Search Ocorian

Asian businesswoman communicating with male colleague, discussing project, collaborating in modern office lounge

MAS raises the bar on payment service providers’ annual audits – internal audit function isn't going anywhere

29 September, 2026

The Monetary Authority of Singapore (MAS) has issued its Guidelines on Audit of Payment Service Providers (Guidelines), which set out clear expectations for the annual audit of all licensed payment service providers (PSPs). The Guidelines introduce structured audit requirements, establish a baseline and mandatory audit scope, and require additional reviews for newly licensed PSPs and newly licensed payment services. It also reinforces the importance of strong compliance and internal audit (IA) functions.

The Guidelines were issued in July 2026 and apply to all PSPs. They reflect MAS’ continued focus on strengthening governance, accountability and risk management across Singapore's payments ecosystem. As payment services become increasingly digital, interconnected and technology-dependent, MAS expects PSPs to demonstrate that their policies, procedures and internal controls are operating effectively and remain aligned with regulatory expectations.

The Guidelines also reinforce the importance of strong compliance and IA functions. These are seen as critical since they help PSPs to strengthen their control environment to achieve more favourable audit outcomes by constantly identifying gaps in policies and controls.
 

Annual audit requirements

Under the Guidelines, every PSP must undergo an annual external audit and submit an audit report to MAS within six months of its financial year-end via Form 4.

The annual submission, made by a single auditor, must include:

  • Audited financial statements.

  • An independent assurance report prepared in accordance with SSAE 3000 (Revised).

Management letters containing findings, observations and recommendations arising from audits of transactions, systems, controls, policies and procedures.
 

Annual audit scope

Core annual audit requirements

For all PSPs, the annual audit will include the following areas:

  • Key risks: Money laundering and terrorism financing (ML/TF) risks, loss of customer monies, and technology risks.

  • Other risk areas: Outsourcing risk management and oversight, regulatory reporting and operational risk.

  • Safeguarding of customer monies and assets.

  • Accuracy and completeness of information reported in PSN04.

  • Compliance with base capital requirements.

  • Whether exempted products and services offered meet the exemption criteria.

  • Remediation of findings arising from previous audits and MAS inspections.

Higher inherent risk areas

Areas assessed by the auditors as posing a higher inherent risk will be reviewed annually. These reviews may include:

  • Cross-border money transfer services,

  • Digital payment token services,

  • Significant outsourcing arrangements,

  • New products, services or markets,

  • And the implementation of new systems and processes.

Low inherent risks

Areas assessed by auditors as posing a lower inherent risk, auditors could be reviewing and performing sample testing on a rotational basis (e.g. once every 2 – 3 years).
 

Do we still need an internal audit function?

Whilst the MAS’ expectations of the annual audit have somewhat broadened, the existing requirements under paragraph 3.1.9 of the Guidelines on Licensing for PSPs for an internal audit function to be in place remain.

In this respect, the MAS’ updated expectations for PSPs now broadly align with those that have been in place for capital market intermediaries (licensed under the Securities and Futures Act) for some time: the external/financial auditor performs the annual assurance review commonly referred to as the “compliance audit” and reports to MAS on this, whilst the IA function (in-house or outsourced) continues to provide an independent, risk-based review of the firm’s internal controls environment.

The internal auditor continues to play a key role in:

  • Assessing whether policies and procedures remain aligned with evolving MAS requirements.

  • Testing the effectiveness of AML/CFT and technology risk controls.

  • Reviewing governance arrangements and management oversight processes.

  • Conducting targeted audits of emerging risk areas, new products and outsourced service providers.

  • Evaluating remediation efforts arising from previous audits and inspections.

With careful coordination, overlap between the external audits and IAs in a particular year can be minimised, and the IA can serve as a useful check on internal controls ahead of the external audit.
 

Additional requirements for new PSPs

A key feature of the Guidelines is the requirement for newly licensed PSPs, as well as PSPs introducing newly licensed payment services, to undergo a comprehensive end-to-end review of their risk management systems and controls in the following areas one year after commencing operations or offering the new service.

Anti-money laundering and countering the financing of terrorism

The review should cover:

  • Enterprise-wide ML/TF risk assessments.

  • Customer due diligence processes.

  • Name screening.

  • Ongoing monitoring.

  • Wire and value transfer controls.

  • Suspicious transaction reporting.

  • Governance and oversight arrangements.

Technology risk management

The review should cover:

  • Technology risk governance.

  • Cyber hygiene practices.

  • IT resilience and service management.

  • Access controls.

  • Cybersecurity operations.

  • Application development and management.

  • Data and infrastructure security.

  • Online financial services controls.

The findings and recommendations arising from these reviews must be reported to MAS as part of the annual audit process.
 

How we can help

We can help PSPs assess their readiness against MAS’ rules and regulations and identify gaps in their existing risk management and control frameworks. Our services include:

  • IA and audit readiness reviews.

  • AML/CFT control assessments.

  • Technology risk and cyber control reviews.

  • Remediation validation and tracking.

  • Independent reviews of governance, policies and procedures.

By taking a proactive approach today, PSPs can strengthen their control environment, enhance regulatory compliance and better position themselves for annual audits, MAS inspections and supervisory reviews.

About the authors

Billie Jo Dixon is the practice lead for Ocorian’s Regulatory and Compliance team in Singapore. She has over twenty years’ experience in financial services and is a respected expert in regulatory compliance. She helps firms decide if they need to be licensed in Singapore and guides them through the MAS licensing process and all aspects of being a licensed business.

Anthony Xavier is a Principal Consultant in Ocorian’s Regulatory and Compliance team, with over 17 years’ experience in financial services. He specialises in MAS licence applications and regulatory advice for capital markets intermediaries and payment service providers. Before joining Ocorian, Anthony worked at the MAS, where he supervised capital markets intermediaries, assessed licence applications and conducted on-site examinations.