← Study index · ← Cheat sheet (digest)RES5 — Rules, Ethics and Skills for Financial Advisory Services — Full Facts
Chapter 6 · every fact by topic · 130 source facts
Priority — core important supporting
📋Faa N17 Scope And Application
Legal basis and who FAA-N17 applies to, effective date and definitions
- Notice FAA-N17 is issued pursuant to Section 58 of the Financial Advisers Act (the Act) and applies to all licensed financial advisers. — Ch. 2, p. 3
⚠ The Notice does not apply to representatives or exempt financial advisers — only licensed financial advisers.
- Notice FAA-N19 covers the following requirements in respect of the distribution of direct purchase insurance products: (a) Implementation of safeguards; (b) Provision of product information; (c) Provision of avenues to address general queries; (d) Implementation of internal policies and processes; (e) Roles and responsibilities of a representative or customer service officer. — Ch. 9, p. 10
⚠ This is a named enumeration of 5 requirements — all five must be recalled together as the scope of FAA-N19.
- Except where defined in this Notice or if the context otherwise requires, the expressions used in this Notice have the same meanings as in the Act. — Ch. 7, p. 7
⚠ There are two exceptions to the default rule: (1) terms defined in the Notice itself, and (2) where context otherwise requires.
- Notice FAA-N19 is issued pursuant to Section 58 of the Financial Advisers Act (2001). — Ch. 9, p. 10
⚠ Section 58 of the FAA is the enabling provision — not section 64 or any section of the SFA or Insurance Act.
- Notice FAA-N19 sets out the requirements for the distribution of DPI. — Ch. 9, p. 10
⚠ DPI = Direct Purchase Insurance, a specific product category — not all insurance products.
- Notice FAA-N19 applies to licensed financial advisers, exempt financial advisers or representatives of financial advisers. — Ch. 9, p. 10
⚠ Three categories are covered: licensed FA, exempt FA, and representatives — not a subset.
- DPI stands for Direct Purchase Insurance products. — Ch. 9, p. 10
- Expressions used in Notice FAA-N17 shall, except where expressly defined in the Notice or where the context otherwise requires, have the same meanings as in the Financial Advisers Act. — Ch. 2, p. 3
- Notice FAA-N17 shall take immediate effect. — Ch. 2, p. 3
- Notice FAA-N19 is also referred to as the Notice on the Distribution of Direct Purchase Insurance Products. — Ch. 9, p. 10
- The Financial Advisers Act (2001) is referred to in Notice FAA-N19 as 'the Act'. — Ch. 9, p. 10
🚨Suspicious Activities And Fraud Reporting
Duty to report suspicious activities and fraud to MAS, the Form F1, deadline, police reporting and documentation of non-reporting
- A licensed financial adviser shall lodge with the Monetary Authority of Singapore a report in the form, manner and within such time as specified in paragraph 4, upon discovery of any suspicious activities and incidents of fraud where such activities or incidents are material to the safety, soundness or reputation of the licensed financial adviser. — Ch. 2, p. 3
⚠ The materiality qualifier ('material to the safety, soundness or reputation') is a distinct gate — not all suspicious activities trigger the FAA-N17 reporting duty.
- The report under FAA-N17 paragraph 2 shall be in Form F1 ("Suspicious Activities & Incidents of Fraud Report") and shall be lodged not later than 5 working days after the discovery of the activity or incident by the licensed financial adviser.5 working days — Ch. 2, p. 3
⚠ Form F1 is specific to FAA-N17 — do not confuse with the STR form for STRO or with a police report.
- The Suspicious Activities and Incidents of Fraud Report is submitted under Notice No. FAA-N17 under the Financial Advisers Act (2001). — Ch. 4, p. 4
⚠ Do not confuse FAA-N17 (suspicious activity/fraud reporting) with FSM-N23 (technology risk management) which appears in the same chapter.
- The Suspicious Activities and Incidents of Fraud Report may be submitted by post, fax or encrypted email. — Ch. 4, p. 4
⚠ The email submission method specifically requires encryption — 'encrypted email' is a single condition, not just 'email'.
- The reporting officer for the Suspicious Activities and Incidents of Fraud Report must be the CEO, Principal Officer or Director of the reporting financial institution. — Ch. 4, p. 4
⚠ The Contact Officer is a separate field ('if different from Reporting Officer'), so they can be different persons but the Reporting Officer must be CEO/Principal Officer/Director.
- The report must include: (a) the date and circumstances under which the activity/incident was discovered; (b) the number of clients/users/customers affected; (c) details of persons involved in the suspicious activity; (d) the monetary amounts involved; and (e) any other relevant information. — Ch. 4, p. 4
⚠ These five items are what must be included in the report details — item (e) is a catch-all 'any other relevant information', not an exhaustive closure.
- The report must state the reasons for not lodging a police report on the incident of fraud. — Ch. 4, p. 4
⚠ This is Section 4 of the form and applies specifically to 'incident of fraud'—not to suspicious activities that are not fraud. If a police report was lodged, the form does not appear to require this explanation (it asks for reasons for NOT lodging).
- For the avoidance of doubt, a licensed financial adviser shall still file suspicious transaction reports to the Suspicious Transaction Reporting Office (STRO), Commercial Affairs Department of the Singapore Police Force, as required under the various Prevention Of Money Laundering and Countering The Financing Of Terrorism Notices applicable to it. — Ch. 2, p. 3
⚠ The FAA-N17 report to MAS does NOT replace the separate STR filing obligation to STRO under AML/CFT notices.
- For incidents of fraud, a licensed financial adviser should lodge a police report and submit to the Authority a copy of the report. Where the licensed financial adviser has not lodged a police report, it should notify the Authority of the reasons for its decision. — Ch. 2, p. 3
⚠ Note the language: 'should' for fraud-incident police reporting (recommendation/expectation), not 'shall' (mandatory) — but failure to explain a decision not to lodge a police report would also raise concerns.
- Where a licensed financial adviser has not reported to the Authority a suspicious activity or incident of fraud, it shall document the reasons for its decision. — Ch. 2, p. 3
⚠ Para 5 (document reasons for non-reporting) is distinct from the para 3 requirement to notify MAS of reasons for not lodging a police report.
- The report requires details of suspicious activity or incident of fraud that is material to the safety, soundness or reputation of the financial institution. — Ch. 4, p. 4
⚠ The three-part materiality test is 'safety, soundness or reputation' — any one of the three suffices, not all three.
- Where available, supporting documents such as written and signed statements, investigation reports and police reports must be attached to the report. — Ch. 4, p. 4
⚠ The phrase 'where available' qualifies the obligation — it is not mandatory to create documents that do not already exist.
- The report must state the reasons why the activity/incident is material to the safety, soundness or reputation of the financial institution. — Ch. 4, p. 4
⚠ This is a separate required section (Section 3 of the form) distinct from the description of the activity in Section 2.
- The report must be signed and dated by the reporting officer. — Ch. 4, p. 4
⚠ The signature block is at the end of the form; the Reporting Officer identity is already specified at the top of the form.
⚙️Fsm N23 Scope
Legal basis and applicability of FSM-N23 (technology risk management) to licensed financial advisers
- FSM-N23 is issued pursuant to section 29(1) of the Financial Services and Markets Act 2022 (the 'Act'). — p. 5, 6
⚠ Do not confuse the parent Act (FSMA 2022) with the FAA 2001 under which the licensee is licensed.
- FSM-N23 applies to all financial advisers licensed under the Financial Advisers Act 2001 ('licensee'). — p. 5, 6
⚠ Do not confuse the parent Act (FSMA 2022) with the FAA 2001 under which licensees are licensed.
- FSM-N23 sets out requirements for a high level of reliability, availability and recoverability of critical IT systems. — p. 5, 6
⚠ The triad is reliability, availability and recoverability — all three are required, not just two.
- FSM-N23 sets out requirements to implement IT controls to protect customer information from unauthorised access or disclosure. — p. 5, 6
- This Notice (FSM-N23) is issued pursuant to section 29(1) of the Financial Services and Markets Act 2022 (the “Act”) and applies to all financial advisers licensed under the Financial Advisers Act 2001 (“licensee”). — Ch. 7, p. 7
⚠ Do not mix up the issuing statute (FSMA 2022) with the licensing statute (FAA 2001).
🔧Technology Risk Definitions
Defined terms for technology risk: critical system, system malfunction, IT security incident, relevant incident, system
- "critical system" in relation to a licensee, means a system, the failure of which will cause significant disruption to the operations of the licensee or materially impact the licensee's service to its customers. — Ch. 7, p. 7
⚠ The definition has two alternative prongs (disruption to operations OR material impact on customer service) plus two example categories — the examples illustrate but do not exhaust the definition.
- "IT security incident" means an event that involves a security breach, such as hacking of, intrusion into, or denial of service attack on, a critical system, or a system which compromises the security, integrity or confidentiality of customer information. — Ch. 7, p. 7
⚠ An IT security incident can involve EITHER a critical system OR any system that compromises customer information — it is not limited to critical systems.
- "relevant incident" means a system malfunction or IT security incident, which has a severe and widespread impact on the licensee's operations or materially impacts the licensee's service to its customers. — Ch. 7, p. 7
⚠ A relevant incident must meet a severity threshold (severe AND widespread impact on operations, or material impact on customer service) — it is NOT every system malfunction or IT security incident.
- "system" means any hardware, software, network, or other information technology ("IT") component which is part of an IT infrastructure. — Ch. 7, p. 7
⚠ The term "system" is the broad foundational definition that feeds into "critical system" and other definitions.
- "system malfunction" means a failure of any of the licensee's critical systems. — Ch. 7, p. 7
⚠ System malfunction and IT security incident are distinct — a system malfunction is a failure of a critical system, while an IT security incident is a security breach.
- A "critical system" includes a system which (a) processes transactions that are time critical; or (b) provides essential services to customers. — Ch. 7, p. 7
⚠ These are illustrative examples, not the definition itself. A system could be critical without falling into either example category.
🛡️Technology Risk Obligations
Critical system identification, high availability (4-hour downtime limit), RTO (4-hour), recovery testing, incident notification (1 hour), root cause report (14 days), IT controls for customer info, effective date
- A licensee must put in place a framework and process to identify critical systems. — Ch. 7, p. 8
- A licensee must ensure that the maximum unscheduled downtime for each critical system that affects the licensee's operations or service to its customers does not exceed a total of 4 hours within any period of 12 months.4 hours — Ch. 7, p. 8
⚠ The 4-hour limit is for unscheduled downtime only (not total/planned downtime), per critical system, measured over any rolling 12-month period — not a calendar year.
- A licensee must establish a recovery time objective (RTO) of not more than 4 hours for each critical system.4 hours — Ch. 7, p. 8
⚠ RTO of ≤4 hours is distinct from the unscheduled downtime limit of ≤4 hours in 12 months. RTO is a recovery target from point of disruption; the downtime limit is a cap on actual unscheduled downtime accumulated over 12 months.
- The RTO is the duration of time, from the point of disruption, within which a system must be restored. — Ch. 7, p. 8
⚠ RTO is measured 'from the point of disruption' — not from discovery or notification.
- A licensee must notify the Authority as soon as possible, but not later than 1 hour, upon the discovery of a relevant incident.1 hours — Ch. 7, p. 8
⚠ The 1-hour notification is from discovery of the incident, not from when the incident occurred. The 'as soon as possible' qualifier means even faster than 1 hour is expected where feasible.
- A licensee must submit a root cause and impact analysis report to the Authority within 14 days, or such longer period as the Authority may allow, from the discovery of the relevant incident.14 days — Ch. 7, p. 8
⚠ The 14-day root cause report deadline runs from discovery (like the 1-hour notification), and the Authority may extend it.
- A licensee must implement IT controls to protect customer information from unauthorised access or disclosure. — Ch. 7, p. 8
- A licensee must make all reasonable effort to maintain high availability for critical systems. — Ch. 7, p. 8
⚠ The high availability obligation is a 'reasonable effort' standard, not an absolute guarantee. The specific downtime limit is a separate fact.
- A licensee must validate and document at least once every 12 months how it performs its system recovery testing and when the RTO is validated during the system recovery testing.12 months — Ch. 7, p. 8
⚠ Both the system recovery testing validation AND the RTO validation are documented in the same 12-monthly cycle.
- The root cause and impact analysis report must contain: (a) an executive summary of the relevant incident; (b) an analysis of the root cause which triggered the relevant incident; (c) a description of the impact of the relevant incident on the licensee's compliance with laws and regulations, operations, and service to its customers; and (d) a description of the remedial measures taken to address the root cause and consequences of the relevant incident. — Ch. 7, p. 8
⚠ The impact description has three mandatory sub-components: (i) compliance with laws, (ii) operations, and (iii) service to customers. All must be included.
- This Notice shall take effect on 10 May 2024.2024-05-10 — Ch. 7, p. 8; p. 23
📘Dpi Scope And Definitions
Scope of FAA-N19 (DPI), which advisers are bound, definitions (DPI, conditional acceptance, customer service officer, direct life insurer, exempt FA, financial adviser, online direct channel, representative, Tier 1 life insurer)
- FAA-N17 applies to a licensed financial adviser, an exempt financial adviser, or a representative of a financial adviser, when providing either or both of the following types of financial advisory service which are solely incidental to the distribution of DPI: (i) advising others, either directly or through any publication or writing (other than by issuing or promulgating any research analysis or research report), concerning any DPI; (ii) arranging any contract of insurance in respect of any DPI. — Ch. 11, p. 11
⚠ The advisory service excluding research analysis/research reports is in sub-paragraph (i) — this is not a carve-out from the whole Notice but from the definition of 'advising others'.
- FAA-N17 does not apply to a financial adviser or representative who is exempt from section 27 of the Act under regulations 32B(1) and (3) or regulation 34(1) (read with regulation 34(2)) of the FAR, in respect of the activity or activities for which the exemption applies. — Ch. 11, p. 11
⚠ The exclusion is activity-specific: a person exempt under these regulations for one activity still falls within FAA-N17 for other non-exempt activities.
- Conditional acceptance, in relation to a DPI, refers to any additional conditions or exclusions imposed by a direct life insurer in respect of the application for a DPI. — Ch. 11, p. 11
⚠ The condition is imposed by the direct life insurer, not the financial adviser or the client.
- Financial adviser means a licensed financial adviser or an exempt financial adviser. — Ch. 11, p. 11
⚠ Representative is a separate defined term — a financial adviser is not the same as a representative.
- Representative means an appointed or provisional representative. — Ch. 11, p. 11
⚠ Representative covers both appointed and provisional — not the same as financial adviser.
- Unless otherwise specified, a representative must comply with every requirement imposed on a financial adviser in this Notice when acting on the financial adviser's behalf in relation to the distribution of DPI. — p. 12
⚠ The 'unless otherwise specified' qualifier is easily overlooked — the default is full incorporation of all FA duties, not just those labelled 'representative' duties.
- The advisory service covered by FAA-N17 includes advising others, either directly or through any publication or writing, concerning any DPI, but does not include issuing or promulgating any research analysis or research report. — Ch. 11, p. 11
⚠ The exclusion is for 'issuing or promulgating' research analysis/reports — a candidate could confuse this with a general exclusion of all written communications.
- The services covered by FAA-N17 include arranging any contract of insurance in respect of any DPI. — Ch. 11, p. 11
⚠ Do not confuse the two sub-paragraphs: sub-paragraph (i) has the research exclusion; sub-paragraph (ii) does not.
- Customer service officer means a customer service officer who is exempt from section 23B(1) of the Act under regulation 40A. — Ch. 11, p. 11
⚠ Section 23B(1) is different from section 23(1). The exemption is under regulation 40A specifically.
- Direct life insurer means a direct insurer licensed under section 8 of the Insurance Act (Cap. 142) to carry on life business. — Ch. 11, p. 11
⚠ It is a direct insurer (not a reinsurer) licensed under section 8 of the Insurance Act, not the FAA.
- Exempt financial adviser means a person who is exempt from holding a financial adviser's licence under section 23(1)(a), (b), (c), (d) or (e) of the Act. — Ch. 11, p. 11
⚠ Do not confuse with customer service officer (exempt from s23B(1) under reg 40A). Exempt financial adviser is exempt from holding a licence under s23(1)(a)-(e).
- Online direct channel, in relation to a DPI, means any web portal in the Internet created, developed, maintained or operated by a financial adviser or a direct life insurer, on which a client may purchase the DPI. — Ch. 11, p. 11
⚠ The channel is limited to DPI (Direct Purchase Insurance) and must be a web portal, operated by either a financial adviser or a direct life insurer.
- Tier 1 life insurer means a financial adviser which is a registered insurer that meets the conditions under regulation 4 of the Insurance (Corporate Governance) Regulations 2013. — Ch. 11, p. 11
⚠ A Tier 1 life insurer is a subset of financial advisers (those that are registered insurers meeting specific conditions) — not the same as a direct life insurer.
- The expressions used in this Notice, except where expressly defined in this Notice or where the context otherwise requires, have the same respective meanings as in the Act and the FAR. — Ch. 11, p. 11
⚠ Terms defined in the Notice itself override the Act/FAR meanings, and context may also override.
- FAA-N17 is issued pursuant to Section 58 of the Financial Advisers Act (2001). — Ch. 11, p. 11
- FAA-N17 sets out the requirements for the distribution of DPI. — Ch. 11, p. 11
🏛️Dpi Distribution Channels
Permitted channels for DPI distribution: representative, customer service officer, online direct channel; Tier 1 life insurer minimum requirements
- Subject to paragraph 9, a financial adviser must only distribute DPI through its representative or customer service officer, or by way of an online direct channel. — p. 12, 13
⚠ The rule is subject to paragraph 9 — the Tier 1 life insurer special rule is a carve-out, not a separate option.
- A financial adviser who is a Tier 1 life insurer must, at the minimum, distribute DPI either through its representative or customer service officer at the Tier 1 life insurer's principal place of business or branch office (not being a mobile branch). The financial adviser may also distribute DPI by way of an online direct channel provided that it also distributes DPI through a representative or customer service officer at its principal place of business or branch office. — p. 12, 13
⚠ This is an additional minimum requirement for Tier 1 life insurers, not a replacement of paragraph 8. Online-only distribution is not sufficient for a Tier 1 life insurer.
📌Dpi Client Safeguards
Five requirements (safeguards, product info, queries/helplines, internal policies, roles and responsibilities) and the check on affordability, coverage, understanding
- Where a client intends to purchase a DPI, the financial adviser must implement safeguards so as to ensure that the client has carried out steps to check that (i) he is able to afford the premiums payable in respect of the DPI; (ii) the DPI adequately covers his protection needs; and (iii) he has not misunderstood any features or terms and conditions of the DPI. — p. 12, 13
⚠ The three checks are a named set (afford premiums, adequate coverage, no misunderstanding of features/terms). All three must be implemented.
- The five requirements a financial adviser must comply with in respect of its distribution of DPI through representatives, customer service officers, or by way of an online direct channel are: (a) implementation of safeguards; (b) provision of product information; (c) provision of avenues to address general queries, complaints and claims; (d) implementation of internal policies and processes; and (e) setting out the roles and responsibilities of a representative or customer service officer. — p. 12, 13
⚠ This is a named enumeration — all five must be recalled together. The fifth requirement (roles and responsibilities) is the most commonly dropped.
- The financial adviser must put in place procedures to ensure that information relating to the DPI is provided to a client who intends to purchase DPI, as set out in paragraphs 13 and 14. — p. 12, 13
⚠ This is about procedures for providing information — the actual content of what information is provided is governed by paragraphs 13 and 14 (not extracted here).
- The financial adviser must set up appropriate avenues to address general queries from its clients relating to DPI, including but not limited to phone or email helplines. The financial adviser must also provide information, such as contact details, information on the claims process and the process for filing complaints. — p. 12, 13
⚠ This covers both query-handling avenues (phone/email helplines) and provision of information (contact details, claims process, complaints process).
- The financial adviser must implement the internal policies and processes as set out in paragraph 15 in relation to the financial adviser's distribution of DPI, including adequate control systems and procedures to ensure that the financial adviser's customer service officer does not provide any financial advisory service which is not solely incidental to the distribution of DPI. — p. 12, 13
⚠ The key phrase is 'not solely incidental' — CSOs may provide advisory services that are incidental to DPI distribution, but nothing beyond that.
- The financial adviser must set out in its policies and procedures the respective roles and scope of responsibilities of a representative and a customer service officer who distributes DPI on behalf of the financial adviser, as set out in paragraphs 16 and 17. — p. 12, 13
⚠ This covers both representatives AND customer service officers — a common source of error on exams.
📄Dpi Product Information Rep Cso
Product information duties when DPI is distributed via representative or customer service officer: tools/calculators, required disclosures (disclaimers, exclusions, conditional acceptance, proposal form, free-look, etc.)
- A financial adviser must, in respect of every DPI it distributes, make available to a client such tools and calculators which enable the client to calculate: (a) the coverage of the DPI, so that the client may determine if the DPI adequately covers his protection needs; and (b) the total amount of premiums payable for the DPI, so that the client may determine if he is able to afford the DPI based on his income and financial commitments. — Ch. 14, p. 14
⚠ Both limbs (a) and (b) are mandatory — exam may test whether one is optional.
- Where a financial adviser distributes DPI through its representative or customer service officer, the financial adviser must require the representative or customer service officer to highlight to the client any conditions, including special exclusions or additional premium loadings imposed by a direct life insurer as a result of underwriting the policy application, and where the client intends to purchase a DPI with a conditional acceptance, obtain the client's acknowledgement that he has read and understood such conditions before purchasing the DPI. — Ch. 14, p. 14
⚠ This is a two-part requirement: (1) highlight conditions from underwriting, (2) if conditional acceptance, obtain signed acknowledgement before purchase.
- Where a financial adviser distributes DPI through its representative or customer service officer, the financial adviser must require the representative or customer service officer, before the client completes his application for the DPI, to alert the client in a clear, simple and concise manner that: (i) the DPI is not a savings account or deposit; (ii) the client may not get back the premiums paid (partially or in full) if the client terminates or surrenders the policy early; (iii) some benefits of the DPI are not guaranteed (only if applicable); and (iv) there is a 14-day free-look period. — Ch. 14, p. 14
⚠ Item (iii) is conditional — 'only if applicable'. The other three are always required.
- Where a financial adviser distributes DPI through its representative or customer service officer, the financial adviser must require the representative or customer service officer to provide the information relating to the DPI as set out in paragraph 13 of FAA-N19 to the client. — Ch. 14, p. 14
⚠ Paragraph 13's information is not reproduced here — the fact is that it must be provided, not its content.
- Where a financial adviser distributes DPI through its representative or customer service officer, the financial adviser must require the representative or customer service officer to highlight to the client any disclaimer, exclusion or warning of the DPI. — Ch. 14, p. 14
⚠ Do not confuse with sub-paragraph (b)(ii) which covers conditions and special exclusions from underwriting.
- Where a financial adviser distributes DPI through its representative or customer service officer, the financial adviser must require the representative or customer service officer to prompt the client to make the necessary declarations in the proposal form, including declarations on any pre-existing medical conditions and whether the client has any other existing life policies. — Ch. 14, p. 14
⚠ The word 'prompt' means actively encourage/remind — not 'fill in' or 'verify'.
- Where a financial adviser distributes DPI through its representative or customer service officer, the financial adviser must require the representative or customer service officer to highlight any portion of the proposal form for the purchase of the DPI which, to the knowledge of the representative or customer service officer, has been incorrectly completed, to the client, and ensure that all mandatory fields in the proposal form for the purchase of the DPI have been completed. — Ch. 14, p. 14
⚠ Two distinct duties: (i) highlight known errors to client, (ii) ensure mandatory fields are completed.
- For the purpose of sub-paragraph (b)(ii), examples of conditional acceptance include instances where the direct life insurer's acceptance of a client's policy is contingent upon exclusion of the client's pre-existing medical condition; or upon additional premium loading imposed by the direct life insurer due to the client's pre-existing medical condition. — Ch. 14, p. 14
⚠ These are examples given by the Notice, not an exhaustive list of what constitutes conditional acceptance.
💻Dpi Product Information Online
Product information duties when DPI is distributed via online direct channel: documents, fact sheet, checklist, policy wordings, mandatory fields
- Where a financial adviser distributes DPI through its representative or customer service officer, the financial adviser must ensure that at the point of a client's application for the purchase of a DPI, the representative or customer service officer furnishes the following documents to the client: (a) the documents set out in paragraph 37(b) of the MAS Notice on Recommendations on Investment Products (FAA-N16); (b) the fact sheet and checklist that are prepared by a direct life insurer in accordance with the industry standards for DPI, as issued by the Life Insurance Association, Singapore. — Ch. 15, p. 15
⚠ Paragraph 13 (representative/customer service officer distribution) requires only (a) FAA-N16 para 37(b) docs + (b) fact sheet & checklist from insurer. The policy wordings requirement belongs to paragraph 14 (online direct channel).
- Where a financial adviser distributes DPI by way of an online direct channel, the financial adviser shall: (a) provide the information required in paragraphs 12(a) to (b) through the online direct channel to the client; (b) comply with the requirements under paragraphs 12(c) and (e) through the online direct channel; (c) ensure that all mandatory fields in the proposal form for the purchase of the DPI have been completed before processing the proposal form; and (d) at the point of a client's application for the purchase of a DPI, provide the information required in paragraph 13(a) and (b), and an online copy of, or access to the full and actual policy wordings of the DPI. — Ch. 15, p. 15
⚠ Distinguish between distribution channels: para 13 (rep/CSO) vs para 14 (online direct). The online channel has additional obligations: mandatory fields completion and providing policy wordings.
- Where a financial adviser distributes DPI by way of an online direct channel, at the point of a client's application for the purchase of a DPI, the financial adviser must provide the information required in paragraph 13(a) and (b), and an online copy of, or access to, the full and actual policy wordings of the DPI. — Ch. 15, p. 15
⚠ Policy wordings are only required for the online direct channel (para 14(d)), not for representative/CSO distribution. Also note the format: 'online copy of, or access to' the wordings.
- The documents set out in paragraph 37(b) of the MAS Notice on Recommendations on Investment Products (FAA-N16) must be furnished to a client purchasing DPI through a representative or customer service officer, and also must be provided at the point of a client's application for DPI purchased through an online direct channel. — Ch. 15, p. 15
⚠ The FAA-N16 para 37(b) documents are required in BOTH distribution channels — this is a bridging fact across paras 13 and 14.
- The fact sheet and checklist for DPI must be prepared by a direct life insurer in accordance with the industry standards for DPI issued by the Life Insurance Association, Singapore. — Ch. 15, p. 15
⚠ The fact sheet & checklist are prepared by the direct life insurer (not the FA), and the standard is from LIA (not MAS).
- Where a financial adviser distributes DPI by way of an online direct channel, the financial adviser must ensure that all mandatory fields in the proposal form for the purchase of the DPI have been completed before processing the proposal form. — Ch. 15, p. 15
⚠ Only mandatory fields must be completed — not all fields — and this applies only to the online direct channel.
- The provision of product information requirements under FAA-N19 distinguish between two methods of DPI distribution: (i) distribution through a representative or customer service officer; and (ii) distribution by way of an online direct channel. — Ch. 15, p. 15
⚠ The section's two paragraphs apply to different distribution channels. Distinguish which requirements apply to which channel.
📎Dpi Internal Policies And Training
Internal policies, processes, controls, training for representatives and CSOs, online channel BCP and information security
- A financial adviser must implement internal policies and processes, including adequate control systems and procedures, relating to the distribution of DPI. — Ch. 16, p. 16
⚠ The word 'must' makes this mandatory — do not confuse with a recommendation.
- The internal policies and processes must include: (a) policies and processes which set out the respective responsibilities of the representative and customer service officer, in relation to their respective distribution of DPI on behalf of the financial adviser, including clear guidelines relating to the manner of distribution of DPI and informing clients the manner in which and the locations at where a DPI may be purchased. — Ch. 16, p. 16
⚠ This names two specific roles (representative and customer service officer) and their respective DPI responsibilities — not just one role.
- The internal policies and processes must include training for every representative or customer service officer who distributes DPI on behalf of the financial adviser, and the training must, at the minimum, cover the role and scope of responsibilities of a representative or customer service officer in relation to his distribution of DPI on behalf of the financial adviser, and the risks and features of DPI. — Ch. 16, p. 16
⚠ Training is mandatory but only for those who distribute DPI, not all staff. Two minimum content areas: (i) role/responsibilities and (ii) risks/features.
- The internal policies and processes must include, in relation to the online direct channel, policies and processes for distribution of DPI, including instituting controls and safeguards to adequately address information security risks, and putting in place an appropriate business continuity plan to minimise system downtime or component failures to the online direct channel, and to ensure the functionality and continued operation of the online direct channel at all times. — Ch. 16, p. 16
⚠ This requirement is specifically about the online direct channel — distinct from the general policies in (a).
- The internal policies and processes must include controls and procedures to ensure the proper conduct of the representative or customer service officer who distributes DPI, including, where appropriate, instituting procedures to make call-backs to clients or conducting mystery shopping exercises. — Ch. 16, p. 16
⚠ The word 'where appropriate' qualifies both call-backs and mystery shopping — neither is an unconditional requirement.
📢Dpi Disclosure Standards
Clear, adequate, not false or misleading standards for DPI information; annual review; reasonable basis for opinions
- A financial adviser or representative who provides a recommendation in relation to a DPI which is not solely incidental to the distribution of the DPI must comply with Part I Chapter 6C of the Act, as well as the Regulations and Notices which apply to the provision of financial advice. — p. 16, 17
⚠ The 'not solely incidental' condition is key — if the recommendation is merely incidental to distribution, this obligation may not arise.
- A financial adviser, or a representative or customer service officer of the financial adviser, is expected to meet the following general standards in all product information disclosures and information provided to clients in relation to a DPI: (a) Clear, (b) Adequate, (c) Not False or Misleading. — p. 17
⚠ There are exactly three named standards — Clear, Adequate, Not False or Misleading. Do not add a fourth or substitute 'Accurate' or 'Concise'.
- Under the 'Clear' standard: (i) information disclosed to clients in any advertisement or publicity material in any media should be presented in plain language and in a manner that is easy for clients to understand; (ii) jargon or technical terms used should be clearly explained to clients. — p. 17
⚠ The 'Clear' standard has two sub-parts — do not confuse with 'Adequate' sub-parts.
- Under the 'Adequate' standard: (i) information disclosed to clients should meet regulatory requirements and accord with industry best practices, and be sufficient to help clients make an informed decision; (ii) warnings and important information such as the nature and objective of DPI, risks of DPI, fees and charges, and contractual rights and obligations of clients should be prominently presented and clearly explained. — p. 17
⚠ The 'Adequate' standard has two sub-parts: (i) regulatory compliance + informed decision; (ii) prominence of warnings.
- Under the 'Not False or Misleading' standard: (i) information disclosed to clients should not be ambiguous in language or presentation; (ii) information relating to DPI should be disclosed in an objective and unbiased manner; (iii) where an opinion is expressed, there should be a reasonable basis for expressing the opinion and it should be unambiguously stated that it is a statement of opinion; (iv) documents to be given to clients should be kept up-to-date and reviewed at least annually.1 year — p. 17
⚠ The 'Not False or Misleading' standard has four sub-parts, including the specific annual document review requirement. 'At least annually' is a numeric deadline.
- Documents to be given to clients in relation to a DPI must be kept up-to-date and reviewed at least annually.1 year — p. 17
⚠ This fact restates sub-part (iv) of the 'Not False or Misleading' standard as a standalone requirement — the annual review applies to documents given to clients.
- Where an opinion is expressed in information provided to clients in relation to a DPI, there must be a reasonable basis for expressing the opinion and it must be unambiguously stated that it is a statement of opinion. — p. 17
⚠ Two cumulative requirements: reasonable basis + unambiguous labelling as opinion. One without the other is non-compliant.
⏳Dpi Transitional And Penalties
Effective date of FAA-N19 Amendment 2019, transitional arrangements for online direct channel, and the section 58(5) penalty for contravention
- Notwithstanding the effective date of FAA-N19 (Amendment) 2019, paragraphs 12 to 14 of the Notice in force immediately before 30 August 2019 continue to apply to financial advisers who have distributed DPI on an online direct channel prior to 30 August 2019 as if the amendments to paragraphs 12 to 14 in FAA-N19 (Amendment) 2019 have not been made, until 31 December 2019. — Ch. 18, p. 18
⚠ The transitional arrangement preserves the old (pre-amendment) paragraphs 12-14, not the new ones — candidates often invert which version applies during the transition.
- Any person who contravenes any requirement specified in a written direction issued by the Authority (which would include this Notice), shall be guilty of an offence and shall be liable on conviction to a fine not exceeding S$25,000 and, in the case of a continuing offence, to a further fine not exceeding S$2,500 for every day or part thereof during which the offence continues after conviction.S$25,000 — Ch. 18, p. 18
⚠ The penalty under s58(5) is a fine only (no imprisonment term), unlike some other FAA offence provisions. The continuing offence daily fine is S$2,500, not a percentage of the maximum.
- FAA-N19 (Amendment) 2019 has effect from 30 August 2019.2019-08-30 — Ch. 18, p. 18
⚠ Do not confuse the effective date (30 Aug 2019) with the transitional period end date (31 Dec 2019).
- In the case of a continuing offence under section 58(5) of the Act, the offender is liable to a further fine not exceeding S$2,500 for every day or part thereof during which the offence continues after conviction.S$2,500 — Ch. 18, p. 18
⚠ The S$2,500 daily fine is per day or part thereof, and only after conviction — not for the entire period of the continuing offence.
- A written direction issued by the Authority includes a notice issued under the FAA for the purposes of section 58(5) of the Act. — Ch. 18, p. 18
⚠ The Notice itself is treated as a 'written direction' for the purpose of the s58(5) offence — candidates sometimes think Notices and written directions are separate categories.
🔐Fsm N24 Scope And Cyber Obligations
Scope of FSM-N24 and the six cyber security requirements: administrative accounts, security patching, baseline standards, network devices, anti-malware, multi-factor authentication
- FSM-N24 is issued pursuant to section 29(1) of the Financial Services and Markets Act 2022 (the 'Act').29(1) section — Ch. 19, p. 20
⚠ Distinguish FAA (Financial Advisers Act) from FSMA (Financial Services and Markets Act) — FSM-N24 is under FSMA, not FAA.
- FSM-N24 applies to all financial advisers licensed under the Financial Advisers Act 2001 (each a 'relevant entity'). — Ch. 19, p. 20
⚠ The term 'relevant entity' is defined here as a financial adviser licensed under the FAA 2001.
- FSM-N24 sets out cyber security requirements on: securing administrative accounts, applying security patching, establishing baseline security standards, deploying network security devices, implementing anti-malware measures, and strengthening user authentication. — Ch. 19, p. 20
⚠ This is a named enumeration — the six areas form a complete set. All six must be recalled together.
- This Notice applies to all financial advisers licensed under the Financial Advisers Act 2001 (each a 'relevant entity'). — Ch. 21, p. 21
⚠ 'Relevant entity' is defined here as a financial adviser licensed under the FAA 2001.
- An "administrative account" means any user account that has full privileges and unrestricted access to any one or more of the following systems: (a) an operating system; (b) a database; (c) an application; (d) a security appliance; or (e) a network device. — p. 6D-4
⚠ The wording is 'any one or more' — access to one system on the list is sufficient, not all five.
- "Customer information" means any information relating to, or any particulars of, any customer of the relevant entity, where a named customer or group of named customers can be identified, or is capable of being identified, from such information. — p. 6D-4
⚠ Covers both named customers and groups of named customers, and includes information from which identification is merely capable (not necessarily already achieved).
- "Critical system" in relation to a relevant entity means a system the failure of which will cause significant disruption to the operations of the relevant entity or materially impact the relevant entity's service to its customers, such as a system which— (a) processes transactions that are time critical; or (b) provides essential services to customers. — p. 6D-4
⚠ The test is 'or' (either significant disruption to operations OR material impact on service), and the examples are illustrative ('such as'), not exhaustive.
- "Multi-factor authentication" means the use of two or more factors to verify an account holder's claimed identity. Such factors include, but are not limited to— (a) something that the account holder knows such as a password or a personal identification number; (b) something that the account holder has such as a cryptographic identification device or token; (c) something that the account holder is such as an account holder's biometrics or his behaviour.2 factors — p. 6D-4
⚠ Multi-factor means two or more different CATEGORIES of factors (know/have/are), not just two pieces of information.
- A relevant entity need not comply with a requirement in this Notice to the extent that it is unable to exercise control over a system to ensure compliance with that requirement, where all three conditions are met: (a) the relevant entity cannot exercise direct control over the system to ensure compliance; (b) the relevant entity cannot exercise indirect control over the system by requiring the system provider to ensure compliance; and (c) it is not reasonable for the relevant entity to procure an alternative system provider over whom the relevant entity is able to exercise such indirect control. — Ch. 22, p. 22
⚠ All three conditions are conjunctive — the entity must satisfy (a) AND (b) AND (c) for the exception to apply.
- A relevant entity must ensure that every administrative account in respect of any operating system, database, application, security appliance or network device is secured to prevent any unauthorised access to or use of such account. — p. 22, 23
⚠ The obligation is limited to administrative accounts, not all accounts. Scope covers operating systems, databases, applications, security appliances, and network devices.
- A relevant entity must ensure that security patches are applied to address vulnerabilities to every system, and apply such security patches within a timeframe that is commensurate with the risks posed by each vulnerability. — p. 22, 23
⚠ The timeframe is risk-based (commensurate with the risk posed by each vulnerability), not a fixed period. Applies to 'every system', not only critical systems.
- Where no security patch is available to address a vulnerability, the relevant entity must ensure that controls are instituted to reduce any risk posed by such vulnerability to such a system. — p. 22, 23
⚠ This is an alternative obligation that kicks in only when no security patch exists. Do not confuse with the patching obligation in 4.2(a).
- A relevant entity must ensure that one or more malware protection measures are implemented on every system, to mitigate the risk of malware infection, where such malware protection measures are available and can be implemented. — p. 22, 23
⚠ The obligation is conditional — it only applies where malware protection measures 'are available and can be implemented'. Also requires 'one or more' measures, not a specific type.
- A relevant entity must ensure that multi-factor authentication is implemented for all administrative accounts in respect of any operating system, database, application, security appliance or network device that is a critical system. — p. 22, 23
⚠ MFA under (a) is only for administrative accounts on critical systems — do not confuse with (b) which covers accounts accessing customer info via the internet. Also distinct from para 4.1 which requires all admin accounts to be secured (not necessarily with MFA).
- A relevant entity must ensure that multi-factor authentication is implemented for all accounts on any system used by the relevant entity to access customer information through the internet. — p. 22, 23
⚠ This is limb (b) of the MFA requirement — covers all accounts (not just admin) on systems accessing customer info via the internet. No 'critical system' condition applies here, unlike limb (a).
- This Notice is issued pursuant to section 29(1) of the Financial Services and Markets Act 2022 (the Act). — Ch. 21, p. 21
⚠ The enabling Act is the Financial Services and Markets Act 2022, not the Financial Advisers Act 2001.
- The three categories of factors for multi-factor authentication are: (a) something the account holder knows (e.g., password or PIN); (b) something the account holder has (e.g., cryptographic identification device or token); and (c) something the account holder is (e.g., biometrics or behaviour). — p. 6D-4
⚠ Distinguish the factor categories (knows/has/is) from the factor examples (password/token/biometric).
- "Security patch", in relation to a system, means an update that can be applied to the system to address a vulnerability. — p. 6D-4
⚠ Do not confuse 'security patch' (an update that addresses a vulnerability) with 'security standards' (a set of configurations).
- "Security standards", in relation to a system, means a set of configurations for the purpose of safeguarding and improving the security of the system. — p. 6D-4
⚠ Security standards are configurations for safeguarding/improving security generally; a security patch is an update addressing a specific vulnerability.
- "System", in relation to a relevant entity, means any hardware or software that is used by the relevant entity. — p. 6D-4
⚠ Note 'used by' (not 'owned by') covers systems the entity employs regardless of ownership.
- "Vulnerability", in relation to a system, means any weakness, susceptibility or flaw of the system that can be exploited, including but not limited to by allowing an unauthorised person to access the system, or to compromise the security configuration settings of the system. — p. 6D-4
⚠ A vulnerability is the weakness itself; a security patch is the update that addresses it.
- A relevant entity must ensure that there is a written set of security standards for every system. — p. 22, 23
⚠ The standards must be 'written' — oral or unwritten standards do not satisfy the requirement. Applies to 'every system', not only critical ones.
- Subject to sub-paragraph (c), a relevant entity must ensure that every system conforms to the set of security standards. — p. 22, 23
⚠ This obligation is 'subject to' para 4.3(c) — the exception for non-conforming systems is a carve-out that must be remembered alongside the rule.
- Where the system is unable to conform to the set of security standards, the relevant entity must ensure that controls are instituted to reduce any risk posed by such non-conformity. — p. 22, 23
⚠ This is the exception that qualifies the conformance obligation in 4.3(b). The carve-out creates a fallback: if the system cannot conform, institute controls instead.
- A relevant entity must implement controls at its network perimeter to restrict all unauthorised network traffic. — p. 22, 23
⚠ The controls are at the 'network perimeter' (boundary of the network), not at individual systems. The restriction applies to 'unauthorised' traffic, not all traffic.
- A relevant entity must ensure that multi-factor authentication is implemented for the following: (a) all administrative accounts in respect of any operating system, database, application, security appliance or network device that is a critical system; and (b) all accounts on any system used by the relevant entity to access customer information through the internet. — p. 22, 23
⚠ This compound fact captures BOTH limbs of the MFA requirement as a named set. Each has different scope: (a) admin accounts on critical systems; (b) all accounts on systems accessing customer info via the internet.
- Except where defined in this Notice or if the context otherwise requires, expressions used in this Notice have the same meanings as in the Act. — p. 6D-4
⚠ Two exceptions: (1) if defined in the Notice, that definition applies; (2) if context requires otherwise, that meaning applies.