Table of Contents
Introduction: From Fragmented Alerts to Shared Financial Crime Intelligence
A bank in Singapore flags an unusual trade finance deal where shipping documents don’t match invoice values. Across town, another institution spots an unexplained corporate structure with rapidly changing directors and opaque beneficial ownership. A third sees repeated high-value inward remittances to a related entity with no clear commercial purpose. Individually, each signal looks incomplete. Together, they reveal a financial crime network.
Traditional AML controls inside single financial institutions struggle against cross-bank networks precisely because each bank sees only its own slice. In modern financial services and markets, criminals exploit these information silos by deliberately spreading activities across multiple institutions and jurisdictions.
COSMIC – Collaborative Sharing of Money Laundering / Terrorism Financing Information & Cases – is a centralised digital platform co-developed by MAS and six major commercial banks (DBS, OCBC, UOB, HSBC, Standard Chartered Bank, and Citibank). COSMIC launched on April 1, 2024, to enable financial institutions to combat money laundering, terrorism financing, and proliferation financing by connecting fragmented risk signals. COSMIC is a collaborative risk-intelligence workflow, not a bulk data lake. It is enabled by the Financial Services and Markets Act 2022 and the Services and Markets Amendment Act 2023, which provide the legal basis for when and how participant financial institutions can share customer information.
How Does COSMIC Work? A 5-Stage View
COSMIC works by allowing participating financial institutions in Singapore to securely share specified customer information and risk indicators when certain objectively defined indicators meet prescribed thresholds under Singapore’s FSMA framework. The receiving institution combines that information with its own customer, transaction, and risk data to strengthen investigations and enable more informed risk assessments.
The five core stages:
Data: existing AML controls generate the initial risk event
Risk Signal: the institution evaluates whether the event meets COSMIC-specific thresholds
Sharing: a formal request or disclosure is made via the COSMIC platform
Investigation: the receiving institution maps shared data against its own records
Intelligence: fragmented signals become actionable financial crime intelligence
COSMIC complements, rather than replaces, existing KYC, transaction monitoring, and suspicious transaction reporting requirements.
The COSMIC Workflow: From Data to Financial Crime Intelligence
Below is the detailed breakdown of the Data → Risk Signal → Sharing → Investigation → Intelligence model. COSMIC does not generate alerts on its own. The workflow sits on top of the legislative framework created by the FSMA amendments, and its initial phase focuses on three key financial crime risks in commercial banking: misuse of legal persons, misuse of trade finance for illicit purposes, and proliferation financing globally.
Step 1 - Data: Where the COSMIC Signal Starts
Source data comes from a bank’s existing AML and risk systems. Participating banks like DBS, OCBC, UOB, HSBC, Standard Chartered, and Citibank already collect this data under MAS AML/CFT Notices and Financial Action Task Force standards. The key data sources feeding COSMIC include:
KYC/CDD records and beneficial ownership data
Customer risk profiles and risk ratings
Sanctions, PEP, and adverse media screening results
Transaction monitoring outputs, including trade finance anomalies
Internal investigation findings
Relationship and entity mapping across corporate structures
A specific control, for example, a trade finance monitoring rule flagging mismatched shipping documents, can create the first risk event that may later become COSMIC-relevant. RegTech tools for name screening, transaction monitoring, entity risk assessment, and adverse media monitoring significantly influence the quality and timeliness of these initial signals. Poor data quality inside any institution degrades the entire collaborative workflow.
Step 2 - Risk Signal: When Does a Case Become COSMIC-Relevant?
Not every AML alert or suspicious transaction becomes a COSMIC case. Institutions first assess alerts against COSMIC-specific red flags and thresholds defined under MAS guidelines and FSMA regulations. COSMIC allows sharing only for defined red-flag indicators; the vast majority of routine alerts never reach the COSMIC platform.
The three priority risk themes for COSMIC’s initial phase are
Misuse of legal persons and arrangements (shell companies, opaque ownership, nominee structures)
Trade-based money laundering through misuse of trade finance (trade finance for illicit purposes such as over-invoicing, document fraud)
Proliferation financing related to weapons of mass destruction and other economic resources
Hypothetical red-flag combinations that could meet COSMIC sharing thresholds include:
A company with complex shareholding structures plus rapid turnover of directors plus unexplained third-country trade counterparties
Trade finance invoices showing value mismatches plus routing through high-risk jurisdictions plus inconsistent goods descriptions
A customer’s profile linked to entities subject to international proliferation sanctions plus unusual transaction volumes
MAS requires objectively defined indicators, and institutions must document their internal logic for when a risk event escalates to COSMIC. This is where strong entity resolution and risk-scoring capabilities matter. Poor signal calibration leads to underuse (missed detection) or overuse (noise and compliance fatigue) of the COSMIC platform.
Step 3 - Sharing: Requests, Disclosures, and Controls Inside COSMIC
The two primary sharing modes are a request for information, where Bank A asks Bank B about a customer or relationship, and a proactive disclosure, where Bank A shares risk information when thresholds are met. Such sharing is permitted only under conditions set out in FSMA Part 4A and accompanying subsidiary legislation, with clear purpose limitation to combat financial crime, combat money laundering, and address terrorism financing and proliferation financing.
A typical sharing sequence looks like this:
Detection: institution identifies a potential financial crime concern
Threshold assessment: COSMIC red-flag criteria are evaluated against the case
Request or Disclosure: formal submission sent via the COSMIC platform
Response: the receiving institution reviews and provides timely responses
Audit: every action is logged for governance and regulatory review
Customer information is not broadcast widely. It is shared in a targeted manner with relevant participant FIs, and only when COSMIC criteria and internal approvals are satisfied. In 2024–2026, many participating banks still rely on semi-manual workflows, with API-based integration to case management and AML systems gradually being rolled out.
Step 4 - Investigation and Intelligence: Turning Shared Data into Action
When a bank receives COSMIC information, its financial crime investigation team links that input with its own KYC files, transaction history, relationship mapping, and previous alerts. Cross-bank link analysis can reveal webs of anomalous activities: common beneficial owners across several legal entities, chains of trade transactions involving multiple institutions, or patterns of potential criminal behaviour across mule accounts.
COSMIC-derived intelligence can lead to concrete actions:
Enhanced due diligence and re-rating of customer risk
Account restrictions or relationship exit for high-risk customers
Filing Suspicious Transaction Reports with the Suspicious Transaction Reporting Office (STRO)
Cooperation with law enforcement authorities
Broader monitoring of linked entities and suspicious activities
COSMIC intelligence supports supervisory engagement and law enforcement without replacing existing reporting duties. The information among financial institutions enables a network view that no single bank could achieve alone, helping to protect legitimate customers while identifying illicit purposes.
A Practical COSMIC Scenario: One Signal, Three Banks, One Network
This scenario is hypothetical but realistic, set around 2025–2026.
Bank A maintains a trade finance relationship with Company X, a Singapore-registered trading firm. Internal monitoring flags unusual trade finance patterns: invoices with value discrepancies and counterparties in high-risk jurisdictions. The behaviour displays several COSMIC red flags related to misuse of trade finance.
Bank B holds accounts for Company Y, whose beneficial owner matches Company X’s ultimate controller. Bank B’s records show a complex holding structure with frequent changes to directorship – classic indicators of misuse of legal persons.
Bank A’s investigation crosses COSMIC thresholds. The bank submits a COSMIC information request to other participant financial institutions. Bank B responds with ownership data that confirms the common beneficial owner. Bank C, which has observed rapid, unexplained fund movements through accounts of a related entity, discloses its own findings.
The sequence: (1) Alert at Bank A → (2) COSMIC request sent → (3) Responses from Banks B and C → (4) Joint understanding of a broader network → (5) Coordinated action including tighter risk ratings, aligned STR filings, exit of high-risk relationships, and disruption of the suspected trade-based money laundering network.
No single bank could have identified this network from its own data. COSMIC transforms isolated risk signals into cross-institutional intelligence.
How COSMIC Differs from Traditional AML Monitoring
Internal AML systems detect risk inside one institution. COSMIC connects relevant risk information across multiple major commercial banks in Singapore, creating a fundamentally different capability.
Key differences:
Data scope: traditional systems see only one institution’s data; COSMIC enables a cross-institutional view
Function: internal monitoring detects and assesses risk; COSMIC supports collaborative sharing and intelligence enrichment
Trigger: internal systems use institution-level rules; COSMIC uses objectively defined indicators and MAS-prescribed thresholds
Network visibility: traditional tools map relationships within one bank; COSMIC links relationships across participant FIs
Legal framework: COSMIC operates under a dedicated statutory scheme (FSMA Part 4A) with specific safeguards, unlike standard internal AML controls
COSMIC does not replace AML name screening, customer due diligence, or transaction monitoring. It relies on their outputs as inputs, building on the industry’s existing close collaboration.
Safeguards: How COSMIC Protects Customer Information and Confidentiality
The FSMA requires safeguards for shared information confidentiality. The Financial Services and Markets Act 2022, as amended in May 2023, establishes a legal perimeter and operational safeguards for COSMIC information sharing.
Key protections include:
Purpose limitation: information may only be used to combat money laundering terrorism financing and proliferation financing
Authorised access: only designated financial crime and compliance teams within participant institutions can access COSMIC data
Internal approval workflows: every request or disclosure requires documented authorisation
Audit trails: all activity is logged for regulatory review and governance
Data quality obligations: MAS expects accuracy, timeliness, and correction when customer clarifications change the risk assessment
Immunity provisions: FSMA provides legal protection for institutions and officers sharing risk information under permitted sections
Anti-tipping-off rules: participant FIs must manage sharing and investigation without alerting customers under suspicion prematurely
Participant FIs must protect shared information confidentiality, and COSMIC is not an open watchlist. Only relevant, proportionate customer information flows through the system on a timely basis, ensuring that potential financial crime concerns are addressed while legitimate customers are protected. Singapore’s goal is to strengthen Singapore’s capabilities as a well regulated and trusted financial centre within the global financial system.
What Makes COSMIC Effective (and Where It Can Fall Short)
Five dependencies determine COSMIC’s effectiveness:
High-quality source data – bad KYC/CDD produces bad intelligence; institutions must invest in data governance to feed accurate signals into COSMIC
Robust entity resolution – different institutions may represent the same legal person differently; standardised identifiers and relationship mapping help banks recognise common beneficial owners
Well-calibrated thresholds – too low drives alert fatigue and over-sharing; too high risks missing sophisticated financial crime risks or proliferation financing patterns
Strong investigative skills – shared information still requires human and analytical assessment by qualified financial crime teams
Seamless technology integration – integrated AML risk management systems reduce manual delays and improve the speed from detection to sharing
Challenges observed in 2025–2026 include manual processing of COSMIC cases, legacy core-banking systems, and cultural resistance to sharing insights with competitor banks. MAS and the assistant managing director overseeing AML policy continue to refine guidelines to address these gaps, including updated Guidelines to MAS Notice FSM-N02 issued in mid-2026.
How RegTech and Platforms Like ZIGRAM Support COSMIC Readiness
COSMIC’s value depends on the quality of signals and investigations generated inside each institution. Modern AML compliance infrastructure directly determines how effectively a bank can participate.
RegTech capabilities map to COSMIC stages:
Name screening and sanctions risk tools generate the initial risk signals that may trigger COSMIC thresholds
Transaction monitoring detects behavioural anomalies in payments, remittances, and trade finance
Entity risk assessment and beneficial ownership analysis provide the network view needed for cross-bank link detection
Due diligence and adverse media monitoring support deeper investigation after COSMIC information is received
ZIGRAM offers tools including PreScreening.io for name screening, Transact Comply for transaction monitoring, Entity Hero for customer risk rating and entity risk scoring, and Dragnet Alpha and SATOC for news and adverse media. These help institutions feed higher-quality alerts into COSMIC and maintain the auditability MAS expects when reviewing information sharing decisions. Technology is an enabler of better COSMIC outcomes – not a replacement for governance or human judgment.
FAQs: Key Questions About How COSMIC Works
This section answers common practitioner questions directly. Note: the acronym COSMIC in Singapore’s regulatory context refers exclusively to the MAS platform for collaborative sharing of financial crime risk information. Singapore’s COSMIC platform.
What is COSMIC in Singapore?
COSMIC is MAS’s first centralised digital platform to facilitate sharing of customer information among financial institutions for money laundering, terrorism financing, and proliferation financing risk detection. It was co-developed by MAS and six major commercial banks and is backed by FSMA legislation and related materials.
How does COSMIC work in practice?
COSMIC follows a five-step workflow: internal AML controls detect a risk event, the institution evaluates it against COSMIC thresholds, a request or disclosure is made via the platform, the receiving institution investigates, and the combined data becomes actionable intelligence.
How does COSMIC help banks detect financial crime?
Cross-bank data points reveal high-risk actors and webs of anomalous activities – such as shared beneficial owners or linked trade flows – that no single institution could identify from its own data alone, enabling more informed risk assessments.
What information can banks share through COSMIC?
Banks may share defined categories of customer information, transactional behaviour, and risk indicators when red-flag criteria are met, subject to FSMA safeguards. COSMIC allows sharing information on misuse of trade finance, misuse of legal persons, and proliferation financing.
Does COSMIC replace KYC and transaction monitoring?
No. COSMIC is a collaboration layer on top of existing AML controls. Banks must still run their own KYC, screening, and monitoring programs under MAS Notices.
Is COSMIC mandatory for all financial institutions?
COSMIC’s initial phase from 2024 focuses on six major banks. MAS has signalled broader participation over time, potentially extending to insurance, capital markets firms, and payment service providers.
What are COSMIC red flags?
They are objectively defined indicators of potential money laundering, terrorism financing, and proliferation financing – particularly related to misuse of legal persons, trade finance abuse, and suspicious ownership or transaction patterns.
How does COSMIC protect customer information?
FSMA and MAS rules require purpose limitation, authorised access only, operational safeguards, audit trails, and policies to protect legitimate customers’ interests. Only authorised compliance teams within participant FIs can access COSMIC data.