by Dean
Share
Share
Every Capital Markets Services (CMS) licensee in Singapore is expected by the Monetary Authority of Singapore (MAS) to maintain an internal audit function that provides independent assurance over the firm’s compliance controls, as part of its annual reporting obligations. In practice, this requirement is often treated as a light-touch, once-a-year formality — a read-through of the compliance manual, signed off and filed. That approach misses the point of what an internal or compliance audit is actually meant to achieve, and leaves firms exposed when MAS does look closely.
💡 Key Takeaway: This guide sets out what a properly run internal compliance audit should cover, who can perform it, and how findings should be handled so the exercise genuinely strengthens the firm’s control environment rather than just satisfying a box on a checklist.
Why MAS Expects an Internal Audit Function
MAS’s supervisory approach relies heavily on licensed entities maintaining effective first-line controls, supported by independent second- and third-line assurance. An internal audit function sits in that third line: it tests whether the policies and procedures a firm has documented are actually being followed, and whether those controls are effective in practice — not just present on paper. This is distinct from, and complements, day-to-day compliance monitoring performed by the compliance function itself.
What a Compliance Audit Actually Covers
A properly scoped internal compliance audit for a CMS licensee typically tests:
✅ Compliance Audit Scope Checklist
- Customer due diligence (CDD) files, sampled across client types, to confirm documentation and risk rating are complete and consistent with policy.
- AML/CFT transaction monitoring and suspicious transaction report (STR) filing timeliness, including whether escalation procedures were actually followed.
- Client money and asset segregation records, to confirm no commingling has occurred.
- Fit and proper reassessment records for directors, key personnel, and representatives.
- Regulatory returns and MAS filings, reconciled against underlying records.
- Staff competency — including, where practical, brief interviews or scenario checks to confirm frontline staff can actually explain the procedures they are meant to follow, not just that they signed an attendance log.
Who Can Perform It — In-House, HQ, or Outsourced
MAS does not mandate a single structural model for meeting the internal audit expectation. Firms can maintain a dedicated in-house internal audit team, rely on qualified auditors from a head office or group entity, or outsource the function to a competent third-party service provider. What matters to MAS is that the function is independent of the staff and processes being tested, and that it is resourced with people who genuinely understand fund management compliance — not that it sits on a particular org chart.
From Findings to Remediation — Closing the Loop
An audit that generates a list of findings and stops there has only done half the job. Each finding should be logged with a clear root cause, an owner, and a remediation deadline, and the audit function (or an independent reviewer) should follow up to confirm the remediation was actually implemented — not just marked as closed. Findings and remediation status should be reported to the board or senior management, consistent with MAS’s expectation that the CEO and directors remain ultimately responsible for the firm’s compliance, even where day-to-day execution is delegated or outsourced.
Common Pitfalls That Undermine an Audit’s Value
⚠️ The most common ways firms undermine their own internal audit process include:
- Scoping the audit too narrowly to avoid uncomfortable findings
- Using the same reviewer year after year without genuine independence from operational decisions
- Treating a clean audit report as evidence of compliance rather than evidence that the sample tested was clean
- Failing to track whether prior findings were actually remediated before the next audit cycle begins
Conclusion
A genuine internal compliance audit is one of the most effective tools a CMS licensee has for catching control gaps before MAS does. Firms that resource it properly — with real independence, a meaningful testing scope, and a closed-loop remediation process — go into an MAS inspection with a far clearer, more defensible picture of their own compliance health.
📌 How Alder Can Help:
Alder’s compliance audit service provides an independent, MAS-aligned review of your firm’s controls, testing whether policies are actually being followed in practice, not just documented on paper. This gives your board a credible, evidence-based picture of compliance health ahead of any MAS inspection.
Contact Alder to discuss your compliance audit scope.
This article is for general information only and does not constitute legal or regulatory advice. Contact Alder for advice specific to your circumstances.
Protect your company's reputation with our expert adverse media screening in Singapore. Ensure compliance and mitigate risks.



