Singapore and ASEAN Financial Crime Controls
Singapore is one of the most important financial centres in Asia, but a bank operating from Singapore into Southeast Asia cannot treat the region as one AML jurisdiction. Singapore has its own laws, supervisors, financial intelligence unit, sanctions implementation, reporting channels and information-sharing arrangements. Each other ASEAN Member State has its own legal framework, competent authorities, reporting thresholds, supervisory expectations and operational procedures. ASEAN creates valuable regional cooperation, but it is not a single AML regulator and it does not issue one banking rulebook that replaces national law.
That distinction is the starting point for this chapter. A regional bank needs a strong group financial-crime standard, but the group standard is only one layer. Under it must sit controlled country overlays that explain which legal entity is in scope, which local obligation applies, which authority receives a report, what data may be shared, how sanctions are implemented, what evidence must be retained and who has authority to decide. A control can be globally designed and still fail locally if the legal nexus, reporting route or customer treatment is wrong.
Singapore provides a useful anchor because its operating model is mature and well documented. The Monetary Authority of Singapore, or MAS, supervises financial institutions within its remit and issues sector-specific AML/CFT requirements. The Suspicious Transaction Reporting Office, or STRO, is Singapore's financial intelligence unit and receives suspicious transaction reports and other financial information. Singapore also maintains national money-laundering, terrorism-financing, proliferation-financing and virtual-asset risk assessments, operates targeted-financial-sanctions frameworks and has developed COSMIC, a legally governed information-sharing platform for prescribed financial institutions. These components work together, but they are not interchangeable.
A bank therefore needs to answer four separate questions whenever a customer, payment, trade transaction or investigation crosses borders. What is the global standard? Which Singapore obligation applies to the Singapore entity? Which obligation applies in the other ASEAN jurisdiction or jurisdictions touched by the relationship? What bank policy or risk-appetite requirement goes beyond the legal minimum? Those four questions should be visible in the case record rather than collapsed into a generic status such as regional AML cleared.
The simplest mental model: one region, many legal regimes
The safest mental model is a layered one. FATF Recommendations provide a common international baseline. FATF-style regional bodies such as the Asia/Pacific Group on Money Laundering support assessment and implementation across much of the Asia-Pacific, but they do not legislate for ASEAN. ASEAN supports political and operational cooperation between Member States, including cooperation on transnational crime and money laundering. National governments then turn international commitments into domestic law, regulation and enforcement. Banks implement those domestic requirements through policies, systems, procedures and accountable people.
This matters because similar words can hide different legal consequences. Two countries may both require customer due diligence, sanctions screening and suspicious transaction reporting, yet differ on who must report, the legal test for suspicion, reporting timelines, confidentiality restrictions, tipping-off rules, record-retention periods, beneficial-ownership thresholds, treatment of politically exposed persons, sanctions lists, freezing mechanics and regulator notification. Even where the principle is similar, the operational design may need a country-specific branch.
As of 2026, ASEAN has eleven Member States following Timor-Leste's admission in October 2025. That membership fact is important for regional operating models because static country tables built around the previous ten-member assumption can become wrong without any system defect. It illustrates a broader lesson: jurisdictional configuration is master data that needs ownership, effective dates and change control. It is not background documentation that can safely remain unchanged for years.
For a group bank, the regional model should therefore contain a controlled jurisdiction registry. Each record should identify the country, bank legal entity, licence or regulated activity, relevant regulator and FIU, core AML/CFT/CPF instruments, applicable sanctions sources, reporting channel, key operational deadlines, data-sharing constraints, local policy owner and last legal review date. A second layer should map those obligations to controls and systems. The result is traceable from law to policy to requirement to system rule to operational procedure to evidence.
Singapore's institutional architecture
Singapore's financial-crime framework is deliberately multi-agency. MAS is the central bank and integrated financial supervisor. STRO sits within the Singapore Police Force's Commercial Affairs Department and performs the FIU function. Other government agencies, law-enforcement bodies and sector supervisors have responsibilities depending on the activity. For a bank, this means the supervisor, FIU and law-enforcement authority may interact with the same risk from different perspectives.
A common design error is to treat MAS and STRO as synonyms. They are not. MAS supervises regulated financial institutions and issues regulatory requirements. STRO receives and analyses suspicious transaction reports and other financial intelligence and disseminates intelligence where relevant. A bank may have a supervisory obligation to MAS and a separate statutory reporting obligation to STRO. The evidence, timing, approval path and confidentiality treatment may differ even if both arise from the same case.
MAS AML/CFT notices are also sector-specific. For banks, MAS Notice 626 is a core instrument, but it should not be described as the universal notice for every financial institution. Other sectors have their own notices and guidelines. This distinction matters in diversified financial groups. A bank, payment institution, insurer, securities intermediary and trust company may share a group platform while remaining subject to different sector-specific requirements. The system should therefore derive the relevant regulatory overlay from legal entity and regulated activity, not merely from the customer being located in Singapore.
Singapore's 2024 updated Money Laundering National Risk Assessment identified fraud, especially cyber-enabled fraud, as a major money-laundering threat and highlighted the exposure created by Singapore's role as an international financial centre and trading hub. It also identified misuse of bank accounts, legal persons, cross-border fund flows and high-value assets as important typologies, and assessed banking, including wealth management, as a high-risk sector. The risk assessment is not a transaction-rejection list. It is an input to risk-based control design, customer-risk methodology, scenario calibration, staff awareness and supervisory dialogue.
The FATF/APG mutual evaluation published in May 2026 provides another important perspective. It recognised strong governance, legal frameworks, cooperation and risk understanding while also stressing the need for consistent and demonstrable risk-based outcomes. For banks, the practical lesson is that policy completeness is not enough. Supervisors and assessors look for evidence that risk understanding changes decisions, resources, controls and outcomes.
Suspicious transaction reporting and STRO
The suspicious-transaction-reporting process is where local legal design becomes very concrete. Singapore's Suspicious Transaction Reporting Office states that persons in the course of trade, profession, business or employment who know or have reasonable grounds to suspect that property may represent proceeds of or be connected with criminal conduct have reporting duties under the Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992. Terrorism-financing information duties also arise under the Terrorism (Suppression of Financing) Act 2002. Banks need approved legal interpretation and internal procedures for how these duties apply in their operating context.
STRs are filed electronically through STRO Online Notices And Reporting, known as SONAR. The operating requirement is therefore not simply file an STR. The bank needs a controlled path from alert or case to suspicion decision, approval, report preparation, data validation, SONAR submission, receipt or acknowledgement handling, record retention and any post-filing restrictions or monitoring. Access to SONAR itself needs administration, entitlements and continuity arrangements.
The difference between an alert and an STR must stay clear. A transaction-monitoring alert is a system-generated or manually generated signal for review. A case is an investigation container. Suspicion is a reasoned conclusion based on facts and context. An STR is a legal disclosure to the FIU. If system design treats every alert as a reportable event, the bank creates noise and poor reporting quality. If it treats filing as an optional compliance preference, it risks missing a legal duty.
The evidence trail should capture what caused concern, what customer information was reviewed, which transactions were relevant, what external intelligence or linked parties were identified, why the explanation did or did not make sense, who reached the suspicion decision, when the decision was made and when the report was submitted. Where the bank continues a relationship after reporting, the case should also record the rationale and any enhanced monitoring or restrictions. This trail is essential because later reviewers may assess not only whether a report was filed, but whether it was timely, meaningful and supported by the bank's own data.
Sanctions and targeted financial sanctions in Singapore
Sanctions controls require another separation of concepts. Screening a name is a detection technique; targeted financial sanctions are legal restrictions implemented through applicable law. Singapore gives effect to relevant United Nations Security Council sanctions through domestic legal instruments. MAS publishes targeted-financial-sanctions material for financial institutions, but the bank still needs to identify the specific legal instrument, scope, designated party, ownership or control implication, prohibited activity and required action.
A name match should therefore not be the final decision. The bank first resolves identity: is the customer, beneficial owner, counterparty, vessel, bank or other party actually the designated subject? It then assesses legal applicability: which Singapore instrument or other jurisdiction's measure applies to this legal entity and transaction? It then determines the required operational outcome, which may involve rejecting, freezing, blocking, restricting, escalating, reporting or obtaining legal guidance depending on the regime and facts.
Regional payments make this more complex. A Singapore bank may process a transaction involving a customer in one ASEAN country, a supplier in another, a correspondent bank elsewhere and a currency that introduces an additional sanctions nexus. The bank should not assume that the strictest rule always legally applies, nor should it ignore group policy that may deliberately set a higher risk standard than local law. The case record should distinguish legal obligation from bank risk appetite.
For technology teams, the country-rule registry should include sanctions source, list source, ownership/control rule, effective date, legal-entity scope, action taxonomy and escalation owner. Screening engines should preserve the list version and rule version used at the time of decision. If a designation changes while a payment is held, the bank should be able to reconstruct both the original and current state.
COSMIC: useful information sharing with legal boundaries
COSMIC, the Collaborative Sharing of ML/TF Information & Cases platform, is an important Singapore development because it addresses a long-standing weakness in financial-crime control: one institution may see only one part of a network. The platform allows prescribed participating financial institutions to share specified customer-risk information within a legal framework and subject to safeguards. It should not be taught as an unrestricted database of suspicious customers or as an ASEAN-wide utility.
The legal threshold and permitted-use conditions matter. Information sharing is not justified simply because an analyst is curious or because a customer is difficult. The participating institution needs to apply the legislation, MAS requirements and its internal procedures, including the relevant objectively defined indicators and confidentiality safeguards. Access, use, onward handling and retention of COSMIC information need strong controls because legitimate customers' information is also sensitive.
From a system-design perspective, COSMIC should be treated as a controlled source and controlled outbound channel. The case-management platform should record why a query or sharing action was permitted, who authorised it, what information was obtained or provided, how it influenced the risk assessment and what restrictions apply to the information. It should not simply copy all COSMIC content into every downstream warehouse where purpose limitation and access control become difficult to enforce.
COSMIC also does not replace STRO. A bank may use information obtained through lawful sharing to improve its risk assessment, but a separate decision is still required on whether the facts give rise to a suspicious-transaction-reporting obligation. Likewise, COSMIC does not replace customer due diligence, transaction monitoring, sanctions screening or law-enforcement cooperation. It is one capability in a broader control architecture.
The regional ASEAN layer
ASEAN cooperation is becoming more relevant to financial crime, particularly because criminal networks, scams, cyber-enabled fraud, informal value transfer, trade flows and mule activity routinely cross national borders. The ASEAN Senior Officials Meeting on Transnational Crime has established a Working Group on Money Laundering, with its concept adopted in September 2025 and its inaugural meeting scheduled for 2026. The stated purpose is to support implementation, information exchange and practical cooperation among Member States.
That development should not be misread as harmonised banking regulation. The Working Group is a cooperation mechanism. National governments remain responsible for domestic AML/CFT laws, supervisors, FIUs and enforcement. For a bank, the operational consequence is that regional intelligence and policy direction can inform risk assessment, but the actual control obligation must still be mapped country by country.
The Asia/Pacific Group on Money Laundering is also relevant but distinct from ASEAN. APG is a FATF-style regional body with membership extending beyond Southeast Asia. Its mutual evaluations, typologies and implementation work can help a bank understand country risk and supervisory maturity, but APG membership does not create one ASEAN legal standard. Mixing these institutions in policy documents creates confusion about authority and can lead to incorrect system requirements.
A regional operating model should therefore use a shared control framework with local overlays. The shared framework may define minimum CDD data, screening principles, transaction-monitoring governance, case-quality standards, recordkeeping, management information and escalation. The local overlay then changes what must change: thresholds, local lists, reporting route, reporting deadline, language, record retention, beneficial-ownership rules, PEP requirements, data-sharing constraints, regulator notifications and specific customer restrictions.
Where the risk appears across customer and payment lifecycles
At onboarding, the most important issue is reliable identity and ownership. Regional corporate structures can involve holding companies, nominee arrangements, trusts, complex ownership chains and directors in several jurisdictions. The bank needs to know not only the registered entity but the natural persons who ultimately own or control it, the purpose of the relationship, expected products, expected countries and counterparties, source of funds where relevant, and the commercial rationale for the structure.
During the relationship, changes can be more revealing than static risk scores. New beneficial owners, new directors, rapid expansion into higher-risk corridors, use of unfamiliar intermediaries, sudden movement into digital assets, unexplained trade patterns or large incoming funds followed by rapid onward transfers can all change the risk picture. Event-driven review should therefore connect customer-master changes with monitoring and case management rather than leave periodic review as the only refresh mechanism.
Payments introduce routing and speed. A domestic-looking credit transfer can still carry cross-border risk through ultimate parties, correspondent banks, funding sources or downstream movement. ISO 20022 can provide structured party and agent data, but only if source systems populate it accurately and mappings preserve the data. Screening and monitoring should distinguish the customer, debtor, creditor, ultimate parties, agents and free-text context instead of flattening them into one string.
Trade finance introduces a different evidence set: invoices, bills of lading, shipping routes, goods descriptions, counterparties, ports, vessels and financing instruments. Singapore's role as a trading hub makes trade-based laundering and sanctions-evasion risk especially important. The bank is not expected to become a customs authority, but it should understand whether the documents, customer profile, goods, route and payment economics tell a coherent story.
Wealth management introduces complex source-of-wealth and cross-border asset issues. The risk may sit in trusts, investment vehicles, private companies, family structures, third-party transfers or assets acquired in several jurisdictions. A high-value relationship should not be assessed solely through customer nationality. The better question is whether the source of wealth is plausible, evidenced and consistent with observed activity, and whether connected parties or structures introduce corruption, sanctions, tax-crime or fraud risk.
Digital-payment-token and virtual-asset activity adds another layer. Singapore's Virtual Assets Risk Assessment highlights cyber-enabled fraud, ransomware, wallet theft and money laundering among relevant threats. For a bank, the control challenge includes identifying regulated counterparties, understanding fiat-to-crypto and crypto-to-fiat flows, linking wallet-related activity to customer purpose where data allows, and recognizing rapid movement designed to reduce recovery time. Virtual-asset exposure should be risk-assessed, not automatically equated with criminality.
Fraud, scams and AML: connected but not identical
Singapore's current risk assessments give substantial attention to fraud and cyber-enabled scams. Banks therefore need strong bridges between fraud operations and AML investigations. A scam victim's payment may become a mule account's incoming credit, which may then be layered through other accounts, converted into digital assets or remitted across borders. Fraud and AML teams may see different points in the same chain.
The legal and operational outcomes can nevertheless differ. Fraud controls may focus on stopping a payment, authenticating a customer, contacting a victim, freezing a mule account or attempting recovery. AML controls focus on suspicious activity, criminal proceeds, customer risk, network analysis and reporting to the FIU. Sanctions controls focus on prohibited parties or activities. A common case platform can support all three, but the decision types should remain distinct.
This separation is especially important for instant payments. A fraud engine may have milliseconds or seconds to decide whether to challenge or hold a transaction. An AML investigation may take much longer because it considers a history of behaviour and connected accounts. The architecture should allow real-time signals to feed post-event AML analytics without pretending that a full AML investigation can occur inside the payment latency budget.
Regional mule networks make information sharing valuable. A customer may receive scam proceeds in Singapore and send them to another ASEAN jurisdiction before the first victim report arrives. The bank should have defined processes for internal network analytics, cross-border escalation within the group, lawful information sharing, recall or recovery attempts and law-enforcement cooperation. The process must respect local confidentiality and data-sharing law rather than assume that group ownership gives unrestricted access to all customer data.
Data and system architecture
A strong regional financial-crime platform starts with data lineage. Customer data should include legal-entity identifiers, account relationships, beneficial ownership, authorised signatories, expected activity and risk attributes. Transaction data should preserve payer, payee, amount, currency, timestamp, channel, payment identifiers, agent chain, remittance information and status. Trade systems should contribute goods, documents, shipping and counterparty information where relevant. Screening systems should preserve matched list data and matching rationale. Case systems should preserve decisions and evidence.
The next layer is the jurisdiction service. Rather than hard-coding local rules independently in every application, mature banks maintain a controlled rules or obligation service that can answer questions such as: which reporting route applies to this legal entity; which sanctions sources are mandatory; which fields are required for this report; which retention period applies; which data may be transferred to a regional hub; and who must approve an exception. Not every rule can be automated, but the source of truth should be explicit.
Case management then becomes the place where the legal and factual stories meet. A case should show the customer, transaction or network trigger; the legal-entity and jurisdiction context; relevant local obligations; evidence reviewed; actions taken; approvals; reports filed; restrictions applied; and subsequent monitoring. The user should not need to open five systems and reconstruct the legal basis from memory.
Regional hubs need special care. A bank may centralise investigation operations in Singapore or another location while serving legal entities across ASEAN. Centralisation can improve expertise and consistency, but it does not move the legal obligation. The case workflow must route local decisions to authorised local owners where required and prevent data access that local law does not permit. Performed centrally and owned legally are different attributes.
Evidence and investigation discipline
A regional case is strongest when investigators build an evidence map rather than a narrative based on one red flag. Customer evidence may include incorporation records, beneficial ownership, business model, account purpose and source of funds or wealth. Transaction evidence may show counterparties, timing, velocity, corridors, amounts and onward movement. Trade evidence may show invoices, goods, shipping, ports and commercial terms. Screening evidence may show sanctions, PEP or adverse-media matches. External intelligence may include FIU feedback, regulator publications or reliable open-source information.
Each piece of evidence should be timestamped and sourced. A corporate registry extract obtained today may not describe ownership at the date of a six-month-old transaction. A sanctions list may have changed. A negative media article may have been corrected. A payment message may have been enriched or repaired after initiation. The system should preserve the version used in the decision where that version matters.
The investigator should also distinguish facts from inferences. The customer sent SGD 2 million to five new counterparties within two days is a fact if supported by transaction data. The customer is layering criminal proceeds is an inference that needs context and corroboration. Good case notes make this separation visible, which improves quality assurance and protects against confirmation bias.
Regional investigation also needs a clear request-for-information process. Questions should be specific: who is the ultimate beneficiary, what goods were supplied, why was a new intermediary introduced, why did the route change, what supports the stated source of funds, what is the relationship between two counterparties? Vague requests generate vague responses. The bank should record the question, response, evidence supplied, timing and whether the answer resolved the concern.
Decisioning and customer impact
Financial-crime controls affect real customers, so decisioning should distinguish legal necessity from precautionary review. A payment may be held because sanctions screening produced a potential match. An account may be restricted because the bank cannot complete required due diligence. A relationship may be exited because risk cannot be managed within appetite. An STR may be filed without telling the customer because confidentiality and tipping-off rules apply. These actions have different legal and operational bases and should not share one generic compliance blocked reason.
Customer communication therefore needs controlled reason codes and scripts. Front-line staff should know what they may say, what they must not disclose and when legal or compliance approval is required. They should not invent explanations when an investigation is confidential. At the same time, the bank should avoid unnecessary opacity for ordinary remediation requests, such as asking a customer to update ownership documents or explain a transaction.
Operational teams need service-level rules that reflect risk. An instant-payment sanctions hit may require immediate decisioning. A periodic KYC refresh may have a longer timeframe. An STR decision may have a statutory urgency that differs from a routine monitoring alert. Backlog management should prioritise legal deadlines, sanctions exposure, customer harm, value at risk and network risk, not simply first-in-first-out ageing.
Management information should show more than volumes. Useful regional metrics include alerts and cases by legal entity and jurisdiction, age distribution, report conversion, sanctions-match outcomes, quality errors, overdue CDD, high-risk customer populations, cross-border network cases, data-quality defects, unresolved regulatory changes and customer-impact events. Metrics become dangerous when management optimises closure rates at the expense of investigation quality.
Governance and decision rights
A regional bank normally needs both group and local ownership. Group Financial Crime sets minimum standards, common methodologies, shared technology patterns and enterprise risk appetite. Local MLROs or equivalent accountable officers own or oversee jurisdiction-specific implementation and reporting. Legal interprets difficult questions. Operations execute workflows. Technology and data teams keep systems and lineage reliable. Internal audit provides independent assurance.
The model should identify who can accept risk, who can file a report, who can release a held payment, who can close a sanctions match, who can approve a high-risk customer, who can authorise information sharing and who can decide an exit. These are not merely workflow permissions; they are governance controls. Role design should be tested against real organisational authority.
Regulatory change should follow a closed lifecycle. The bank detects a change, assesses applicability, obtains legal interpretation where needed, identifies affected policies and systems, creates requirements, implements configuration or code, tests positive and negative scenarios, trains staff, deploys, and then verifies that the change works in production. The evidence pack should show the source text, interpretation, decisions, implementation artifacts, test results and effective date.
Country overlays should be reviewed when more than law changes. A new payment rail, merger, booking model, outsourcing arrangement, regional operations hub or customer segment can change applicability even if regulation is unchanged. Likewise, a new national risk assessment or FATF evaluation can require recalibration of risk-based controls without creating a new statute.
What a business analyst should capture
A business analyst working on Singapore or regional financial-crime change should begin with the legal and operating scope. Which legal entities are affected? Which products? Which customer types? Which channels? Which countries? Which regulator or FIU? What is the effective date? Which current process or system implements the obligation? What is changing? Those questions prevent requirements from becoming generic statements such as system shall comply with MAS and ASEAN rules.
Requirements should then translate obligations into testable behaviour. If a Singapore-bank customer triggers a reportable suspicion, the case platform must capture mandatory information, preserve supporting evidence, route approval to an authorised function, support SONAR submission or controlled hand-off, record submission status and protect report confidentiality. If a sanctions-list update arrives, the screening service must load it within the approved service level, validate record counts and checksums where applicable, rescreen in-scope parties according to policy, create cases for potential matches and preserve the list version.
For regional controls, a requirement should include the jurisdiction decision. A customer may be domiciled in Thailand, booked in Singapore and paid through a correspondent in another country. The case system needs to know which attribute drives which rule. Country = Thailand is not enough. The model may need customer domicile, account-servicing entity, booking entity, branch, payment origin, payment destination, agent location, currency and product location.
Acceptance criteria should include failure modes. What happens if the country-rules service is unavailable? If a sanctions list is late? If SONAR is unavailable? If a local FIU reporting gateway rejects a file? If beneficial-ownership data is missing? If one country's confidentiality rule prevents the regional hub from seeing a document? Safe degraded-mode behaviour should be designed before an incident rather than improvised during it.
Testing the regional control
Testing should prove both the common control and the local overlays. Positive tests verify that a Singapore-bank scenario invokes the correct Singapore rules, creates the right workflow and preserves evidence. Negative tests verify that the same rules are not incorrectly applied to a different legal entity. Boundary tests check effective dates, ownership thresholds, list changes, branch versus subsidiary logic and reporting cut-offs. Regression tests confirm that a change for one country does not silently alter another.
Data-quality testing is essential. Names, dates of birth, national identifiers, legal-entity identifiers, addresses and beneficial ownership must survive transformations between source systems and screening engines. Payment party roles must remain distinguishable. Country codes must not be overwritten by channel defaults. Historical ownership should be retrievable for lookback investigations. Testers should compare source-to-target values rather than rely only on UI screenshots.
Workflow testing should include entitlements and segregation of duties. An investigator should not automatically have authority to release a sanctions hold. A user allowed to prepare an STR may not be allowed to approve or submit it. COSMIC information may require restricted access. Local-country cases may need escalation to a local owner even if initial analysis is performed by a regional team.
Operational-resilience testing should cover external dependencies. SONAR, sanctions-list sources, identity services, corporate registries, case-management integrations and message feeds can fail. The bank should know which activities can queue, which must stop, which can use a controlled manual fallback and which require immediate escalation. Recovery should include reconciliation so that no cases or reports disappear between systems.
Mini case study: a Singapore corporate payment into the region
Consider a Singapore-incorporated trading company that has banked with a Singapore legal entity for three years. Its expected activity is regional import and distribution of industrial equipment. The company initiates a large payment to a newly added supplier in another ASEAN Member State. The payment itself is not prohibited and neither party produces a confirmed sanctions match. However, the transaction-monitoring system notes that the amount is unusually high, the beneficiary is new, the invoice description is vague and funds received the previous day from an unrelated overseas company are funding most of the payment.
The first control is not block because ASEAN. The bank identifies the booking entity and relevant Singapore obligations, checks customer profile and beneficial ownership, validates the payment parties and screening results, reviews the incoming source of funds and examines available trade documentation. It also checks whether the new supplier or connected parties create risk under the destination country's context and whether any correspondent or currency nexus introduces another sanctions regime under bank policy.
The investigator finds that the customer's majority shareholder changed two months earlier, but the KYC record was not updated. Corporate-registry information shows the new shareholder also controls the company that sent the previous day's incoming funds. The customer explains that both companies are part of a new group and the payment is for machinery. The invoice is real, but the goods description is too generic to confirm whether it matches the customer's stated business. The bank asks for ownership documents, purchase contract and shipping information.
The response confirms the group relationship but reveals that the shipment route and end user are different from the original explanation. This inconsistency does not prove money laundering, sanctions evasion or proliferation financing. It does create a stronger reason for review. The bank's sanctions and trade specialists assess goods, parties and route; the AML investigator analyses the flow of funds and linked entities; the local Singapore decision owner assesses whether the facts create a reportable suspicion. If the legal threshold is met, the bank files an STR to STRO through SONAR under its controlled reporting process. If COSMIC sharing conditions are met for a participating institution, that is assessed separately under the COSMIC legal framework; the bank does not treat COSMIC use as automatic.
The case is useful because it shows how several controls connect without collapsing into one. KYC identified stale ownership. Transaction monitoring identified unusual funding and payment behaviour. Screening checked parties. Trade review assessed commercial documents. Jurisdiction mapping identified the legal and reporting framework. The investigator built a case. Governance determined the decision. Reporting, if required, followed the Singapore FIU route. Regional context informed the risk but did not create an imaginary ASEAN STR or ASEAN sanctions list.
Common failure modes
The first failure mode is treating ASEAN as a single AML jurisdiction. It produces generic procedures, incorrect reporting routes and poor legal traceability. The second is applying Singapore requirements to every group entity merely because regional operations are centralised in Singapore. The third is the reverse: assuming a local entity is outside Singapore requirements even when a Singapore legal or transaction nexus is relevant.
Another failure is confusing cooperation mechanisms with legal permissions. A group bank may want to share customer intelligence across borders, but legal ability to do so depends on applicable confidentiality, secrecy, privacy, data-transfer and financial-crime provisions. COSMIC provides a specific Singapore framework for prescribed participants and defined circumstances; it is not a general permission to share data throughout ASEAN.
Weak data lineage is equally dangerous. If a screening engine cannot show which party field was screened, if an ownership percentage is overwritten rather than historically versioned, or if a country code reflects the user's device location instead of the customer or transaction, later investigators may draw the wrong conclusion. Financial-crime technology must preserve meaning, not just data values.
A final failure is measuring the programme only by throughput. Fast closure can hide poor investigations, late reports, weak escalation, excessive false positives or customer harm. Mature governance combines efficiency with quality, risk outcomes, legal timeliness, data integrity and remediation.
Key takeaways
Singapore has a strong and increasingly sophisticated financial-crime framework, but it is still a jurisdiction-specific framework. MAS supervision, STRO reporting, Singapore targeted financial sanctions, national risk assessments and COSMIC each have distinct roles. Banks need to map those roles accurately rather than use Singapore AML as one undifferentiated requirement.
ASEAN provides regional cooperation, including newer cooperation on money laundering, but it does not replace national law. A regional bank therefore needs a stable group standard plus effective-dated local country overlays for all eleven Member States. The same principle applies beyond ASEAN: global consistency should reduce unnecessary variation while preserving every variation that the law, regulator, product or local risk genuinely requires.
The strongest operating model connects obligations to data, controls, systems, cases, decisions, reports and evidence. It can explain why a Singapore rule applied, why another country's rule also mattered, what the bank did, who approved it and what the customer experienced. That traceability is what turns a regional policy into a defensible financial-crime control system.
Operational deep dive: turning regional policy into country-aware controls
The base chapter explains why a regional financial-crime programme cannot treat ASEAN as one legal jurisdiction. This deep dive follows that principle into the operating detail that usually creates delivery defects: legal-entity scoping, country overlays, FIU reporting, cross-border data access, payment routing and evidence quality.
Build the jurisdiction matrix before building workflow
A regional workflow should never begin with a country dropdown that has no defined legal meaning. The implementation team first needs a jurisdiction matrix that says what each country attribute represents. Customer domicile, incorporation country, branch location, booking entity, account-servicing entity, payment origin, payment destination, correspondent location, currency and transaction channel can all matter, but they do not all trigger the same rule.
Consider a customer incorporated in Indonesia, maintaining an account with a Singapore bank entity, initiating a USD payment to Vietnam through a US correspondent. The customer country is Indonesia, the account legal entity is Singapore, the beneficiary country is Vietnam and the payment introduces a US-dollar correspondent nexus. A single country = Indonesia field cannot support correct sanctions, reporting or local-policy decisions. Requirements should define which attributes drive which obligations and preserve all relevant values through the case lifecycle.
The jurisdiction matrix should also record the source and effective date of every local requirement. When a regulator changes a rule, the bank should be able to identify which customers, products, systems, procedures and open cases are affected. The change process then becomes a controlled impact assessment rather than a search through policy documents and spreadsheets.
Local reporting ownership and a regional investigation hub
Many banks centralise investigations because a regional hub can provide scale, specialist skills and consistent quality. Centralisation does not transfer statutory responsibility from one legal entity to another. A Singapore hub reviewing an alert for another ASEAN legal entity may perform analysis, but the local entity may retain responsibility for the final suspicion decision, FIU filing, regulator communication and recordkeeping.
The workflow therefore needs separate fields for investigation performed by, legal decision owner, reporting entity, FIU destination and submission status. Combining these into one queue owner creates ambiguity during audit. A case can be assigned to a Singapore analyst while still requiring approval by a local MLRO and submission through a different national FIU portal.
Singapore cases require their own route. Where the legal reporting threshold is met, STRs are filed to STRO electronically through SONAR. The case-management platform should prepare the investigator to file an accurate report, but it should not silently assume successful submission. Submission identifiers, acknowledgements, rejected filings, resubmissions and amendments need controlled handling. Access to SONAR should be restricted to authorised users and contingency procedures should exist for an outage.
Confidentiality also needs workflow controls. Staff who service the customer may need enough information to manage an account restriction or obtain documents, but they may not need to know that an STR was filed. User permissions, customer-facing reason codes and case notes should prevent accidental tipping off. Regional hubs make this harder because more teams can potentially see the same case, so access should follow need-to-know rather than organisational convenience.
Country overlays should change only what truly differs
An efficient regional programme does not create eleven completely separate AML platforms. It establishes common controls and then parameterises genuine local differences. Common elements may include customer-risk architecture, case-quality standards, sanctions-match investigation, transaction-monitoring governance, alert triage principles, control testing and management information. Local overlays change reporting routes, legal thresholds, sector-specific obligations, mandatory lists, retention periods, approval roles and other country-specific requirements.
This design avoids two opposite failures. Excessive local customisation creates duplicate technology, inconsistent terminology and difficult assurance. Excessive global standardisation can erase legal requirements. The correct design is common by default, local where justified, with every local deviation carrying an owner, source, rationale and review date.
A country configuration should be testable. If the Singapore legal entity is selected, the correct reporting destination and Singapore-specific control attributes should become available. If the same customer is booked to another legal entity, Singapore-only report options should not appear merely because the investigator sits in Singapore. Negative testing of this kind is as important as proving the happy path.
Cross-border data sharing and COSMIC are different questions
Regional banks often describe information sharing as if there were only one issue. In practice there are at least three. First, can one group entity share customer information with another group entity across borders? Second, can information be shared with another financial institution? Third, can information be disclosed to a regulator, FIU or law-enforcement body? Different legal permissions, restrictions and safeguards can apply to each.
COSMIC addresses a specific Singapore information-sharing framework for prescribed participating financial institutions and defined financial-crime circumstances. It does not automatically authorise a bank to distribute COSMIC-derived information to every affiliate in ASEAN. The case platform should therefore tag the source and handling restrictions of shared information. Downstream systems should receive only what is permitted and necessary.
This is also a data-lineage problem. If a COSMIC signal becomes a risk factor in a case, the reviewer should know that it came from COSMIC, when it was obtained, the permitted use, and which decision it informed. Copying the information into an unlabelled free-text note destroys that lineage and makes later access-control decisions difficult.
Payment screening and transaction monitoring need different regional logic
Screening typically asks whether parties or transaction data match sanctions or other risk lists and whether a legal or policy restriction applies. Transaction monitoring asks whether behaviour is unusual or suspicious when considered over time and against customer context. A regional platform should integrate their outputs without merging the questions.
For payment screening, important attributes include debtor and creditor names, addresses, ultimate parties where present, financial institutions in the agent chain, free text, vessel or trade data where relevant, currency and route. The disposition needs to record match quality, legal regime, list version and action. For monitoring, the system needs historical customer behaviour, peer context, velocity, counterparties, corridors, cash or trade patterns and links to related accounts.
A payment can pass sanctions screening and still be suspicious. It can also trigger a sanctions potential match without being suspicious in the AML sense. The investigator may later conclude both issues are relevant, but the system should preserve the distinct reasoning. This separation is particularly important when reporting obligations, customer communications and legal actions differ.
How to use national risk assessments intelligently
National risk assessments should change control focus, not create automatic guilt. Singapore's 2024 ML risk assessment highlights cyber-enabled fraud, foreign predicate crime, misuse of legal persons, banking and wealth-management exposure, cross-border money transfer and digital-payment-token risks. A bank can use those findings to challenge whether its customer-risk model, monitoring scenarios, staffing and training reflect current threats.
The right question is not Is this sector high risk? therefore reject. It is What vulnerabilities are material, what evidence would reduce uncertainty, and what control intensity is proportionate? A legitimate cross-border trading company may operate in a higher-risk environment while remaining well understood and transparent. Conversely, an apparently low-risk company can become concerning through opaque ownership, unexplained funding and unusual transaction behaviour.
The 2026 FATF/APG evaluation reinforces outcome-based thinking. A bank should be able to demonstrate that risk assessments influence resources, controls and decisions. If risk documents change but scenario coverage, due-diligence standards and QA findings remain unchanged, the programme may be procedurally complete but operationally static.
Investigation file quality for a multi-country case
A good regional investigation file should read like a reproducible decision. It identifies the booking entity and legal context, records the trigger, explains the customer's expected activity, maps counterparties and ownership, analyses the relevant transactions, states which country and sanctions rules were considered, records requests for information and preserves the response. It then separates fact, inference and unresolved uncertainty before documenting the final decision.
Investigators should avoid country-name shorthand such as high-risk ASEAN corridor. Country risk is not a substitute for transaction analysis and ASEAN is too diverse for a regional label to carry analytical value. If geography matters, the file should identify the specific jurisdiction, risk source, relevant typology and transaction connection.
Evidence should also remain historically accurate. If the customer changed ownership after the transaction, the investigator needs ownership at the transaction date. If sanctions lists changed, the bank needs the list version that applied at the decision point. If a regulator changed guidance, the case should show which version governed the activity. Effective dating is therefore part of financial-crime evidence, not merely configuration management.
What quality assurance should challenge
QA should sample more than whether required fields were populated. Reviewers should challenge whether the correct legal entity was selected, whether the right country overlays were applied, whether the investigator used relevant evidence, whether contradictory explanations were resolved, whether an STR decision was timely, whether confidentiality was protected and whether customer restrictions were proportionate.
Regional QA should also compare outcomes across countries. Large differences may be justified by law or risk, but they may also reveal inconsistent training, weak local governance or configuration errors. Comparison is a diagnostic tool, not a demand for identical outcomes.
The final control objective is straightforward: a bank should be able to explain a cross-border financial-crime decision without hiding behind the word regional. It should show exactly which entity acted, which law or policy applied, what evidence was considered, which local owner made the decision and how the outcome was executed.
Advanced practice: assurance, change and architecture
A mature regional programme is judged on whether its controls stay accurate when laws, sanctions measures, products and operating models change. The strongest assurance mechanism is an obligation-to-control inventory. For every material obligation, record the authoritative source, jurisdiction, legal entity, regulated activity, effective date, internal policy statement, implementing control, system or procedure, control owner and testing evidence. This makes regulatory change traceable rather than dependent on spreadsheets or individual memory.
For Singapore banking, that inventory should distinguish MAS supervisory requirements from statutory suspicious-transaction-reporting duties, targeted-financial-sanctions obligations and STRO reporting mechanics. It should also keep bank-specific requirements such as MAS Notice 626 separate from instruments applying to other regulated sectors. Across ASEAN, the same model applies country by country: group Financial Crime sets minimum standards, while local legal interpretation defines the required overlay.
Regulatory change as controlled delivery
A regulatory-change story should specify scope, effective date, affected customers and products, data requirements, decision logic, approval rights, reporting path, historical treatment and retained evidence. A change to beneficial-ownership rules, for example, can affect onboarding, periodic review, screening, customer-risk rating and remediation of existing customers. Testing should cover the rule before and after its effective date, including threshold boundaries and any lookback population.
Sanctions change needs a faster path. A new designation can require list ingestion, validation, rescreening, case creation and legal action without waiting for a normal release cycle. The bank therefore needs measurable service levels and a controlled fallback if its normal list source or screening service is unavailable.
Where a shared country-rules service drives regional workflows, that service is itself a financial-crime control. Configuration needs maker-checker approval, version history, effective dating and regression tests. A Singapore-only reporting option should appear for the appropriate Singapore entity, not merely because the investigator sits in Singapore. A local confidentiality restriction must remain effective even when analysis is centralised in a regional hub.
Information-sharing assurance
COSMIC and internal group information sharing are different legal questions. COSMIC should be tested against the conditions, users, indicators and safeguards of the Singapore framework. The case should record why sharing was permitted, what was exchanged, who accessed it and how it influenced the risk assessment. Use of COSMIC does not replace the separate decision on whether an STR must be filed to STRO.
Cross-border group sharing requires its own controls for secrecy, privacy, data transfer and need-to-know access. If a regional investigator cannot lawfully receive a document, the control should route the work to an authorised local reviewer rather than either copying the data anyway or abandoning the risk analysis.
Detection, incidents and independent review
Monitoring and screening calibration should reflect local risk without turning nationality into a proxy for suspicion. Teams should examine alert yield, report conversion, missed-issue analysis, scenario overlap, false positives, customer impact and typology coverage. Name screening should be tested across aliases, transliteration and data quality. Network or machine-learning models should remain explainable enough for a human decision maker to understand why a case was prioritised.
Incidents such as a failed sanctions feed, corrupted customer data, delayed alert generation or an unavailable FIU portal require a defined recovery population. The bank should know what must be rescreened or regenerated, how duplicates are prevented and whether prior decisions need reassessment. Backlog is also a control risk: ageing should be prioritised by legal deadline, sanctions exposure, customer harm and network risk rather than only first-in-first-out processing.
An independent reviewer should be able to select one cross-border case and trace it end to end: trigger, legal entity, country rules, data used, investigator reasoning, approval, customer action, reporting and evidence. The reviewer should then trace backwards from the case to the configuration and authoritative source. If that chain breaks, the programme has a design weakness even when the individual outcome happened to be correct.
Practice close: requirements and tests
The practical test is whether a learner can turn a regional financial-crime requirement into a jurisdiction-aware control without inventing a single ASEAN rulebook.
Before writing a requirement, identify the bank legal entity, regulated activity, customer and product scope, booking location, operational location, affected countries, authoritative source, effective date and decision owner. Then identify the data, workflow, reporting route and evidence needed to implement the obligation.
Support Singapore STR reporting is not yet testable. A good requirement explains which cases enter the process, which information must be captured, who may prepare and approve the report, how SONAR submission and acknowledgement are recorded, how confidentiality is protected and what happens if the channel is unavailable. Sanctions requirements should similarly prove list ingestion, identity resolution, applicable legal regime, disposition, audit trail and rescreening.
A useful test pack includes a Singapore customer booked to the Singapore bank entity; a non-Singapore customer booked to that entity; a customer booked to another ASEAN legal entity but investigated in a Singapore hub; and a payment with an additional currency or correspondent nexus. Positive tests prove the correct local workflow. Negative tests prove that Singapore-only actions are not triggered simply because the analyst sits in Singapore.
Failure-mode tests should cover unavailable SONAR access, a delayed sanctions list, missing beneficial-ownership data, a country-rules-service outage and a rejected FIU submission. The outcome should be safe, logged and reconcilable.
Several misconceptions should be rejected explicitly. ASEAN does not provide one AML rulebook. MAS Notice 626 is a core bank-sector instrument, not the universal notice for every Singapore financial institution. COSMIC does not replace reporting to STRO. A sanctions-screening hit is not automatically a confirmed designated party. A regional operations hub does not automatically own the local statutory obligation. A national risk assessment informs proportionate controls; it is not a customer blacklist.
For a final exercise, take a Singapore-booked corporate payment to a new supplier in another ASEAN Member State. Identify the relevant legal entity, country attributes, screening data, monitoring context, KYC and ownership evidence, decision owner, possible sanctions action, STR decision, permitted information-sharing route and customer communication. Then explain what would change if the account were booked to another ASEAN legal entity. If the answer distinguishes global standard, Singapore obligation, another country's overlay and bank risk appetite while preserving one coherent case story, the design is working.
Masterclass: the regional case that looked local
This case is fictional but built from common banking mechanics. It is designed to show how Singapore supervision, STRO reporting, sanctions controls and ASEAN country overlays interact without pretending that ASEAN itself is a single regulator.
A Singapore bank entity maintains an account for Meridian Components Pte Ltd, a regional distributor of industrial electronics. The customer has operated for four years and normally pays established suppliers in Malaysia, Thailand and Vietnam. Its KYC file records two Singapore-resident shareholders and expected annual cross-border turnover of SGD 18 million.
On Monday morning the customer receives SGD 3.8 million equivalent from a newly incorporated company in a third country. Less than six hours later, it instructs a USD payment for almost the same amount to a new supplier in another ASEAN Member State. The payment message contains a short description, industrial control equipment, and the transaction is funded almost entirely by the new incoming credit.
The sanctions-screening engine produces no confirmed match. A transaction-monitoring rule nevertheless creates an alert because the incoming and outgoing values are closely matched, both counterparties are new and the amount is outside the customer's historical range. The fraud platform also notes that the beneficiary account has recently received payments from several unrelated customers of the bank.
Step 1: establish legal and operating scope
The investigator first confirms that the account is booked to the Singapore bank entity. That makes the Singapore entity's AML/CFT framework central to the case. The beneficiary's location in another ASEAN country does not replace that Singapore nexus, although the destination-country context may inform risk and the bank's local affiliate may have information relevant to the beneficiary.
The investigator does not select a generic ASEAN AML rule. The case platform pulls the Singapore overlay, identifies the relevant reporting path to STRO if suspicion is reached, displays the bank's sanctions and trade-review requirements and records the destination-country overlay separately. The USD correspondent route is also visible because bank policy requires consideration of additional sanctions exposure.
Step 2: resolve the customer profile
The KYC record is six months old, but a corporate-registry refresh shows that one original shareholder transferred most of his interest to a foreign holding company eight weeks earlier. The customer had not notified the bank. The new holding company is not sanctioned, but public company information is limited and its ownership chain passes through two entities before reaching a natural person.
The investigator asks the KYC team to complete the ownership chain and checks whether the customer-risk rating remains appropriate. The team establishes the ultimate owner and finds no sanctions match, but the owner has business links to the company that sent the SGD 3.8 million incoming payment. This explains a connection that was not visible in the account profile, but it does not explain the economic purpose of the transfer.
Step 3: test the commercial story
Meridian states that the incoming funds were an intercompany advance and the outgoing payment purchases equipment for a new regional distribution contract. It provides an invoice and sales agreement. The invoice is genuine in form, but the goods description is broad and the delivery address is a warehouse not previously associated with the beneficiary.
The trade-finance specialist reviews the goods description, route and counterparties. Nothing in the documents establishes a prohibited item, but the specialist notes that some product categories can have sensitive applications and requests a more precise model description and end-user information. The objective is not to classify goods from keywords; it is to determine whether the transaction is commercially coherent and whether any sanctions or proliferation-financing concern requires specialist escalation.
Step 4: connect the payment network
Network analysis shows that the beneficiary has received similar same-day transfers from four other companies over three weeks. Two of those companies bank with the same Singapore institution, and one had previously generated an AML case involving unexplained third-party funding. The fraud signal about the beneficiary is therefore not merely a customer-protection issue; it becomes useful AML context.
The investigator checks whether internal information can be combined under the bank's approved controls and whether any external information-sharing step is legally available. COSMIC is considered only under the Singapore legal framework and the bank's participant procedures. The investigator does not assume that the existence of COSMIC authorises unrestricted querying or regional dissemination.
Step 5: decide and document
The combined facts now include stale ownership information, a new related-party funding source, rapid pass-through of value, an unfamiliar beneficiary, weak initial trade descriptions and a beneficiary network with related financial-crime concerns. None of those facts alone proves criminal conduct. Together they create a pattern the investigator cannot reasonably reconcile with the previously understood account purpose without stronger evidence.
The Singapore decision owner reviews the case and determines that the legal suspicion threshold is met under the bank's approved interpretation. An STR is prepared and submitted to STRO through SONAR. The report describes the parties, ownership change, transactions, linked cases and unanswered commercial questions. It does not state as fact that the customer is laundering money or breaching sanctions.
The bank separately decides how to handle the payment and relationship. The payment is not automatically frozen merely because an STR is filed. Sanctions specialists find no legal freezing trigger on the information available. The bank applies an account restriction and enhanced review under its risk policy while obtaining additional information. Customer communication uses approved wording and does not disclose the STR.
Step 6: learn from the case
The post-case review identifies two control weaknesses. First, the beneficial-ownership change should have triggered event-driven KYC earlier. Second, transaction-monitoring rules detected the rapid pass-through only after the outgoing instruction was created; network intelligence about the beneficiary was not available to the payment-risk layer in time to support earlier intervention.
The remediation backlog therefore contains a customer-master event feed, improved ownership-change triggers and a controlled beneficiary-risk interface between fraud and AML analytics. None of those changes requires inventing a regional rule. They improve the bank's ability to apply the correct Singapore and local-country obligations using better evidence.
The masterclass lesson is that a cross-border case is rarely solved by one screen or one jurisdiction label. The defensible outcome comes from legal scope, customer understanding, transaction evidence, trade context, network intelligence, controlled information sharing and accountable decisioning working together.
References and further reading
These public, authoritative sources were used for this chapter. Singapore requirements should be interpreted against the current law, MAS instrument and the bank's approved legal guidance. ASEAN cooperation does not replace the domestic law of each Member State.
- Financial Action Task Force and Asia/Pacific Group on Money Laundering, Mutual Evaluation Report of Singapore 2026: https://www.fatf-gafi.org/en/publications/Mutualevaluations/mer-singapore-2026.html
- Monetary Authority of Singapore, Anti-Money Laundering regulatory hub: https://www.mas.gov.sg/regulation/anti-money-laundering
- Monetary Authority of Singapore, Targeted Financial Sanctions: https://www.mas.gov.sg/regulation/anti-money-laundering/targeted-financial-sanctions
- Monetary Authority of Singapore, COSMIC: https://www.mas.gov.sg/regulation/anti-money-laundering/cosmic
- Singapore Police Force, Suspicious Transaction Reporting Office: https://www.police.gov.sg/Advisories/Commercial-Crimes/Suspicious-Transaction-Reporting-Office
- Singapore Police Force, Suspicious Transaction Reporting: https://www.police.gov.sg/Advisories/Commercial-Crimes/Suspicious-Transaction-Reporting-Office/Suspicious-Transaction-Reporting
- Singapore Police Force, STRO Online Notices And Reporting platform (SONAR): https://www.police.gov.sg/SONAR
- Singapore Ministry of Finance, Singapore Publishes Updated Money Laundering National Risk Assessment, 20 June 2024: https://www.mof.gov.sg/news-resources/newsroom/singapore-publishes-updated-money-laundering-national-risk-assessment/
- Singapore Ministry of Finance, Singapore Publishes National Anti-Money Laundering Strategy, 30 October 2024: https://www.mof.gov.sg/news-resources/newsroom/singapore-publishes-national-anti-money-laundering-strategy/
- Singapore Ministry of Finance, Virtual Assets Risk Assessment, 30 October 2024: https://www.mof.gov.sg/news-resources/newsroom/virtual-assets-risk-assessment/
- Singapore Ministry of Finance, Singapore Refreshes the Terrorism Financing National Risk Assessment and National Strategy for Countering the Financing of Terrorism: https://www.mof.gov.sg/news-resources/newsroom/singapore-refreshes-the-terrorism-financing-national-risk-assessment-and-national-strategy-for-countering-the-financing-of-terrorism/
- ASEAN, Senior Officials Meeting on Transnational Crime, including the Working Group on Money Laundering: https://asean.org/senior-officials-meeting-on-transnational-crime-somtc/
- ASEAN, Timor-Leste admitted as the 11th ASEAN Member State, 26 October 2025: https://asean.org/forging-a-new-era-timor-leste-admitted-into-asean/
- Asia/Pacific Group on Money Laundering, official website: https://www.apgml.org/
- Financial Action Task Force, The FATF Recommendations: https://www.fatf-gafi.org/en/publications/Fatfrecommendations/Fatf-recommendations.html
- Basel Committee on Banking Supervision, Sound management of risks related to money laundering and financing of terrorism: https://www.bis.org/bcbs/publ/d505.htm
- Egmont Group, Financial Intelligence Units and international cooperation: https://egmontgroup.org/
- For Singapore banks, MAS Notice 626 is a core AML/CFT instrument. The Singapore Police Force's official reporting page identifies MAS Notice 626 and its guidelines for commercial banks, while other regulated sectors use different MAS notices. Retrieve the current version from MAS before implementation: https://www.police.gov.sg/Advisories/Commercial-Crimes/Suspicious-Transaction-Reporting-Office/Suspicious-Transaction-Reporting