COSMIC Singapore: How Collaborative AML Information Sharing Is Transforming Financial Crime Detection

Table of Contents

COSMIC Singapore collaborative AML information sharing platform

Singapore is a city-state known for many things with “cosmic” in the name. Cosmic Singapore may refer to a popular cross-border executive bus operator, and the Cosmic Singapore bus service connects travellers across Singapore and Malaysia. 

But the COSMIC, which we will be talking about in this article, that is reshaping Singapore’s financial landscape, has nothing to do with buses, bowling, or light shows. COSMIC, a.k.a. the Collaborative Sharing of ML/TF Information & Cases, is Singapore’s first centralised digital platform for sharing specified customer risk information among prescribed financial institutions to combat money laundering, terrorism financing, and proliferation financing globally. Launched on 1 April 2024 by the Monetary Authority of Singapore under the Financial Services and Markets (Amendment) Act 2023, it represents a landmark initiative in private-to-private information sharing for financial crime detection.

Six major banks participate in the initial phase: DBS, OCBC, UOB, Citibank, HSBC, and Standard Chartered. The platform targets three key financial crime risks – misuse of legal persons, misuse of trade finance for illicit purposes, and proliferation financing – and it works alongside existing compliance controls like name screening, transaction monitoring, and entity risk assessment used by financial institutions across Singapore.

This article answers the questions compliance teams and AML professionals are asking: What is COSMIC in Singapore? How does it work? What information can banks share? What are the red flags? How does COSMIC protect customer data? How does it differ from traditional KYC? And what has changed since its launch?

COSMIC at a Glance: Key Facts and Answers

This section serves as a quick-reference fact grid for compliance teams, financial institutions, and anyone seeking fast, precise answers about the COSMIC platform.

  • Full name: Collaborative Sharing of Money Laundering/Terrorism Financing (ML/TF) Information & Cases

  • Regulator: Monetary Authority of Singapore (MAS)

  • Country: Singapore

  • Legal basis: Financial Services and Markets (Amendment) Act 2023, Part 4A (Sections 28A–28J)

  • Launch date: 1 April 2024

  • Initial participants: Six banks – DBS, OCBC, UOB, Citibank, HSBC, Standard Chartered

  • Core risks targeted: Misuse of legal persons, misuse of trade finance, proliferation financing

  • Main purpose: Secure, governed collaborative sharing of customer risk information to detect and disrupt illicit activities across the financial system

  • 2026 direction: Expansion to significant cases and additional major commercial banks

Is COSMIC mandatory? COSMIC participation is currently voluntary among prescribed financial institutions in its initial phase. However, MAS has legal authority to mandate certain disclosures in higher-risk cases or issue notices requiring sharing. The law provides for expanding the scope of prescribed institutions over time, and financial institutions that participate must comply with MAS Notice FSM-N02 and its Guidelines.

Is COSMIC part of Singapore’s AML framework? Yes. COSMIC is a central tactical tool within MAS’ Prevention–Detection–Enforcement AML/CFT strategy. It works alongside Suspicious Transaction Reporting Office (STRO) reporting, supervisory reviews, and enforcement actions. Information from COSMIC, including material networks of suspicious actors, feeds into MAS’ risk surveillance framework and Singapore’s broader national AML architecture.

What Is COSMIC in Singapore, and Why Was It Created?

COSMIC is a centralised digital platform established under Singapore law that enables prescribed financial institutions to securely share specified customer risk information when objectively defined indicators of suspicion or red flags are present. It operates under MAS supervision with specific legal safeguards, purpose limitations, and confidentiality requirements designed to ensure such sharing is proportionate and lawful.

COSMIC is not a standalone regime. It fits within MAS’ three-pronged AML/CFT/CPF strategy:

  • Prevention: driving better internal controls and governance around high-risk customers

  • Detection: earlier identification of illicit networks across financial institutions

  • Enforcement: informing supervisory assessments and follow-up action when red flags are systematically mishandled

The information-silo problem. Before COSMIC, a criminal could maintain accounts or corporate relationships across multiple financial institutions, and each institution would see only a fragment of the network. A shell company with accounts at three different banks might appear low-risk at each one individually. Only by connecting the dots across institutions could bad actors be identified.

Singapore’s internationally connected financial center, one of Asia’s largest, attracts legitimate global capital but also cross-border financial crime. Money laundering, terrorism financing, and proliferation financing networks exploit the complexity of international trade, corporate structures, and banking relationships. High-profile cases in the industry, including investigations linked to 1MDB and Wirecard-related flows, underscored the urgency of stronger collaborative information sharing between financial institutions and regulators, as well as a broader focus on combating cross-border illicit finance threats.

COSMIC allows financial institutions to share suspicious activity information specifically to close these gaps by creating visibility that no single bank could achieve alone.

How Does the COSMIC AML Platform Work in Practice?

COSMIC works by allowing participating banks to share specified customer risk information only when well-defined indicators of suspicion are present. The process follows a governed workflow with strict confidentiality rules set by MAS, and sharing is permitted exclusively for AML/CFT/CPF purposes – never for commercial decisions like marketing or credit scoring.

The operational process follows five steps:

  1. Internal red-flag detection. A bank’s internal systems with name screening, transaction monitoring, or risk alerts identify a concern about a customer, entity, or transaction pattern.

  2. Threshold assessment. The bank evaluates whether the detected red flags meet the legislated threshold criteria for COSMIC sharing. Not every alert qualifies, only those meeting objective, predefined indicators.

  3. Information request or disclosure. The bank either requests risk information from another prescribed financial institution (Section 28D of the FSM Act), proactively discloses to another (Section 28E), or publishes certain details to all participant FIs on the platform (Section 28F, only after filing an STR and exiting the customer relationship).

  4. Cross-institution review. The receiving institution reviews the shared intelligence alongside its own data, looking for network connections, corroborating patterns, or additional red flags.

  5. Enhanced risk assessment and action. Banks update internal risk ratings, file Suspicious Transaction Reports to STRO where warranted, or exit high-risk relationships.

COSMIC guidelines require sharing information on suspicious activities through this structured process. Name screening is crucial for compliance with financial regulations; it provides the initial trigger for many COSMIC-eligible cases. The platform complements traditional KYC and transaction monitoring: KYC builds the baseline customer profile, transaction monitoring spots unusual activity inside one institution, and COSMIC lets institutions jointly view risk indicators across multiple banks.

What AML/CFT/CPF Information Sharing Can Financial Institutions Do Through COSMIC?

Banks cannot freely exchange all customer data on COSMIC. They can only share specified customer information and risk information that is relevant to suspected money laundering, terrorism financing, or proliferation financing, and only when red-flag conditions are met. Purpose limitation and necessity apply to every disclosure.

Customer identifiers and relationships:

  • Company name, Unique Entity Number (UEN), account types

  • Beneficial ownership details where known, key controllers, authorised signatories

  • Connections to other legal persons or related entities

Risk and behaviour information:

  • Unusual transaction patterns inconsistent with declared business profiles

  • Suspicious trade finance flows like mispricing, mismatched documentation, phantom shipments

  • Use of complex corporate structures to obscure beneficial ownership

  • Links to high-risk jurisdictions, sanctioned countries, or sectors subject to heightened scrutiny

Network intelligence:

  • Relationships between multiple accounts and counterparties across financial institutions

  • Repeated attempts to open accounts at different banks

  • Signs of illicit networks using Singapore’s financial system as a transit point

Such information is subject to strict governance. MAS’ Guidelines to Notice FSM-N02, issued on 18 October 2024, require internal approvals, audit trails, role-based access, and quality standards for all such sharing. Outsourcing controls took effect on 11 December 2024, ensuring governance extends to any delegated functions. Financial institutions must ensure confidentiality of shared data and restrict its use to AML/CFT/CPF purposes only.

What Are COSMIC's Red Flags and Priority Risk Areas?

COSMIC red flags are objectively defined indicators of suspicion in commercial banking relationships. When present, they allow banks to share information through the platform. These indicators are focused on specific risk domains set by MAS – not every form of suspicious activity qualifies. The goal is targeted, high-value intelligence sharing rather than bulk data exchange.

COSMIC targets misuse of legal persons and trade finance for illicit purposes, along with proliferation financing. These three priority risk areas were selected because they represent key risks where cross-institutional visibility delivers the greatest detection gains.

1. Misuse of legal persons

  • Shell companies with no visible business substance or operations

  • Frequent changes in directors, shareholders, or beneficial owners

  • Layering of entities across jurisdictions to obscure control

  • Transactions inconsistent with the customer’s stated profile and sector

  • For more on identifying hidden ownership, see this guide on UBO identification in AML compliance.

2. Misuse of trade finance

  • Involvement of sanctioned countries or vessels

  • Mismatched shipping and payment documentation

  • Over-invoicing or under-invoicing suggesting value transfer

  • Sudden shifts in trade corridors or counterparties

  • Unusual use of letters of credit across multiple financial institutions

3. Proliferation financing

  • Repeated, structured purchases of dual-use goods

  • Counterparties located near known proliferation hubs

  • Attempts to obscure end-users through intermediaries and logistics companies

  • Supply chain patterns involving types of financial crimes tied to WMD programmes

Calibration challenges. A persistent concern is getting thresholds right. Set too low, COSMIC risks becoming overloaded with low-value alerts that drain AML resources. Set too high, genuine illicit activities slip through. Achieving consistency in red-flag definitions across different banks – each with different risk appetites, monitoring systems, and data quality – remains an ongoing challenge for the industry.

Who Uses COSMIC? From Six Banks to a Wider Financial Ecosystem

COSMIC was co-developed by MAS and six major banks – DBS, OCBC, UOB, Citibank, HSBC, and Standard Chartered – and participation is currently prescribed for these selected institutions. Singapore has signalled plans to expand the platform to more significant cases and additional major banks as the initiative matures.

These six banks were chosen because of their systemic importance and heavy exposure to trade finance and commercial banking, the primary channels through which misuse of legal persons and international trade-based money laundering occurs. As gatekeepers in Singapore’s AML/CFT regime, these institutions detect and disrupt money laundering, terrorism financing, and proliferation financing in cooperation with MAS, STRO, and other agencies.

Six major banks participate in COSMIC’s initial phase, but the scope is not static. Singapore’s 2026 FATF/APG Mutual Evaluation Report explicitly recommends expanding COSMIC to additional prescribed FIs and risk areas. An official statement from Singapore’s Ministry of Home Affairs confirms that COSMIC will be extended to other banks and potentially selected non-bank financial institutions to cover significant cases more comprehensively.

Importantly, while COSMIC enables collaboration, financial institutions remain individually responsible for their internal AML controls, transaction monitoring, and reporting. Participant FIs must not outsource judgement solely to COSMIC – each bank’s own customer due diligence and risk assessment obligations remain fully in force.

COSMIC vs Traditional KYC and Transaction Monitoring

How does COSMIC differ from traditional KYC? Traditional KYC focuses on institution-level onboarding and periodic review, using a bank’s own internal data to assess individual customers. COSMIC enables cross-institution sharing of risk intelligence when red flags arise, providing a broader view of illicit networks and relationships that no single bank’s KYC process can reveal on its own.

How does COSMIC support transaction monitoring? Transaction monitoring assists regulated organizations in detecting suspicious activities within a single institution’s dataset. COSMIC enhances these outcomes by letting banks validate whether unusual behaviour seen at one bank appears at others – revealing multi-bank layering, coordinated trade schemes, or networks of related legal persons.

Here is how the two compare across key dimensions:

  • Scope: Traditional KYC and monitoring operate within a single financial institution. COSMIC enables a multi-FI view.

  • Information type: KYC produces customer profiles. COSMIC shares risk intelligence triggered by specific concerns.

  • Trigger: KYC is routine and ongoing. COSMIC is activated only when defined red-flag thresholds are met.

  • Focus: KYC centres on the individual customer. COSMIC centres on risk, networks, and suspicious patterns.

  • Regulatory expectation: KYC and monitoring are mandatory for every regulated entity. COSMIC is an additional, complementary layer.

COSMIC does not replace KYC or transaction monitoring in AML. It adds a network and entity-risk dimension: shared intelligence on directors, beneficial owners, counterparties, and trade routes can reveal hidden relationships that were invisible under traditional, siloed setups.

For example, Bank A might detect over-invoicing in shipments to a particular country, while Bank B sees mismatched shipping documents for the same exporter. Under COSMIC, these connections help detect a trade-based money laundering ring that neither bank could have identified alone.

Data Privacy, Legal Framework and Governance Around COSMIC

How does COSMIC protect customer data? Information sharing under COSMIC is strictly limited to defined AML/CFT/CPF purposes, backed by the Financial Services and Markets (Amendment) Act 2023. The law includes confidentiality and operational safeguards, purpose limitations, and protections from liability when financial institutions share in good faith with reasonable care.

The legal basis is explicit: Part 4A of the FSM Act overrides other legal restrictions – including contractual or professional secrecy – when sharing meets the Act’s requirements. MAS imposes strict AML/CFT requirements on financial institutions, and the COSMIC framework is no exception.

Key governance expectations from MAS Guidelines to Notice FSM-N02 include:

  • Board and senior management oversight of COSMIC-related policies

  • Robust internal procedures for requesting, disclosing, and publishing risk information

  • Clear roles and responsibilities – only authorised officers may access the platform

  • Training for compliance and frontline staff

  • Quality controls for the accuracy of shared data and analysis

Data protection controls include restricted access within banks, encryption, secure connectivity, logging and audit trails, and strict prohibitions on re-disclosure or misuse of COSMIC information for non-AML purposes. These guidelines align with FATF standards and international best practices.

COSMIC is not a public database. Legitimate customers should benefit from a safer, more trusted financial system when financial crime risks are better controlled. Financial institutions must still conduct independent assessments – a COSMIC disclosure does not automatically create an obligation to exit a customer relationship.

Penalties exist for false or reckless disclosure under Section 28J of the FSM Act, including fines and imprisonment. Non-compliance with MAS notices can attract fines up to SGD 1 million.

COSMIC's Role in Singapore's Wider AML/CFT/CPF Strategy and 2026 Updates

COSMIC is a central tactical tool supporting MAS’ Prevention–Detection–Enforcement strategy, working alongside STRO reporting, supervisory reviews, and enforcement actions against financial institutions. Compliance with COSMIC governance requirements impacts MAS’s risk assessment of financial institutions, making it a practical concern for every bank operating in Singapore.

COSMIC fits into a broader national architecture connecting MAS, the Ministry of Home Affairs, the Ministry of Finance, and law enforcement. MAS collaborates with international regulators to combat money laundering, and COSMIC provides a domestic mechanism that strengthens Singapore’s ability to detect and disrupt illicit networks before they reach international enforcement channels. MAS also alerts financial institutions to emerging risks and criminal typologies, which in turn inform how banks calibrate their COSMIC red flags.

2024–2026 Timeline:

  • 1 April 2024: COSMIC launched with six banks

  • 18 October 2024: MAS issued AML/CFT guidelines (Guidelines to Notice FSM-N02)

  • 11 December 2024: Outsourcing provisions under FSM-N02 took effect

  • 6 May 2026: FATF/APG Mutual Evaluation Report recognises COSMIC and recommends expansion

First-year results tell a compelling story. In its initial twelve months, COSMIC contributed to 461 additional Suspicious Transaction Reports filed, covering transactions valued at over SGD 1.6 billion. Banks closed 1,152 suspicious customer accounts and detected two illicit networks that had been invisible under traditional, institution-level monitoring.

Looking ahead, challenges remain: expanding participation to more FIs beyond the initial six banks, including non-bank regulated entities; improving data quality and entity resolution across institutions; fine-tuning red-flag thresholds to balance effectiveness against operational burden; and integrating advanced analytics, entity risk assessment, and network analysis tools to create sharper intelligence.

ZIGRAM's Perspective: Leveraging COSMIC with RegTech and Financial Crime Analytics

Regulatory technology solutions aid in anti-money laundering and financial crime compliance – and platforms like COSMIC make this more relevant than ever. RegTech providers like ZIGRAM help financial institutions operationalise COSMIC by improving data quality, entity risk assessment, and analytics so that information sharing is targeted, compliant, and effective.

ZIGRAM’s product suite directly addresses the capabilities banks need to participate effectively in COSMIC:

  • PreScreening.io for name screening against sanctions watchlists, PEP databases, and adverse media – providing the initial detection layer that feeds COSMIC triggers

  • Transact Comply for transaction monitoring that identifies suspicious patterns before they reach the COSMIC sharing threshold

  • Entity Hero for systematic customer risk assessment, beneficial ownership analysis, and network-level entity risk scoring

  • Adverse media monitoring and due diligence report generation for deeper investigation once COSMIC intelligence is received

By building stronger internal AML frameworks, covering sanctions screening, beneficial ownership analysis, trade finance risk assessment, and emerging risks – banks can share higher-quality intelligence on COSMIC and avoid noise from poorly investigated alerts. The effectiveness of COSMIC ultimately depends on the quality of each institution’s own detection and compliance capabilities.

COSMIC is expanding. The resources and guidance from regulators are clear: financial institutions need to be ready. If you are a compliance leader or AML team member at a bank, fintech, or other regulated entity looking to modernise your financial crime compliance stack in anticipation of COSMIC expansion, Book a Demo or schedule a discovery call with ZIGRAM to see how integrated RegTech can sharpen your detection, improve your data, and make collaboration work.

Enhance Your AML Compliance Efforts

Empower your organization with ZIGRAM's integrated RegTech solutions

Financial Crime Prevention Image

Articles

Explore insightful articles on cutting-edge topics like regulations, technological advancements, and critical insights into AML and financial crime risks
COSMIC Singapore: How Collaborative AML Information Sharing...

COSMIC Singapore: How Collaborative AML Information Sharing...

12 Min
AML Egypt: Practical Challenges, Risk Hotspots, and...

AML Egypt: Practical Challenges, Risk Hotspots, and...

12 Min
AML Software in South Africa: 10 Essential...

AML Software in South Africa: 10 Essential...

9 Min
Transaction Monitoring Egypt: Optimizing for Egyptian AML...

Transaction Monitoring Egypt: Optimizing for Egyptian AML...

11 Min
AML Compliance in Egypt: Regulations, Regulators and...

AML Compliance in Egypt: Regulations, Regulators and...

7 Min
TD Bank AML Transformation: From an $18.3...

TD Bank AML Transformation: From an $18.3...

13 Min