Bulletin: MAS PS-G04 – Guidelines on Audit of Payment Service Providers

MAS PS-G04
Introduction

This bulletin provides an overview of the Monetary Authority of Singapore (MAS) Guidelines PS-G04, highlighting the annual external audit requirements and submission obligations applicable to Payment Service Providers. It outlines MAS’ expectations for demonstrating the operational effectiveness of key controls, complying with prescribed reporting deadlines, and implementing immediate escalation procedures for any identified critical gaps or deficiencies.  This also covers the mandatory end-to-end audit review requirements for both new licensees and existing licensees.


Key Requirements & Governance Highlights

1. Audit, Reporting & End-to-End Review Requirements

  • Regulatory Submission: Submit Form 4, audited financial statements, an Independent Assurance Report (SSAE 3000/AGS1), and a Management Letter within 6 months of FYE.
  • External Auditor Requirement: Appoint one qualified external auditor to conduct all required audit engagements.
  • Annual Audit Scope: Assess customer fund safeguarding, capital compliance, PSN04 reporting accuracy, exempted product eligibility, and remediation of prior findings.
  • End-to-End Audit Review: Newly licensed PSPs and PSPs introducing new payment services must undergo an end-to-end audit review within 1 year of commencing operations or introducing the new payment service.
  • Review Scope: Cover AML/CFT controls and technology risk management, including key governance, monitoring, security, and resilience measures.

2. Immediate Reporting Obligations

  • Auditor Escalation: Auditors must promptly report significant issues to MAS, including safeguarding failures, capital breaches, unauthorised changes to key personnel, fraud, and major risk management weaknesses.
  • PSP Reporting Duty: PSPs must independently and immediately notify MAS of material breaches or control deficiencies and cannot rely solely on auditor notifications.

What This Means for Your Business

Business Impact

Non-compliance may expose your business to heightened regulatory scrutiny, financial penalties, operational disruption and, in severe cases, licence suspension or revocation. PSPs should therefore ensure that their controls, reporting processes and audit readiness are sufficiently robust to meet MAS expectations from the outset.

How BDO Singapore Can Support Your Business

At BDO Singapore, we combine strong local expertise with the global reach of the world’s fifth-largest accounting network to help Payment Service Providers (PSPs) meet the audit and assurance requirements set out in MAS PS-G04. Our integrated assurance approach goes beyond regulatory compliance by helping organisations strengthen governance, enhance risk management and build operational resilience.

  • Local Expertise, Global Reach: Established in Singapore in 1972, BDO combines strong local market knowledge with the resources of a global network spanning 164 countries, enabling seamless support for both local and cross-border operations.
  • Multidisciplinary Capabilities: Our specialists across Assurance, Financial Services, Technology & Risk Advisory, Corporate Governance, and Tax provide holistic support for complex regulatory requirements.
  • Single-Auditor Solution: We deliver a fully integrated engagement covering the statutory financial audit, SSAE 3000 (Revised)/AGS 1 Independent Assurance Report, and regulatory management letter in line with MAS requirements.
  • Fintech & Regulatory Focus: Our tailored audit approach assesses safeguarding controls, payment processes, and PSN04 Form 4 reporting to support regulatory compliance and data integrity.
  • Practical, Actionable Insights: We provide clear recommendations and remediation plans to help address control gaps and strengthen governance ahead of regulatory reviews.
  • Partner-Led Delivery: Senior partners and directors remain actively involved throughout the engagement, ensuring responsive service, quality oversight, and trusted advice.