Catalog / DPT Platform

DPT Platform MAS PSA · Digital Payment Token

Platform audit for MAS-regulated Digital Payment Token service providers — custody, deposit and withdrawal, and the PSA compliance obligations.

10
domains
26
controls
26
tests the agent runs

Control catalog

Deposit & Withdrawal Controls

DW · 3 controls
  • DW-001

    All deposits are accurately captured and credited only after sufficient

    Ensure all deposits are accurately captured and credited only after sufficient blockchain confirmations, with automated reconciliation.

  • DW-002

    All withdrawals are initiated by authenticated, authorized customers and processed

    Ensure all withdrawals are initiated by authenticated, authorized customers and processed accurately to the correct destination after multi-control validation.

  • DW-003

    Erroneous transmission to incorrect or incompatible addresses through technical validation

    Prevent erroneous transmission to incorrect or incompatible addresses through technical validation and mandatory confirmation controls.

Wallet Management & Governance

WM · 3 controls
  • WM-001

    No single individual has end-to-end control over wallet creation, key

    Ensure no single individual has end-to-end control over wallet creation, key custody, and transaction signing, preventing insider theft or unauthorized fund movements.

  • WM-002

    Defined maximum limits on hot wallet balances relative to total

    Maintain defined maximum limits on hot wallet balances relative to total customer assets under custody, with automated alerts and documented rebalancing procedures.

  • WM-003

    Complete segregation of customer crypto assets from company operational funds

    Ensure complete segregation of customer crypto assets from company operational funds in separate, clearly labelled wallets with documented ownership records.

Crypto Balance Integrity

CB · 3 controls
  • CB-001

    Customer balance records are accurate, complete, and consistent with on-chain

    Ensure customer balance records are accurate, complete, and consistent with on-chain holdings through automated reconciliation and data integrity controls.

  • CB-002

    Unauthorized manipulation of customer balances through access controls, monitoring,

    Prevent unauthorized manipulation of customer balances through access controls, monitoring, and an audit trail enabling detection and attribution of all balance changes.

  • CB-003

    Zero unexplained variance between on-chain holdings and internal ledger balances

    Achieve and maintain zero unexplained variance between on-chain holdings and internal ledger balances through automated daily reconciliation with documented variance resolution.

Gas Fee Accounting

GF · 2 controls
  • GF-001

    All gas fees are accurately captured, correctly allocated between company

    Ensure all gas fees are accurately captured, correctly allocated between company and customer accounts, and reported accurately in financial records.

  • GF-002

    Unauthorized modification of gas fee calculation parameters through access controls

    Prevent unauthorized modification of gas fee calculation parameters through access controls and change management procedures.

Key Management & Storage

KM · 2 controls
  • KM-001

    All private keys controlling customer assets are stored in tamper-resistant

    Ensure all private keys controlling customer assets are stored in tamper-resistant hardware security modules (HSMs) with no unencrypted key material in software memory or files.

  • KM-002

    A comprehensive cryptographic key lifecycle policy covering generation, rotation, revocation

    Establish and enforce a comprehensive cryptographic key lifecycle policy covering generation, rotation, revocation, backup, and disaster recovery.

AML/CFT Compliance

AC · 3 controls
  • AC-001

    Robust, risk-based transaction monitoring to detect, investigate, and report suspicious

    Implement robust, risk-based transaction monitoring to detect, investigate, and report suspicious transactions in accordance with MAS Notice PSN02.

  • AC-002

    Real-time screening of all customers and counterparties against applicable sanctions

    Ensure real-time screening of all customers and counterparties against applicable sanctions lists with immediate blocking of flagged transactions.

  • AC-003

    Timely and accurate filing of STRs with STRO for all

    Ensure timely and accurate filing of STRs with STRO for all transactions suspected of being related to money laundering, terrorist financing, or criminal proceeds.

KYC / KYT Compliance

KY · 2 controls
  • KY-001

    All customers are identified, verified, and risk-rated prior to account

    Ensure all customers are identified, verified, and risk-rated prior to account activation in accordance with MAS Notice PSN02 Customer Due Diligence requirements.

  • KY-002

    Blockchain analytics to assess risk of on-chain transactions and block

    Deploy blockchain analytics to assess risk of on-chain transactions and block or flag those with exposure to high-risk entities or activities.

MAS / PSA Compliance

MAS · 4 controls
  • MAS-001

    Full compliance with MAS PSA licensing conditions including ongoing obligations

    Maintain full compliance with MAS PSA licensing conditions including ongoing obligations related to capital, notifications, and conduct of business.

  • MAS-002

    Required base capital and liquid asset requirements at all times

    Maintain required base capital and liquid asset requirements at all times, with compliant safeguarding of customer funds in approved institutions.

  • MAS-003

    Full compliance with the Travel Rule for all applicable DPT

    Ensure full compliance with the Travel Rule for all applicable DPT transfers including accurate collection, transmission, and receipt of required information.

  • MAS-004

    A technology risk management framework aligned with MAS TRM Guidelines

    Implement and maintain a technology risk management framework aligned with MAS TRM Guidelines covering system security, resilience, and third-party risk.

Cybersecurity & Access Controls

CYB · 2 controls
  • CYB-001

    DPT platform systems from unauthorized access through robust identity

    Protect DPT platform systems from unauthorized access through robust identity and access management, privileged access management, and network security controls.

  • CYB-002

    All APIs for blockchain interactions and customer-facing services are secured

    Ensure all APIs for blockchain interactions and customer-facing services are secured with appropriate authentication, encryption, rate limiting, and input validation.

Reconciliation & Reporting

RR · 2 controls
  • RR-001

    A three-way reconciliation process (on-chain > internal ledger > financial

    Establish and maintain a three-way reconciliation process (on-chain > internal ledger > financial accounting) daily with documented variance resolution.

  • RR-002

    All required regulatory reports are filed with MAS accurately

    Ensure all required regulatory reports are filed with MAS accurately and within prescribed timelines with a documented reporting governance framework.

See DPT Platform tested against your evidence.