The Monetary Authority of Singapore (MAS) has issued new guidelines setting out its expectations for the annual audit of payment service providers (PSPs), requiring licensed firms to strengthen oversight of risk management, regulatory compliance, and controls as the city-state’s digital payments sector expands.
The Guidelines on Audit of Payment Service Providers (PS-G04), seen by CrowdFund Insider, apply to all holders of a payment service licence under the Payment Services Act 2019, including money-changing licensees.
They outline annual audit requirements, mandatory audit coverage areas, and baseline expectations for external auditors.
Under the guidelines, PSPs must appoint an appropriately qualified external auditor each year and submit an audit report to MAS within six months after their financial year-end.
The regulator said firms should not engage separate auditors for different parts of the annual audit, with the same auditor responsible for the audit of accounts, the Independent Assurance Report and any findings and observations arising from the audit.
The audit submission will include audited financial statements, an Independent Assurance Report, and findings related to the PSP’s observance of regulatory requirements, as well as the adequacy of its risk management and controls.
The Independent Assurance Report must be prepared in accordance with the Singapore Standard on Assurance Engagements (SSAE) 3000 (Revised).
As part of the annual audit, external auditors must also submit a management letter detailing findings, observations, and recommendations covering the licensee’s accounts, transactions, systems, controls, policies, and procedures.
MAS said it will consider these findings as part of its assessment of a licensee’s control framework, including whether the firm had proactively identified and remediated control gaps.
The regulator said external auditors must immediately report serious breaches instead of waiting for the annual Form 4 submission.
These include cases where customers’ monies are not properly segregated or safeguarded, base capital falls below minimum requirements, regulated activities are conducted without the appropriate licence, or changes in controllers, board members or chief executive officers occur without prior MAS approval.
Systemic and severe gaps in risk management systems and controls must also be reported immediately.
Separately, MAS said PSPs remain responsible for notifying the regulator immediately upon discovering any serious breach or systemic weakness, regardless of whether the external auditor has also reported the matter.
Failure to do so could result in supervisory action.
The guidelines also require PSPs to provide auditors with information, including their business model, customer profile, regulated and exempted products and services, licensing conditions, regulatory breaches, outstanding control deficiencies and enterprise-wide risk assessments to facilitate the audit process.
MAS said annual audits should be commensurate with the level of risk and complexity of a PSP’s business, but at a minimum should cover key risks, including money laundering and terrorism financing, loss of customer monies, and technology risks.
Mandatory annual audit areas include safeguarding customer funds and assets, accuracy of regulatory reporting, compliance with base capital requirements, exempted products, and remediation of previous audit findings.
For newly licensed PSPs and firms that begin offering newly licensed payment services, MAS expects auditors to perform an end-to-end review one year after operations commence, focusing on anti-money laundering and countering the financing of terrorism (AML/CFT) controls and technology risk management.
The reviews should assess both the adequacy and operating effectiveness of the PSP’s risk management systems and controls.