The Answer in 60 Seconds

A payment services licence under the Payment Services Act 2019 does not make a commercial insurance policy a condition of the licence. What the Act compels is two things, and neither is an insurance policy in the ordinary sense. First, a major payment institution must maintain security with MAS for the due performance of its obligations to customers, furnished as a cash deposit or a bank guarantee. Second, an institution that handles customer money must safeguard that money, which it can do through an undertaking or guarantee from a safeguarding institution, or by holding the money in a trust account.

Read the definition and the point becomes plain: the safeguarding institution is a bank in Singapore or a prescribed financial institution, not a general insurer issuing a liability policy. So the safeguarding "undertaking" is a banking instrument, not the cyber, professional indemnity or directors and officers cover a payment firm might buy to protect itself.

The one insurance the law actually compels has nothing to do with the licence. Your firm is an employer, and under section 24 of the Work Injury Compensation Act 2019 every employer must take out and maintain approved work-injury cover for its staff. Cyber, professional indemnity and directors and officers cover are sensible for the real exposures a payment firm carries, but no statute ties them to the licence. The honest answer: the licence needs safeguarding and, for a major institution, security; the policy decisions are yours.

The Sourced Detail

The question "what insurance does my payment services licence need" hides four different things: the security a major payment institution lodges with MAS, the safeguarding of customer money the Act demands, the work-injury cover every employer owes its staff, and the commercial liability cover a payment firm would be unwise to skip. They get conflated because all four feel like "financial protection the licence forces on me". Only one is a commercial insurance policy the law compels, and it is not compelled by the licence at all. Sort them apart and the picture is clear.

Three licence classes, and what each one actually triggers

Under section 6 of the Payment Services Act 2019, a firm applies for one of three licences: a money-changing licence, a standard payment institution licence, or a major payment institution licence. A money-changing licence covers only a money-changing service. A standard or major payment institution licence is needed to provide the broader set of regulated payment services, which includes account issuance, domestic and cross-border money transfer, merchant acquisition, e-money issuance and digital payment token services.

The split between standard and major turns on transaction and float thresholds set by MAS, but the licensing distinction matters here for one reason: the heaviest statutory obligations, security and safeguarding, attach to the major payment institution, not to the money-changer or the standard institution in the same way. Knowing which class you fall into tells you which obligations bite. None of the three classes carries a line in the Act that says "hold a commercial insurance policy".

Security: what a major payment institution lodges with MAS

Section 22 of the Act requires every major payment institution to maintain security with MAS of a prescribed amount "for the due performance of the obligations of the major payment institution to every payment service user who is a customer". The security must be in the form of a cash deposit, a bank guarantee that satisfies MAS requirements, or such other form as MAS may allow in a particular case.

This is the same family of instrument as a licensing bond, not an insurance policy. If the institution surrenders, lapses or has its licence revoked, MAS may enforce the security to pay outstanding customer claims, and may call on a bank guarantee directly. The security is also ring-fenced: it is not liable to be attached for the firm's debts, and on insolvency it is deemed not to form part of the firm's property. An insurance policy pays a third party when an insured loss occurs. This security is money or a bank's promise that MAS can deploy for customers if the firm fails. Different purpose, different mechanism.

Safeguarding: an undertaking from a bank, not a policy from an insurer

This is the provision most often mistaken for an insurance requirement, because one of its options is called an "undertaking". Section 23 requires a major payment institution that handles relevant customer money, for money transfer, merchant acquisition or e-money issuance, to safeguard that money in one of four ways:

Safeguarding methodWhat it is
Undertaking from a safeguarding institutionThe institution undertakes to be fully liable to the customer for the money
Guarantee from a safeguarding institutionA guarantee for the amount of the relevant money
Trust accountThe money is deposited in a trust account with a safeguarding institution
Prescribed mannerAny other manner MAS prescribes

The crucial word is "safeguarding institution". The Act defines it as a bank in Singapore or another financial institution that MAS may prescribe for that purpose, or the person a qualifying trust account is held with. It is a banking and custody concept. The "undertaking" and "guarantee" are instruments a bank or prescribed financial institution provides, not a liability insurance policy a general insurer underwrites. For e-money issuance the safeguarding must be in place from the moment the money is received; for the other services, by the next business day.

So when a founder hears that safeguarding "can include an insurance undertaking", the precise position is narrower. The statutory safeguarding options are a bank undertaking, a bank guarantee, or a trust account. These protect customer money if the firm fails. They do nothing to protect the firm itself against a data breach, a negligence claim or a regulatory action. That gap is where commercial insurance lives, and the Act does not require the firm to fill it.

Technology risk and cyber expectations sit outside the policy question

MAS sets technology-risk and cyber resilience expectations for licensees through its notices and guidelines, and a payment firm is squarely within scope because it handles money and customer data at speed. Those expectations are about controls, governance and incident response, not about holding a particular insurance policy. A firm can meet every technology-risk expectation and still carry no cyber insurance, and it can carry generous cyber cover and still fall short on controls. The two are independent. Treat the regulatory expectation as an operational obligation, and treat cyber insurance as a separate decision about who absorbs the loss when, despite the controls, an incident still lands.

The insurance the law does compel: WICA

Here is the one genuine insurance obligation, and it has nothing to do with the payment services licence. Your firm employs people: compliance officers, engineers, operations staff. As an employer you fall under section 24 of the Work Injury Compensation Act 2019, which requires every employer to insure and maintain insurance under one or more approved employee insurance policies against the liabilities the employer may incur under the Act, in respect of every employee, subject to the classes the regulations exclude.

That duty is triggered by employment, not by the licence. A solo founder with no staff may fall outside it; a payment firm with a real team is almost always inside it. The mechanics of who must be covered are set out in our note on WICA section 24, the mandatory insurance provision.

The cover the licence does not require, but a payment firm rarely skips

Three commercial policies come up for every payment firm, and the Act mandates none of them. Cyber responds to the breach, business interruption and incident-response costs that follow an attack on a business built on data and money movement. Professional indemnity responds to claims that the firm was negligent in the service it provided, a misdirected transfer, a processing failure, a breach of a client's instructions. Directors and officers cover responds to claims against the individuals running a regulated, fast-scaling business, including the regulatory and shareholder exposures that come with an MAS licence. None of these is a licence condition. Each is a commercial risk decision shaped by your clients' contracts, your investors and your own exposure.

Common Mistakes

  1. Reading the safeguarding "undertaking" as an insurance policy. The section 23 undertaking or guarantee comes from a bank or prescribed financial institution and protects customer money, not the firm.

  2. Confusing the section 22 security with insurance. The major payment institution security is a cash deposit or bank guarantee MAS can enforce for customers. It pays nothing to the firm when the firm itself suffers a loss.

  3. Assuming all three licence classes carry the same obligations. Security and safeguarding attach principally to the major payment institution, not uniformly across money-changers and standard institutions.

  4. Treating MAS technology-risk expectations and cyber insurance as the same thing. One is an operational controls obligation; the other is a decision about who absorbs the loss. Meeting one does not satisfy the other.

  5. Thinking the licence excuses you from WICA. The section 24 duty follows employment, independent of any payment services licence.

  6. Assuming the safeguarding regime protects the firm. It protects customer money on the firm's failure. It does nothing for the firm if a client sues over a botched transfer, which is the professional indemnity gap.

What This Means for Your Business

If you are applying for or holding an MAS payment services licence, separate the four obligations and handle each on its terms.

Treat the section 22 security and the section 23 safeguarding as licensing and custody mechanics, not insurance lines. Confirm your licence class, then arrange the bank guarantee, undertaking or trust account the Act requires for your activities, and keep the instrument live for as long as you hold customer money.

Treat WICA as the one insurance the law makes you carry, and carry it because you employ people. Check your headcount and roles against the section 24 duty and the excluded classes, and keep the cover current as you hire.

Treat cyber, professional indemnity and directors and officers as deliberate risk decisions, not compliance ticks. A payment firm runs concentrated cyber, processing-error and management-liability exposure, and your client contracts and investors will often dictate minimum limits. Let the contract and the exposure drive the decision, not the false comfort that the licence has it covered.

Covarage helps with the part that quietly goes wrong: keeping the safeguarding instrument, the WICA policy and any cyber, professional indemnity or directors and officers cover organised in one place, with renewal reminders before anything lapses, and a route to a licensed adviser when you need to arrange or compare cover.

Questions to Ask Your Adviser

  1. For our licence class, what security and safeguarding obligations apply, and is the instrument we hold the right one for the customer money we touch?
  2. Does our current headcount bring us within the WICA section 24 duty, and is every covered employee actually insured?
  3. Given our transaction volumes and data exposure, what cyber limit and incident-response cover would match our real risk?
  4. Do any of our client or partner contracts require professional indemnity or directors and officers cover at a stated limit, and do we meet it?
  5. Are the safeguarding instrument, the WICA policy and any commercial cover documented somewhere we can produce them at renewal or on a MAS query?

Related Information

Published 31 May 2026. Source verified 31 May 2026. COVA is an introducer under MAS Notice FAA-N02. We do not recommend insurance products. We provide factual information sourced from primary regulators and route you to a licensed IFA who can match a policy to your specific situation.