Calder & Vance International Sanctions & Compliance Counsel

Sanctions Risk & Compliance · Singapore

Sanctions compliance programmes under Singapore: step by step

A regional bank's Singapore operations process a payment for a trading company. Routine screening returns a clean result. Three weeks later, the group's head office flags that the trading company's parent is subject to a designations regime administered by the Monetary Authority of Singapore – and that the payment may have been caught. The compliance team must now decide whether a breach has occurred, what to report, and how to stop it happening again.

Sanctions compliance programmes under the Singapore regime are governed primarily by the Monetary Authority of Singapore (MAS), which administers financial-sanctions obligations through the relevant MAS regulations implementing United Nations Security Council resolutions as well as Singapore's autonomous measures. A well-constructed programme maps those obligations against the firm's business model, tests screening logic against the full ownership chain, and embeds clear escalation and reporting lines. As of July 2026, MAS has sharpened its supervisory expectations for financial institutions and, increasingly, non-financial businesses.

This guide walks through each design step in sequence, flags where Singapore's approach diverges from OFAC, OFSI, and the EU, and identifies the moments at which outside counsel adds the most value.

Step 1: Understand who the Singapore sanctions regime covers and what it prohibits

The Singapore sanctions regime binds a broad range of persons and entities. It applies to all businesses and individuals in Singapore, Singaporean citizens and permanent residents wherever they are located, and any body incorporated or constituted under Singapore law. That reach is broader than many compliance officers assume when they first map their obligations.

The legal basis is a layered structure. At its foundation sit the United Nations Act and the subsidiary legislation that implements binding Security Council measures. Alongside those sit MAS-issued regulations that impose financial-sanctions obligations directly on financial institutions and designated non-financial businesses and professions. The Terrorism (Suppression of Financing) Act adds further obligations relating to terrorist financing. Together, these instruments create prohibitions on making funds or economic resources available to designated persons, on processing payments that would benefit a listed entity, and on dealing in property that is owned or controlled by a designated person.

The concept of ownership and control (the test for whether a non-listed entity is caught through a listed person) deserves particular attention. Singapore's approach follows the structure of the UN Consolidated List obligations and the related MAS guidance: an entity that is owned or controlled by a listed person may itself be subject to the same prohibitions, even if not separately named. In our cross-border practice, the control limb is the element most often underweighted by compliance teams focused on direct-name screening.

How does this compare with the comparable tests elsewhere? Under OFAC, the 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked) is mechanical and ownership-focused. Under OFSI and the EU, the ownership-and-control test is broader and requires an assessment of effective control even where ownership thresholds are not met. Singapore's position sits closer to the UN standard – which tends toward a combined ownership-and-control analysis – and MAS guidance should be read alongside the relevant Security Council documentation to understand its full scope.

Step 2: Map your firm's exposure and identify the high-risk nodes

Before any policy is drafted, a compliance programme requires a formal risk assessment that maps the firm's specific exposure to the Singapore sanctions regime. That mapping exercise is not a generic document; it must reflect the firm's actual products, customer base, transaction corridors, and jurisdictional reach.

The risk assessment should identify, at a minimum:

  • The customer and counterparty population, including the sectors and geographies they operate in.
  • The products and services the firm provides, and the sanctions risk each carries (payment processing, trade finance, correspondent banking, custody, and digital-asset services each carry different profiles).
  • The transaction corridors that pass through or are linked to jurisdictions subject to enhanced measures under the UN Consolidated List or Singapore's autonomous designations.
  • Third-party intermediaries – correspondent banks, agents, freight forwarders – through which the firm's transactions flow.
  • Indirect exposure through group structures, where a parent or affiliate in another jurisdiction is subject to OFAC, OFSI, or EU measures that create secondary considerations.

The output of the mapping exercise is a risk register. It ranks the firm's exposure by likelihood and consequence. It also identifies the control gaps that the compliance programme must close.

In a recent matter, a financial-technology business processing cross-border payments between Southeast Asia and the Gulf identified, through a structured mapping exercise, that three of its payment corridors intersected with UN-listed entities at the correspondent level. The firm had not caught this through its existing first-layer screening. We assisted with a redesign of the screening logic and the correspondent-bank due-diligence process. The matter illustrated how a risk assessment is not a paper exercise – it surfaces the actual exposure that a flat screening list comparison misses.

Step 3: Design the five core programme elements

A well-tested Singapore sanctions compliance programme rests on five elements, each of which MAS supervisory guidance and broader international standards treat as foundational. These are: governance and senior responsibility, policies and procedures, screening and monitoring, training, and independent testing.

Governance and senior responsibility

The programme must have an identifiable owner at a senior level – typically a Chief Compliance Officer, Head of Financial Crime Compliance, or an equivalent. That person carries responsibility for the programme's design, its maintenance, and its operation. Boards and senior management are expected to understand the firm's sanctions risk and to have approved the programme's parameters. MAS has been explicit in supervisory correspondence that governance failures – the absence of board-level ownership – represent a primary driver of programme weaknesses.

Policies and procedures

Written policies must cover, at minimum: how the firm screens customers, counterparties, and transactions; what happens when a screening alert is generated; who has authority to clear an alert or escalate it; how the firm handles a potential match against the MAS designation list, the UN Consolidated List, or a foreign-regime list relevant to its business; and the firm's approach to voluntary disclosure and record-keeping. Procedures should be written to operational level – not at the level of principle statements, but at the level of steps a compliance analyst can follow in real time.

Screening and monitoring

Screening is the operational core of a sanctions compliance programme, and it is also the most technically complex element to get right. The firm must screen customers and beneficial owners at onboarding, screen counterparties and intermediaries on a transaction basis, and re-screen its customer population when the MAS designation list or the UN Consolidated List is updated. The screening tool must be configured to handle transliteration variants, aliases, and date-of-birth fields for natural persons, and to capture ownership-chain analysis for legal entities.

The questions a compliance officer should ask of the screening tool are: does it receive list updates in a timely way when Singapore or the UN publishes new designations? Does it aggregate holdings to test the ownership-and-control question, or does it match only on direct names? Does it generate a manageable alert rate, or does it generate so many false positives that analysts discount the alerts systematically? The last point is a practical risk we see regularly. A screening configuration that produces an unworkable alert volume effectively disables the control.

Training

Training must be role-specific. The obligations on a relationship manager differ from those on a payment-processing operations team, which differ again from those on a trade-finance documentary-credit analyst. Annual all-staff awareness training is a floor, not a ceiling. Targeted, scenario-based training for high-risk roles is what distinguishes a genuinely effective programme from a check-the-box exercise.

Independent testing

The programme must be tested independently – not by the first line of defence that operates it. Independent testing may be conducted by the internal audit function, a specialist compliance team with no operational stake in the programme, or by external advisers. Testing should cover both design adequacy (does the programme address the firm's risk?) and operational effectiveness (is it working in practice?). Gaps identified in testing must be tracked to remediation.

The position above covers the standard architecture. Your firm's size, risk profile, and business model change the emphasis at each step. A smaller trading company with a concentrated customer base needs a different configuration from an international bank with correspondent relationships across dozens of jurisdictions.

For an assessment of how these elements map to your specific operations, contact Calder & Vance at info@caldervance.com.

How does Singapore's programme design differ from OFAC, OFSI, and EU requirements?

Singapore's compliance expectations draw heavily from international standards – primarily the Financial Action Task Force recommendations and the UN Security Council framework – but the specific implementation requirements and supervisory emphasis differ in ways that matter for a cross-border business.

Under OFAC, the core framework is its five-component compliance programme model, which aligns substantially with the architecture described above. OFAC has published detailed guidance on each component, including on what senior-management commitment means in practice. One significant US-specific element is the voluntary self-disclosure regime (a VSD – voluntary self-disclosure to a regulator), which OFAC has historically treated as a significant mitigating factor in enforcement. OFAC also applies extraterritorial reach through secondary-sanctions provisions under IEEPA and certain programme-specific authorities, meaning that a Singapore business dealing with US-dollar transactions or US counterparties may have parallel OFAC obligations regardless of its primary registration.

Under OFSI in the United Kingdom, the supervisory expectation includes a specific obligation to report knowledge or reasonable cause to suspect that a designated person holds or controls funds under the licence holder's administration. OFSI's enforcement posture has shifted materially in recent years, with an increased focus on financial penalties for inadequate compliance. A Singapore business with UK operations, UK customers, or pound-sterling payment flows needs to map its OFSI obligations separately from its MAS obligations.

The EU regime, implemented through Council regulations, imposes obligations on all persons in the EU as well as on EU nationals and entities wherever incorporated. For a Singapore business with EU subsidiaries or EU-person directors, the EU ownership-and-control test – which captures entities controlled by a listed person even without majority ownership – creates an additional compliance layer. The EU also imposes circumvention prohibitions that are drafted broadly and have been interpreted expansively in enforcement guidance.

The practical implication for a Singapore-based business operating cross-border is that a single compliance programme cannot simply assume that MAS compliance equals global compliance. The regimes diverge on: the list sources that must be screened, the ownership-and-control thresholds, the reporting obligations and their triggers, the treatment of general licences and specific authorisations, and the extraterritorial reach of secondary-sanctions provisions. We regularly advise businesses on how to structure a programme that addresses these multiple obligations in a way that is operationally coherent rather than a series of disconnected single-regime controls.

What are the most significant risk flags in programme design?

Risk flags in sanctions compliance programmes tend to cluster around a small number of recurring weaknesses. Recognising them before they become enforcement issues is the purpose of periodic programme testing.

The first is list-coverage gaps. Firms sometimes screen against the MAS designation list alone and overlook the broader UN Consolidated List, which Singapore implements through its subsidiary legislation. A listed entity under the UN Consolidated List that does not appear on the MAS list by name may still create obligations. Similarly, where a firm's transaction activity connects to US-dollar clearing or US counterparties, the OFAC SDN List must be screened, and omitting it creates a gap.

The second is ownership analysis limited to the first layer. The MAS ownership-and-control question requires looking through the full beneficial-ownership chain, not just the immediate counterparty. Where a listed person owns a minority stake in a holding company that in turn controls the counterparty, first-layer screening will not catch it. This is where the control limb of the test, rather than the ownership percentage alone, becomes important.

The third is an alert-management process that is documented poorly. When a regulatory review or enforcement inquiry arrives, MAS and its counterparts in other regimes will ask to see the escalation decisions made on individual alerts. If the records show that alerts were cleared without documented analysis, the programme's credibility collapses. Every material alert-clearance decision should carry a written rationale, an identified decision-maker, and a date.

The fourth – and one that deserves emphasis – is the absence of a cross-regime view. A Singapore-incorporated business whose group treasury function holds US-dollar accounts and whose parent is EU-incorporated is simultaneously exposed to MAS, OFAC, and EU obligations. A programme that addresses each regime in isolation, without a joined-up view of how they interact, will have gaps at the intersections.

If a transaction has already been flagged, or an alert has generated an internal escalation that was not resolved cleanly, an early review can preserve options that narrow with time. For a confidential review of a potential programme gap or a specific alert, contact us at info@caldervance.com.

What records must a Singapore business keep, and when must it report?

Record-keeping and reporting are the two operational disciplines that MAS supervision most frequently scrutinises – because they are the evidence base against which a firm's programme is assessed in the event of a breach or an inquiry.

On record-keeping: Singapore's MAS regulations and the broader anti-money-laundering and counter-terrorist-financing notices require financial institutions to maintain records of transactions, customer due-diligence documents, and screening decisions. The required retention period under MAS notices is, as currently in force, five years from the end of the business relationship or the completion of the transaction, verify the current position before relying on it. That five-year benchmark aligns with the record-keeping standard applied under OFAC guidance, OFSI requirements, and EU Council regulations. Cross-border businesses should ensure that their record-keeping architecture meets the strictest applicable standard across the regimes they are subject to.

On reporting: the reporting obligations under the Singapore regime divide into two streams. The first is suspicious-transaction reporting to the Suspicious Transaction Reporting Office, which is triggered when a person in the course of carrying on business knows or has reasonable grounds to suspect that a transaction relates to the proceeds of criminal conduct (including sanctions violations, which are criminal offences under Singapore law). The second is the direct obligation to inform MAS when a financial institution knows or suspects that it holds funds belonging to or controlled by a designated person. These two streams are distinct. Confusing them, or failing to appreciate that both may be triggered by the same facts, is a common source of reporting failure.

The reporting windows applicable to specific obligations under MAS notices should be verified against the current text of those notices before reliance, as they are subject to amendment. What can be said with confidence is that a delay in reporting – once a firm has identified a match or a suspicious transaction – will be treated as an aggravating factor in any enforcement review. Speed of escalation, once a possible match is confirmed, is therefore an operational priority, not a procedural courtesy.

When should a Singapore business involve sanctions counsel?

There is a common misconception in this area. Many businesses assume that outside counsel is relevant only when something has gone wrong – a penalty notice, an enforcement enquiry, a transaction that has already been blocked. In our experience, the most valuable interventions happen earlier: at programme design, at the point of entry into a new market or product line, and when a material acquisition or transaction changes the firm's risk profile.

The moments that most consistently benefit from early specialist involvement are:

  • Initial programme design or a substantial redesign, where the firm needs to translate its risk assessment into a written programme that will withstand supervisory review.
  • Entry into a new business line – for example, digital-asset services or trade-finance products – where the sanctions-risk profile differs materially from the firm's existing activities.
  • Acquisition due diligence, where the target's customer base, correspondent relationships, or jurisdictional exposure requires a dedicated sanctions risk-assessment before signing.
  • A screening alert that cannot be resolved with confidence, particularly where the counterparty is structured through multiple holding layers or where the transaction involves a jurisdiction subject to enhanced measures.
  • An apparent violation, where the firm needs to scope the exposure, assess whether voluntary disclosure is appropriate, and manage the process from disclosure through to resolution.

The AUDIENCE_MYTH worth addressing directly is this: that a Singapore business with no US or EU nexus can set its programme by reference to MAS guidance alone and ignore other regimes entirely. This is not a safe assumption. The extraterritorial reach of OFAC's secondary-sanctions measures, the EU's treatment of EU-person directors and shareholders, and the UK's post-Brexit sanctions regulations all create obligations that may bite on a Singapore-registered entity depending on its transaction profile, banking relationships, and corporate structure. A programme designed only to satisfy MAS may leave the business exposed in ways that are invisible until a correspondent bank or a counter-party's compliance function raises the issue.

Related practices

Frequently asked questions

What are the steps to design a sanctions compliance programme under Singapore?
The steps are: (1) map the legal obligations under MAS regulations and the UN Consolidated List as implemented in Singapore; (2) conduct a risk assessment identifying high-exposure customers, products, and corridors; (3) design the five core elements – governance, policies, screening, training, and testing; (4) implement record-keeping and reporting procedures aligned to MAS notices; and (5) test the programme independently and remediate gaps. Each step must be documented to withstand supervisory review. Cross-regime obligations – OFAC, OFSI, EU – should be layered over the Singapore baseline where the business has a relevant nexus.
What is the most common mistake in sanctions compliance programmes?
The most common mistake, in our experience, is limiting screening to direct-name matching on a single list – typically the MAS designation list – without testing the full beneficial-ownership chain or including the UN Consolidated List and the OFAC SDN List where relevant. The result is a screening programme that passes its configuration test but misses real exposure at the ownership and correspondent layers. A close second is poor alert-management documentation: alerts cleared without a written rationale cannot be defended in an enforcement review, regardless of whether the underlying decision was correct.
How does Singapore differ from other regimes here?
Singapore's primary obligations flow from UN Security Council implementation and MAS-issued notices, rather than from a domestic autonomous-sanctions architecture as extensive as OFAC's or the EU's. That means the designation lists are shaped by UN measures, though Singapore also maintains autonomous designations. OFAC's mechanical 50 percent rule and its secondary-sanctions extraterritorial reach, OFSI's specific reporting obligation when funds of a designated person are held, and the EU's broad circumvention prohibition each add obligations that the Singapore regime does not replicate directly. A cross-border business must map all applicable regimes separately and comply with whichever imposes the stricter requirement on a given transaction.

Talk to Caldervance

For a scoped view of your exposure, contact info@caldervance.com.

Discuss your matter

This publication is general information and does not constitute legal advice. For advice on your situation, contact info@caldervance.com.