On paper, a decentralised finance protocol looks technology-neutral: smart contracts execute autonomously, governance tokens distribute decision-making, and no single entity holds user funds. In practice, the Monetary Authority of Singapore (MAS) reads the substance of what a protocol does, not the label its founders attach to it. A protocol that intermediates payments, facilitates trading, or issues instruments that carry economic rights can fall squarely inside Singapore's Payment Services Act (PSA) or the Securities and Futures Act regime – whether or not the founders ever intended to run a regulated business.
The legal structuring question therefore has a direct answer: before a DeFi protocol launches for users in or from Singapore, the entity structure, the token classification, and the activity map must align with MAS expectations. Getting that alignment wrong converts a product launch into an unregistered financial-services operation. This guide walks the key steps in sequence – from classification through entity choice to the banking and tax interactions that determine whether the structure actually works in practice.
Why MAS scrutiny applies to DeFi protocols
MAS applies a substance-over-label test. If a protocol facilitates the exchange of digital payment tokens (DPTs) – the PSA's defined category for cryptocurrencies such as BTC and ETH – the exchange activity itself triggers the licensing analysis, regardless of how automated the settlement is. Similarly, if governance or yield tokens carry profit-participation rights, revenue-sharing, or voting rights analogous to equity, MAS may treat them as capital markets products regulated under the Securities and Futures Act. The critical point is that the mere act of deploying smart contracts does not insulate a protocol from these analyses.
In our cross-border practice, we regularly see founders conflate decentralisation with deregulation. The two are unrelated in Singaporean law. MAS has published guidance making clear that the legal characterisation follows the rights conferred on the holder and the function performed by the service – not the degree of on-chain automation. A protocol with a Singapore-incorporated operating company, a Singapore-resident team, or Singapore-domiciled users faces a meaningful risk of being within MAS's supervisory perimeter whether or not it holds a licence.
The regime's three most relevant instruments are the Payment Services Act (which covers DPT services, including dealing, exchange, and custody), the Securities and Futures Act (which covers dealing in capital markets products and operating organised markets), and the Financial Advisers Act (which captures advice on investment products). A well-structured DeFi protocol is designed so that none of its core activities falls in an unintended regulated category – or, where they do, that the correct licence is in place.
Step 1: Token classification before anything else
Token classification is the gateway decision: every subsequent structuring choice depends on where the token sits in MAS's taxonomy. Singapore's framework recognises DPTs (payment-function crypto), capital markets products (securities, units in collective investment schemes, derivatives), and e-money – and a protocol's token may fit more than one category depending on how rights are bundled.
A common assumption in the market is that attaching a "utility" label to a whitepaper settles the legal classification. It does not. MAS assesses classification against the substance of rights conferred, not the marketing label. A governance token that entitles holders to a share of protocol fees looks economically like a profit-participation right. A token that pools contributions and allocates returns on a discretionary basis may constitute a unit in a collective investment scheme. Neither classification is avoided simply by calling the token a utility token.
The practical work at this step involves mapping every right the token confers – voting, economic, redemption, collateral – against MAS's published classification guidance. Where the analysis produces a borderline outcome, founders have two routes: restructure the rights bundle so the token falls cleanly outside the regulated perimeter, or obtain the applicable licence before launch. A pre-submission consultation with MAS is available for novel structures, and we advise using it where the classification is genuinely ambiguous – an informal answer from MAS at this stage is far less costly than a post-launch enforcement inquiry.
Common mistake at this step: treating a jurisdiction-shopping exercise as a substitute for classification work. Incorporating in the BVI or Cayman Islands does not immunise a Singapore-facing protocol from MAS's reach; the connection test turns on the activities performed and the users served, not the place of incorporation alone.
What entity structure suits a DeFi protocol in Singapore?
The optimal entity structure for a DeFi protocol in Singapore depends on the token classification outcome, the protocol's governance model, and how the founding team plans to allocate liability. There is no single correct answer, but there are clear structural patterns that MAS-licensed and unlicensed protocols each follow.
For protocols that require a DPT service licence under the PSA, the operating entity must be a Singapore-incorporated company; MAS does not licence foreign entities directly for standard DPT services. The licence-holding company carries the regulatory obligations – capital, AML/KYC, the Travel Rule (the obligation to pass originator and beneficiary data with qualifying transfers), and ongoing MAS reporting. A holding-company layer, typically in a low-tax jurisdiction such as the Cayman Islands or BVI, is common above the Singapore opco to hold intellectual property and provide governance-token issuance insulation.
For protocols that take the position that their activities do not require a licence – either because tokens are pure utility instruments or because the protocol is sufficiently decentralised to fall outside the definition of a DPT service – a Singapore private limited company remains common as the development entity, but the structural priority shifts to documenting and maintaining the non-custodial, non-intermediary character of the protocol. This documentation is the first thing MAS or a court would examine if the classification were challenged later.
DAO (decentralised autonomous organisation) structures present a distinct challenge. An unincorporated DAO has no legal personality under Singapore law. Members can face unlimited joint liability if the DAO is treated as a general partnership. The practical solution is to wrap governance functions in an incorporated entity – a Singapore company, a Cayman Foundation Company, or a Marshall Islands DAO LLC – while keeping on-chain governance separate from legal-entity obligations. The wrapper choice has tax and banking consequences that flow through the entire stack.
Process-transparency note: in our structuring mandates, we map the entity choices at the outset as a single structure diagram covering the IP entity, the operating or licensed entity, the token issuance vehicle, and the DAO wrapper (where applicable). That map also drives the banking and tax analysis in the same document, so the three workstreams do not produce conflicting outcomes.
For a scoped assessment of your protocol's entity options, contact OBOLUS at info@oboluslaw.com. The entity and classification decision sets every downstream obligation – getting it right before launch is materially cheaper than restructuring after.
How does the MAS PSA licence process work?
A DPT service licence application under the PSA follows a structured sequence: pre-application preparation, formal submission to MAS, in-principle approval (IPA), and full grant. Each phase has distinct requirements, and the timeline between formal submission and IPA is not fixed – MAS processes applications at a pace that reflects the complexity of the applicant's business model and the completeness of the submission package.
Pre-application preparation involves building the compliance programme to MAS's expectations before any forms are filed. This means a fully documented AML/KYC framework, a Travel Rule solution that covers qualifying DPT transfers, a risk-management framework, a technology and cybersecurity policy, and in many cases a local compliance officer whose appointment MAS will review. Submitting before these elements exist is not a shortcut – MAS returns incomplete applications, and the clock effectively restarts.
The formal application requires submission of the prescribed forms, audited financial statements, business plans, key-person declarations, and the compliance documentation. MAS may issue information requests (IRs) at any stage; responding to IRs promptly and completely is the single largest determinant of processing time. Operators we advise are told to treat IR response as higher priority than product development during the application phase.
At IPA stage, MAS confirms the licence will be granted subject to conditions – the entity may then move toward commercial operations, though typically under conditions (such as restricted user onboarding) until the full licence is granted. The MAS Fintech Regulatory Sandbox is available for genuinely novel protocols that cannot fit neatly into the existing framework, and we have seen it used effectively for DeFi structures where the activity sits at the boundary of a DPT service and an organised market.
A cross-border note: if the same protocol operates users in the EU, MAS licensing does not substitute for MiCA (the EU Markets in Crypto-Assets Regulation) obligations, and vice versa. A dual-track structure – a Singapore entity for APAC and a MiCA-passported EU entity for European users – is the architecture we map for protocols with global ambitions.
How does AML and the Travel Rule apply to DeFi?
AML compliance under the PSA and the Travel Rule – the obligation, grounded in FATF Recommendation 15, to transmit originator and beneficiary information alongside qualifying virtual-asset transfers – applies to licensed DPT service providers in Singapore. For a DeFi protocol that takes the position it does not require a licence, the AML question does not disappear; it shifts to whether the protocol's design inadvertently creates a regulated intermediary.
The structural risk is that a smart-contract protocol with an upgradeable admin key, a fee-collecting entity, or a governance structure capable of halting or redirecting funds may be characterised as a centralised service provider that happens to use on-chain settlement. That characterisation brings the full AML/Travel Rule framework into scope. Founders who structure around this risk do so by designing genuine non-custodial, non-administrative architectures – and documenting that design in detail.
For protocols that are licensed, the Travel Rule requires a technology solution capable of identifying counterparty VASPs, transmitting required data fields with qualifying transfers, and handling the sunrise problem – what to do when the counterparty is in a jurisdiction without Travel Rule implementation. Singapore's MAS has worked within the FATF framework, and the practical solutions available include purpose-built Travel Rule compliance software that integrates with the protocol's transaction flow. Selecting and integrating that solution is part of the pre-launch compliance build.
In a recent structuring matter, a DeFi team had designed a protocol with a fee-accumulation contract controlled by a multi-sig held by the core development entity. That structure, while appearing decentralised to users, created a point of control that MAS would likely have treated as evidence of a DPT service operation. We restructured the fee mechanism and the multi-sig governance so that no single entity could be characterised as the operator – and documented the design decision in the legal opinion that accompanied the token launch.
What are the banking and tax interactions for a Singapore DeFi entity?
Banking access for a DeFi-focused company in Singapore is materially harder than the jurisdiction's crypto-friendly reputation suggests. Most local and international banks operating in Singapore maintain elevated due-diligence requirements for DPT-related businesses; some decline to onboard DPT licensees entirely. The practical solution is to approach banking as a parallel workstream to the licensing application, not as a post-licence afterthought.
Banks assess three things above all: the AML programme's credibility, the source of the protocol's revenue, and the identity and risk profile of the ultimate beneficial owners. A well-documented pre-application compliance framework – the same documentation MAS requires – is the most efficient tool for banking due diligence. A protocol team that can present its MAS application materials to a prospective bank demonstrates regulatory engagement; one that cannot typically faces an extended due-diligence process or a declined account.
On tax, Singapore's corporate income tax regime is competitive, and there is no capital gains tax on corporate investment returns as a general matter. However, the tax treatment of token issuance, protocol fee revenue, staking income, and DeFi yield is fact-specific and has not been comprehensively codified in IRAS guidance to date. In our practice, we treat token issuance proceeds as presumptively taxable revenue until the facts support an alternative characterisation – and we build the holding-entity and token-issuance-vehicle structure to produce the most defensible tax outcome before the token is issued, not after.
The cross-border interaction is particularly significant for protocols that issue tokens to holders in multiple jurisdictions. A Singapore-incorporated token issuer may create withholding-tax exposure in jurisdictions where token holders are tax-resident, depending on whether token distributions are characterised as dividends, interest, or royalties under the relevant double-tax agreement. Mapping this exposure at the structuring stage – before the token distribution mechanism is locked in smart-contract code – is substantially easier than changing it after launch.
If your structure has already been built and banking or tax complications have emerged, reach our structuring desk at Map your options. A second read of an existing structure frequently surfaces the cause and the route to resolution.
Decision point: which profile should choose which path?
The structuring decision for a DeFi protocol in Singapore ultimately turns on four variables: the token's classification, the protocol's degree of decentralisation, the intended user base, and the founding team's appetite for the ongoing compliance burden of a licensed entity.
Profile A – licensed DPT operator: a protocol that facilitates DPT exchange or custody for retail or institutional users, with a Singapore-resident team and Singapore users in scope. The correct path is a PSA DPT service licence, a Singapore opco, a documented AML/Travel Rule programme, and a holding structure above the opco that separates IP and governance-token issuance from the regulated entity. Timeline to IPA varies and is not fixed by the statute; budget for a substantive pre-application build before submission. Key risk: undercapitalised compliance function at submission leads to repeated IRs and extended timelines.
Profile B – non-custodial protocol with governance token: a protocol with genuinely non-custodial architecture, no Singapore-entity fee collection, and a governance token assessed as outside capital-markets product definition. The correct path is a development entity (Singapore or offshore), a documented classification opinion, a DAO wrapper in a recognised legal form (Cayman Foundation Company is the most widely used), and a proactive non-action-letter or sandbox engagement with MAS where the classification is borderline. Key risk: a control mechanism (admin key, fee-accumulator, upgrade proxy) is later characterised as evidence of a DPT service operation.
Profile C – global protocol with APAC and EU user base: the dual-track structure – Singapore PSA licence for APAC, a MiCA-authorised CASP entity in an EU member state for European users – with a holding layer that coordinates IP licensing between the two operating entities. This is the architecture we map for protocols with ambitions beyond any single regulatory perimeter. Key risk: the two regulatory programmes generate conflicting compliance requirements; early coordination between the Singapore and EU workstreams prevents that conflict from crystallising in product design.
Related at OBOLUS
- DeFi, Tokenization & Smart-Contract Law – our core practice covering protocol structuring, token classification and smart-contract legal risk
- NFT project legal structuring in the Czech Republic – structuring analysis for token-based projects under the EU MiCA regime
- Token issuance and offering rules in Malta – MFSA framework and MiCA transition rules for token issuers in an EU member state
FAQ
Can a DeFi protocol be regulated?
Yes. Regulatory analysis in Singapore follows substance, not structure. A protocol that facilitates DPT exchange, operates a custody mechanism, or issues instruments with economic rights can fall within the Payment Services Act or the Securities and Futures Act regardless of how automated its settlement is. The critical question is whether the activity, the token, or the entity operating the smart contracts brings the protocol within a defined regulated category under MAS's regime. Genuine decentralisation – with no controlling entity and no admin key – is a relevant factor, but it does not automatically exempt a protocol from analysis.
What legal wrapper suits a DAO?
An unincorporated DAO has no legal personality in Singapore and exposes members to joint liability. The most widely used solution is a Cayman Islands Foundation Company, which can hold assets and enter contracts while separating legal obligations from on-chain governance participation. A Singapore private limited company is common as the development entity below the DAO wrapper. Marshall Islands DAO LLCs are an emerging alternative. The right choice depends on the protocol's governance design, the tax profile of the founding team, and the jurisdictions where the protocol intends to be active.
Who is liable when a smart contract fails?
Liability when a smart contract fails depends on the legal relationship between the deploying entity and the users. Where a licensed DPT service provider deploys the contract as part of its regulated service, Singapore's contractual and regulatory frameworks may impose liability on that entity for losses attributable to the failure. For non-custodial protocols, liability analysis turns on the terms of service, the governance structure, and whether any entity held administrative control over the contract at the relevant time. There is no universal rule; the legal exposure is a function of the structuring decisions made before deployment.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, DeFi protocols and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around every structure. We assess token classification against the substance of rights, not the marketing label. We structure licensing, banking and tax as one mandate rather than three disconnected workstreams. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Roman Levitt, Technology & DeFi Counsel – specialising in smart-contract legal risk, DeFi protocol structuring, and token classification under Singapore and multi-jurisdictional frameworks.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.