MAS Notice 626 Requirements (2026): AML/CFT Obligations + Downloadable Checklist.
Turn MAS Notice 626 into an operational AML/CFT inventory that links each current requirement to an implemented control, accountable owner and evidence record.
Download the MAS 626 evidence workbook
What is MAS Notice 626?
MAS Notice 626 is the Monetary Authority of Singapore’s notice on the prevention of money laundering and countering the financing of terrorism for banks. It applies to banks in Singapore as defined by the applicable Singapore banking legislation.
The Notice should be read with its accompanying Guidelines, relevant Singapore legislation, targeted financial-sanctions requirements, MAS guidance and applicable supervisory communications. The Notice establishes binding requirements; the Guidelines help explain MAS expectations and practical application.
Do not rely on a static summary alone. Always confirm the latest version on the MAS website and assess changes against the bank’s products, customers, delivery channels and risk profile.
Who is in scope?
Notice 626 applies to banks in Singapore. Other financial institutions—such as payment service providers, capital-markets intermediaries, insurers, financial advisers and trust companies—are generally subject to their own sector-specific AML/CFT notices.
A financial group should therefore determine scope legal entity by legal entity. A group policy may establish a common standard, but the Singapore bank must still evidence how the Notice’s requirements are satisfied in its local operations.
MAS Notice 626 control checklist
1. Governance and enterprise-wide risk assessment
Evidence examples: approved framework, risk-assessment methodology, risk results, committee minutes, management information and action plans.
2. Customer due diligence
Evidence examples: onboarding records, verification results, ownership chart, beneficial-owner evidence, customer-risk assessment, approvals and refresh history.
3. Customer risk and enhanced measures
Evidence examples: risk-scoring methodology, PEP-screening result, source-of-wealth assessment, enhanced review, approval and periodic-review schedule.
4. Ongoing monitoring
Evidence examples: monitoring methodology, scenario inventory, validation, alert cases, quality assurance, threshold changes and governance minutes.
Sia RegAI does not replace a transaction-monitoring system. It can help trace the applicable regulatory requirement to the policy, scenario governance, control owner, review and evidence that support it.
5. Correspondent banking and intermediary reliance
Evidence examples: respondent questionnaire, independent research, risk assessment, approval, agreement, review record and intermediary document-retrieval test.
6. Wire transfers and screening
Evidence examples: payment-field controls, exception queue, screening configuration, list-update record, alert case and quality testing.
Confirm which requirements arise directly from Notice 626 and which arise from associated Singapore legislation, MAS notices or guidance; preserve that distinction in the requirements inventory.
7. Suspicious transaction reporting
Evidence examples: internal referral, investigation file, decision record, submission confirmation, confidentiality controls and subsequent monitoring.
8. Records, training and independent assurance
Evidence examples: retention schedule, retrieval test, training records, monitoring plan, audit report, remediation tracker and closure validation.
Turn the Notice into an operational requirements map
A traditional control spreadsheet often records one row per paragraph but loses the relationship between the source, interpretation, control and evidence. A stronger inventory includes:
| Field | What to record |
|---|---|
| Source | Notice or Guideline paragraph, version and direct MAS URL |
| Requirement | Plain-language obligation without removing important conditions |
| Applicability | Legal entity, customer type, product, channel and scenario |
| Interpretation | Approved internal reading and any assumptions |
| Policy and procedure | Controlled documents implementing the requirement |
| Control | Preventive, detective or governance activity |
| System or data | Supporting platform, model, data source or report |
| Owner and reviewer | Accountable function and qualified review |
| Evidence | Current proof that the control operates |
| Change history | Previous wording, impact decision and effective date |
| Gap or action | Risk, owner, deadline, status and closure evidence |
How Sia RegAI supports MAS 626 change management
Review source changes
Use RegReview to compare a new MAS publication or revised internal source against the controlled version. Record the relevant change, interpretation, applicability and reviewer decision.
Match obligations to controls
Use RegMatcher to connect the requirement to policies, onboarding procedures, monitoring governance, screening, reporting, training and assurance controls. Surface missing or weak mappings for expert review.
Route remediation
Assign affected requirements to the correct owners across AML compliance, operations, technology, data, legal, risk and audit. Preserve deadlines, dependencies, approval and implementation evidence.
Maintain supervisory traceability
Show how the bank moved from MAS source to obligation, control, evidence and decision. Export the record required for internal review, audit preparation or supervisory engagement.
Frequently asked questions
Does
MAS Notice 626 apply to every Singapore financial institution?
No. Notice 626 applies to banks in Singapore. Other categories of financial institution are subject to their relevant sector-specific AML/CFT notices and requirements.
What
is the difference between the Notice and the Guidelines?
The Notice sets requirements. The accompanying Guidelines explain MAS’s expectations and provide guidance on applying parts of the Notice. Teams should preserve the relationship between both sources without treating guidance text as if it were the same legal instrument.
How often should
MAS 626 controls be reviewed?
Review frequency should reflect the legal requirement, control type and risk. The inventory should also be reassessed when MAS changes a relevant source or the bank changes its customers, products, delivery channels, systems or risk profile.
Does
Sia RegAI perform customer screening or transaction monitoring?
No. Those activities remain in the bank’s designated AML systems and processes. Sia RegAI connects the governing requirements and changes to the related policies, controls, owners and evidence.
Can a group
AML policy demonstrate local compliance?
A group policy may support the control environment, but the Singapore bank should document how each applicable local requirement is implemented and evidenced in its own operations.
Build a current, evidence-backed MAS 626 inventory
Use the checklist above as a baseline, or see how Sia RegAI connects the current MAS source to obligations, controls, owners, evidence and remediation.
Primary sources
- MAS anti-money laundering and countering the financing of terrorism
- Singapore Statutes Online
- FATF Recommendations
Informational content only; it is not legal, financial-crime or supervisory advice.