by Dean

Share

Share

by Dean

Share

Cryptocurrency has become an increasingly established part of Singapore’s financial landscape, but its growth also brings significant regulatory, technological and operational risks. Understanding these cryptocurrency risks is essential for businesses involved in digital payment token (DPT) activities and other businesses operating within Singapore’s regulated financial sector.

Singapore has developed a regulatory framework for digital payment token services under the Payment Services Act 2019. As the sector continues to develop, cryptocurrency regulation in Singapore has also evolved to address risks relating to money laundering and terrorist financing, technology and cybersecurity, consumer protection and financial stability.

For businesses operating in this space, understanding cryptocurrency risk factors involves more than assessing the risks of digital assets themselves. Businesses must also consider the regulatory and operational controls needed to manage these risks effectively.

This article examines four key risks associated with cryptocurrencies that businesses should consider when operating within Singapore’s regulatory environment.

1. Money Laundering and Terrorist Financing Risks

One of the key cryptocurrency risks for businesses operating in Singapore is the potential misuse of digital payment tokens for money laundering and terrorist financing (ML/TF). The nature of digital payment token activities can create additional challenges when businesses identify customers, assess transaction activity and detect potentially suspicious behaviour.

Under Singapore’s regulatory framework, digital payment token service is a regulated payment service under the Payment Services Act 2019. Businesses providing regulated DPT services may therefore need to obtain the appropriate payment services licence unless an exemption applies.

The Monetary Authority of Singapore (MAS) maintains a Financial Institutions Directory that allows businesses and the public to identify payment service providers carrying out digital payment token services. The directory currently lists entities under the Digital Payment Token Service activity, including Major Payment Institutions.

Businesses can refer to the MAS Financial Institutions Directory to verify the licensing status and regulated activities of payment service providers.

For businesses operating in the sector, effective cryptocurrency risk management requires more than obtaining a licence. Appropriate AML/CFT controls should form part of the organisation’s wider compliance framework. Depending on the nature of the business, these controls may include customer due diligence, transaction monitoring, sanctions screening, suspicious transaction reporting and ongoing assessment of ML/TF risks.

Businesses should also ensure that their AML/KYC controls are appropriate to the nature, scale and complexity of their activities.

Businesses that require assistance establishing and strengthening these controls can explore Alder Compliance’s AML/KYC Support.

2. Technology and Cybersecurity Risks

Technology is fundamental to cryptocurrency businesses, but reliance on digital infrastructure also creates significant technology and cybersecurity risks.

Digital payment token service providers may rely on online platforms, digital wallets, blockchain infrastructure, APIs and other technology systems to provide their services. A system failure, cyberattack, data breach or other technology incident could affect the availability, security or integrity of these services.

Technology risk is therefore an important part of cryptocurrency risk management.

MAS’s Notice on Technology Risk Management applies to holders of payment services licences carrying on digital payment token services. The current notice sets out requirements relating to technology risk management and critical systems.

Businesses should refer to MAS Notice PSN05 — Notice on Technology Risk Management for the applicable requirements.

It is important to distinguish the current requirements from the earlier version of PSN05. The February 2024 MAS document states that its amendments were compared against the PSN05 issued on 5 December 2019, and that the amendments took effect on 6 November 2024.

This distinction is important when updating regulatory content because businesses should not rely on wording from the older 2019 version when assessing their current technology-risk obligations.

For businesses operating cryptocurrency-related services, appropriate technology-risk controls may include identifying critical systems, managing technology risks, maintaining appropriate security measures and establishing processes to respond to technology incidents.

Technology and cybersecurity should therefore be treated as an ongoing compliance responsibility rather than a one-time requirement.

3. Consumer Protection Risks

Another important area of cryptocurrency risk factors relates to consumer protection.

Cryptocurrency and digital payment tokens can involve significant price volatility and may expose consumers to losses. Consumers may also face risks associated with the security of their accounts or digital assets, the reliability of service providers and the way information about cryptocurrency products and services is presented.

For businesses operating in Singapore, appropriate controls and clear communication are important for managing these risks. Businesses should ensure that their operations, customer-facing processes and disclosures are consistent with the regulatory requirements applicable to their activities.

The broader Singapore crypto regulation landscape has continued to develop as MAS and other authorities respond to risks arising from digital payment token activities. Businesses should therefore avoid treating consumer protection as a one-off compliance exercise and instead incorporate it into their ongoing risk-management framework.

From an operational perspective, businesses should consider whether customers are provided with appropriate information about the nature and risks of the services being offered. Internal processes should also clearly define responsibilities for handling customer issues, complaints and incidents.

These measures can help businesses identify and address potential consumer-related risks before they develop into broader regulatory or reputational issues.

4. Financial Stability Risks

The fourth area to consider is the potential impact of cryptocurrency activities on financial stability.

The growing adoption and integration of digital assets can create additional risks where cryptocurrency activities become increasingly connected with traditional financial services and markets. Volatility, liquidity risks, operational disruptions and broader market developments can affect businesses operating in the sector.

For individual businesses, these risks may arise through their exposure to digital assets, counterparties, liquidity arrangements, technology infrastructure or other parts of the cryptocurrency ecosystem.

This makes it important for businesses to consider cryptocurrency-related risks as part of their broader enterprise risk-management framework.

Rather than looking at individual risks associated with cryptocurrencies in isolation, businesses should consider how different risks may interact. For example, a technology incident could affect service availability, create customer-protection concerns and potentially result in financial or reputational consequences.

A structured cryptocurrency risk management approach can help businesses identify these interconnected risks, establish appropriate controls and respond more effectively when circumstances change.

How Businesses Can Manage Cryptocurrency Risks

The regulatory environment surrounding cryptocurrency continues to develop, making ongoing compliance an important consideration for businesses operating in Singapore.

A robust compliance framework should consider the risks relevant to the business’s specific activities, including:

  • Money laundering and terrorist financing risks
  • Customer due diligence and AML/KYC requirements
  • Technology and cybersecurity risks
  • Consumer protection considerations
  • Operational and financial risks
  • Regulatory reporting and ongoing compliance obligations

Businesses should also regularly review their policies and controls to ensure they remain appropriate as their operations, technology and regulatory obligations evolve.

Businesses that require support with their wider regulatory obligations can explore Alder Compliance’s Compliance Support services.

Where licensing requirements apply, businesses should also assess the appropriate regulatory framework and licensing requirements before commencing regulated activities.

Alder Compliance provides MAS Licensing support for businesses assessing their licensing requirements and preparing for the application process.

Conclusion

Cryptocurrency presents opportunities for businesses, but it also introduces a range of regulatory, operational and technology-related risks. Understanding these cryptocurrency risks is therefore an important part of operating responsibly within Singapore’s financial ecosystem.

From AML/CFT and cybersecurity to consumer protection and financial stability, businesses need to identify the cryptocurrency risk factors relevant to their activities and establish appropriate controls to manage them.

As cryptocurrency regulation in Singapore continues to evolve, businesses should keep their compliance frameworks up to date and review their policies, processes and controls regularly.

Taking a proactive approach to cryptocurrency risk management can help businesses respond to regulatory developments, strengthen their internal controls and operate more effectively within Singapore’s evolving digital asset landscape.

About the Author: Dean

Dean is the Co-Founder of Alder. An IBF Scholar, he holds a Bachelor of Business (Banking & Finance) from Nanyang Technological University. With 20+ years of regional B2B sales and marketing experience across banking, finance, technology, and professional services, he leads Alder’s business development and client relationships, supporting companies with practical outsourced compliance solutions.