Singapore Payment Services Act: DPT Licensing and Asset Protection

abstrak:Singapore’s DPT regime now covers custody, transfer and transaction-arrangement activities, with customer-asset safeguarding rules and a separate overseas DTSP framework. This guide explains what MAS licensing actually covers in 2026.

Singapore's crypto regulatory framework is best understood as an activity-based licensing system rather than a single “crypto licence.”

The Payment Services Act 2019 (PSA) regulates Digital Payment Token, or DPT, services alongside other payment activities. Its scope was materially expanded on April 4, 2024 to capture custody, token transfers and exchange-arrangement activities that previously could fall outside the perimeter.

Customer-asset safeguards followed in October 2024, requiring relevant DPT service providers to place customer assets into trust arrangements or return them within the prescribed timeframe, maintain proper records and separate safeguarding functions from trading and investment decisions.

A second framework then became important in 2025.

From June 30, 2025, Singapore introduced a separate Digital Token Service Provider regime under the Financial Services and Markets Act for specified Singapore-linked businesses that provide digital-token services only to customers outside Singapore. MAS has said the licensing bar for that model is high and that it will generally not issue such licences.

These two regimes should not be combined.

For a crypto platform operating from Singapore in 2026, the useful questions are:

Which legal entity provides the service?

Does it serve customers in Singapore, customers overseas, or both?

Which regulated activity does it perform?

Does its MAS permission actually include Digital Payment Token Service?

Those questions are far more useful than the statement:

“The company has a Singapore payments licence.”

The Payment Services Act regulates activities, not crypto brands

The PSA organizes regulated payment activities into service categories.

The First Schedule includes:

  • account issuance service;
  • domestic money transfer service;
  • cross-border money transfer service;
  • merchant acquisition service;
  • e-money issuance service;
  • digital payment token service;
  • money-changing service.

A licence category such as Major Payment Institution therefore does not tell a user which crypto activity the company is permitted to conduct.

A Major Payment Institution can be authorised for one group of services while another Major Payment Institution has a completely different permission set.

For a crypto business, the relevant check is:

Legal entity → Licence type → Digital Payment Token Service permission → Customer agreement

not:

Company → Major Payment Institution → all crypto services approved

The MAS Financial Institutions Directory is the practical starting point

MAS maintains a Financial Institutions Directory that can be filtered by:

Digital Payment Token Service

The directory shows the legal entities currently holding the relevant activity permission and the licence status attached to them.

Because the list changes, a static count is less useful than a live entity check.

When reviewing a platform:

  • Find the full company name in the account agreement.
  • Search that exact entity in the MAS directory.
  • Confirm that Digital Payment Token Service appears among its activities.
  • Compare the website and contact details.
  • Check whether another affiliate actually provides the product being used.
  • This avoids a common problem where a global crypto group has one MAS-regulated Singapore entity but the customer actually contracts with an offshore affiliate.

    Official directory:

    https://eservices.mas.gov.sg/fid/institution?activity=Digital+Payment+Token+Service

    Standard and Major Payment Institution are not safety ratings

    The PSA contains different licence categories, including Standard Payment Institution and Major Payment Institution.

    The distinction is connected to the scale and regulatory structure of the payment business.

    It should not be interpreted as:

    Major = safer investment

    or:

    Standard = lightly regulated crypto exchange

    The service permission still matters.

    The Payment Services Regulations expressly contemplate DPT service requirements for both relevant Major Payment Institutions and Standard Payment Institutions.

    In practice, the current MAS directory should be checked for the actual provider rather than inferring permission from the licence category.

    Singapore expanded DPT regulation on April 4, 2024

    The 2024 expansion was one of the most important changes to Singapore's crypto framework.

    Amendments to the Payment Services Act brought additional activities into the regulated DPT perimeter.

    These included:

    • custodial services for DPTs;
    • transmission of DPTs between accounts;
    • arranging for DPT transmission;
    • facilitating DPT exchange;
    • activities that induce or attempt to induce a person to enter into a DPT buy or sell agreement;
    • relevant activities even where the service provider does not itself take possession of the money or DPTs.

    MAS also expanded the cross-border money transfer perimeter in situations where money is not accepted or received in Singapore.

    This means the regulatory analysis is broader than:

    Who holds the private keys?

    A company can perform a regulated intermediary function even where another entity ultimately holds or transfers the assets.

    Non-custodial does not automatically mean unregulated

    This point is particularly important for modern crypto applications.

    A platform might claim:

    “We never custody customer assets.”

    That can be relevant.

    It does not by itself determine whether the PSA applies.

    The expanded definition can capture activities such as arranging or facilitating token transmission or exchange even where the intermediary never receives the money or token.

    The correct questions are therefore:

    • Who solicits the customer?
    • Who arranges the transaction?
    • Who transmits the order?
    • Who controls the customer interface?
    • Who executes the transaction?
    • Who holds the assets?

    A non-custodial front end can still perform a regulated function.

    Historical exemptions should not be treated as current licences

    When the expanded PSA scope took effect in April 2024, MAS provided transitional arrangements for businesses already carrying on newly regulated activities.

    Eligible entities had to take specific steps, including:

    • notifying MAS within the required period;
    • applying for a licence within the transitional window;
    • providing the required external auditor attestation.

    Those transitional mechanisms were designed to avoid an immediate disruption while MAS reviewed applications.

    They were not permanent licences.

    A company appearing on an old exemption or transition list should therefore not automatically be described as licensed in 2026.

    The current Financial Institutions Directory should take precedence.

    Customer-asset safeguarding became a major part of the regime

    Singapore's DPT framework now regulates more than entry into the market.

    The Payment Services Regulations contain a dedicated section for customer assets belonging to customers of DPT service providers.

    A key rule requires a licensee providing DPT services to ensure that customer assets received by it are, no later than the next business day:

    • deposited in an appropriate trust account; or
    • returned to the customer.

    The trust account needs to be identified as a trust or customer account under the applicable requirements.

    This is materially stronger than an exchange merely promising on its website that it “segregates user funds.”

    The safeguard is part of the regulatory framework.

    Safeguarding is not the same thing as keeping every coin in a separate wallet

    A trust or safeguarding arrangement should not be interpreted as a requirement for one blockchain address per customer.

    Centralized exchanges can use omnibus custody structures.

    The important questions are whether:

    • customer entitlements are recorded correctly;
    • customer assets are distinguishable from corporate assets;
    • the trust structure is legally effective;
    • books and records can reconcile customer balances with safeguarded assets.

    Blockchain wallet architecture and legal segregation are related but different concepts.

    A platform can use one omnibus wallet while maintaining customer-level records.

    Conversely, displaying many wallet addresses does not by itself prove that customer liabilities are properly segregated.

    Safeguarding applies quickly after customer assets are received

    The next-business-day requirement is practically important.

    It reduces the period during which newly received customer assets can remain outside the required safeguarding arrangement.

    For users, that creates a more specific regulatory question than:

    “Does the exchange keep funds safe?”

    The useful questions become:

    • Who is the safeguarding person?
    • Where is the trust account maintained?
    • How quickly are assets transferred into it?
    • How are customer balances recorded?
    • What happens during a withdrawal?

    The answers may differ among providers.

    DPT providers need records that identify customer entitlements

    The regulations also impose recordkeeping requirements.

    The purpose is to make it possible to determine the relationship between:

    • assets held in safeguarding arrangements;
    • customer balances;
    • transactions affecting those balances.

    This matters during:

    • insolvency;
    • cyber incidents;
    • reconciliation disputes;
    • customer complaints.

    A blockchain can show that an address holds 1,000 ETH.

    It does not identify which customer owns what portion of those 1,000 ETH.

    The provider's internal records remain critical.

    Safeguarding staff must be separated from trading decisions

    Singapore's DPT rules also address internal conflicts.

    The current Payment Services Regulations require DPT providers to maintain systems and controls appropriate to safeguarding risk.

    They also require controls and segregation of duties designed to manage conflicts between:

    safeguarding customer assets

    and

    the provider's business interests.

    The regulations specifically require that safeguarding is not performed by, or under the influence or direction of, persons who:

    • execute trades;
    • make investment decisions;
    • make trading decisions.

    That is an important structural control.

    It reduces the risk that the same individuals responsible for commercial trading decisions can freely control safeguarded customer assets.

    Customer-asset safeguarding does not guarantee full recovery in every failure

    Segregation and trust arrangements improve the legal and operational protection of customer assets.

    They do not produce an unconditional guarantee.

    Recovery can still depend on:

    • whether records are accurate;
    • whether assets were actually safeguarded;
    • third-party custody arrangements;
    • foreign law where assets are held abroad;
    • insolvency procedures;
    • operational failures.

    A provider can also suffer losses unrelated to safeguarded customer assets.

    Users should therefore distinguish:

    asset segregation

    from

    government deposit insurance.

    They are not the same thing.

    A DPT licence does not make crypto government-guaranteed

    MAS licensing regulates the provider and its service.

    It does not mean MAS guarantees:

    • Bitcoin's price;
    • token liquidity;
    • exchange solvency;
    • investment returns;
    • successful recovery after every scam.

    Singapore's public investor guidance repeatedly warns that digital tokens can remain highly risky even when a service provider is regulated.

    The regulatory framework can reduce provider-level risks.

    It cannot remove market risk.

    A DPT is not automatically the same thing as a security token

    The PSA's DPT framework should not be used as a catch-all for every blockchain asset.

    A token can instead represent or constitute:

    • a security;
    • a unit in a collective investment scheme;
    • a derivative;
    • another capital-markets product.

    Those products can fall within the Securities and Futures Act and related capital-markets regulation.

    This distinction becomes especially important for tokenized traditional assets.

    A token representing rights in shares should not be analysed only through the DPT framework merely because it is transferable on a blockchain.

    The underlying legal rights matter.

    One app can contain several different regulated products

    A crypto platform can present multiple products behind the same login.

    For example:

    • BTC spot trading;
    • tokenized securities;
    • custody;
    • staking;
    • derivatives;
    • fiat payments.

    The interface may make those services look like one regulated product.

    They are not necessarily governed by one permission.

    A robust review should map:

    Product → Legal entity → Regulated activity → Licence

    for each significant service.

    This is especially important where a Singapore entity is part of a larger global exchange group.

    Stablecoins need separate analysis

    Stablecoins also require more careful classification than the label “DPT.”

    A token marketed as maintaining a stable value can have different legal structures.

    Questions include:

    • What currency or asset does it reference?
    • Who issues it?
    • Is there a redemption right?
    • What backs it?
    • Which legal entity holds the reserves?
    • Which Singapore regulatory framework applies?

    Singapore has also developed a separate stablecoin regulatory framework for qualifying single-currency stablecoins.

    That framework should not be confused with the general DPT service licence.

    An exchange being licensed to provide DPT services does not automatically mean it is authorised as the issuer of every stablecoin it lists.

    Trading a stablecoin and issuing one are different activities

    This distinction is useful even without resolving the legal classification of a particular token.

    Consider two businesses.

    Business A

    A licensed exchange allows customers to buy and sell a stablecoin.

    Business B

    A company issues the stablecoin and promises redemption at par.

    Those businesses perform different functions.

    The risks are also different.

    The exchange creates:

    • trading;
    • custody;
    • withdrawal;
    • intermediary risk.

    The issuer creates:

    • reserve;
    • redemption;
    • issuer solvency;
    • stable-value risk.

    A user should therefore evaluate both where relevant.

    DPT lending, yield and investment products need separate terms

    A regulated exchange can offer additional products involving customer tokens.

    Examples include:

    • lending;
    • staking;
    • yield;
    • structured products.

    A customer who moves crypto from ordinary custody into another arrangement can change the legal and economic risk.

    The useful questions are:

    • Does title transfer?
    • Can the platform lend the asset?
    • Is a third-party borrower involved?
    • Can the asset be withdrawn immediately?
    • Does the safeguarding framework apply in the same way?

    The fact that the provider holds a DPT permission does not make every product economically equivalent to custody.

    The 2025 overseas DTSP regime is a separate framework

    Singapore added another important regulatory layer on June 30, 2025.

    The Financial Services and Markets (Digital Token Service Providers) Regulations 2025 created a licensing regime under the Financial Services and Markets Act.

    This framework targets specific Singapore-linked businesses providing digital-token services outside Singapore.

    It should not be treated as an amendment that replaced the Payment Services Act.

    The PSA continues to regulate relevant DPT services involving the Singapore market.

    The FSMA DTSP regime addresses a different problem.

    Who does the overseas DTSP regime target?

    MAS clarified the position in June 2025.

    From June 30, 2025, a Singapore-linked DTSP that provides relevant services solely to customers outside Singapore in relation to:

    • digital payment tokens; or
    • tokens of capital market products;

    needs a licence under the DTSP framework.

    MAS said it has set a high bar for such licensing and will generally not issue a licence.

    Its reasoning is that these business models can present higher money-laundering risks while the substantive regulated activity occurs outside Singapore, limiting MAS's ability to supervise the business effectively.

    Without the required licence, the provider must cease the regulated activity.

    There was no broad transition period for overseas-only DTSPs

    This is one of the clearest differences from the 2024 PSA expansion.

    For the overseas-only DTSP framework, MAS stated that existing providers caught by the rule would have to cease the regulated activity when the regime took effect on June 30, 2025 if they did not have the required licence.

    The framework therefore should not be described as:

    “Singapore allowed offshore-only crypto firms to continue while they slowly apply.”

    MAS took a materially stricter position.

    For an international crypto company incorporated in Singapore but serving only foreign customers, this can be a critical regulatory issue.

    The overseas rule did not force ordinary Singapore DPT licensees to stop serving foreign customers

    This is another common misunderstanding.

    MAS expressly clarified that providers offering DPT or capital-markets-token services to customers in Singapore were already regulated under existing Singapore frameworks.

    There was no change to what those licensed providers could do merely because the DTSP regime began.

    A Singapore-regulated provider that serves customers in Singapore can also provide services to customers outside Singapore, subject to the applicable laws.

    The DTSP regime is primarily concerned with the special case where the Singapore-linked business provides the regulated digital-token services only overseas.

    That distinction matters for global exchanges headquartered or incorporated in Singapore.

    “Singapore company serving overseas” does not automatically mean DTSP licence required

    The activity still matters.

    MAS clarified that the overseas DTSP regime applies to relevant services involving:

    • DPTs;
    • tokens of capital-market products.

    Services involving other tokens can fall outside the licensing requirement depending on their characteristics.

    MAS specifically noted that services involving tokens used only as utility or governance tokens are not automatically subject to licensing under the new overseas regime.

    The correct test is therefore not:

    Company incorporated in Singapore + blockchain = DTSP licence.

    The token and service need to fall within the statutory definitions.

    Singapore headquarters does not create one global regulatory umbrella

    A global exchange can have:

    • a Singapore operating company;
    • a Cayman entity;
    • a European subsidiary;
    • U.S. affiliates;
    • separate custody companies.

    The fact that the group has a Singapore office does not mean every global customer is protected under the Singapore PSA.

    Likewise, a Singapore DPT permission does not automatically govern an account contracted with an offshore affiliate.

    Users should compare:

    Customer agreement

    with

    MAS directory

    and verify that the same legal entity appears in both.

    In-principle approval is not a final licence

    Singapore crypto companies often announce In-Principle Approval, or IPA, before receiving a full payment institution licence.

    IPA can be an important regulatory milestone.

    It is not the same thing as final authorisation.

    A user should not rely on an old press release saying:

    “Company X received MAS in-principle approval.”

    The next step is to check the MAS Financial Institutions Directory for the current position.

    Possible outcomes can include:

    • final licence granted;
    • scope changed;
    • application withdrawn;
    • permission no longer current.

    The live MAS record is stronger evidence than a historical announcement.

    Marketing language should match the actual permission

    A payments licence can sound broader than it is.

    For example, saying:

    “MAS licensed”

    without explaining the entity and service can imply more than the official record supports.

    A stronger disclosure identifies:

    • legal entity;
    • licence category;
    • Digital Payment Token Service permission;
    • other services where relevant.

    This is particularly important for groups offering capital-markets products alongside crypto.

    A PSA payment licence should not be used to imply authorization for securities or derivatives that require different permissions.

    Customer protection and investment suitability are separate

    The safeguarding framework is designed to address custody and customer-property risks.

    It does not make every listed token suitable for retail investors.

    A regulated provider can still offer access to an asset whose price falls sharply.

    Likewise, a user can lose money because of:

    • leverage;
    • market volatility;
    • a bad investment decision.

    Those losses are different from:

    • unauthorized use of customer assets;
    • failure to safeguard tokens;
    • operational misconduct by the provider.

    A good regulatory review separates the source of risk before deciding what protection is relevant.

    Crypto derivatives require a different regulatory check

    Crypto derivatives should not be analysed only through the PSA DPT framework.

    A perpetual futures or options product can involve capital-markets regulation.

    For a platform offering both:

    BTC spot

    and

    BTC derivatives

    the product permissions may differ.

    The correct check is:

    Does the legal entity have the appropriate capital-markets permission for the derivative activity?

    rather than:

    Does the company have a DPT licence?

    This is particularly important for global exchanges whose Singapore subsidiary offers a narrower product set than the offshore platform.

    Self-custody does not remove every regulatory question

    A customer moving assets to a personal wallet changes the custody relationship.

    Once a token is withdrawn successfully, the exchange no longer controls the private key.

    But the exchange's transfer and AML obligations can still apply when processing the withdrawal.

    Likewise, a wallet-connected service can still perform regulated intermediary or arrangement functions even though the user retains control of the wallet.

    Self-custody therefore affects the analysis.

    It does not automatically end it.

    MAS regulation does not mean crypto is legal tender

    Digital payment tokens are not Singapore legal tender merely because DPT services are regulated.

    Regulating an exchange service and granting legal-tender status are different legal questions.

    A merchant is not generally required to accept Bitcoin because a licensed exchange can trade it.

    The same principle applies internationally.

    Regulation of the intermediary does not transform the underlying asset into sovereign money.

    Customer asset rules do not protect against mistaken blockchain transfers

    Singapore's safeguarding requirements apply to the provider's handling of customer assets.

    They do not make public blockchain transactions reversible.

    If a user sends tokens to:

    • the wrong wallet;
    • the wrong network;
    • a scammer;
    • an unsupported smart contract;

    the regulatory status of the exchange does not automatically recover the funds.

    Users should still verify:

    • asset;
    • blockchain;
    • address;
    • memo or tag;
    • destination compatibility.

    Regulatory protection and transaction finality are separate issues.

    Security controls remain necessary at user level

    A regulated provider can maintain strong custody controls while an individual customer's account is compromised.

    Users should still use:

    • unique passwords;
    • authenticator-based MFA;
    • withdrawal allowlists where available;
    • secured email accounts;
    • device review.

    A scammer impersonating a MAS-regulated exchange does not become legitimate because the real company appears in the MAS directory.

    MAS itself warns users to verify contact details and deal only through official channels.

    How to verify a Singapore crypto platform

    A practical check can be completed in several steps.

    1. Identify the contracting entity

    Open the Terms of Service or customer agreement.

    Find the exact Singapore or offshore company serving the account.

    2. Search the MAS Financial Institutions Directory

    Filter for:

    Digital Payment Token Service

    Then search the legal entity.

    3. Check the service scope

    Confirm which activities appear in the MAS record.

    Do not stop at:

    Major Payment Institution

    or:

    Standard Payment Institution.

    4. Check other products separately

    If the platform offers:

    • derivatives;
    • tokenized securities;
    • investment products;
    • advisory services;

    check the appropriate capital-markets permissions.

    5. Review custody terms

    Determine:

    • who safeguards the assets;
    • whether a third party is involved;
    • how customer assets are segregated;
    • how withdrawals work.

    6. Check whether the customer is served by the Singapore entity

    A group licence does not automatically extend to every overseas affiliate.

    7. For overseas-only businesses, check the DTSP framework

    If a Singapore-linked company provides relevant digital-token services solely outside Singapore, determine whether the FSMA DTSP regime applies.

    The verification chain should be activity-based

    A useful Singapore regulatory record should look like:

    Brand → Legal Entity → Customer Location → Product → Regulatory Act → Licence Type → Permitted Activity → Customer Agreement

    The weaker version is:

    Brand → MAS licence found → entire global platform considered regulated

    The second approach can produce serious errors.

    Singapore intentionally regulates different activities under different frameworks.

    A database should reflect that structure.

    What Singapore's framework means for exchanges

    For exchanges, the 2024 expansion and safeguarding rules raise the operational bar.

    Relevant providers need systems for:

    • customer asset safeguarding;
    • trust-account arrangements;
    • reconciliation;
    • recordkeeping;
    • conflict management;
    • cybersecurity;
    • AML/CFT;
    • transaction controls.

    The regulatory burden therefore extends well beyond filing a licence application.

    The provider needs an operating model capable of meeting continuing obligations.

    What the framework means for custodians

    Custodians are now explicitly inside the expanded DPT service perimeter where the statutory tests are met.

    That means the regulatory question is no longer limited to whether the custodian buys or sells tokens.

    Control over DPTs and DPT instruments can itself create regulated obligations.

    For users, the custody review should identify:

    • legal custodian;
    • safeguarding arrangement;
    • recordkeeping;
    • key control;
    • withdrawal process.

    A company saying:

    “We don't operate an exchange”

    does not automatically place custody outside regulation.

    What the framework means for intermediaries

    Businesses that arrange transactions can also fall within the regulatory perimeter even without taking possession of customer assets.

    This is increasingly important for:

    • broker interfaces;
    • aggregator apps;
    • order-routing businesses;
    • OTC intermediaries.

    The provider's role in causing or arranging the transaction can matter independently of custody.

    This makes business-model mapping more important than a simple wallet-control test.

    What the framework means for international crypto groups

    Singapore's approach draws a clear distinction between:

    • providers serving the Singapore market;
    • Singapore-linked businesses serving only foreign markets;
    • offshore affiliates with no relevant Singapore regulatory connection.

    That makes corporate structure especially important.

    An international group should be able to explain:

    • which entity serves Singapore customers;
    • which entity serves international customers;
    • which MAS licences each entity holds;
    • where customer assets are safeguarded.

    For users, those distinctions determine which legal and regulatory protections actually apply.

    What the regime does not guarantee

    Several misconceptions should be avoided.

    MAS licensing does not guarantee crypto prices

    A regulated DPT can still fall sharply in value.

    Safeguarding does not mean government deposit insurance

    Trust and segregation requirements improve customer-property protection but do not create a universal state guarantee.

    A DPT licence does not cover every financial product

    Securities and derivatives can require separate capital-markets permissions.

    Major Payment Institution is not an investment rating

    It is a licensing category, not an assessment that the company or tokens are low-risk.

    Singapore incorporation is not a crypto licence

    The legal entity still needs the applicable regulatory permission.

    An IPA is not a final licence

    Current status should be checked in the MAS directory.

    Self-custody does not automatically remove intermediary regulation

    Transaction arrangement and facilitation can still matter.

    Singapore's main 2026 regulatory lesson is entity-and-activity matching

    The most important feature of Singapore's crypto regime is not one particular licence.

    It is the way different regulatory layers fit together.

    For an ordinary local DPT exchange:

    Payment Services Act → DPT Service permission → customer asset safeguards

    For a tokenized security platform:

    capital-markets legislation → relevant securities permissions

    For a Singapore-linked business providing specified digital-token services only overseas:

    Financial Services and Markets Act → DTSP regime

    The same corporate group can therefore interact with multiple regulatory frameworks.

    This is why broad claims such as:

    “Singapore licensed crypto company”

    should always be unpacked.

    Conclusion

    Singapore's Payment Services Act remains the central framework for Digital Payment Token services in the domestic market, but the regime is much broader than it was when the PSA first took effect.

    The most important changes are now operational.

    The DPT perimeter expanded on April 4, 2024 to include custody, transfer, exchange-arrangement and other intermediary activities.

    Customer-asset safeguarding rules require relevant DPT providers to place customer assets into trust arrangements or return them within the prescribed timeframe.

    Safeguarding functions must be supported by records, risk controls and segregation of duties.

    A payment institution licence is not enough by itself — the entity's actual DPT Service permission must be checked.

    Capital-markets products and derivatives require separate analysis.

    The overseas-only DTSP framework under the Financial Services and Markets Act is separate from the PSA and has applied since June 30, 2025.

    For users, the practical process is:

    Check the legal entity.

    Check the MAS directory.

    Check Digital Payment Token Service permission.

    Check the product.

    Check custody.

    Check whether the account is actually served by that entity.

    For global crypto groups, Singapore's regulatory status should be described entity by entity rather than brand by brand.

    That is the most reliable way to understand what an MAS licence actually covers.

    Frequently asked questions

    What law regulates crypto exchanges in Singapore?

    The Payment Services Act 2019 is the main framework for Digital Payment Token services involving the Singapore market.

    Other laws, including the Securities and Futures Act, can apply to products such as securities and derivatives.

    What is a Digital Payment Token Service?

    The PSA defines a regulated DPT service by reference to specified activities.

    The scope includes relevant buying and selling, transfer, transaction arrangement and custody activities under the statutory definitions.

    The exact activity should be checked against the current Act and First Schedule.

    What changed on April 4, 2024?

    Singapore expanded the scope of regulated payment services.

    The changes brought activities including DPT custody and broader transfer and exchange-facilitation services into the PSA perimeter, including some services where the provider does not itself take possession of the customer's money or DPT.

    Does non-custodial mean unregulated in Singapore?

    Not automatically.

    The expanded framework can regulate transaction facilitation or arrangement activities even where the provider does not possess the customer's assets.

    What are the DPT customer-asset safeguarding rules?

    Relevant DPT providers must ensure customer assets are deposited into the required trust arrangement or returned to the customer no later than the next business day after receipt, subject to the regulatory conditions.

    The provider must also maintain records and appropriate safeguarding controls.

    Does every customer need a separate blockchain wallet?

    The regulations focus on legal safeguarding, records and customer entitlements rather than necessarily requiring a unique on-chain wallet address for every customer.

    The actual custody arrangement should be reviewed provider by provider.

    Are Major Payment Institutions safer than Standard Payment Institutions?

    “Major” is a regulatory licence category, not an investment-safety rating.

    Users should check the specific services and permissions of the legal entity.

    How can I check whether an exchange has DPT permission?

    Use the MAS Financial Institutions Directory and filter for:

    Digital Payment Token Service

    Then match the legal entity to the company in the customer agreement.

    Is an MAS In-Principle Approval a final licence?

    No.

    IPA is an application milestone.

    The MAS Financial Institutions Directory should be checked for current final licence status.

    Does a DPT licence cover crypto derivatives?

    Not automatically.

    Derivatives and other capital-markets products can fall under separate securities and financial-markets regulation.

    The relevant capital-markets permissions should be checked separately.

    Are stablecoins regulated the same way as Bitcoin?

    Not necessarily.

    Stablecoins can have different legal structures, issuer obligations and redemption arrangements.

    Singapore has also developed a separate regulatory framework for qualifying stablecoin issuers.

    The issuer and exchange should be analysed separately.

    What is the overseas DTSP regime?

    From June 30, 2025, specified Singapore-linked Digital Token Service Providers that provide relevant services solely to customers outside Singapore need a licence under the Financial Services and Markets Act framework.

    MAS has said it has set a high bar and will generally not issue such licences.

    Did the overseas DTSP regime replace the Payment Services Act?

    No.

    The PSA continues to regulate relevant DPT services involving Singapore.

    The FSMA DTSP regime addresses a separate category of Singapore-linked overseas-only digital-token businesses.

    Can a Singapore DPT licensee also serve overseas customers?

    MAS has clarified that providers already regulated for services to Singapore customers can also serve customers outside Singapore, subject to applicable requirements.

    The stricter DTSP rule targets businesses providing the relevant digital-token services solely outside Singapore.

    Is there a transition period for overseas-only DTSPs?

    MAS stated that existing providers caught by the overseas-only DTSP regime had to cease the regulated activity when the regime began on June 30, 2025 unless they held the required licence.

    The framework did not provide the broad transitional arrangement used for the 2024 PSA expansion.

    Does MAS licensing guarantee customer crypto?

    No.

    Licensing and safeguarding rules regulate the provider and customer-asset handling.

    They do not guarantee crypto prices, business solvency or recovery from every type of fraud or mistaken blockchain transfer.

    Is Bitcoin legal tender in Singapore?

    No.

    Regulation of DPT services does not make Bitcoin or other cryptocurrencies Singapore legal tender.

    What is the best way to verify a Singapore crypto platform?

    Use this chain:

    Brand → Legal Entity → Customer Location → Product → MAS Licence → DPT Permission → Customer Agreement

    Do not rely on a generic claim that a company is “MAS licensed.”

    Official sources

    • Singapore Statutes Online — Payment Services Act 2019
    • Singapore Statutes Online — Payment Services Act First Schedule
    • Payment Services (Amendment) Act 2021
    • Payment Services (Amendment) Regulations 2024
    • Payment Services Regulations 2019 — current version
    • MAS — 2024 expansion of regulated payment services and DPT user protection
    • MAS Financial Institutions Directory — Digital Payment Token Service
    • Financial Services and Markets (Digital Token Service Providers) Regulations 2025
    • MAS — Clarification of the Digital Token Service Provider regime
    • MoneySense — Risks of trading digital payment tokens and token derivatives
    • Disclaimer: This article is for regulatory research and informational purposes only. It is not legal or investment advice. MAS licence status, DPT permissions, customer-asset requirements and overseas DTSP rules can change, so current information should be verified against Singapore Statutes Online, the MAS Financial Institutions Directory and the applicable customer agreement before use.

Disclaimer

Ang mga pananaw sa artikulong ito ay kumakatawan lamang sa mga personal na pananaw ng may-akda at hindi bumubuo ng payo sa pamumuhunan para sa platform na ito. Ang platform na ito ay hindi ginagarantiyahan ang kawastuhan, pagkakumpleto at pagiging maagap na impormasyon ng artikulo, o mananagot din para sa anumang pagkawala na sanhi ng paggamit o pag-asa ng impormasyon ng artikulo.
Nakaraang post

3 Token Unlock na Dapat Bantayan sa Last Week ng September 2026

Susunod

Nagbigay si Nvidia CEO Jensen Huang ng ultimatum sa OpenAI at Anthropic