How Does COSMIC Work? Inside Singapore’s Collaborative AML Platform

Table of Contents

How does COSMIC work in Singapore: five-stage AML workflow from data and risk signals to information sharing, investigation and financial crime intelligence

Introduction: From Fragmented Alerts to Shared Financial Crime Intelligence

A bank in Singapore flags an unusual trade finance deal where shipping documents don’t match invoice values. Across town, another institution spots an unexplained corporate structure with rapidly changing directors and opaque beneficial ownership. A third sees repeated high-value inward remittances to a related entity with no clear commercial purpose. Individually, each signal looks incomplete. Together, they reveal a financial crime network.

Traditional AML controls inside single financial institutions struggle against cross-bank networks precisely because each bank sees only its own slice. In modern financial services and markets, criminals exploit these information silos by deliberately spreading activities across multiple institutions and jurisdictions.

COSMIC – Collaborative Sharing of Money Laundering / Terrorism Financing Information & Cases – is a centralised digital platform co-developed by MAS and six major commercial banks (DBS, OCBC, UOB, HSBC, Standard Chartered Bank, and Citibank). COSMIC launched on April 1, 2024, to enable financial institutions to combat money laundering, terrorism financing, and proliferation financing by connecting fragmented risk signals. COSMIC is a collaborative risk-intelligence workflow, not a bulk data lake. It is enabled by the Financial Services and Markets Act 2022 and the Services and Markets Amendment Act 2023, which provide the legal basis for when and how participant financial institutions can share customer information.

How Does COSMIC Work? A 5-Stage View

COSMIC works by allowing participating financial institutions in Singapore to securely share specified customer information and risk indicators when certain objectively defined indicators meet prescribed thresholds under Singapore’s FSMA framework. The receiving institution combines that information with its own customer, transaction, and risk data to strengthen investigations and enable more informed risk assessments.

The five core stages:

  1. Data: existing AML controls generate the initial risk event

  2. Risk Signal: the institution evaluates whether the event meets COSMIC-specific thresholds

  3. Sharing: a formal request or disclosure is made via the COSMIC platform

  4. Investigation: the receiving institution maps shared data against its own records

  5. Intelligence: fragmented signals become actionable financial crime intelligence

COSMIC complements, rather than replaces, existing KYC, transaction monitoring, and suspicious transaction reporting requirements.

The COSMIC Workflow: From Data to Financial Crime Intelligence

Below is the detailed breakdown of the Data → Risk Signal → Sharing → Investigation → Intelligence model. COSMIC does not generate alerts on its own. The workflow sits on top of the legislative framework created by the FSMA amendments, and its initial phase focuses on three key financial crime risks in commercial banking: misuse of legal persons, misuse of trade finance for illicit purposes, and proliferation financing globally.

Step 1 - Data: Where the COSMIC Signal Starts

Source data comes from a bank’s existing AML and risk systems. Participating banks like DBS, OCBC, UOB, HSBC, Standard Chartered, and Citibank already collect this data under MAS AML/CFT Notices and Financial Action Task Force standards. The key data sources feeding COSMIC include:

  1. KYC/CDD records and beneficial ownership data

  2. Customer risk profiles and risk ratings

  3. Sanctions, PEP, and adverse media screening results

  4. Transaction monitoring outputs, including trade finance anomalies

  5. Internal investigation findings

  6. Relationship and entity mapping across corporate structures

A specific control, for example, a trade finance monitoring rule flagging mismatched shipping documents, can create the first risk event that may later become COSMIC-relevant. RegTech tools for name screening, transaction monitoring, entity risk assessment, and adverse media monitoring significantly influence the quality and timeliness of these initial signals. Poor data quality inside any institution degrades the entire collaborative workflow.

Step 2 - Risk Signal: When Does a Case Become COSMIC-Relevant?

Not every AML alert or suspicious transaction becomes a COSMIC case. Institutions first assess alerts against COSMIC-specific red flags and thresholds defined under MAS guidelines and FSMA regulations. COSMIC allows sharing only for defined red-flag indicators; the vast majority of routine alerts never reach the COSMIC platform.

The three priority risk themes for COSMIC’s initial phase are

  • Misuse of legal persons and arrangements (shell companies, opaque ownership, nominee structures)

  • Trade-based money laundering through misuse of trade finance (trade finance for illicit purposes such as over-invoicing, document fraud)

  • Proliferation financing related to weapons of mass destruction and other economic resources

Hypothetical red-flag combinations that could meet COSMIC sharing thresholds include:

  • A company with complex shareholding structures plus rapid turnover of directors plus unexplained third-country trade counterparties

  • Trade finance invoices showing value mismatches plus routing through high-risk jurisdictions plus inconsistent goods descriptions

  • A customer’s profile linked to entities subject to international proliferation sanctions plus unusual transaction volumes

MAS requires objectively defined indicators, and institutions must document their internal logic for when a risk event escalates to COSMIC. This is where strong entity resolution and risk-scoring capabilities matter. Poor signal calibration leads to underuse (missed detection) or overuse (noise and compliance fatigue) of the COSMIC platform.

Step 3 - Sharing: Requests, Disclosures, and Controls Inside COSMIC

The two primary sharing modes are a request for information, where Bank A asks Bank B about a customer or relationship, and a proactive disclosure, where Bank A shares risk information when thresholds are met. Such sharing is permitted only under conditions set out in FSMA Part 4A and accompanying subsidiary legislation, with clear purpose limitation to combat financial crime, combat money laundering, and address terrorism financing and proliferation financing.

A typical sharing sequence looks like this:

  1. Detection: institution identifies a potential financial crime concern

  2. Threshold assessment: COSMIC red-flag criteria are evaluated against the case

  3. Request or Disclosure: formal submission sent via the COSMIC platform

  4. Response: the receiving institution reviews and provides timely responses

  5. Audit: every action is logged for governance and regulatory review

Customer information is not broadcast widely. It is shared in a targeted manner with relevant participant FIs, and only when COSMIC criteria and internal approvals are satisfied. In 2024–2026, many participating banks still rely on semi-manual workflows, with API-based integration to case management and AML systems gradually being rolled out.

Step 4 - Investigation and Intelligence: Turning Shared Data into Action

When a bank receives COSMIC information, its financial crime investigation team links that input with its own KYC files, transaction history, relationship mapping, and previous alerts. Cross-bank link analysis can reveal webs of anomalous activities: common beneficial owners across several legal entities, chains of trade transactions involving multiple institutions, or patterns of potential criminal behaviour across mule accounts.

COSMIC-derived intelligence can lead to concrete actions:

  • Enhanced due diligence and re-rating of customer risk

  • Account restrictions or relationship exit for high-risk customers

  • Filing Suspicious Transaction Reports with the Suspicious Transaction Reporting Office (STRO)

  • Cooperation with law enforcement authorities

  • Broader monitoring of linked entities and suspicious activities

COSMIC intelligence supports supervisory engagement and law enforcement without replacing existing reporting duties. The information among financial institutions enables a network view that no single bank could achieve alone, helping to protect legitimate customers while identifying illicit purposes.

A Practical COSMIC Scenario: One Signal, Three Banks, One Network

This scenario is hypothetical but realistic, set around 2025–2026.

Bank A maintains a trade finance relationship with Company X, a Singapore-registered trading firm. Internal monitoring flags unusual trade finance patterns: invoices with value discrepancies and counterparties in high-risk jurisdictions. The behaviour displays several COSMIC red flags related to misuse of trade finance.

Bank B holds accounts for Company Y, whose beneficial owner matches Company X’s ultimate controller. Bank B’s records show a complex holding structure with frequent changes to directorship – classic indicators of misuse of legal persons.

Bank A’s investigation crosses COSMIC thresholds. The bank submits a COSMIC information request to other participant financial institutions. Bank B responds with ownership data that confirms the common beneficial owner. Bank C, which has observed rapid, unexplained fund movements through accounts of a related entity, discloses its own findings.

The sequence: (1) Alert at Bank A → (2) COSMIC request sent → (3) Responses from Banks B and C → (4) Joint understanding of a broader network → (5) Coordinated action including tighter risk ratings, aligned STR filings, exit of high-risk relationships, and disruption of the suspected trade-based money laundering network.

No single bank could have identified this network from its own data. COSMIC transforms isolated risk signals into cross-institutional intelligence.

How COSMIC Differs from Traditional AML Monitoring

Internal AML systems detect risk inside one institution. COSMIC connects relevant risk information across multiple major commercial banks in Singapore, creating a fundamentally different capability.

Key differences:

  • Data scope: traditional systems see only one institution’s data; COSMIC enables a cross-institutional view

  • Function: internal monitoring detects and assesses risk; COSMIC supports collaborative sharing and intelligence enrichment

  • Trigger: internal systems use institution-level rules; COSMIC uses objectively defined indicators and MAS-prescribed thresholds

  • Network visibility: traditional tools map relationships within one bank; COSMIC links relationships across participant FIs

  • Legal framework: COSMIC operates under a dedicated statutory scheme (FSMA Part 4A) with specific safeguards, unlike standard internal AML controls

COSMIC does not replace AML name screening, customer due diligence, or transaction monitoring. It relies on their outputs as inputs, building on the industry’s existing close collaboration.

Safeguards: How COSMIC Protects Customer Information and Confidentiality

The FSMA requires safeguards for shared information confidentiality. The Financial Services and Markets Act 2022, as amended in May 2023, establishes a legal perimeter and operational safeguards for COSMIC information sharing.

Key protections include:

  • Purpose limitation: information may only be used to combat money laundering terrorism financing and proliferation financing

  • Authorised access: only designated financial crime and compliance teams within participant institutions can access COSMIC data

  • Internal approval workflows: every request or disclosure requires documented authorisation

  • Audit trails: all activity is logged for regulatory review and governance

  • Data quality obligations: MAS expects accuracy, timeliness, and correction when customer clarifications change the risk assessment

  • Immunity provisions: FSMA provides legal protection for institutions and officers sharing risk information under permitted sections

  • Anti-tipping-off rules: participant FIs must manage sharing and investigation without alerting customers under suspicion prematurely

Participant FIs must protect shared information confidentiality, and COSMIC is not an open watchlist. Only relevant, proportionate customer information flows through the system on a timely basis, ensuring that potential financial crime concerns are addressed while legitimate customers are protected. Singapore’s goal is to strengthen Singapore’s capabilities as a well regulated and trusted financial centre within the global financial system.

What Makes COSMIC Effective (and Where It Can Fall Short)

Five dependencies determine COSMIC’s effectiveness:

  • High-quality source data – bad KYC/CDD produces bad intelligence; institutions must invest in data governance to feed accurate signals into COSMIC

  • Robust entity resolution – different institutions may represent the same legal person differently; standardised identifiers and relationship mapping help banks recognise common beneficial owners

  • Well-calibrated thresholds – too low drives alert fatigue and over-sharing; too high risks missing sophisticated financial crime risks or proliferation financing patterns

  • Strong investigative skills – shared information still requires human and analytical assessment by qualified financial crime teams

  • Seamless technology integration – integrated AML risk management systems reduce manual delays and improve the speed from detection to sharing

Challenges observed in 2025–2026 include manual processing of COSMIC cases, legacy core-banking systems, and cultural resistance to sharing insights with competitor banks. MAS and the assistant managing director overseeing AML policy continue to refine guidelines to address these gaps, including updated Guidelines to MAS Notice FSM-N02 issued in mid-2026.

How RegTech and Platforms Like ZIGRAM Support COSMIC Readiness

COSMIC’s value depends on the quality of signals and investigations generated inside each institution. Modern AML compliance infrastructure directly determines how effectively a bank can participate.

RegTech capabilities map to COSMIC stages:

  • Name screening and sanctions risk tools generate the initial risk signals that may trigger COSMIC thresholds

  • Transaction monitoring detects behavioural anomalies in payments, remittances, and trade finance

  • Entity risk assessment and beneficial ownership analysis provide the network view needed for cross-bank link detection

  • Due diligence and adverse media monitoring support deeper investigation after COSMIC information is received

ZIGRAM offers tools including PreScreening.io for name screening, Transact Comply for transaction monitoring, Entity Hero for customer risk rating and entity risk scoring, and Dragnet Alpha and SATOC for news and adverse media. These help institutions feed higher-quality alerts into COSMIC and maintain the auditability MAS expects when reviewing information sharing decisions. Technology is an enabler of better COSMIC outcomes – not a replacement for governance or human judgment.

FAQs: Key Questions About How COSMIC Works

This section answers common practitioner questions directly. Note: the acronym COSMIC in Singapore’s regulatory context refers exclusively to the MAS platform for collaborative sharing of financial crime risk information. Singapore’s COSMIC platform.

What is COSMIC in Singapore?

COSMIC is MAS’s first centralised digital platform to facilitate sharing of customer information among financial institutions for money laundering, terrorism financing, and proliferation financing risk detection. It was co-developed by MAS and six major commercial banks and is backed by FSMA legislation and related materials.

COSMIC follows a five-step workflow: internal AML controls detect a risk event, the institution evaluates it against COSMIC thresholds, a request or disclosure is made via the platform, the receiving institution investigates, and the combined data becomes actionable intelligence.

Cross-bank data points reveal high-risk actors and webs of anomalous activities – such as shared beneficial owners or linked trade flows – that no single institution could identify from its own data alone, enabling more informed risk assessments.

Banks may share defined categories of customer information, transactional behaviour, and risk indicators when red-flag criteria are met, subject to FSMA safeguards. COSMIC allows sharing information on misuse of trade finance, misuse of legal persons, and proliferation financing.

No. COSMIC is a collaboration layer on top of existing AML controls. Banks must still run their own KYC, screening, and monitoring programs under MAS Notices.

COSMIC’s initial phase from 2024 focuses on six major banks. MAS has signalled broader participation over time, potentially extending to insurance, capital markets firms, and payment service providers.

They are objectively defined indicators of potential money laundering, terrorism financing, and proliferation financing – particularly related to misuse of legal persons, trade finance abuse, and suspicious ownership or transaction patterns.

FSMA and MAS rules require purpose limitation, authorised access only, operational safeguards, audit trails, and policies to protect legitimate customers’ interests. Only authorised compliance teams within participant FIs can access COSMIC data.

Enhance Your AML Compliance Efforts

Empower your organization with ZIGRAM's integrated RegTech solutions

Financial Crime Prevention Image

Articles

Explore insightful articles on cutting-edge topics like regulations, technological advancements, and critical insights into AML and financial crime risks
How Does COSMIC Work? Inside Singapore’s Collaborative...

How Does COSMIC Work? Inside Singapore’s Collaborative...

11 Min
KYC in Egypt: 2026 Compliance Requirements, eKYC...

KYC in Egypt: 2026 Compliance Requirements, eKYC...

7 Min
COSMIC Singapore: How Collaborative AML Information Sharing...

COSMIC Singapore: How Collaborative AML Information Sharing...

12 Min
AML Egypt: Practical Challenges, Risk Hotspots, and...

AML Egypt: Practical Challenges, Risk Hotspots, and...

12 Min
AML Software in South Africa: 10 Essential...

AML Software in South Africa: 10 Essential...

9 Min
Transaction Monitoring Egypt: Optimizing for Egyptian AML...

Transaction Monitoring Egypt: Optimizing for Egyptian AML...

11 Min