Running a cryptocurrency exchange in Singapore used to feel like navigating a gray area. You could set up shop, serve clients overseas, and fly under the radar. That era ended abruptly on June 30, 2025.
The Monetary Authority of Singapore is a global financial hub with one of the world's most comprehensive cryptocurrency licensing frameworks closed that loophole for good. With the implementation of the Financial Services and Markets Act (FSMA), the regulatory landscape shifted from permissive to precise. If you are planning to launch or operate a digital asset platform here, understanding these new rules isn't just legal advice-it's survival.
This guide breaks down exactly what you need to know about getting licensed, the capital you must hold, and why the regulators are cracking down now. We will look at the two main laws governing this space, the specific licenses available, and how to navigate the application process without wasting months on rejected submissions.
The Two Pillars of Regulation: PSA and FSMA
To get your license, you first need to understand which law applies to your business model. In Singapore, crypto regulation rests on two primary legislative instruments: the Payment Services Act 2019 (PSA) and the newer Financial Services and Markets Act 2022 (FSMA).
The Payment Services Act 2019 is the foundational legislation governing payment service providers, including those handling digital tokens has been the backbone of crypto regulation since 2020. It categorizes businesses based on their transaction volume and operational scope. Most exchanges start here. The PSA requires you to prove you can handle money safely, prevent fraud, and keep your customers' funds secure.
However, the game changed with the Financial Services and Markets Act 2022 is a comprehensive financial services law that introduced the Digital Token Service Provider framework to close regulatory loopholes. Effective June 30, 2025, FSMA introduced the Digital Token Service Provider (DTSP) framework. This was a direct response to high-profile collapses like Three Arrows Capital and Terraform Labs. The regulator, known as the Monetary Authority of Singapore is the central bank and financial regulatory authority of Singapore responsible for enforcing financial integrity (MAS), made it clear: if you are based in Singapore, you follow Singaporean rules, even if your clients are abroad. No more "offshore-only" exemptions.
Choosing Your License Type Under the PSA
If your business involves transferring money or dealing in virtual payment tokens, you likely fall under the PSA. The type of license you need depends entirely on your monthly transaction volume. There are three distinct categories.
| License Type | Monthly Transaction Limit | Minimum Capital Requirement | Key Obligations |
|---|---|---|---|
| Standard Payment Institution (SPI) | Up to SGD 3 million | SGD 100,000 | Basic customer due diligence, regular reporting, standard AML protocols |
| Major Payment Institution (MPI) | Exceeds SGD 3 million | SGD 250,000 | Enhanced risk management, comprehensive auditing, stricter operational standards, advanced monitoring |
| Exempt Payment Service Provider | Specific low-risk activities | Varies (Notification only) | Limited scope operations, specific restrictions, notification to MAS required |
Most serious exchanges will aim for the Major Payment Institution (MPI) license. Why? Because once you hit that SGD 3 million monthly threshold, you have no choice. But even if you start small with an SPI, be prepared to upgrade quickly. The MPI license demands significantly more from you. You need SGD 250,000 in minimum capital, but the real cost lies in compliance. You will need advanced risk management systems, comprehensive internal audits, and a robust team dedicated to monitoring transactions.
The New Reality: DTSP Framework and Anti-Arbitrage
Here is where many founders trip up. Before mid-2025, some companies registered in Singapore but operated solely for foreign clients, arguing they didn't need full local oversight. MAS shut that door firmly with the DTSP regime.
Under the FSMA, the DTSP framework covers two major entity types immediately, with zero transitional period. This means if you were operating in a gray area, you had four weeks-from the final consultation response on May 30, 2025, to the June 30 deadline-to comply or cease operations. Chengyi Ong, head of Asia Pacific policy at Chainalysis, noted that MAS is reinforcing that "financial integrity is a red line." The goal is simple: insulate Singapore from reputational risk. They do not want illicit activity flowing through their jurisdiction, even if the end-user is in another country.
This approach differs sharply from other regions. Unlike the European Union's MiCA regulation, which offered longer timelines for adaptation, Singapore moved fast. Compared to the United States' fragmented state-by-state approach, Singapore offers a unified national standard. And while Switzerland has higher capital barriers-often reaching millions of francs-Singapore’s SGD 100,000 to SGD 250,000 requirements make it more accessible, provided you can meet the stringent operational standards.
Anti-Money Laundering: The Non-Negotiable Core
You cannot get a license without rock-solid anti-money laundering (AML) procedures. This is governed by MAS Notice PSN02. Think of this as the baseline for trust. Regulators expect crypto platforms to operate with the same rigor as traditional banks.
Your AML framework must include:
- Comprehensive Customer Verification: Know Your Customer (KYC) isn't optional. You need detailed identity verification processes.
- Ongoing Transaction Monitoring: Real-time tracking of suspicious patterns. If a wallet moves funds in a way that looks like layering or structuring, your system must flag it.
- Suspicious Activity Reporting: Mandatory reporting to authorities when irregularities are detected.
- Risk Assessment Protocols: Regular updates on potential threats and mitigation strategies.
MAS Notice PSN02 mandates that these aren't just paper policies. They must be actively enforced. Auditors will check your logs. If your monitoring system missed a obvious red flag, your license is at risk.
Navigating the Application Process
Applying for a license is not a fill-in-the-blank form. It is an extensive documentation exercise. Based on industry feedback and current timelines, here is what you should expect.
Timeline Expectations:
- Standard Payment Institution (SPI): Typically takes 3 to 6 months with professional legal support.
- Major Payment Institution (MPI): Can extend to 6 to 12 months due to enhanced due diligence and deeper scrutiny of your risk models.
Required Documentation:
You will need to submit a comprehensive business plan. This isn't a pitch deck for investors; it's a strategic roadmap for regulators. It must cover your mission, business model, projected revenues, and detailed marketing strategies. You also need Singapore-compliant KYC and AML policy documents. These must outline exact procedures for customer verification and financial crime prevention.
Don't forget the technical side. You must demonstrate how you secure customer funds. This includes cold storage solutions, insurance coverage, and cybersecurity protocols. Risk assessment documentation is mandatory, detailing how you monitor market conditions and identify potential operational threats. Finally, you must prove you have the authorized capital ready. Bank statements or confirmed financial support letters are essential.
Many applicants face multiple submission rounds. MAS reviewers are thorough. If your risk mitigation strategy is vague, they will ask for clarification. Hiring experienced compliance consultants familiar with MAS expectations can save you months of back-and-forth.
Challenges and Industry Feedback
The transition hasn't been smooth for everyone. Smaller operators have struggled with the immediate implementation of the DTSP regime. Without a grace period, many faced rapid restructuring or decided to exit the market entirely. Reddit discussions in crypto communities highlight the frustration with the sheer volume of documentation required. Users report spending substantial amounts on legal and consulting fees just to prepare the initial application.
Larger exchanges, however, generally welcome the clarity. While they complain about the high compliance costs associated with MPI licenses, they appreciate the level playing field. Institutional users value the regulatory certainty. As one industry observer put it, the changes represent a "step toward consistency" rather than a crackdown. The key is that MAS has set the bar high. They will generally not issue a license for operations serving only overseas clients unless those operations meet the highest standards of supervision.
Future Outlook: Staying Compliant
As we move into late 2026, Singapore continues to position itself as a regulated crypto hub. While Hong Kong has introduced its own licensing framework, Singapore's first-mover advantage in comprehensive regulation gives it an edge. The trajectory suggests continued tightening. MAS has indicated that the focus will remain on substance over form. If your substantive regulated activity is outside Singapore, supervision becomes difficult, and licenses may be denied.
For well-capitalized, compliance-focused operators, the future looks bright. The regulatory clarity attracts institutional capital. For smaller, offshore-focused businesses, the market is becoming increasingly inaccessible. Success in Singapore now depends on treating compliance not as a hurdle, but as a core product feature.
What is the minimum capital required for a crypto exchange license in Singapore?
The minimum capital requirement depends on the license type. For a Standard Payment Institution (SPI) license, you need SGD 100,000. For a Major Payment Institution (MPI) license, which is required for larger operations exceeding SGD 3 million in monthly transactions, the minimum capital is SGD 250,000.
Can I operate a crypto exchange in Singapore if I only serve foreign clients?
Yes, but the rules have tightened significantly. Since the implementation of the Financial Services and Markets Act (FSMA) in June 2025, the Monetary Authority of Singapore (MAS) has closed the loophole that allowed firms to serve only offshore clients without full local oversight. You must still obtain a license and meet all compliance standards, including anti-money laundering (AML) requirements, regardless of where your clients are located.
How long does it take to get a crypto license in Singapore?
The timeline varies by license type. A Standard Payment Institution (SPI) license typically takes 3 to 6 months to process. A Major Payment Institution (MPI) license can take 6 to 12 months due to the more rigorous due diligence and enhanced compliance requirements involved.
What is the difference between the PSA and FSMA regulations?
The Payment Services Act (PSA) has been the primary framework since 2020, focusing on payment institutions and basic crypto operations. The Financial Services and Markets Act (FSMA), effective June 30, 2025, introduced the Digital Token Service Provider (DTSP) framework to address gaps in regulation, particularly for firms serving offshore clients. FSMA imposes stricter oversight and closes previous regulatory arbitrage opportunities.
Is Singapore's crypto regulation stricter than Europe's MiCA?
Singapore's approach is often seen as more immediate and stringent in terms of implementation speed. While the EU's MiCA regulation provides longer transitional periods for compliance, Singapore's DTSP regime took effect without a grace period. However, Singapore's capital requirements are lower than some other jurisdictions like Switzerland, making it more accessible for medium-sized operators who can meet the high operational standards.