company shall ensure that its group policy on AML/CFT is strictly observed by the management of that branch or subsidiary. 13.6 Subject to the trust company putting in place adequate safeguards to protect the confidentiality and use of any information that is shared, the trust company shall develop and implement group policies and procedures for its branches and subsidiaries within the financial group, to share information required for the purposes of CDD, and for money laundering and terrorism financing risk management, to the extent permitted by the law of the countries or jurisdictions that its branches and subsidiaries are in. 13.7 Such policies and procedures shall include the provision, to the trust company’s group￾level compliance, audit, and AML/CFT functions, of trust relevant party and business contact information from its branches and subsidiaries within the financial group, when necessary for money laundering and terrorism financing risk management purposes. 13.7A For the purposes of this paragraph 13.7, the information to be shared within the trust company’s financial group shall include any information and analysis of transactions or activities that appear unusual.10 13.8 Where the AML/CFT requirements in the host country or jurisdiction differ from those in Singapore, the trust company shall require that the overseas branch or subsidiary apply the higher of the two standards, to the extent that the law of the host country or jurisdiction so permits. 10 Subject to section 57 of the CDSA on tipping-off, information shared may include an STR, the underlying information of the STR, or the fact that an STR was filed.

28 13.9 Where the law of the host country or jurisdiction conflicts with Singapore law such that the overseas branch or subsidiary is unable to fully observe the higher standard, the trust company shall apply additional appropriate measures to manage the money laundering and terrorism financing risks, report this to the Authority and comply with such further directions as may be given by the Authority. 13.9A In the case of a Singapore branch of a trust company incorporated outside Singapore, subject to the Singapore branch putting in place adequate safeguards to protect the confidentiality and use of any information that is shared, the Singapore branch shall share customer, account and transaction information within the trust company’s financial group when necessary for money laundering and terrorism financing risk management purposes. Such information to be shared within the trust company’s financial group shall include any information and analysis of transactions or activities that appear unusual.11 Compliance 13.10 A trust company shall develop appropriate compliance management arrangements, including at least, the appointment of an AML/CFT compliance officer at the management level. 13.11 A trust company shall ensure that the AML/CFT compliance officer, as well as any other persons appointed to assist the AML/CFT compliance officer, is suitably qualified, and has adequate resources and timely access to all records of trust relevant parties and other relevant information which the AML/CFT compliance officer requires to discharge the AML/CFT compliance officer’s functions. Audit 13.12 A trust company shall maintain an audit function that is adequately resourced and independent, and that is able to regularly assess the effectiveness of the trust company’s internal policies, procedures and controls, and its compliance with regulatory requirements. Employee Hiring 13.13 A trust company shall have in place screening procedures to ensure high standards when hiring employees and appointing officers. Training 13.14 A trust company shall take all appropriate steps to ensure that its employees and officers (whether in Singapore or elsewhere) are regularly and appropriately trained on - (a) AML/CFT laws and regulations, and in particular, CDD measures, and detecting and reporting of suspicious transactions; 11 Subject to section 57 of the CDSA on tipping-off, information shared may include an STR, the underlying information of the STR, or the fact that an STR was filed.

29 (b) prevailing techniques, methods and trends in money laundering and terrorism financing; and (c) the trust company’s internal AML/CFT policies, procedures and controls, and the roles and responsibilities of employees and officers in combating money laundering and terrorism financing.

30 Appendix 1

  1. Financial institutions that are licensed, approved, registered or regulated by the Authority but does not include a person (other than a person referred to in paragraphs 2 and 3) who is exempted from licensing, approval or regulation by the Authority under any Act administered by the Authority, including a private trust company exempted from licensing under section 15 of the TCA read with regulation 4 of the Trust Companies (Exemption) Regulations (Rg. 1).
  2. Persons exempted under section 20(1)(g) of the Financial Advisers Act 2001 read with regulation 27(1)(d) of the Financial Advisers Regulations (Rg. 2).
  3. Persons exempted under section 99(1)(h) of the SFA read with paragraph 7(1)(b) of the Second Schedule to the Securities and Futures (Licensing and Conduct of Business) Regulations (Rg. 10). Note: For the avoidance of doubt, the financial institutions set out in Appendix 2 fall within Appendix 1.

31 Appendix 2

  1. Banks in Singapore licensed under the Banking Act 1970.
  2. Merchant banks in Singapore licensed under the Banking Act 1970.
  3. Finance companies licensed under section 6 of the Finance Companies Act 1967.
  4. Financial advisers licensed under section 6 of the Financial Advisers Act 2001 except those which only provide advice by issuing or promulgating research analyses or research reports, whether in electronic, print or other form, concerning any investment product.
  5. Holders of a capital markets services licence under section 82 of the SFA.
  6. Persons exempted under section 20(1)(g) of the Financial Advisers Act 2001 read with regulation 27(1)(d) of the Financial Advisers Regulations (Rg. 2) except those which only provide advice by issuing or promulgating research analyses or research reports, whether in electronic, print or other form, concerning any investment product.
  7. Persons exempted under section 99(1)(h) of the SFA read with paragraph 7(1)(b) of the Second Schedule to the Securities and Futures (Licensing and Conduct of Business) Regulations (Rg. 10).
  8. Approved trustees approved under section 289 of the SFA.
  9. Trust companies licensed under section 5 of the TCA.
  10. Direct life insurers licensed under section 11 of the Insurance Act 1966.
  11. Insurance brokers registered under the Insurance 1966 Act which, by virtue of such registration, are exempted under section 20(1)(c) of the Financial Advisers Act 2001 except those which only provide advice by issuing or promulgating research analyses or research reports, whether in electronic, print or other form, concerning any investment product.

More like this from MAS

We email you every new MAS publication the day it's published.

Topics
Share