Regulation 11
Due diligence obligation
Subregulation 1
A reporting Singaporean crypto‑asset service provider must establish and maintain the following arrangements in relation to each crypto‑asset user:
arrangements to establish all the residences for a tax purpose of —
the crypto‑asset user; and
where the crypto‑asset user is an entity crypto‑asset user other than an excluded person or an active entity — every controlling person of the entity crypto‑asset user;
arrangements to identify whether —
the crypto‑asset user is a reportable user; and (ii)where the crypto‑asset user is an entity crypto‑asset user other than an excluded person or an active entity — the crypto‑asset user has one or more controlling persons each of whom is a reportable person.
Subregulation 2
A reporting Singaporean crypto‑asset service provider must establish and maintain the arrangements mentioned in paragraph (1) in relation to each crypto‑asset user even if —
the residence for a tax purpose of the crypto‑asset user is not a reportable jurisdiction; or
where the crypto‑asset user is an entity crypto‑asset user other than an excluded person or an active entity — the residence for a tax purpose of any controlling person of the entity crypto‑asset user is not a reportable jurisdiction.
Subregulation 3
A reporting Singaporean crypto‑asset service provider is treated as having complied with paragraph (1) only if —
in establishing and maintaining such arrangements, the provider complies with the due diligence requirements in Section III of the CARF, as modified by regulation 4; and
where any provision in Section III of the CARF (as modified by regulation 4) requires anything to be obtained in respect of any relevant transaction effectuated for the crypto‑asset user — the provider keeps all information that is needed to explain the relevant transaction.
Subregulation 4
The reporting Singaporean crypto‑asset service provider must, in relation to any crypto‑asset user, ensure that all of the following are kept for the period mentioned in paragraph (5):
all evidence, record or information in relation to the crypto‑asset user and every relevant transaction effectuated for the crypto‑asset user that it has obtained in accordance with paragraph (3);
a record of the steps it has taken in accordance with paragraph (3) in relation to the crypto‑asset user and every relevant transaction effectuated for the crypto‑asset user.
Subregulation 5
In paragraph (4), the period is —
in the case of any evidence, record or information mentioned in paragraph (4)(a) that identifies the crypto‑asset user, is a document establishing a relationship with the crypto‑asset user, or is correspondence with the crypto‑asset user — 5 years after the end of the relationship with the crypto‑asset user; (b)in the case of any evidence, record or information mentioned in paragraph (4)(a) relating to any relevant transaction effectuated for the crypto‑asset user — 5 years after 31 December of the calendar year in which the reporting Singaporean crypto‑asset service provider is required to provide any information relating to the relevant transaction to the Comptroller under regulation 12(1); and
in the case of any record mentioned in paragraph (4)(b) — 5 years after 31 December of the calendar year in which the reporting Singaporean crypto‑asset service provider is required to provide any information relating to the crypto‑asset user and the relevant transaction effectuated for the crypto‑asset user to the Comptroller under regulation 12(1).
Subregulation 6
A reporting Singaporean crypto‑asset service provider must, on or before establishing a relationship with a person that is a crypto‑asset user —
obtain a valid self‑certification to determine whether the person is a reportable person, and confirm its reasonableness; and
in a case where the person is an entity crypto‑asset user other than an excluded person or an active entity — obtain one or more valid self‑certifications to determine whether each controlling person of the entity crypto‑asset user is a reportable person, and confirm the reasonableness of each valid self‑certification.
Subregulation 7
A reporting Singaporean crypto‑asset service provider must obtain a valid self‑certification, and confirm its reasonableness, from a crypto‑asset user that is a pre‑existing entity crypto‑asset user or a pre‑existing individual crypto‑asset user by 31 December 2027.
Subregulation 8
A reporting Singaporean crypto‑asset service provider must not effectuate any relevant transaction for any crypto‑asset user that is a pre‑existing entity crypto‑asset user or a pre‑existing individual crypto‑asset user on or after 1 January 2028, unless it has obtained a valid self‑certification, and confirmed its reasonableness, from the crypto‑asset user.
Subregulation 9
In the case of a reporting Singaporean crypto‑asset service provider that is a trust, a requirement under paragraph (1), (4), (6), (7) or (8) must be complied with by the trustee of the reporting Singaporean crypto‑asset service provider.
Subregulation 10
A requirement under paragraph (1), (4), (6), (7) or (8) is a requirement the failure or neglect to comply with which (if such failure or neglect is without reasonable excuse) is an offence under section 105M(1B) of the Act.