The Monetary Authority of Singapore (MAS) has introduced new guidelines setting out its supervisory expectations for the annual audits of licensed payment service providers under the Payment Services Act 2019. The requirements will apply to audits for financial years ending on or after 31 December 2026, with the first affected Form 4 submissions due from 30 June 2027.
The new guidance, designated PS-G04: Guidelines on Audit of Payment Service Providers, establishes a more structured framework for the scope, conduct and reporting of regulatory audits. It identifies the reports that payment service providers are expected to submit and prescribes baseline and mandatory areas that must be addressed during each annual audit.
A revised Form 4 is expected to be made available through the MAS Financial Institutions Transactions Platform, or MAS-Tx, in the second quarter of 2027. MAS-Tx is the regulatory platform used by financial institutions for specified filings and submissions to MAS.
Key audit and compliance implications
More consistent regulatory audit coverage
The guidelines are expected to promote greater consistency in how auditors assess payment service providers. Audit planning will need to incorporate the prescribed baseline and mandatory areas rather than relying solely on a general risk-based scope agreed between the provider and its auditor.
Payment service providers should therefore review whether their current statutory or regulatory audit arrangements cover all areas required under the new guidance.
Greater emphasis on regulatory controls
The annual audit is likely to require clearer evidence that the provider has designed and operated appropriate controls to meet its obligations under the Payment Services Act and related regulatory requirements. Relevant areas may include safeguarding arrangements, regulatory reporting, transaction records, governance, risk management and other requirements applicable to the provider’s licence and payment services.
Management should not assume that evidence prepared for the financial statement audit will automatically be sufficient for the regulatory audit. The two engagements may have different objectives, scopes and materiality considerations.
Expanded responsibilities for external auditors
Audit firms accepting payment service provider engagements will need to ensure that their audit programmes address the compulsory coverage areas specified by MAS. Engagement teams may also require expertise beyond conventional financial statement auditing, particularly where the work involves regulatory compliance, information technology, transaction processing or operational controls.
The guidelines may consequently affect engagement scoping, staffing, fees and reporting timelines.
Potential interaction with financial reporting
Although the MAS audit is primarily regulatory in nature, findings may also be relevant to the financial statement audit. Control deficiencies involving customer monies, transaction completeness, reconciliations or regulatory reporting could indicate broader risks affecting account balances, disclosures, provisions or the assessment of regulatory compliance.
Auditors should establish procedures for evaluating whether regulatory audit findings have implications for the financial statements or the auditor’s report.
Practical issues
- Determining the applicable audit scope: Providers will need to map the mandatory coverage requirements to their specific licence categories, payment services, operating model and use of third-party service providers.
- Availability of audit evidence: Existing records may not provide sufficiently clear or complete evidence that controls operated throughout the financial year. Providers may need to strengthen reconciliations, control logs, approval records and exception-management documentation.
- System and data readiness: Regulatory audit procedures may require detailed transaction-level information from payment platforms, safeguarding systems and financial ledgers. Providers should assess whether such information can be extracted accurately and reconciled across systems.
- Reliance on outsourced service providers: Where key processes are outsourced, management remains responsible for demonstrating compliance. Contracts, service-level arrangements and assurance reports should provide adequate audit access and evidence.
- Coordination between audit workstreams: Providers using separate firms or teams for financial statement and regulatory audits should establish clear responsibilities, information-sharing protocols and reporting timetables.
- Timing of the revised Form 4: As the updated form is expected only in the second quarter of 2027, providers and auditors may have a limited period to familiarise themselves with its final format before the first submissions become due from 30 June 2027.
- Remediation before the effective date: Deficiencies identified during readiness reviews may require changes to policies, systems or control ownership. Providers should allow sufficient time for revised controls to operate before the first in-scope financial year closes.
Action points
Payment service providers with a financial year ending on 31 December should begin preparations during 2026 rather than waiting until the revised Form 4 is released. Management should:
- obtain and review the PS-G04 requirements in detail;
- compare the required audit coverage against the existing regulatory audit programme;
- perform a readiness or gap assessment of relevant policies, controls and documentation;
- confirm the scope and timetable with the appointed auditor;
- address system, data-retention and third-party assurance gaps; and
- brief the board or appropriate governance committee on implementation progress and significant deficiencies.
Audit firms should update their methodologies, develop appropriate testing procedures and evaluate whether engagement teams possess the necessary regulatory and technology capabilities.
Conclusion
The new guidelines represent a move towards a more standardised and comprehensive regulatory audit framework for Singapore payment service providers. Although the requirements take effect only for financial years ending from 31 December 2026, early preparation will be important because providers may need to improve documentation, system reporting and operational controls before those controls can be tested over an appropriate period.
Providers and auditors should refer to the final PS-G04 document and revised Form 4 from MAS website to confirm the precise scope, reporting format and submission instructions.