by Dean
Share
Share
A surprising number of Capital Markets Services (CMS) licensees in Singapore are still operating on the compliance policy manual they drafted at the point of licensing — sometimes years earlier, with no formal review in between. Keeping policies current is not a bureaucratic nicety; it is one of the more common gaps that surfaces during an MAS supervisory review, and one of the more avoidable ones.
Why Policies Go Stale
Policies go out of date for entirely ordinary reasons: MAS notices get amended, the firm’s business activities or client base evolve, headcount and reporting lines change, and new products or services get launched without the compliance manual being updated to reflect them. None of this happens through negligence — it happens because policy review isn’t built into anyone’s ongoing workflow. As a result, it only gets attention when something forces the issue (a licence renewal, an inspection notice, or a new hire asking why the manual doesn’t match reality).
What “Up to Date” Actually Means to MAS
An up-to-date policy is not simply one that has been re-approved on schedule. It needs to accurately describe what the firm actually does — its current organisational structure, its current risk assessment, and its current operational processes — and it needs to reflect the current version of the MAS notices and guidelines it is meant to implement.
💡 Pro Tip: A policy that is technically “reviewed annually” but rubber-stamped without substantive checking against operating reality provides little real protection.
A Practical Policy Review Cadence
Most CMS licensees can manage this with a two-track review cadence: a scheduled annual review of the full policy suite (often aligned with the annual compliance review), and a triggered review whenever a relevant MAS notice, guideline, or consultation response is finalised, or whenever the firm’s own business activities materially change.
Core policies — AML/CFT, conduct of business, risk management, outsourcing — generally warrant closer attention than lower-risk administrative policies.
Version Control and Audit Trail
Beyond the content itself, MAS inspectors expect to see evidence of the review process: a version history showing when each policy was last reviewed, who reviewed it, what changed and why, and explicit sign-off from the designated policy owner.
⚠️ Critical Compliance Note: A policy manual with no visible review history — even if the content happens to be current — reads as a governance gap in its own right.
What Happens When Policies Are Out of Date
Outdated policies create risk on two fronts. Operationally, staff may be following an outdated or informal process that was never properly documented or risk-assessed. From a supervisory perspective, a policy that visibly hasn’t been touched in years — or that describes a process the firm no longer follows — signals to an MAS inspector that governance isn’t being actively maintained, which tends to invite closer scrutiny of everything else in the compliance framework.
Who Should Own the Review
Policy review works best when ownership is explicit rather than assumed.
✅ Policy Ownership Checklist
- Core regulatory policies (AML/CFT, conduct of business, risk management): The compliance function should own the substantive review, with sign-off from the CEO or board reflecting MAS’s expectation that senior management remains actively engaged with the firm’s compliance posture.
- Narrower operational policies: The relevant function head is often better placed to confirm the policy still matches how the team actually works, with compliance reviewing for regulatory alignment rather than operational detail.
- The Benefit: Splitting ownership this way avoids the common failure mode where one person is nominally responsible for reviewing policies across the entire business and, realistically, cannot do so with genuine rigour.
Aligning Policy Review with the Annual Compliance Cycle
Policy review shouldn’t run as an isolated exercise disconnected from the rest of the firm’s compliance calendar. Firms get the most value when policy review is timed to feed into, or draw from, the annual compliance review, fit and proper reassessments, and any internal or outsourced compliance audit — so that findings from one process inform updates to the other, rather than three separate teams independently re-discovering the same gaps.
Conclusion
Treating policy review as a continuous discipline, rather than a one-off exercise from the licensing stage, is one of the more cost-effective ways a CMS licensee can reduce its inspection risk. It doesn’t require a large team — it requires a clear cadence, clear ownership, and a habit of checking policies against what the firm actually does, not just re-approving what’s already on file.
How Alder Can Help: Alder’s compliance policy drafting and review service keeps your firm’s policies current with the latest MAS notices and your actual operating practices, with proper version control and review documentation to withstand supervisory scrutiny.
Contact Alder to review your policy framework and set up a regular review cadence.
This article is for general information only and does not constitute legal or regulatory advice. Contact Alder for advice specific to your circumstances.
The Monetary Authority of Singapore (MAS) can take a range of enforcement actions for breaches of the laws it administers — reprimands, composition penalties, prohibition orders, civil penalties, and referrals for criminal prosecution. MAS’s own stated enforcement priorities for 2025–26 centre on market misconduct, AML/CFT failures, and technology risk. A review of MAS’s recent
The Monetary Authority of Singapore (MAS) published a consultation paper on 10 June 2026 proposing amendments to the MAS Notices on Technology Risk Management. The consultation closes at 11.30 PM on 31 July 2026—giving MAS-regulated firms just under two months to assess the proposed changes and, where warranted, submit a formal response. This article explains
Suspicious transaction reporting is a core AML/CFT obligation for every MAS-licensed fund manager in Singapore. Yet it remains one of the compliance areas most likely to have inadequate policies, insufficient training, and underdocumented decision-making. This guide explains the legal framework, the filing timeline, and the practical steps your firm should take to meet its STR




