MAS issues Guidelines on Audit of Payment Service Providers
27 August 2026
On 16 July 2026, the Monetary Authority of Singapore (“MAS”) published the Guidelines on Audit of Payment Service Providers (“Guidelines”). The Guidelines, issued pursuant to the Payment Services Act 2019 (“Act”), apply to all holders of a payment service licence (payment service providers or “PSPs”). The Guidelines set out MAS’ expectations on the annual audits for all PSPs, including reports that should be submitted to MAS, baseline and mandatory coverage areas, and audit coverage for new licensees and newly licensed payment services. The extent and degree to which a PSP implements the Guidelines should be commensurate with the level of risk and complexity of its business model, as well as the products and services offered.
Annual audit requirement
The Guidelines provide that a PSP must, on an annual basis, appoint an auditor and ensure that a report of the audit is submitted to MAS in Form 4 within six months after the financial year end.
The PSP should ensure that it appoints an appropriate and suitably qualified external auditor in advance of the stipulated Form 4 submission timeline, to allow sufficient time for the auditor to complete the annual audit. PSPs should not engage separate auditors for different parts of the annual audit.
A copy of the management letter from the external auditor (“management letter”), including any findings, observations, and recommendations noted from the audit of the licensee’s accounts, transactions, systems, and controls, as well as policies and procedures in accordance with regulatory requirements, should be submitted in Form 4 as part of the annual audit requirement.
MAS will consider the findings and observations in the management letter as part of its assessment of the licensee’s control framework. MAS will also take into account factors such as whether the licensee had self-identified control gaps for improvement, management’s receptiveness towards issues raised, and willingness and proactiveness to remediate these findings.
Information to be provided to auditors
To enable the appointed external auditors to discharge their duties under section 37(4) of the Act, PSPs should provide their auditors with the necessary information on a timely basis. Such information includes, but is not limited to:
- the PSP’s business model, profile of customers, and jurisdictions served;
- the regulated products and services offered by the PSP, including the payment services conducted at each stage of the transaction process;
- the exempted products and services offered by the PSP and the controls in place to ensure that the PSP continues to meet the exemption criteria;
- licensing conditions and any regulatory directions issued to the PSP;
- regulatory breaches, fines, and any other regulatory or supervisory actions taken against the PSP;
- outstanding findings in relation to control deficiencies and non-compliance with applicable requirements arising from prior and current years’ internal audit reports, external audit reports, and inspections conducted; and
- any other information required by the external auditors such as the latest Enterprise-Wide Risk Assessment conducted by the PSP, relevant committee meeting minutes, and latest gap analysis performed against existing requirements.
Baseline expectations for audit of PSPs
All PSPs are expected to have robust risk management systems and controls to identify, assess, and mitigate the inherent risks arising from their business activities. PSPs should also have the necessary policies and processes in place to ensure compliance with applicable regulations on an ongoing basis.
The annual audit scope and coverage of the licensee’s systems, risk management, and controls should be commensurate with the level of risk and complexity of the business activities. Annual audits of PSPs should at minimum cover the key risks for payment services, namely, money laundering and terrorism financing risks, loss of customer monies, and technology risks. Other risk areas that could be covered include, but are not limited to, outsourcing risk management and oversight, regulatory reporting, and operational risk.
MAS expects the following mandatory audit areas to be covered during audits on an annual basis (“Mandatory Annual Audit Areas”):
- Safeguarding of relevant monies and customer assets in accordance with the safeguarding requirements;
- Accuracy and completeness of the reported figures in PSN04 (Notice on Submission of Regulatory Returns);
- Compliance with base capital requirements;
- Where PSPs are offering exempted products pursuant to PSN01 (Prevention of Money Laundering and Countering the Financing of Terrorism - Specified Payment Services), whether the exempted products and services offered continue to meet the exemption criteria; and
- Remediation of findings from prior external audits and MAS inspections.
PSPs should provide the appointed auditors with updated and relevant information on a timely basis to facilitate the audit for these mandatory areas.
Mandatory end-to-end review for new licensees and licensees with newly licensed payment services
In addition to the Mandatory Annual Audit Areas, newly licensed PSPs are expected to ensure that auditors perform, one year after the commencement of their operations, an end-to-end review of the adequacy and operating effectiveness of their risk management systems and controls for (i) money laundering and terrorism financing risk; and (ii) technology risk.
Licensed PSPs that have started offering newly licensed payment services should also ensure that the same end-to-end review is performed for the new payment service(s), one year after the commencement of their new payment service(s).
Reference materials
The Guidelines are available on the MAS website www.mas.gov.sg.