Download PDF for Due Diligence
DeSuite Logo

Memorandum of Regulatory Classification

Pursuant to the Singapore Payment Services Act 2019
TO: Compliance & Risk Management Divisions / Strategic Partners
FROM: DeSuite Engineering & Compliance
DATE: February 23, 2026
SUBJECT: Classification under the Singapore Payment Services Act 2019 (PSA)

1. Executive Summary

This memorandum serves as the formal regulatory self-assessment of DeSuite’s infrastructure. Based on the "Key-Blind" architectural model, DeSuite operates strictly as an Excluded Information Technology (IT) Service Provider. DeSuite does not carry on a business of providing regulated payment services and is therefore not subject to licensing as a Major Payment Institution (MPI) under the PSA. All regulated movement of value is executed by Circle Internet Singapore Pte. Ltd. (MAS MPI License Holder).

2. Technical Factual Matrix

DeSuite provides an integration layer between Oracle ERP and licensed digital asset custodians. The architecture enforces Non-Custodial Sovereignty through two pillars:

"DeSuite operates strictly as a data-routing utility. Cryptographic authorization remains under the exclusive custody of the customer's private cloud network, while fund custody and settlement execution are managed entirely by the licensed Major Payment Institution."

3. Legal Analysis (PSA 2019 & 2024 Amendments)

Under the First Schedule, Part 2 of the Payment Services Act 2019 (as amended in April 2024), technical service providers that support payment services—without entering into possession or control of the assets—are explicitly excluded from the definition of a payment service.

DeSuite maintains its Excluded Service Provider status under the amended framework as:

Industry Precedent: This architecture mirrors established enterprise models deployed by global ERP vendors, such as SAP's Digital Currency Hub (DCH) for SAP S/4HANA. Similar to these platforms, DeSuite acts as an integration gateway rather than a custodian, maintaining a strict division of responsibility between the data-routing software layer and the regulated financial custody layer.

4. Institutional Reliance & Custody

All actual settlement and fund transmission are executed through the regulated infrastructure of Circle Internet Singapore Pte. Ltd., a Major Payment Institution licensed by the Monetary Authority of Singapore. Circle, as the licensed Major Payment Institution hosting the transactional rail, executes the mandatory KYB/AML screening, transaction monitoring, and custody of underlying digital assets.

5. Client Regulatory Status & Compliance Allocation

Under this division of responsibility, the corporate client is legally classified as a commercial end-user, not a payment service provider. DPT licensing under the Singapore Payment Services Act 2019 applies exclusively to entities offering digital payment token services to third parties as a business activity. Because the client is using stablecoins solely to settle its own first-party Accounts Payable invoices via a wallet hosted by Circle, the client carries zero licensing requirements under the PS Act as a payment service provider, maintaining only standard corporate customer onboarding (KYB) and transaction screening compliance with its chosen payment institution.

Regarding Travel Rule compliance (FATF Recommendation 16 / MAS PSN02) for the transaction flow (Circle Mint Sweep ➔ Client Developer-Controlled Wallet ➔ Client Suppliers), the execution and reporting responsibility resides entirely with Circle as the licensed sending VASP. The client does not act as a VASP and holds no independent Travel Rule transmission liabilities; their operational role is limited to providing beneficiary details (automatically retrieved from the Oracle ERP DFFs) to Circle via API metadata, which Circle then processes and transmits to the receiving VASP or records internally.