Singapore's Financial Regulatory Framework Takes a Major Leap Forward with Licensing Regime for Digital Token Services
Singapore has implemented a stringent licensing regime for digital token services, effective June 30, 2025. The Financial Services and Markets Act 2022 (FSMA) mandates that entities involved in digital token services, even if operating offshore, must navigate a detailed, mandatory licensing regime if operating from or incorporated in Singapore. This move cements Singapore's stance as a jurisdiction with a strict compliance framework for digital token activities.
Key Takeaways:
- The FSMA now requires any individual, partnership, or company offering digital token services from a Singapore-based business location, serving customers outside Singapore, to apply for a Digital Token Service Provider (DTSP) licence.
- Singapore-incorporated businesses conducting DT activities abroad must also obtain a DTSP licence.
- The regime covers a wide range of services, including buying, selling, or transferring digital tokens, facilitating token exchanges, and providing safekeeping services or DT-related advisory.
- Strict licensing standards with no transitional period applied; operators must hold a DTSP licence by June 30, 2025, to continue operations.
- Licences will be granted only under "exceptional conditions," and applicants must demonstrate a clear business rationale for excluding Singaporean clientele, strong AML/CFT controls, and transparent ownership and operational structures.
- Pre-Regulated Entities, such as those licensed under the Payment Services Act, Securities and Futures Act, and Financial Advisers Act, do not need a separate DTSP licence for overlapping activities.
- Compliance Obligations for DTSP Licence Holders include meeting capital and licence fee requirements, establishing internal controls and staffing, and complying with technology risk, cyber hygiene, and AML/CFT expectations.
- Mandatory Audits, Technology Risk Management, Cyber Hygiene Measures, and AML/CFT Expectations are also key compliance requirements.
- Penalties for non-compliance can reach up to SGD 1 million per breach.
Statistics:
- Minimum base capital: SGD 250,000
- Annual licence fee: SGD 10,000 (flat, regardless of size or scope)
- Unscheduled downtime of critical systems: 4 hours annually
- Immediate incident reporting: 1 hour of major breach
- Penalty for non-compliance: up to SGD 1 million per breach
Sources:
- Financial Services and Markets Act 2022 (FSMA)
- Monetary Authority of Singapore (MAS)
- MAS Notice FSM-N30: Technology Risk Management
- MAS Notice FSM-N31: Cyber Hygiene Measures
- MAS Notice FSM-N27: Anti-Money Laundering (AML) and Countering the Financing of Terrorism (CFT) Expectations
- MAS Notice FSM-N32: Operational Days
- MAS Notice FSM-N33: Disclosure