A digital-asset trading platform targeting Singapore users, or seeking the credibility of a Monetary Authority of Singapore authorisation, faces a threshold question the moment it incorporates: does the business require a licence under the Payment Services Act (the principal statutory regime governing digital payment token services), and if so, at which tier? Getting that answer wrong exposes the business to enforcement, frozen banking rails and the effective loss of its operating model before a single trade is executed.
Singapore's MAS operates one of the most structured and internationally recognised licensing regimes for virtual-asset businesses in the Asia-Pacific region. The Payment Services Act creates three tiers of payment institution licence – money-changing, standard payment institution and major payment institution – and the applicable tier turns on transaction volume and float thresholds, not on the label the operator chooses for its service. A Digital Payment Token (DPT) service, which includes operating a crypto exchange, falls squarely within the Act's scope. This page sets out the regulatory basis, the application process, the cross-border interactions that most inbound operators underestimate, and the practical decision points a business should resolve before filing.
What is the MAS licensing regime for a crypto exchange?
Operating a crypto exchange in Singapore requires authorisation as a payment institution under the Payment Services Act, specifically for the provision of Digital Payment Token services. MAS does not issue a standalone "crypto exchange licence" as a distinct instrument; the exchange activity is captured within the DPT service category, which sits alongside other regulated activities such as account issuance, e-money issuance and domestic or cross-border money transfer.
The Payment Services Act distinguishes between a Standard Payment Institution (SPI) and a Major Payment Institution (MPI). An operator whose monthly DPT transaction volume, or whose e-money float, exceeds the thresholds set in the legislation must hold an MPI licence. A business below those thresholds may qualify for the lighter SPI tier. Both tiers impose AML/CFT obligations, conduct requirements and, in the case of an MPI, more exacting capital, technology risk and business continuity obligations. The threshold figures are set by MAS regulation and should be confirmed against the current version of the Act and its subsidiary instruments at the point of application – we do not reproduce them here because they are subject to legislative amendment.
MAS has also progressively tightened the consumer-access rules for DPT services. Restrictions on retail advertising and incentive schemes now apply to all DPT service providers, reflecting MAS's stated policy of limiting retail exposure to speculative digital assets. An inbound exchange operator must account for these conduct rules from day one of Singapore operations, not as an afterthought to the licence itself.
Engage counsel before choosing your Singapore entity structure. The process above describes the standard path. Your facts – the entity, the user base, the banking – change the analysis considerably. Map your options with OBOLUS.
Who needs a DPT service licence in Singapore?
Any business that buys, sells or facilitates the exchange of digital payment tokens as a service in Singapore must be licensed, regardless of where the business is incorporated. The Payment Services Act applies to services provided "in Singapore," and MAS interprets that phrase with reference to where the solicitation occurs, where the customer is located and where the service is actively marketed – not only where the server sits or the company is registered.
An exchange incorporated in the BVI, Cayman Islands or any other offshore hub that actively markets to Singapore residents, maintains a local office or employs sales staff in Singapore, or holds out a Singapore address, will likely be considered to be carrying on business in Singapore. The absence of a Singapore entity is not a defence; it is, in MAS's enforcement posture, an aggravating feature.
The critical planning question for an inbound operator is therefore jurisdictional scope: which users does the platform intend to serve, and does that scope bring Singapore residents within the perimeter? A platform that geofences Singapore at the point of onboarding, that does not market to Singapore residents and that maintains no Singapore presence operates outside the Act's reach. A platform that intends to serve Singapore must be licensed before it does so.
There is a related category – the exempt class under transitional arrangements – that historically allowed certain businesses already operating in Singapore to continue while their application was under review. That window has progressively narrowed. Businesses seeking to rely on any transitional position should obtain specific legal advice on the current state of those provisions rather than assume continued availability.
How does the MAS licence application process work?
The MAS application process for a DPT service licence follows a structured pre-submission and formal submission sequence, and the depth of MAS's information requirements makes thorough preparation the single biggest determinant of timeline.
Before submission, MAS expects applicants to have a Singapore-incorporated or Singapore-registered entity, a qualified management team with relevant financial-services or digital-asset experience, and documented AML/CFT policies that meet the Financial Action Task Force's Recommendation 15 standard on virtual assets. The Travel Rule – the obligation to pass originator and beneficiary data alongside a DPT transfer to a counterpart service provider – applies to Singapore DPT service providers. Applicants must demonstrate a credible Travel Rule solution at the point of application, not after licensing.
The formal application is submitted through MAS's SPACE online portal. MAS reviews the application, issues queries and may call for meetings with management. The timeline from submission to decision varies with the complexity of the application and the volume of applications under review at MAS at any given time. In our cross-border practice, we regularly advise clients to budget for a process measured in months rather than weeks, and to treat the initial query-response phase as the substantive engagement with the regulator rather than as an administrative formality.
MAS expects applicants to have resolved their technology risk management posture, including penetration testing, incident response plans and business continuity arrangements, before approval. Outsourced technology providers – cloud infrastructure, matching engines, custodial wallets – must be disclosed and assessed under MAS's outsourcing guidelines. An exchange that relies on a third-party matching engine needs to map that dependency and demonstrate contractual and operational control over service continuity.
Post-approval, the licensee enters ongoing supervisory obligations: periodic reporting to MAS, annual audit requirements and the obligation to notify MAS of material changes to the business, its controllers or its activities. A change of ownership above a specified threshold is a notifiable or approvable event under the Act.
What AML and Travel Rule obligations apply to a Singapore crypto exchange?
Singapore DPT service providers are subject to the full FATF-aligned AML/CFT regime administered by MAS, including the Travel Rule obligation that requires identifying information about the originator and beneficiary of a DPT transfer to accompany the transaction when it moves between virtual asset service providers. MAS has issued detailed guidance on the Travel Rule implementation standard expected of Singapore-licensed entities, and compliance with that standard is assessed as part of both initial licensing and ongoing supervision.
The practical consequence for an exchange is that its technology stack must include a compliant Travel Rule solution capable of querying counterparty VASP status, transmitting required data fields in a recognised protocol, and handling the "sunrise problem" – the gap where a counterparty VASP is based in a jurisdiction that has not yet implemented the Travel Rule domestically. MAS's guidance addresses the sunrise problem and sets out the conduct expected of Singapore licensees when transacting with non-compliant counterparts.
Customer due diligence under the Payment Services Act mirrors the FATF standard: know-your-customer onboarding, ongoing monitoring, enhanced due diligence for higher-risk customers and transactions, and screening against applicable sanctions lists. MAS places particular weight on screening against OFAC, UN and MAS's own lists. An exchange that operates with deficient CDD processes will face supervisory scrutiny at its first examination, regardless of the strength of its licence application.
Transaction monitoring is an area where MAS has demonstrated enforcement willingness. Operators we advise routinely integrate on-chain analytics tooling – the kind of capability that generates a forensic audit trail meeting MAS's expectation of risk-proportionate monitoring – into their compliance stack before submitting their licence application, not as a post-approval improvement programme.
How does the cross-border structure affect a Singapore licensed exchange?
Very few exchanges operate from a single jurisdiction, and the Singapore MAS licence does not, by itself, authorise the operator to serve clients in the European Union, the United Kingdom, Hong Kong or any other regulated market. This is the structural reality that the "one offshore licence covers everything" assumption misses – and it is the assumption that most frequently produces the friction between a business's operating model and its actual legal position.
For an exchange with a Singapore licensed entity and ambitions beyond Singapore residents, the structural questions are: which other markets require local authorisation; which activities (custody, fiat on-ramp, OTC desk) generate separate regulatory footprints; and whether the Singapore entity is the correct holding point for each activity or whether a hub-and-spoke structure across multiple licensed entities is more appropriate.
In the European Union, an operator serving EU residents must hold a CASP authorisation under MiCA (the Markets in Crypto-Assets Regulation) or passport through a licensed EU entity. MiCA does not extend mutual recognition to Singapore-licensed businesses. In the UAE, a separate VARA (Virtual Assets Regulatory Authority) authorisation is required for Dubai market activity. In Hong Kong, the SFC VASP licensing regime for virtual-asset trading platforms applies independently of any Singapore authorisation.
The banking layer compounds this complexity. A Singapore-licensed exchange does not automatically obtain bank accounts; MAS's licence creates regulatory legitimacy, but individual banks make their own commercial and compliance decisions about DPT service provider clients. Operators we advise frequently find that their banking strategy requires as much preparation as their licence application – and that the jurisdictions in which the exchange can maintain fiat settlement accounts shape the practical scope of the business as much as the regulatory perimeter does.
Tax treatment of exchange income, token disposals and staking revenue is jurisdiction-specific and materially affects the choice of entity structure. Singapore's corporate tax regime and the Inland Revenue Authority of Singapore's (IRAS) guidance on the income tax treatment of digital tokens are relevant to an operator domiciling its principal entity in Singapore. Cross-border intragroup arrangements – IP holding, management fees, intercompany trading – must be structured to withstand transfer-pricing scrutiny in each jurisdiction where the group operates.
What are the most common structuring mistakes in a Singapore exchange setup?
The most consistent structuring mistake in a Singapore exchange setup is treating the licence application as the end of the legal project rather than the beginning of a compliance programme. MAS grants authorisation to businesses that have demonstrated they can meet the regime's requirements; it does not thereafter reduce its supervisory expectations.
A second common mistake is the custody assumption. Exchanges that hold customer digital assets are generally performing custody as well as exchange services. Custody is a regulated activity in its own right under many regimes – including MAS's own evolving standards for safeguarding customer assets – and an exchange that treats custody as incidental to its exchange licence without separately addressing the safeguarding obligations runs a structural compliance gap.
A third mistake, particularly prevalent among operators who incorporated offshore before deciding to seek Singapore authorisation, is the controller and ownership disclosure gap. MAS examines ultimate beneficial ownership to the level of natural persons, and structures that were designed for privacy rather than regulatory disclosure create friction at the application stage. We have seen applications stall for months because controller structures required restructuring before MAS would engage substantively on the licence itself.
Fourth: underestimating the technology-risk component. MAS expects material specificity on the exchange's technology architecture, including its wallet custody model, key management arrangements and incident response capability. Applicants who submit generic technology-risk policies rather than policies mapped to their actual infrastructure encounter repeated MAS queries and extended timelines.
Finally, the user-base assumption. Operators who assume that a Singapore MAS licence implicitly covers their existing user base – including users acquired under a prior unregistered operation – misunderstand the licence's scope. MAS may require remediation of pre-licence operations as a condition of authorisation. Grandfathering of existing users is not automatic.
If your application has stalled, or your banking rails have been disrupted, a structural review can surface the underlying cause. If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back. Contact OBOLUS to discuss a review.
Singapore exchange authorisation: a structuring matter in practice
In a recent licensing matter, a payments technology group based in Southeast Asia sought MAS DPT service authorisation for an exchange subsidiary. The group's holding structure had been designed for a prior business model and placed the controlling shareholder interest in a jurisdiction that raised MAS disclosure concerns. We worked with the group's corporate advisers and allied counsel in the relevant jurisdiction to redesign the controller disclosure chain, producing a simplified structure with transparent beneficial ownership documentation that MAS's fit-and-proper assessment could follow cleanly. The application, which had been delayed for several months before instruction, progressed to in-principle approval within the subsequent review cycle. The group's parallel banking engagement – a process we ran concurrently with the MAS application – resulted in confirmed fiat settlement accounts in two jurisdictions by the time the licence issued.
Which operator profile is best suited to Singapore?
Singapore suits operators whose primary market is Asia-Pacific and who can meet MAS's substantive compliance bar. The MAS authorisation carries strong credibility with institutional counterparties, banking providers and potential acquisition partners. The regulatory cost – in time, personnel and compliance infrastructure – is real, and operators who cannot sustain a genuine compliance programme in Singapore will find the licensing process difficult and the ongoing supervision more difficult still.
Profile A: a well-capitalised exchange with an experienced compliance function, a clear Asia-Pacific user focus and no material ownership opacity. This operator is well placed to pursue MAS authorisation as its primary jurisdiction of operation. The timeline will be measured in months; the outcome, if the compliance infrastructure is genuine, is achievable.
Profile B: a startup exchange with limited compliance history and a global user-base ambition. Singapore is not the wrong answer for this profile, but it is a demanding one. A phased approach – building the compliance function and business history in a less intensive regime first, then transitioning to Singapore – is a path we regularly discuss with operators at this stage.
Profile C: a European or UK exchange seeking an Asia-Pacific hub alongside an existing EU or FCA authorisation. Singapore works well in this configuration because MAS authorisation and a MiCA CASP authorisation are structurally compatible: the two regimes do not conflict, and the operator can use the Singapore entity for Asia-Pacific clients and the EU/UK entity for European clients, with clear legal and operational segregation between them.
The decision is not only about Singapore versus another jurisdiction. It is about whether the operator's current structure, compliance capability and banking position can support a Singapore application now, or whether work is needed first. We map that picture for clients before they commit to a filing.
Related at OBOLUS
- Licensing & Registration for Digital-Asset Businesses – the firm's full licensing practice across 70+ jurisdictions, from CASP authorisation to VASP registration.
- Digital-Asset Licensing in Bermuda – offshore licensing strategy for exchanges and funds seeking a credible Atlantic hub.
- Creditor Claims in Crypto Insolvency in the Seychelles – recovery and creditor-side strategy where an exchange counterparty has failed.
FAQ
How long does a crypto licence take to obtain?
The timeline for MAS DPT service authorisation varies with the complexity of the application and MAS's current caseload, but operators should plan for a process measured in months rather than weeks. Pre-submission preparation – resolving controller structure, building out AML/CFT policies and technology-risk documentation, and selecting a Travel Rule solution – substantially influences how quickly MAS can complete its assessment once the formal application is filed. Incomplete or generic applications generate query cycles that extend the timeline materially.
Which jurisdiction is best for licensing my crypto business?
There is no universally correct answer. The right jurisdiction depends on your target user base, the activities you intend to conduct, your current compliance capability and your banking strategy. Singapore suits Asia-Pacific focused businesses that can meet a demanding compliance standard. The EU's MiCA regime suits businesses seeking EU market access with passporting. Offshore hubs such as BVI, Cayman and Bermuda suit specific structural purposes rather than direct retail-facing operations. We assess these options against your specific profile rather than recommending a single default answer.
Do I need a separate custody licence?
Whether custody requires a separate authorisation depends on the jurisdiction and the custody model. Under the MAS regime, an exchange that holds customer assets must meet MAS's safeguarding requirements, which have been progressively tightened. In some jurisdictions – notably the EU under MiCA and the UAE under VARA – custody is a separately defined regulated activity that requires its own authorisation, even if the same entity also holds an exchange licence. An operator that performs both exchange and custody functions across multiple markets should audit each market's requirements independently rather than assume the exchange licence covers custody.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit, so the structure you build is the one that holds. We also work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications where recovery is at issue. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in inbound exchange and VASP authorisation strategy across the Asia-Pacific and Gulf licensing hubs.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.