Monetary Authority of Singapore (MAS) has published new guidance setting out its expectations for the annual audit. payment service providers (PSPs) require licensed firms to strengthen their oversight of risk management, compliance and controls as the city-state’s digital payments sector expands.
Guidance on Supervision of Payment Service Providers (PS-G04), as seen by Crowdfund ContentIt applies to all payment service licensees under the Payment Services Act 2019, including money exchange licensees.
They outline annual audit requirements, mandatory audit scope areas, and key expectations for external auditors.
Under the guidelines, PSPs are required to appoint a suitably qualified external auditor each year and submit an audit report to MAS within six months of the financial year end.
The regulator said firms should not appoint separate auditors for different parts of the annual audit, where the same auditor will be responsible for the audit of accounts, the Independent Assurance Report and the findings and observations arising from the audit.
The audit presentation will include the audited financial statements, Independent Assurance Report and findings regarding the PSP’s compliance with regulatory requirements as well as the adequacy of risk management and controls.
The Independent Assurance Report must be prepared in accordance with the Singapore Standard for Assurance Engagements (SSAE) 3000 (Revised).
As part of the annual audit, external auditors must also provide a management letter detailing findings, observations and recommendations covering the licensee’s accounts, transactions, systems, controls, policies and procedures.
MAS said it would consider these findings as part of its assessment of the licensee’s control framework, including whether the firm proactively identified and remedied control gaps.
The regulator said external auditors should report serious breaches immediately rather than waiting for the annual Form 4 submission.
These include where clients’ funds are not properly segregated or protected, basic capital falls below minimum requirements, regulated activities are carried out without appropriate licensing or changes in controllers, board members or chief executive officers occur without prior MAS approval.
Systemic and serious gaps in risk management systems and controls should also be reported immediately.
Additionally, MAS said PSPs remain responsible for notifying the regulator immediately if they discover any serious breaches or systemic weaknesses, regardless of whether the external auditor also reports the matter.
Failure to do so may result in audit action.
The guidelines also require PSPs to provide auditors with information to facilitate the audit process, including business models, customer profiles, regulated and exempt products and services, licensing conditions, regulatory violations, significant control deficiencies, and entity-wide risk assessments.
MAS said annual audits should be commensurate with the level of risk and complexity of the PSP’s business, but should at least cover key risks, including money laundering and terrorist financing, loss of customer funds and technology risks.
Mandatory annual audit areas include protection of client funds and assets, accuracy of regulatory reporting, compliance with core capital requirements, exempt products and remediation of previous audit findings.
For newly licensed PSPs and newly licensed firms that begin offering payment services, MAS expects auditors to conduct an end-to-end review one year after the start of operations, focusing on anti-money laundering and countering the financing of terrorism (AML/CFT) controls and technology risk management.
Reviews should evaluate both the adequacy and operating effectiveness of the PSP’s risk management systems and controls.





