LPS Academy Interactive Reference Table
Maximum Coverage Offences, Misconduct, Regulatory Breaches & Punishments
Banks, Merchant Banks, Digital Banks, Branches, Banking Groups, Officers, Representatives, Vendors, Outsourced Providers and Banking Operations
Publication note: This maximum-coverage master table is prepared as a training, compliance and investigation reference. It expands the earlier 260-row bank-sector table into a broader practical checklist. Final legislation, section numbers, offence descriptions and punishments must be verified against the current Singapore Statutes Online, MAS legislation, MAS notices, directions, guidelines, licensing conditions and enforcement materials before publication or operational use.
Showing 0 records
Tip: click column headers to sort. Use “More” to expand long cells.
| Offence No | Offence Category | Offences | Legislation | Legal Description | Organisational Applications | Punishment |
|---|---|---|---|---|---|---|
| 1 | Property Offences | Theft of bank cash or teller float | Penal Code 1871, ss378-379 | Defines theft as dishonestly taking movable property without consent. It supports assessment of dishonest taking, retention, entrusted-property misuse, property loss and the consent element relevant to bank assets or customer property. | Applies where bank cash, devices, documents, valuables or customer/bank property are dishonestly taken. It should be reviewed across branch counters, teller operations, vaults, cash rooms, ATMs, secured storage, customer-service areas, delivery points, outsourced handling and property entrusted to staff or vendors. | Imprisonment up to 3 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 2 | Property Offences | Theft of customer cash or valuables | Penal Code 1871, ss378-379 | Defines theft as dishonestly taking movable property without consent. It supports assessment of dishonest taking, retention, entrusted-property misuse, property loss and the consent element relevant to bank assets or customer property. | Applies where bank cash, devices, documents, valuables or customer/bank property are dishonestly taken. It should be reviewed across branch counters, teller operations, vaults, cash rooms, ATMs, secured storage, customer-service areas, delivery points, outsourced handling and property entrusted to staff or vendors. | Imprisonment up to 3 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 3 | Property Offences | Theft of bank cards, tokens or cheque books | Penal Code 1871, ss378-379 | Defines theft as dishonestly taking movable property without consent. It supports assessment of dishonest taking, retention, entrusted-property misuse, property loss and the consent element relevant to bank assets or customer property. | Applies where bank cash, devices, documents, valuables or customer/bank property are dishonestly taken. It should be reviewed across branch counters, teller operations, vaults, cash rooms, ATMs, secured storage, customer-service areas, delivery points, outsourced handling and property entrusted to staff or vendors. | Imprisonment up to 3 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 4 | Property Offences | Theft of bank devices, laptops or security equipment | Penal Code 1871, ss378-379 | Defines theft as dishonestly taking movable property without consent. It supports assessment of dishonest taking, retention, entrusted-property misuse, property loss and the consent element relevant to bank assets or customer property. | Applies where bank cash, devices, documents, valuables or customer/bank property are dishonestly taken. It should be reviewed across branch counters, teller operations, vaults, cash rooms, ATMs, secured storage, customer-service areas, delivery points, outsourced handling and property entrusted to staff or vendors. | Imprisonment up to 3 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 5 | Property Offences | Theft of negotiable instruments or securities certificates | Penal Code 1871, ss378-379 | Defines theft as dishonestly taking movable property without consent. It supports assessment of dishonest taking, retention, entrusted-property misuse, property loss and the consent element relevant to bank assets or customer property. | Applies where bank cash, devices, documents, valuables or customer/bank property are dishonestly taken. It should be reviewed across branch counters, teller operations, vaults, cash rooms, ATMs, secured storage, customer-service areas, delivery points, outsourced handling and property entrusted to staff or vendors. | Imprisonment up to 3 years, fine, or both. Detailed punishment description: market or sector consequences may include civil penalty orders, criminal prosecution, fines, imprisonment, MAS enforcement action, prohibition orders, licence consequences, customer remediation and disgorgement where ordered. |
| 6 | Property Offences | Theft by bank employee, clerk or servant | Penal Code 1871, s381 | Aggravates theft committed by an employee of property in employer possession. It supports assessment of dishonest taking, retention, entrusted-property misuse, property loss and the consent element relevant to bank assets or customer property. | Applies where bank staff, branch staff, operations staff, contractors or secondees steal property held through banking work. It should be reviewed across branch counters, teller operations, vaults, cash rooms, ATMs, secured storage, customer-service areas, delivery points, outsourced handling and property entrusted to staff or vendors. | Imprisonment up to 7 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 7 | Property Offences | Dishonest misappropriation of branch collections or cash deposits | Penal Code 1871, s403 | Covers dishonest conversion of property to personal use. It supports assessment of dishonest taking, retention, entrusted-property misuse, property loss and the consent element relevant to bank assets or customer property. | Applies where funds, cards, documents, recovered property or customer assets are dishonestly retained or diverted. It should be reviewed across branch counters, teller operations, vaults, cash rooms, ATMs, secured storage, customer-service areas, delivery points, outsourced handling and property entrusted to staff or vendors. | Imprisonment up to 2 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 8 | Property Offences | Dishonest misappropriation of unclaimed or recovered customer property | Penal Code 1871, s403 | Covers dishonest conversion of property to personal use. It supports assessment of dishonest taking, retention, entrusted-property misuse, property loss and the consent element relevant to bank assets or customer property. | Applies where funds, cards, documents, recovered property or customer assets are dishonestly retained or diverted. It should be reviewed across branch counters, teller operations, vaults, cash rooms, ATMs, secured storage, customer-service areas, delivery points, outsourced handling and property entrusted to staff or vendors. | Imprisonment up to 2 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 9 | Property Offences | Criminal breach of trust by bank staff | Penal Code 1871, ss405-406 | Covers dishonest misappropriation or conversion of property entrusted to a person. It supports assessment of dishonest taking, retention, entrusted-property misuse, property loss and the consent element relevant to bank assets or customer property. | Applies where staff, agents or service providers misuse funds, securities, devices, access tokens, documents or customer property entrusted to them. It should be reviewed across branch counters, teller operations, vaults, cash rooms, ATMs, secured storage, customer-service areas, delivery points, outsourced handling and property entrusted to staff or vendors. | Imprisonment up to 7 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 10 | Property Offences | Criminal breach of trust by employee in banking operations | Penal Code 1871, s408 | Enhances punishment for criminal breach of trust by a clerk, servant or employee. It supports assessment of dishonest taking, retention, entrusted-property misuse, property loss and the consent element relevant to bank assets or customer property. | Applies where a bank employee misappropriates entrusted funds, securities, payment instruments, records or customer property. It should be reviewed across branch counters, teller operations, vaults, cash rooms, ATMs, secured storage, customer-service areas, delivery points, outsourced handling and property entrusted to staff or vendors. | Imprisonment up to 15 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 11 | Property Offences | Criminal breach of trust by banker or relationship manager | Penal Code 1871, s409 | Aggravates criminal breach of trust by banker, agent or person in a high-trust capacity. It supports assessment of dishonest taking, retention, entrusted-property misuse, property loss and the consent element relevant to bank assets or customer property. | Applies where banker, relationship manager, operations officer or entrusted agent dishonestly misuses customer or bank assets. It should be reviewed across branch counters, teller operations, vaults, cash rooms, ATMs, secured storage, customer-service areas, delivery points, outsourced handling and property entrusted to staff or vendors. | Imprisonment up to 20 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 12 | Property Offences | Misuse of customer deposits or entrusted funds | Penal Code 1871, s409 | Aggravates criminal breach of trust by banker, agent or person in a high-trust capacity. It supports assessment of dishonest taking, retention, entrusted-property misuse, property loss and the consent element relevant to bank assets or customer property. | Applies where banker, relationship manager, operations officer or entrusted agent dishonestly misuses customer or bank assets. It should be reviewed across branch counters, teller operations, vaults, cash rooms, ATMs, secured storage, customer-service areas, delivery points, outsourced handling and property entrusted to staff or vendors. | Imprisonment up to 20 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 13 | Property Offences | Misuse of client securities or custody assets | Penal Code 1871, s409 | Aggravates criminal breach of trust by banker, agent or personin a high-trust capacity. It supports assessment of dishonest taking, retention, entrusted-property misuse, property loss and the consent element relevant to bank assets or customer property. | Applies where banker, relationship manager, operations officer or entrustedagent dishonestly misuses customer or bank assets. It should be reviewed across branch counters, teller operations, vaults, cash rooms, ATMs, secured storage, customer-service areas, delivery points, outsourced handling and property entrusted to staff or vendors. | Imprisonment up to 20 years and liable to fine. Detailed punishmentdescription: market or sector consequences may include civil penalty orders, criminal prosecution, fines, imprisonment, MAS enforcement action, prohibition orders, licence consequences, customer remediation and disgorgement where ordered. |
| 14 | Property Offences | Misuse of safe deposit box contents | Penal Code 1871, s409 | Aggravates criminal breach of trust by banker, agent or person in a high-trust capacity. It supports assessment of dishonest taking, retention, entrusted-property misuse, property loss and the consent element relevant to bank assets or customer property. | Applies where banker, relationship manager, operations officer or entrusted agent dishonestly misuses customer or bank assets. It should be reviewed across branch counters, teller operations, vaults, cash rooms, ATMs, secured storage, customer-service areas, delivery points, outsourced handling and property entrusted to staff or vendors. | Imprisonment up to 20 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 15 | Property Offences | Misuse of escrow, trust or settlement monies | Penal Code 1871, s409 | Aggravates criminal breach of trust by banker, agent or person in a high-trust capacity. It supports assessment of dishonest taking, retention, entrusted-property misuse, property loss and the consent element relevant to bank assets or customer property. | Applies where banker, relationship manager, operations officer or entrusted agent dishonestly misuses customer or bank assets. It should be reviewed across branch counters, teller operations, vaults, cash rooms, ATMs, secured storage, customer-service areas, delivery points, outsourced handling and property entrusted to staff or vendors. | Imprisonment up to 20 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 16 | Property Offences | Receiving stolen bank or customer property | Penal Code 1871, ss410-411 | Covers receiving or retaining property known or believed to be stolen. It supports assessment of dishonest taking, retention, entrusted-property misuse, property loss and the consent element relevant to bank assets or customer property. | Applies where stolen cards, devices, documents, cash, cheques, tokens or securities are knowingly received or retained. It should be reviewed across branch counters, teller operations, vaults, cash rooms, ATMs, secured storage, customer-service areas, delivery points, outsourced handling and property entrusted to staff or vendors. | Imprisonment up to 5 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 17 | Property Offences | Assisting disposal of stolen cards, cheques or bank property | Penal Code 1871, s414 | Covers assisting concealment or disposal of stolen or dishonestly obtained property. It supports assessment of dishonest taking, retention, entrusted-property misuse, property loss and the consent element relevant to bank assets or customer property. | Applies where a person helps conceal stolen bank assets, customer property, fraud proceeds or compromised payment instruments. It should be reviewed across branch counters, teller operations, vaults, cash rooms, ATMs, secured storage, customer-service areas, delivery points, outsourced handling and property entrusted to staff or vendors. | Imprisonment up to 5 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 18 | Fraud Deception | Cheating a customer or bank counterparty | Penal Code 1871, ss415, 417 | Covers deception inducing a person to deliver property, consent, act or omit to act causing harm. It supports assessment of deception, false representation, non-disclosure, inducement, dishonest gain and loss caused to the bank, customer or counterparty. | Applies to deception of customers, bank officers, counterparties, guarantors, regulators, vendors or the public. It should be reviewed across onboarding, account servicing, lending, cards, payments, trade finance, customer instructions, vendor claims, approvals, refunds, waivers and customer or counterparty representations. | Imprisonment up to 3 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 19 | Fraud Deception | Cheating to obtain loan, credit card, overdraft or facility | Penal Code 1871, s420 | Covers cheating that dishonestly induces delivery of property or alteration/destruction of valuable security. It supports assessment of deception, false representation, non-disclosure, inducement, dishonest gain and loss caused to the bank, customer or counterparty. | Applies to fraudulent loan, account, card, investment, trade-finance, guarantee, insurance or payment claims. It should be reviewed across onboarding, account servicing, lending, cards, payments, trade finance, customer instructions, vendor claims, approvals, refunds, waivers and customer or counterparty representations. | Imprisonment up to 10 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 20 | Fraud Deception | Cheating to obtain bank account, payment service or guarantee | Penal Code 1871, s420 | Covers cheating that dishonestly induces delivery of property or alteration/destruction of valuable security. It supports assessment of deception, false representation, non-disclosure, inducement, dishonest gain and loss caused to the bank, customer or counterparty. | Applies to fraudulent loan, account, card, investment, trade-finance, guarantee, insurance or payment claims. It should be reviewed across onboarding, account servicing, lending, cards, payments, trade finance, customer instructions, vendor claims, approvals, refunds, waivers and customer or counterparty representations. | Imprisonment up to 10 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 21 | Fraud Deception | Cheating by personation as customer or authorised signatory | Penal Code 1871, ss416, 419 | Covers cheating by pretending to be another person or by personation. It supports assessment of deception, false representation, non-disclosure, inducement, dishonest gain and loss caused to the bank, customer or counterparty. | Applies where a person impersonates a customer, banker, authorised signatory, regulator, vendor, cardholder or beneficial owner. It should be reviewed across onboarding, account servicing, lending, cards, payments, trade finance, customer instructions, vendor claims, approvals, refunds, waivers and customer or counterparty representations. | Imprisonment up to 5 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 22 | Fraud Deception | Impersonating bank officer or MAS officer | Penal Code 1871, ss416, 419 | Covers cheating by pretending to be another person or by personation. It supports assessment of deception, false representation, non-disclosure, inducement, dishonest gain and loss caused to the bank, customer or counterparty. | Applies where a person impersonates a customer, banker, authorised signatory, regulator, vendor, cardholder or beneficial owner. It should be reviewed across onboarding, account servicing, lending, cards, payments, trade finance, customer instructions, vendor claims, approvals, refunds, waivers and customer or counterparty representations. | Imprisonment up to 5 years, fine, or both. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 23 | Fraud Deception | Loan application fraud | Penal Code 1871, s420 | Covers cheating that dishonestly induces delivery of property or alteration/destruction of valuable security. It supports assessment of deception, false representation, non-disclosure, inducement, dishonest gain and loss caused to the bank, customer or counterparty. | Applies to fraudulent loan, account, card, investment, trade-finance, guarantee, insurance or payment claims. It should be reviewed across onboarding, account servicing, lending, cards, payments, trade finance, customer instructions, vendor claims, approvals, refunds, waivers and customer or counterparty representations. | Imprisonment up to 10 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 24 | Fraud Deception | Mortgage or property-finance fraud | Penal Code 1871, s420 | Covers cheating that dishonestly induces delivery of property or alteration/destruction of valuable security. It supports assessment of deception, false representation, non-disclosure, inducement, dishonest gain and loss caused to the bank, customer or counterparty. | Applies to fraudulent loan, account, card, investment, trade-finance, guarantee, insurance or payment claims. It should be reviewed across onboarding, account servicing, lending, cards, payments, trade finance, customer instructions, vendor claims, approvals, refunds, waivers and customer or counterparty representations. | Imprisonment up to 10 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 25 | Fraud Deception | Trade-finance fraud involving invoices, bills or letters of credit | Penal Code 1871, s420 | Covers cheating that dishonestly induces delivery of property or alteration/destruction of valuable security. It supports assessment of deception, false representation, non-disclosure, inducement, dishonest gain and loss caused to the bank, customer or counterparty. | Applies to fraudulent loan, account, card, investment, trade-finance, guarantee, insurance or payment claims. It should be reviewed across onboarding, account servicing, lending, cards, payments, trade finance, customer instructions, vendor claims, approvals, refunds, waivers and customer or counterparty representations. | Imprisonment up to 10 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 26 | Fraud Deception | Credit card application or usage fraud | Penal Code 1871, s420 | Covers cheating that dishonestly induces delivery of property or alteration/destruction of valuable security. It supports assessment of deception, false representation, non-disclosure, inducement, dishonest gain and loss caused to the bank, customer or counterparty. | Applies to fraudulent loan, account, card, investment, trade-finance, guarantee, insurance or payment claims. It should be reviewed across onboarding, account servicing, lending, cards, payments, trade finance, customer instructions, vendor claims, approvals, refunds, waivers and customer or counterparty representations. | Imprisonment up to 10 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 27 | Fraud Deception | Debit card, ATM or payment-card fraud | Penal Code 1871, s420 | Covers cheating that dishonestly induces delivery of property or alteration/destruction of valuable security. It supports assessment of deception, false representation, non-disclosure, inducement, dishonest gain and loss caused to the bank, customer or counterparty. | Applies to fraudulent loan, account, card, investment, trade-finance, guarantee, insurance or payment claims. It should be reviewed across onboarding, account servicing, lending, cards, payments, trade finance, customer instructions, vendor claims, approvals, refunds, waivers and customer or counterparty representations. | Imprisonment up to 10 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 28 | Fraud Deception | Internet banking scam or payment instruction fraud | Penal Code 1871, s420 | Covers cheating that dishonestly induces delivery of property or alteration/destruction of valuable security. It supports assessment of deception, false representation, non-disclosure, inducement, dishonest gain and loss caused to the bank, customer or counterparty. | Applies to fraudulent loan, account, card, investment, trade-finance, guarantee, insurance or payment claims. It should be reviewed across onboarding, account servicing, lending, cards, payments, trade finance, customer instructions, vendor claims, approvals, refunds, waivers and customer or counterparty representations. | Imprisonment up to 10 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 29 | Fraud Deception | Business email compromise affecting bank payments | Penal Code 1871, s420 | Covers cheating that dishonestly induces delivery of property or alteration/destruction of valuable security. It supports assessment of deception, false representation, non-disclosure, inducement, dishonest gain and loss caused to the bank, customer or counterparty. | Applies to fraudulent loan, account, card, investment, trade-finance, guarantee, insurance or payment claims. It should be reviewed across onboarding, account servicing, lending, cards, payments, trade finance, customer instructions, vendor claims, approvals, refunds, waivers and customer or counterparty representations. | Imprisonment up to 10 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 30 | Fraud Deception | Fraud by false representation to bank | Penal Code 1871, s424A | Covers fraud by false representation, non-disclosure or abuse of position. It supports assessment of deception, false representation, non-disclosure, inducement, dishonest gain and loss caused to the bank, customer or counterparty. | Applies where banking position, information, system access or customer trust is abused for dishonest gain or to cause loss. It should be reviewed across onboarding, account servicing, lending, cards, payments, trade finance, customer instructions, vendor claims, approvals, refunds, waivers and customer or counterparty representations. | Imprisonment up to 20 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 31 | Fraud Deception | Fraud by failing to disclose material banking information | Penal Code 1871, s424A | Covers fraud by false representation, non-disclosure or abuse of position. It supports assessment of deception, false representation, non-disclosure, inducement, dishonest gain and loss caused to the bank, customer or counterparty. | Applies where banking position, information, system access or customer trust is abused for dishonest gain or to cause loss. It should be reviewed across onboarding, account servicing, lending, cards, payments, trade finance, customer instructions, vendor claims, approvals, refunds, waivers and customer or counterparty representations. | Imprisonment up to 20 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 32 | Fraud Deception | Fraud by abuse of banking position | Penal Code 1871, s424A | Covers fraud by false representation, non-disclosure or abuse of position. It supports assessment of deception, false representation, non-disclosure, inducement, dishonest gain and loss caused to the bank, customer or counterparty. | Applies where banking position, information, system access or customer trust is abused for dishonest gain or to cause loss. It should be reviewed across onboarding, account servicing, lending, cards, payments, trade finance, customer instructions, vendor claims, approvals, refunds, waivers and customer or counterparty representations. | Imprisonment up to 20 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 33 | Fraud Deception | False collateral, guarantee or security representation | Penal Code 1871, s424A | Covers fraud by false representation, non-disclosure or abuse of position. It supports assessment of deception, false representation, non-disclosure, inducement, dishonest gain and loss caused to the bank, customer or counterparty. | Applies where banking position, information, system access or customer trust is abused for dishonest gain or to cause loss. It should be reviewed across onboarding, account servicing, lending, cards, payments, trade finance, customer instructions, vendor claims, approvals, refunds, waivers and customer or counterparty representations. | Imprisonment up to 20 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 34 | Fraud Deception | False invoice or inflated billing to bank | Penal Code 1871, s424A | Covers fraud by false representation, non-disclosure or abuse of position. It supports assessment of deception, false representation, non-disclosure, inducement, dishonest gain and loss caused to the bank, customer or counterparty. | Applies where banking position, information, system access or customer trust is abused for dishonest gain or to cause loss. It should be reviewed across onboarding, account servicing, lending, cards, payments, trade finance, customer instructions, vendor claims, approvals, refunds, waivers and customer or counterparty representations. | Imprisonment up to 20 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 35 | Fraud Deception | Ghost vendor, ghost service or ghost employee scheme | Penal Code 1871, s420 | Covers cheating that dishonestly induces delivery of property or alteration/destruction of valuable security. It supports assessment of deception, false representation, non-disclosure, inducement, dishonest gain and loss caused to the bank, customer or counterparty. | Applies to fraudulent loan, account, card, investment, trade-finance, guarantee, insurance or payment claims. It should be reviewed across onboarding, account servicing, lending, cards, payments, trade finance, customer instructions, vendor claims, approvals, refunds, waivers and customer or counterparty representations. | Imprisonment up to 10 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 36 | Fraud Deception | Unauthorised refund, fee waiver or reversal | Penal Code 1871, ss405-406 | Covers dishonest misappropriation or conversion of property entrusted to a person. It supports assessment of deception, false representation, non-disclosure, inducement, dishonest gain and loss caused to the bank, customer or counterparty. | Applies where staff, agents or service providers misuse funds, securities, devices, access tokens, documents or customer property entrusted to them. It should be reviewed across onboarding, account servicing, lending, cards, payments, trade finance, customer instructions, vendor claims, approvals, refunds, waivers and customer or counterparty representations. | Imprisonment up to 7 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 37 | Fraud Deception | Unauthorised transfer or withdrawal from bank account | Penal Code 1871, s420 | Covers cheating that dishonestly induces delivery of property or alteration/destruction of valuable security. It supports assessment of deception, false representation, non-disclosure, inducement, dishonest gain and loss caused to the bank, customer or counterparty. | Applies to fraudulent loan, account, card, investment, trade-finance, guarantee, insurance or payment claims. It should be reviewed across onboarding, account servicing, lending, cards, payments, trade finance, customer instructions, vendor claims, approvals, refunds, waivers and customer or counterparty representations. | Imprisonment up to 10 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 38 | Property Offences | Mischief causing damage to ATM, branch or bank equipment | Penal Code 1871, ss425-427 | Covers wrongful loss or damage to property, including disruption of services or public agency functions. It supports assessment of dishonest taking, retention, entrusted-property misuse, property loss and the consent element relevant to bank assets or customer property. | Applies to damaging bank property, ATMs, network equipment, branch premises, records, safes or payment infrastructure. It should be reviewed across branch counters, teller operations, vaults, cash rooms, ATMs, secured storage, customer-service areas, delivery points, outsourced handling and property entrusted to staff or vendors. | Punishment depends on section and damage; may include imprisonment, fine, or both. Detailed punishment description: the exact penalty must be checked against the specific charging provision, offence facts, harm caused, offender role, aggravating factors, corporate liability rules and current statutory amendments. |
| 39 | Property Offences | Criminal trespass into branch, cash room, vault or data centre | Penal Code 1871, ss441, 447-448 | Covers criminal trespass and house-breaking into buildings or secured places. It supports assessment of dishonest taking, retention, entrusted-property misuse, property loss and the consent element relevant to bank assets or customer property. | Applies to unauthorised access to branches, cash rooms, data centres, vaults, operations floors or restricted premises. It should be reviewed across branch counters, teller operations, vaults, cash rooms, ATMs, secured storage, customer-service areas, delivery points, outsourced handling and property entrusted to staff or vendors. | Punishment depends on section; criminal trespass may carry imprisonment, fine, or both. Detailed punishment description: the exact penalty must be checked against the specific charging provision, offence facts, harm caused, offender role, aggravating factors, corporate liability rules and current statutory amendments. |
| 40 | Abetment Attempts | Abetment, conspiracy or attempt in banking theft, CBT or fraud | Penal Code 1871, ss107-109, 120A-120Band relevant principal offence | Covers abetment, conspiracy and attempts involving underlying offences. It supports assessment of assistance, planning, conspiracy, facilitation, coordinated misconduct and attempted commission of the underlying offence. | Applies where staff, customers, vendors, mule account holders or outsiders coordinate or attempt banking-related dishonesty. It should be reviewed wherever employees, customers, mule account holders, vendors, intermediaries, outsiders or managers coordinate, assist, attempt, conceal or facilitate the underlying misconduct. | Generally punished according to the principal offence, subject to applicable provisions. Detailed punishment description: liability normally tracks the principal offence and may extend to persons who plan, encourage, assist, facilitate, coordinate, conceal or attempt the misconduct, subject to the applicable Penal Code provisions and the facts proved. |
| 41 | Forgery Records | Making a false banking document or electronic record | Penal Code 1871, ss463-465 | Defines forgery and making false documents or electronic records. It supports assessment of false documents, altered records, forged signatures, dishonest record creation and reliance on documents as genuine. | Applies to false forms, signatures, instructions, statements, confirmations, facility documents, guarantees or digital records. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs, statements, confirmations, credit papers, audit files and regulatory submissions. | Imprisonment up to 4 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 42 | Forgery Records | Forgery for purpose of cheating a bank or customer | Penal Code 1871, s468 | Covers forgery committed for the purpose of cheating. It supports assessment of false documents, altered records, forged signatures, dishonest record creation and reliance on documents as genuine. | Applies where forged banking documents are used to obtain accounts, credit, payments, transfers, securities or regulatory advantage. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs, statements, confirmations, credit papers, audit files and regulatory submissions. | Imprisonment up to 10 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 43 | Forgery Records | Using forged banking document as genuine | Penal Code 1871, s471 | Covers fraudulent or dishonest use of a forged document or electronic record as genuine. It supports assessment of false documents, altered records, forged signatures, dishonest record creation and reliance on documents as genuine. | Applies where forged forms, cheques, trade documents, statements or identity documents are submitted to a bank. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs, statements, confirmations, credit papers, audit files and regulatory submissions. | Punished as if the person had forged the document or record. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 44 | Forgery Records | Forgery of customer signature or mandate | Penal Code 1871, ss463-465 | Defines forgery and making false documents or electronic records. It supports assessment of false documents, altered records, forged signatures, dishonest record creation and reliance on documents as genuine. | Applies to false forms, signatures, instructions, statements, confirmations, facility documents, guarantees or digital records. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs, statements, confirmations, credit papers, audit files and regulatory submissions. | Imprisonment up to 4 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 45 | Forgery Records | Forgery of cheque, cashier's order or bank draft | Penal Code 1871, s468 | Covers forgery committed for the purpose of cheating. It supports assessment of false documents, altered records, forged signatures, dishonest record creation and reliance on documents as genuine. | Applies where forged banking documents are used to obtain accounts, credit, payments, transfers, securities or regulatory advantage. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs, statements, confirmations, credit papers, audit files and regulatory submissions. | Imprisonment up to 10 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 46 | Forgery Records | Forgery of letter of credit or trade-finance document | Penal Code 1871, s468 | Covers forgery committed for the purpose of cheating. It supports assessment of false documents, altered records, forged signatures, dishonest record creation and reliance on documents as genuine. | Applies where forged banking documents are used to obtain accounts, credit, payments, transfers, securities or regulatory advantage. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs, statements, confirmations, credit papers, audit files and regulatory submissions. | Imprisonment up to 10 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 47 | Forgery Records | Forgery of bank guarantee or standby credit | Penal Code 1871, s468 | Covers forgery committed for the purpose of cheating. It supports assessment of false documents, altered records, forged signatures, dishonest record creation and reliance on documents as genuine. | Applies where forged banking documents are used to obtain accounts, credit, payments, transfers, securities or regulatory advantage. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs, statements, confirmations, credit papers, audit files and regulatory submissions. | Imprisonment up to 10 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 48 | Forgery Records | Forgery of account opening or KYC document | Penal Code 1871, ss463-465 | Defines forgery and making false documents or electronic records. It supports assessment of false documents, altered records, forged signatures, dishonest record creation and reliance on documents as genuine. | Applies to false forms, signatures, instructions, statements, confirmations, facility documents, guarantees or digital records. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs, statements, confirmations, credit papers, audit files and regulatory submissions. | Imprisonment up to 4 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 49 | Forgery Records | Forgery of identity document or proof of address submitted to bank | Penal Code 1871, s468 | Covers forgery committed for the purpose of cheating. It supports assessment of false documents, altered records, forged signatures, dishonest record creation and reliance on documents as genuine. | Applies where forged banking documents are used to obtain accounts, credit, payments, transfers, securities or regulatory advantage. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs, statements, confirmations, credit papers, audit files and regulatory submissions. | Imprisonment up to 10 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 50 | Forgery Records | Forgery of board resolution or authorised signatory list | Penal Code 1871, s468 | Covers forgery committed for the purpose of cheating. It supports assessment of false documents, altered records, forged signatures, dishonest record creation and reliance on documents as genuine. | Applies where forged banking documents are used to obtain accounts, credit, payments, transfers, securities or regulatory advantage. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs, statements, confirmations, credit papers, audit files and regulatory submissions. | Imprisonment up to 10 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 51 | Forgery Records | Forgery of loan, mortgage or security document | Penal Code 1871, s468 | Covers forgery committed for the purpose of cheating. It supports assessment of false documents, altered records, forged signatures, dishonest record creation and reliance on documents as genuine. | Applies where forged banking documents are used to obtain accounts, credit, payments, transfers, securities or regulatory advantage. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs, statements, confirmations, credit papers, audit files and regulatory submissions. | Imprisonment up to 10 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 52 | Forgery Records | Forgery of valuation, income or employment document | Penal Code 1871, s468 | Covers forgery committed for the purpose of cheating. It supports assessment of false documents, altered records, forged signatures, dishonest record creation and reliance on documents as genuine. | Applies where forged banking documents are used to obtain accounts, credit, payments, transfers, securities or regulatory advantage. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs, statements, confirmations, credit papers, audit files and regulatory submissions. | Imprisonment up to 10 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 53 | Forgery Records | Forgery of financial statement or management account | Penal Code 1871, s468 | Covers forgery committed for the purpose of cheating. It supports assessment of false documents, altered records, forged signatures, dishonest record creation and reliance on documents as genuine. | Applies where forged banking documents are used to obtain accounts, credit, payments, transfers, securities or regulatory advantage. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs, statements, confirmations, credit papers, audit files and regulatory submissions. | Imprisonment up to 10 years and liable to fine. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 54 | Forgery Records | Falsification of bank accounts, ledgers or reconciliations | Penal Code 1871, s477A | Covers falsifying accounts, books, electronic records or documents with intent to defraud. It supports assessment of false documents, altered records, forged signatures, dishonest record creation and reliance on documents as genuine. | Applies to false ledgers, reconciliations, approvals, logs, transaction records, account files or audit materials. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs, statements, confirmations, credit papers, audit files and regulatory submissions. | Imprisonment up to 10 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 55 | Forgery Records | Falsification of customer due diligence records | Penal Code 1871, s477A | Covers falsifying accounts, books, electronic records or documents with intent to defraud. It supports assessment of false documents, altered records, forged signatures, dishonest record creation and reliance on documents as genuine. | Applies to false ledgers, reconciliations, approvals, logs, transaction records, account files or audit materials. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs, statements, confirmations, credit papers, audit files and regulatory submissions. | Imprisonment up to 10 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 56 | Forgery Records | Falsification of transaction monitoring notes | Penal Code 1871, s477A | Covers falsifying accounts, books, electronic records or documents with intent to defraud. It supports assessment of false documents, altered records, forged signatures, dishonest record creation and reliance on documents as genuine. | Applies to false ledgers, reconciliations, approvals, logs, transaction records, account files or audit materials. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs, statements, confirmations, credit papers, audit files and regulatory submissions. | Imprisonment up to 10 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 57 | Forgery Records | Falsification of credit assessment or approval records | Penal Code 1871, s477A | Covers falsifying accounts, books, electronic records or documents with intent to defraud. It supports assessment of false documents, altered records, forged signatures, dishonest record creation and reliance on documents as genuine. | Applies to false ledgers, reconciliations, approvals, logs, transaction records, account files or audit materials. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs, statements, confirmations, credit papers, audit files and regulatory submissions. | Imprisonment up to 10 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 58 | Forgery Records | Falsification of collateral or security records | Penal Code 1871, s477A | Covers falsifying accounts, books, electronic records or documents with intent to defraud. It supports assessment of false documents, altered records, forged signatures, dishonest record creation and reliance on documents as genuine. | Applies to false ledgers, reconciliations, approvals, logs, transaction records, account files or audit materials. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs, statements, confirmations, credit papers, audit files and regulatory submissions. | Imprisonment up to 10 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 59 | Forgery Records | Falsification of treasury, trading or position records | Penal Code 1871, s477A | Covers falsifying accounts, books, electronic records or documents with intent to defraud. It supports assessment of false documents, altered records, forged signatures, dishonest record creation and reliance on documents as genuine. | Applies to false ledgers, reconciliations, approvals, logs, transaction records, account files or audit materials. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs, statements, confirmations, credit papers, audit files and regulatory submissions. | Imprisonment up to 10 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 60 | Forgery Records | Falsification of audit, compliance or risk records | Penal Code 1871, s477A | Covers falsifying accounts, books, electronic records or documents with intent to defraud. It supports assessment of false documents, altered records, forged signatures, dishonest record creation and reliance on documents as genuine. | Applies to false ledgers, reconciliations, approvals, logs, transaction records, account files or audit materials. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs, statements, confirmations, credit papers, audit files and regulatory submissions. | Imprisonment up to 10 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 61 | Forgery Records | Backdating of approvals, instructions or confirmations | Penal Code 1871, s477A | Covers falsifying accounts, books, electronic records or documents with intent to defraud. It supports assessment of false documents, altered records, forged signatures, dishonest record creation and reliance on documents as genuine. | Applies to false ledgers, reconciliations, approvals, logs, transaction records, account files or audit materials. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs, statements, confirmations, credit papers, audit files and regulatory submissions. | Imprisonment up to 10 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 62 | Forgery Records | False regulatory return or MAS submission | Penal Code 1871, ss191-193, 196, 199and related provisions | Protects legal, regulatory and investigative proceedings from false evidence and false statements. It supports assessment of false documents, altered records, forged signatures, dishonest record creation and reliance on documents as genuine. | Applies where false statements, declarations, evidence, confirmations or reports are given to auditors, MAS, police, court or investigators. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs, statements, confirmations, credit papers, audit files and regulatory submissions. | Punishment depends on section; false evidence may carry imprisonment and fine. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 63 | Evidence Obstruction | False statement to auditor, MAS, police or investigator | Penal Code 1871, ss191-193, 196, 199and related provisions | Protects legal, regulatory and investigative proceedings from false evidence and false statements. It supports assessment of concealment, destruction, withholding, false statements and conduct that frustrates lawful inquiries, audits or enforcement action. | Applies where false statements, declarations, evidence, confirmations or reports are given to auditors, MAS, police, court or investigators. It should be reviewed across internal inquiries, audit reviews, MAS inspections, police investigations, complaint handling, disciplinary processes, document production, CCTV retention and electronic-record preservation. | Punishment depends on section; false evidence may carry imprisonment and fine. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 64 | Evidence Obstruction | False suspicious transaction explanation or investigation note | Penal Code 1871, ss191-193, 196, 199and related provisions | Protects legal, regulatory and investigative proceedings from false evidence and false statements. It supports assessment of concealment, destruction, withholding, false statements and conduct that frustrates lawful inquiries, audits or enforcement action. | Applies where false statements, declarations, evidence, confirmations or reports are given to auditors, MAS, police, court or investigators. It should be reviewed across internal inquiries, audit reviews, MAS inspections, police investigations, complaint handling, disciplinary processes, document production, CCTV retention and electronic-record preservation. | Punishment depends on section; false evidence may carry imprisonment and fine. Detailed punishment description: the exact penalty must be checked against the specific charging provision, offence facts, harm caused, offender role, aggravating factors, corporate liability rules and current statutory amendments. |
| 65 | Evidence Obstruction | Concealment or destruction of bank records | Penal Code 1871, ss175, 186, 201, 203, 204 | Protects lawful production of documents, investigations and evidence integrity. It supports assessment of concealment, destruction, withholding, false statements and conduct that frustrates lawful inquiries, audits or enforcement action. | Applies where documents are withheld, evidence destroyed, witnesses coached or MAS/police/auditors are obstructed. It should be reviewed across internal inquiries, audit reviews, MAS inspections, police investigations, complaint handling, disciplinary processes, document production, CCTV retention and electronic-record preservation. | Penalty depends on section and underlying offence; regulatory action may also apply. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 66 | Evidence Obstruction | Deletion or alteration of audit logs or CCTV evidence | Penal Code 1871, ss175, 186, 201, 203, 204 | Protects lawful production of documents, investigations and evidence integrity. It supports assessment of concealment, destruction, withholding, false statements and conduct thatfrustrates lawful inquiries, audits or enforcement action. | Applies where documents are withheld, evidence destroyed, witnesses coached or MAS/police/auditors are obstructed. It should be reviewed across internal inquiries, audit reviews, MAS inspections, police investigations,complaint handling, disciplinary processes, document production, CCTV retention and electronic-record preservation. | Penalty depends on section and underlying offence; regulatory action may also apply. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directionsto remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 67 | Evidence Obstruction | Refusal to produce documents when legally required | Penal Code 1871, ss175, 186, 201, 203, 204 | Protects lawful production of documents, investigations and evidence integrity. It supports assessment of concealment, destruction, withholding, false statements and conduct that frustrates lawful inquiries, audits or enforcement action. | Applies where documents are withheld, evidence destroyed, witnesses coached or MAS/police/auditors are obstructed. It should be reviewed across internal inquiries, audit reviews, MAS inspections, police investigations, complaint handling, disciplinary processes, document production, CCTV retention and electronic-record preservation. | Penalty depends on section and underlying offence; regulatory action may also apply. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 68 | Evidence Obstruction | Obstruction of MAS, police, auditor or internal investigation | Penal Code 1871, ss175, 186, 201, 203, 204 | Protects lawful production of documents, investigations and evidence integrity. It supports assessment of concealment, destruction, withholding, false statements and conduct that frustrates lawful inquiries, audits or enforcement action. | Applies where documents are withheld, evidence destroyed, witnesses coached or MAS/police/auditors are obstructed. It should be reviewed across internal inquiries, audit reviews, MAS inspections, police investigations, complaint handling, disciplinary processes, document production, CCTV retention and electronic-record preservation. | Penalty depends on section and underlying offence; regulatory action may also apply. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 69 | Evidence Obstruction | Witness intimidation or coaching in bank inquiry | Penal Code 1871, ss175, 186, 201, 203, 204 | Protects lawful production of documents, investigations and evidence integrity. It supports assessment of concealment, destruction, withholding, false statements and conduct that frustrates lawful inquiries, audits or enforcement action. | Applies where documents are withheld, evidence destroyed, witnesses coached or MAS/police/auditors are obstructed. It should be reviewed across internal inquiries, audit reviews, MAS inspections, police investigations, complaint handling, disciplinary processes, document production, CCTV retention and electronic-record preservation. | Penalty depends on section and underlying offence; regulatory action may also apply. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 70 | Abetment Attempts | Abetment, conspiracy or attempt in forgery or false-record offences | Penal Code 1871, ss107-109, 120A-120Band relevant principal offence | Covers abetment, conspiracy and attempts involving underlying offences. It supports assessment of assistance, planning, conspiracy, facilitation, coordinated misconduct and attempted commission of the underlying offence. | Applies where staff, customers, vendors, mule account holders or outsiders coordinate or attempt banking-related dishonesty. It should be reviewed wherever employees, customers, mule account holders, vendors, intermediaries, outsiders or managers coordinate, assist, attempt, conceal or facilitate the underlying misconduct. | Generally punished according to the principal offence, subject to applicable provisions. Detailed punishment description: liability normally tracks the principal offence and may extend to persons who plan, encourage, assist, facilitate, coordinate, conceal or attempt the misconduct, subject to the applicable Penal Code provisions and the facts proved. |
| 71 | Licensing Approvals | Carrying on banking business without licence | Banking Act 1970, ss4, 4A, 4B, 20, 66-67, 71;Monetary Authority of Singapore Act 1970, ss27A-27B, 28; MAS notices | Regulates licensing, prudential soundness, governance, supervision and conduct of banking business. It supports assessment of authorisation status, licence scope, approval conditions, regulatory permissions and whether banking or related activities were conducted lawfully. | Applies where a bank, merchant bank, branch, subsidiary, controller, officer or outsourced service provider breaches banking regulatory requirements. It should be reviewed across licensed banking activities, merchant banking, digital banking, payment services, representative appointments, control changes, approved persons, licence conditions and scope restrictions. | MAS directions, reprimands, composition, civil penalties, licence restrictions/revocation or prosecution; exact provision to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 72 | Licensing Approvals | Operating outside scope of banking licence or approval | Banking Act 1970, ss4, 4A, 4B, 20, 66-67, 71;Monetary Authority of Singapore Act 1970, ss27A-27B, 28; MAS notices | Regulates licensing, prudential soundness, governance, supervision and conduct of banking business. It supports assessment of authorisation status, licence scope, approval conditions, regulatory permissions and whether banking or related activities were conducted lawfully. | Applies where a bank, merchant bank, branch, subsidiary, controller, officer or outsourced service provider breaches banking regulatory requirements. It should be reviewed across licensed banking activities, merchant banking, digital banking, payment services, representative appointments, control changes, approved persons, licence conditions and scope restrictions. | MAS directions, reprimands, composition, civil penalties, licence restrictions/revocation or prosecution; exact provision to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 73 | Licensing Approvals | Breach of bank licence condition or MAS restriction | Banking Act 1970, ss4, 4A, 4B, 20, 66-67, 71;Monetary Authority of Singapore Act 1970, ss27A-27B, 28; MAS notices | Regulates licensing, prudential soundness, governance, supervision and conduct of banking business. It supports assessment of authorisation status, licence scope, approval conditions, regulatory permissions and whether banking or related activities were conducted lawfully. | Applies where a bank, merchant bank, branch, subsidiary, controller, officer or outsourced service provider breaches banking regulatory requirements. It should be reviewed across licensed banking activities, merchant banking, digital banking, payment services, representative appointments, control changes, approved persons, licence conditions and scope restrictions. | MAS directions, reprimands, composition, civil penalties, licence restrictions/revocation or prosecution; exact provision to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 74 | Regulatory Duties | Failure to comply with MAS direction or requirement | Banking Act 1970, ss4, 4A, 4B, 20, 66-67, 71;Monetary Authority of Singapore Act 1970, ss27A-27B, 28; MAS notices | Regulates licensing, prudential soundness, governance, supervision and conduct of banking business. It supports assessment of statutory duties, MAS requirements, prudential obligations, reporting duties and compliance standards imposed on banking operations. | Applies where a bank, merchant bank, branch, subsidiary, controller, officer or outsourced service provider breaches banking regulatory requirements. It should be reviewed across prudential reporting, MAS returns, capital and liquidity monitoring, large exposures, related-party dealings, remediation tracking, incident notification and regulatory correspondence. | MAS directions, reprimands, composition, civil penalties, licence restrictions/revocation or prosecution; exact provision to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 75 | Licensing Approvals | False or misleading information in banking licence application | Banking Act 1970, ss4, 4A, 4B, 20, 66-67, 71;Monetary Authority of Singapore Act 1970, ss27A-27B, 28; MAS notices | Regulates licensing, prudential soundness, governance, supervision and conduct of banking business. It supports assessment of authorisation status, licence scope, approval conditions, regulatory permissions and whether banking or related activities were conducted lawfully. | Applies where a bank, merchant bank, branch, subsidiary, controller, officer or outsourced service provider breaches banking regulatory requirements. It should be reviewed across licensed banking activities, merchant banking, digital banking, payment services, representative appointments, control changes, approved persons, licence conditions and scope restrictions. | MAS directions, reprimands, composition, civil penalties, licence restrictions/revocation or prosecution; exact provision to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 76 | Licensing Approvals | Failure to obtain approval for substantial shareholding or control change | Banking Act 1970, ss15-17, 66-67, 71; MAS notices | Supports MAS supervision through accurate information, approval requirements, prudential rules and regulatory reporting. It supports assessment of authorisation status, licence scope, approval conditions, regulatory permissions and whether banking or related activities were conducted lawfully. | Applies to breaches involving capital, liquidity, exposures, related-party transactions, outsourcing, risk management, governance or returns. It should be reviewed across licensed banking activities, merchant banking, digital banking, payment services, representative appointments, control changes, approved persons, licence conditions and scope restrictions. | Regulatory action, financial penalties, licence conditions or prosecution depending provision; verify exact penalty. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 77 | Professional Conduct | Failure to comply with fit-and-proper expectations for directors or senior managers | Banking Act 1970, ss65-67, 71; MAS notices | Supports MAS supervision through accurate information, approval requirements, prudential rules and regulatory reporting. It supports assessment of advisory duties, fair dealing, competence, suitability, supervision, disclosure and customer-facing conduct standards. | Applies to breaches involving capital, liquidity, exposures, related-party transactions, outsourcing, risk management, governance or returns. It should be reviewed across wealth management, relationship managers, advisory representatives, product distribution, investment recommendations, product switching, vulnerable customers, complaint handling and supervisory review. | Regulatory action, financial penalties, licence conditions or prosecution depending provision; verify exact penalty. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 78 | Regulatory Duties | Failure to maintain minimum capital or capital adequacy requirement | Banking Act 1970, ss9-10B, 66-67, 71; MAS notices | Supports MAS supervision through accurate information, approval requirements, prudential rules and regulatory reporting. It supports assessment of statutory duties, MAS requirements, prudential obligations, reporting duties and compliance standards imposed on banking operations. | Applies to breaches involving capital, liquidity, exposures, related-party transactions, outsourcing, risk management, governance or returns. It should be reviewed across prudential reporting, MAS returns, capital and liquidity monitoring, large exposures, related-party dealings, remediation tracking, incident notification and regulatory correspondence. | Regulatory action, financial penalties, licence conditions or prosecution depending provision; verify exact penalty. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 79 | Regulatory Duties | Failure to maintain liquidity or liquidity coverage requirements | Banking Act 1970, s38, ss66-67, 71; MAS notices | Supports MAS supervision through accurate information, approval requirements, prudential rules and regulatory reporting. It supports assessment of statutory duties, MAS requirements, prudential obligations, reporting duties and compliance standards imposed on banking operations. | Applies to breaches involving capital, liquidity, exposures, related-party transactions, outsourcing, risk management, governance or returns. It should be reviewed across prudential reporting, MAS returns, capital and liquidity monitoring, large exposures, related-party dealings, remediation tracking, incident notification and regulatory correspondence. | Regulatory action, financial penalties, licence conditions or prosecution depending provision; verify exact penalty. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 80 | Regulatory Duties | Failure to comply with large exposure limits | Banking Act 1970, ss27-29, 66-67, 71; MAS notices | Supports MAS supervision through accurate information, approval requirements, prudential rules and regulatory reporting. It supports assessment of statutory duties, MASrequirements, prudential obligations, reporting duties and compliance standards imposed on banking operations. | Applies to breaches involving capital, liquidity, exposures, related-party transactions, outsourcing, risk management, governance or returns. It should be reviewed across prudential reporting, MAS returns, capital and liquiditymonitoring, large exposures, related-party dealings, remediation tracking, incident notification and regulatory correspondence. | Regulatory action, financial penalties, licence conditions or prosecution depending provision; verify exact penalty. Detailed punishment description: enforcement may include MAS reprimands, compositionsums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 81 | Regulatory Duties | Excessive related-party exposure or connected lending breach | Banking Act 1970, ss27-29, 66-67, 71; MAS notices | Supports MAS supervision through accurate information, approval requirements, prudential rules and regulatory reporting. It supports assessment of statutory duties, MAS requirements, prudential obligations, reporting duties and compliance standards imposed on banking operations. | Applies to breaches involving capital, liquidity, exposures, related-party transactions, outsourcing, risk management, governance or returns. It should be reviewed across prudential reporting, MAS returns, capital and liquidity monitoring, large exposures, related-party dealings, remediation tracking, incident notification and regulatory correspondence. | Regulatory action, financial penalties, licence conditions or prosecution depending provision; verify exact penalty. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 82 | Regulatory Duties | Breach of credit concentration or country risk limits | Banking Act 1970, ss27-29, 66-67, 71; MAS notices | Supports MAS supervision through accurate information, approval requirements, prudential rules and regulatory reporting. It supports assessment of statutory duties, MAS requirements, prudential obligations, reporting duties and compliance standards imposed on banking operations. | Applies to breaches involving capital, liquidity, exposures, related-party transactions, outsourcing, risk management, governance or returns. It should be reviewed across prudential reporting, MAS returns, capital and liquidity monitoring, large exposures, related-party dealings, remediation tracking, incident notification and regulatory correspondence. | Regulatory action, financial penalties, licence conditions or prosecution depending provision; verify exact penalty. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 83 | Regulatory Duties | Improper classification or provisioning of credit exposures | Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71; MAS notices | Supports MAS supervision through accurate information, approval requirements, prudential rules and regulatory reporting. It supports assessment of statutory duties, MAS requirements, prudential obligations, reporting duties and compliance standards imposed on banking operations. | Applies to breaches involving capital, liquidity, exposures, related-party transactions, outsourcing, risk management, governance or returns. It should be reviewed across prudential reporting, MAS returns, capital and liquidity monitoring, large exposures, related-party dealings, remediation tracking, incident notification and regulatory correspondence. | Regulatory action, financial penalties, licence conditions or prosecution depending provision; verify exact penalty. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 84 | Regulatory Duties | Failure to maintain sound credit underwriting controls | Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71; MAS notices | Supports MAS supervision through accurate information, approval requirements, prudential rules and regulatory reporting. It supports assessment of statutory duties, MAS requirements, prudential obligations, reporting duties and compliance standards imposed on banking operations. | Applies to breaches involving capital, liquidity, exposures, related-party transactions, outsourcing, risk management, governance or returns. It should be reviewed across prudential reporting, MAS returns, capital and liquidity monitoring, large exposures, related-party dealings, remediation tracking, incident notification and regulatory correspondence. | Regulatory action, financial penalties, licence conditions or prosecution depending provision; verify exact penalty. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 85 | Regulatory Duties | Failure to manage non-performing loans and impaired assets properly | Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71; MAS notices | Supports MAS supervision through accurate information, approval requirements, prudential rules and regulatory reporting. It supports assessment of statutory duties, MAS requirements, prudential obligations, reporting duties and compliance standards imposed on banking operations. | Applies to breaches involving capital, liquidity, exposures, related-party transactions, outsourcing, risk management, governance or returns. It should be reviewed across prudential reporting, MAS returns, capital and liquidity monitoring, large exposures, related-party dealings, remediation tracking, incident notification and regulatory correspondence. | Regulatory action, financial penalties, licence conditions or prosecution depending provision; verify exact penalty. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 86 | Governance Controls | Failure to maintain proper risk management framework | Banking Act 1970, ss43-45, 58, 66-67, 71; MAS notices | Supports MAS supervision through accurate information, approval requirements, prudential rules and regulatory reporting. It supports assessment of oversight, risk ownership, internal controls, auditability, management accountability and whether control failures enabled the breach. | Applies to breaches involving capital, liquidity, exposures, related-party transactions, outsourcing, risk management, governance or returns. It should be reviewed across board oversight, senior management, risk committees, compliance, internal audit, operations, outsourcing governance, segregation of duties, escalation channels and remediation ownership. | Regulatory action, financial penalties, licence conditions or prosecution depending provision; verify exact penalty. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 87 | Governance Controls | Failure to maintain internal controls over branch operations | Banking Act 1970, ss43-45, 58, 66-67, 71; MAS notices | Supports MAS supervision through accurate information, approval requirements, prudential rules and regulatory reporting. It supports assessment of oversight, risk ownership, internal controls, auditability, management accountability and whether control failures enabled the breach. | Applies to breaches involving capital, liquidity, exposures, related-party transactions, outsourcing, risk management, governance or returns. It should be reviewed across board oversight, senior management, risk committees, compliance, internal audit, operations, outsourcing governance, segregation of duties, escalation channels and remediation ownership. | Regulatory action, financial penalties, licence conditions or prosecution depending provision; verify exact penalty. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 88 | Governance Controls | Failure to maintain segregation of duties in banking operations | Banking Act 1970, ss43-45, 58, 66-67, 71; MAS notices | Supports MAS supervision through accurate information, approval requirements, prudential rules and regulatory reporting. It supports assessment of oversight, risk ownership, internal controls, auditability, management accountability and whether control failures enabled the breach. | Applies to breaches involving capital, liquidity, exposures, related-party transactions, outsourcing, risk management, governance or returns. It should be reviewed across board oversight, senior management, risk committees, compliance, internal audit, operations, outsourcing governance, segregation of duties, escalation channels and remediation ownership. | Regulatory action, financial penalties, licence conditions or prosecution depending provision; verify exact penalty. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 89 | Governance Controls | Failure to maintain compliance function independence | Banking Act 1970, ss43-45, 58, 66-67, 71; MAS notices | Supports MAS supervision through accurate information, approval requirements, prudential rules and regulatory reporting. It supports assessment of oversight, risk ownership, internal controls, auditability, management accountability and whether control failures enabled the breach. | Applies to breaches involving capital, liquidity, exposures, related-party transactions, outsourcing, risk management, governance or returns. It should be reviewed across board oversight, senior management, risk committees, compliance, internal audit, operations, outsourcing governance, segregation of duties, escalation channels and remediation ownership. | Regulatory action, financial penalties, licence conditions or prosecution depending provision; verify exact penalty. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 90 | Governance Controls | Failure to maintain internal audit coverage | Banking Act 1970, ss43-45, 58, 66-67, 71; MAS notices | Supports MAS supervision through accurate information, approval requirements, prudential rules and regulatory reporting. It supports assessment of oversight, risk ownership, internal controls, auditability, management accountability and whether control failures enabled the breach. | Applies to breaches involving capital, liquidity, exposures, related-party transactions, outsourcing, risk management, governance or returns. It should be reviewed across board oversight, senior management, risk committees, compliance, internal audit, operations, outsourcing governance, segregation of duties, escalation channels and remediation ownership. | Regulatory action, financial penalties, licence conditions or prosecution depending provision; verify exact penalty. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 91 | Governance Controls | Failure to maintain outsourcing controls for material services | Banking Act 1970, s47A;Financial Services and Markets Act 2022, s29; MAS notices | Supports MAS supervision through accurate information, approval requirements, prudential rules and regulatory reporting. It supports assessment of oversight, risk ownership, internal controls, auditability, management accountability and whether control failures enabled the breach. | Applies to breaches involving capital, liquidity, exposures, related-party transactions, outsourcing, risk management, governance or returns. It should be reviewed across board oversight, senior management, risk committees, compliance, internal audit, operations, outsourcing governance, segregation of duties, escalation channels and remediation ownership. | Regulatory action, financial penalties, licence conditions or prosecution depending provision; verify exact penalty. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 92 | Governance Controls | Failure to manage overseas branch or subsidiary regulatory risk | Banking Act 1970, ss47, 47Aand Third Schedule; MAS notices | Supports MAS supervision through accurate information, approval requirements, prudential rules and regulatory reporting. It supports assessment of oversight, risk ownership, internal controls, auditability, management accountability and whether control failures enabled the breach. | Applies to breaches involving capital, liquidity, exposures, related-party transactions, outsourcing, risk management, governance or returns. It should be reviewed across board oversight, senior management, risk committees, compliance, internal audit, operations, outsourcing governance, segregation of duties, escalation channels and remediation ownership. | Regulatory action, financial penalties, licence conditions or prosecution depending provision; verify exact penalty. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 93 | Licensing Approvals | Improper use of bank name, licence status or MAS authorisation | Banking Act 1970, ss4, 4A, 4B, 20, 66-67, 71;Monetary Authority of Singapore Act 1970, ss27A-27B, 28; MAS notices | Regulates licensing, prudential soundness, governance, supervision and conduct of banking business. It supports assessment of authorisation status, licence scope, approval conditions, regulatory permissions and whether banking or related activities were conducted lawfully. | Applies where a bank, merchant bank, branch, subsidiary, controller, officer or outsourced service provider breaches banking regulatory requirements. It should be reviewed across licensed banking activities, merchant banking, digital banking, payment services, representative appointments, control changes, approved persons, licence conditions and scope restrictions. | MAS directions, reprimands, composition, civil penalties, licence restrictions/revocation or prosecution; exact provision to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation,prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 94 | Licensing Approvals | Misleading representation that entity is authorised as a bank | Banking Act 1970, ss4, 4A, 4B, 20, 66-67, 71;Monetary Authority of Singapore Act 1970, ss27A-27B, 28; MAS notices | Regulates licensing, prudential soundness, governance, supervision and conduct of banking business. It supports assessment of authorisation status, licence scope, approval conditions, regulatory permissions and whether banking or related activities were conducted lawfully. | Applies where a bank, merchant bank, branch, subsidiary, controller, officer or outsourced service provider breaches banking regulatory requirements. It should be reviewed across licensed banking activities, merchant banking, digital banking, payment services, representative appointments, control changes, approved persons, licence conditions and scope restrictions. | MAS directions, reprimands, composition, civil penalties, licence restrictions/revocation or prosecution; exact provision to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 95 | Data Protection | Breach of bank secrecy or customer information rules | Banking Act 1970, ss47, 47Aand Third Schedule;PDPA 2012, ss24, 48D-48J | Protects customer information and restricts unauthorised disclosure. It supports assessment of confidentiality, personal data handling, disclosure controls, protection obligations, retention practices and breach notification duties. | Applies where customer account, transaction, credit, wealth, KYC or personal data is disclosed without lawful basis. It should be reviewed across customer records, employee records, beneficial-owner files, statements, KYC documents, call-centre records, vendor transfers, overseas processing, AI tools and breach-response workflows. | Banking Act/PDPA penalties, MAS action, civil liability and disciplinary consequences depending facts. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 96 | Data Protection | Unauthorised access to or disclosure of customer financial information | Banking Act 1970, ss47, 47Aand Third Schedule;PDPA 2012, ss24, 48D-48J | Protects customer information and restricts unauthorised disclosure. It supports assessment of confidentiality, personal data handling, disclosure controls, protection obligations, retention practices and breach notification duties. | Applies where customer account, transaction, credit, wealth, KYC or personal data is disclosed without lawful basis. It should be reviewed across customer records, employee records, beneficial-owner files, statements, KYC documents, call-centre records, vendor transfers, overseas processing, AI tools and breach-response workflows. | Banking Act/PDPA penalties, MAS action, civil liability and disciplinary consequences depending facts. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 97 | Data Protection | Improper disclosure to related company or external vendor | Banking Act 1970, ss47, 47Aand Third Schedule;PDPA 2012, ss24, 26, 26B-26D, 48I-48J | Protects customer information and restricts unauthorised disclosure. It supports assessment of confidentiality, personal data handling, disclosure controls, protection obligations, retention practices and breach notification duties. | Applies where customer account, transaction, credit, wealth, KYC or personal data is disclosed without lawful basis. It should be reviewed across customer records, employee records, beneficial-owner files, statements, KYC documents, call-centre records, vendor transfers, overseas processing, AI tools and breach-response workflows. | Banking Act/PDPA penalties, MAS action, civil liability and disciplinary consequences depending facts. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 98 | Data Protection | Failure to safeguard customer statements, account files or KYC data | Banking Act 1970, ss47, 47Aand Third Schedule;PDPA 2012, ss24, 48D-48J | Protects customer information and restricts unauthorised disclosure. It supports assessment of confidentiality, personal data handling, disclosure controls, protection obligations, retention practices and breach notification duties. | Applies where customer account, transaction, credit, wealth, KYC or personal data is disclosed without lawful basis. It should be reviewed across customer records, employee records, beneficial-owner files, statements, KYC documents, call-centre records, vendor transfers, overseas processing, AI tools and breach-response workflows. | Banking Act/PDPA penalties, MAS action, civil liability and disciplinary consequences depending facts. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 99 | Regulatory Duties | Failure to notify MAS of material incident or breach where required | Banking Act 1970, ss43-45, 58, 66-67, 71; MAS notices | Supports MAS supervision through accurate information, approval requirements, prudential rules and regulatory reporting. It supports assessment of statutory duties, MAS requirements, prudential obligations, reporting duties and compliance standards imposed on banking operations. | Applies to breaches involving capital, liquidity, exposures, related-party transactions, outsourcing, risk management, governance or returns. It should be reviewed across prudential reporting, MAS returns, capital and liquidity monitoring, large exposures, related-party dealings, remediation tracking, incident notification and regulatory correspondence. | Regulatory action, financial penalties, licence conditions or prosecution depending provision; verify exact penalty. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 100 | Regulatory Duties | Failure to submit accurate prudential returns | Banking Act 1970, ss43-45, 58, 66-67, 71; MAS notices | Supports MAS supervision through accurate information, approval requirements, prudential rules and regulatory reporting. It supports assessment of statutory duties, MAS requirements, prudential obligations, reporting duties and compliance standards imposed on banking operations. | Applies to breaches involving capital, liquidity, exposures, related-party transactions, outsourcing, risk management, governance or returns. It should be reviewed across prudential reporting, MAS returns, capital and liquidity monitoring, large exposures, related-party dealings, remediation tracking, incident notification and regulatory correspondence. | Regulatory action, financial penalties, licence conditions or prosecution depending provision; verify exact penalty. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 101 | Regulatory Duties | Failure to submit accurate statistical, liquidity or capital reports | Banking Act 1970, ss9-10B, 66-67, 71; MAS notices | Supports MAS supervision through accurate information, approval requirements, prudential rules and regulatory reporting. It supports assessment of statutory duties, MAS requirements, prudential obligations, reporting duties and compliance standards imposed on banking operations. | Applies to breaches involving capital, liquidity, exposures, related-party transactions, outsourcing, risk management, governance or returns. It should be reviewed across prudential reporting, MAS returns, capital and liquidity monitoring, large exposures, related-party dealings, remediation tracking, incident notification and regulatory correspondence. | Regulatory action, financial penalties, licence conditions or prosecution depending provision; verify exact penalty. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 102 | Regulatory Duties | Failure to keep proper books, accounts and records | Banking Act 1970, ss43-45, 58, 66-67, 71; MAS notices | Supports MAS supervision through accurate information, approval requirements, prudential rules and regulatory reporting. It supports assessment of statutory duties, MAS requirements, prudential obligations, reporting duties and compliance standards imposed on banking operations. | Applies to breaches involving capital, liquidity, exposures, related-party transactions, outsourcing, risk management, governance or returns. It should be reviewed across prudential reporting, MAS returns, capital and liquidity monitoring, large exposures, related-party dealings, remediation tracking, incident notification and regulatory correspondence. | Regulatory action, financial penalties, licence conditions or prosecution depending provision; verify exact penalty. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 103 | Regulatory Duties | Failure to comply with MAS inspection or supervisory review | Banking Act 1970, ss43-45, 58, 66-67, 71;Monetary Authority of Singapore Act 1970, ss27A-27B, 28; MAS notices | Supports MAS supervision through accurate information, approval requirements, prudential rules and regulatory reporting. It supports assessment of statutory duties, MAS requirements, prudential obligations, reporting duties and compliance standards imposed on banking operations. | Applies to breaches involving capital, liquidity, exposures, related-party transactions, outsourcing, risk management, governance or returns. It should be reviewed across prudential reporting, MAS returns, capital and liquidity monitoring, large exposures, related-party dealings, remediation tracking, incident notification and regulatory correspondence. | Regulatory action, financial penalties, licence conditions or prosecution depending provision; verify exact penalty. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 104 | Regulatory Duties | Failure to remediate MAS inspection finding | Banking Act 1970, ss43-45, 58, 66-67, 71;Monetary Authority of Singapore Act 1970, ss27A-27B, 28; MAS notices | Supports MAS supervision through accurate information, approval requirements, prudential rules and regulatory reporting. It supports assessment of statutory duties, MAS requirements, prudential obligations, reporting duties and compliance standards imposed on banking operations. | Applies to breaches involving capital, liquidity, exposures, related-party transactions, outsourcing, risk management, governance or returns. It should be reviewed across prudential reporting, MAS returns, capital and liquidity monitoring, large exposures, related-party dealings, remediation tracking, incident notification and regulatory correspondence. | Regulatory action, financial penalties, licence conditions or prosecution depending provision; verify exact penalty. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 105 | Regulatory Duties | Failure to comply with public disclosure or financial reporting requirements | Banking Act 1970, ss47, 47Aand Third Schedule; MAS notices | Supports MAS supervision through accurate information, approval requirements, prudential rules and regulatory reporting. It supports assessment of statutory duties, MAS requirements, prudential obligations, reporting duties and compliance standards imposed on banking operations. | Applies to breaches involving capital, liquidity, exposures, related-party transactions, outsourcing, risk management, governance or returns. It should be reviewed across prudential reporting, MAS returns, capital and liquidity monitoring, large exposures, related-party dealings, remediation tracking, incident notification and regulatory correspondence. | Regulatory action, financial penalties, licence conditions or prosecution depending provision; verify exact penalty. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 106 | Sector Breaches | Failure to comply with deposit-taking restrictions | Banking Act 1970, ss4, 4A, 4B, 20, 66-67, 71;Monetary Authority of Singapore Act 1970, ss27A-27B, 28; MAS notices | Regulates licensing, prudential soundness, governance, supervision and conduct of banking business. It supports assessment of specialised banking, payments, capital-markets, product, infrastructure or regulator-specific obligations applicable to the activity. | Applies where a bank, merchant bank, branch, subsidiary, controller, officer or outsourced service provider breaches banking regulatory requirements. It should be reviewed across specialised banking, payment rails, custody, capital-markets operations, product governance, client assets, contract notes, exchange reporting and sector-specific operational obligations. | MAS directions, reprimands, composition, civil penalties, licence restrictions/revocation or prosecution; exact provision to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 107 | Sector Breaches | Failure to comply with merchant bank regulatory obligations | Banking Act 1970, ss55S-55T, 55Z;Monetary Authority of Singapore Act 1970, ss27A-27B, 28; MAS notices | Regulates licensing, prudential soundness, governance, supervision and conduct of banking business. It supports assessment of specialised banking, payments, capital-markets, product, infrastructure or regulator-specific obligations applicable to the activity. | Applies where a bank, merchant bank, branch, subsidiary, controller, officer or outsourced service provider breaches banking regulatory requirements. It should be reviewed across specialised banking, payment rails, custody, capital-markets operations, product governance, client assets, contract notes, exchange reporting and sector-specific operational obligations. | MAS directions, reprimands, composition, civil penalties, licence restrictions/revocation or prosecution; exact provision to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 108 | Sector Breaches | Failure to comply with credit card or charge card regulatory obligations | Banking Act 1970, ss56, 57, 57A-57G;Monetary Authority of Singapore Act 1970, ss27A-27B, 28; MAS notices | Regulates licensing, prudential soundness, governance, supervision and conduct of banking business. It supports assessment of specialised banking, payments, capital-markets, product, infrastructure or regulator-specific obligations applicable to the activity. | Applies where a bank, merchant bank, branch, subsidiary, controller, officer or outsourced service provider breaches banking regulatory requirements. It should be reviewed across specialised banking, payment rails, custody, capital-markets operations, product governance, client assets, contract notes, exchange reporting and sector-specific operational obligations. | MAS directions, reprimands, composition, civil penalties, licence restrictions/revocation or prosecution; exact provision to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 109 | Evidence Obstruction | Concealment of material banking regulatory breach | Banking Act 1970, ss43-45, 58, 66-67, 71; MAS notices | Supports MAS supervision through accurate information, approval requirements, prudential rules and regulatory reporting. It supports assessment of concealment, destruction, withholding, false statements and conduct that frustrates lawful inquiries, audits or enforcement action. | Applies to breaches involving capital, liquidity, exposures, related-party transactions, outsourcing, risk management, governance or returns. It should be reviewed across internal inquiries, audit reviews, MAS inspections, police investigations, complaint handling, disciplinary processes, document production, CCTV retention and electronic-record preservation. | Regulatory action, financial penalties, licence conditions or prosecution depending provision; verify exact penalty. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 110 | Abetment Attempts | Abetment, conspiracy or attempt in Banking Act or MAS regulatory breaches | Penal Code 1871, ss107-109, 120A-120Band relevant principal offence | Covers abetment, conspiracy and attempts involving underlying offences. It supports assessment of assistance, planning, conspiracy, facilitation, coordinated misconduct and attempted commission of the underlying offence. | Applies where staff, customers, vendors, mule account holders or outsiders coordinate or attempt banking-related dishonesty. It should be reviewed wherever employees, customers, mule account holders, vendors, intermediaries, outsiders or managers coordinate, assist, attempt, conceal or facilitate the underlying misconduct. | Generally punished according to the principal offence, subject to applicable provisions. Detailed punishment description: liability normally tracks the principal offence and may extend to persons who plan, encourage, assist, facilitate, coordinate, conceal or attempt the misconduct, subject to the applicable Penal Code provisions and the facts proved. |
| 111 | Financial Crime | Failure to conduct customer due diligence before establishing relationship | CDSA 1992, ss39, 50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 112 | Financial Crime | Failure to identify or verify beneficial owner | CDSA 1992, ss39, 50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 113 | Financial Crime | Failure to conduct enhanced due diligence for high-risk customer | CDSA 1992, ss39, 50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 114 | Financial Crime | Failure to conduct politically exposed person screening | CDSA 1992, ss39, 50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 115 | Financial Crime | Failure to screen against sanctions or designated persons lists | Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2 | Implements financial sanctions, asset freezing and prohibitions on dealing with designated persons or entities. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies where a bank processes, facilitates or fails to block prohibited transactions or sanctioned relationships. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | Criminal/regulatory penalties, directions and financial penalties depending sanction regime; verify exact provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 116 | Financial Crime | Failure to perform ongoing monitoring of customer relationship | CDSA 1992, ss39, 50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 117 | Financial Crime | Failure to monitor unusual or suspicious transactions | CDSA 1992, ss39, 50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 118 | Financial Crime | Failure to file suspicious transaction report where required | CDSA 1992, ss39, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 119 | Financial Crime | Tipping off customer about suspicious transaction report or investigation | CDSA 1992, s57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 120 | Financial Crime | Failure to maintain AML/CFT policies, procedures and controls | CDSA 1992, ss39, 50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFTduties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctionsscreening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands,composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 121 | Financial Crime | Failure to keep customer identification and transaction records | CDSA 1992, ss39, 50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 122 | Financial Crime | Failure to perform wire transfer originator or beneficiary information checks | CDSA 1992, ss50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss8-10;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 123 | Financial Crime | Failure to reject or hold incomplete wire transfer where required | CDSA 1992, ss50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 124 | Financial Crime | Failure to manage correspondent banking AML/CFT risk | CDSA 1992, ss39, 50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 125 | Financial Crime | Payable-through account or nested relationship risk not controlled | CDSA 1992, ss39, 50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 126 | Financial Crime | Trade-based money laundering control failure | CDSA 1992, ss50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 127 | Financial Crime | Private banking high-risk relationship control failure | CDSA 1992, ss39, 50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 128 | Financial Crime | Shell company or nominee structure risk not addressed | CDSA 1992, ss39, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 129 | Financial Crime | Mule account onboarding or retention failure | CDSA 1992, ss50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 130 | Financial Crime | Failure to detect scam proceeds, fraud funds or illicit account activity | CDSA 1992, ss50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 131 | Financial Crime | Failure to freeze or block sanctioned funds or assets | Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2 | Implements financial sanctions, asset freezing and prohibitions on dealing with designated persons or entities. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies where a bank processes, facilitates or fails to block prohibited transactions or sanctioned relationships. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | Criminal/regulatory penalties, directions and financial penalties depending sanction regime; verify exact provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 132 | Financial Crime | Dealing with designated terrorist, sanctioned person or prohibited entity | Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2 | Implements financial sanctions, asset freezing and prohibitions on dealing with designated persons or entities. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies where a bank processes, facilitates or fails to block prohibited transactions or sanctioned relationships. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | Criminal/regulatory penalties, directions and financial penalties depending sanction regime; verify exact provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 133 | Financial Crime | Facilitating terrorism financing transaction | Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2 | Implements financial sanctions, asset freezing and prohibitions on dealing with designated persons or entities. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies where a bank processes, facilitates or fails to block prohibited transactions or sanctioned relationships. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | Criminal/regulatory penalties, directions and financial penalties depending sanction regime; verify exact provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders,senior-management accountability measures and prosecution where the statute allows. |
| 134 | Financial Crime | Facilitating proliferation financing or sanctioned trade transaction | Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2 | Implements financial sanctions, asset freezing and prohibitions on dealing with designated persons or entities. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies where a bank processes, facilitates or fails to block prohibited transactions or sanctioned relationships. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | Criminal/regulatory penalties, directions and financial penalties depending sanction regime; verify exact provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 135 | Financial Crime | Failure to escalate sanctions match or false-positive decision properly | Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2 | Implements financial sanctions, asset freezing and prohibitions on dealing with designated persons or entities. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies where a bank processes, facilitates or fails to block prohibited transactions or sanctioned relationships. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | Criminal/regulatory penalties, directions and financial penalties depending sanction regime; verify exact provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 136 | Financial Crime | Inadequate AML/CFT training for staff | CDSA 1992, ss39, 50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 137 | Financial Crime | Inadequate AML/CFT independent audit or testing | CDSA 1992, ss39, 50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss8-10;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 138 | Financial Crime | Failure to apply group-wide AML/CFT controls | CDSA 1992, ss39, 50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 139 | Financial Crime | Failure to manage AML/CFT risk in outsourcing or agent arrangements | CDSA 1992, ss39, 50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 140 | Forgery Records | False AML/CFT assurance or compliance attestation | Penal Code 1871, ss191-193, 196, 199and related provisions | Protects legal, regulatory and investigative proceedings from false evidence and false statements. It supports assessment of false documents, altered records, forged signatures, dishonest record creation and reliance on documents as genuine. | Applies where false statements, declarations, evidence, confirmations or reports are given to auditors, MAS, police, court or investigators. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs, statements, confirmations, credit papers, audit files and regulatory submissions. | Punishment depends on section; false evidence may carry imprisonment and fine. Detailed punishment description: consequences may include criminal penalties under the relevant financial-crime statute, MAS enforcement action, asset freezing, remedial directions, enhanced monitoring, control reviews, reporting obligations and escalation to law enforcement where required. |
| 141 | Evidence Obstruction | Concealment of suspicious transaction or financial crime indicator | Penal Code 1871, ss175, 186, 201, 203, 204 | Protects lawful production of documents, investigations and evidence integrity. It supports assessment of concealment, destruction, withholding, false statements and conduct that frustrates lawful inquiries, audits or enforcement action. | Applies where documents are withheld, evidence destroyed, witnesses coached or MAS/police/auditors are obstructed. It should be reviewed across internal inquiries, audit reviews, MAS inspections, police investigations, complaint handling, disciplinary processes, document production, CCTV retention and electronic-record preservation. | Penalty depends on section and underlying offence; regulatory action may also apply. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 142 | Financial Crime | Assisting another person to retain benefits of criminal conduct | CDSA 1992, ss50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 143 | Financial Crime | Money laundering involving conversion, transfer or concealment of criminal benefits | CDSA 1992, ss50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 144 | Financial Crime | Acquiring, possessing, using or dealing with criminal benefits | CDSA 1992, ss50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 145 | Evidence Obstruction | Failure to comply with production, disclosure or information order in AML investigation | Penal Code 1871, ss175, 186, 201, 203, 204 | Protects lawful production of documents, investigations and evidence integrity. It supports assessment of concealment, destruction, withholding, false statements and conduct that frustrates lawful inquiries, audits or enforcement action. | Applies where documents are withheld, evidence destroyed, witnesses coached or MAS/police/auditors are obstructed. It should be reviewed across internal inquiries, audit reviews, MAS inspections, police investigations, complaint handling, disciplinary processes, document production, CCTV retention and electronic-record preservation. | Penalty depends on section and underlying offence; regulatory action may also apply. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 146 | Evidence Obstruction | Failure to provide accurate account information to law enforcement or MAS | Penal Code 1871, ss191-193, 196, 199and related provisions | Protects legal, regulatory and investigative proceedings from false evidence and false statements. It supports assessment of concealment, destruction, withholding, false statements and conduct that frustrates lawful inquiries, audits or enforcement action. | Applies where false statements, declarations, evidence, confirmations or reports are given to auditors, MAS, police, court or investigators. It should be reviewed across internal inquiries, audit reviews, MAS inspections, police investigations, complaint handling, disciplinary processes, document production, CCTV retention and electronic-record preservation. | Punishment depends on section; false evidence may carry imprisonment and fine. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 147 | Financial Crime | Failure to remediate AML/CFT control deficiencies | CDSA 1992, ss39, 50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer duediligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking,trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independentreviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 148 | Financial Crime | Systemic AML/CFT governance failure by bank management | CDSA 1992, ss39, 50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Requires customer due diligence, monitoring, suspicious transaction reporting and controls against money laundering and terrorism financing. It supports assessment of AML/CFT duties, suspicious transactions, sanctions risk, customer due diligence, illicit funds and financial-crime control weaknesses. | Applies to onboarding, account monitoring, trade finance, correspondent banking, private banking, remittance, sanctions and high-risk customers. It should be reviewed across onboarding, beneficial ownership checks, sanctions screening, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts and suspicious transaction escalation. | MAS enforcement action, financial penalties, directions and criminal penalties under applicable statutes; exact provisions to verify. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 149 | Abetment Attempts | Abetment or conspiracy in AML/CFT, sanctions or financial crime breaches | Penal Code 1871, ss107-109, 120A-120Band relevant principal offence;United Nations Act 2001, s2 | Covers abetment, conspiracy and attempts involving underlying offences. It supports assessment of assistance, planning, conspiracy, facilitation, coordinated misconduct and attempted commission of the underlying offence. | Applies where staff, customers, vendors, mule account holders or outsiders coordinate or attempt banking-related dishonesty. It should be reviewed wherever employees, customers, mule account holders, vendors, intermediaries, outsiders or managers coordinate, assist, attempt, conceal or facilitate the underlying misconduct. | Generally punished according to the principal offence, subject to applicable provisions. Detailed punishment description: liability normally tracks the principal offence and may extend to persons who plan, encourage, assist, facilitate, coordinate, conceal or attempt the misconduct, subject to the applicable Penal Code provisions and the facts proved. |
| 150 | Abetment Attempts | Attempt to evade AML/CFT or sanctions controls | Penal Code 1871, ss107-109, 120A-120Band relevant principal offence;United Nations Act 2001, s2 | Covers abetment, conspiracy and attempts involving underlying offences. It supports assessment of assistance, planning, conspiracy, facilitation, coordinated misconduct and attempted commission of the underlying offence. | Applies where staff, customers, vendors, mule account holders or outsiders coordinate or attempt banking-related dishonesty. It should be reviewed wherever employees, customers, mule account holders, vendors, intermediaries, outsiders or managers coordinate, assist, attempt, conceal or facilitate the underlying misconduct. | Generally punished according to the principal offence, subject to applicable provisions. Detailed punishment description: liability normally tracks the principal offence and may extend to persons who plan, encourage, assist, facilitate, coordinate, conceal or attempt the misconduct, subject to the applicable Penal Code provisions and the facts proved. |
| 151 | Cyber Technology | Unauthorised access to core banking system | Computer Misuse Act 1993, ss3-4, 11 | Criminalises unauthorised access, modification, interception and obstruction of computer systems. It supports assessment of unauthorised access, system misuse, operational resilience, technology risk, security controls and digital banking harm. | Applies to core banking, mobile banking, internet banking, ATM, SWIFT, payment, customer, CRM, HR and audit systems. It should be reviewed across core banking, internet and mobile banking, ATM, SWIFT, payment systems, privileged access, logs, vendors, cloud services, incident response and technology-risk governance. | Fines and imprisonment under CMA; enhanced penalties may apply depending damage, intent and protected systems. Detailed punishment description: cyber-related penalties may increase where protected systems, serious disruption, unauthorised modification, malicious tools, repeated conduct, fraud facilitation, customer harm or significant banking-system impact is involved. |
| 152 | Cyber Technology | Unauthorised access to internet or mobile banking platform | Computer Misuse Act 1993, ss3-4, 11 | Criminalises unauthorised access, modification, interception and obstruction of computer systems. It supports assessment of unauthorised access, system misuse, operational resilience, technology risk, security controls and digital banking harm. | Applies to core banking, mobile banking, internet banking, ATM, SWIFT, payment, customer, CRM, HR and audit systems. It should be reviewed across core banking, internet and mobile banking, ATM, SWIFT, payment systems, privileged access, logs, vendors, cloud services, incident response and technology-risk governance. | Fines and imprisonment under CMA; enhanced penalties may apply depending damage, intent and protected systems. Detailed punishment description: cyber-related penalties may increase where protected systems, serious disruption, unauthorised modification, malicious tools, repeated conduct, fraud facilitation, customer harm or significant banking-system impact is involved. |
| 153 | Cyber Technology | Unauthorised access to ATM or card management system | Computer Misuse Act 1993, ss3-4, 11 | Criminalises unauthorised access, modification, interception and obstruction of computer systems. It supports assessment of unauthorised access, system misuse, operational resilience, technology risk, security controls and digital banking harm. | Applies to core banking, mobile banking, internet banking, ATM, SWIFT, payment, customer, CRM, HR and audit systems. It should be reviewed across core banking, internet and mobile banking, ATM, SWIFT, payment systems, privileged access, logs, vendors, cloud services, incident response and technology-risk governance. | Fines and imprisonment under CMA; enhanced penalties may apply depending damage, intent and protected systems. Detailed punishment description: cyber-related penalties may increase where protected systems, serious disruption, unauthorised modification, malicious tools, repeated conduct, fraud facilitation, customer harm or significant banking-system impact is involved. |
| 154 | Cyber Technology | Unauthorised access to SWIFT, payments or settlement system | Computer Misuse Act 1993, ss3-4, 11 | Criminalises unauthorised access, modification, interception and obstruction of computer systems. It supports assessment of unauthorised access, system misuse, operational resilience, technology risk, security controls and digital banking harm. | Applies to core banking, mobile banking, internet banking, ATM, SWIFT, payment, customer, CRM, HR and audit systems. It should be reviewed across core banking, internet and mobile banking, ATM, SWIFT, payment systems, privileged access, logs, vendors, cloud services, incident response and technology-risk governance. | Fines and imprisonment under CMA; enhanced penalties may apply depending damage, intent and protected systems. Detailed punishment description: cyber-related penalties may increase where protected systems, serious disruption, unauthorised modification, malicious tools, repeated conduct, fraud facilitation, customer harm or significant banking-system impact is involved. |
| 155 | Cyber Technology | Unauthorised modification of customer account data | Computer Misuse Act 1993, ss5-7, 11 | Criminalises unauthorised access, modification, interception and obstruction of computer systems. It supports assessment of unauthorised access, system misuse, operational resilience, technology risk, security controls and digital banking harm. | Applies to core banking, mobile banking, internet banking, ATM, SWIFT, payment, customer, CRM, HR and audit systems. It should be reviewed across core banking, internet and mobile banking, ATM, SWIFT, payment systems, privileged access, logs, vendors, cloud services, incident response and technology-risk governance. | Fines and imprisonment under CMA; enhanced penalties may apply depending damage, intent and protected systems. Detailed punishment description: cyber-related penalties may increase where protected systems, serious disruption, unauthorised modification, malicious tools, repeated conduct, fraud facilitation, customer harm or significant banking-system impact is involved. |
| 156 | Cyber Technology | Unauthorised modification of transaction, limit or standing instruction data | Computer Misuse Act 1993, ss5-7, 11 | Criminalises unauthorised access, modification, interception and obstruction of computer systems. It supports assessment of unauthorised access, system misuse, operational resilience, technology risk, security controls and digital banking harm. | Applies to core banking, mobile banking, internet banking, ATM, SWIFT, payment, customer, CRM, HR and audit systems. It should be reviewed across core banking, internet and mobile banking, ATM, SWIFT, payment systems, privileged access, logs, vendors, cloud services, incident response and technology-risk governance. | Fines and imprisonment under CMA; enhanced penalties may apply depending damage, intent and protected systems. Detailed punishment description: cyber-related penalties may increase where protected systems, serious disruption, unauthorised modification, malicious tools, repeated conduct, fraud facilitation, customer harm or significant banking-system impact is involved. |
| 157 | Cyber Technology | Unauthorised modification of credit, collateral or risk records | Computer Misuse Act 1993, ss5-7, 11 | Criminalises unauthorised access, modification, interception and obstruction of computer systems. It supports assessment of unauthorised access, system misuse, operational resilience, technology risk, security controls and digital banking harm. | Applies to core banking, mobile banking, internet banking, ATM, SWIFT, payment, customer, CRM, HR and audit systems. It should be reviewed across core banking, internet and mobile banking, ATM, SWIFT, payment systems, privileged access, logs, vendors, cloud services, incident response and technology-risk governance. | Fines and imprisonment under CMA; enhanced penalties may apply depending damage, intent and protected systems. Detailed punishment description: cyber-related penalties may increase where protected systems, serious disruption, unauthorised modification, malicious tools, repeated conduct, fraud facilitation, customer harm or significant banking-system impact is involved. |
| 158 | Cyber Technology | Unauthorised deletion of logs, alerts or investigation records | Computer Misuse Act 1993, ss5-7, 11 | Criminalises unauthorised access, modification, interception and obstruction of computer systems. It supports assessment of unauthorised access, system misuse, operational resilience, technology risk, security controls and digital banking harm. | Applies to core banking, mobile banking, internet banking, ATM, SWIFT, payment, customer, CRM, HR and audit systems. It should be reviewed across core banking, internet and mobile banking, ATM, SWIFT, payment systems, privileged access, logs, vendors, cloud services, incident response and technology-risk governance. | Fines and imprisonment under CMA; enhanced penalties may apply depending damage, intent and protected systems. Detailed punishment description: cyber-related penalties may increase where protected systems, serious disruption, unauthorised modification, malicious tools, repeated conduct, fraud facilitation, customer harm or significant banking-system impact is involved. |
| 159 | Cyber Technology | Malware or ransomware affecting bank systems | Computer Misuse Act 1993, ss5-7, 11 | Criminalises unauthorised access, modification, interception and obstruction of computer systems. It supports assessment of unauthorised access, system misuse, operational resilience, technology risk, security controls and digital banking harm. | Applies to core banking, mobile banking, internet banking, ATM, SWIFT, payment, customer, CRM, HR and audit systems. It should be reviewed across core banking, internet and mobile banking, ATM, SWIFT, payment systems, privileged access, logs, vendors, cloud services, incident response and technology-risk governance. | Fines and imprisonment under CMA; enhanced penalties may apply depending damage, intent and protected systems. Detailed punishment description: cyber-related penalties may increase where protected systems, serious disruption, unauthorised modification, malicious tools, repeated conduct, fraud facilitation, customer harm or significant banking-system impact is involved. |
| 160 | Cyber Technology | Phishing, credential harvesting or account takeover involving bank users | Computer Misuse Act 1993, ss3-4, 8, 8B, 11 | Criminalises unauthorised access, modification, interception and obstruction of computer systems. It supports assessment of unauthorised access, system misuse, operational resilience, technology risk, security controls and digital banking harm. | Applies to core banking, mobile banking, internet banking, ATM, SWIFT, payment, customer, CRM, HR and audit systems. It should be reviewed across core banking, internet and mobile banking, ATM, SWIFT, payment systems, privileged access, logs, vendors, cloud services, incident response and technology-risk governance. | Fines and imprisonment under CMA; enhanced penalties may apply depending damage, intent and protected systems. Detailed punishment description: cyber-related penalties may increase where protected systems, serious disruption, unauthorised modification, malicious tools, repeated conduct, fraud facilitation, customer harm or significant banking-system impact is involved. |
| 161 | Cyber Technology | Unauthorised disclosure or sharing of access code, OTP or token | Computer Misuse Act 1993, ss3-4, 8, 8B, 11 | Criminalises unauthorised access, modification, interception and obstruction of computer systems. It supports assessment of unauthorised access, system misuse, operational resilience, technology risk, security controls and digital banking harm. | Applies to core banking, mobile banking, internet banking, ATM, SWIFT, payment, customer, CRM, HR and audit systems. It should be reviewed across core banking, internet and mobile banking, ATM, SWIFT, payment systems, privileged access, logs, vendors, cloud services, incident response and technology-risk governance. | Fines and imprisonment under CMA; enhanced penalties may apply depending damage, intent and protected systems. Detailed punishment description: cyber-related penalties may increase where protected systems, serious disruption, unauthorised modification, malicious tools, repeated conduct, fraud facilitation, customer harm or significant banking-system impact is involved. |
| 162 | Cyber Technology | Credential sharing or privilege misuse by bank staff or vendor | Computer Misuse Act 1993, ss3-4, 8, 8B, 11 | Criminalises unauthorised access, modification, interception and obstruction of computer systems. It supports assessment of unauthorised access, system misuse, operational resilience, technology risk, security controls and digital banking harm. | Applies to core banking, mobile banking, internet banking, ATM, SWIFT, payment, customer, CRM, HR and audit systems. It should be reviewed across core banking, internet and mobile banking, ATM, SWIFT, payment systems, privileged access, logs, vendors, cloud services, incident response andtechnology-risk governance. | Fines and imprisonment under CMA; enhanced penalties may apply depending damage, intent and protected systems. Detailed punishment description: cyber-related penalties may increase where protected systems, serious disruption, unauthorised modification,malicious tools, repeated conduct, fraud facilitation, customer harm or significant banking-system impact is involved. |
| 163 | Cyber Technology | Failure to revoke access after staff, vendor or contractor departure | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS Technology Risk Management requirements | Supports sector-wide regulation, technology risk management and operational resilience in financial services. It supports assessment of unauthorised access, system misuse, operational resilience, technology risk, security controls and digital banking harm. | Applies to material system outages, weak controls, outsourcing failures, cyber resilience lapses or technology-risk governance failures. It should be reviewed across core banking, internet and mobile banking, ATM, SWIFT, payment systems, privileged access, logs, vendors, cloud services, incident response and technology-risk governance. | MAS directions, financial penalties, licence consequences or prosecution depending provision and breach. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 164 | Cyber Technology | Failure to restrict privileged access to critical systems | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS Technology Risk Management requirements | Supports sector-wide regulation, technology risk management and operational resilience in financial services. It supports assessment of unauthorised access, system misuse, operational resilience, technology risk, security controls and digital banking harm. | Applies to material system outages, weak controls, outsourcing failures, cyber resilience lapses or technology-risk governance failures. It should be reviewed across core banking, internet and mobile banking, ATM, SWIFT, payment systems, privileged access, logs, vendors, cloud services, incident response and technology-risk governance. | MAS directions, financial penalties, licence consequences or prosecution depending provision and breach. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 165 | Cyber Technology | Failure to protect critical banking systems from cyber risk | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS Technology Risk Management requirements | Supports sector-wide regulation, technology risk management and operational resilience in financial services. It supports assessment of unauthorised access, system misuse, operational resilience, technology risk, security controls and digital banking harm. | Applies to material system outages, weak controls, outsourcing failures, cyber resilience lapses or technology-risk governance failures. It should be reviewed across core banking, internet and mobile banking, ATM, SWIFT, payment systems, privileged access, logs, vendors, cloud services, incident response and technology-risk governance. | MAS directions, financial penalties, licence consequences or prosecution depending provision and breach. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 166 | Cyber Technology | Failure to report or escalate material technology incident | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS Technology Risk Management requirements | Supports sector-wide regulation, technology risk management and operational resilience in financial services. It supports assessment of unauthorised access, system misuse, operational resilience, technology risk, security controls and digital banking harm. | Applies to material system outages, weak controls, outsourcing failures, cyber resilience lapses or technology-risk governance failures. It should be reviewed across core banking, internet and mobile banking, ATM, SWIFT, payment systems, privileged access, logs, vendors, cloud services, incident response and technology-risk governance. | MAS directions, financial penalties, licence consequences or prosecution depending provision and breach. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 167 | Cyber Technology | Failure to maintain business continuity for digital banking services | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS Technology Risk Management requirements | Supports sector-wide regulation, technology risk management and operational resilience in financial services. It supports assessment of unauthorised access, system misuse, operational resilience, technology risk, security controls and digital banking harm. | Applies to material system outages, weak controls, outsourcing failures, cyber resilience lapses or technology-risk governance failures. It should be reviewed across core banking, internet and mobile banking, ATM, SWIFT, payment systems, privileged access, logs, vendors, cloud services, incident response and technology-risk governance. | MAS directions, financial penalties, licence consequences or prosecution depending provision and breach. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 168 | Cyber Technology | Failure to test disaster recovery or system resilience | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS Technology Risk Management requirements | Supports sector-wide regulation, technology risk management and operational resilience in financial services. It supports assessment of unauthorised access, system misuse, operational resilience, technology risk, security controls and digital banking harm. | Applies to material system outages, weak controls, outsourcing failures, cyber resilience lapses or technology-risk governance failures. It should be reviewed across core banking, internet and mobile banking, ATM, SWIFT, payment systems, privileged access, logs, vendors, cloud services, incident response and technology-risk governance. | MAS directions, financial penalties, licence consequences or prosecution depending provision and breach. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 169 | Cyber Technology | Failure to manage third-party technology or cloud service provider risk | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS Technology Risk Management requirements | Supports sector-wide regulation, technology risk management and operational resilience in financial services. It supports assessment of unauthorised access, system misuse, operational resilience, technology risk, security controls and digital banking harm. | Applies to material system outages, weak controls, outsourcing failures, cyber resilience lapses or technology-risk governance failures. It should be reviewed across core banking, internet and mobile banking, ATM, SWIFT, payment systems, privileged access, logs, vendors, cloud services, incident response and technology-risk governance. | MAS directions, financial penalties, licence consequences or prosecution depending provision and breach. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 170 | Cyber Technology | Failure to implement secure software development controls | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS Technology Risk Management requirements | Supports sector-wide regulation, technology risk management and operational resilience in financial services. It supports assessment of unauthorised access, system misuse, operational resilience, technology risk, security controls and digital banking harm. | Applies to material system outages, weak controls, outsourcing failures, cyber resilience lapses or technology-risk governance failures. It should be reviewed across core banking, internet and mobile banking, ATM, SWIFT, payment systems, privileged access, logs, vendors, cloud services, incident response and technology-risk governance. | MAS directions, financial penalties, licence consequences or prosecution depending provision and breach. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 171 | Cyber Technology | Failure to patch critical vulnerability in banking systems | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS Technology Risk Management requirements | Supports sector-wide regulation, technology risk management and operational resilience in financial services. It supports assessment of unauthorised access, system misuse, operational resilience, technology risk, security controls and digital banking harm. | Applies to material system outages, weak controls, outsourcing failures, cyber resilience lapses or technology-risk governance failures. It should be reviewed across core banking, internet and mobile banking, ATM, SWIFT, payment systems, privileged access, logs, vendors, cloud services, incident response and technology-risk governance. | MAS directions, financial penalties, licence consequences or prosecution depending provision and breach. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 172 | Cyber Technology | Failure to detect or respond to fraud alerts in digital banking | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS Technology Risk Management requirements | Supports sector-wide regulation, technology risk management and operational resilience in financial services. It supports assessment of unauthorised access, system misuse, operational resilience, technology risk, security controls and digital banking harm. | Applies to material system outages, weak controls, outsourcing failures, cyber resilience lapses or technology-risk governance failures. It should be reviewed across core banking, internet and mobile banking, ATM, SWIFT, payment systems, privileged access, logs, vendors, cloud services, incident response and technology-risk governance. | MAS directions, financial penalties, licence consequences or prosecution depending provision and breach. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 173 | Data Protection | Unauthorised disclosure of personal data | PDPA 2012, ss24, 48D-48J | Regulates collection, use, disclosure, protection, retention and breach notification for personal data. It supports assessment of confidentiality, personal data handling, disclosure controls, protection obligations, retention practices and breach notification duties. | Applies to customer, employee, applicant, beneficial-owner, guarantor, cardholder and transaction-related personal data handled by banks or vendors. It should be reviewed across customer records, employee records, beneficial-owner files, statements, KYC documents, call-centre records, vendor transfers, overseas processing, AI tools and breach-response workflows. | PDPC directions and financial penalties; individual offences may carry fines/imprisonment depending provision. Detailed punishment description: consequences may include PDPC directions, financial penalties, mandatory remediation, breach notification obligations, audits, internal disciplinary action, civil exposure and prosecution for individual offences where applicable. |
| 174 | Data Protection | Failure to protect personal data through reasonable security arrangements | PDPA 2012, ss24, 48D-48J | Regulates collection, use, disclosure, protection, retention and breach notification for personal data. It supports assessment of confidentiality, personal data handling, disclosure controls, protection obligations, retention practices and breach notification duties. | Applies to customer, employee, applicant, beneficial-owner, guarantor, cardholder and transaction-related personal data handled by banks or vendors. It should be reviewed across customer records, employee records, beneficial-owner files, statements, KYC documents, call-centre records, vendor transfers, overseas processing, AI tools and breach-response workflows. | PDPC directions and financial penalties; individual offences may carry fines/imprisonment depending provision. Detailed punishment description: consequences may include PDPC directions, financial penalties, mandatory remediation, breach notification obligations, audits, internal disciplinary action, civil exposure and prosecution for individual offences where applicable. |
| 175 | Data Protection | Failure to notify notifiable data breach | PDPA 2012, ss24, 26B-26D, 48I-48J | Regulates collection, use, disclosure, protection, retention and breach notification for personal data. It supports assessment of confidentiality, personal data handling, disclosure controls, protection obligations, retention practices and breach notification duties. | Applies to customer, employee, applicant, beneficial-owner, guarantor, cardholder and transaction-related personal data handled by banks or vendors. It should be reviewed across customer records, employee records, beneficial-owner files, statements, KYC documents, call-centre records, vendor transfers, overseas processing, AI tools and breach-response workflows. | PDPC directions and financial penalties; individual offences may carry fines/imprisonment depending provision. Detailed punishment description: consequences may include PDPC directions, financial penalties, mandatory remediation, breach notification obligations, audits, internal disciplinary action, civil exposure and prosecution for individual offences where applicable. |
| 176 | Data Protection | Improper collection, use or retention of personal data | PDPA 2012, ss24, 48D-48J | Regulates collection, use, disclosure, protection, retention and breach notification for personal data. It supports assessment of confidentiality, personal data handling, disclosure controls,protection obligations, retention practices and breach notification duties. | Applies to customer, employee, applicant, beneficial-owner, guarantor, cardholder and transaction-related personal data handled by banks or vendors. It should be reviewed across customer records, employee records, beneficial-owner files, statements, KYC documents, call-centre records, vendor transfers, overseas processing, AI tools and breach-response workflows. | PDPC directions and financial penalties; individual offences may carry fines/imprisonment depending provision. Detailed punishment description: consequences may include PDPC directions, financialpenalties, mandatory remediation, breach notification obligations, audits, internal disciplinary action, civil exposure and prosecution for individual offences where applicable. |
| 177 | Data Protection | Improper overseas transfer of customer personal data | PDPA 2012, ss24, 26, 26B-26D, 48I-48J | Regulates collection, use, disclosure, protection, retention and breach notification for personal data. It supports assessment of confidentiality, personal data handling, disclosure controls, protection obligations, retention practices and breach notification duties. | Applies to customer, employee, applicant, beneficial-owner, guarantor, cardholder and transaction-related personal data handled by banks or vendors. It should be reviewed across customer records, employee records, beneficial-owner files, statements, KYC documents, call-centre records, vendor transfers, overseas processing, AI tools and breach-response workflows. | PDPC directions and financial penalties; individual offences may carry fines/imprisonment depending provision. Detailed punishment description: consequences may include PDPC directions, financial penalties, mandatory remediation, breach notification obligations, audits, internal disciplinary action, civil exposure and prosecution for individual offences where applicable. |
| 178 | Data Protection | Uploading protected customer data to unauthorised AI or cloud tools | PDPA 2012, ss24, 26, 26B-26D, 48I-48J | Regulates collection, use, disclosure, protection, retention and breach notification for personal data. It supports assessment of confidentiality, personal data handling, disclosure controls, protection obligations, retention practices and breach notification duties. | Applies to customer, employee, applicant, beneficial-owner, guarantor, cardholder and transaction-related personal data handled by banks or vendors. It should be reviewed across customer records, employee records, beneficial-owner files, statements, KYC documents, call-centre records, vendor transfers, overseas processing, AI tools and breach-response workflows. | PDPC directions and financial penalties; individual offences may carry fines/imprisonment depending provision. Detailed punishment description: consequences may include PDPC directions, financial penalties, mandatory remediation, breach notification obligations, audits, internal disciplinary action, civil exposure and prosecution for individual offences where applicable. |
| 179 | Licensing Approvals | Operating payment service without required licence where applicable | Banking Act 1970, ss4, 4A, 4B, 20, 66-67, 71;Payment Services Act 2019, ss5-7, 11-13; MAS payment services requirements | Regulates payment services, payment systems and payment-related conduct, risk and safeguarding obligations. It supports assessment of authorisation status, licence scope, approval conditions, regulatory permissions and whether banking or related activities were conducted lawfully. | Applies to card issuing, acquiring, e-money, domestic transfers, cross-border transfers, digital payment tokens or payment infrastructure operated by a bank. It should be reviewed across licensed banking activities, merchant banking, digital banking, payment services, representative appointments, control changes, approved persons, licence conditions and scope restrictions. | MAS regulatory action, financial penalties, licence consequences or prosecution depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 180 | Licensing Approvals | Breach of payment service licence or exemption condition | Banking Act 1970, ss4, 4A, 4B, 20, 66-67, 71;Payment Services Act 2019, ss5-7, 11-13; MAS payment services requirements | Regulates payment services, payment systems and payment-related conduct, risk and safeguarding obligations. It supports assessment of authorisation status, licence scope, approval conditions, regulatory permissions and whether banking or related activities were conducted lawfully. | Applies to card issuing, acquiring, e-money, domestic transfers, cross-border transfers, digital payment tokens or payment infrastructure operated by a bank. It should be reviewed across licensed banking activities, merchant banking, digital banking, payment services, representative appointments, control changes, approved persons, licence conditions and scope restrictions. | MAS regulatory action, financial penalties, licence consequences or prosecution depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 181 | Sector Breaches | Failure to safeguard customer monies or e-money float | Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71;Payment Services Act 2019, ss23-24; MAS payment services requirements | Regulates payment services, payment systems and payment-related conduct, risk and safeguarding obligations. It supports assessment of specialised banking, payments, capital-markets, product, infrastructure or regulator-specific obligations applicable to the activity. | Applies to card issuing, acquiring, e-money, domestic transfers, cross-border transfers, digital payment tokens or payment infrastructure operated by a bank. It should be reviewed across specialised banking, payment rails, custody, capital-markets operations, product governance, client assets, contract notes, exchange reporting and sector-specific operational obligations. | MAS regulatory action, financial penalties, licence consequences or prosecution depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 182 | Sector Breaches | Failure to comply with payment transaction record obligations | Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71;Payment Services Act 2019, ss25-26, 51; MAS payment services requirements | Regulates payment services, payment systems and payment-related conduct, risk and safeguarding obligations. It supports assessment of specialised banking, payments, capital-markets, product, infrastructure or regulator-specific obligations applicable to the activity. | Applies to card issuing, acquiring, e-money, domestic transfers, cross-border transfers, digital payment tokens or payment infrastructure operated by a bank. It should be reviewed across specialised banking, payment rails, custody, capital-markets operations, product governance, client assets, contract notes, exchange reporting and sector-specific operational obligations. | MAS regulatory action, financial penalties, licence consequences or prosecution depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 183 | Sector Breaches | Failure to manage payment system operational risk | Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71;Payment Services Act 2019, ss25-26, 51; MAS payment services requirements | Regulates payment services, payment systems and payment-related conduct, risk and safeguarding obligations. It supports assessment of specialised banking, payments, capital-markets, product, infrastructure or regulator-specific obligations applicable to the activity. | Applies to card issuing, acquiring, e-money, domestic transfers, cross-border transfers, digital payment tokens or payment infrastructure operated by a bank. It should be reviewed across specialised banking, payment rails, custody, capital-markets operations, product governance, client assets, contract notes, exchange reporting and sector-specific operational obligations. | MAS regulatory action, financial penalties, licence consequences or prosecution depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 184 | Data Protection | Failure to protect cardholder data or payment credentials | Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71;Payment Services Act 2019, ss25-26, 51; MAS payment services requirements | Regulates payment services, payment systems and payment-related conduct, risk and safeguarding obligations. It supports assessment of confidentiality, personal data handling, disclosure controls, protection obligations, retention practices and breach notification duties. | Applies to card issuing, acquiring, e-money, domestic transfers, cross-border transfers, digital payment tokens or payment infrastructure operated by a bank. It should be reviewed across customer records, employee records, beneficial-owner files, statements, KYC documents, call-centre records, vendor transfers, overseas processing, AI tools and breach-response workflows. | MAS regulatory action, financial penalties, licence consequences or prosecution depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 185 | Sector Breaches | Unauthorised card issuing, acquiring or merchant payment conduct | Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71;Payment Services Act 2019, ss25-26, 51; MAS payment services requirements | Regulates payment services, payment systems and payment-related conduct, risk and safeguarding obligations. It supports assessment of specialised banking, payments, capital-markets, product, infrastructure or regulator-specific obligations applicable to the activity. | Applies to card issuing, acquiring, e-money, domestic transfers, cross-border transfers, digital payment tokens or payment infrastructure operated by a bank. It should be reviewed across specialised banking, payment rails, custody, capital-markets operations, product governance, client assets, contract notes, exchange reporting and sector-specific operational obligations. | MAS regulatory action, financial penalties, licence consequences or prosecution depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 186 | Sector Breaches | Failure to comply with major payment institution or standard payment institution requirements | Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71;Payment Services Act 2019, ss5-7, 11-13; MAS payment services requirements | Regulates payment services, payment systems and payment-related conduct, risk and safeguarding obligations. It supports assessment of specialised banking, payments, capital-markets, product, infrastructure or regulator-specific obligations applicable to the activity. | Applies to card issuing, acquiring, e-money, domestic transfers, cross-border transfers, digital payment tokens or payment infrastructure operated by a bank. It should be reviewed across specialised banking, payment rails, custody, capital-markets operations, product governance, client assets, contract notes, exchange reporting and sector-specific operational obligations. | MAS regulatory action, financial penalties, licence consequences or prosecution depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 187 | Sector Breaches | Failure to manage digital payment token risk where bank provides related service | Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71;Payment Services Act 2019, ss5-7, 11-13; MAS payment services requirements | Regulates payment services, payment systems and payment-related conduct, risk and safeguarding obligations. It supports assessment of specialised banking, payments, capital-markets, product, infrastructure or regulator-specific obligations applicable to the activity. | Applies to card issuing, acquiring, e-money, domestic transfers, cross-border transfers, digital payment tokens or payment infrastructure operated by a bank. It should be reviewed across specialised banking, payment rails, custody, capital-markets operations, product governance, client assets, contract notes, exchange reporting and sector-specific operational obligations. | MAS regulatory action, financial penalties, licence consequences or prosecution depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 188 | Cyber Technology | Misuse of QR, PayNow, FAST, GIRO or payment rail access | Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71;Payment Services Act 2019, ss25-26, 51; MAS payment services requirements | Regulates payment services, payment systems and payment-related conduct, risk and safeguarding obligations. It supports assessment of unauthorised access, system misuse, operational resilience, technology risk, security controls and digital banking harm. | Applies to card issuing, acquiring, e-money, domestic transfers, cross-border transfers, digital payment tokens or payment infrastructure operated by a bank. It should be reviewed across core banking, internet and mobile banking, ATM, SWIFT, payment systems, privileged access, logs, vendors, cloud services, incident response and technology-risk governance. | MAS regulatory action, financial penalties, licence consequences or prosecution depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 189 | Evidence Obstruction | Concealment of technology, cyber, payment or data incident | Penal Code 1871, ss175, 186, 201, 203, 204 | Protects lawful production of documents, investigations and evidence integrity. It supports assessment of concealment, destruction, withholding, false statements and conduct that frustrates lawful inquiries, audits or enforcement action. | Applies where documents are withheld, evidence destroyed, witnesses coached or MAS/police/auditors are obstructed. It should be reviewed across internal inquiries, audit reviews, MAS inspections, police investigations, complaint handling, disciplinary processes, document production, CCTV retention and electronic-record preservation. | Penalty depends on section and underlying offence; regulatory action may also apply. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 190 | Abetment Attempts | Abetment, conspiracy or attempt in cyber, payment or data protection offences | Penal Code 1871, ss107-109, 120A-120Band relevant principal offence | Covers abetment, conspiracy and attempts involving underlying offences. It supports assessment of assistance, planning,conspiracy, facilitation, coordinated misconduct and attempted commission of the underlying offence. | Applies where staff, customers, vendors, mule account holders or outsiders coordinate or attempt banking-related dishonesty. It should be reviewedwherever employees, customers, mule account holders, vendors, intermediaries, outsiders or managers coordinate, assist, attempt, conceal or facilitate the underlying misconduct. | Generally punished according to the principal offence, subject to applicable provisions. Detailed punishment description: liabilitynormally tracks the principal offence and may extend to persons who plan, encourage, assist, facilitate, coordinate, conceal or attempt the misconduct, subject to the applicable Penal Code provisions and the facts proved. |
| 191 | Licensing Approvals | Dealing in capital markets products without proper authorisation | SFA 2001, ss82, 84-88, 92-99O; MAS capital markets conduct rules | Regulates securities, derivatives, capital markets products, market conduct and licensed activities. It supports assessment of authorisation status, licence scope, approval conditions, regulatory permissions and whether banking or related activities were conducted lawfully. | Applies where a bank deals in, advises on, distributes, trades or intermediates capital markets products or securities-linked products. It should be reviewed across licensed banking activities, merchant banking, digital banking, payment services, representative appointments, control changes, approved persons, licence conditions and scope restrictions. | Civil penalties, criminal penalties, licence action, prohibition orders or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 192 | Licensing Approvals | Bank representative conducting regulated activity without proper appointment | SFA 2001, ss82, 84-88, 92-99O; MAS capital markets conduct rules | Regulates securities, derivatives, capital markets products, market conduct and licensed activities. It supports assessment of authorisation status, licence scope, approval conditions, regulatory permissions and whether banking or related activities were conducted lawfully. | Applies where a bank deals in, advises on, distributes, trades or intermediates capital markets products or securities-linked products. It should be reviewed across licensed banking activities, merchant banking, digital banking, payment services, representative appointments, control changes, approved persons, licence conditions and scope restrictions. | Civil penalties, criminal penalties, licence action, prohibition orders or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 193 | Professional Conduct | Misrepresentation in sale of investment product | FAA 2001, ss6, 20, 23, 34-36, 60; MAS notices | Regulates financial advisory services, representatives, supervisors and advice on investment products. It supports assessment of advisory duties, fair dealing, competence, suitability, supervision, disclosure and customer-facing conduct standards. | Applies to bank wealth management, investment advisory, insurance referrals, structured product recommendations and relationship managers acting as representatives. It should be reviewed across wealth management, relationship managers, advisory representatives, product distribution, investment recommendations, product switching, vulnerable customers, complaint handling and supervisory review. | Fines, imprisonment, civil penalties, prohibition orders, representative action or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 194 | Professional Conduct | Unsuitable investment recommendation to customer | FAA 2001, ss23, 34-36, 60; MAS notices | Regulates financial advisory services, representatives, supervisors and advice on investment products. It supports assessment of advisory duties, fair dealing, competence, suitability, supervision, disclosure and customer-facing conduct standards. | Applies to bank wealth management, investment advisory, insurance referrals, structured product recommendations and relationship managers acting as representatives. It should be reviewed across wealth management, relationship managers, advisory representatives, product distribution, investment recommendations, product switching, vulnerable customers, complaint handling and supervisory review. | Fines, imprisonment, civil penalties, prohibition orders, representative action or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 195 | Professional Conduct | Failure to disclose material product risk | FAA 2001, ss23, 34-36, 60; MAS notices | Regulates financial advisory services, representatives, supervisors and advice on investment products. It supports assessment of advisory duties, fair dealing, competence, suitability, supervision, disclosure and customer-facing conduct standards. | Applies to bank wealth management, investment advisory, insurance referrals, structured product recommendations and relationship managers acting as representatives. It should be reviewed across wealth management, relationship managers, advisory representatives, product distribution, investment recommendations, product switching, vulnerable customers, complaint handling and supervisory review. | Fines, imprisonment, civil penalties, prohibition orders, representative action or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 196 | Professional Conduct | Failure to disclose fees, charges or commissions | FAA 2001, ss23, 34-36, 60; MAS notices | Regulates financial advisory services, representatives, supervisors and advice on investment products. It supports assessment of advisory duties, fair dealing, competence, suitability, supervision, disclosure and customer-facing conduct standards. | Applies to bank wealth management, investment advisory, insurance referrals, structured product recommendations and relationship managers acting as representatives. It should be reviewed across wealth management, relationship managers, advisory representatives, product distribution, investment recommendations, product switching, vulnerable customers, complaint handling and supervisory review. | Fines, imprisonment, civil penalties, prohibition orders, representative action or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 197 | Professional Conduct | Failure to conduct customer knowledge or risk-profile assessment | FAA 2001, ss23, 34-36, 60; MAS notices | Regulates financial advisory services, representatives, supervisors and advice on investment products. It supports assessment of advisory duties, fair dealing, competence, suitability, supervision, disclosure and customer-facing conduct standards. | Applies to bank wealth management, investment advisory, insurance referrals, structured product recommendations and relationship managers acting as representatives. It should be reviewed across wealth management, relationship managers, advisory representatives, product distribution, investment recommendations, product switching, vulnerable customers, complaint handling and supervisory review. | Fines, imprisonment, civil penalties, prohibition orders, representative action or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 198 | Professional Conduct | Mis-selling of structured products or dual currency investments | FAA 2001, ss23, 34-36, 60; MAS notices | Regulates financial advisory services, representatives, supervisors and advice on investment products. It supports assessment of advisory duties, fair dealing, competence, suitability, supervision, disclosure and customer-facing conduct standards. | Applies to bank wealth management, investment advisory, insurance referrals, structured product recommendations and relationship managers acting as representatives. It should be reviewed across wealth management, relationship managers, advisory representatives, product distribution, investment recommendations, product switching, vulnerable customers, complaint handling and supervisory review. | Fines, imprisonment, civil penalties, prohibition orders, representative action or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 199 | Professional Conduct | Mis-selling of unit trusts, bonds or securities-linked products | FAA 2001, ss23, 34-36, 60; MAS notices | Regulates financial advisory services, representatives, supervisors and advice on investment products. It supports assessment of advisory duties, fair dealing, competence, suitability, supervision, disclosure and customer-facing conduct standards. | Applies to bank wealth management, investment advisory, insurance referrals, structured product recommendations and relationship managers acting as representatives. It should be reviewed across wealth management, relationship managers, advisory representatives, product distribution, investment recommendations, product switching, vulnerable customers, complaint handling and supervisory review. | Fines, imprisonment, civil penalties, prohibition orders, representative action or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 200 | Professional Conduct | Mis-selling of insurance or bancassurance product | FAA 2001, ss23, 34-36, 60; MAS notices | Regulates financial advisory services, representatives, supervisors and advice on investment products. It supports assessment of advisory duties, fair dealing, competence, suitability, supervision, disclosure and customer-facing conduct standards. | Applies to bank wealth management, investment advisory, insurance referrals, structured product recommendations and relationship managers acting as representatives. It should be reviewed across wealth management, relationship managers, advisory representatives, product distribution, investment recommendations, product switching, vulnerable customers, complaint handling and supervisory review. | Fines, imprisonment, civil penalties, prohibition orders, representative action or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 201 | Professional Conduct | False or misleading statement in financial advisory process | FAA 2001, ss23, 34-36, 60; MAS notices | Regulates financial advisory services, representatives, supervisors and advice on investment products. It supports assessment of advisory duties, fair dealing, competence, suitability, supervision, disclosure and customer-facing conduct standards. | Applies to bank wealth management, investment advisory, insurance referrals, structured product recommendations and relationship managers acting as representatives. It should be reviewed across wealth management, relationship managers, advisory representatives, product distribution, investment recommendations, product switching, vulnerable customers, complaint handling and supervisory review. | Fines, imprisonment, civil penalties, prohibition orders, representative action or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 202 | Professional Conduct | Unauthorised financial advice by bank staff | FAA 2001, ss6, 20, 23; MAS notices | Regulates financial advisory services, representatives, supervisors and advice on investment products. It supports assessment of advisory duties, fair dealing, competence, suitability, supervision, disclosure and customer-facing conduct standards. | Applies to bank wealth management, investment advisory, insurance referrals, structured product recommendations and relationship managers acting as representatives. It should be reviewed across wealth management, relationship managers, advisory representatives, product distribution, investment recommendations, product switching, vulnerable customers, complaint handling and supervisory review. | Fines, imprisonment, civil penalties, prohibition orders, representative action or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 203 | Professional Conduct | Failure to supervise financial advisory representatives | FAA 2001, ss6, 20, 23, 34-36, 60; MAS notices | Regulates financial advisory services, representatives, supervisors and advice on investment products. It supports assessment of advisory duties, fair dealing, competence, suitability, supervision, disclosure and customer-facing conduct standards. | Applies to bank wealth management, investment advisory, insurance referrals, structured product recommendations and relationship managers acting as representatives. It should be reviewed across wealth management, relationship managers, advisory representatives, product distribution, investment recommendations, product switching, vulnerable customers, complaint handlingand supervisory review. | Fines, imprisonment, civil penalties, prohibition orders, representative action or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 204 | Professional Conduct | Improper switching, churning or replacement of products | FAA 2001, ss23, 34-36, 60; MAS notices | Regulates financial advisory services, representatives, supervisors and advice on investment products. It supports assessment of advisory duties, fair dealing, competence, suitability, supervision, disclosure and customer-facing conduct standards. | Applies to bank wealth management, investment advisory, insurance referrals, structured product recommendations and relationship managers acting as representatives. It should be reviewed across wealth management, relationship managers, advisory representatives, product distribution, investment recommendations, product switching, vulnerable customers, complaint handling and supervisory review. | Fines, imprisonment, civil penalties, prohibition orders, representative action or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 205 | Professional Conduct | Improper handling of vulnerable customer advisory process | FAA 2001, ss23, 34-36, 60; MAS notices | Regulates financial advisory services, representatives, supervisors and advice on investment products. It supports assessment of advisory duties, fair dealing, competence, suitability, supervision, disclosure and customer-facing conduct standards. | Applies to bank wealth management, investment advisory, insurance referrals, structured product recommendations and relationship managers acting as representatives. It should be reviewed across wealth management, relationship managers, advisory representatives, product distribution, investment recommendations, product switching, vulnerable customers, complaint handling and supervisory review. | Fines, imprisonment, civil penalties, prohibition orders, representative action or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 206 | Professional Conduct | Failure to maintain advisory documentation and rationale | FAA 2001, ss6, 20, 23, 34-36, 60; MAS notices | Regulates financial advisory services, representatives, supervisors and advice on investment products. It supports assessment of advisory duties, fair dealing, competence, suitability, supervision, disclosure and customer-facing conduct standards. | Applies to bank wealth management, investment advisory, insurance referrals, structured product recommendations and relationship managers acting as representatives. It should be reviewed across wealth management, relationship managers, advisory representatives, product distribution, investment recommendations, product switching, vulnerable customers, complaint handling and supervisory review. | Fines, imprisonment, civil penalties, prohibition orders, representative action or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 207 | Professional Conduct | Failure to deal fairly with customers in product distribution | FAA 2001, ss6, 20, 23, 34-36, 60; MAS notices | Regulates financial advisory services, representatives, supervisors and advice on investment products. It supports assessment of advisory duties, fair dealing, competence, suitability, supervision, disclosure and customer-facing conduct standards. | Applies to bank wealth management, investment advisory, insurance referrals, structured product recommendations and relationship managers acting as representatives. It should be reviewed across wealth management, relationship managers, advisory representatives, product distribution, investment recommendations, product switching, vulnerable customers, complaint handling and supervisory review. | Fines, imprisonment, civil penalties, prohibition orders, representative action or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 208 | Professional Conduct | Misleading advertisement or product marketing material | FAA 2001, ss6, 20, 23, 34-36, 60; MAS notices | Regulates financial advisory services, representatives, supervisors and advice on investment products. It supports assessment of advisory duties, fair dealing, competence, suitability, supervision, disclosure and customer-facing conduct standards. | Applies to bank wealth management, investment advisory, insurance referrals, structured product recommendations and relationship managers acting as representatives. It should be reviewed across wealth management, relationship managers, advisory representatives, product distribution, investment recommendations, product switching, vulnerable customers, complaint handling and supervisory review. | Fines, imprisonment, civil penalties, prohibition orders, representative action or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 209 | Sector Breaches | Insider trading involving bank staff or customer information | SFA 2001, ss218-219 | Prohibits insider trading, market manipulation, false trading, price rigging and misleading statements. It supports assessment of specialised banking, payments, capital-markets, product, infrastructure or regulator-specific obligations applicable to the activity. | Applies where bank staff, traders, analysts, relationship managers or customers misuse information or manipulate markets through bank channels. It should be reviewed across specialised banking, payment rails, custody, capital-markets operations, product governance, client assets, contract notes, exchange reporting and sector-specific operational obligations. | Civil/criminal penalties and possible imprisonment, fines and prohibition orders depending offence. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 210 | Sector Breaches | False trading or market manipulation through bank channels | SFA 2001, ss197-204, 218-219 | Prohibits insider trading, market manipulation, false trading, price rigging and misleading statements. It supports assessment of specialised banking, payments, capital-markets, product, infrastructure or regulator-specific obligations applicable to the activity. | Applies where bank staff, traders, analysts, relationship managers or customers misuse information or manipulate markets through bank channels. It should be reviewed across specialised banking, payment rails, custody, capital-markets operations, product governance, client assets, contract notes, exchange reporting and sector-specific operational obligations. | Civil/criminal penalties and possible imprisonment, fines and prohibition orders depending offence. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 211 | Sector Breaches | Market rigging, price manipulation or matched orders | SFA 2001, ss197-204, 218-219 | Prohibits insider trading, market manipulation, false trading, price rigging and misleading statements. It supports assessment of specialised banking, payments, capital-markets, product, infrastructure or regulator-specific obligations applicable to the activity. | Applies where bank staff, traders, analysts, relationship managers or customers misuse information or manipulate markets through bank channels. It should be reviewed across specialised banking, payment rails, custody, capital-markets operations, product governance, client assets, contract notes, exchange reporting and sector-specific operational obligations. | Civil/criminal penalties and possible imprisonment, fines and prohibition orders depending offence. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 212 | Sector Breaches | Dissemination of false or misleading market information | SFA 2001, ss197-204, 218-219 | Prohibits insider trading, market manipulation, false trading, price rigging and misleading statements. It supports assessment of specialised banking, payments, capital-markets, product, infrastructure or regulator-specific obligations applicable to the activity. | Applies where bank staff, traders, analysts, relationship managers or customers misuse information or manipulate markets through bank channels. It should be reviewed across specialised banking, payment rails, custody, capital-markets operations, product governance, client assets, contract notes, exchange reporting and sector-specific operational obligations. | Civil/criminal penalties and possible imprisonment, fines and prohibition orders depending offence. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 213 | Sector Breaches | Front-running client orders | SFA 2001, ss197-204, 218-219 | Prohibits insider trading, market manipulation, false trading, price rigging and misleading statements. It supports assessment of specialised banking, payments, capital-markets, product, infrastructure or regulator-specific obligations applicable to the activity. | Applies where bank staff, traders, analysts, relationship managers or customers misuse information or manipulate markets through bank channels. It should be reviewed across specialised banking, payment rails, custody, capital-markets operations, product governance, client assets, contract notes, exchange reporting and sector-specific operational obligations. | Civil/criminal penalties and possible imprisonment, fines and prohibition orders depending offence. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 214 | Sector Breaches | Misuse of confidential order or research information | SFA 2001, ss197-204, 218-219 | Prohibits insider trading, market manipulation, false trading, price rigging and misleading statements. It supports assessment of specialised banking, payments, capital-markets, product, infrastructure or regulator-specific obligations applicable to the activity. | Applies where bank staff, traders, analysts, relationship managers or customers misuse information or manipulate markets through bank channels. It should be reviewed across specialised banking, payment rails, custody, capital-markets operations, product governance, client assets, contract notes, exchange reporting and sector-specific operational obligations. | Civil/criminal penalties and possible imprisonment, fines and prohibition orders depending offence. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 215 | Sector Breaches | Improper personal account dealing by bank employee | SFA 2001, ss197-204, 218-219 | Prohibits insider trading, market manipulation, false trading, price rigging and misleading statements. It supports assessment of specialised banking, payments, capital-markets, product, infrastructure or regulator-specific obligations applicable to the activity. | Applies where bank staff, traders, analysts, relationship managers or customers misuse information or manipulate markets through bank channels. It should be reviewed across specialised banking, payment rails, custody, capital-markets operations, product governance, client assets, contract notes, exchange reporting and sector-specific operational obligations. | Civil/criminal penalties and possible imprisonment, fines and prohibition orders depending offence. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 216 | Sector Breaches | Failure to maintain information barriers or Chinese walls | SFA 2001, ss197-204, 218-219; MAS capital markets conduct rules | Regulates securities, derivatives, capital markets products, market conduct and licensed activities. It supports assessment of specialised banking, payments, capital-markets, product, infrastructure or regulator-specific obligations applicable to the activity. | Applies where a bank deals in, advises on, distributes, trades or intermediates capital markets products or securities-linked products. It should be reviewed across specialised banking, payment rails, custody, capital-markets operations, product governance, client assets, contract notes, exchange reporting and sector-specific operational obligations. | Civil penalties, criminal penalties, licence action, prohibition orders or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 217 | Sector Breaches | Failure to manage conflicts in research, sales or trading | SFA 2001, ss199-200, 202-204; MAS capital markets conduct rules | Regulates securities, derivatives, capital markets products, market conduct and licensed activities. It supports assessment of specialised banking, payments, capital-markets, product, infrastructure or regulator-specific obligations applicable to the activity. | Applies where a bank deals in, advises on, distributes, trades or intermediates capital markets products or securities-linked products. It should be reviewed across specialised banking, payment rails, custody, capital-markets operations, product governance, client assets, contract notes, exchange reporting and sector-specific operational obligations. | Civil penalties, criminal penalties, licence action, prohibition orders or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 218 | Sector Breaches | Improper allocation of IPO, bond or structured product opportunities | SFA 2001, ss82, 99B-99O, 102-105, 197-204, 218-219; MAS capital markets conduct rules | Regulates securities, derivatives, capital markets products, market conduct and licensed activities. It supports assessment of specialised banking, payments, capital-markets, product, infrastructure or regulator-specific obligations applicable to the activity. | Applies where a bank deals in, advises on, distributes, trades or intermediates capital markets products or securities-linked products. It should be reviewed across specialised banking, payment rails, custody, capital-markets operations, product governance, client assets, contract notes, exchange reporting and sector-specific operational obligations. | Civil penalties, criminal penalties, licence action, prohibition orders or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 219 | Sector Breaches | Failure to comply with client asset or custody obligations | SFA 2001, ss103A-105; MAS capital markets conduct rules | Regulates securities, derivatives, capital markets products, market conduct and licensed activities. It supports assessment of specialised banking, payments, capital-markets, product, infrastructure or regulator-specific obligations applicable to the activity. | Applies where a bank deals in, advises on, distributes, trades or intermediates capital markets products or securities-linked products. It should be reviewed across specialised banking, payment rails, custody, capital-markets operations, product governance, client assets, contract notes, exchange reporting and sector-specific operational obligations. | Civil penalties, criminal penalties, licence action, prohibition orders or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 220 | Sector Breaches | Failure to provide accurate contract notes or confirmations | SFA 2001, ss102-103, 106-107; MAS capital markets conduct rules | Regulates securities, derivatives, capital markets products, market conduct and licensed activities. It supports assessment of specialised banking, payments, capital-markets, product, infrastructure or regulator-specific obligations applicable to the activity. | Applies where a bank deals in, advises on, distributes, trades or intermediates capital markets products or securities-linked products. It should be reviewed across specialised banking, payment rails, custody, capital-markets operations, product governance, client assets, contract notes, exchange reporting and sector-specific operational obligations. | Civil penalties, criminal penalties, licence action, prohibition orders or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 221 | Sector Breaches | Failure to keep capital markets records | SFA 2001, ss82, 99B-99O, 102-105, 197-204, 218-219; MAS capital markets conduct rules | Regulates securities, derivatives, capital markets products, market conduct and licensed activities. It supports assessment of specialised banking, payments, capital-markets, product, infrastructure or regulator-specific obligations applicable to the activity. | Applies where a bank deals in, advises on, distributes, trades or intermediates capital markets products or securities-linked products. It should be reviewed across specialised banking, payment rails, custody, capital-markets operations, product governance, client assets, contract notes, exchange reporting and sector-specific operational obligations. | Civil penalties, criminal penalties, licence action, prohibition orders or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 222 | Forgery Records | False or misleading report to MAS or exchange | SFA 2001, ss199-200, 202-204; MAS capital markets conduct rules | Regulates securities, derivatives, capital markets products, market conduct and licensed activities. It supports assessment of false documents, altered records, forged signatures, dishonest record creation and reliance on documents as genuine. | Applies where a bank deals in, advises on, distributes, trades or intermediates capital markets products or securities-linked products. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs, statements, confirmations, credit papers, audit files and regulatory submissions. | Civil penalties, criminal penalties, licence action, prohibition orders or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 223 | Evidence Obstruction | Obstruction of capital markets or financial advisory investigation | Penal Code 1871, ss175, 186, 201, 203, 204 | Protects lawful production of documents, investigations and evidence integrity. It supports assessment of concealment, destruction, withholding, false statements and conduct that frustrates lawful inquiries, audits or enforcement action. | Applies where documents are withheld, evidence destroyed, witnesses coached or MAS/police/auditors are obstructed. It should be reviewed across internal inquiries, audit reviews, MAS inspections, police investigations, complaint handling, disciplinary processes, document production, CCTV retention and electronic-record preservation. | Penalty depends on section and underlying offence; regulatory action may also apply. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 224 | Licensing Approvals | Failure to comply with prohibition order or representative restriction | FAA 2001, ss6, 20, 23, 34-36, 60; MAS notices | Regulates financial advisory services, representatives, supervisors and advice on investment products. It supports assessment of authorisation status, licence scope, approval conditions, regulatory permissions and whether banking or related activities were conducted lawfully. | Applies to bank wealth management, investment advisory, insurance referrals, structured product recommendations and relationship managers acting as representatives. It should be reviewed across licensed banking activities, merchant banking, digital banking, payment services, representative appointments, control changes, approved persons, licence conditions and scope restrictions. | Fines, imprisonment, civil penalties, prohibition orders, representative action or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 225 | Professional Conduct | Improper complaint handling for investment or advisory complaint | FAA 2001, ss23, 34-36, 60; MAS notices | Regulates financial advisory services, representatives, supervisors and advice on investment products. It supports assessment of advisory duties, fair dealing, competence, suitability, supervision, disclosure and customer-facing conduct standards. | Applies to bank wealth management, investment advisory, insurance referrals, structured product recommendations and relationship managers acting as representatives. It should be reviewed across wealth management, relationship managers, advisory representatives, product distribution, investment recommendations, product switching, vulnerable customers, complaint handling and supervisory review. | Fines, imprisonment, civil penalties, prohibition orders, representative action or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 226 | Professional Conduct | Failure to compensate or remediate customer after systemic mis-selling where directed | FAA 2001, ss23, 34-36, 60; MAS notices | Regulates financial advisory services, representatives, supervisors and advice on investment products. It supports assessment of advisory duties, fair dealing, competence, suitability, supervision, disclosure and customer-facing conduct standards. | Applies to bank wealth management, investment advisory, insurance referrals, structured product recommendations and relationship managers acting as representatives. It should be reviewed across wealth management, relationship managers, advisory representatives, product distribution, investment recommendations, product switching, vulnerable customers, complaint handling and supervisory review. | Fines, imprisonment, civil penalties, prohibition orders, representative action or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 227 | Abetment Attempts | Abetment or conspiracy in securities, advisory or market conduct offence | Penal Code 1871, ss107-109, 120A-120Band relevant principal offence | Covers abetment, conspiracy and attempts involving underlying offences. It supports assessment of assistance, planning, conspiracy, facilitation, coordinated misconduct and attempted commission of the underlying offence. | Applies where staff, customers, vendors, mule account holders or outsiders coordinate or attempt banking-related dishonesty. It should be reviewed wherever employees, customers, mule account holders, vendors, intermediaries, outsiders or managers coordinate, assist, attempt, conceal or facilitate the underlying misconduct. | Generally punished according to the principal offence, subject to applicable provisions. Detailed punishment description: liability normally tracks the principal offence and may extend to persons who plan, encourage, assist, facilitate, coordinate, conceal or attempt the misconduct, subject to the applicable Penal Code provisions and the facts proved. |
| 228 | Abetment Attempts | Attempt to commit insider trading, market misconduct or mis-selling offence | Penal Code 1871, ss107-109, 120A-120Band relevant principal offence | Covers abetment, conspiracy and attempts involving underlying offences. It supports assessment of assistance, planning, conspiracy, facilitation, coordinated misconduct and attempted commission of the underlying offence. | Applies where staff, customers, vendors, mule account holders or outsiders coordinate or attempt banking-related dishonesty. It should be reviewed wherever employees, customers, mule account holders, vendors, intermediaries, outsiders or managers coordinate, assist, attempt, conceal or facilitate the underlying misconduct. | Generally punished according to the principal offence, subject to applicable provisions. Detailed punishment description: liability normally tracks the principal offence and may extend to persons who plan, encourage, assist, facilitate, coordinate, conceal or attempt the misconduct, subject to the applicable Penal Code provisions and the facts proved. |
| 229 | Sector Breaches | Failure to manage cross-border advisory or solicitation restrictions | FAA 2001, ss6, 20, 23, 34-36, 60; MAS notices | Regulates financial advisory services, representatives, supervisors and advice on investment products. It supports assessment of specialised banking, payments, capital-markets, product, infrastructure or regulator-specific obligations applicable to the activity. | Applies to bank wealth management, investment advisory, insurance referrals, structured product recommendations and relationship managers acting as representatives. It should be reviewed across specialised banking, payment rails, custody, capital-markets operations, product governance, client assets, contract notes, exchange reporting and sector-specific operational obligations. | Fines, imprisonment, civil penalties, prohibition orders, representative action or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 230 | Professional Conduct | Failure to comply with product due diligence governance | FAA 2001, ss23, 34-36, 60; MAS notices | Regulates financial advisory services, representatives, supervisors and advice on investment products. It supports assessment of advisory duties, fair dealing, competence, suitability, supervision, disclosure and customer-facing conduct standards. | Applies to bank wealth management, investment advisory, insurance referrals, structured product recommendations and relationship managers acting as representatives. It should be reviewed across wealth management, relationship managers, advisory representatives, product distribution, investment recommendations, product switching, vulnerable customers, complaint handlingand supervisory review. | Fines, imprisonment, civil penalties, prohibition orders, representative action or MAS enforcement depending provision. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 231 | Corruption Ethics | Bank employee accepting gratification from customer, vendor or intermediary | Prevention of Corruption Act 1960, ss5-6 | Criminalises corrupt giving, receiving, soliciting or offering of gratification. It supports assessment of gratification, kickbacks, conflicts, abuse of authority, private gain and improper influence over banking decisions. | Applies to procurement, credit approval, onboarding, vendor selection, debt recovery, referral, hiring, advisory or regulatory interactions. It should be reviewed across procurement, lending approvals, onboarding, referrals, valuation work, vendor selection, debt recovery, commission arrangements, hiring, advisory decisions and senior approval processes. | Fine up to $100,000, imprisonment up to 5 years, or both; higher in certain public-sector contexts. Detailed punishment description: corruption cases may also involve confiscation of benefits, employment termination, disciplinary action, vendor debarment, reputational consequences, cooperation obligations and enhanced treatment for aggravating circumstances. |
| 232 | Corruption Ethics | Customer, vendor or intermediary offering gratification to bank employee | Prevention of Corruption Act 1960, ss5-6 | Criminalises corrupt giving, receiving, soliciting or offering of gratification. It supports assessment of gratification, kickbacks, conflicts, abuse of authority, private gain and improper influence over banking decisions. | Applies to procurement, credit approval, onboarding, vendor selection, debt recovery, referral, hiring, advisory or regulatory interactions. It should be reviewed across procurement, lending approvals, onboarding, referrals, valuation work, vendor selection, debt recovery, commission arrangements, hiring, advisory decisions and senior approval processes. | Fine up to $100,000, imprisonment up to 5 years, or both; higher in certain public-sector contexts. Detailed punishment description: corruption cases may also involve confiscation of benefits, employment termination, disciplinary action, vendor debarment, reputational consequences, cooperation obligations and enhanced treatment for aggravating circumstances. |
| 233 | Corruption Ethics | Corrupt reward for loan approval, credit limit or facility variation | Prevention of Corruption Act 1960, ss5-6 | Criminalises corrupt giving, receiving, soliciting or offering of gratification. It supports assessment of gratification, kickbacks, conflicts, abuse of authority, private gain and improper influence over banking decisions. | Applies to procurement, credit approval, onboarding, vendor selection, debt recovery, referral, hiring, advisory or regulatory interactions. It should be reviewed across procurement, lending approvals, onboarding, referrals, valuation work, vendor selection, debt recovery, commission arrangements, hiring, advisory decisions and senior approval processes. | Fine up to $100,000, imprisonment up to 5 years, or both; higher in certain public-sector contexts. Detailed punishment description: corruption cases may also involve confiscation of benefits, employment termination, disciplinary action, vendor debarment, reputational consequences, cooperation obligations and enhanced treatment for aggravating circumstances. |
| 234 | Corruption Ethics | Corrupt reward for onboarding, KYC clearance or account opening | Prevention of Corruption Act 1960, ss5-6 | Criminalises corrupt giving, receiving, soliciting or offering of gratification. It supports assessment of gratification, kickbacks, conflicts, abuse of authority, private gain and improper influence over banking decisions. | Applies to procurement, credit approval, onboarding, vendor selection, debt recovery, referral, hiring, advisory or regulatory interactions. It should be reviewed across procurement, lending approvals, onboarding, referrals, valuation work, vendor selection, debt recovery, commission arrangements, hiring, advisory decisions and senior approval processes. | Fine up to $100,000, imprisonment up to 5 years, or both; higher in certain public-sector contexts. Detailed punishment description: corruption cases may also involve confiscation of benefits, employment termination, disciplinary action, vendor debarment, reputational consequences, cooperation obligations and enhanced treatment for aggravating circumstances. |
| 235 | Corruption Ethics | Corrupt procurement, vendor selection or contract award | Prevention of Corruption Act 1960, ss5-6 | Criminalises corrupt giving, receiving, soliciting or offering of gratification. It supports assessment of gratification, kickbacks, conflicts, abuse of authority, private gain and improper influence over banking decisions. | Applies to procurement, credit approval, onboarding, vendor selection, debt recovery, referral, hiring, advisory or regulatory interactions. It should be reviewed across procurement, lending approvals, onboarding, referrals, valuation work, vendor selection, debt recovery, commission arrangements, hiring, advisory decisions and senior approval processes. | Fine up to $100,000, imprisonment up to 5 years, or both; higher in certain public-sector contexts. Detailed punishment description: corruption cases may also involve confiscation of benefits, employment termination, disciplinary action, vendor debarment, reputational consequences, cooperation obligations and enhanced treatment for aggravating circumstances. |
| 236 | Corruption Ethics | Kickback arrangement with broker, valuer, vendor or introducer | Prevention of Corruption Act 1960, ss5-6 | Criminalises corrupt giving, receiving, soliciting or offering of gratification. It supports assessment of gratification, kickbacks, conflicts, abuse of authority, private gain and improper influence over banking decisions. | Applies to procurement, credit approval, onboarding, vendor selection, debt recovery, referral, hiring, advisory or regulatory interactions. It should be reviewed across procurement, lending approvals, onboarding, referrals, valuation work, vendor selection, debt recovery, commission arrangements, hiring, advisory decisions and senior approval processes. | Fine up to $100,000, imprisonment up to 5 years, or both; higher in certain public-sector contexts. Detailed punishment description: corruption cases may also involve confiscation of benefits, employment termination, disciplinary action, vendor debarment, reputational consequences, cooperation obligations and enhanced treatment for aggravating circumstances. |
| 237 | Corruption Ethics | Use of false receipt, invoice or account in corrupt transaction | Prevention of Corruption Act 1960, ss5-6 | Criminalises corrupt giving, receiving, soliciting or offering of gratification. It supports assessment of gratification, kickbacks, conflicts, abuse of authority, private gain and improper influence over banking decisions. | Applies to procurement, credit approval, onboarding, vendor selection, debt recovery, referral, hiring, advisory or regulatory interactions. It should be reviewed across procurement, lending approvals, onboarding, referrals, valuation work, vendor selection, debt recovery, commission arrangements, hiring, advisory decisions and senior approval processes. | Fine up to $100,000, imprisonment up to 5 years, or both; higher in certain public-sector contexts. Detailed punishment description: corruption cases may also involve confiscation of benefits, employment termination, disciplinary action, vendor debarment, reputational consequences, cooperation obligations and enhanced treatment for aggravating circumstances. |
| 238 | Corruption Ethics | Conflict of interest not disclosed in credit, procurement or advisory decision | Penal Code 1871, ss405-409, 420, 424A, 477A;Banking Act 1970, ss43-45, 58, 66-67, 71;Companies Act 1967, ss156-157; MAS governance/corporate governance guidelines | Supports sound governance, internal controls, fit-and-proper management, auditability and accountability. It supports assessment of gratification, kickbacks, conflicts, abuse of authority, private gain and improper influence over banking decisions. | Applies to board, senior management, committees, risk, audit, compliance, finance, outsourcing and reporting functions in banks. It should be reviewed across procurement, lending approvals, onboarding, referrals, valuation work, vendor selection, debt recovery, commission arrangements, hiring, advisory decisions and senior approval processes. | Regulatory, civil, disciplinary and criminal consequences depending breach and statute. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 239 | Corruption Ethics | Undisclosed outside business, referral or commission arrangement | Penal Code 1871, ss405-409, 420, 424A, 477A;Banking Act 1970, ss43-45, 58, 66-67, 71;Companies Act 1967, ss156-157; MAS governance/corporate governance guidelines | Supports sound governance, internal controls, fit-and-proper management, auditability and accountability. It supports assessment of gratification, kickbacks, conflicts, abuse of authority, private gain and improper influence over banking decisions. | Applies to board, senior management, committees, risk, audit, compliance, finance, outsourcing and reporting functions in banks. It should be reviewed across procurement, lending approvals, onboarding, referrals, valuation work, vendor selection, debt recovery, commission arrangements, hiring, advisory decisions and senior approval processes. | Regulatory, civil, disciplinary and criminal consequences depending breach and statute. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 240 | Corruption Ethics | Misuse of confidential bank or customer information for private gain | Penal Code 1871, s424A | Covers fraud by false representation, non-disclosure or abuse of position. It supports assessment of gratification, kickbacks, conflicts, abuse of authority, private gain and improper influence over banking decisions. | Applies where banking position, information, system access or customer trust is abused for dishonest gain or to cause loss. It should be reviewed across procurement, lending approvals, onboarding, referrals, valuation work, vendor selection, debt recovery, commission arrangements, hiring, advisory decisions and senior approval processes. | Imprisonment up to 20 years, fine, or both. Detailed punishment description: corruption cases may also involve confiscation of benefits, employment termination, disciplinary action, vendor debarment, reputational consequences, cooperation obligations and enhanced treatment for aggravating circumstances. |
| 241 | Corruption Ethics | Abuse of authority by senior banker, manager or approving officer | Penal Code 1871, s424A | Covers fraud by false representation, non-disclosure or abuse of position. It supports assessment of gratification, kickbacks, conflicts, abuse of authority, private gain and improper influence over banking decisions. | Applies where banking position, information, system access or customer trust is abused for dishonest gain or to cause loss. It should be reviewed across procurement, lending approvals, onboarding, referrals, valuation work, vendor selection, debt recovery, commission arrangements, hiring, advisory decisions and senior approval processes. | Imprisonment up to 20 years, fine, or both. Detailed punishment description: corruption cases may also involve confiscation of benefits, employment termination, disciplinary action, vendor debarment, reputational consequences, cooperation obligations and enhanced treatment for aggravating circumstances. |
| 242 | Corruption Ethics | Retaliation against whistleblower or complainant | Penal Code 1871, ss405-409, 420, 424A, 477A;Banking Act 1970, ss43-45, 58, 66-67, 71;Companies Act 1967, ss156-157, 199-201, 401-402; MAS governance/corporate governance guidelines | Supports sound governance, internal controls, fit-and-proper management, auditability and accountability. It supports assessment of gratification, kickbacks, conflicts, abuse of authority, private gain and improper influence over banking decisions. | Applies to board, senior management, committees, risk, audit, compliance, finance, outsourcing and reporting functions in banks. It should be reviewed across procurement, lending approvals, onboarding, referrals, valuation work, vendor selection, debt recovery, commission arrangements, hiring, advisory decisions and senior approval processes. | Regulatory, civil, disciplinary and criminal consequences depending breach and statute. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 243 | Governance Controls | Failure to maintain whistleblowing or complaint escalation controls | Penal Code 1871, ss405-409, 420, 424A, 477A;Banking Act 1970, ss43-45, 58, 66-67, 71;Companies Act 1967, ss156-157, 199-201, 401-402; MAS governance/corporate governance guidelines | Supports sound governance, internal controls, fit-and-proper management, auditability and accountability. It supports assessment of oversight, risk ownership, internal controls, auditability, management accountability and whether control failures enabled the breach. | Applies to board, senior management, committees, risk, audit, compliance, finance, outsourcing and reporting functions in banks. It should be reviewed across board oversight, senior management, risk committees, compliance, internal audit, operations, outsourcing governance, segregation of duties, escalation channels and remediation ownership. | Regulatory, civil, disciplinary and criminal consequences depending breach and statute. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 244 | Governance Controls | Failure to maintain proper governance, risk and compliance framework | Penal Code 1871, ss405-409, 420, 424A, 477A;Banking Act 1970, ss43-45, 58, 66-67, 71;Companies Act 1967, ss156-157, 199-201, 401-402; MAS governance/corporate governance guidelines | Supports sound governance, internal controls, fit-and-proper management, auditability and accountability. It supports assessment of oversight, risk ownership, internal controls, auditability, management accountability and whether control failures enabled the breach. | Applies to board, senior management, committees, risk, audit, compliance, finance, outsourcing and reporting functions in banks. It should be reviewed across board oversight, senior management, risk committees, compliance, internal audit, operations, outsourcing governance, segregation of duties, escalation channels and remediation ownership. | Regulatory, civil, disciplinary and criminal consequences depending breach and statute. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 245 | Forgery Records | Failure to maintain accurate financial statements or management accounts | Penal Code 1871, s477A | Covers falsifying accounts, books, electronic records or documents with intent to defraud. It supports assessment of false documents, altered records, forged signatures, dishonest record creation and reliance on documents as genuine. | Applies to false ledgers, reconciliations, approvals, logs, transaction records, account files or audit materials. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs, statements, confirmations, credit papers, audit files and regulatory submissions. | Imprisonment up to 10 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority, cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 246 | Forgery Records | False or misleading board, committee or risk paper | Penal Code 1871, s477A | Covers falsifying accounts, books, electronic records or documents with intent to defraud. It supports assessment of false documents, altered records, forged signatures, dishonestrecord creation and reliance on documents as genuine. | Applies to false ledgers, reconciliations, approvals, logs, transaction records, account files or audit materials. It should be reviewed across account files, mandates, KYC records, approvals, reconciliations, transaction logs,statements, confirmations, credit papers, audit files and regulatory submissions. | Imprisonment up to 10 years, fine, or both. Detailed punishment description: sentencing and enforcement may consider offence value, customer impact, breach of trust, planning, concealment, seniority,cooperation, restitution, aggravating factors, related charges and regulatory consequences. |
| 247 | Governance Controls | Failure to retain records required for audit, MAS review or investigation | Penal Code 1871, ss405-409, 420, 424A, 477A;Banking Act 1970, ss43-45, 58, 66-67, 71;Companies Act 1967, ss199-201, 207, 401-402; MAS governance/corporate governance guidelines | Supports sound governance, internal controls, fit-and-proper management, auditability and accountability. It supports assessment of oversight, risk ownership, internal controls, auditability, management accountability and whether control failures enabled the breach. | Applies to board, senior management, committees, risk, audit, compliance, finance, outsourcing and reporting functions in banks. It should be reviewed across board oversight, senior management, risk committees, compliance, internal audit, operations, outsourcing governance, segregation of duties, escalation channels and remediation ownership. | Regulatory, civil, disciplinary and criminal consequences depending breach and statute. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 248 | Governance Controls | Failure to implement audit or regulatory remediation actions | Penal Code 1871, ss405-409, 420, 424A, 477A;Banking Act 1970, ss43-45, 58, 66-67, 71;Companies Act 1967, ss199-201, 207, 401-402; MAS governance/corporate governance guidelines | Supports sound governance, internal controls, fit-and-proper management, auditability and accountability. It supports assessment of oversight, risk ownership, internal controls, auditability, management accountability and whether control failures enabled the breach. | Applies to board, senior management, committees, risk, audit, compliance, finance, outsourcing and reporting functions in banks. It should be reviewed across board oversight, senior management, risk committees, compliance, internal audit, operations, outsourcing governance, segregation of duties, escalation channels and remediation ownership. | Regulatory, civil, disciplinary and criminal consequences depending breach and statute. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 249 | Governance Controls | Failure to maintain operational risk controls in cash, card or branch operations | Penal Code 1871, ss405-409, 420, 424A, 477A;Banking Act 1970, ss43-45, 58, 66-67, 71;Companies Act 1967, ss156-157, 199-201, 401-402; MAS governance/corporate governance guidelines | Supports sound governance, internal controls, fit-and-proper management, auditability and accountability. It supports assessment of oversight, risk ownership, internal controls, auditability, management accountability and whether control failures enabled the breach. | Applies to board, senior management, committees, risk, audit, compliance, finance, outsourcing and reporting functions in banks. It should be reviewed across board oversight, senior management, risk committees, compliance, internal audit, operations, outsourcing governance, segregation of duties, escalation channels and remediation ownership. | Regulatory, civil, disciplinary and criminal consequences depending breach and statute. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 250 | Governance Controls | Failure to manage fraud risk in customer service, call centre or branch operations | Penal Code 1871, ss405-409, 420, 424A, 477A;Banking Act 1970, ss43-45, 58, 66-67, 71;Companies Act 1967, ss156-157, 199-201, 401-402; MAS governance/corporate governance guidelines | Supports sound governance, internal controls, fit-and-proper management, auditability and accountability. It supports assessment of oversight, risk ownership, internal controls, auditability, management accountability and whether control failures enabled the breach. | Applies to board, senior management, committees, risk, audit, compliance, finance, outsourcing and reporting functions in banks. It should be reviewed across board oversight, senior management, risk committees, compliance, internal audit, operations, outsourcing governance, segregation of duties, escalation channels and remediation ownership. | Regulatory, civil, disciplinary and criminal consequences depending breach and statute. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 251 | Safety Security | Failure to maintain safe bank premises and workplace | Workplace Safety and Health Act 2006, ss11-12, 14-15;Fire Safety Act 1993, ss58, 60 | Requires safe workplace, fire safety, emergency preparedness and protection of staff, customers and visitors. It supports assessment of workplace safety, fire safety, physical security, emergency preparedness and protection of staff, customers, visitors and contractors. | Applies to branches, offices, data centres, ATMs, cash operations, vaults, call centres, events, contractors and facilities management. It should be reviewed across branches, offices, data centres, vaults, ATMs, cash movements, contractors, customer queues, emergencies, fire-safety controls, premises security and incident reporting. | Fines, imprisonment, stop-work/remedial orders, fire safety enforcement or civil liability depending breach. Detailed punishment description: safety consequences may include fines, imprisonment for serious breaches, remedial orders, stop-work directions, fire-safety enforcement, contractor sanctions, insurance consequences, civil liability and internal corrective action. |
| 252 | Safety Security | Failure to manage contractor safety in branches, offices or data centres | Workplace Safety and Health Act 2006, ss11-12, 14-15;Fire Safety Act 1993, ss58, 60 | Requires safe workplace, fire safety, emergency preparedness and protection of staff, customers and visitors. It supports assessment of workplace safety, fire safety, physical security, emergency preparedness and protection of staff, customers, visitors and contractors. | Applies to branches, offices, data centres, ATMs, cash operations, vaults, call centres, events, contractors and facilities management. It should be reviewed across branches, offices, data centres, vaults, ATMs, cash movements, contractors, customer queues, emergencies, fire-safety controls, premises security and incident reporting. | Fines, imprisonment, stop-work/remedial orders, fire safety enforcement or civil liability depending breach. Detailed punishment description: safety consequences may include fines, imprisonment for serious breaches, remedial orders, stop-work directions, fire-safety enforcement, contractor sanctions, insurance consequences, civil liability and internal corrective action. |
| 253 | Safety Security | Fire safety breach in branch, vault, office or data centre | Workplace Safety and Health Act 2006, ss11-12, 14-15;Fire Safety Act 1993, ss58, 60 | Requires safe workplace, fire safety, emergency preparedness and protection of staff, customers and visitors. It supports assessment of workplace safety, fire safety, physical security, emergency preparedness and protection of staff, customers, visitors and contractors. | Applies to branches, offices, data centres, ATMs, cash operations, vaults, call centres, events, contractors and facilities management. It should be reviewed across branches, offices, data centres, vaults, ATMs, cash movements, contractors, customer queues, emergencies, fire-safety controls, premises security and incident reporting. | Fines, imprisonment, stop-work/remedial orders, fire safety enforcement or civil liability depending breach. Detailed punishment description: safety consequences may include fines, imprisonment for serious breaches, remedial orders, stop-work directions, fire-safety enforcement, contractor sanctions, insurance consequences, civil liability and internal corrective action. |
| 254 | Safety Security | Failure to secure cash movement, vault or ATM replenishment operation | Penal Code 1871, ss405-409, 420, 424A, 477A;Banking Act 1970, ss43-45, 58, 66-67, 71;Companies Act 1967, ss156-157, 199-201, 401-402; MAS governance/corporate governance guidelines | Supports sound governance, internal controls, fit-and-proper management, auditability and accountability. It supports assessment of workplace safety, fire safety, physical security, emergency preparedness and protection of staff, customers, visitors and contractors. | Applies to board, senior management, committees, risk, audit, compliance, finance, outsourcing and reporting functions in banks. It should be reviewed across branches, offices, data centres, vaults, ATMs, cash movements, contractors, customer queues, emergencies, fire-safety controls, premises security and incident reporting. | Regulatory, civil, disciplinary and criminal consequences depending breach and statute. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 255 | Safety Security | Failure to protect customers during branch crowd, emergency or incident | Workplace Safety and Health Act 2006, ss11-12, 14-15;Fire Safety Act 1993, ss58, 60 | Requires safe workplace, fire safety, emergency preparedness and protection of staff, customers and visitors. It supports assessment of workplace safety, fire safety, physical security, emergency preparedness and protection of staff, customers, visitors and contractors. | Applies to branches, offices, data centres, ATMs, cash operations, vaults, call centres, events, contractors and facilities management. It should be reviewed across branches, offices, data centres, vaults, ATMs, cash movements, contractors, customer queues, emergencies, fire-safety controls, premises security and incident reporting. | Fines, imprisonment, stop-work/remedial orders, fire safety enforcement or civil liability depending breach. Detailed punishment description: safety consequences may include fines, imprisonment for serious breaches, remedial orders, stop-work directions, fire-safety enforcement, contractor sanctions, insurance consequences, civil liability and internal corrective action. |
| 256 | Safety Security | Failure to manage physical security at branch, vault, ATM or data centre | Penal Code 1871, ss405-409, 420, 424A, 477A;Banking Act 1970, ss43-45, 58, 66-67, 71;Companies Act 1967, ss156-157, 199-201, 401-402; MAS governance/corporate governance guidelines | Supports sound governance, internal controls, fit-and-proper management, auditability and accountability. It supports assessment of workplace safety, fire safety, physical security, emergency preparedness and protection of staff, customers, visitors and contractors. | Applies to board, senior management, committees, risk, audit, compliance, finance, outsourcing and reporting functions in banks. It should be reviewed across branches, offices, data centres, vaults, ATMs, cash movements, contractors, customer queues, emergencies, fire-safety controls, premises security and incident reporting. | Regulatory, civil, disciplinary and criminal consequences depending breach and statute. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 257 | Safety Security | Failure to report serious operational, safety or security incident | Penal Code 1871, ss405-409, 420, 424A, 477A;Banking Act 1970, ss43-45, 58, 66-67, 71;Companies Act 1967, ss401-402; MAS governance/corporate governance guidelines | Supports sound governance, internal controls, fit-and-proper management, auditability and accountability. It supports assessment of workplace safety, fire safety, physical security, emergency preparedness and protection of staff, customers, visitors and contractors. | Applies to board, senior management, committees, risk, audit, compliance, finance, outsourcing and reporting functions in banks. It should be reviewed across branches, offices, data centres, vaults, ATMs, cash movements, contractors, customer queues, emergencies, fire-safety controls, premises security and incident reporting. | Regulatory, civil, disciplinary and criminal consequences depending breach and statute. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 258 | Evidence Obstruction | Concealment of operational loss, fraud event or regulatory breach | Penal Code 1871, ss175, 186, 201, 203, 204 | Protects lawful production of documents, investigations and evidence integrity. It supports assessment of concealment, destruction, withholding, false statements and conduct that frustrates lawful inquiries, audits or enforcement action. | Applies where documents are withheld, evidence destroyed, witnesses coached or MAS/police/auditors are obstructed. It should be reviewed across internal inquiries, audit reviews, MAS inspections, police investigations, complaint handling, disciplinary processes, document production, CCTV retention and electronic-record preservation. | Penalty depends on section and underlying offence; regulatory action may also apply. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 259 | Governance Controls | Corporate or senior management liability for systemic banking failure | Penal Code 1871, ss405-409, 420, 424A, 477A;Banking Act 1970, ss65-67, 71;Companies Act 1967, ss156-157; MAS governance/corporate governance guidelines | Supports sound governance, internal controls, fit-and-proper management, auditability and accountability. It supports assessment of oversight, risk ownership, internal controls, auditability, management accountability and whether control failures enabled the breach. | Applies to board, senior management, committees, risk, audit, compliance, finance, outsourcing and reporting functions in banks. It should be reviewed across board oversight, senior management, risk committees, compliance, internal audit, operations, outsourcing governance, segregation of duties, escalation channels and remediation ownership. | Regulatory, civil, disciplinary and criminal consequences depending breach and statute. Detailed punishment description: enforcement may include MAS reprimands, composition sums, civil penalties, directions to remediate, independent reviews, licence conditions, restrictions, revocation, prohibition orders, senior-management accountability measures and prosecution where the statute allows. |
| 260 | Abetment Attempts | Conspiracy, abetment or attempt in corruption, governance, safety or public protection breaches | Penal Code 1871, ss107-109, 120A-120Band relevant principal offence | Covers abetment, conspiracy and attempts involving underlying offences. It supports assessment of assistance, planning, conspiracy, facilitation, coordinated misconduct and attempted commission of the underlying offence. | Applies where staff, customers, vendors, mule account holders or outsiders coordinate or attempt banking-related dishonesty. It should be reviewed wherever employees, customers, mule account holders, vendors, intermediaries, outsiders or managers coordinate, assist, attempt, conceal or facilitate the underlying misconduct. | Generally punished according to the principal offence, subject to applicable provisions. Detailed punishment description: liability normally tracks the principal offence and may extend to persons who plan, encourage, assist, facilitate, coordinate, conceal or attempt the misconduct, subject to the applicable Penal Code provisions and the facts proved. |
| 261 | Licensing Approvals | Operating a digital bank business beyond approved digital-bank licence scope | Banking Act 1970, ss4, 4A, 4B, 20, 66-67, 71 | Covers the legal or regulatory requirement relevant to operating a digital bank business beyond approved digital-bank licence scope under Banking Act 1970; MAS digital bank licence conditions and directions. It addresses authorisation status, licensing scope, MAS approvals, licence conditions, approved persons, permitted activities and regulated financial-serviceboundaries. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in operating a digital bank business beyond approved digital-bank licence scope. It applies to banking licences, merchant-bank approvals, digital-bank conditions, payment services, capital-markets activities, representative appointments, branch operations, changes in control, approved officers andactivity-scope restrictions. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 262 | Licensing Approvals | Operating a wholesale bank activity beyond approved licence restrictions | Banking Act 1970, ss4, 4A, 4B, 20, 66-67, 71 | Covers the legal or regulatory requirement relevant to operating a wholesale bank activity beyond approved licence restrictions under Banking Act 1970; MAS licence restrictions and conditions. It addresses authorisation status, licensing scope, MAS approvals, licence conditions, approved persons, permitted activities and regulated financial-service boundaries. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in operating a wholesale bank activity beyond approved licence restrictions. It applies to banking licences, merchant-bank approvals, digital-bank conditions, payment services, capital-markets activities, representative appointments, branch operations, changes in control, approved officers and activity-scope restrictions. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 263 | Regulatory Duties | Operating an offshore or overseas booking model that circumvents Singapore banking restrictions | Banking Act 1970, ss4, 4A, 4B, 20, 66-67, 71; MAS notices | Covers the legal or regulatory requirement relevant to operating an offshore or overseas booking model that circumvents singapore banking restrictions under Banking Act 1970; MAS notices, directions and licensing conditions. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in operating an offshore or overseas booking model that circumvents singapore banking restrictions. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 264 | Licensing Approvals | Establishing a bank branch or place of business without required MAS approval | Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71 | Covers the legal or regulatory requirement relevant to establishing a bank branch or place of business without required mas approval under Banking Act 1970; MAS approval requirements. It addresses authorisation status, licensing scope, MAS approvals, licence conditions, approved persons, permitted activities and regulated financial-service boundaries. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in establishing a bank branch or place of business without required mas approval. It applies to banking licences, merchant-bank approvals, digital-bank conditions, payment services, capital-markets activities, representative appointments, branch operations, changes in control, approved officers and activity-scope restrictions. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 265 | Licensing Approvals | Relocating branch, representative office or banking outlet without required approval or notification | Banking Act 1970, ss4, 4A, 4B, 20, 66-67, 71 | Covers the legal or regulatory requirement relevant to relocating branch, representative office or banking outlet without required approval or notification under Banking Act 1970; MAS licensing conditions and notification requirements. It addresses authorisation status, licensing scope, MAS approvals, licence conditions, approved persons, permitted activities and regulated financial-service boundaries. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in relocating branch, representative office or banking outlet without required approval or notification. It applies to banking licences, merchant-bank approvals, digital-bank conditions, payment services, capital-markets activities, representative appointments, branch operations, changes in control, approved officers and activity-scope restrictions. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 266 | Licensing Approvals | Using restricted banking name, description or branding without lawful authorisation | Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71;Monetary Authority of Singapore Act 1970, ss27A-27B, 28 | Covers the legal or regulatory requirement relevant to using restricted banking name, description or branding without lawful authorisation under Banking Act 1970; MAS Act 1970; Penal Code where deception occurs. It addresses authorisation status, licensing scope, MAS approvals, licence conditions, approved persons, permitted activities and regulated financial-service boundaries. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in using restricted banking name, description or branding without lawful authorisation. It applies to banking licences, merchant-bank approvals, digital-bank conditions, payment services, capital-markets activities, representative appointments, branch operations, changes in control, approved officers and activity-scope restrictions. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 267 | Fraud Deception | Holding out as bank, merchant bank or MAS-authorised institution when not authorised | Penal Code 1871, ss420 and 424A;Banking Act 1970, ss55S-55T, 55Z;Monetary Authority of Singapore Act 1970, ss27A-27B, 28 | Covers the legal or regulatory requirement relevant to holding out as bank, merchant bank or mas-authorised institution when not authorised under Banking Act 1970; MAS Act 1970; Penal Code 1871, ss420 and 424A. It addresses deception, false representation, non-disclosure, dishonest inducement, abuse of position and resulting loss or improper gain in banking activity. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in holding out as bank, merchant bank or mas-authorised institution when not authorised. It applies across onboarding, lending, cards, payments, trade finance, wealth management, vendor claims, customer communications, digital channels, approval workflows, refunds, waivers and representations made to customers, counterparties or regulators. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 268 | Licensing Approvals | Failure to obtain MAS approval for appointment of key officer where approval is required | Banking Act 1970, ss65-67, 71 | Covers the legal or regulatory requirement relevant to failure to obtain mas approval for appointment of key officer where approval is required under Banking Act 1970; MAS fit-and-proper requirements. It addresses authorisation status, licensing scope, MAS approvals, licence conditions, approved persons, permitted activities and regulated financial-service boundaries. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to obtain mas approval for appointment of key officer where approval is required. It applies to banking licences, merchant-bank approvals, digital-bank conditions, payment services, capital-markets activities, representative appointments, branch operations, changes in control, approved officers and activity-scope restrictions. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 269 | Regulatory Duties | Failure to remove or replace director or senior manager after MAS objection or condition | Banking Act 1970, ss65-67, 71;Monetary Authority of Singapore Act 1970, ss27A-27B, 28 | Covers the legal or regulatory requirement relevant to failure to remove or replace director or senior manager after mas objection or condition under Banking Act 1970; MAS directions and fit-and-proper requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to remove or replace director or senior manager after mas objection or condition. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 270 | Regulatory Duties | Failure to notify MAS of adverse fit-and-proper information on director or senior manager | Banking Act 1970, ss65-67, 71 | Covers the legal or regulatory requirement relevant to failure to notify mas of adverse fit-and-proper information on director or senior manager under Banking Act 1970; MAS fit-and-proper and notification requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to notify mas of adverse fit-and-proper information on director or senior manager. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 271 | Governance Controls | Failure to maintain required board composition, independence or governance committee arrangements | Banking Act 1970, ss65-67, 71; MAS governance/corporate governance guidelines | Covers the legal or regulatory requirement relevant to failure to maintain required board composition, independence or governance committee arrangements under Banking Act 1970; MAS corporate governance requirements and guidelines. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain required board composition, independence or governance committee arrangements. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 272 | Governance Controls | Failure to maintain board-approved risk appetite for material banking risks | Banking Act 1970, ss65-67, 71 | Covers the legal or regulatory requirement relevant to failure to maintain board-approved risk appetite for material banking risks under Banking Act 1970; MAS risk management guidelines. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain board-approved risk appetite for material banking risks. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 273 | Governance Controls | Failure to escalate material risk breach to board or senior management | Banking Act 1970, ss65-67, 71; MAS governance/corporate governance guidelines | Covers the legal or regulatory requirement relevant to failure to escalate material risk breach to board or senior management under Banking Act 1970; MAS governance and risk management requirements. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to escalate material risk breach to board or senior management. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 274 | Regulatory Duties | Failure to maintain accurate register of controllers, substantial shareholders or relevant owners | Banking Act 1970, ss15-17, 66-67, 71 | Covers the legal or regulatory requirement relevant to failure to maintain accurate register of controllers, substantial shareholders or relevant owners under Banking Act 1970; MAS approval and control requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain accurate register of controllers, substantial shareholders or relevant owners. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 275 | Licensing Approvals | Acquisition of control or substantial shareholdingwithout MAS approval | Banking Act 1970, ss15-17, 66-67, 71 | Covers the legal or regulatory requirement relevant toacquisition of control or substantial shareholding without mas approval under Banking Act 1970, control and shareholding approval provisions. It addresses authorisation status, licensing scope, MAS approvals, licence conditions, approved persons, permitted activities and regulated financial-service boundaries. | Applies where the bank, banking group, branch, officer, representative,employee, contractor, outsourced provider, customer or intermediary is involved in acquisition of control or substantial shareholding without mas approval. It applies to banking licences, merchant-bank approvals, digital-bank conditions, payment services, capital-markets activities, representative appointments, branch operations, changes in control, approved officers and activity-scope restrictions. | Banking Act or MAS-related breaches may result in MAS directions,reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 276 | Regulatory Duties | Failure to comply with MAS condition imposed on controller or substantial shareholder | Banking Act 1970, ss15-17, 66-67, 71 | Covers the legal or regulatory requirement relevant to failure to comply with mas condition imposed on controller or substantial shareholder under Banking Act 1970; MAS approval conditions. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to comply with mas condition imposed on controller or substantial shareholder. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 277 | Regulatory Duties | Failure to maintain required leverage ratio or leverage disclosure | Banking Act 1970, ss47, 47Aand Third Schedule | Covers the legal or regulatory requirement relevant to failure to maintain required leverage ratio or leverage disclosure under Banking Act 1970; MAS capital and leverage requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain required leverage ratio or leverage disclosure. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 278 | Regulatory Duties | Failure to calculate risk-weighted assets accurately for capital adequacy | Banking Act 1970, ss9-10B, 66-67, 71 | Covers the legal or regulatory requirement relevant to failure to calculate risk-weighted assets accurately for capital adequacy under Banking Act 1970; MAS capital adequacy notices. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to calculate risk-weighted assets accurately for capital adequacy. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 279 | Regulatory Duties | Failure to deduct capital items or apply prudential adjustments correctly | Banking Act 1970, ss9-10B, 66-67, 71 | Covers the legal or regulatory requirement relevant to failure to deduct capital items or apply prudential adjustments correctly under Banking Act 1970; MAS capital adequacy notices. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to deduct capital items or apply prudential adjustments correctly. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 280 | Regulatory Duties | Failure to maintain capital conservation, countercyclical or systemic buffers where applicable | Banking Act 1970, ss9-10B, 66-67, 71 | Covers the legal or regulatory requirement relevant to failure to maintain capital conservation, countercyclical or systemic buffers where applicable under Banking Act 1970; MAS capital buffer requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain capital conservation, countercyclical or systemic buffers where applicable. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 281 | Regulatory Duties | Improper recognition of eligible capital instruments or loss-absorbing capacity | Banking Act 1970, ss9-10B, 66-67, 71 | Covers the legal or regulatory requirement relevant to improper recognition of eligible capital instruments or loss-absorbing capacity under Banking Act 1970; MAS capital and resolution requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in improper recognition of eligible capital instruments or loss-absorbing capacity. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 282 | Regulatory Duties | Failure to maintain minimum liquid assets or liquidity coverage ratio controls | Banking Act 1970, s38, ss66-67, 71 | Covers the legal or regulatory requirement relevant to failure to maintain minimum liquid assets or liquidity coverage ratio controls under Banking Act 1970; MAS liquidity requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain minimum liquid assets or liquidity coverage ratio controls. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 283 | Regulatory Duties | Failure to maintain net stable funding ratio or structural liquidity controls | Banking Act 1970, s38, ss66-67, 71 | Covers the legal or regulatory requirement relevant to failure to maintain net stable funding ratio or structural liquidity controls under Banking Act 1970; MAS liquidity and funding requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain net stable funding ratio or structural liquidity controls. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 284 | Governance Controls | Failure to manage intraday liquidity risk in payment or settlement activity | Banking Act 1970, s38, ss66-67, 71 | Covers the legal or regulatory requirement relevant to failure to manage intraday liquidity risk in payment or settlement activity under Banking Act 1970; MAS liquidity risk and payment system expectations. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to manage intraday liquidity risk in payment or settlement activity. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 285 | Governance Controls | Failure to maintain adequate funding concentration controls | Banking Act 1970, s38, ss66-67, 71 | Covers the legal or regulatory requirement relevant to failure to maintain adequate funding concentration controls under Banking Act 1970; MAS liquidity risk management guidelines. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain adequate funding concentration controls. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 286 | Regulatory Duties | Breach of single counterparty exposure limit | Banking Act 1970, ss27-29, 66-67, 71 | Covers the legal or regulatory requirement relevant to breach of single counterparty exposure limit under Banking Act 1970; MAS large exposure requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in breach of single counterparty exposure limit. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 287 | Regulatory Duties | Breach of group exposure limit or connected counterparty aggregation requirement | Banking Act 1970, ss27-29, 66-67, 71 | Covers the legal or regulatory requirement relevant to breach of group exposure limit or connected counterparty aggregation requirement under Banking Act 1970; MAS large exposure requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in breach of group exposure limit or connected counterparty aggregation requirement. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 288 | Governance Controls | Failure to identify related parties for exposure and connected lending controls | Banking Act 1970, ss27-29, 66-67, 71 | Covers the legal or regulatory requirement relevant to failure to identify related parties for exposure and connected lending controls under Banking Act 1970; MAS related-party transaction requirements. It addresses board oversight, management accountability, internal controls, riskmanagement, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to identify related parties for exposure and connected lending controls. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflictsmanagement, escalation channels, policy ownership and control testing. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 289 | Regulatory Duties | Granting connected lending or related-party facility without required approval or controls | Banking Act 1970, ss27-29, 66-67, 71 | Covers the legal or regulatory requirement relevant to granting connected lending or related-party facility without required approval or controls under Banking Act 1970; MAS related-party transaction requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in granting connected lending or related-party facility without required approval or controls. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 290 | Governance Controls | Failure to price related-party banking transactions on arm’s-length basis | Banking Act 1970, ss27-29, 66-67, 71; MAS governance/corporate governance guidelines | Covers the legal or regulatory requirement relevant to failure to price related-party banking transactions on arm’s-length basis under Banking Act 1970; MAS corporate governance and related-party requirements. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to price related-party banking transactions on arm’s-length basis. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 291 | Governance Controls | Failure to maintain country risk, transfer risk or sovereign exposure limits | Banking Act 1970, ss27-29, 66-67, 71 | Covers the legal or regulatory requirement relevant to failure to maintain country risk, transfer risk or sovereign exposure limits under Banking Act 1970; MAS risk management guidelines. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain country risk, transfer risk or sovereign exposure limits. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 292 | Regulatory Duties | Failure to classify credit exposures, past-due status or non-performing loans accurately | Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71 | Covers the legal or regulatory requirement relevant to failure to classify credit exposures, past-due status or non-performing loans accurately under Banking Act 1970; MAS credit risk and provisioning requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to classify credit exposures, past-due status or non-performing loans accurately. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 293 | Regulatory Duties | Failure to maintain adequate expected credit loss or specific allowance controls | Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71 | Covers the legal or regulatory requirement relevant to failure to maintain adequate expected credit loss or specific allowance controls under Banking Act 1970; MAS accounting and credit risk requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain adequate expected credit loss or specific allowance controls. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 294 | Governance Controls | Failure to conduct independent credit review or loan portfolio stress testing | Banking Act 1970, ss43-45, 58, 66-67, 71 | Covers the legal or regulatory requirement relevant to failure to conduct independent credit review or loan portfolio stress testing under Banking Act 1970; MAS credit risk management requirements. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to conduct independent credit review or loan portfolio stress testing. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 295 | Governance Controls | Failure to maintain collateral valuation, margining or revaluation controls | Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71 | Covers the legal or regulatory requirement relevant to failure to maintain collateral valuation, margining or revaluation controls under Banking Act 1970; MAS credit and collateral risk requirements. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain collateral valuation, margining or revaluation controls. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 296 | Governance Controls | Failure to manage concentration risk in property, SME, trade or consumer lending portfolio | Banking Act 1970, ss27-29, 66-67, 71 | Covers the legal or regulatory requirement relevant to failure to manage concentration risk in property, sme, trade or consumer lending portfolio under Banking Act 1970; MAS credit concentration and stress-testing expectations. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to manage concentration risk in property, sme, trade or consumer lending portfolio. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 297 | Regulatory Duties | Failure to comply with MAS public disclosure requirements for capital, risk or prudential information | Banking Act 1970, ss47, 47Aand Third Schedule | Covers the legal or regulatory requirement relevant to failure to comply with mas public disclosure requirements for capital, risk or prudential information under Banking Act 1970; MAS public disclosure requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to comply with mas public disclosure requirements for capital, risk or prudential information. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 298 | Forgery Records | False or misleading prudential disclosure to the public or investors | Penal Code 1871, ss415-420, 424A;Banking Act 1970, ss47, 47Aand Third Schedule | Covers the legal or regulatory requirement relevant to false or misleading prudential disclosure to the public or investors under Banking Act 1970; Penal Code 1871, ss477A and 424A where dishonest. It addresses false documents, altered records, inaccurate returns, backdated approvals, manipulated evidence or dishonest reliance on records as genuine. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in false or misleading prudential disclosure to the public or investors. It applies to account files, KYC records, returns, approvals, credit papers, reconciliations, audit logs, payment instructions, board papers, correspondence, customer statements, regulatory submissions and electronic records used in banking decisions. | Bank secrecy and customer-information breaches may result in criminal penalties under the Banking Act, MAS enforcement action, confidentiality restrictions, civil liability, customer remediation, disciplinary action and possible fitness-and-propriety consequences for responsible persons. |
| 299 | Regulatory Duties | Failure to submit group-level consolidated return to MAS where required | Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71 | Covers the legal or regulatory requirement relevant to failure to submit group-level consolidated return to mas where required under Banking Act 1970; MAS regulatory return requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to submit group-level consolidated return to mas where required. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 300 | Regulatory Duties | Failure to maintain books and records sufficient for MAS supervisory review | Banking Act 1970, ss43-45, 58, 66-67, 71;Monetary Authority of Singapore Act 1970, ss27A-27B, 28 | Covers the legal or regulatory requirement relevant to failure to maintain books and records sufficient for mas supervisory review under Banking Act 1970; MAS inspection and record-keeping powers. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain books and records sufficient for mas supervisory review. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 301 | Evidence Obstruction | Failure to provide MAS with requested information, documents or explanations | Penal Code 1871, ss175 and 186;Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71;Monetary Authority of Singapore Act 1970, ss27A-27B, 28 | Covers the legal or regulatory requirement relevant to failure to provide mas with requested information, documents or explanations under Banking Act 1970; MAS Act 1970; Penal Code 1871, ss175 and 186. It addresses concealment, destruction, withholding, delay, misleading statements or interference that frustrates lawful audit, supervision, investigation or enforcement. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to provide mas with requested information, documents or explanations. It applies during MAS inspections, internal investigations, audit reviews, police inquiries, customer complaints, disciplinary processes, incident response, document production, CCTV retrieval, audit-log preservation and whistleblowing investigations. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 302 | Evidence Obstruction | Providing incomplete, delayed or evasiveresponse to MAS supervisory request | Penal Code 1871, ss177, 182, 191-193, 199;Banking Act 1970, ss43-45, 58, 66-67, 71;Monetary Authority of Singapore Act 1970, ss27A-27B, 28 | Covers the legal or regulatory requirement relevant to providingincomplete, delayed or evasive response to mas supervisory request under Banking Act 1970; MAS Act 1970; Penal Code 1871 where false information is given. It addresses concealment, destruction, withholding, delay, misleading statements or interference that frustrates lawful audit, supervision, investigation or enforcement. | Applies where the bank, banking group, branch, officer, representative,employee, contractor, outsourced provider, customer or intermediary is involved in providing incomplete, delayed or evasive response to mas supervisory request. It applies during MAS inspections, internal investigations, audit reviews, police inquiries, customer complaints, disciplinary processes, incident response, document production, CCTV retrieval, audit-log preservation and whistleblowing investigations. | Banking Act or MAS-related breaches may result in MAS directions,reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 303 | Evidence Obstruction | Concealing breach of licence condition from MAS or internal governance body | Penal Code 1871, ss201, 203 and 204;Banking Act 1970, ss4, 4A, 4B, 20, 66-67, 71 | Covers the legal or regulatory requirement relevant to concealing breach of licence condition from mas or internal governance body under Banking Act 1970; Penal Code 1871, ss201, 203 and 204. It addresses concealment, destruction, withholding, delay, misleading statements or interference that frustrates lawful audit, supervision, investigation or enforcement. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in concealing breach of licence condition from mas or internal governance body. It applies during MAS inspections, internal investigations, audit reviews, police inquiries, customer complaints, disciplinary processes, incident response, document production, CCTV retrieval, audit-log preservation and whistleblowing investigations. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 304 | Regulatory Duties | Failure to comply with MAS written direction, restriction or supervisory measure | Banking Act 1970, ss43-45, 58, 66-67, 71;Monetary Authority of Singapore Act 1970, ss27A-27B, 28;Financial Services and Markets Act 2022, ss3, 29, 169-170, 176 | Covers the legal or regulatory requirement relevant to failure to comply with mas written direction, restriction or supervisory measure under Banking Act 1970; MAS Act 1970; FSMA 2022. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to comply with mas written direction, restriction or supervisory measure. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 305 | Regulatory Duties | Failure to comply with MAS requirement to appoint auditor, external reviewer or skilled person | Banking Act 1970, ss43-45, 58, 66-67, 71 | Covers the legal or regulatory requirement relevant to failure to comply with mas requirement to appoint auditor, external reviewer or skilled person under Banking Act 1970; MAS supervisory powers and directions. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to comply with mas requirement to appoint auditor, external reviewer or skilled person. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 306 | Evidence Obstruction | Failure to provide auditor with access to books, records or explanations | Penal Code 1871, ss186 and 204;Banking Act 1970, ss43-45, 58, 66-67, 71;Companies Act 1967, ss199-201, 207, 401-402 | Covers the legal or regulatory requirement relevant to failure to provide auditor with access to books, records or explanations under Banking Act 1970; Companies Act 1967; Penal Code 1871, ss186 and 204. It addresses concealment, destruction, withholding, delay, misleading statements or interference that frustrates lawful audit, supervision, investigation or enforcement. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to provide auditor with access to books, records or explanations. It applies during MAS inspections, internal investigations, audit reviews, police inquiries, customer complaints, disciplinary processes, incident response, document production, CCTV retrieval, audit-log preservation and whistleblowing investigations. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 307 | Regulatory Duties | Failure to notify MAS of auditor resignation, adverse report or qualified opinion where required | Banking Act 1970, ss43-45, 58, 66-67, 71 | Covers the legal or regulatory requirement relevant to failure to notify mas of auditor resignation, adverse report or qualified opinion where required under Banking Act 1970; MAS reporting requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to notify mas of auditor resignation, adverse report or qualified opinion where required. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 308 | Regulatory Duties | Failure to ring-fence Singapore operations or maintain required asset maintenance arrangements | Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71 | Covers the legal or regulatory requirement relevant to failure to ring-fence singapore operations or maintain required asset maintenance arrangements under Banking Act 1970; MAS asset maintenance requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to ring-fence singapore operations or maintain required asset maintenance arrangements. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 309 | Regulatory Duties | Improper booking, transfer or removal of Singapore assets contrary to MAS restrictions | Banking Act 1970, ss43-45, 58, 66-67, 71 | Covers the legal or regulatory requirement relevant to improper booking, transfer or removal of singapore assets contrary to mas restrictions under Banking Act 1970; MAS asset maintenance and supervisory requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in improper booking, transfer or removal of singapore assets contrary to mas restrictions. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 310 | Governance Controls | Failure to prepare, maintain or test recovery and resolution planning information | Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71 | Covers the legal or regulatory requirement relevant to failure to prepare, maintain or test recovery and resolution planning information under Banking Act 1970; MAS recovery and resolution planning requirements. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to prepare, maintain or test recovery and resolution planning information. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 311 | Financial Crime | Failure to perform enterprise-wide money laundering and terrorism financing risk assessment | CDSA 1992, ss50-54, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to perform enterprise-wide money laundering and terrorism financing risk assessment under MAS Notice 626; CDSA 1992; Terrorism (Suppression of Financing) Act 2002. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to perform enterprise-wide money laundering and terrorism financing risk assessment. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 312 | Financial Crime | Failure to update AML/CFT risk assessment after new products, channels or geographies | MAS Notice 626; MAS Guidelines to Notice 626; MAS Notice 626; MAS Guidelines to Notice 626; MAS guidelines | Covers the legal or regulatory requirement relevant to failure to update aml/cft risk assessment after new products, channels or geographies under MAS Notice 626; MAS Guidelines to Notice 626. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to update aml/cft risk assessment after new products, channels or geographies. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 313 | Financial Crime | Failure to assign appropriate customer risk rating at onboarding | MAS Notice 626; MAS Guidelines to Notice 626; MAS Notice 626; MAS Guidelines to Notice 626; MAS guidelines | Covers the legal or regulatory requirement relevant to failure to assign appropriate customer risk rating at onboarding under MAS Notice 626; MAS Guidelines to Notice 626. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to assign appropriate customer risk rating at onboarding. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 314 | Financial Crime | Failure to refresh customer due diligence for dormant or long-standing accounts | CDSA 1992, ss39, 50-54, 57; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to refresh customer due diligence for dormant or long-standing accounts under MAS Notice 626; CDSA 1992. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to refresh customer due diligence for dormant or long-standing accounts. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 315 | Financial Crime | Failure to identify senior managing official where beneficial owner cannot be identified | MAS Notice 626; MAS Guidelines to Notice 626; MAS Notice 626; MAS Guidelines to Notice 626; MAS guidelines | Covers the legal or regulatory requirement relevant to failure to identify senior managing official where beneficial owner cannot be identified under MAS Notice 626; MAS Guidelines to Notice626. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to identify senior managing official where beneficial ownercannot be identified. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reportingconsequences, prohibition orders and management accountability measures. |
| 316 | Financial Crime | Failure to verify source of wealth for high-risk private banking customer | CDSA 1992, ss39, 50-54, 57; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to verify source of wealth for high-risk private banking customer under MAS Notice 626; CDSA 1992. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to verify source of wealth for high-risk private banking customer. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 317 | Financial Crime | Failure to verify source of funds for unusually large or complex transaction | CDSA 1992, ss39, 50-54, 57; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to verify source of funds for unusually large or complex transaction under MAS Notice 626; CDSA 1992. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to verify source of funds for unusually large or complex transaction. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 318 | Financial Crime | Failure to identify nominee shareholder, nominee director or complex ownership structure risk | MAS Notice 626; MAS Guidelines to Notice 626; MAS Notice 626; MAS Guidelines to Notice 626; MAS guidelines | Covers the legal or regulatory requirement relevant to failure to identify nominee shareholder, nominee director or complex ownership structure risk under MAS Notice 626; MAS Guidelines to Notice 626. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to identify nominee shareholder, nominee director or complex ownership structure risk. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 319 | Financial Crime | Failure to conduct enhanced due diligence for high-risk jurisdiction customer | MAS Notice 626; MAS high-risk jurisdiction guidance; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to conduct enhanced due diligence for high-risk jurisdiction customer under MAS Notice 626; MAS high-risk jurisdiction guidance. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to conduct enhanced due diligence for high-risk jurisdiction customer. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 320 | Financial Crime | Failure to conduct enhanced due diligence for politically exposed person close associate | MAS Notice 626; MAS Guidelines to Notice 626; MAS Notice 626; MAS Guidelines to Notice 626; MAS guidelines | Covers the legal or regulatory requirement relevant to failure to conduct enhanced due diligence for politically exposed person close associate under MAS Notice 626; MAS Guidelines to Notice 626. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to conduct enhanced due diligence for politically exposed person close associate. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 321 | Governance Controls | Failure to obtain senior management approval for high-risk customer relationship | MAS Notice 626; MAS AML/CFT governance requirements; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to obtain senior management approval for high-risk customer relationship under MAS Notice 626; MAS AML/CFT governance requirements. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to obtain senior management approval for high-risk customer relationship. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 322 | Financial Crime | Failure to terminate or restrict relationship where customer due diligence cannot be completed | CDSA 1992, ss39, 57; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to terminate or restrict relationship where customer due diligence cannot be completed under MAS Notice 626; CDSA 1992. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to terminate or restrict relationship where customer due diligence cannot be completed. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 323 | Financial Crime | Failure to screen customer names against sanctions at onboarding | Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to screen customer names against sanctions at onboarding under MAS Notice 626; United Nations Act 2001; TSFA 2002. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to screen customer names against sanctions at onboarding. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 324 | Financial Crime | Failure to rescreen existing customers after sanctions list update | Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to rescreen existing customers after sanctions list update under MAS Notice 626; United Nations Act 2001; TSFA 2002. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to rescreen existing customers after sanctions list update. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 325 | Financial Crime | Failure to screen beneficial owners, controllers and authorised signatories for sanctions | Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to screen beneficial owners, controllers and authorised signatories for sanctions under MAS Notice 626; United Nations Act 2001; TSFA 2002. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to screen beneficial owners, controllers and authorised signatories for sanctions. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 326 | Financial Crime | Failure to screen payment messages, trade documents or vessel names for sanctions risk | United Nations Act 2001, s2; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to screen payment messages, trade documents or vessel names for sanctions risk under MAS Notice 626; United Nations Act 2001; sanctions regulations. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to screen payment messages, trade documents or vessel names for sanctions risk. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 327 | Financial Crime | Failure to freeze assets after confirmed sanctioned person match | Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2 | Covers the legal or regulatory requirement relevant to failure to freeze assets after confirmed sanctioned person match under United Nations Act 2001; TSFA 2002; MAS sanctions notices and directions. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to freeze assets after confirmed sanctioned person match. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 328 | Financial Crime | Processing prohibited payment for sanctioned person, entity, vessel or country | Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2 | Covers the legal or regulatory requirement relevant to processing prohibited payment for sanctioned person, entity, vessel or country under United Nations Act 2001; TSFA 2002; MAS sanctions regulations. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence,transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in processing prohibited payment for sanctioned person, entity, vessel or country. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, tradefinance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 329 | Financial Crime | Failure to report frozen assets or attempted sanctions transaction to authority | Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2 | Covers the legal or regulatory requirement relevant to failure to report frozen assets or attempted sanctions transaction to authority under United Nations Act 2001; TSFA 2002; MAS sanctions requirements. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to report frozen assets or attempted sanctions transaction to authority. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 330 | Financial Crime | Failure to manage proliferation financing risk in trade finance transaction | United Nations Act 2001, s2; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to manage proliferation financing risk in trade finance transaction under MAS Notice 626; United Nations Act 2001; sanctions regulations. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to manage proliferation financing risk in trade finance transaction. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 331 | Financial Crime | Failure to apply travel rule information controls for wire transfers | MAS Notice 626; MAS wire transfer requirements; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to apply travel rule information controls for wire transfers under MAS Notice 626; MAS wire transfer requirements. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to apply travel rule information controls for wire transfers. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 332 | Financial Crime | Failure to include accurate originator information in outgoing wire transfer | MAS Notice 626; MAS wire transfer requirements; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to include accurate originator information in outgoing wire transfer under MAS Notice 626; MAS wire transfer requirements. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to include accurate originator information in outgoing wire transfer. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 333 | Financial Crime | Failure to include accurate beneficiary information in incoming or intermediary wire transfer | MAS Notice 626; MAS wire transfer requirements; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to include accurate beneficiary information in incoming or intermediary wire transfer under MAS Notice 626; MAS wire transfer requirements. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to include accurate beneficiary information in incoming or intermediary wire transfer. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 334 | Financial Crime | Failure to reject or suspend payment with missing mandatory wire transfer information | MAS Notice 626; MAS wire transfer requirements; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to reject or suspend payment with missing mandatory wire transfer information under MAS Notice 626; MAS wire transfer requirements. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to reject or suspend payment with missing mandatory wire transfer information. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 335 | Financial Crime | Failure to manage nested correspondent banking relationship risk | MAS Notice 626; MAS correspondent banking requirements; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to manage nested correspondent banking relationship risk under MAS Notice 626; MAS correspondent banking requirements. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to manage nested correspondent banking relationship risk. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 336 | Financial Crime | Failure to prohibit shell bank relationship or payable-through account risk | MAS Notice 626; MAS correspondent banking requirements; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to prohibit shell bank relationship or payable-through account risk under MAS Notice 626; MAS correspondent banking requirements. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to prohibit shell bank relationship or payable-through account risk. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 337 | Financial Crime | Failure to understand respondent bank AML/CFT controls before relationship approval | MAS Notice 626; MAS correspondent banking requirements; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to understand respondent bank aml/cft controls before relationship approval under MAS Notice 626; MAS correspondent banking requirements. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to understand respondent bank aml/cft controls before relationship approval. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 338 | Financial Crime | Failure to monitor trade finance red flags involving over-invoicing or under-invoicing | CDSA 1992, ss39, 50-54, 57; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to monitor trade finance red flags involving over-invoicing or under-invoicing under MAS Notice 626; CDSA 1992. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to monitor trade finance red flags involving over-invoicing or under-invoicing. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 339 | Financial Crime | Failure to monitor round-tripping, carousel transactions or circular fund flows | CDSA 1992, ss39, 50-54, 57; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to monitor round-tripping, carousel transactions or circular fund flows under MAS Notice 626; CDSA 1992. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to monitor round-tripping, carousel transactions or circular fund flows. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 340 | Financial Crime | Failure to monitor rapid in-and-out movement of funds through newly opened account | CDSA 1992, ss39, 50-54, 57; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to monitor rapid in-and-out movement of funds through newly opened account under MAS Notice 626; CDSA 1992. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to monitor rapid in-and-out movement of funds through newly opened account. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 341 | Financial Crime | Failure to identify mule account typology in retail banking operations | CDSA 1992, ss50-54, 57; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to identify mule account typology in retail banking operations under MAS Notice 626; CDSA 1992; Penal Code where cheating or facilitation occurs. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to identify mule account typology in retail banking operations. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 342 | Financial Crime | Failure to detect scam proceeds entering account after police or industry alert | CDSA 1992, ss39, 57; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to detect scam proceeds entering account after police or industry alert under MAS Notice 626; CDSA 1992; MAS anti-scam guidance. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to detect scam proceeds entering account after police or industry alert. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 343 | Financial Crime | Failure to act on adverse media or law enforcement request linked to financial crime | CDSA 1992, s57; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to act on adverse media or law enforcement request linked to financial crime under MAS Notice 626; CDSA 1992; MAS supervisory requirements. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to act on adverse media or law enforcement request linked to financial crime. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 344 | Financial Crime | Failure to file suspicious transaction report after reasonable grounds for suspicion arise | CDSA 1992, ss39, 57; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to file suspicious transaction report after reasonable grounds for suspicion arise under CDSA 1992; MAS Notice 626. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to file suspicious transaction report after reasonable grounds for suspicion arise. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 345 | Financial Crime | Late filing of suspicious transaction report due to inadequate escalation process | CDSA 1992, ss39, 57; MAS Notice 626 | Covers the legal or regulatory requirement relevant to late filing of suspicious transaction report due to inadequate escalation process under CDSA 1992; MAS Notice 626. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in late filing of suspicious transaction report due to inadequate escalation process. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 346 | Forgery Records | Filing materially incomplete or misleading suspicious transaction report | Penal Code 1871, ss182, 199 and 477A;CDSA 1992, ss39, 57 | Covers the legal or regulatory requirement relevant to filing materially incomplete or misleading suspicious transaction report under CDSA 1992; Penal Code 1871, ss182, 199 and 477A. It addresses false documents, altered records, inaccurate returns, backdated approvals, manipulated evidence or dishonest reliance on records as genuine. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in filing materially incomplete or misleading suspicious transaction report. It applies to account files, KYC records, returns, approvals, credit papers, reconciliations, audit logs, payment instructions, board papers, correspondence, customer statements, regulatory submissions and electronic records used in banking decisions. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 347 | Financial Crime | Tipping off customer, relationship manager or third party about suspicious transaction report | CDSA 1992, s57; MAS Notice 626 | Covers the legal or regulatory requirement relevant to tipping off customer, relationship manager or third party about suspicious transaction report under CDSA 1992; MAS Notice 626. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in tipping off customer, relationship manager or third party about suspicious transaction report. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 348 | Financial Crime | Assisting customer to restructure transaction to avoid AML/CFT threshold or controls | CDSA 1992, ss39, 57; MAS Notice 626 | Covers the legal or regulatory requirement relevant to assisting customer to restructure transaction to avoid aml/cft threshold or controls under CDSA 1992; MAS Notice 626; Penal Code abetment provisions. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in assisting customer to restructure transaction to avoid aml/cft threshold or controls. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 349 | Governance Controls | Failure to maintain independent AML/CFT compliance function with adequate authority | MAS Notice 626; MAS AML/CFT governance requirements; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to maintain independent aml/cft compliance function with adequate authority under MAS Notice 626; MAS AML/CFT governance requirements. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain independent aml/cft compliance function with adequate authority. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 350 | Governance Controls | Failure to conduct periodic independent AML/CFT audit or quality assurance review | MAS Notice 626; MAS AML/CFT governance requirements; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to conduct periodic independent aml/cft audit or quality assurance review under MAS Notice 626; MAS AML/CFT governance requirements. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to conduct periodic independent aml/cft audit or quality assurance review. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 351 | Regulatory Duties | Failure to remediate AML/CFT audit finding within approved timeline | MAS Notice 626; MAS supervisory directions; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to remediate aml/cft audit finding within approved timeline under MAS Notice 626; MAS supervisory directions. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to remediate aml/cft audit finding within approved timeline. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 352 | Regulatory Duties | Failure to maintain AML/CFT training records for frontline and operations staff | MAS Notice 626; MAS AML/CFT governance requirements; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to maintain aml/cft training records for frontline and operations staff under MAS Notice 626; MAS AML/CFT governance requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain aml/cft training records for frontline and operations staff. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 353 | Financial Crime | Failure to manage AML/CFT risk of outsourced onboarding or screening vendor | MAS Notice 626; MAS outsourcing guidelines; MAS Notice 626; MAS outsourcing guidelines | Covers the legal or regulatory requirement relevant to failure to manage aml/cft risk of outsourced onboarding or screening vendor under MAS Notice 626; MAS outsourcing guidelines. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to manage aml/cft risk of outsourced onboarding or screening vendor. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 354 | Financial Crime | Failure to maintain group-wide AML/CFT standards across overseas branches and subsidiaries | MAS Notice 626; MAS group-wide controls requirements; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to maintain group-wide aml/cft standards across overseas branches and subsidiaries under MAS Notice 626; MAS group-wide controls requirements. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain group-wide aml/cft standards across overseas branches and subsidiaries. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 355 | Financial Crime | Failure to share relevant AML/CFT information within banking group where required and lawful | Banking Act 1970, ss47, 47Aand Third Schedule; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to share relevant aml/cft information within banking group whererequired and lawful under MAS Notice 626; Banking Act customer information provisions. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary isinvolved in failure to share relevant aml/cft information within banking group where required and lawful. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | Bank secrecy and customer-information breaches may result in criminal penalties under the Banking Act, MAS enforcement action,confidentiality restrictions, civil liability, customer remediation, disciplinary action and possible fitness-and-propriety consequences for responsible persons. |
| 356 | Financial Crime | Failure to manage digital onboarding AML/CFT risks and non-face-to-face verification controls | MAS Notice 626; MAS digital onboarding guidance; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to manage digital onboarding aml/cft risks and non-face-to-face verification controls under MAS Notice 626; MAS digital onboarding guidance. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to manage digital onboarding aml/cft risks and non-face-to-face verification controls. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 357 | Financial Crime | Failure to maintain transaction monitoring scenarios for emerging scam or fraud typologies | MAS Notice 626; MAS anti-scam and transaction monitoring expectations; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to maintain transaction monitoring scenarios for emerging scam or fraud typologies under MAS Notice 626; MAS anti-scam and transaction monitoring expectations. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain transaction monitoring scenarios for emerging scam or fraud typologies. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 358 | Evidence Obstruction | Disabling or suppressing transaction monitoring alerts without documented rationale | Penal Code 1871, ss204 and 477A; MAS Notice 626 | Covers the legal or regulatory requirement relevant to disabling or suppressing transaction monitoring alerts without documented rationale under MAS Notice 626; Penal Code 1871, ss204 and 477A. It addresses concealment, destruction, withholding, delay, misleading statements or interference that frustrates lawful audit, supervision, investigation or enforcement. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in disabling or suppressing transaction monitoring alerts without documented rationale. It applies during MAS inspections, internal investigations, audit reviews, police inquiries, customer complaints, disciplinary processes, incident response, document production, CCTV retrieval, audit-log preservation and whistleblowing investigations. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 359 | Forgery Records | Backdating AML approval, customer review or sanctions screening decision | Penal Code 1871, s477A;United Nations Act 2001, s2; MAS Notice 626 | Covers the legal or regulatory requirement relevant to backdating aml approval, customer review or sanctions screening decision under Penal Code 1871, s477A; MAS Notice 626. It addresses false documents, altered records, inaccurate returns, backdated approvals, manipulated evidence or dishonest reliance on records as genuine. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in backdating aml approval, customer review or sanctions screening decision. It applies to account files, KYC records, returns, approvals, credit papers, reconciliations, audit logs, payment instructions, board papers, correspondence, customer statements, regulatory submissions and electronic records used in banking decisions. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 360 | Abetment Attempts | Abetment or conspiracy to help customer evade AML/CFT, sanctions or STR controls | Penal Code 1871, ss107-109 and 120A-120B;CDSA 1992, ss39, 57;Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2 | Covers the legal or regulatory requirement relevant to abetment or conspiracy to help customer evade aml/cft, sanctions or str controls under Penal Code 1871, ss107-109 and 120A-120B; CDSA 1992; TSFA 2002. It addresses attempts, conspiracy, facilitation, assistance, coordination and planning connected to the principal banking, regulatory or criminal offence. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in abetment or conspiracy to help customer evade aml/cft, sanctions or str controls. It applies where employees, customers, vendors, intermediaries, mule account holders, representatives, agents or outsiders plan, facilitate, assist, coordinate or attempt another banking-related offence. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 361 | Cyber Technology | Failure to identify critical banking systems for technology risk controls | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS Technology Risk Management requirements | Covers the legal or regulatory requirement relevant to failure to identify critical banking systems for technology risk controls under FSMA 2022; MAS Technology Risk Management requirements. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to identify critical banking systems for technology risk controls. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 362 | Cyber Technology | Failure to classify system criticality for core banking, payments or internet banking platform | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS Technology Risk Management requirements | Covers the legal or regulatory requirement relevant to failure to classify system criticality for core banking, payments or internet banking platform under FSMA 2022; MAS Technology Risk Management guidelines. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to classify system criticality for core banking, payments or internet banking platform. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 363 | Cyber Technology | Failure to implement multi-factor authentication for high-risk administrative access | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS Technology Risk Management requirements | Covers the legal or regulatory requirement relevant to failure to implement multi-factor authentication for high-risk administrative access under FSMA 2022; MAS Technology Risk Management requirements. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to implement multi-factor authentication for high-risk administrative access. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 364 | Cyber Technology | Failure to review privileged access rights periodically | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS Technology Risk Management requirements | Covers the legal or regulatory requirement relevant to failure to review privileged access rights periodically under FSMA 2022; MAS Technology Risk Management requirements. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to review privileged access rights periodically. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 365 | Cyber Technology | Failure to segregate production, development and testing environments | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS Technology Risk Management requirements | Covers the legal or regulatory requirement relevant to failure to segregate production, development and testing environments under FSMA 2022; MAS Technology Risk Management guidelines. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to segregate production, development and testing environments. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 366 | Cyber Technology | Failure to maintain secure change management over banking applications | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS Technology Risk Management requirements | Covers the legal or regulatory requirement relevant to failure to maintain secure change management over banking applications under FSMA 2022; MAS Technology Risk Management guidelines. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain secure change management over banking applications. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 367 | Cyber Technology | Deploying unauthorised code change to production banking system | Financial Services and Markets Act 2022, ss29, 169-170, 176;Computer Misuse Act 1993, ss3-4, 11; MAS Technology Risk Management requirements | Covers the legal or regulatory requirement relevant to deploying unauthorised code change to production banking system under Computer Misuse Act 1993; FSMA 2022; MAS TRM requirements. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in deploying unauthorised code change to production banking system. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | Computer Misuse Act offences may attract fines and imprisonment, with enhanced penalties for unauthorised modification, further offences, serious harm, protected systems, repeated conduct or large-scale compromise. MAS technology-risk action and disciplinary consequences may also follow. |
| 368 | Cyber Technology | Failure to maintain vulnerability assessment and penetration testing programme | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS Technology Risk Management requirements | Covers the legal or regulatory requirement relevant to failure to maintain vulnerability assessment and penetration testing programme under FSMA 2022; MAS Technology Risk Management guidelines. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain vulnerability assessment and penetration testing programme. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 369 | Cyber Technology | Failure to remediate critical vulnerability affecting customer-facing banking platform | Financial Services and Markets Act 2022, ss3, 29, 169-170, 176;Computer Misuse Act 1993, ss3-4, 11 | Covers the legal or regulatory requirement relevant to failure to remediate critical vulnerability affecting customer-facing banking platform under FSMA 2022; Computer Misuse Act where exploitation occurs. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to remediate critical vulnerability affecting customer-facing banking platform. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | Computer Misuse Act offences may attract fines and imprisonment, with enhanced penalties for unauthorised modification, further offences, serious harm, protected systems, repeated conduct or large-scale compromise. MAS technology-risk action and disciplinary consequences may also follow. |
| 370 | Cyber Technology | Failure to monitor security logs for core banking, SWIFT, ATM or payment systems | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS Technology Risk Management requirements | Covers the legal or regulatory requirement relevant to failure to monitor security logs for core banking, swift, atm or payment systems under FSMA 2022; MAS Technology Risk Management requirements. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to monitor security logs for core banking, swift, atm or payment systems. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 371 | Cyber Technology | Failure to maintain security operations centre escalation for cyber incident | Financial Services and Markets Act 2022, ss29, 169-170, 176 | Covers the legal or regulatory requirement relevant to failure to maintain security operations centre escalation for cyber incident under FSMA 2022; MAS cyber incident reporting requirements. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain security operations centre escalation for cyber incident. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 372 | Regulatory Duties | Failure to notify MAS of material technology incident within required timeframe | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS incident reporting expectations | Covers the legal or regulatory requirement relevant to failure to notify mas of material technology incident within required timeframe under FSMA 2022; MAS incident notification requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to notify mas of material technology incident within required timeframe. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 373 | Regulatory Duties | Failure to notify affected customers of material digital banking service disruption where required | Financial Services and Markets Act 2022, ss29, 169-170, 176 | Covers the legal or regulatory requirement relevant to failure to notify affected customers of material digital banking service disruption where required under FSMA 2022; MAS operational resilience and incident management expectations. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to notify affected customers of material digital banking service disruption where required. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 374 | Governance Controls | Failure to maintain root-cause analysis for material system outage | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS Technology Risk Management requirements | Covers the legal or regulatory requirement relevant to failure to maintain root-cause analysis for material system outage under FSMA 2022; MAS Technology Risk Management guidelines. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain root-cause analysis for material system outage. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 375 | Cyber Technology | Failure to test business continuity and disaster recovery for critical banking service | Financial Services and Markets Act 2022, ss3, 29, 169-170, 176 | Covers the legal or regulatory requirement relevant to failure to test business continuity and disaster recovery for critical banking service under FSMA 2022; MAS business continuity and TRM requirements. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to test business continuity and disaster recovery for critical banking service. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 376 | Cyber Technology | Failure to meet recovery time objective or recovery point objective for critical system | Financial Services and Markets Act 2022, ss29, 169-170, 176 | Covers the legal or regulatory requirement relevant to failure to meet recovery time objective or recovery point objective for critical system under FSMA 2022; MAS operational resilience requirements. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to meet recovery time objective or recovery point objective for critical system. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 377 | Cyber Technology | Failure to manage cyber risk of cloud service provider hosting banking data or systems | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS outsourcing guidelines | Covers the legal or regulatory requirement relevant to failure to manage cyber risk of cloud service provider hosting banking data or systems under FSMA 2022; MAS outsourcing and TRM requirements. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to manage cyber risk of cloud service provider hosting banking data or systems. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 378 | Governance Controls | Failure to maintain exit strategy for material cloud or technology outsourcing arrangement | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS outsourcing guidelines | Covers the legal or regulatory requirement relevant to failure to maintain exit strategy for material cloud or technology outsourcing arrangement under FSMA 2022; MAS outsourcing guidelines. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain exit strategy for material cloud or technology outsourcing arrangement. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 379 | Governance Controls | Failure to conduct due diligence on technology vendor before onboarding | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS outsourcing guidelines | Covers the legal or regulatory requirement relevant to failure to conduct due diligence on technology vendor before onboarding under FSMA 2022; MAS outsourcing and TRM requirements. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to conduct due diligence on technology vendor before onboarding. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 380 | Governance Controls | Failure to ensure audit and access rights over material outsourced technology provider | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS outsourcing guidelines | Covers the legal or regulatory requirement relevant to failure to ensure audit and access rights over material outsourced technology provider under FSMA 2022; MAS outsourcing guidelines. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to ensure audit and access rights over material outsourced technology provider. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 381 | Data Protection | Failure to encrypt sensitive customer data in storage or transmission where required | Financial Services and Markets Act 2022, ss29, 169-170, 176;PDPA 2012, ss11-12, 13-26D, 48D-48J; MAS Technology Risk Management requirements | Covers the legal or regulatory requirement relevant to failure to encrypt sensitive customer data in storage or transmission where required under PDPA 2012; FSMA 2022; MAS Technology Risk Management requirements. It addresses customer confidentiality, personal data handling, disclosure limitations, protection safeguards, retention, transfer, access controls and breach management. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to encrypt sensitive customer data in storage or transmission where required. It applies to customer information, personal data, KYC documents, call recordings, statements, transaction records, employee data, outsourcing arrangements, overseas transfers, AI tools, digital channels and breach response. | PDPA consequences may include PDPC directions, financial penalties, corrective orders, breach notification requirements and individual criminal liability for unauthorised disclosure, improper use or re-identification. Banking secrecy, civil claims and disciplinary action may also apply. |
| 382 | Cyber Technology | Failure to secure API used for digital banking, open banking or partner integration | Financial Services and Markets Act 2022, ss3, 29, 169-170, 176;Computer Misuse Act 1993, ss3-4, 11 | Covers the legal or regulatory requirement relevant to failure to secure api used for digital banking, open banking or partner integration under FSMA 2022; Computer Misuse Act 1993where misuse occurs. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to secure api used for digital banking, open banking orpartner integration. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | Computer Misuse Act offences may attract fines and imprisonment, with enhanced penalties for unauthorised modification, further offences, serious harm, protected systems, repeated conduct or large-scale compromise. MAS technology-risk action and disciplinary consequences may also follow. |
| 383 | Cyber Technology | Failure to protect SMS, push notification or in-app authentication channel against compromise | Financial Services and Markets Act 2022, ss29, 169-170, 176 | Covers the legal or regulatory requirement relevant to failure to protect sms, push notification or in-app authentication channel against compromise under FSMA 2022; MAS digital banking security expectations. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to protect sms, push notification or in-app authentication channel against compromise. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 384 | Cyber Technology | Failure to implement transaction signing or high-risk payment confirmation control | Financial Services and Markets Act 2022, ss3, 29, 169-170, 176 | Covers the legal or regulatory requirement relevant to failure to implement transaction signing or high-risk payment confirmation control under FSMA 2022; MAS anti-scam and digital banking security expectations. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to implement transaction signing or high-risk payment confirmation control. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 385 | Cyber Technology | Failure to detect abnormal login, device-binding or account-takeover activity | Financial Services and Markets Act 2022, ss3, 29, 169-170, 176 | Covers the legal or regulatory requirement relevant to failure to detect abnormal login, device-binding or account-takeover activity under FSMA 2022; MAS fraud surveillance expectations. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to detect abnormal login, device-binding or account-takeover activity. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 386 | Regulatory Duties | Failure to freeze or restrict compromised digital banking access after confirmed fraud report | Financial Services and Markets Act 2022, ss3, 29, 169-170, 176 | Covers the legal or regulatory requirement relevant to failure to freeze or restrict compromised digital banking access after confirmed fraud report under FSMA 2022; MAS anti-scam and operational risk requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to freeze or restrict compromised digital banking access after confirmed fraud report. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 387 | Cyber Technology | Unauthorised use of customer credentials by bank employee or contractor | Penal Code 1871, ss420 and 424A;Computer Misuse Act 1993, ss3-4, 8, 8B, 11 | Covers the legal or regulatory requirement relevant to unauthorised use of customer credentials by bank employee or contractor under Computer Misuse Act 1993; Penal Code 1871, ss420 and 424A. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in unauthorised use of customer credentials by bank employee or contractor. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | Computer Misuse Act offences may attract fines and imprisonment, with enhanced penalties for unauthorised modification, further offences, serious harm, protected systems, repeated conduct or large-scale compromise. MAS technology-risk action and disciplinary consequences may also follow. |
| 388 | Cyber Technology | Creation of unauthorised staff account, service account or privileged account | Financial Services and Markets Act 2022, ss3, 29, 169-170, 176;Computer Misuse Act 1993, ss3-4, 11 | Covers the legal or regulatory requirement relevant to creation of unauthorised staff account, service account or privileged account under Computer Misuse Act 1993; FSMA 2022. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in creation of unauthorised staff account, service account or privileged account. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | Computer Misuse Act offences may attract fines and imprisonment, with enhanced penalties for unauthorised modification, further offences, serious harm, protected systems, repeated conduct or large-scale compromise. MAS technology-risk action and disciplinary consequences may also follow. |
| 389 | Cyber Technology | Failure to disable service accounts after system migration or vendor exit | Financial Services and Markets Act 2022, ss29, 169-170, 176;PDPA 2012, ss24, 26, 26B-26D, 48I-48J; MAS Technology Risk Management requirements | Covers the legal or regulatory requirement relevant to failure to disable service accounts after system migration or vendor exit under FSMA 2022; PDPA 2012; MAS TRM requirements. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to disable service accounts after system migration or vendor exit. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | PDPA consequences may include PDPC directions, financial penalties, corrective orders, breach notification requirements and individual criminal liability for unauthorised disclosure, improper use or re-identification. Banking secrecy, civil claims and disciplinary action may also apply. |
| 390 | Cyber Technology | Failure to maintain tamper-resistant audit logs for digital banking transactions | Financial Services and Markets Act 2022, ss3, 29, 169-170, 176;Computer Misuse Act 1993, ss5-7, 11 | Covers the legal or regulatory requirement relevant to failure to maintain tamper-resistant audit logs for digital banking transactions under FSMA 2022; Computer Misuse Act 1993; Penal Code s477A. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain tamper-resistant audit logs for digital banking transactions. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | Computer Misuse Act offences may attract fines and imprisonment, with enhanced penalties for unauthorised modification, further offences, serious harm, protected systems, repeated conduct or large-scale compromise. MAS technology-risk action and disciplinary consequences may also follow. |
| 391 | Evidence Obstruction | Deletion or suppression of cyber incident logs before investigation | Penal Code 1871, ss204 and 477A;Computer Misuse Act 1993, ss5-7, 11 | Covers the legal or regulatory requirement relevant to deletion or suppression of cyber incident logs before investigation under Penal Code 1871, ss204 and 477A; Computer Misuse Act 1993. It addresses concealment, destruction, withholding, delay, misleading statements or interference that frustrates lawful audit, supervision, investigation or enforcement. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in deletion or suppression of cyber incident logs before investigation. It applies during MAS inspections, internal investigations, audit reviews, police inquiries, customer complaints, disciplinary processes, incident response, document production, CCTV retrieval, audit-log preservation and whistleblowing investigations. | Computer Misuse Act offences may attract fines and imprisonment, with enhanced penalties for unauthorised modification, further offences, serious harm, protected systems, repeated conduct or large-scale compromise. MAS technology-risk action and disciplinary consequences may also follow. |
| 392 | Data Protection | Failure to manage data-loss prevention controls for email, removable media or cloud tools | Financial Services and Markets Act 2022, ss29, 169-170, 176;PDPA 2012, ss24, 26, 26B-26D, 48I-48J; MAS Technology Risk Management requirements | Covers the legal or regulatory requirement relevant to failure to manage data-loss prevention controls for email, removable media or cloud tools under PDPA 2012; FSMA 2022; MAS TRM requirements. It addresses customer confidentiality, personal data handling, disclosure limitations, protection safeguards, retention, transfer, access controls and breach management. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to manage data-loss prevention controls for email, removable media or cloud tools. It applies to customer information, personal data, KYC documents, call recordings, statements, transaction records, employee data, outsourcing arrangements, overseas transfers, AI tools, digital channels and breach response. | PDPA consequences may include PDPC directions, financial penalties, corrective orders, breach notification requirements and individual criminal liability for unauthorised disclosure, improper use or re-identification. Banking secrecy, civil claims and disciplinary action may also apply. |
| 393 | Data Protection | Unauthorised upload of customer banking data to generative AI, external chatbot or public cloud tool | Banking Act 1970, ss47, 47Aand Third Schedule;Financial Services and Markets Act 2022, ss29, 169-170, 176;PDPA 2012, ss24, 26, 26B-26D, 48I-48J | Covers the legal or regulatory requirement relevant to unauthorised upload of customer banking data to generative ai, external chatbot or public cloud tool under PDPA 2012; Banking Act 1970 customer information provisions; FSMA 2022. It addresses customer confidentiality, personal data handling, disclosure limitations, protection safeguards, retention, transfer, access controls and breach management. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in unauthorised upload of customer banking data to generative ai, external chatbot or public cloud tool. It applies to customer information, personal data, KYC documents, call recordings, statements, transaction records, employee data, outsourcing arrangements, overseas transfers, AI tools, digital channels and breach response. | PDPA consequences may include PDPC directions, financial penalties, corrective orders, breach notification requirements and individual criminal liability for unauthorised disclosure, improper use or re-identification. Banking secrecy, civil claims and disciplinary action may also apply. |
| 394 | Cyber Technology | Failure to perform secure software development review before release of banking application | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS Technology Risk Management requirements | Covers the legal or regulatory requirement relevant to failure to perform secure software development review before release of banking application under FSMA 2022; MAS Technology Risk Management guidelines. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to perform secure software development review before release of banking application. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 395 | Cyber Technology | Failure to scan open-source libraries or third-party code for known vulnerabilities | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS Technology Risk Management requirements | Covers the legal or regulatory requirement relevant to failure to scan open-source libraries or third-party code for known vulnerabilities under FSMA 2022; MAS Technology Risk Management guidelines. It addresses unauthorised access, digital banking controls, system resilience, cyber security,technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to scan open-source libraries or third-party code for known vulnerabilities. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, changemanagement, logs, vendors, incident response and technology-risk governance. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 396 | Cyber Technology | Failure to manage ATM malware, jackpotting or terminal compromise risk | Financial Services and Markets Act 2022, ss3, 29, 169-170, 176;Computer Misuse Act 1993, ss5-7, 11; MAS Technology Risk Management requirements | Covers the legal or regulatory requirement relevant to failure to manage atm malware, jackpotting or terminal compromise risk under Computer Misuse Act 1993; FSMA 2022; MAS TRM requirements. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to manage atm malware, jackpotting or terminal compromise risk. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | Computer Misuse Act offences may attract fines and imprisonment, with enhanced penalties for unauthorised modification, further offences, serious harm, protected systems, repeated conduct or large-scale compromise. MAS technology-risk action and disciplinary consequences may also follow. |
| 397 | Cyber Technology | Failure to protect SWIFT environment from unauthorised payment-message creation | Financial Services and Markets Act 2022, ss3, 29, 169-170, 176;Computer Misuse Act 1993, ss3-4, 11; MAS Technology Risk Management requirements | Covers the legal or regulatory requirement relevant to failure to protect swift environment from unauthorised payment-message creation under Computer Misuse Act 1993; FSMA 2022; MAS TRM requirements. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to protect swift environment from unauthorised payment-message creation. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | Computer Misuse Act offences may attract fines and imprisonment, with enhanced penalties for unauthorised modification, further offences, serious harm, protected systems, repeated conduct or large-scale compromise. MAS technology-risk action and disciplinary consequences may also follow. |
| 398 | Governance Controls | Failure to reconcile payment messages after SWIFT, FAST or settlement system incident | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS payment services requirements | Covers the legal or regulatory requirement relevant to failure to reconcile payment messages after swift, fast or settlement system incident under FSMA 2022; MAS payment and operational risk requirements. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to reconcile payment messages after swift, fast or settlement system incident. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 399 | Cyber Technology | Failure to manage fraud rules for card-not-present, e-commerce or tokenised payment transactions | Financial Services and Markets Act 2022, ss3, 29, 169-170, 176;Payment Services Act 2019, ss5-7, 23-26, 51 | Covers the legal or regulatory requirement relevant to failure to manage fraud rules for card-not-present, e-commerce or tokenised payment transactions under Payment Services Act 2019; FSMA 2022; MAS anti-fraud expectations. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to manage fraud rules for card-not-present, e-commerce or tokenised payment transactions. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 400 | Regulatory Duties | Failure to report cybercrime evidence to law enforcement where required by internal or regulatory process | Financial Services and Markets Act 2022, ss29, 169-170, 176;Computer Misuse Act 1993, ss3-4, 11; MAS incident reporting expectations | Covers the legal or regulatory requirement relevant to failure to report cybercrime evidence to law enforcement where required by internal or regulatory process under Computer Misuse Act 1993; FSMA 2022; MAS incident expectations. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to report cybercrime evidence to law enforcement where required by internal or regulatory process. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Computer Misuse Act offences may attract fines and imprisonment, with enhanced penalties for unauthorised modification, further offences, serious harm, protected systems, repeated conduct or large-scale compromise. MAS technology-risk action and disciplinary consequences may also follow. |
| 401 | Governance Controls | Failure to maintain cyber insurance, incident playbooks or crisis communication plan where required by governance framework | Financial Services and Markets Act 2022, ss29, 169-170, 176 | Covers the legal or regulatory requirement relevant to failure to maintain cyber insurance, incident playbooks or crisis communication plan where required by governance framework under FSMA 2022; MAS operational resilience guidelines. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain cyber insurance, incident playbooks or crisis communication plan where required by governance framework. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 402 | Governance Controls | Inadequate board oversight of technology risk, cyber resilience or major outage remediation | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS Technology Risk Management requirements | Covers the legal or regulatory requirement relevant to inadequate board oversight of technology risk, cyber resilience or major outage remediation under FSMA 2022; MAS Technology Risk Management guidelines. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in inadequate board oversight of technology risk, cyber resilience or major outage remediation. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 403 | Governance Controls | Failure to conduct independent post-implementation review for major banking system change | Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS Technology Risk Management requirements | Covers the legal or regulatory requirement relevant to failure to conduct independent post-implementation review for major banking system change under FSMA 2022; MAS Technology Risk Management guidelines. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to conduct independent post-implementation review for major banking system change. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 404 | Safety Security | Failure to maintain physical security of data centre hosting banking systems | Financial Services and Markets Act 2022, ss29, 169-170, 176;Workplace Safety and Health Act 2006, ss11-12, 14-15; MAS Technology Risk Management requirements | Covers the legal or regulatory requirement relevant to failure to maintain physical security of data centre hosting banking systems under FSMA 2022; WSH Act 2006; MAS TRM physical and environmental controls. It addresses physical security, workplace safety, fire safety, cash movement, emergency response and protection of staff, customers, vendors and visitors. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain physical security of data centre hosting banking systems. It applies to branches, data centres, ATMs, vaults, offices, cash movement, contractors, customer queues, emergency procedures, premises security, fire safety, workplace safety and incident reporting. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 405 | Data Protection | Failure to secure backup media, backup vault or disaster recovery site containing customer data | Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71;Financial Services and Markets Act 2022, ss3, 29, 169-170, 176;PDPA 2012, ss11-12, 13-26D, 48D-48J | Covers the legal or regulatory requirement relevant to failure to secure backup media, backup vault or disaster recovery site containing customer data under PDPA 2012; Banking Act 1970; FSMA 2022. It addresses customer confidentiality, personal data handling, disclosure limitations, protection safeguards, retention, transfer, access controls and breach management. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to secure backup media, backup vault or disaster recovery site containing customer data. It applies to customer information, personal data, KYC documents, call recordings, statements, transaction records, employee data, outsourcing arrangements, overseas transfers, AI tools, digital channels and breach response. | PDPA consequences may include PDPC directions, financial penalties, corrective orders, breach notification requirements and individual criminal liability for unauthorised disclosure, improper use or re-identification. Banking secrecy, civil claims and disciplinary action may also apply. |
| 406 | Cyber Technology | Failure to monitor and control robotic process automation bots in banking operations | Financial Services and Markets Act 2022, ss3, 29, 169-170, 176; MAS Technology Risk Management requirements | Covers the legal or regulatory requirement relevant to failure to monitor and control robotic process automation bots in banking operations under FSMA 2022; MAS TRM and operational risk requirements. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to monitor and control robotic process automation bots in banking operations. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 407 | Governance Controls | Failure to maintain model risk controls for AI-driven credit, fraud or customer decisioning system | Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71;Financial Services and Markets Act 2022, ss29, 169-170, 176 | Covers the legal or regulatory requirement relevant to failure to maintain model risk controls for ai-driven credit, fraud or customer decisioning system under Banking Act 1970; FSMA 2022; MAS model risk and fairness expectations. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain model risk controls for ai-driven credit, fraud or customer decisioning system. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 408 | Professional Conduct | Using unvalidated AI model causing unfair, inaccurate or undisclosed banking decision | Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71;Financial Services and Markets Act 2022, ss3, 29, 169-170, 176;PDPA 2012, ss11-12, 13-26D, 48D-48J; MAS fair dealing requirements | Covers the legal or regulatory requirement relevant to using unvalidated ai model causing unfair, inaccurate or undisclosed banking decision under Banking Act 1970; FSMA 2022; PDPA 2012; MAS fair dealing expectations. It addresses fair dealing, customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in using unvalidated ai model causing unfair, inaccurate or undisclosed banking decision. It applies to relationship managers, advisers, traders, product specialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | PDPA consequences may include PDPC directions, financial penalties, corrective orders, breach notification requirements and individual criminal liability for unauthorised disclosure, improper use or re-identification. Banking secrecy, civil claims and disciplinary action may also apply. |
| 409 | Data Protection | Failure to maintain adequate controls over customer biometric authentication data | Financial Services and Markets Act 2022, ss29, 169-170, 176;PDPA 2012, ss11-12, 13-26D, 48D-48J | Covers the legal or regulatory requirement relevant to failure to maintain adequate controls over customer biometric authentication data under PDPA 2012; FSMA 2022; MAS digital banking security expectations. It addresses customer confidentiality, personal data handling, disclosure limitations, protection safeguards, retention, transfer, access controls and breach management. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain adequate controls over customer biometric authentication data. It applies to customer information, personal data, KYC documents, call recordings, statements, transaction records, employee data, outsourcing arrangements, overseas transfers, AI tools, digital channels and breach response. | PDPA consequences may include PDPC directions, financial penalties, corrective orders, breach notification requirements and individual criminal liability for unauthorised disclosure, improper use or re-identification. Banking secrecy, civil claims and disciplinary action may also apply. |
| 410 | Abetment Attempts | Abetment or conspiracy in cyber compromise, credential misuse or digital banking fraud | Penal Code 1871, ss107-109 and 120A-120B;Computer Misuse Act 1993, ss3-4, 8, 8B, 11 | Covers the legal or regulatory requirement relevant to abetment or conspiracy in cyber compromise, credential misuse or digital banking fraud under Penal Code 1871, ss107-109 and 120A-120B; Computer Misuse Act 1993. It addresses attempts, conspiracy, facilitation, assistance, coordination and planning connected to the principal banking, regulatory or criminal offence. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in abetment or conspiracy in cyber compromise, credential misuse or digital banking fraud. It applies where employees, customers, vendors, intermediaries, mule account holders, representatives, agents or outsiders plan, facilitate, assist, coordinate or attempt another banking-related offence. | Computer Misuse Act offences may attract fines and imprisonment, with enhanced penalties for unauthorised modification, further offences, serious harm, protected systems, repeated conduct or large-scale compromise. MAS technology-risk action and disciplinary consequences may also follow. |
| 411 | Licensing Approvals | Providing account issuance service without required payment services licence or exemption | Banking Act 1970, ss4, 4A, 4B, 20, 66-67, 71;Payment Services Act 2019, ss5-7, 11-13 | Covers the legal or regulatory requirement relevant to providing account issuance service without required payment services licence or exemption under Payment Services Act 2019; Banking Act 1970 where bank exemption applies. It addresses authorisation status, licensing scope, MAS approvals, licence conditions, approved persons, permitted activities and regulated financial-service boundaries. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in providing account issuance service without required payment services licence or exemption. It applies to banking licences, merchant-bank approvals, digital-bank conditions, payment services, capital-markets activities, representative appointments, branch operations, changes in control, approved officers and activity-scope restrictions. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 412 | Licensing Approvals | Providing domestic money transfer service outside approved scope or exemption | Payment Services Act 2019, ss5-7, 11-13 | Covers the legal or regulatory requirement relevant to providing domestic money transfer service outside approved scope or exemption under Payment Services Act 2019; MAS licence conditions. It addresses authorisation status, licensing scope, MAS approvals, licence conditions, approved persons, permitted activities and regulated financial-service boundaries. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in providing domestic money transfer service outside approved scope or exemption. It applies to banking licences, merchant-bank approvals, digital-bank conditions, payment services, capital-markets activities, representative appointments, branch operations, changes in control, approved officers and activity-scope restrictions. | Payment Services Act breaches may attract MAS directions, composition, financial penalties, licence suspension or revocation, prosecution, safeguarding remediation, customer compensation, operational restrictions and continuing-offence consequences depending on the specific provision. |
| 413 | Licensing Approvals | Providing cross-border money transfer service outside approved scope or exemption | Payment Services Act 2019, ss5-7, 11-13 | Covers the legal or regulatory requirement relevant to providing cross-border money transfer service outside approved scope or exemption under Payment Services Act 2019; MAS licence conditions. It addresses authorisation status, licensing scope, MAS approvals, licence conditions, approved persons, permitted activities and regulated financial-service boundaries. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in providing cross-border money transfer service outside approved scope or exemption. It applies to banking licences, merchant-bank approvals, digital-bank conditions, payment services, capital-markets activities, representative appointments, branch operations, changes in control, approved officers and activity-scope restrictions. | Payment Services Act breaches may attract MAS directions, composition, financial penalties, licence suspension or revocation, prosecution, safeguarding remediation, customer compensation, operational restrictions and continuing-offence consequences depending on the specific provision. |
| 414 | Licensing Approvals | Providing merchant acquisition service without required licence or controls | Payment Services Act 2019, ss5-7, 11-13; MAS payment services requirements | Covers the legal or regulatory requirement relevant to providing merchant acquisition service without required licence or controls under Payment Services Act 2019; MAS payment services requirements. It addresses authorisation status, licensing scope, MAS approvals, licence conditions, approved persons, permitted activities and regulated financial-service boundaries. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in providing merchant acquisition service without required licence or controls. It applies to banking licences, merchant-bank approvals, digital-bank conditions, payment services, capital-markets activities, representative appointments, branch operations, changes in control, approved officers and activity-scope restrictions. | Payment Services Act breaches may attract MAS directions, composition, financial penalties, licence suspension or revocation, prosecution, safeguarding remediation, customer compensation, operational restrictions and continuing-offence consequences depending on the specific provision. |
| 415 | Regulatory Duties | Issuing e-money or stored value facility without required safeguarding arrangement | Payment Services Act 2019, ss23-24 | Covers the legal or regulatory requirement relevant to issuing e-money or stored value facility without required safeguarding arrangement under Payment Services Act 2019; MAS safeguarding requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in issuing e-money or stored value facility without required safeguarding arrangement. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Payment Services Act breaches may attract MAS directions, composition, financial penalties, licence suspension or revocation, prosecution, safeguarding remediation, customer compensation, operational restrictions and continuing-offence consequences depending on the specific provision. |
| 416 | Regulatory Duties | Failure to safeguard customer monies in designated trust, guarantee or undertaking arrangement | Payment Services Act 2019, ss23-24 | Covers the legal or regulatory requirement relevant to failure to safeguard customer monies in designated trust, guarantee or undertaking arrangement under Payment Services Act 2019; MAS safeguarding requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to safeguard customer monies in designated trust, guarantee or undertaking arrangement. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Payment Services Act breaches may attract MAS directions, composition, financial penalties, licence suspension or revocation, prosecution, safeguarding remediation, customer compensation, operational restrictions and continuing-offence consequences depending on the specific provision. |
| 417 | Governance Controls | Commingling customer payment funds with bank or operating funds contrary to requirement | Payment Services Act 2019, ss23-24 | Covers the legal or regulatory requirement relevant to commingling customer payment funds with bank or operating funds contrary to requirement under Payment Services Act 2019; MAS safeguarding requirements. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in commingling customer payment funds with bank or operating funds contrary to requirement. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | Payment Services Act breaches may attract MAS directions, composition, financial penalties, licence suspension or revocation, prosecution, safeguarding remediation, customer compensation, operational restrictions and continuing-offence consequences depending on the specific provision. |
| 418 | Regulatory Duties | Failure to maintain accurate transaction records for payment service activity | Payment Services Act 2019, ss5-7, 23-26, 51 | Covers the legal or regulatory requirement relevant to failure to maintain accurate transaction records for payment service activity under Payment Services Act 2019; MAS record-keeping requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain accurate transaction records for payment service activity. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Payment Services Act breaches may attract MAS directions, composition, financial penalties, licence suspension or revocation, prosecution, safeguarding remediation, customer compensation, operational restrictions and continuing-offence consequences depending on the specific provision. |
| 419 | Professional Conduct | Failure to issue accurate receipt, statement or transaction confirmation for payment service | Payment Services Act 2019, ss5-7, 23-26, 51; MAS conduct requirements | Covers the legal or regulatory requirement relevant to failure to issue accurate receipt, statement or transaction confirmation for payment service under Payment Services Act 2019; MAS conduct requirements. It addresses fair dealing, customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to issue accurate receipt, statement or transaction confirmation for payment service. It applies to relationship managers, advisers, traders, product specialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | Payment Services Act breaches may attract MAS directions, composition, financial penalties, licence suspension or revocation, prosecution, safeguarding remediation, customer compensation, operational restrictions and continuing-offence consequences depending on the specific provision. |
| 420 | Professional Conduct | Failure to disclose fees, exchange rate or charges for cross-border remittance | Payment Services Act 2019, ss5-7, 11-13;Consumer Protection (Fair Trading) Act 2003, ss4-6 | Covers the legal or regulatory requirement relevant to failure to disclose fees, exchange rate or charges for cross-border remittance under Payment Services Act 2019; Consumer Protection (Fair Trading) Act where applicable. It addresses fair dealing, customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to disclose fees, exchange rate or charges for cross-border remittance. It applies to relationship managers, advisers, traders, product specialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | Payment Services Act breaches may attract MAS directions, composition, financial penalties, licence suspension or revocation, prosecution, safeguarding remediation, customer compensation, operational restrictions and continuing-offence consequences depending on the specific provision. |
| 421 | Forgery Records | False or misleading statement in payment services licence application or notification | Penal Code 1871, ss177, 182 and 477A;Payment Services Act 2019, ss5-7, 11-13 | Covers the legal or regulatory requirement relevant to false or misleading statement in payment services licence application or notification under Payment Services Act 2019; Penal Code 1871, ss177, 182 and 477A. It addresses false documents, altered records, inaccurate returns, backdated approvals, manipulated evidence or dishonest reliance on records as genuine. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in false or misleading statement in payment services licence application or notification. It applies to account files, KYC records, returns, approvals, credit papers, reconciliations, audit logs, payment instructions, board papers, correspondence, customer statements, regulatory submissions and electronic records used in banking decisions. | Payment Services Act breaches may attract MAS directions, composition, financial penalties, licence suspension or revocation, prosecution, safeguarding remediation, customer compensation, operational restrictions and continuing-offence consequences depending on the specific provision. |
| 422 | Regulatory Duties | Failure to notify MAS of material change in payment services business | Payment Services Act 2019, ss5-7, 23-26, 51 | Covers the legal or regulatory requirement relevant to failure to notify mas of material change in payment services businessunder Payment Services Act 2019; MAS notification requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary isinvolved in failure to notify mas of material change in payment services business. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Payment Services Act breaches may attract MAS directions, composition, financial penalties, licence suspension or revocation,prosecution, safeguarding remediation, customer compensation, operational restrictions and continuing-offence consequences depending on the specific provision. |
| 423 | Regulatory Duties | Failure to comply with MAS direction relating to payment service risk or safeguarding | Monetary Authority of Singapore Act 1970, ss27A-27B, 28;Payment Services Act 2019, ss23-24 | Covers the legal or regulatory requirement relevant to failure to comply with mas direction relating to payment service risk or safeguarding under Payment Services Act 2019; MAS Act 1970. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to comply with mas direction relating to payment service risk or safeguarding. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 424 | Governance Controls | Failure to manage payment system operational risk for FAST, GIRO, PayNow or card rail access | Financial Services and Markets Act 2022, ss29, 169-170, 176;Payment Services Act 2019, ss25-26, 51; MAS payment services requirements | Covers the legal or regulatory requirement relevant to failure to manage payment system operational risk for fast, giro, paynow or card rail access under Payment Services Act 2019; FSMA 2022; MAS payment system requirements. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to manage payment system operational risk for fast, giro, paynow or card rail access. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 425 | Cyber Technology | Unauthorised access to PayNow proxy, FAST payment or GIRO instruction data | Computer Misuse Act 1993, ss3-4, 11;Payment Services Act 2019, ss5-7, 23-26, 51 | Covers the legal or regulatory requirement relevant to unauthorised access to paynow proxy, fast payment or giro instruction data under Computer Misuse Act 1993; Payment Services Act 2019. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in unauthorised access to paynow proxy, fast payment or giro instruction data. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | Computer Misuse Act offences may attract fines and imprisonment, with enhanced penalties for unauthorised modification, further offences, serious harm, protected systems, repeated conduct or large-scale compromise. MAS technology-risk action and disciplinary consequences may also follow. |
| 426 | Professional Conduct | Failure to verify payee, proxy or beneficiary information before high-risk transfer | Payment Services Act 2019, ss5-7, 23-26, 51;Consumer Protection (Fair Trading) Act 2003, ss4-6 | Covers the legal or regulatory requirement relevant to failure to verify payee, proxy or beneficiary information before high-risk transfer under Payment Services Act 2019; MAS anti-scam and consumer protection expectations. It addresses fair dealing, customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to verify payee, proxy or beneficiary information before high-risk transfer. It applies to relationship managers, advisers, traders, product specialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | Payment Services Act breaches may attract MAS directions, composition, financial penalties, licence suspension or revocation, prosecution, safeguarding remediation, customer compensation, operational restrictions and continuing-offence consequences depending on the specific provision. |
| 427 | Cyber Technology | Failure to implement cooling-off, kill-switch or fraud-control process where required | Financial Services and Markets Act 2022, ss3, 29, 169-170, 176;Payment Services Act 2019, ss5-7, 23-26, 51 | Covers the legal or regulatory requirement relevant to failure to implement cooling-off, kill-switch or fraud-control process where required under FSMA 2022; Payment Services Act 2019; MAS anti-scam measures. It addresses unauthorised access, digital banking controls, system resilience, cyber security, technology risk, incident reporting and protection of critical systems. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to implement cooling-off, kill-switch or fraud-control process where required. It applies to core banking, internet and mobile banking, ATM, SWIFT, payment systems, cloud platforms, APIs, privileged access, change management, logs, vendors, incident response and technology-risk governance. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 428 | Professional Conduct | Failure to resolve unauthorised electronic payment transaction complaint in accordance with applicable framework | Payment Services Act 2019, ss5-7, 23-26, 51 | Covers the legal or regulatory requirement relevant to failure to resolve unauthorised electronic payment transaction complaint in accordance with applicable framework under Payment Services Act 2019; MAS e-payments user protection guidance. It addresses fair dealing, customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to resolve unauthorised electronic payment transaction complaint in accordance with applicable framework. It applies to relationship managers, advisers, traders, product specialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | Payment Services Act breaches may attract MAS directions, composition, financial penalties, licence suspension or revocation, prosecution, safeguarding remediation, customer compensation, operational restrictions and continuing-offence consequences depending on the specific provision. |
| 429 | Governance Controls | Improper reversal, refund or chargeback processing contrary to card scheme or regulatory duties | Penal Code 1871, ss405-409, 420, 424A, 477A;Payment Services Act 2019, ss5-7, 23-26, 51 | Covers the legal or regulatory requirement relevant to improper reversal, refund or chargeback processing contrary to card scheme or regulatory duties under Payment Services Act 2019; Penal Code where dishonest. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in improper reversal, refund or chargeback processing contrary to card scheme or regulatory duties. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | Payment Services Act breaches may attract MAS directions, composition, financial penalties, licence suspension or revocation, prosecution, safeguarding remediation, customer compensation, operational restrictions and continuing-offence consequences depending on the specific provision. |
| 430 | Data Protection | Failure to protect cardholder data or payment token data | Financial Services and Markets Act 2022, ss3, 29, 169-170, 176;PDPA 2012, ss24, 48D-48J;Payment Services Act 2019, ss5-7, 23-26, 51 | Covers the legal or regulatory requirement relevant to failure to protect cardholder data or payment token data under PDPA 2012; Payment Services Act 2019; FSMA 2022. It addresses customer confidentiality, personal data handling, disclosure limitations, protection safeguards, retention, transfer, access controls and breach management. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to protect cardholder data or payment token data. It applies to customer information, personal data, KYC documents, call recordings, statements, transaction records, employee data, outsourcing arrangements, overseas transfers, AI tools, digital channels and breach response. | PDPA consequences may include PDPC directions, financial penalties, corrective orders, breach notification requirements and individual criminal liability for unauthorised disclosure, improper use or re-identification. Banking secrecy, civil claims and disciplinary action may also apply. |
| 431 | Regulatory Duties | Issuing credit card or charge card contrary to regulatory restrictions or customer eligibility rules | Banking Act 1970, ss56, 57, 57A-57G | Covers the legal or regulatory requirement relevant to issuing credit card or charge card contrary to regulatory restrictions or customer eligibility rules under Banking Act 1970; MAS credit card and charge card requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in issuing credit card or charge card contrary to regulatory restrictions or customer eligibility rules. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 432 | Regulatory Duties | Failure to apply credit card income, credit limit or debt servicing checks where required | Banking Act 1970, ss56, 57, 57A-57G | Covers the legal or regulatory requirement relevant to failure to apply credit card income, credit limit or debt servicing checks where required under Banking Act 1970; MAS credit card requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to apply credit card income, credit limit or debt servicing checks where required. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 433 | Professional Conduct | Failure to disclose credit card interest, fees, late charges or minimum payment terms clearly | Banking Act 1970, ss47, 47Aand Third Schedule | Covers the legal or regulatory requirement relevant to failure to disclose credit card interest, fees, late charges or minimum payment terms clearly under Banking Act 1970; MAS credit card disclosure requirements. It addresses fair dealing, customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to disclose credit card interest, fees, late charges or minimum payment terms clearly. It applies to relationship managers, advisers, traders, product specialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 434 | Professional Conduct | Misleading promotion of rewards, miles, cashback or card benefits | Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71;Consumer Protection (Fair Trading) Act 2003, ss4-6 | Covers the legal or regulatory requirement relevant to misleading promotion of rewards, miles, cashback or card benefits under Banking Act 1970; Consumer Protection (Fair Trading) Act 2003. It addresses fair dealing, customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in misleading promotion of rewards, miles, cashback or card benefits. It applies to relationship managers, advisers, traders, product specialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 435 | Financial Crime | Failure to monitor suspicious card merchant, acquirer or terminal activity | CDSA 1992, ss39, 50-54, 57;Payment Services Act 2019, ss5-7, 23-26, 51; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to monitor suspicious card merchant, acquirer or terminal activity under Payment Services Act 2019; MAS Notice 626; CDSA 1992. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transactionmonitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to monitor suspicious card merchant, acquirer or terminal activity. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, tradefinance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 436 | Financial Crime | Failure to terminate merchant account used for laundering, scams or prohibited activity after confirmed risk | CDSA 1992, ss39, 50-54, 57;Payment Services Act 2019, ss5-7, 23-26, 51; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to terminate merchant account used for laundering, scams or prohibited activity after confirmed risk under Payment Services Act 2019; MAS Notice 626; CDSA 1992. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to terminate merchant account used for laundering, scams or prohibited activity after confirmed risk. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 437 | Licensing Approvals | Providing digital payment token service beyond approved scope where bank provides such service | Payment Services Act 2019, ss5-7, 11-13 | Covers the legal or regulatory requirement relevant to providing digital payment token service beyond approved scope where bank provides such service under Payment Services Act 2019; MAS digital payment token requirements. It addresses authorisation status, licensing scope, MAS approvals, licence conditions, approved persons, permitted activities and regulated financial-service boundaries. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in providing digital payment token service beyond approved scope where bank provides such service. It applies to banking licences, merchant-bank approvals, digital-bank conditions, payment services, capital-markets activities, representative appointments, branch operations, changes in control, approved officers and activity-scope restrictions. | Payment Services Act breaches may attract MAS directions, composition, financial penalties, licence suspension or revocation, prosecution, safeguarding remediation, customer compensation, operational restrictions and continuing-offence consequences depending on the specific provision. |
| 438 | Regulatory Duties | Failure to segregate or safeguard customer assets in digital payment token service | Payment Services Act 2019, ss5-7, 11-13 | Covers the legal or regulatory requirement relevant to failure to segregate or safeguard customer assets in digital payment token service under Payment Services Act 2019; MAS digital payment token requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to segregate or safeguard customer assets in digital payment token service. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Payment Services Act breaches may attract MAS directions, composition, financial penalties, licence suspension or revocation, prosecution, safeguarding remediation, customer compensation, operational restrictions and continuing-offence consequences depending on the specific provision. |
| 439 | Professional Conduct | Misleading statement about digital payment token risk, custody or regulatory protection | Payment Services Act 2019, ss5-7, 11-13; MAS conduct requirements | Covers the legal or regulatory requirement relevant to misleading statement about digital payment token risk, custody or regulatory protection under Payment Services Act 2019; MAS conduct requirements; Penal Code s424A. It addresses fair dealing, customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in misleading statement about digital payment token risk, custody or regulatory protection. It applies to relationship managers, advisers, traders, product specialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | Payment Services Act breaches may attract MAS directions, composition, financial penalties, licence suspension or revocation, prosecution, safeguarding remediation, customer compensation, operational restrictions and continuing-offence consequences depending on the specific provision. |
| 440 | Financial Crime | Failure to detect or prevent payment mule recruitment through bank channels | Payment Services Act 2019, ss5-7, 23-26, 51; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to detect or prevent payment mule recruitment through bank channels under MAS Notice 626; Payment Services Act 2019; Penal Code where facilitation occurs. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to detect or prevent payment mule recruitment through bank channels. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 441 | Financial Crime | Failure to screen payment messages against sanctions before release | Terrorism (Suppression of Financing) Act 2002, ss3-8, 11-13;United Nations Act 2001, s2 | Covers the legal or regulatory requirement relevant to failure to screen payment messages against sanctions before release under United Nations Act 2001; TSFA 2002; MAS sanctions and payment requirements. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to screen payment messages against sanctions before release. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 442 | Regulatory Duties | Failure to retain payment investigation records for required period | Payment Services Act 2019, ss5-7, 23-26, 51 | Covers the legal or regulatory requirement relevant to failure to retain payment investigation records for required period under Payment Services Act 2019; MAS record-keeping requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to retain payment investigation records for required period. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Payment Services Act breaches may attract MAS directions, composition, financial penalties, licence suspension or revocation, prosecution, safeguarding remediation, customer compensation, operational restrictions and continuing-offence consequences depending on the specific provision. |
| 443 | Evidence Obstruction | Concealment of payment system outage, payment error or customer-impacting incident | Financial Services and Markets Act 2022, ss29, 169-170, 176;Payment Services Act 2019, ss25-26, 51 | Covers the legal or regulatory requirement relevant to concealment of payment system outage, payment error or customer-impacting incident under Payment Services Act 2019; FSMA 2022; Penal Code ss201, 203 and 204. It addresses concealment, destruction, withholding, delay, misleading statements or interference that frustrates lawful audit, supervision, investigation or enforcement. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in concealment of payment system outage, payment error or customer-impacting incident. It applies during MAS inspections, internal investigations, audit reviews, police inquiries, customer complaints, disciplinary processes, incident response, document production, CCTV retrieval, audit-log preservation and whistleblowing investigations. | FSMA breaches may result in MAS directions, financial penalties, technology-risk management orders, prohibition orders, reprimands, licence consequences, remediation requirements, independent reviews and accountability action against the institution or responsible persons. |
| 444 | Abetment Attempts | Abetment or conspiracy in unauthorised payment service, payment fraud or e-money breach | Penal Code 1871, ss107-109 and 120A-120B;Payment Services Act 2019, ss23-24 | Covers the legal or regulatory requirement relevant to abetment or conspiracy in unauthorised payment service, payment fraud or e-money breach under Penal Code 1871, ss107-109 and 120A-120B; Payment Services Act 2019. It addresses attempts, conspiracy, facilitation, assistance, coordination and planning connected to the principal banking, regulatory or criminal offence. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in abetment or conspiracy in unauthorised payment service, payment fraud or e-money breach. It applies where employees, customers, vendors, intermediaries, mule account holders, representatives, agents or outsiders plan, facilitate, assist, coordinate or attempt another banking-related offence. | Payment Services Act breaches may attract MAS directions, composition, financial penalties, licence suspension or revocation, prosecution, safeguarding remediation, customer compensation, operational restrictions and continuing-offence consequences depending on the specific provision. |
| 445 | Abetment Attempts | Attempt to bypass payment services licence, safeguarding or AML control through business structuring | Penal Code 1871, ss107-109, 120A-120B, 511;Payment Services Act 2019, ss5-7, 11-13 | Covers the legal or regulatory requirement relevant to attempt to bypass payment services licence, safeguarding or aml control through business structuring under Payment Services Act 2019; Penal Code 1871 attempt and abetment provisions. It addresses attempts, conspiracy, facilitation, assistance, coordination and planning connected to the principal banking, regulatory or criminal offence. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in attempt to bypass payment services licence, safeguarding or aml control through business structuring. It applies where employees, customers, vendors, intermediaries, mule account holders, representatives, agents or outsiders plan, facilitate, assist, coordinate or attempt another banking-related offence. | Payment Services Act breaches may attract MAS directions, composition, financial penalties, licence suspension or revocation, prosecution, safeguarding remediation, customer compensation, operational restrictions and continuing-offence consequences depending on the specific provision. |
| 446 | Licensing Approvals | Conducting fund management activity through bank group without proper capital markets authorisation | SFA 2001, ss82, 84-88, 92-99O; MAS capital markets conduct rules | Covers the legal or regulatory requirement relevant to conducting fund management activity through bank group without proper capital markets authorisation under Securities and Futures Act 2001; MAS capital markets licensing requirements. It addresses authorisation status, licensing scope, MAS approvals, licence conditions, approved persons, permitted activities and regulated financial-service boundaries. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in conducting fund management activity through bank group without proper capital markets authorisation. It applies to banking licences, merchant-bank approvals, digital-bank conditions, payment services, capital-markets activities, representative appointments, branch operations, changes in control, approved officers and activity-scope restrictions. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 447 | Licensing Approvals | Conducting corporate finance advisory activity without proper authorisation | SFA 2001, ss82, 84-88, 92-99O; MAS capital markets conduct rules | Covers the legal or regulatory requirement relevant to conducting corporate finance advisory activity without proper authorisation under Securities and Futures Act 2001; MAS capital markets licensing requirements. It addresses authorisation status, licensing scope, MAS approvals, licence conditions, approved persons, permitted activities and regulated financial-service boundaries. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in conducting corporate finance advisory activity without proper authorisation. It applies to banking licences, merchant-bank approvals, digital-bank conditions, payment services, capital-markets activities, representative appointments, branch operations, changes in control, approved officers and activity-scope restrictions. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 448 | Licensing Approvals | Acting as custodian or providing custodial service without required regulatory authority | SFA 2001, ss103A-105;Trust Companies Act 2005, ss3-4 | Covers the legal or regulatory requirement relevant to acting as custodian or providing custodial service without required regulatory authority under Securities and Futures Act 2001; Trust Companies Act 2005 where applicable. It addresses authorisation status, licensing scope, MAS approvals, licence conditions, approved persons, permitted activities and regulated financial-service boundaries. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in acting as custodian or providing custodial service without required regulatory authority. It applies to banking licences, merchant-bank approvals, digital-bank conditions, payment services, capital-markets activities, representative appointments, branch operations, changes in control, approved officers and activity-scope restrictions. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 449 | Regulatory Duties | Failure to notify MAS of appointed representative changes for capital markets activity | SFA 2001, ss82, 84-88, 92-99O | Covers the legal or regulatory requirement relevant to failure to notify mas of appointed representative changes for capital markets activity under Securities and Futures Act 2001; MAS representative notification requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to notify mas of appointed representative changes for capital markets activity. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 450 | Forgery Records | False statement in capital markets representative notification | Penal Code 1871, ss177, 182 and 477A;SFA 2001, ss82, 84-88, 92-99O | Covers the legal or regulatory requirement relevant to false statement in capital markets representative notification under Securities and Futures Act 2001; Penal Code 1871, ss177, 182 and 477A. It addresses false documents, altered records, inaccurate returns, backdated approvals, manipulated evidence or dishonest reliance on records as genuine. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in false statement in capital markets representative notification. It applies to account files, KYC records, returns, approvals, credit papers, reconciliations, audit logs, payment instructions, board papers, correspondence, customer statements, regulatory submissions and electronic records used in banking decisions. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 451 | Professional Conduct | Bank representative trading or advising while suspended, restricted or prohibited | SFA 2001, ss82, 84-88, 92-99O;FAA 2001, ss6, 20, 23, 34-36, 60 | Covers the legal or regulatory requirement relevant to bank representative trading or advising while suspended, restricted or prohibited under Securities and Futures Act 2001; FAA 2001; MAS prohibition order framework. It addresses fair dealing, customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in bank representative trading or advising while suspended, restricted or prohibited. It applies to relationship managers, advisers, traders, product specialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 452 | Governance Controls | Failure to maintain fit-and-proper assessment for representatives | SFA 2001, ss82, 84-88, 92-99O;FAA 2001, ss6, 20, 23, 34-36, 60 | Covers the legal or regulatory requirement relevant to failure to maintain fit-and-proper assessment for representatives under Securities and Futures Act 2001; FAA 2001; MAS fit-and-proper guidelines. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain fit-and-proper assessment for representatives. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 453 | Governance Controls | Failure to supervise dealing representative, trader or relationship manager | SFA 2001, ss82, 84-88, 92-99O;FAA 2001, ss6, 20, 23, 34-36, 60; MAS conduct requirements | Covers the legal or regulatory requirement relevant to failure to supervise dealing representative, trader or relationship manager under Securities and Futures Act 2001; FAA 2001; MAS conduct requirements. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to supervise dealing representative, trader or relationship manager. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 454 | Regulatory Duties | Failure to maintain training and competence records for investment representatives | SFA 2001, ss82, 84-88, 92-99O;FAA 2001, ss6, 20, 23, 34-36, 60 | Covers the legal or regulatory requirement relevant to failure to maintain training and competence records for investment representatives under Securities and Futures Act 2001; FAA 2001; MAS representative requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain training and competence records for investment representatives. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 455 | Regulatory Duties | Failure to segregate client assets from bank assets in capital markets activity | SFA 2001, ss103A-105; MAS client asset/custody requirements | Covers the legal or regulatory requirement relevant to failure to segregate client assets from bank assets in capital markets activity under Securities and Futures Act 2001; MAS client asset requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to segregate client assets from bank assets in capital markets activity. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 456 | Governance Controls | Failure to reconcile client money, securities or custody positions | SFA 2001, ss103A-105; MAS client asset/custody requirements | Covers the legal or regulatory requirement relevant to failure to reconcile client money, securities or custody positions under Securities and Futures Act 2001; MAS custody and client asset requirements. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to reconcile client money, securities or custody positions. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 457 | Property Offences | Using client assets, securities or collateral without authority | Penal Code 1871, ss405-409;SFA 2001, ss103A-105 | Covers the legal or regulatory requirement relevant to using client assets, securities or collateral without authority under Securities and Futures Act 2001; Penal Code 1871, ss405-409. It addresses dishonest taking, misuse, retention or conversion of property, funds, securities, documents or entrusted assets within a regulated banking environment. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in using client assets, securities or collateral without authority. It applies across branches, vaults, ATMs, cash rooms, securities custody, loan documentation, safe-deposit arrangements, customer files, courier handling, outsourced processing and any asset entrusted to employees, agents or vendors. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 458 | Regulatory Duties | Failure to provide contract note, statement or confirmation within required time | SFA 2001, ss102-103, 106-107; MAS capital markets conduct rules | Covers the legal or regulatory requirement relevant to failure to provide contract note, statement or confirmation within required time under Securities and Futures Act 2001; MAS capital markets conduct rules. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to provide contract note, statement or confirmation within required time. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 459 | Forgery Records | Issuing false or misleading trade confirmation, custody statement or investment report | Penal Code 1871, s477A;SFA 2001, ss103A-105 | Covers the legal or regulatory requirement relevant to issuing false or misleading trade confirmation, custody statement or investment report under Securities and Futures Act 2001; Penal Code 1871, s477A. It addresses false documents, altered records, inaccurate returns, backdated approvals, manipulated evidence or dishonest reliance on records as genuine. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in issuing false or misleading trade confirmation, custody statement or investment report. It applies to account files, KYC records, returns, approvals, credit papers, reconciliations, audit logs, payment instructions, board papers, correspondence, customer statements, regulatory submissions and electronic records used in banking decisions. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 460 | Regulatory Duties | Failure to maintain order records, voice logs or trade reconstruction materials | SFA 2001, ss102-103, 106-107 | Covers the legal or regulatory requirement relevant to failure to maintain order records, voice logs or trade reconstruction materials under Securities and Futures Act 2001; MAS record-keeping requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain order records, voice logs or trade reconstruction materials. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 461 | Governance Controls | Failure to monitor employee personal trading or outside brokerage accounts | SFA 2001, ss197-204, 218-219 | Covers the legal or regulatory requirement relevant to failure to monitor employee personal trading or outside brokerage accounts under Securities and Futures Act 2001; MAS market conduct expectations. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to monitor employee personal trading or outside brokerage accounts. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 462 | Professional Conduct | Failure to prevent front-running of customer order by trader or relationship manager | SFA 2001, ss197-204, 218-219 | Covers the legal or regulatory requirement relevant to failure to prevent front-running of customer order by trader orrelationship manager under Securities and Futures Act 2001, market misconduct provisions. It addresses fair dealing, customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary isinvolved in failure to prevent front-running of customer order by trader or relationship manager. It applies to relationship managers, advisers, traders, product specialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representativeaction, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 463 | Professional Conduct | Failure to prevent misuse of confidential information from lending, M&A or private banking relationship | Banking Act 1970, ss47, 47Aand Third Schedule;SFA 2001, ss197-204, 218-219 | Covers the legal or regulatory requirement relevant to failure to prevent misuse of confidential information from lending, m&a or private banking relationship under Securities and Futures Act 2001; Banking Act customer information provisions. It addresses fair dealing, customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to prevent misuse of confidential information from lending, m&a or private banking relationship. It applies to relationship managers, advisers, traders, product specialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | Bank secrecy and customer-information breaches may result in criminal penalties under the Banking Act, MAS enforcement action, confidentiality restrictions, civil liability, customer remediation, disciplinary action and possible fitness-and-propriety consequences for responsible persons. |
| 464 | Governance Controls | Failure to maintain information barriers between research, sales, trading and private side teams | SFA 2001, ss197-204, 218-219 | Covers the legal or regulatory requirement relevant to failure to maintain information barriers between research, sales, trading and private side teams under Securities and Futures Act 2001; MAS conflict management requirements. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain information barriers between research, sales, trading and private side teams. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 465 | Governance Controls | Failure to manage wall-crossing, restricted list or watch-list controls | SFA 2001, ss197-204, 218-219 | Covers the legal or regulatory requirement relevant to failure to manage wall-crossing, restricted list or watch-list controls under Securities and Futures Act 2001; MAS market conduct requirements. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to manage wall-crossing, restricted list or watch-list controls. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 466 | Professional Conduct | Publishing investment research with undisclosed conflict, inducement or issuer relationship | SFA 2001, ss199-200, 202-204;FAA 2001, ss6, 20, 23, 34-36, 60; MAS conduct requirements | Covers the legal or regulatory requirement relevant to publishing investment research with undisclosed conflict, inducement or issuer relationship under Securities and Futures Act 2001; FAA 2001; MAS conduct rules. It addresses fair dealing, customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in publishing investment research with undisclosed conflict, inducement or issuer relationship. It applies to relationship managers, advisers, traders, product specialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 467 | Fraud Deception | False or misleading statement to induce customer to deal in capital markets product | Penal Code 1871, ss420 and 424A;SFA 2001, ss199-200, 202-204 | Covers the legal or regulatory requirement relevant to false or misleading statement to induce customer to deal in capital markets product under Securities and Futures Act 2001; Penal Code 1871, ss420 and 424A. It addresses deception, false representation, non-disclosure, dishonest inducement, abuse of position and resulting loss or improper gain in banking activity. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in false or misleading statement to induce customer to deal in capital markets product. It applies across onboarding, lending, cards, payments, trade finance, wealth management, vendor claims, customer communications, digital channels, approval workflows, refunds, waivers and representations made to customers, counterparties or regulators. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 468 | Professional Conduct | Omitting material product risk in structured note, derivative or bond distribution | SFA 2001, ss275-305, 309A-309B;FAA 2001, ss23, 34-36, 60; MAS product governance / due diligence requirements | Covers the legal or regulatory requirement relevant to omitting material product risk in structured note, derivative or bond distribution under FAA 2001; Securities and Futures Act 2001; MAS product disclosure rules. It addresses fair dealing, customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in omitting material product risk in structured note, derivative or bond distribution. It applies to relationship managers, advisers, traders, product specialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 469 | Professional Conduct | Failure to assess customer knowledge and experience before selling specified investment product | FAA 2001, ss6, 20, 23, 34-36, 60; MAS notices | Covers the legal or regulatory requirement relevant to failure to assess customer knowledge and experience before selling specified investment product under FAA 2001; MAS notices on sale of investment products. It addresses fair dealing, customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to assess customer knowledge and experience before selling specified investment product. It applies to relationship managers, advisers, traders, product specialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | Financial Advisers Act breaches may result in fines, imprisonment for specified offences, MAS reprimands, representative restrictions, prohibition orders, licence action, customer remediation, compensation directions and disciplinary consequences for supervisors or representatives. |
| 470 | Professional Conduct | Failure to assess product suitability for vulnerable or elderly customer | FAA 2001, ss23, 34-36, 60; MAS fair dealing requirements | Covers the legal or regulatory requirement relevant to failure to assess product suitability for vulnerable or elderly customer under FAA 2001; MAS fair dealing and advisory requirements. It addresses fair dealing, customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to assess product suitability for vulnerable or elderly customer. It applies to relationship managers, advisers, traders, product specialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | Financial Advisers Act breaches may result in fines, imprisonment for specified offences, MAS reprimands, representative restrictions, prohibition orders, licence action, customer remediation, compensation directions and disciplinary consequences for supervisors or representatives. |
| 471 | Professional Conduct | Failure to explain leverage, margin call or downside risk in investment recommendation | SFA 2001, ss82, 99B-99O, 102-105, 197-204, 218-219;FAA 2001, ss23, 34-36, 60; MAS conduct requirements | Covers the legal or regulatory requirement relevant to failure to explain leverage, margin call or downside risk in investment recommendation under FAA 2001; SFA 2001; MAS conduct rules. It addresses fair dealing, customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to explain leverage, margin call or downside risk in investment recommendation. It applies to relationship managers, advisers, traders, product specialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 472 | Professional Conduct | Improper classification of customer as accredited investor, expert investor or institutional investor | SFA 2001, ss275-305, 309A-309B;FAA 2001, ss6, 20, 23, 34-36, 60; MAS investor classification requirements | Covers the legal or regulatory requirement relevant to improper classification of customer as accredited investor, expert investor or institutional investor under SFA 2001; FAA 2001; MAS classification and opt-in requirements. It addresses fair dealing, customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in improper classification of customer as accredited investor, expert investor or institutional investor. It applies to relationship managers, advisers, traders, product specialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 473 | Regulatory Duties | Failure to obtain valid accredited investor opt-in or acknowledgement | SFA 2001, ss275-305, 309A-309B;FAA 2001, ss6, 20, 23, 34-36, 60 | Covers the legal or regulatory requirement relevant to failure to obtain valid accredited investor opt-in or acknowledgement under SFA 2001; FAA 2001; MAS investor classification requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to obtain valid accredited investor opt-in or acknowledgement. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 474 | Professional Conduct | Mis-selling of margin trading, FX, derivative or dual-currency investment product | SFA 2001, ss275-305, 309A-309B;FAA 2001, ss23, 34-36, 60; MAS conduct requirements | Covers the legal or regulatory requirement relevant to mis-selling of margin trading, fx, derivative or dual-currency investment product under SFA 2001; FAA 2001; MAS conduct rules. It addresses fair dealing, customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in mis-selling of margin trading, fx, derivative or dual-currency investment product. It applies to relationship managers, advisers, traders, product specialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 475 | Professional Conduct | Churning, excessive switching or unnecessary product replacement for commission | Penal Code 1871, ss405-409, 420, 424A, 477A;FAA 2001, ss23, 34-36, 60; MAS fair dealing requirements | Covers the legal or regulatory requirement relevant to churning, excessive switching or unnecessary product replacement for commission under FAA 2001; MAS fair dealing requirements; Penal Code where dishonest. It addresses fair dealing,customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in churning, excessive switching or unnecessary product replacement for commission. It applies to relationship managers, advisers, traders, productspecialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | Financial Advisers Act breaches may result in fines, imprisonment for specified offences, MAS reprimands, representative restrictions, prohibition orders, licence action, customer remediation, compensation directions and disciplinary consequences for supervisors orrepresentatives. |
| 476 | Professional Conduct | Failure to disclose trailer fee, retrocession, commission or sales incentive | FAA 2001, ss23, 34-36, 60 | Covers the legal or regulatory requirement relevant to failure to disclose trailer fee, retrocession, commission or sales incentive under FAA 2001; MAS disclosure requirements. It addresses fair dealing, customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to disclose trailer fee, retrocession, commission or sales incentive. It applies to relationship managers, advisers, traders, product specialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | Financial Advisers Act breaches may result in fines, imprisonment for specified offences, MAS reprimands, representative restrictions, prohibition orders, licence action, customer remediation, compensation directions and disciplinary consequences for supervisors or representatives. |
| 477 | Regulatory Duties | Failure to maintain basis-of-recommendation documentation | FAA 2001, ss23, 34-36, 60 | Covers the legal or regulatory requirement relevant to failure to maintain basis-of-recommendation documentation under FAA 2001; MAS advisory documentation requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain basis-of-recommendation documentation. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Financial Advisers Act breaches may result in fines, imprisonment for specified offences, MAS reprimands, representative restrictions, prohibition orders, licence action, customer remediation, compensation directions and disciplinary consequences for supervisors or representatives. |
| 478 | Professional Conduct | Failure to handle investment complaint, dispute or remediation fairly | FAA 2001, ss23, 34-36, 60 | Covers the legal or regulatory requirement relevant to failure to handle investment complaint, dispute or remediation fairly under FAA 2001; MAS complaints handling requirements. It addresses fair dealing, customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to handle investment complaint, dispute or remediation fairly. It applies to relationship managers, advisers, traders, product specialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | Financial Advisers Act breaches may result in fines, imprisonment for specified offences, MAS reprimands, representative restrictions, prohibition orders, licence action, customer remediation, compensation directions and disciplinary consequences for supervisors or representatives. |
| 479 | Regulatory Duties | Failure to comply with MAS direction to compensate or remediate mis-sold customers | Monetary Authority of Singapore Act 1970, ss27A-27B, 28;FAA 2001, ss6, 20, 23, 34-36, 60 | Covers the legal or regulatory requirement relevant to failure to comply with mas direction to compensate or remediate mis-sold customers under FAA 2001; MAS Act 1970; MAS enforcement direction. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to comply with mas direction to compensate or remediate mis-sold customers. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 480 | Governance Controls | Failure to conduct product due diligence before distributing investment product | SFA 2001, ss82, 99B-99O, 102-105, 197-204, 218-219;FAA 2001, ss23, 34-36, 60; MAS product governance / due diligence requirements | Covers the legal or regulatory requirement relevant to failure to conduct product due diligence before distributing investment product under FAA 2001; SFA 2001; MAS product due diligence requirements. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to conduct product due diligence before distributing investment product. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 481 | Governance Controls | Failure to review target market, distribution channel or product risk after material event | FAA 2001, ss23, 34-36, 60; MAS product governance / due diligence requirements | Covers the legal or regulatory requirement relevant to failure to review target market, distribution channel or product risk after material event under FAA 2001; MAS product governance requirements. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to review target market, distribution channel or product risk after material event. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | Financial Advisers Act breaches may result in fines, imprisonment for specified offences, MAS reprimands, representative restrictions, prohibition orders, licence action, customer remediation, compensation directions and disciplinary consequences for supervisors or representatives. |
| 482 | Professional Conduct | Failure to monitor concentration risk in customer portfolio recommended by relationship manager | FAA 2001, ss23, 34-36, 60; MAS fair dealing requirements | Covers the legal or regulatory requirement relevant to failure to monitor concentration risk in customer portfolio recommended by relationship manager under FAA 2001; MAS fair dealing requirements. It addresses fair dealing, customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to monitor concentration risk in customer portfolio recommended by relationship manager. It applies to relationship managers, advisers, traders, product specialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | Financial Advisers Act breaches may result in fines, imprisonment for specified offences, MAS reprimands, representative restrictions, prohibition orders, licence action, customer remediation, compensation directions and disciplinary consequences for supervisors or representatives. |
| 483 | Corruption Ethics | Improper inducement, referral fee or benefit paid for investment product recommendation | FAA 2001, ss23, 34-36, 60;Prevention of Corruption Act 1960, ss5-6; MAS conduct requirements | Covers the legal or regulatory requirement relevant to improper inducement, referral fee or benefit paid for investment product recommendation under FAA 2001; Prevention of Corruption Act 1960; MAS conduct rules. It addresses gratification, kickbacks, secret commissions, conflicts of interest, improper influence, abuse of authority and private gain affecting banking decisions. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in improper inducement, referral fee or benefit paid for investment product recommendation. It applies to procurement, credit approvals, onboarding, referrals, debt recovery, vendor selection, valuation, commissions, gifts, entertainment, outside interests, hiring and senior-management decision-making. | For corruption-related offences, punishment may include a fine up to $100,000, imprisonment up to 5 years, or both, with restitution, confiscation, employment consequences, MAS fitness-and-propriety action and prohibition orders where relevant. |
| 484 | Regulatory Duties | Failure to manage cross-border solicitation into or from Singapore | SFA 2001, ss82, 99B-99O, 102-105, 197-204, 218-219;FAA 2001, ss6, 20, 23, 34-36, 60 | Covers the legal or regulatory requirement relevant to failure to manage cross-border solicitation into or from singapore under FAA 2001; SFA 2001; MAS cross-border conduct requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to manage cross-border solicitation into or from singapore. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 485 | Licensing Approvals | Acting as trust company or providing trust business without required licence | Trust Companies Act 2005, ss3-4 | Covers the legal or regulatory requirement relevant to acting as trust company or providing trust business without required licence under Trust Companies Act 2005; MAS trust business licensing requirements. It addresses authorisation status, licensing scope, MAS approvals, licence conditions, approved persons, permitted activities and regulated financial-service boundaries. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in acting as trust company or providing trust business without required licence. It applies to banking licences, merchant-bank approvals, digital-bank conditions, payment services, capital-markets activities, representative appointments, branch operations, changes in control, approved officers and activity-scope restrictions. | Trust Companies Act breaches may result in fines, imprisonment for specified offences, licence conditions, suspension or revocation, MAS directions, restitution of client assets, civil liability and fitness-and-propriety consequences. |
| 486 | Property Offences | Failure to safeguard trust property or client assets held in fiduciary capacity | Penal Code 1871, ss405-409;Trust Companies Act 2005, ss3-4 | Covers the legal or regulatory requirement relevant to failure to safeguard trust property or client assets held in fiduciary capacity under Trust Companies Act 2005; Penal Code 1871, ss405-409. It addresses dishonest taking, misuse, retention or conversion of property, funds, securities, documents or entrusted assets within a regulated banking environment. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to safeguard trust property or client assets held in fiduciary capacity. It applies across branches, vaults, ATMs, cash rooms, securities custody, loan documentation, safe-deposit arrangements, customer files, courier handling, outsourced processing and any asset entrusted to employees, agents or vendors. | Trust Companies Act breaches may result in fines, imprisonment for specified offences, licence conditions, suspension or revocation, MAS directions, restitution of client assets, civil liability and fitness-and-propriety consequences. |
| 487 | Regulatory Duties | Failure to maintain trust accounting records and reconciliations | Trust Companies Act 2005, ss3-4;Companies Act 1967, ss199-201, 207, 401-402 | Covers the legal or regulatory requirement relevant to failure to maintain trust accounting records and reconciliations under Trust Companies Act 2005; Companies Act 1967; Penal Code s477A where falsified. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain trust accounting records and reconciliations. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Trust Companies Act breaches may result in fines, imprisonment for specified offences, licence conditions, suspension or revocation, MAS directions, restitution of client assets, civil liability and fitness-and-propriety consequences. |
| 488 | Professional Conduct | Improper distribution, transfer or investment of trust assets contrary to mandate | Penal Code 1871, ss405-409;Trust Companies Act 2005, ss3-4 | Covers the legal or regulatory requirement relevant to improper distribution, transfer or investment of trust assets contrary to mandate under Trust Companies Act 2005; Penal Code where dishonest. It addresses fair dealing, customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in improper distribution, transfer or investment of trust assets contrary to mandate. It applies to relationship managers, advisers, traders, product specialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | Trust Companies Act breaches may result in fines, imprisonment for specified offences, licence conditions, suspension or revocation, MAS directions, restitution of client assets, civil liability and fitness-and-propriety consequences. |
| 489 | Financial Crime | Failure to conduct due diligence on settlor, protector, beneficiary or trust structure | Trust Companies Act 2005, ss3-4; MAS Notice 626 | Covers the legal or regulatory requirement relevant to failure to conduct due diligence on settlor, protector, beneficiary or trust structure under Trust Companies Act 2005; MAS Notice 626 where bank is involved; AML/CFT rules. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to conduct due diligence on settlor, protector, beneficiary or trust structure. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | AML/CFT, sanctions or financial-crime breaches may lead to MAS enforcement, financial penalties, directions, licence consequences, criminal prosecution, asset freezing, suspicious transaction reporting consequences, prohibition orders and management accountability measures. |
| 490 | Financial Crime | Failure to identify politically exposed person risk in trust or fiduciary structure | Trust Companies Act 2005, ss3-4 | Covers the legal or regulatory requirement relevant to failure to identify politically exposed person risk in trust or fiduciary structure under Trust Companies Act 2005; MAS AML/CFT requirements. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to identify politically exposed person risk in trust or fiduciary structure. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | Trust Companies Act breaches may result in fines, imprisonment for specified offences, licence conditions, suspension or revocation, MAS directions, restitution of client assets, civil liability and fitness-and-propriety consequences. |
| 491 | Governance Controls | Failure to manage conflict between trustee role, banking relationship and investment recommendation | FAA 2001, ss23, 34-36, 60;Trust Companies Act 2005, ss3-4; MAS governance/corporate governance guidelines | Covers the legal or regulatory requirement relevant to failure to manage conflict between trustee role, banking relationship and investment recommendation under Trust Companies Act 2005; FAA 2001; MAS governance requirements. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to manage conflict between trustee role, banking relationship and investment recommendation. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | Financial Advisers Act breaches may result in fines, imprisonment for specified offences, MAS reprimands, representative restrictions, prohibition orders, licence action, customer remediation, compensation directions and disciplinary consequences for supervisors or representatives. |
| 492 | Forgery Records | False trust statement, trust account statement or fiduciary report | Penal Code 1871, s477A;Trust Companies Act 2005, ss3-4 | Covers the legal or regulatory requirement relevant to false trust statement, trust account statement or fiduciary report under Trust Companies Act 2005; Penal Code 1871, s477A. It addresses false documents, altered records, inaccurate returns, backdated approvals, manipulated evidence or dishonest reliance on records as genuine. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in false trust statement, trust account statement or fiduciary report. It applies to account files, KYC records, returns, approvals, credit papers, reconciliations, audit logs, payment instructions, board papers, correspondence, customer statements, regulatory submissions and electronic records used in banking decisions. | Trust Companies Act breaches may result in fines, imprisonment for specified offences, licence conditions, suspension or revocation, MAS directions, restitution of client assets, civil liability and fitness-and-propriety consequences. |
| 493 | Evidence Obstruction | Obstruction of MAS or auditor in trust business inspection | Monetary Authority of Singapore Act 1970, ss27A-27B, 28;Trust Companies Act 2005, ss3-4 | Covers the legal or regulatory requirement relevant to obstruction of mas or auditor in trust business inspection under Trust Companies Act 2005; MAS Act 1970; Penal Code ss175, 186 and 204. It addresses concealment, destruction, withholding, delay, misleading statements or interference that frustrates lawful audit, supervision, investigation or enforcement. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in obstruction of mas or auditor in trust business inspection. It applies during MAS inspections, internal investigations, audit reviews, police inquiries, customer complaints, disciplinary processes, incident response, document production, CCTV retrieval, audit-log preservation and whistleblowing investigations. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 494 | Abetment Attempts | Abetment or conspiracy in securities, advisory, trust or market-conduct offence | Penal Code 1871, ss107-109 and 120A-120B;SFA 2001, ss82, 99B-99O, 102-105, 197-204, 218-219;FAA 2001, ss6, 20, 23, 34-36, 60;Trust Companies Act 2005, ss3-4 | Covers the legal or regulatory requirement relevant to abetment or conspiracy in securities, advisory, trust or market-conduct offence under Penal Code 1871, ss107-109 and 120A-120B; SFA 2001; FAA 2001; TCA 2005. It addresses attempts, conspiracy, facilitation, assistance, coordination and planning connected to the principal banking, regulatory or criminal offence. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in abetment or conspiracy in securities, advisory, trust or market-conduct offence. It applies where employees, customers, vendors, intermediaries, mule account holders, representatives, agents or outsiders plan, facilitate, assist, coordinate or attempt another banking-related offence. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 495 | Abetment Attempts | Attempt to commit insider trading, market manipulation, mis-selling or client-asset misuse | Penal Code 1871, s511;SFA 2001, ss218-219;FAA 2001, ss23, 34-36, 60 | Covers the legal or regulatory requirement relevant to attempt to commit insider trading, market manipulation, mis-selling or client-asset misuse under Penal Code attempt provisions; Securities and Futures Act 2001; FAA 2001. It addresses attempts, conspiracy, facilitation, assistance, coordination and planning connected to the principal banking, regulatory or criminal offence. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in attempt to commit insider trading, market manipulation, mis-selling or client-asset misuse. It applies where employees, customers, vendors, intermediaries, mule account holders, representatives, agents or outsiders plan, facilitate, assist, coordinate or attempt another banking-related offence. | SFA-related breaches may result in civil penalties, criminal fines, imprisonment for serious market misconduct, licence or representative action, prohibition orders, disgorgement, compensation orders, exchange discipline and MAS enforcement depending on the offence. |
| 496 | Data Protection | Failure to classify customer information under Banking Act secrecy controls | Banking Act 1970, ss47, 47Aand Third Schedule;PDPA 2012, ss24, 48D-48J | Covers the legal or regulatory requirement relevant to failure to classify customer information under banking act secrecy controls under Banking Act 1970, s47; PDPA 2012. It addresses customer confidentiality, personal data handling, disclosure limitations, protection safeguards, retention, transfer, access controls and breach management. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to classify customer information under banking act secrecy controls. It applies to customer information, personal data, KYC documents, call recordings, statements, transaction records, employee data, outsourcing arrangements, overseas transfers, AI tools, digital channels and breach response. | PDPA consequences may include PDPC directions, financial penalties, corrective orders, breach notification requirements and individual criminal liability for unauthorised disclosure, improper use or re-identification. Banking secrecy, civil claims and disciplinary action may also apply. |
| 497 | Data Protection | Disclosure of customer information to overseas branch without lawful exception or controls | Banking Act 1970, ss47, 47Aand Third Schedule;PDPA 2012, ss24, 26, 26B-26D, 48I-48J | Covers the legal or regulatory requirement relevant to disclosure of customer information to overseas branch without lawful exception or controls under Banking Act 1970, s47; PDPA 2012 cross-border transfer requirements. It addresses customer confidentiality, personal data handling, disclosure limitations, protection safeguards, retention, transfer, access controls and breach management. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in disclosure of customer information to overseas branch without lawful exception or controls. It applies to customer information, personal data, KYC documents, call recordings, statements, transaction records, employee data, outsourcing arrangements, overseas transfers, AI tools, digital channels and breach response. | PDPA consequences may include PDPC directions, financial penalties, corrective orders, breach notification requirements and individual criminal liability for unauthorised disclosure, improper use or re-identification. Banking secrecy, civil claims and disciplinary action may also apply. |
| 498 | Data Protection | Disclosure of customer information to outsourced service provider without required confidentiality safeguards | Banking Act 1970, ss47, 47Aand Third Schedule;PDPA 2012, ss24, 26, 26B-26D, 48I-48J; MAS outsourcing guidelines | Covers the legal or regulatory requirement relevant to disclosure of customer information to outsourced service provider without required confidentiality safeguards under Banking Act 1970, s47A; PDPA 2012; MAS outsourcing guidelines. It addresses customer confidentiality, personal data handling, disclosure limitations, protection safeguards, retention, transfer, access controls and breach management. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in disclosure of customer information to outsourced service provider without required confidentiality safeguards. It applies to customer information, personal data, KYC documents, call recordings, statements, transaction records, employee data, outsourcing arrangements, overseas transfers, AI tools, digital channels and breach response. | PDPA consequences may include PDPC directions, financial penalties, corrective orders, breach notification requirements and individual criminal liability for unauthorised disclosure, improper use or re-identification. Banking secrecy, civil claims and disciplinary action may also apply. |
| 499 | Data Protection | Failure to maintain customer consent, authorisation or statutory basis for information disclosure | Banking Act 1970, ss47, 47Aand Third Schedule;PDPA 2012, ss24, 48D-48J | Covers the legal or regulatory requirement relevant to failure to maintain customer consent, authorisation or statutory basis for information disclosure under Banking Act 1970, customer information provisions; PDPA 2012. It addresses customer confidentiality, personal data handling, disclosure limitations, protection safeguards, retention, transfer, access controls and breach management. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain customer consent, authorisation or statutory basis for information disclosure. It applies to customer information, personal data, KYC documents, call recordings, statements, transaction records, employee data, outsourcing arrangements, overseas transfers, AI tools, digital channels and breach response. | PDPA consequences may include PDPC directions, financial penalties, corrective orders, breach notification requirements and individual criminal liability for unauthorised disclosure, improper use or re-identification. Banking secrecy, civil claims and disciplinary action may also apply. |
| 500 | Financial Crime | Improper disclosure of suspicious transaction, account freeze or law enforcement request to customer | Banking Act 1970, ss47, 47Aand Third Schedule;CDSA 1992, s57; MAS Notice 626 | Covers the legal or regulatory requirement relevant to improper disclosure of suspicious transaction, account freeze or law enforcement request to customer under CDSA 1992; MAS Notice 626; Banking Act 1970. It addresses AML/CFT, sanctions, suspicious transactions, illicit funds, customer due diligence, transaction monitoring and prevention of financial-crime facilitation. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in improper disclosure of suspicious transaction, account freeze or law enforcement request to customer. It applies to onboarding, sanctions screening, beneficial ownership checks, transaction monitoring, correspondent banking, private banking, trade finance, wire transfers, mule accounts, scam proceeds and suspicious transaction escalation. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 501 | Data Protection | Failure to mask, minimise or restrict access to customer information in call centre or operations unit | Banking Act 1970, ss47, 47Aand Third Schedule;PDPA 2012, ss24, 48D-48J; MAS outsourcing guidelines | Covers the legal or regulatory requirement relevant to failure to mask, minimise or restrict access to customer information in call centre or operations unit under PDPA 2012; Banking Act 1970; MAS outsourcing guidelines. It addresses customer confidentiality, personal data handling, disclosure limitations, protection safeguards, retention, transfer, access controls and breach management. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to mask, minimise or restrict access to customer information in call centre or operations unit. It applies to customer information, personal data, KYC documents, call recordings, statements, transaction records, employee data, outsourcing arrangements, overseas transfers, AI tools, digital channels and breach response. | PDPA consequences may include PDPC directions, financial penalties, corrective orders, breach notification requirements and individual criminal liability for unauthorised disclosure, improper use or re-identification. Banking secrecy, civil claims and disciplinary action may also apply. |
| 502 | Data Protection | Failure to protect physical customer files, cheque images, statements or KYC documents | Banking Act 1970, ss47, 47Aand Third Schedule;PDPA 2012, ss24, 48D-48J | Covers the legal or regulatory requirement relevant to failure to protect physical customer files, cheque images, statements orkyc documents under PDPA 2012; Banking Act 1970; MAS record security requirements. It addresses customer confidentiality, personal data handling, disclosure limitations, protection safeguards, retention, transfer, access controls and breach management. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary isinvolved in failure to protect physical customer files, cheque images, statements or kyc documents. It applies to customer information, personal data, KYC documents, call recordings, statements, transaction records, employee data, outsourcing arrangements, overseas transfers, AI tools, digital channels and breach response. | PDPA consequences may include PDPC directions, financial penalties, corrective orders, breach notification requirements and individualcriminal liability for unauthorised disclosure, improper use or re-identification. Banking secrecy, civil claims and disciplinary action may also apply. |
| 503 | Data Protection | Improper use of customer data for marketing without consent or applicable exception | Banking Act 1970, ss47, 47Aand Third Schedule;PDPA 2012, ss13-20, 43-48, 48D-48J | Covers the legal or regulatory requirement relevant to improper use of customer data for marketing without consent or applicable exception under PDPA 2012; Banking Act 1970; Do Not Call provisions where applicable. It addresses customer confidentiality, personal data handling, disclosure limitations, protection safeguards, retention, transfer, access controls and breach management. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in improper use of customer data for marketing without consent or applicable exception. It applies to customer information, personal data, KYC documents, call recordings, statements, transaction records, employee data, outsourcing arrangements, overseas transfers, AI tools, digital channels and breach response. | PDPA consequences may include PDPC directions, financial penalties, corrective orders, breach notification requirements and individual criminal liability for unauthorised disclosure, improper use or re-identification. Banking secrecy, civil claims and disciplinary action may also apply. |
| 504 | Data Protection | Failure to correct inaccurate customer data after verified correction request | PDPA 2012, ss21-22, 22A, 48I-48J | Covers the legal or regulatory requirement relevant to failure to correct inaccurate customer data after verified correction request under PDPA 2012 access and correction obligations. It addresses customer confidentiality, personal data handling, disclosure limitations, protection safeguards, retention, transfer, access controls and breach management. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to correct inaccurate customer data after verified correction request. It applies to customer information, personal data, KYC documents, call recordings, statements, transaction records, employee data, outsourcing arrangements, overseas transfers, AI tools, digital channels and breach response. | PDPA consequences may include PDPC directions, financial penalties, corrective orders, breach notification requirements and individual criminal liability for unauthorised disclosure, improper use or re-identification. Banking secrecy, civil claims and disciplinary action may also apply. |
| 505 | Regulatory Duties | Failure to retain customer records for required statutory or regulatory period | Banking Act 1970, ss43-45, 58, 66-67, 71; MAS Notice 626; MAS notices | Covers the legal or regulatory requirement relevant to failure to retain customer records for required statutory or regulatory period under Banking Act 1970; MAS notices; MAS Notice 626 record retention requirements. It addresses statutory duties, MAS notices, directions, prudential standards, reporting obligations, notification duties and mandatory compliance expectations for banking operations. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to retain customer records for required statutory or regulatory period. It applies across prudential reporting, MAS returns, incident notifications, AML/CFT compliance, payment operations, product obligations, capital and liquidity monitoring, record retention, remediation tracking and supervisory communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 506 | Data Protection | Retaining customer data longer than necessary without legal or business basis | PDPA 2012, s25, ss48I-48J | Covers the legal or regulatory requirement relevant to retaining customer data longer than necessary without legal or business basis under PDPA 2012 retention limitation obligation. It addresses customer confidentiality, personal data handling, disclosure limitations, protection safeguards, retention, transfer, access controls and breach management. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in retaining customer data longer than necessary without legal or business basis. It applies to customer information, personal data, KYC documents, call recordings, statements, transaction records, employee data, outsourcing arrangements, overseas transfers, AI tools, digital channels and breach response. | PDPA consequences may include PDPC directions, financial penalties, corrective orders, breach notification requirements and individual criminal liability for unauthorised disclosure, improper use or re-identification. Banking secrecy, civil claims and disciplinary action may also apply. |
| 507 | Governance Controls | Failure to conduct data protection impact assessment for new banking product or digital channel | PDPA 2012, ss24, 48D-48J; MAS Technology Risk Management requirements | Covers the legal or regulatory requirement relevant to failure to conduct data protection impact assessment for new banking product or digital channel under PDPA 2012; MAS TRM and outsourcing requirements. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to conduct data protection impact assessment for new banking product or digital channel. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | PDPA consequences may include PDPC directions, financial penalties, corrective orders, breach notification requirements and individual criminal liability for unauthorised disclosure, improper use or re-identification. Banking secrecy, civil claims and disciplinary action may also apply. |
| 508 | Governance Controls | Failure to maintain outsourcing register for material banking services | Banking Act 1970, s47A;Financial Services and Markets Act 2022, s29;Financial Services and Markets Act 2022, ss29, 169-170, 176; MAS outsourcing guidelines | Covers the legal or regulatory requirement relevant to failure to maintain outsourcing register for material banking services under MAS outsourcing guidelines; Banking Act 1970; FSMA 2022. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain outsourcing register for material banking services. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 509 | Governance Controls | Failure to obtain board or senior management approval for material outsourcing arrangement | Banking Act 1970, ss65-67, 71; MAS outsourcing guidelines | Covers the legal or regulatory requirement relevant to failure to obtain board or senior management approval for material outsourcing arrangement under MAS outsourcing guidelines; Banking Act 1970. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to obtain board or senior management approval for material outsourcing arrangement. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 510 | Governance Controls | Failure to monitor outsourced debt collection, call centre, KYC or payment processing vendor | Banking Act 1970, s47A;Financial Services and Markets Act 2022, s29;PDPA 2012, ss24, 26, 26B-26D, 48I-48J; MAS outsourcing guidelines | Covers the legal or regulatory requirement relevant to failure to monitor outsourced debt collection, call centre, kyc or payment processing vendor under MAS outsourcing guidelines; PDPA 2012; Banking Act 1970. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to monitor outsourced debt collection, call centre, kyc or payment processing vendor. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | PDPA consequences may include PDPC directions, financial penalties, corrective orders, breach notification requirements and individual criminal liability for unauthorised disclosure, improper use or re-identification. Banking secrecy, civil claims and disciplinary action may also apply. |
| 511 | Governance Controls | Failure to ensure outsourced vendor complies with audit, confidentiality and business continuity requirements | Financial Services and Markets Act 2022, ss29, 169-170, 176;PDPA 2012, ss24, 26, 26B-26D, 48I-48J; MAS outsourcing guidelines | Covers the legal or regulatory requirement relevant to failure to ensure outsourced vendor complies with audit, confidentiality and business continuity requirements under MAS outsourcing guidelines; FSMA 2022; PDPA 2012. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to ensure outsourced vendor complies with audit, confidentiality and business continuity requirements. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | PDPA consequences may include PDPC directions, financial penalties, corrective orders, breach notification requirements and individual criminal liability for unauthorised disclosure, improper use or re-identification. Banking secrecy, civil claims and disciplinary action may also apply. |
| 512 | Professional Conduct | Failure to manage third-party misconduct by debt collector acting for bank | Banking Act 1970, s47A;Financial Services and Markets Act 2022, s29;Protection from Harassment Act 2014, ss3-7; MAS fair dealing requirements | Covers the legal or regulatory requirement relevant to failure to manage third-party misconduct by debt collector acting for bank under Banking Act 1970; MAS fair dealing expectations; Protection from Harassment Act where applicable. It addresses fair dealing, customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to manage third-party misconduct by debt collector acting for bank. It applies to relationship managers, advisers, traders, product specialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 513 | Professional Conduct | Misleading debt collection, recovery or restructuring communication to customer | Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71;Consumer Protection (Fair Trading) Act 2003, ss4-6 | Covers the legal or regulatory requirement relevant to misleading debt collection, recovery or restructuring communication to customer under Banking Act 1970; Consumer Protection (Fair Trading) Act; Penal Code where deception occurs. It addresses fair dealing, customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in misleading debt collection, recovery or restructuring communication to customer. It applies to relationship managers, advisers, traders, product specialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 514 | Professional Conduct | Failure to handle customer complaint, fraud claim or hardship request fairly and promptly | Banking Act 1970, ss4, 4A, 43-45, 58, 66-67, 71; MAS fair dealing requirements | Covers the legal or regulatory requirement relevant to failure to handle customer complaint, fraud claim or hardship request fairly and promptly under Banking Act 1970; MAS fair dealing and complaints handling expectations. It addresses fair dealing, customer communications, suitability, competence, representative supervision, conflicts, advice quality and treatment of vulnerable customers. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to handle customer complaint, fraud claim or hardship request fairly and promptly. It applies to relationship managers, advisers, traders, product specialists, call centres, debt collection, complaints, vulnerable customers, investment recommendations, product distribution and customer-facing communications. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 515 | Governance Controls | Failure to maintain whistleblowing channel independent from implicated management | Companies Act 1967, ss156-157, 199-201, 401-402; MAS governance/corporate governance guidelines | Covers the legal or regulatory requirement relevant to failure to maintain whistleblowing channel independent from implicated management under Companies Act 1967; MAS corporategovernance guidelines. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain whistleblowing channel independent fromimplicated management. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | Companies Act and governance breaches may result in fines, officer liability, disqualification consequences, civil claims, audit qualifications, regulatory reporting obligations and, where dishonesty is involved,related Penal Code or MAS enforcement action. |
| 516 | Governance Controls | Failure to investigate employee misconduct, fraud or regulatory breach after credible report | Banking Act 1970, ss43-45, 58, 66-67, 71;Companies Act 1967, ss401-402; MAS governance/corporate governance guidelines | Covers the legal or regulatory requirement relevant to failure to investigate employee misconduct, fraud or regulatory breach after credible report under Companies Act 1967; Banking Act 1970; MAS governance requirements. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to investigate employee misconduct, fraud or regulatory breach after credible report. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 517 | Evidence Obstruction | Suppressing internal audit finding relating to regulatory breach or customer harm | Penal Code 1871, ss201, 203, 204 and 477A;Companies Act 1967, ss199-201, 207, 401-402 | Covers the legal or regulatory requirement relevant to suppressing internal audit finding relating to regulatory breach or customer harm under Penal Code 1871, ss201, 203, 204 and 477A; Companies Act 1967. It addresses concealment, destruction, withholding, delay, misleading statements or interference that frustrates lawful audit, supervision, investigation or enforcement. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in suppressing internal audit finding relating to regulatory breach or customer harm. It applies during MAS inspections, internal investigations, audit reviews, police inquiries, customer complaints, disciplinary processes, incident response, document production, CCTV retrieval, audit-log preservation and whistleblowing investigations. | Companies Act and governance breaches may result in fines, officer liability, disqualification consequences, civil claims, audit qualifications, regulatory reporting obligations and, where dishonesty is involved, related Penal Code or MAS enforcement action. |
| 518 | Governance Controls | Failure to maintain conflict-of-interest register for directors, senior managers and key staff | Banking Act 1970, ss65-67, 71;Companies Act 1967, ss156-157; MAS governance/corporate governance guidelines | Covers the legal or regulatory requirement relevant to failure to maintain conflict-of-interest register for directors, senior managers and key staff under Companies Act 1967; Banking Act 1970; MAS corporate governance guidelines. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to maintain conflict-of-interest register for directors, senior managers and key staff. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
| 519 | Corruption Ethics | Failure to manage gifts, entertainment, referral benefits or outside business interests | Banking Act 1970, ss43-45, 58, 66-67, 71;Prevention of Corruption Act 1960, ss5-6 | Covers the legal or regulatory requirement relevant to failure to manage gifts, entertainment, referral benefits or outside business interests under Prevention of Corruption Act 1960; Banking Act 1970; internal governance requirements. It addresses gratification, kickbacks, secret commissions, conflicts of interest, improper influence, abuse of authority and private gain affecting banking decisions. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in failure to manage gifts, entertainment, referral benefits or outside business interests. It applies to procurement, credit approvals, onboarding, referrals, debt recovery, vendor selection, valuation, commissions, gifts, entertainment, outside interests, hiring and senior-management decision-making. | For corruption-related offences, punishment may include a fine up to $100,000, imprisonment up to 5 years, or both, with restitution, confiscation, employment consequences, MAS fitness-and-propriety action and prohibition orders where relevant. |
| 520 | Governance Controls | Corporate or senior management liability for repeated systemic control failure across bank group | Banking Act 1970, ss65-67, 71;Monetary Authority of Singapore Act 1970, ss27A-27B, 28;Financial Services and Markets Act 2022, ss29, 169-170, 176;Companies Act 1967, ss156-157 | Covers the legal or regulatory requirement relevant to corporate or senior management liability for repeated systemic control failure across bank group under Banking Act 1970; Companies Act 1967; MAS Act 1970; FSMA 2022. It addresses board oversight, management accountability, internal controls, risk management, auditability, escalation, independent review and remediation of systemic weaknesses. | Applies where the bank, banking group, branch, officer, representative, employee, contractor, outsourced provider, customer or intermediary is involved in corporate or senior management liability for repeated systemic control failure across bank group. It applies to board committees, senior management, risk, compliance, internal audit, technology governance, outsourcing, model risk, conflicts management, escalation channels, policy ownership and control testing. | Banking Act or MAS-related breaches may result in MAS directions, reprimands, composition, civil penalties, licence conditions, business restrictions, suspension or revocation, prohibition orders, prosecution and accountability action against directors, officers or responsible staff. |
Page 1 of 1
Reference and Verification Checklist
- Verify all Penal Code 1871 sections and punishments against the current Singapore Statutes Online text.
- Verify Banking Act 1970 licensing, bank secrecy, prudential, credit card/charge card, merchant bank and supervisory provisions, including current amendments and MAS instruments.
- Verify Monetary Authority of Singapore Act 1970 provisions on MAS powers, inspections, directions, information gathering, resolution and financial-sector oversight.
- Verify Financial Services and Markets Act 2022 provisions on sector-wide regulation, technology risk management, prohibition orders and financial-sector misconduct.
- Verify MAS Notice 626, Guidelines to Notice 626 and current AML/CFT requirements for banks, including CDD, EDD, STR, wire transfers, correspondent banking, sanctions screening and group controls.
- Verify CDSA 1992, Terrorism (Suppression of Financing) Act 2002 and United Nations Act sanctions requirements before publication.
- Verify Payment Services Act 2019 obligations where banks provide regulated payment services, e-money, transfer services, digital payment token or payment system functions.
- Verify Securities and Futures Act 2001 and Financial Advisers Act 2001 obligations where banks conduct capital markets, wealth management, advisory, securities, derivatives or investment-product distribution activities.
- Verify Trust Companies Act 2005, Deposit Insurance and Policy Owners Protection Schemes Act and any other bank-specific or product-specific statutes where applicable.
- Verify PDPA 2012 obligations and current PDPC enforcement framework for customer, employee, beneficial-owner and transaction personal data.
- Verify Computer Misuse Act 1993 and MAS technology risk requirements for cyber, digital banking, payment, SWIFT, ATM, mobile/internet banking and third-party technology risks.
- Verify Prevention of Corruption Act 1960 provisions relating to gratification, procurement corruption, kickbacks, referral arrangements, credit approval, onboarding and customer/vendor dealings.
- Verify Companies Act 1967, corporate governance, audit, financial reporting and director/officer duties applicable to bank entities.
- Verify WSH Act 2006, Fire Safety Act 1993 and physical security/public-safety obligations for branches, offices, data centres, cash operations and contractors.
- Verify MAS Notices, Guidelines, Circulars, Enforcement Reports and current licensing conditions applicable to full banks, wholesale banks, merchant banks, digital banks and relevant banking groups.
- Verify all references to penalties, composition, civil penalties, prohibition orders, licence restrictions, revocation, supervisory directions and criminal punishments before training, publication or operational use.
(C) Copy Rights Reserved, Alan Elangovan - LPS Academy
