Welcome

AML/CFT/CPF Foundations for Corporate Service Providers

A foundational training programme on anti-money laundering, counter-financing of terrorism, and counter-proliferation financing for people who work in or for Singapore-registered Corporate Service Providers.

Before you begin

This programme is the foundation of your AML/CFT/CPF training. It covers what you need to recognise, what you need to escalate, and where you fit in the firm's controls. It is the starting point — not the entirety — of what your CSP will train you on.

The programme is in six lessons, each 45–60 minutes. There is one terminal assessment of 20 questions and one certificate at the end. Total time, including the assessment, is around five and a half hours.

Used only to personalise your certificate at the end of the programme. Held in your browser session — not transmitted anywhere.

When you are ready, click Continue to read the programme disclaimer. You must read and acknowledge the disclaimer before starting Lesson 1.

Audience
All staff
Total time
~5h 30m
Lessons
6
Assessment
20 questions, 80% pass
Programme disclaimer

Please read before starting

About this programme

This is a training programme on anti-money laundering (AML), counter-financing of terrorism (CFT), and counter-proliferation financing (CPF) for people who work in or for Singapore-registered Corporate Service Providers (CSPs).

The programme is foundational. It covers the concepts, obligations, and behaviours expected of every member of staff. It is the starting point of your AML/CFT/CPF training, not the entirety of it.

What this programme is

  • Training content covering the foundations of AML/CFT/CPF as relevant to a Singapore CSP.
  • A structured introduction to the Singapore regulatory framework — the Corporate Service Providers Act 2024, the Corporate Service Providers Regulations 2025, and the ACRA Guidelines for Registered Corporate Service Providers.
  • A reference point for what ordinary staff are expected to recognise, escalate, and document.

What this programme is NOT

  • It is not legal advice. Nothing in this programme should be relied on as legal advice in any specific situation.
  • It is not regulatory advice. ACRA, MAS, the Police, STRO, and other authorities provide their own guidance which takes precedence.
  • It is not a substitute for your CSP's own Internal Policies, Procedures and Controls (IPPC). The IPPC is the operational rulebook for your firm. This programme teaches the foundations on which your IPPC is built — but the IPPC tells you how your firm specifically does things.
  • This programme is designed to support the registered Corporate Service Provider's obligation to train the people who work in or for it on AML/CFT/CPF laws and on its Internal Policies, Procedures and Controls (IPPC), as required under regulation 37 of the Corporate Service Providers Regulations 2025 and paragraph 6.72 of the ACRA Guidelines for Registered Corporate Service Providers. Completing this programme is one part of that training framework. It does not, on its own, fully satisfy the CSP's training obligations — those obligations also require IPPC-specific training that is unique to each CSP. The registered Corporate Service Provider using this programme remains solely responsible for confirming that the content, depth, frequency, and IPPC-specific supplementation are adequate to meet its training obligations.

Your responsibility

  • Complete the programme in good faith.
  • Apply what you learn in your work.
  • Follow your CSP's IPPC at all times.
  • When in doubt, escalate to your Compliance Officer or MLRO. Recognising that you are not sure is itself a useful instinct — escalation is the safe response.

Currency of content

The regulatory framework changes. This programme content is correct as at the date stated on the welcome screen. Where there has been a regulatory change since that date, the content in this programme may not reflect the current position. Your CSP is responsible for ensuring the version of this programme that is deployed to its staff is current.

Tick the box above to acknowledge before continuing.
Lesson 1 of 6

Foundations of AML/CFT/CPF for Corporate Service Providers

The concepts, the global framework, and the role you play.

Audience
All staff
Duration
~45 minutes
Screens
11 + 2 checks
Knowledge checks
2 (formative)

By the end of this lesson, you will be able to:

  1. Distinguish money laundering, terrorism financing, and proliferation financing.
  2. Recognise the three stages of money laundering and identify which stages a CSP is most exposed to.
  3. Explain why corporate service providers are specifically targeted by financial criminals.
  4. Identify Singapore's place within the FATF framework.
  5. Recognise that AML/CFT/CPF responsibility extends to every staff member, not only client-facing staff.
Screen 1.2

Why this matters

Anti-money laundering, counter-financing of terrorism, and counter-proliferation financing are not abstract concepts. They are the daily background to every customer relationship a CSP holds.

Singapore is one of the world's leading financial and corporate-services hubs. That status comes with exposure. Criminals look for jurisdictions with strong financial infrastructure and access to the global economy — the same qualities that make Singapore an attractive place to do legitimate business.

Corporate service providers sit at the entry point. The CSP incorporates the company, provides the registered office, files with ACRA, holds the customer relationship. Almost every cross-border financial structure that touches Singapore touches a CSP.

That position carries responsibility. ACRA regulates CSPs precisely because the corporate-services sector is exposed to misuse. The training you are starting now is the foundation of how the firm — and you, as a member of staff — meet that responsibility.

What this lesson is for. Lesson 1 sets the foundations. You will finish able to recognise what money laundering, terrorism financing, and proliferation financing actually are, why CSPs are exposed, and where you fit in. The lessons that follow build on this base.
Screen 1.3

What is money laundering?

ACRA defines money laundering as a process carried out with the intention to conceal the benefits obtained from criminal activity so that they appear to have originated from legitimate sources.

The criminal proceeds — money, securities, property — are mixed with or exchanged for assets that have no obvious link to their criminal origin. By the time the laundering process is complete, the proceeds look clean.

The act of laundering is itself a criminal offence in Singapore. The legal framework that criminalises it is examined in Lesson 6. For now, the foundational point is this: laundering is a process, not a single act, and it is designed to defeat detection.

Key terms used throughout the programme

Tap each card to see the definition.

SourceACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraph 5.1.
Screen 1.4

The three stages of money laundering

Money laundering generally moves through three distinct stages: placement, layering, and integration. Each stage has different exposure for a CSP — step through the diagram below to see each in turn.

Placement → Layering → Integration
CASH BANK deposit Shell Co A (Jurisdiction X) Shell Co B (Jurisdiction Y) Shell Co C (Jurisdiction Z) BANK PROPERTY "investment"
Stage 1 of 3
Placement

The physical disposal of the benefits of criminal activity. Cash or assets are introduced into the financial system through deposits, exchanges, or asset purchases.

A CSP is rarely the entry point for placement directly, but may see its consequences — for instance, an unexplained large initial deposit into a newly-incorporated structure.
SourceACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraph 5.2.
Knowledge Check 1 of 2

Identify the stage

Knowledge Check

Which stage of money laundering is best illustrated below?

A customer has incorporated a Singapore private limited company through the CSP three weeks ago. The customer now uses that company to receive and on-pay funds rapidly between three other corporate entities in different jurisdictions. There is no apparent commercial activity — money in, money out, no trading.
Choose the best answer.

Knowledge checks are formative — they help you consolidate. Your answer is not scored toward the terminal assessment.

Screen 1.5

What is terrorism financing?

Terrorism seeks to influence, compel, or intimidate governments or the public through threats or violence. Terrorism financing is the funding of those activities. It overlaps with money laundering in method but differs in important ways.

The most consequential difference: the source of terrorism financing may be entirely legitimate. Funds for a terrorist act can come from criminal sources, but they can also come from a legitimate business, a charitable donation, or a personal salary.

Tap through the tabs below to see how TF is defined, how the funds move, and where it differs from ML.

What terrorism financing is

Terrorism is action that seeks to influence, compel, or intimidate governments or the public through threats or violence — to cause damage to property or danger to life, to create serious risks to public health or safety, or to disrupt critical public services or infrastructure.

Terrorism financing is the funding of those activities. The methods used by terrorist organisations to obtain, move, or conceal funds can be similar to those used by criminal organisations to launder funds.

In Singapore, terrorism financing is criminalised under the Terrorism (Suppression of Financing) Act 2002. The framework that the staff member needs to recognise is examined in Lessons 4 and 6.

Where the funds can come from

Sources of terrorism financing may be legitimate or illegitimate.

  • Funds may be derived from criminal activities — narcotics, fraud, smuggling.
  • Funds may be derived from legitimate sources — a business operated by sympathisers, a salary diverted to a cause, a charitable donation.
  • Funds may be very small in individual amount but large in aggregate.
A CSP cannot screen on source-of-funds alone for TF. Pattern recognition matters more — does the relationship match what the customer says it is?

The key differences from money laundering

Money laundering is about disguising the origin of funds. Terrorism financing is about disguising the destination.

Three operational consequences for a CSP:

  • TF amounts can be small. Threshold-based controls miss them.
  • TF can use legitimate funds. Source-of-funds investigation alone will not detect TF.
  • TF detection often comes from screening against designated persons and entities, not from transaction analysis.
Lesson 4 covers the Singapore targeted financial sanctions regime — UN Act, TSOFA, MAS, IMC-TD — and what it means for the CSP.
Viewed 1 of 3 tabsClick each tab to explore
SourceACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraphs 5.3 and 5.4. Terrorism (Suppression of Financing) Act 2002.
Screen 1.6

What is proliferation financing?

Proliferation financing — abbreviated PF — is the provision of funds or financial services that support the development, acquisition, or transfer of nuclear, chemical, or biological weapons and their delivery systems.

This includes funding research and development, procuring materials and equipment, facilitating transportation and logistics, and supporting the overall infrastructure needed for weapons-of-mass-destruction programmes. The funds may flow through traditional banking, informal value transfer methods, or emerging technologies including cryptocurrencies. The methods are often deliberately complex to evade detection and sanctions.

Designated person/entity Front Co (opaque) Trading Co (opaque) Dual-use goods or technology (WMD-relevant)
A typical PF structure: funds from a designated person flow through opaque corporate vehicles toward dual-use goods or technology. CSPs are exposed at the corporate-vehicle layer.

Why this matters in Singapore

Singapore is a global trade and financial hub. Goods and funds transit through it, and corporate vehicles are incorporated and administered here. PF actors look for jurisdictions where the trade-and-finance ecosystem is deep and where structures can be set up quickly. CSPs are exposed because the corporate vehicles in the chain often run through CSP-incorporated companies.

Where PF surfaces in CSP work. The staff member is unlikely to see the dual-use goods themselves. What you may see is the corporate vehicle — a customer with no apparent commercial activity, instructions to move funds toward jurisdictions of proliferation concern, or links to shipping or trading entities with opaque ownership. Lesson 5 covers the specific PF red flags in detail.
SourceACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraph 5.5. United Nations Act 2001 and the regulations made under it.
Screen 1.7

Why CSPs are gatekeepers

Corporate service providers occupy a structural position in the financial system that financial criminals find useful. The CSP incorporates the company. The CSP provides the registered office. The CSP files with ACRA. The CSP holds the relationship.

That is exactly why ACRA regulates CSPs. The CSP Act 2024 was enacted to regulate persons who carry on a business of providing corporate services and to impose requirements on those persons so as to detect or prevent money laundering, the financing of the proliferation of weapons of mass destruction, and terrorism financing. The CSP is part of the front line.

The diagram below shows how a CSP-incorporated entity sits inside a typical layering structure. Click each entity to see what role it plays.

Click each entity to see what it represents in the laundering chain.The CSP-incorporated company sits at the centre — that is the structural position regulators care about.
Criminal source (predicate offence proceeds) Foreign Shell Co (opaque jurisdiction) Singapore Pte Ltd (CSP-incorporated · CSP-served) ★ Where the CSP sees the customer Apparent legitimate asset (property · business · investment)
Click any entity in the diagram to see what role it plays in the laundering chain — and where the CSP fits in.
Origin

Criminal source

The proceeds of a predicate offence — fraud, drug trafficking, corruption, or other serious crime. The CSP almost never sees the source directly. The CSP sees what comes after.

If you see funds moving through your customer's structure that look unusual or unexplained, the source you cannot see is what your suspicion attaches to.
Layering vehicle

Foreign shell company

An offshore entity in a jurisdiction with limited transparency. Used to introduce distance between the criminal source and the apparently legitimate destination. May have opaque ownership, no real activity, and a single bank account.

Foreign shell companies are not illegal — but a Singapore customer whose ownership trail leads to an opaque foreign vehicle is a CDD priority.
Where the CSP works

Singapore Pte Ltd

The Singapore-incorporated entity that the CSP has been engaged to set up and service. From a launderer's perspective, this entity adds a layer of respectability — Singapore registration, real corporate documents, a real registered office.

This is the position that creates the CSP's regulatory exposure. ACRA expects the CSP to know who the customer really is, what the structure is for, and to recognise when the structure does not make commercial sense.
Integration destination

Apparently legitimate asset

The end-point of integration. The funds re-enter the legitimate economy as property, a business acquisition, or an investment that looks ordinary. By this stage the audit trail back to the criminal source is heavily obscured.

CSPs may not see the asset purchase itself — but they may see the corporate vehicle being prepared for it (capital injection, change of activity, change of bank instructions).
Examined 0 of 4 entitiesClick any entity to begin
SourceCorporate Service Providers Act 2024, long title and Part 1. ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), Section 2 (Scope of Regulation of Corporate Service Providers).
Knowledge Check 2 of 2

Recognise the pattern

Knowledge Check

What does this customer pattern most clearly suggest?

A walk-in customer requests incorporation of a Singapore private limited company. They do not want to disclose the ultimate owner. They request a nominee director. Their stated business is "investment holding, details to follow." The capital will come from a foreign holding company in a jurisdiction with no public ownership register.
Choose the best answer.

Knowledge checks are formative — they help you consolidate. Your answer is not scored toward the terminal assessment.

Screen 1.8

The global framework — FATF

The Financial Action Task Force (FATF) is the intergovernmental body that sets the global standards for combating money laundering, terrorism financing, and proliferation financing. Singapore is a FATF member.

You do not need to memorise the FATF framework. What you do need to recognise is that the obligations the CSP — and you — operate under are not local inventions. They sit on a global standard that Singapore implements through its own laws.

Tap each tab to orient yourself to the pieces.

What FATF is

FATF is an intergovernmental body that develops and promotes global standards for combating money laundering, terrorism financing, and the financing of proliferation of weapons of mass destruction.

FATF is not a Singapore body. It is global. Its standards are adopted by member countries — including Singapore — and are then implemented through national law. The CSP Act, the CSP Regulations, the CDSA, TSOFA, and the UN Act all reflect FATF expectations.

FATF maintains lists of high-risk jurisdictions and jurisdictions under increased monitoring. These lists are referenced in CDD risk assessments — covered in Lesson 4.

The FATF 40 Recommendations

The FATF Recommendations are the internationally agreed standards. There are 40 of them, organised across distinct areas covering legal frameworks, preventive measures (CDD, beneficial ownership, record keeping), institutional measures, transparency, international co-operation, and sanctions.

You will not be tested on the 40 Recommendations themselves. Recognition matters: when you see a Singapore obligation (for example, the CSP's obligation to identify the beneficial owner of a customer), that obligation is the local implementation of a FATF Recommendation.

FATF Recommendation 24 deals with transparency of legal persons and beneficial ownership. Singapore's framework — the CSP Regulations 2025, the Companies Act 1967 register obligations — implements this.

Singapore's place in the FATF framework

Singapore is a FATF member country. As a member, Singapore is subject to mutual evaluations — peer reviews where other FATF members assess Singapore's compliance with the FATF Recommendations and the effectiveness of its AML/CFT/CPF system.

Mutual evaluations have practical consequences. They drive regulatory change. They identify areas where the Singapore framework needs strengthening — and the response to those findings is often new legislation or revised guidelines. The CSP Act 2024 itself is part of how Singapore has responded to FATF expectations on the corporate-services sector.

Singapore's 5th-round mutual evaluation was adopted by the FATF Plenary in February 2026.

What this all means for you

The framework is global, but the obligation is local. The CSP must comply with Singapore law. You as a staff member must comply with the CSP's IPPC. The IPPC is the firm's translation of all of the above — FATF, ACRA, CSP Act, CSP Regulations, CDSA, TSOFA, UN Act — into practical operating rules.

Lesson 2 covers the Singapore regulatory framework directly. Lesson 1 has set the global context.

When in doubt about whether something is "really required" — the answer is almost always yes. The Singapore obligations on a CSP are detailed and prescriptive precisely because the framework is built on a global standard.
Viewed 1 of 4 tabsClick each tab to explore
SourceFinancial Action Task Force, fatf-gafi.org (verified current 29 April 2026). ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), Glossary entries for FATF and FATF Recommendation.
Screen 1.9

Why this matters to you

Whatever your role at the CSP — Compliance Officer, corporate-secretarial executive, accounts staff, IT support, reception — you are part of the firm's AML/CFT/CPF control framework.

The framework does not work because of the Compliance Officer alone. It works because the people who actually meet customers, handle documents, see transactions, and answer the phone notice things and escalate them. ACRA's expectations on the CSP run through the firm's people, and that includes you.

What is expected of every staff member

  • Recognise. Notice when something does not look right — a customer's explanation that does not match the documents, an instruction that is unusual for that customer, a request to bypass a normal process.
  • Escalate. Tell the Compliance Officer or MLRO per the IPPC. Internal escalation is the staff member's role. The MLRO decides what happens next.
  • Document. Note what you saw, when, and who you told. Contemporaneous records protect both you and the firm.
  • Do not investigate. Investigation is not the staff member's role. Asking the customer probing questions can damage the firm's response and can risk the criminal offence of tipping-off (covered in Lesson 6).
  • Do not tell the customer. Even casual mentions can be tipping-off. Silence on the matter is the rule.
The single most important behavioural anchor of this programme. Recognise and escalate. The framework relies on every staff member doing this. The lessons that follow give you the substance of what to recognise — but the response is always the same: escalate per the IPPC.
Screen 1.10

The legal obligation to train you

This training exists because the law requires the CSP to train its staff. The obligation is not optional and not a matter of internal preference — it is a regulatory mandate.

Under the Corporate Service Providers Regulations 2025 and the ACRA Guidelines for Registered Corporate Service Providers, the registered CSP must ensure that its employees are trained on:

  • The laws for the prevention of money laundering, proliferation financing, and terrorism financing — including the CSP Regulations themselves, the Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act, the Terrorism (Suppression of Financing) Act, and other legislation specified by ACRA.
  • Prevailing methods of, and trends in, money laundering, terrorism financing, and proliferation financing.
  • The CSP's own Internal Policies, Procedures and Controls (IPPC), including the roles and responsibilities of employees, registered Qualified Individuals, and officers in relation to those policies and procedures.

ACRA's Guidelines further state that training should cover recognition of suspicious activities and transactions, the impact of ML/TF/PF on the firm, the risks the firm faces given its business profile, the changing behaviour of those who launder and finance terrorism, and the firm's CDD and ongoing monitoring measures.

On frequency, ACRA's Guidelines are direct: "the frequency of training should be sufficient to maintain the knowledge and competence of employees to apply CDD measures appropriately. For avoidance of doubt, employees should at least be trained on an annual basis."

What this programme is — and is not. This programme is foundational training that helps the CSP meet part of its obligation under regulation 37 of the CSP Regulations 2025. It is not a substitute for the CSP's own IPPC, and it is not legal or regulatory advice. The firm's IPPC tells you how this firm specifically operates these obligations.
SourceCorporate Service Providers Regulations 2025, regulation 37(1)(b). ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraph 6.72.
Screen 1.11

Lesson 1 wrap

The five things to take from this lesson.

  1. Money laundering, terrorism financing, and proliferation financing are different things. ML hides the origin of criminal funds. TF funds harmful activity, often from legitimate sources. PF funds weapons of mass destruction.
  2. Money laundering moves through three stages: placement, layering, integration. CSPs are most exposed at the layering stage, where corporate vehicles are used to obscure the audit trail.
  3. CSPs are gatekeepers. The CSP-incorporated company is a respectability layer in many laundering structures. ACRA regulates CSPs precisely because of this exposure.
  4. The framework is global, the obligation is local. FATF sets the standards. Singapore implements them through the CSP Act, the CSP Regulations, the ACRA Guidelines, the CDSA, TSOFA, and the UN Act.
  5. Recognise and escalate. Every staff member is part of the control framework. Notice things. Tell the Compliance Officer or MLRO per the IPPC. Do not investigate. Do not tell the customer.
What's next. Lesson 2 covers the Singapore regulatory framework — ACRA's role, the CSP Act 2024, the CSP Regulations 2025, who is a registered CSP, fit-and-proper requirements, the IPPC, the roles in the firm, and what happens when the obligations are breached.
Lesson 2 of 6

The CSP Regulatory Framework

CSP Act, ACRA, the IPPC, and your role.

Audience
All staff
Duration
~45 minutes
Screens
11 + 2 checks
Knowledge checks
2 (formative)

By the end of this lesson, you will be able to:

  1. Identify ACRA as the regulator of CSPs in Singapore.
  2. Recognise that the CSP Act 2024 and CSP Regulations 2025 govern the firm's AML/CFT/CPF obligations.
  3. Identify which corporate services trigger CSP registration.
  4. Explain what fit-and-proper means at the firm level and at the staff level.
  5. Recognise the IPPC as the firm's internal rulebook and identify your obligation to follow it.
  6. Distinguish the roles of Compliance Officer, MLRO, RQI, KAH, Senior Management, and ordinary staff.
  7. Recognise that breach of AML/CFT/CPF obligations exposes both the firm and individuals.
Screen 2.2

ACRA — the regulator

The Accounting and Corporate Regulatory Authority is the regulator of business registration, financial reporting, public accountants, and corporate service providers in Singapore.

For a CSP and its staff, ACRA matters in three concrete ways.

1. ACRA registers the firm

A person who carries on a business of providing corporate services must be registered with ACRA as a registered Corporate Service Provider. Registration is granted under section 8 of the CSP Act, with conditions and a registration period set by the Registrar. The CSP must renew its registration to continue operating.

2. ACRA supervises the firm

Registration is not a one-time check. ACRA supervises CSPs continuously. The Registrar can request information, can inspect the CSP's records, and can take regulatory action where the CSP is contravening or has failed to comply with the CSP Act, the CSP Regulations, or the conditions of its registration.

3. ACRA enforces the framework

ACRA's enforcement powers are detailed and graduated — censure, financial penalty, ETS restriction, suspension, cancellation. Lesson 2.9 covers the consequences of breach in detail.

What this means in practice. When you join a CSP, the firm holding the registration is the regulated entity. When ACRA inspects, ACRA inspects the firm. When ACRA enforces, ACRA enforces against the firm — and, where appropriate, against the individuals holding key positions in it.
SourceAbout ACRA — Accounting and Corporate Regulatory Authority. Corporate Service Providers Act 2024, Parts 2, 4 and 5.
Screen 2.3

The CSP Act 2024 and CSP Regulations 2025

On 9 June 2025, the regime for corporate service providers in Singapore changed. The Corporate Service Providers Act 2024 and the Corporate Service Providers Regulations 2025 came into force, replacing the old Registered Filing Agent (RFA) regime under the ACRA Act.

The change was substantial. Under the previous regime, regulation focused mainly on entities filing transactions in BizFile. The new regime is broader and more demanding. It covers a wider set of corporate services, imposes more detailed AML/CFT/CPF duties, and introduces a more prescriptive framework around CDD, the IPPC, and the responsibilities of registered Qualified Individuals.

What you need to recognise

  • The CSP Act 2024 is the primary statute governing the CSP's regulatory obligations.
  • The CSP Regulations 2025 are the subsidiary legislation that puts detailed requirements on top of the Act — including the CDD measures, the IPPC components, and the staff training obligation.
  • The ACRA Guidelines for Registered Corporate Service Providers translate the Act and Regulations into operational guidance the CSP follows. The Guidelines are how ACRA expects the framework to be applied in practice.

You do not need to read the Act and the Regulations cover-to-cover. The CSP's IPPC operationalises them for the firm, and your training operationalises the IPPC for you. But you should recognise the names — when a CO references "regulation 37" or "Guidelines paragraph 6.72," those references come from this framework.

What this programme refers to. "The Act" means the CSP Act 2024. "The Regulations" means the CSP Regulations 2025. "The Guidelines" means the ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, version 2.0). Where this programme cites a specific provision, the citation appears at the foot of the screen.
SourceCorporate Service Providers Act 2024 (commencement 9 June 2025). Corporate Service Providers Regulations 2025 (S 292/2025, in force from 9 June 2025). ACRA Guidelines for Registered Corporate Service Providers, version 2.0 (9 May 2025).
Screen 2.4

Who is a Registered CSP?

The CSP Act regulates persons who carry on a business of providing "corporate services." That phrase has a specific meaning in the Act. Tap each tab to see the four categories at recognition level.

Acting as, or arranging for another person to act as, a director or a nominee shareholder

A person who acts, or arranges for another person to act, as a director or nominee shareholder of a corporation as a business activity, is providing a corporate service.

This is the category that brings nominee director services and nominee shareholder services into CSP regulation. It is one of the highest-risk categories and one ACRA pays particular attention to.

A firm that arranges nominee directors for client companies on a commercial basis is providing a corporate service and must be registered.

Providing a registered office, business or correspondence address

Providing a registered office for a Singapore-incorporated company, or providing a business or correspondence address as a service, is a corporate service.

A firm that lets multiple unrelated client companies use its address as their registered office is providing a corporate service.

Providing corporate secretarial services

Acting as, or arranging for another person to act as, a corporate secretary, or otherwise carrying out the functions of a corporate secretary, on a commercial basis is a corporate service.

A firm that maintains the corporate registers, prepares board resolutions, and files annual returns for client companies is providing a corporate service.

Filing transactions with ACRA on behalf of customers

Performing, on behalf of another person, transactions with the Registrar through ACRA's electronic transaction system (BizFile) — for instance, incorporation filings, change-of-particulars filings, annual filings.

Access to the electronic transaction system is restricted to registered Qualified Individuals and authorised employees. Lesson 6 covers record-keeping for ACRA transactions; the operational handling of the system itself is RQI-level content.

A firm that files incorporation transactions with ACRA on behalf of clients is providing a corporate service. This was the core of the old RFA regime; it remains regulated under the CSP Act.
Viewed 1 of 4 categoriesClick each tab to explore
What this means for your firm. If your firm carries on any one of these categories as a business, the firm must be registered with ACRA as a registered CSP. The four categories are not exhaustive variants of every possible corporate service — at the All-Staff level, you need to recognise that these activities are within scope. The firm's CO and RQI handle the detailed scoping.
SourceCorporate Service Providers Act 2024, Part 1 (definition of "corporate service"). ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), Section 2.
Knowledge Check 1 of 2

Recognise CSP-regulated activity

Knowledge Check

Which of the following firms is required to be registered with ACRA as a Corporate Service Provider?

Choose the best answer.
Screen 2.5

Fit and proper — the firm

For a firm to be registered as a CSP, every Key Appointment Holder of the firm must be a fit and proper person. This is checked at registration, at renewal, and continuously throughout the registration period.

"Fit and proper" is not a single test. It is a set of factors that the Registrar may consider. The Regulations and the Guidelines set out the factors.

The fit-and-proper factors for a Key Appointment Holder include

  • Whether the person has been convicted (in Singapore or elsewhere) of an offence involving fraud or dishonesty punishable by imprisonment of three months or more, or of any other relevant offence.
  • Whether the person is an undischarged bankrupt, in Singapore or elsewhere.
  • Whether the person's previous conduct and compliance history as a KAH, registered CSP, or registered Qualified Individual has been satisfactory.
  • Whether the person has acted in a manner that adversely reflects on their commercial integrity — including professional misconduct, breach of fiduciary duty, or serious negligence.
  • Whether it would be contrary to the national or general public interest for the person to hold the position.

The Registrar may decline or withdraw a registration on fit-and-proper grounds. The firm's continued fitness and propriety is a continuous obligation — events after registration (a conviction, a bankruptcy, regulatory breaches) can change the position.

The continuous nature of fit-and-proper is the single most important point on this screen. A firm does not become "fit and proper" once at registration and stay that way regardless of what happens. Loss of fit-and-proper status by a KAH can trigger regulatory action against the firm.
SourceCorporate Service Providers Regulations 2025, regulation 7. Corporate Service Providers Act 2024, section 9(2). ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraph 3.2.
Screen 2.6

Fit and proper — staff

The fit-and-proper concept does not stop at the KAH layer. The CSP must screen the people it hires and continues to employ — and the people it authorises to use the electronic transaction system on the firm's behalf must themselves meet a fit-and-proper standard.

The Regulations require the registered CSP to screen its employees as part of its IPPC. The CSP must also be able to demonstrate that authorised employees of the firm are fit and proper to use the electronic transaction system.

What this means for you as a staff member

  • Pre-employment screening. The CSP will carry out checks before hiring you — typically including criminal-record check, bankruptcy check, prior employment, and references. This is part of the firm's IPPC.
  • Ongoing disclosure. The firm relies on you to disclose changes during your employment. If you become bankrupt, are charged with or convicted of an offence, are subject to regulatory action by another supervisor, or otherwise have a circumstance that would change the firm's assessment of you, you must tell the firm. The IPPC sets out how.
  • Authorised employees. If you are an authorised employee using the electronic transaction system, your fit-and-proper status is supervised continuously by the registered Qualified Individual.
The IPPC is your reference point. Your firm's IPPC will set out the firm's specific staff-screening requirements, the disclosures it expects from you, and the timing for those disclosures. This screen tells you the framework. The IPPC tells you the procedure.
SourceCorporate Service Providers Regulations 2025, regulations 37 and 47. ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraph 6.71.
Screen 2.7

The IPPC — your firm's internal rulebook

The Internal Policies, Procedures and Controls (IPPC) is the document — or set of documents — in which the CSP records how it meets its AML/CFT/CPF obligations. Every registered CSP must have one. Every staff member must follow it.

The Regulations require the IPPC to cover specified components. The Guidelines elaborate on what each component contains. Tap through the four groupings below to see what is in scope.

Customer due diligence and ongoing monitoring

The IPPC covers how the firm performs CDD when it onboards a customer, how it identifies and verifies the customer and beneficial owners, when simplified or enhanced CDD applies, and how the firm monitors the relationship over time.

Lesson 3 covers the substance of CDD. Your IPPC translates Lesson 3 into "this is how we, specifically, do CDD."

Suspicious transaction reporting and record-keeping

The IPPC sets out how the firm escalates suspicion internally, how the MLRO files Suspicious Transaction Reports with STRO, what records the firm must keep, and for how long.

Lesson 6 covers STR procedure, tipping-off, and the five-year record-keeping period in detail. The IPPC tells you who in your firm receives the internal escalation.

Risk assessment and audit

The IPPC covers how the firm assesses its overall ML/PF/TF risk exposure (the firm-level enterprise-wide risk assessment), how it assesses customer risk, and how the firm's compliance with the IPPC is independently audited.

Risk assessment at customer level is covered in Lesson 4. Risk assessment at firm level and audit are CO/RQI/Senior Management responsibilities — covered separately.

Employee screening, training, and internal communication

The IPPC sets out how the firm screens new employees, what training employees receive (including this programme), and the internal communication channels for AML/CFT/CPF matters — including who reports to whom.

This programme is part of how the firm meets the training component. The IPPC will record that fact and set out the firm's overall training plan.
Viewed 1 of 4 groupingsClick each tab to explore
The IPPC is referenced in every lesson of this programme. Wherever you see "follow the IPPC" or "the IPPC tells you how" — that is a reference to your firm's specific document. If you have not been given access to the IPPC or shown how to find it, ask the CO.
SourceCorporate Service Providers Regulations 2025, regulation 33. ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), Section 6 and Annex D (Sample IPPC structure).
Screen 2.8

Roles in the firm

The CSP's controls are operated by people in defined roles. Click each role in the diagram below to see what the role does and how you interact with it.

Click each role to see its function and your interaction with it.The exact titles your firm uses may differ — these are the generic governance labels used in the Regulations and Guidelines.
Senior Management (KAH · ultimate accountability) CO / MLRO (may be same person) RQI (supervises ETS use) Authorised employees (use ETS under RQI) All staff (recognise & escalate) YOU (part of all-staff control framework)
Click any role in the diagram to see its function in the firm and how you interact with it.
Top of the structure

Senior Management

Key Appointment Holders

The directors, partners, or owners of the firm. They are Key Appointment Holders for fit-and-proper purposes, and they hold ultimate accountability for the firm's compliance with the CSP Act and Regulations.

Senior Management approves the IPPC, approves high-risk customer onboardings, and is responsible to the Registrar for the firm's overall conduct.
Compliance leadership

Compliance Officer / MLRO

Day-to-day AML/CFT/CPF

The Compliance Officer manages the firm's day-to-day AML/CFT/CPF programme. The Money Laundering Reporting Officer receives internal escalations of suspicion and decides whether to file Suspicious Transaction Reports. In smaller CSPs the same person holds both roles.

When this programme says "escalate to your CO/MLRO," this is the role. Your IPPC will name the specific person.
Qualified Individual

Registered Qualified Individual (RQI)

ETS supervisor

An individual registered with ACRA who is competent to perform corporate services and to use the electronic transaction system on behalf of the firm. The RQI supervises the firm's use of the ETS and is responsible for the integrity of ACRA filings.

If you are an authorised employee using BizFile under the RQI's supervision, the RQI is your reporting line for ETS-related matters.
Authorised use of ETS

Authorised employees

RQI-supervised

Employees specifically authorised by the firm and the RQI to use ACRA's electronic transaction system. Authorised employees must themselves be fit and proper. They operate under the RQI's supervision and are subject to the firm's IPPC for ETS use.

Whether you are an authorised employee depends on your role. The CO will tell you. If you are not authorised, you must not use ETS or share another person's credentials.
Where you fit

All staff

Recognise & escalate

Every employee of the firm — whether or not client-facing, whether or not authorised to use the ETS — is part of the AML/CFT/CPF control framework. The role of all-staff is to recognise things that do not look right and to escalate them to the CO or MLRO per the IPPC.

This is the role this programme is designed to equip you for. Your job is recognition and escalation. The CO/MLRO does the assessment and decides what happens next.
You

You — the staff member

Part of all-staff

You are inside the all-staff layer. Your specific role at the firm — accounts, secretarial, IT, reception, junior corp-sec, paralegal, KYC analyst, onboarding officer — varies. The all-staff AML/CFT/CPF role applies to you regardless of which seat you occupy.

If you are unsure who your CO is, who your MLRO is, or where the IPPC is kept — find out. That is part of being equipped for the role.
Examined 0 of 6 rolesClick any role to begin
SourceCorporate Service Providers Regulations 2025, regulation 36 (Compliance Officer); Part 4 generally (RQI, authorised employees, KAH). ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), Section 6.
Knowledge Check 2 of 2

Correct internal escalation

Knowledge Check

A staff member sees something concerning during an onboarding meeting. What is the correct first step?

A junior corporate-secretarial executive is taking a customer through onboarding. The customer's stated source of funds does not appear consistent with the documents the customer has just provided. The customer is still in the room.
Choose the best answer.
Screen 2.9

Consequences of breach — the firm

When a CSP contravenes or fails to comply with the CSP Act, the CSP Regulations, or the conditions of its registration — and that contravention is not a criminal offence — the Registrar has a graduated set of regulatory tools. Tap each card to see what they are.

The financial penalty figure to remember. Up to S$25,000 per contravention or non-compliance, under section 19 of the CSP Act. Per breach, not per regulatory action — multiple breaches accumulate.

Before the Registrar takes any of these regulatory actions, the CSP must be given written notice of the proposed action and at least 14 days to make written representations. The CSP also has a right of appeal to the Minister, within 30 days of the regulatory decision. These are due-process protections — they do not stop the action, they regulate how it is taken.

Where the criminal offences sit

The S$25,000 financial penalty is for contraventions that are not criminal offences under the CSP Act. Where a contravention is a criminal offence under the Act, the criminal penalties for that offence apply instead — these can include imprisonment. Separately, criminal liability for money laundering itself sits under the CDSA (covered in Lesson 6) and for terrorism financing under TSOFA. A serious AML breach can therefore involve regulatory action under the CSP Act and separate criminal proceedings under another statute.

SourceCorporate Service Providers Act 2024, sections 18, 19, 20, 21, 22, and 23. ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraphs on regulatory action.
Screen 2.10

Consequences of breach — individuals

The CSP Act regime does not stop at the firm. Key Appointment Holders, Registered Qualified Individuals, and ordinary staff each have individual exposure under the framework — though the type of exposure differs.

Key Appointment Holders

A KAH must be fit and proper continuously. Loss of fit-and-proper status — through a criminal conviction, bankruptcy, prior regulatory action, or conduct adverse to commercial integrity — can result in the firm losing its registration, or in regulatory action targeting the KAH directly.

Registered Qualified Individuals

An RQI is individually registered with ACRA. The Registrar can take regulatory action against an RQI directly under section 21 of the Act, including cancellation of the RQI's registration, suspension up to 12 months, ETS restriction, financial penalty, and censure. The RQI's individual fit-and-proper status is checked at registration and continuously.

Authorised employees

Authorised employees who use the electronic transaction system must themselves meet a fit-and-proper standard, supervised by the RQI. Loss of fit-and-proper status terminates their authorisation.

All staff — and you

For ordinary staff, the regulatory exposure under the CSP Act is indirect — through the firm and through your fit-and-proper status as an employee. But criminal exposure is direct: criminal offences under the CDSA (money laundering offences, tipping-off), under TSOFA (terrorism financing offences), and under the UN Act (sanctions offences) apply to individuals regardless of role. These are covered in Lesson 6.

The most important point on this screen. The CSP Act framework places real exposure on individuals at every level — KAHs, RQIs, authorised employees, and through criminal law on every staff member. Fit-and-proper is continuous. Regulatory and criminal liability run on parallel tracks. Following the IPPC and escalating in good faith is your protection on both.
SourceCorporate Service Providers Act 2024, sections 18, 19, 20, 21. Corporate Service Providers Regulations 2025, regulations 7, 8, 47. CDSA, TSOFA, and UN Act 2001 (criminal liability of individuals — covered in Lesson 6).
Screen 2.11

Lesson 2 wrap

The seven things to take from this lesson.

  1. ACRA is the regulator. ACRA registers, supervises, and enforces against CSPs.
  2. The CSP Act 2024 and CSP Regulations 2025 are the framework. They came into force on 9 June 2025 and replaced the old RFA regime.
  3. Four broad categories of corporate services trigger CSP registration — director/nominee provision, registered office, corporate secretarial, and ACRA filing.
  4. Fit-and-proper is continuous. KAHs, RQIs, and staff must meet the standard at registration and throughout their role.
  5. The IPPC is your firm's rulebook. Eight components grouped across CDD/monitoring, reporting/records, risk/audit, and people/communication.
  6. Roles and escalation paths are defined. CO/MLRO, RQI, authorised employees, all staff. Recognise and escalate to the CO/MLRO per the IPPC.
  7. Consequences of breach are graduated and reach individuals. Up to S$25,000 per contravention at firm level; cancellation, suspension, ETS restriction, censure on top. Individual regulatory exposure for KAHs and RQIs. Individual criminal exposure for everyone under the CDSA, TSOFA, and UN Act.
What's next. Lesson 3 covers Customer Due Diligence — the central control of the AML/CFT/CPF framework. CDD is what the IPPC operationalises and what every staff member needs to recognise.
Lesson 3 of 6

Customer Due Diligence

What CDD is, why it exists, and how to recognise the steps.

Audience
All staff
Duration
~60 minutes
Screens
12 + 2 checks
Knowledge checks
2 (formative)

By the end of this lesson, you will be able to:

  1. Recognise the four situations that trigger CDD.
  2. Distinguish identification from verification.
  3. Recognise what beneficial ownership means under both the CSP Regulations and the Companies Act controller methodology — and how the two connect.
  4. Identify the difference between Simplified CDD and Enhanced CDD and recognise when each applies.
  5. Recognise that CDD does not stop at onboarding — ongoing monitoring continues throughout the relationship.
  6. Identify common CDD red flags that should be escalated.
Screen 3.2

What CDD is

Customer Due Diligence — CDD — is the structured set of measures the CSP performs on every customer to know who the customer is, who really owns or controls the customer, what the relationship is for, and to keep watching the relationship over time.

CDD is the central AML/CFT/CPF control. It is what the regulator inspects when it inspects a CSP. It is what makes the firm's risk-based approach possible — without knowing the customer, the firm cannot calibrate its controls to risk. And it is what gives the staff member the information they need to recognise when something does not look right.

Why CDD exists

CDD is not paperwork for the sake of paperwork. It is the firm's evidence — to itself, to its regulator, and if necessary to the authorities — that it knew its customer and acted reasonably on what it knew. Where a customer turns out to be involved in ML, TF, or PF, the firm's CDD is what shows whether the firm met its obligations or did not.

Where CDD sits in the framework. The CSP Act requires the CSP to perform CDD measures (section 17). The CSP Regulations set out what the measures are (Part 4). The ACRA Guidelines explain how the measures are applied. The IPPC operationalises all of it for the firm. This lesson covers the foundations of CDD at recognition level.
SourceCorporate Service Providers Act 2024, section 17. Corporate Service Providers Regulations 2025, Part 4. ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), Section 6.
Screen 3.3

The four CDD triggers

CDD applies in four specific situations. Tap each tab to explore — at the All-Staff level, you need to recognise that all four exist and that any one of them triggers CDD.

Starting a new business relationship

The most familiar CDD trigger. When the CSP takes on a new customer, full CDD must be completed before the relationship begins to operate. The CSP cannot rely on later CDD to fix a relationship onboarded without it.

A walk-in customer requests incorporation of a new private limited company. CDD must be performed before the incorporation is filed. The IPPC will set out the firm's onboarding workflow.

Suspicion of money laundering, terrorism financing or proliferation financing

Where the CSP has any reason to suspect that funds, assets, or transactions are linked to ML, TF, or PF — whether the customer is new or longstanding — fresh CDD is triggered. Suspicion does not require proof; reasonable grounds are enough.

An existing customer suddenly issues an instruction that does not match their established profile. The unusual instruction is itself a suspicion trigger.

Doubt about previously obtained identification or verification

If the CSP later doubts the truth or accuracy of identification or verification information collected earlier — for instance, if a document turns out to be questionable, or if new information contradicts what was provided — CDD must be re-performed.

A passport copy used at onboarding is later flagged as potentially altered. The CSP must obtain fresh verification.

Appropriate intervals based on risk

CDD does not stop at onboarding. The CSP refreshes CDD at intervals determined by risk — higher-risk customers more often, lower-risk customers less often. The IPPC sets out the firm's specific refresh cycles.

A customer rated higher-risk at onboarding is reviewed annually. A lower-risk customer may be reviewed less frequently. Risk rating itself is covered in Lesson 4.
Viewed 1 of 4 triggersClick each tab to explore
SourceCorporate Service Providers Act 2024, section 17(1). ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraph 6.1.
Screen 3.4

Identification vs verification

Identification and verification are different things. Both are required. A common error in compliance work is to treat collecting the customer's information as completing CDD — it is not.

Step 1

Identification

What the customer claims to be. The CSP collects the customer's identifying information — name, identity-document number, address, date of birth, nationality. The CSP records what the customer says they are.

Identification on its own is not enough. A name and address can be invented or stolen. Identification establishes the claim, not the truth of the claim.

Step 2

Verification

Independent evidence the claim is true. The CSP obtains evidence from a reliable, independent source that confirms the customer's identification information. Original or certified copy of the identity document. Independent confirmation of the address. Documents from a trusted register.

Verification is what turns identification into CDD. Both must be done.

Why this matters in practice. A customer who readily provides identification documents but resists verification — refuses to provide originals, declines independent address proof, will not allow document copies to be retained — is a recognisable pattern. Identification without verification is a CDD failure, and customer resistance to verification is itself a red flag worth escalating.
SourceCorporate Service Providers Regulations 2025, regulation 20. ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraph 6.7.
Knowledge Check 1 of 2

Identification vs verification

Knowledge Check

A customer has provided their NRIC number, residential address, and date of birth. Has the CSP completed CDD?

A new individual customer has just walked in. They have written their NRIC number, residential address, and date of birth on the firm's onboarding form. The corporate-secretarial executive is asked whether CDD on this customer is complete.
Choose the best answer.
Screen 3.5

Identifying an individual customer

For an individual customer — a natural person — the CSP must identify and verify the following five data points. Tap each card to see what the data point is and what counts as verification.

Procedure follows the IPPC. The five data points above are the regulatory floor. Your firm's IPPC will set out which documents the firm accepts, how copies are made and stored, who signs off on identification, and how verification is recorded. Follow the IPPC.
SourceCorporate Service Providers Regulations 2025, regulation 20(2). ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraph 6.8.
Screen 3.6

Identifying a corporate or legal-entity customer

When the customer is a company, partnership, trust, or other legal arrangement, identification has more layers. The CSP must identify the entity itself, the individuals who are authorised to act for the entity, and — crucially — the natural persons who ultimately own or control the entity (covered in detail on the next two screens).

What the CSP identifies for a corporate customer

  • The entity's name and registered name(s). Verified from the corporate registry of the place of incorporation.
  • The entity's registration number. ACRA UEN for Singapore companies; equivalent for foreign companies.
  • The entity's registered address and place of business. Verified from the corporate registry and from independent sources.
  • The entity's legal form. Pte Ltd, public company, partnership, LLP, foundation, trust, etc.
  • The entity's directors, partners, or equivalent. Identified individually as natural persons.
  • The persons authorised to act for the entity. Officers, signatories, agents — covered on screen 3.9.
  • The beneficial owners. Covered on screens 3.7 and 3.8.

The challenge with corporate customers

An individual customer is one natural person whose identity can be checked against one identification document. A corporate customer is a legal entity whose ownership and control can run through multiple layers, multiple jurisdictions, and multiple legal forms. CDD on a corporate customer is more demanding because the firm must keep tracing until it reaches the natural persons behind the structure.

The IPPC handles the procedure. The mechanics of obtaining and verifying corporate registry extracts, certified copies of constitutional documents, board resolutions authorising the relationship, and so on are operational matters. Your IPPC sets out how. The point at the All-Staff level is to recognise that corporate customers carry more layers — and that beneficial ownership is the heart of it.
SourceCorporate Service Providers Regulations 2025, regulation 20. ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), Section 6.
Screen 3.7

Beneficial ownership — two regimes that connect

Identifying the beneficial owner is the hardest and most important part of CDD. In Singapore, two distinct regimes both require identification of who really owns or controls a company. They overlap, but they are not the same. A staff member needs to recognise both.

Regime 1 — The CSP Regulations beneficial-owner test

Under the CSP Regulations 2025, a "beneficial owner" of a customer is:

Beneficial owner means an individual who:
  • (a) ultimately owns all of the assets or undertakings of the customer; or
  • (b) has ultimate control or ultimate effective control over, or has executive authority in, the customer; or
  • (c) on whose behalf the customer has employed or engaged the services of a registered CSP.

Note what is and is not in this definition. No percentage threshold. No minimum shareholding. The test is "ultimate" ownership, "ultimate" control, or "on whose behalf." The CSP must keep tracing until it reaches a natural person who answers one of (a), (b), or (c).

Regime 2 — The Companies Act controller-identification methodology

Singapore companies must maintain a Register of Registrable Controllers (RORC) under the Companies Act 1967. To identify who goes in the RORC, the company applies the controller-identification methodology in the Sixteenth Schedule of the Companies Act. The methodology uses a 25% threshold for "significant interest" plus additional tests for "significant control."

An individual or legal entity is a registrable controller if they have either significant interest or significant control:
  • Significant interest — typically more than 25% of shares, or more than 25% of voting power, or more than 25% of capital or profits in companies without share capital.
  • Significant control — including the right to appoint or remove a majority of directors, more than 25% of voting rights on member resolutions, or significant influence or control over the company.

The methodology also includes an indirect-deeming rule: where a person controls 20% or more of the voting power in a legal entity that is itself a registrable controller of the company, that person is deemed to have an interest in the underlying shares.

How they connect

The Companies Act controller methodology is the practical Singapore tool for tracing ownership through layered structures. It is what the CSP often uses to identify candidate beneficial owners. But it is not the same as the CSP Regulations CDD obligation.

  • Every registrable controller under the Companies Act methodology is a strong candidate to be a beneficial owner under the CSP Regulations.
  • But the CSP Regulations definition is broader. A person can be a beneficial owner under regulation 16 even if they do not cross the 25% controller thresholds — because the test is "ultimate" ownership or control, not a percentage.
  • This matters most with nominee arrangements, trust structures, and chains where each layer has small ownership stakes that aggregate to a single ultimate person.
The single most important point of this lesson. Identifying every controller under the RORC methodology is necessary but not always sufficient. The CSP's CDD obligation is to identify the natural person who ultimately owns or controls — and where the structure is layered, the CSP keeps tracing until it gets there. The next screen walks through this with a real example.
SourceCorporate Service Providers Regulations 2025, regulation 16 (definition of "beneficial owner"). Companies Act 1967, Sixteenth Schedule. ACRA Registers of Registrable Controllers Guidance for Companies, version 2.0 (16 June 2025), paragraphs 7.3, 7.4, 7.11. ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraphs 6.13 to 6.18.
Screen 3.8

Tracing beneficial ownership — a worked example

Click each entity in the structure below. Each click shows you what the entity is, whether it is a registrable controller under the Companies Act methodology, whether it is a beneficial owner under the CSP Regulations, or both.

Click each entity to see how it factors into beneficial-ownership identification.Watch how the two regimes overlap — and where the CSP Regulations obligation extends beyond the 25% controller test.
Customer Pte Ltd (Singapore) 30% 15%+15% 40% Mr A (direct, 30%) Nominee Co (2 × 15%) Holding Ltd (BVI · 40%) on behalf of 100% Mr B (nominator — must be disclosed) Trust X (Liechtenstein) settlor Mr C (settlor of Trust X) Beneficial owners under CSP Regs reg. 16 Mr A · Mr B · Mr C Natural person Layer / vehicle The customer
Click any entity in the diagram. Watch which entities are registrable controllers under the Companies Act, which are beneficial owners under the CSP Regulations, and where the two diverge.
The customer

Customer Pte Ltd

CDD subject

This is the entity the CSP has been engaged to incorporate or service. CDD is performed on this entity. The next step — and the harder one — is identifying who really owns and controls it.

CDD does not stop here. The CSP must trace ownership upward and identify every beneficial owner under the Regulations.
Direct 30% shareholder

Mr A — direct 30%

Controller AND beneficial owner

Mr A holds 30% of the shares directly. He crosses the 25% threshold for "significant interest" under the Companies Act methodology — so he is a registrable controller and his particulars go in the customer's RORC.

He is also a beneficial owner under CSP Regulations regulation 16(a) — he ultimately owns 30% of the customer's assets through his direct shareholding.

The two regimes agree on Mr A. This is the most common case.
Nominee Co — 2 × 15%

Nominee Co

Layer — not the BO

Nominee Co holds two share parcels of 15% each — total 30% — on behalf of an undisclosed nominator. Note: Nominee Co itself is not the beneficial owner. A nominee never is.

Under the Companies Act methodology, the nominator (the person on whose behalf Nominee Co holds) is the registrable controller — the nominee status is looked through. The CSP's CDD obligation does the same: the CSP must identify the nominator.

Concealment of the nominator is a red flag. Lawful nominee arrangements name the nominator. Click "Mr B" next to see how this resolves.
Foreign holding — 40%

Holding Ltd (BVI · 40%)

Layer — look through

Holding Ltd is a foreign company holding 40% of the customer. As a corporate entity, Holding Ltd is itself a registrable controller — its particulars go in the customer's RORC as a corporate controller. But Holding Ltd is not a natural person, so it cannot be the beneficial owner.

The CSP must trace through Holding Ltd to find the natural person who ultimately controls it — in this structure, that leads to Trust X and then to Mr C the settlor.

A corporate entity is never the answer to "who is the beneficial owner?" — it is a layer that needs to be looked through.
The undisclosed nominator

Mr B — nominator behind Nominee Co

Controller AND beneficial owner

Mr B is the natural person on whose behalf Nominee Co holds the 30% (2 × 15%). Under the Companies Act methodology, Mr B is the registrable controller — the nominee is looked through. Under CSP Regulations regulation 16(a), Mr B is a beneficial owner because he ultimately owns 30% of the customer through the nominee arrangement.

Lawful nominee arrangements identify the nominator to the CSP and to the customer's RORC. Concealment of the nominator is itself a red flag.
Trust X (Liechtenstein)

Trust X

Layer — settlor / trustee / beneficiaries

Trust X holds 100% of Holding Ltd. Trusts add complexity: the CSP must understand the settlor (who funded the trust), the trustee (who administers it), and the beneficiaries (who receive the value). Each may be relevant to beneficial ownership.

For this customer, the settlor is Mr C. The CSP would also collect details of the trustee and named beneficiaries as part of CDD on the trust.

In a Liechtenstein trust the settlor's role is often substantive. The IPPC sets out the firm's procedure for trust BO identification.
Settlor of Trust X

Mr C — settlor

Beneficial owner under reg 16

Mr C is the natural person who funded Trust X. Through Trust X, then Holding Ltd, then the 40% in Customer Pte Ltd, Mr C ultimately owns 40% of the customer's assets — well above the 25% threshold and clearly within reg 16(a).

Note: at the trust → Holding Ltd link, the chain remains intact. The Companies Act indirect-deeming rule (≥20% in a legal entity that is a registrable controller) ensures Mr C also appears as a registrable controller in the customer's RORC through the Holding Ltd → Customer chain.

Mr C is identified through layered tracing. The methodology and the BO obligation agree on him. The CSP must keep tracing until every natural person at the end of every chain is identified.
Examined 0 of 7 entitiesClick any entity to begin
SourceCorporate Service Providers Regulations 2025, regulation 16. Companies Act 1967, Sixteenth Schedule. ACRA Registers of Registrable Controllers Guidance for Companies, version 2.0 (16 June 2025).
Screen 3.9

Agents and authorised representatives

Sometimes the customer does not deal with the CSP directly. An agent, an attorney, an introducing professional, or a corporate officer may act on the customer's behalf.

When that happens, the CSP must identify and verify both the customer and the person acting for them. The customer remains the customer — CDD on the customer is unchanged. The agent is identified as a separate matter, and the CSP must also satisfy itself that the agent has authority to act.

What the CSP identifies and verifies

  • The agent's identity. The same five data points as for an individual customer — name, identity number, address, date of birth, nationality.
  • The agent's authority. Power of attorney, board resolution, appointment letter, or equivalent. The CSP must record what authority the agent has and the limits of that authority.
  • The relationship between the agent and the customer. How they are connected, why this person is acting for the customer.

A common pattern that needs care

Where the agent is also the person who appears to make all the decisions, who never lets the CSP speak with the customer directly, who is the only point of contact and resists any direct customer engagement — that combination is a recognisable red flag. It can mean the named "customer" is a front for the agent.

What to do if the agent pattern feels wrong. Recognise and escalate. The CO or MLRO assesses whether the firm's CDD has reached the real customer or only the agent's version of the customer. The staff member's job is to flag the unease, not to investigate.
SourceCorporate Service Providers Regulations 2025, regulation 20(1). ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraph 6.10.
Knowledge Check 2 of 2

Beneficial ownership in a layered structure

Knowledge Check

Who is a beneficial owner of the customer in this structure?

A new customer, Customer Pte Ltd, is owned 100% by Holding Ltd, a BVI company. Holding Ltd is owned 100% by Trust X, a Liechtenstein trust. Trust X was settled by Mr Y, a natural person. The customer's onboarding documents disclose Holding Ltd and Trust X but stop at the trustee.
Choose the best answer.
Screen 3.10

Purpose and ongoing monitoring

CDD has two further components beyond identification, verification, and beneficial ownership: understanding the purpose of the relationship, and monitoring the relationship over time.

Purpose and intended nature of the relationship

At onboarding, the CSP must understand what the customer wants the corporate structure for. "Investment holding" without further detail is insufficient. "International trade" is insufficient unless the CSP knows what is being traded, with whom, and why this structure suits that activity. The purpose informs the firm's risk assessment and informs what looks unusual later.

Ongoing monitoring

The relationship is monitored throughout its life. Trigger events for CDD refresh include:

  • Changes in ownership or control — new directors, new shareholders, change of beneficial ownership.
  • Changes in the nature of the customer's business activity.
  • Unusual transactions or instructions inconsistent with the established profile.
  • Periodic review based on risk rating — higher-risk customers more often, lower-risk customers less often.

Why monitoring matters

Onboarding CDD is a snapshot. The relationship lives over months or years. A customer who looked low-risk at onboarding may become higher-risk later — perhaps because the customer's circumstances changed, or because the CSP learns something new. Monitoring is what catches that change.

What this means for you. When you see a change in a customer's pattern — a new instruction, a new counterparty, a sudden rise in activity, a new person giving instructions — pause. The change might be entirely innocent. Or it might be the sign that the relationship has shifted and the firm's controls need to refresh. Either way, it is worth raising with the CO or MLRO.
SourceCorporate Service Providers Regulations 2025, regulation 32. ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraph 6.57.
Screen 3.11

Simplified CDD vs Enhanced CDD

Standard CDD is the default. The CSP performs the full set of CDD measures on every customer. In two specific situations, the level of CDD changes: Simplified CDD is permitted for genuinely lower-risk customers, and Enhanced CDD is required for higher-risk customers. Tap each tab.

Standard CDD — the default

Every customer gets full CDD measures unless the firm has assessed the customer as genuinely lower-risk (Simplified) or higher-risk (Enhanced). Standard CDD includes:

  • Identification of the customer.
  • Verification of identity from reliable independent sources.
  • Identification and verification of beneficial owners.
  • Understanding the purpose of the relationship.
  • Ongoing monitoring at risk-sensitive frequency.
If in any doubt about the risk level, the firm applies Standard CDD as a safe default. Lessen or intensify only on documented assessment.

Simplified CDD — limited circumstances only

Simplified CDD permits the firm to apply reduced or modified CDD measures. It is available only when:

  • The CSP has assessed the customer as low risk for ML, TF, and PF.
  • The assessment is supported by adequate analysis.
  • The customer is not from a country or territory in respect of which the FATF has called for countermeasures or enhanced due diligence.
  • There is no suspicion of ML, TF, or PF.

If any of these conditions fails, Simplified CDD cannot be used. Examples of customers that may qualify in some firms include Singapore-listed companies and Singapore financial institutions — but eligibility is firm-by-firm and must be documented in the IPPC.

Simplified CDD is a deliberate, documented decision — not a shortcut. The firm must keep the analysis on file.

Enhanced CDD — required for higher-risk customers

Enhanced CDD is required where the customer presents higher ML, TF, or PF risk. Examples — covered in detail in Lesson 4 — include:

  • Politically Exposed Persons (foreign PEPs in particular).
  • Customers from FATF-listed jurisdictions or jurisdictions identified as high-risk.
  • Complex or unusually large transactions, or unusual transaction patterns with no apparent economic or lawful purpose.
  • Customers with complex ownership structures with no commercial logic.

Enhanced CDD typically requires additional information about source of wealth and source of funds, deeper verification, senior management approval before onboarding or continuation, and more frequent ongoing monitoring.

Senior management approval for an Enhanced CDD onboarding is a control point. The CO or MLRO will be involved. The IPPC sets out the firm's process.
Viewed 1 of 3 levelsClick each tab to explore
SourceCorporate Service Providers Regulations 2025, regulation 25 (Simplified CDD), regulation 26 (Enhanced CDD). ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraphs 6.32 to 6.39.
Screen 3.12

Reliance on third parties for CDD

In limited circumstances, the CSP may rely on CDD performed by another regulated party — for example, a Singapore financial institution that has already done CDD on the same customer. Reliance is permitted under regulation 24 of the CSP Regulations, but it comes with a critical caveat.

The conditions for reliance

  • The third party must be a permitted person — typically a Singapore-regulated financial institution, an advocate or solicitor, a public accountant, or a group entity subject to equivalent AML/CFT/CPF requirements.
  • The third party must be subject to AML/CFT/CPF measures equivalent to FATF standards.
  • The third party must be able and willing to provide the CDD documents to the CSP without delay on request.
  • The CSP must satisfy itself that the third party has adequate measures in place.

The critical caveat

The CSP remains responsible for the CDD obligation regardless of reliance. Reliance on a third party does not transfer the regulatory obligation. If the third party's CDD turns out to be deficient, the CSP — not the third party — bears the regulatory consequence. The CSP cannot use reliance as a defence against a CDD failure.

This is the most important point on this screen. Reliance is permitted as a practical accommodation, not as a transfer of liability. A CSP that relies on a third party must do so deliberately, document the basis for the reliance, and keep evidence on file.

What this means at the All-Staff level. If you are told "we already have CDD on this customer through their bank" — recognise that reliance on the bank's CDD has its own conditions, and the firm still has to satisfy itself. The IPPC sets out how the firm handles reliance. Do not assume reliance simplifies the customer file.
SourceCorporate Service Providers Regulations 2025, regulation 24. ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraphs 6.28 to 6.31.
Screen 3.13

CDD red flags — recognise and escalate

The list below is a recognition checklist. These are the kinds of features that should make a staff member pause during CDD and consider whether the matter should be escalated. The drag-and-match exercise sorts each red flag into the part of the customer relationship where it typically appears.

Sort each red flag into the part of the customer relationship where it typically appears. Drag with the mouse, or click an item then click a category for keyboard / touch use. Click Check when you are done.
Items to sort
Onboarding red flags
During-relationship red flags
Transaction red flags
Sort all 7 items, then click Check.
The response is always the same. Whichever category a red flag sits in, your job at the All-Staff level does not change: recognise, document, escalate to the CO or MLRO per the IPPC. Lesson 5 covers red-flag recognition in much greater depth — Lesson 3 introduces the recognise-and-escalate discipline at the CDD level.
SourceACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), Section 6 and Annex A (Red Flag Indicators).
Screen 3.14

Lesson 3 wrap

The six things to take from this lesson.

  1. CDD is the central control. Identification, verification, beneficial ownership, purpose, and ongoing monitoring — performed and documented.
  2. Four CDD triggers. New relationship, suspicion, doubt about earlier information, periodic risk-based refresh.
  3. Identification ≠ verification. Both are required. Identification is the claim. Verification is the independent evidence the claim is true.
  4. Beneficial ownership runs through two regimes. The Companies Act methodology (25% controller test plus significant-control tests) is the practical Singapore tool for tracing ownership. The CSP Regulations definition (ultimate ownership, ultimate control, on whose behalf) is the broader CDD test. Identifying every controller is necessary; reaching every natural person at the end of every chain is sufficient.
  5. Standard CDD is the default. Simplified CDD is reserved for documented low-risk customers. Enhanced CDD is required for higher-risk customers — PEPs, FATF-listed jurisdictions, complex unexplained structures.
  6. Reliance on a third party does not transfer the obligation. The CSP remains responsible for CDD even where another regulated party has already performed it.
What's next. Lesson 4 covers Risk, PEPs, country risk, and sanctions — the risk-based approach that decides which CDD level applies, and the high-risk customer categories that drive Enhanced CDD.

Lesson 4 covers Risk, PEPs, Country Risk, and Sanctions — continue when you are ready.

Lesson 4 of 6

Risk, PEPs, Country Risk, and Sanctions

The risk-based approach and the higher-risk categories that drive Enhanced CDD.

Audience
All staff
Duration
~50 minutes
Screens
11 + 2 checks
Knowledge checks
2 (formative)

By the end of this lesson, you will be able to:

  1. Recognise that the regulator of CSPs in Singapore expects a risk-based approach — controls calibrated to the risk the customer presents.
  2. Identify the customer, country, service, and source-of-funds factors that drive customer risk.
  3. Distinguish FATF "black list" jurisdictions from FATF "grey list" jurisdictions and the CDD treatment each requires.
  4. Recognise the three categories of Politically Exposed Person — Singapore, Foreign, and International Organisation — and the family/close-associate extension.
  5. Distinguish Source of Wealth from Source of Funds and recognise when the firm must establish each.
  6. Identify the four sources of targeted financial sanctions screening: UN Act, TSOFA, MAS lists, and the MHA Inter-Ministry Committee on Terrorist Designation.
Screen 4.2

The risk-based approach

Not every customer presents the same risk. The CSP Regulations require the firm to perform CDD on a risk-sensitive basis — meaning the level of CDD applied to a particular customer must reflect the risk that customer presents.

This is the risk-based approach. It is the framework that decides whether a customer gets Standard CDD, Simplified CDD, or Enhanced CDD. It is the framework that decides how often the firm refreshes CDD on a customer. And it is the framework the regulator inspects when it examines whether the firm's controls are adequate.

Two layers of risk assessment

The risk-based approach has two layers, and you should recognise both.

  • Firm-level risk assessment. The CSP must assess its overall ML/PF/TF risk exposure — the risks it faces given its customer base, the corporate services it provides, the jurisdictions it touches, and the contextual environment. This is the firm's enterprise-wide risk assessment, and it informs the firm's controls overall.
  • Customer-level risk rating. For each individual customer, the CSP rates the risk that customer presents — typically as low, medium, or high. The customer rating drives the CDD level applied to that customer.
Why this matters at the All-Staff level. You will not perform the firm's enterprise-wide risk assessment. You may, depending on your role, contribute to customer-level risk ratings. What you must recognise is that risk-based does not mean "low effort by default." It means appropriate effort calibrated to actual risk — and where a customer turns out to be higher risk than expected, the CDD level rises with it.
SourceCorporate Service Providers Regulations 2025, regulations 18, 19. ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraphs 6.2 to 6.4.
Screen 4.3

Customer risk factors — what drives the rating

A customer's risk rating is built from several dimensions. ACRA's Guidelines and Annex B set out the factors. Tap each tab to explore the four major dimensions.

Customer profile

Who the customer is and what they look like.

  • Nationality and dual nationalities — exposure to high-risk jurisdictions.
  • Whether the customer or any beneficial owner is a Politically Exposed Person.
  • Layered or unusual ownership structures — multi-jurisdictional, deeply layered, or with no apparent commercial logic.
  • Type and scale of activities — does the activity match the customer's stated business and capacity?
  • Adverse news — public reporting, regulatory actions, prior offences.
A customer with a clean profile in a low-risk jurisdiction with simple ownership and a clear business may rate as lower-risk. A customer with PEP exposure or layered structures rates higher.

Country and jurisdiction

Where the customer is from, where they operate, and where their funds touch.

  • Customer's country of nationality, incorporation, residence, and operation.
  • Whether any of those touch a country subject to a FATF call for countermeasures or enhanced CDD ("black list") — examined on the next screen.
  • Whether any touch a country under FATF increased monitoring ("grey list").
  • Whether any touch a country sanctioned by the UN, MAS, or other regulator.
  • Whether any touch a country known to fund terrorism or to host designated terrorist organisations.
Country risk is often the single most determinative factor. A customer's risk rating frequently elevates because of a jurisdiction in their structure that they themselves may not have flagged.

Service and transaction

What the customer wants the CSP to do, and how it is being done.

  • Non-face-to-face onboarding and transactions.
  • Incorporation of companies with no apparent commercial purpose.
  • Use of nominee directors or nominee shareholders, especially in combination.
  • Complex or unusually large transactions inconsistent with the customer's business.
  • Anonymous instructions, instructions to hold funds without underlying activity, instructions to incorporate "shell" structures.
A customer requesting incorporation of a private limited company with nominee directors and no apparent business activity is asking for a higher-risk service combination — which the CSP rates accordingly.

Source of funds

Where the customer's money comes from, and whether the explanation matches what the firm sees.

  • Funds transferred without underlying services or transactions.
  • Unaccounted payments from unknown or unassociated third parties.
  • Cash payments where bank instruments would be normal.
  • Unusual remittance patterns — large amounts in, similar amounts straight out, low end-of-day balances.
  • Funds from countries that don't match the customer's stated business footprint.
A trading company whose remittance pattern shows funds in and immediately out, with no operating costs visible, is exhibiting a recognisable risk pattern even before the firm reaches Source of Wealth and Source of Funds.
Viewed 1 of 4 factorsClick each tab to explore
SourceACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraphs 6.4 and Annex B (Customer Risk Assessment Form).
Screen 4.4

Country risk — the FATF lists

Country and jurisdiction risk is often the single most consequential risk factor. ACRA's Guidelines explicitly require the CSP to keep up to date on two FATF lists and to apply different CDD treatment depending on which list a customer's jurisdiction is on.

FATF "black list"

Call for countermeasures or enhanced CDD

"Relevant country or territory" in the CSP Regulations means a country subject to a FATF call (through public statement, notice, or directive on the FATF website) for countermeasures or enhanced CDD measures. This is the FATF black list.

CDD treatment: Enhanced CDD is mandatory for any customer from or in such a country. Simplified CDD is prohibited. There is no risk-sensitive escape from this — the obligation is firm.

FATF "grey list"

Jurisdictions under increased monitoring

The FATF also publishes a list of jurisdictions under increased monitoring — countries that are working with FATF to address strategic deficiencies in their AML/CFT/CPF regimes. This is the FATF grey list.

CDD treatment: The CSP must take grey list jurisdictions into account in its risk assessment and apply Enhanced CDD where necessary. The treatment is risk-sensitive rather than automatic, but the lists must still inform the firm's approach.

Where the lists live. Both lists are maintained on the FATF website at fatf-gafi.org/en/countries/black-and-grey-lists.html. They change at every FATF Plenary, which happens three times a year. ACRA expects the CSP to keep its information current — which is why specific country names are not memorised in this training. The list is the live source.

What this means for the CSP

The firm must subscribe to FATF updates and refresh its country-risk information as the lists change. A customer onboarded when their country was unlisted may need a CDD refresh if the country is added to the black list or grey list later. This is one of the trigger events for ongoing monitoring (Lesson 3).

SourceCorporate Service Providers Regulations 2025, regulation 16 (definition of "relevant country or territory"). ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraphs 6.4(b)(ii), 6.36, 6.39(b).
Knowledge Check 1 of 2

Country risk and CDD level

Knowledge Check

A new customer is incorporated in a jurisdiction that has just been placed on the FATF "black list" (call for countermeasures). What is the correct CDD response?

A walk-in customer requests incorporation services. Their proposed beneficial owner is incorporated in Country X. Country X has just been added to the FATF black list — the FATF has called for countermeasures or enhanced CDD measures. The CO has flagged this in the day's compliance briefing.
Choose the best answer.
Screen 4.5

What is a Politically Exposed Person?

A Politically Exposed Person — PEP — is an individual entrusted with a prominent public function. PEPs are higher-risk customers because of their position, exposure to influence, and access to public funds. The CSP Regulations define three categories, plus an extension to family members and close associates.

What "prominent public function" excludes. The Guidelines are explicit that middle-ranking and junior officials are not PEPs. The role must be senior — exercising real authority, influence, or decision-making capacity — to fall within the definition.
SourceCorporate Service Providers Regulations 2025, regulation 17(1). ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraphs 6.40, 6.41, 6.42, and 6.43.
Screen 4.6

PEP risk treatment — not all PEPs are treated the same

The CSP Regulations and ACRA Guidelines treat the three PEP categories differently. The decision tree below shows the treatment for each category. Foreign PEPs always receive Enhanced CDD; Singapore and International Organisation PEPs may receive a risk-sensitive approach in defined circumstances.

Foreign PEP
Enhanced CDD is always required. Foreign PEPs — and their immediate family members and close associates — are always considered high-risk. There is no risk-sensitive option. The CSP must perform Enhanced CDD before establishing the relationship and continue enhanced ongoing monitoring throughout.
Singapore PEP
Risk-sensitive approach permitted. The CSP may take a risk-sensitive approach to whether and how Enhanced CDD applies — but only if the relationship and proposed transactions do not present a high risk of ML/PF/TF. Where high risk is present, Enhanced CDD becomes mandatory.
IO PEP
Risk-sensitive approach permitted. Same as for Singapore PEPs — risk-sensitive treatment is available, but Enhanced CDD becomes mandatory if the relationship and proposed transactions present high ML/PF/TF risk.
Stepped down
Risk-sensitive approach considering remaining influence. A PEP who has left the prominent public function may still wield significant influence. The CSP considers remaining influence and applies Enhanced CDD where appropriate. This applies across all three categories of former PEP.
Risk-sensitive does not mean "lower than Standard". The risk-sensitive approach for Singapore and IO PEPs allows the firm to assess whether Enhanced CDD applies, and to determine the extent of Enhanced CDD where it does. It does not allow the firm to drop below Standard CDD. PEPs are never lower-risk customers.
SourceACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraphs 6.45 and 6.46. Foreign-PEP rule confirmed at paragraph 6.39(f).
Screen 4.7

Source of Wealth and Source of Funds

For Enhanced CDD, the CSP must establish — by appropriate and reasonable means — both the Source of Wealth (SOW) and the Source of Funds (SOF) involved in the proposed business relationship. They are different things, and the firm must document both.

SOW

Source of Wealth

The origin of the customer's overall wealth. How did the customer come to have the money or assets they have? Inheritance, business sale, professional career, investment returns, family wealth transfer, ownership of operating businesses.

SOW is about the customer as a whole — the broader story of how they accumulated wealth, not just the funds in this particular transaction.

SOF

Source of Funds

The origin of the specific funds in this relationship. Where did the money the customer is bringing into this transaction or this corporate structure come from? Salary, business proceeds, sale of an asset, distribution from a trust, loan from a specific party.

SOF is about the specific funds at hand — the underlying economic activity that generated the funds being used in the relationship with the CSP.

Why the firm needs both

SOW and SOF together let the firm assess whether the customer's profile makes sense. A customer with substantial declared wealth (SOW) but unexplained funds in the relationship (SOF) is a recognisable concern. A customer with modest declared wealth but very large funds in a single transaction is another. The two together give the firm a check.

What this means at the All-Staff level. Establishing SOW and SOF is operational work performed by the CO, MLRO, or an appointed compliance team — not by the All-Staff member. What you need to recognise is that for Enhanced CDD, both must be established and documented; that "we know roughly where the funds came from" is not enough; and that a customer's resistance to providing SOW or SOF evidence is itself a CDD red flag worth escalating.
SourceCorporate Service Providers Regulations 2025, regulation 26(3)(c). ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraph 6.44(c).
Screen 4.8

Targeted financial sanctions — the four sources

The CSP must screen every customer, agent, connected party, and beneficial owner against designation lists. ACRA's Guidelines identify four sources the CSP must subscribe to and screen against. Click each source in the diagram below to see what it is.

Click each source to see what it is and what the CSP screens against it.The four sources together make up the targeted financial sanctions screening obligation under regulation 22.
Customer screening obligation (regulation 22 of the CSP Regulations) UN Act (designated persons) TSOFA (terrorists) MAS TFS (consolidated) MHA IMC-TD (terrorist designations) Who must be screened Customer · Agent · Connected party · Beneficial owner Plus, for newly-formed entities, the proposed company's agent, connected party, and BOs Document results · keep records · re-screen on changes (regulation 22(3))
Click any source in the diagram to see what list it is, who maintains it, and what the CSP screens against it.
The obligation itself

Regulation 22 — customer screening

Source obligation

The CSP must screen the customer, the customer's agent, every connected party, and every beneficial owner against (a) lists and information from the Registrar and law enforcement, and (b) any other source of information relating to ML, PF, or TF that the Registrar may direct.

The four sources below are how the CSP discharges this obligation in practice. Failure to screen, or screening only some of the listed persons, is a regulatory contravention.

Screening is a CDD measure — it must be performed at onboarding, on changes, and on a risk-sensitive periodic basis.
Source 1

UN Act 2001 — designated persons

Mandatory screening

The United Nations Act 2001 and the regulations made under it implement UN Security Council sanctions in Singapore law. The regulations identify "designated persons" and prohibit dealings with their funds, property, and economic resources.

Designations include persons under UN sanctions regimes — North Korea, Iran (where active), Al-Qaida and ISIL, Taliban, country-specific regimes, and others. The list is updated as the UN updates it.

The CSP must determine if any customer, agent, connected party, or BO is a designated person under the UN Act.
Source 2

TSOFA First Schedule — designated terrorists

Mandatory screening

The Terrorism (Suppression of Financing) Act 2002 includes a First Schedule listing terrorists and terrorist entities. The Schedule is updated by ministerial order as new terrorist designations are made.

TSOFA prohibits providing or collecting property for terrorist acts, providing financial services for terrorist purposes, and dealing with terrorist property. Operating in any of these ways with a person on the First Schedule is a criminal offence.

The First Schedule is published on Singapore Statutes Online and updated as designations are added or removed.
Source 3

MAS targeted financial sanctions list

Mandatory subscription

The Monetary Authority of Singapore maintains a consolidated list of designated individuals and entities under the targeted financial sanctions regime. ACRA's Guidelines explicitly direct CSPs to subscribe to the MAS list and to receive alerts when it changes.

The MAS list draws together the various sanctions sources affecting financial activity in Singapore. It is the consolidated working list for screening purposes.

The MAS list is updated as new designations are made under any of its underlying sources. CSPs must keep up.
Source 4

MHA Inter-Ministry Committee on Terrorist Designation

Mandatory subscription

The Inter-Ministry Committee on Terrorist Designation, hosted by the Ministry of Home Affairs, makes Singapore-specific terrorist designations and maintains the related lists. ACRA's Guidelines direct CSPs to subscribe to the IMC-TD updates.

The IMC-TD list complements the TSOFA First Schedule. It captures the operational designations that drive Singapore's counter-financing-of-terrorism framework.

The IMC-TD list and the TSOFA First Schedule are different but related. The CSP must reference both.
Examined 0 of 5 elementsClick any element to begin
SourceCorporate Service Providers Regulations 2025, regulation 22. ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraphs 6.23 to 6.27. Terrorism (Suppression of Financing) Act 2002, First Schedule. United Nations Act 2001 and regulations made under it.
Screen 4.9

Customer screening — what, when, and who

The previous screen showed the four sources to screen against. This screen sets out the operational discipline of screening — who gets screened, when, and what the CSP does with the results.

Who must be screened

Under regulation 22, the CSP must screen each of the following against the four sources:

  • The customer.
  • Every agent of the customer.
  • Every connected party of the customer (directors, officers, partners, equivalent).
  • Every beneficial owner of the customer.
  • Where the transaction relates to forming a new corporation or other legal person — every agent, connected party, and beneficial owner of the proposed entity.

When screening happens

  • At onboarding. Before the relationship is established or the corporate service is provided.
  • On periodic basis. The frequency depends on the customer's risk rating — higher-risk customers more often.
  • On changes to the customer. New beneficial owner, new director, new authorised representative — re-screening is triggered.
  • On changes to the lists. When the MAS list, the TSOFA First Schedule, the IMC-TD list, or the UN designations are updated, the CSP must re-screen affected customers.

What the CSP must document

The CSP must document the results of every screening — including any determination made about ML/PF/TF risk in relation to the customer or any agent, connected party, or beneficial owner. Screenshots or printouts of search results are typical evidence. Without documentation, the CSP cannot demonstrate to the regulator that screening was performed.

What you may see at the All-Staff level. If you are involved in onboarding, you may run name checks through the firm's screening tool. If you see a hit — or even a partial hit — escalate immediately to the CO or MLRO. Do not dismiss a hit on your own assessment. Hit assessment is a compliance decision, not an operational one.
SourceCorporate Service Providers Regulations 2025, regulation 22. ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraphs 6.23 to 6.27.
Knowledge Check 2 of 2

Foreign PEP CDD treatment

Knowledge Check

A new corporate customer's beneficial owner is a former Foreign PEP who stepped down from a senior cabinet position eight years ago. What CDD treatment applies?

A new corporate customer is being onboarded. CDD has identified the ultimate beneficial owner as Mr A, a foreign individual who served as a senior cabinet minister in his country until eight years ago, when he resigned from public service. He has had no public role since. The CO has asked the onboarding executive what CDD level should apply.
Choose the best answer.
Screen 4.10

Scenario — recognising and responding

A short branching scenario. You will move through three decision points — at each, choose the response you think is correct. Each choice plays out and you see the consequence. Restart at any time.

Scenario: a high-net-worth onboarding You are a corporate-secretarial executive. A new high-net-worth customer is being onboarded. Your CO is in another meeting. The customer is in front of you.
Decision 1 of 3

The introduction

The customer is Mr K, a former senior official from an East European country. He resigned from his role two years ago and now runs a private investment business. He says he wants to set up a Singapore Pte Ltd as part of his investment portfolio. He is friendly, well-prepared, and has brought clean-looking documentation.
What is your first move?
Decision 2 of 3

The CO's request

The CO has reviewed the file. She tells you Mr K's onboarding will require Enhanced CDD, including establishing his Source of Wealth and Source of Funds. She has asked you to follow up with Mr K. He calls back two days later, irritated. He says, "I have done business with reputable firms across Europe. Just process the company. I will send you a balance sheet from my accountant." He does not want to provide bank statements or asset records.
What do you say?
Decision 3 of 3

The closure

The CO has decided not to onboard Mr K. She has prepared the firm's internal documentation and signed off on the decision. She tells you she will be filing a Suspicious Transaction Report with STRO. She asks you, "Have you said anything to Mr K about our concerns?"
What is the right answer?
Scenario complete

Three decisions, three principles

Recap of the principles this scenario tested. Each one will appear repeatedly across this programme.
  • Decision 1. Recognise PEP status and pause. The corporate-secretarial executive is not the person who decides what CDD level applies. The CO is.
  • Decision 2. Do not lower the standard. The IPPC sets the evidence the firm needs, not the customer.
  • Decision 3. Do not tip the customer off. Silence is the rule. Lesson 6 covers the criminal offence in full.
Scenario complete
SourceScenario synthesised from ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraphs 6.39 to 6.46 (PEPs and Enhanced CDD), paragraph 6.44 (SOW/SOF), and CDSA section 48 (tipping-off — covered in Lesson 6).
Screen 4.11

Lesson 4 wrap

The seven things to take from this lesson.

  1. The risk-based approach. CDD level is calibrated to risk. Firm-level risk assessment plus customer-level rating drive the controls applied.
  2. Customer risk has four major dimensions. Profile, country, service or transaction, source of funds.
  3. FATF black list = mandatory Enhanced CDD; FATF grey list = informs the firm's risk assessment. Both lists are live and change at every FATF Plenary.
  4. PEPs come in three categories. Singapore, Foreign, International Organisation. Plus immediate family members and close associates.
  5. Foreign PEPs always get Enhanced CDD. Singapore and IO PEPs get a risk-sensitive approach unless high risk is present. Stepped-down PEPs are assessed on remaining influence.
  6. Source of Wealth ≠ Source of Funds. Both must be established for Enhanced CDD. Customer pushback on either is a red flag.
  7. Targeted financial sanctions screening has four sources. UN Act, TSOFA First Schedule, MAS list, MHA IMC-TD list. Customer + agent + connected party + beneficial owner all get screened.
What's next. Lesson 5 covers red flags and typologies — the recognition models that pull together everything from Lessons 1 to 4 into the patterns that should make you escalate.
Lesson 5 of 6

Red Flags and Typologies

The patterns to recognise — and the response that follows recognition.

Audience
All staff
Duration
~50 minutes
Screens
11 + 2 checks
Knowledge checks
2 (formative)

By the end of this lesson, you will be able to:

  1. Identify the categories of red flags in ACRA's Annex A — incorporation, address, nominee, transaction, and typology-specific.
  2. Recognise the Singapore-specific shell-company pattern that ACRA documents.
  3. Distinguish terrorism financing red flags from money laundering red flags.
  4. Identify proliferation financing patterns relevant to corporate vehicles.
  5. Recognise sanctions evasion patterns.
  6. Apply the recognise-and-escalate principle: do not investigate, do not tell the customer, document and escalate per the IPPC.
Screen 5.2

What red flags are

A red flag is a feature of a customer, a transaction, or a structure that does not look right and that warrants further attention. ACRA's Guidelines include a substantial Annex A — "Indicators of Suspicious Transactions" — which sets out red flags by category.

Annex A is the canonical Singapore red-flag list for CSPs. It is not exhaustive — and it explicitly says so. New patterns emerge, criminals adapt, typologies evolve. The Annex is a recognition baseline, not a closed catalogue. The CSP and its staff must also recognise patterns that are not specifically listed but that share the features of patterns that are.

Recognition vs investigation

This is the central discipline of Lesson 5. The All-Staff member's role is recognition — noticing the red flag — and escalation. Investigation is not the All-Staff member's role.

  • Recognise. See the pattern. Note what you saw.
  • Document. Write it down — what you saw, when, who said what.
  • Escalate. Report internally to the CO or MLRO per the IPPC.
  • Do not investigate. Asking the customer probing questions is not your job.
  • Do not tell the customer. Silence is the rule. Tipping-off is a criminal offence — covered fully in Lesson 6.
What this lesson is — and is not. This lesson teaches you to recognise the patterns. It does not equip you to assess whether a particular pattern in a particular case is or is not suspicious. That assessment is the CO/MLRO's job. Your job stops at recognition and escalation.
SourceACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), Annex A (Indicators of Suspicious Transactions).
Screen 5.3

Red flags by category

ACRA's Annex A organises red flags by where in the customer relationship they appear. Tap each tab to see the major categories. The lists below are illustrative — Annex A contains more.

Incorporation and provision-of-address indicators

  • Use of complex, multi-layered ownership structures or bearer shares that obscure beneficial owners.
  • Extensive use of nominees with no apparent connection to the business.
  • Initial capital from high-risk jurisdictions or sources that cannot easily be verified.
  • Lack of physical presence, employees, or genuine business operations.
  • Pressure to complete incorporation unusually quickly with incomplete due diligence information.
  • Company representatives unfamiliar with the business or industry they claim to be entering.
  • Formation of numerous related companies in a short period without clear business justification.
  • Frequent changes in registered address, especially to locations unrelated to the business.
  • Frequent requests to forward mail to various addresses, particularly in high-risk jurisdictions.
  • Companies registered at the firm's address with business activities that don't match their correspondence or visitors.
These red flags surface most often during onboarding or registered-office work. The corporate-secretarial executive often sees them first.

Nominee arrangements

  • Frequent or unexplained transfers of beneficial ownership.
  • Beneficial owners whose profiles do not match the company's stated business or financial capacity.
  • Requests to handle share transfers or dividend payments in ways designed to obscure the money trail.
  • Requests for nominees to act for other nominee entities — creating layers of opacity.
  • Nominee arrangements disproportionate or unnecessary for the stated business type or size.
  • Use of bearer shares, which allow anonymous ownership.
  • Loans or capital injections from sources that cannot be clearly identified.
  • Use of power-of-attorney where the principal's identity is not clearly established.
Nominee misuse is one of the highest-priority categories for ACRA. Nominee director and nominee shareholder services are themselves regulated CSP activities — the CSP itself may be the nominee.

Transactions that don't make economic sense

  • Transactions that cannot be reconciled with the customer's usual activities.
  • Frequent changes in directors, shareholders, name, signatories, or business activities without apparent justification.
  • Frequent changes in company ownership, especially involving complex structures or offshore entities.
  • Excessive share capital increases or reductions without clear business justification.
  • Business dealings significantly larger or smaller than would be expected for the company's apparent size or industry.
  • Transactions with shell companies or entities that appear to have no real business operations.
  • Customer fails to reasonably justify the purpose of a transaction when queried.
  • Customer uses intermediaries not subject to adequate AML/CFT/CPF laws.
"Doesn't make economic sense" is the test. If the activity does not match what the customer says they do, that is the flag.

Money laundering — Singapore-specific patterns

  • Companies registered in Singapore with no apparent business and low paid-up capital.
  • Companies using the firm's or PO Box addresses as their registered/mailing addresses.
  • Multiple bank accounts opened with various banks for no apparent economic reason.
  • Authorised signatories are foreign directors and shareholders located overseas.
  • Bank accounts opened at around the same period foreign directors are in Singapore to incorporate.
  • Frequent large incoming remittances from different individuals and companies, mainly overseas.
  • After receipt, funds are usually moved out of Singapore within days, with low end-of-day balances.
  • Transaction patterns that don't align with the company's principal business.
  • Companies incorporated by foreign directors with no links or activities in Singapore.
  • Multi-jurisdictional or complex corporate structures established without clear rationale.
This is the core Singapore typology pattern — examined in detail on the next screen.

TF, PF, and sanctions evasion — combined

  • TF: Transactions to non-profits in conflict zones; small-amount transfers consistent with funding terrorist activities; dormant accounts suddenly active with conflict-zone destinations; funds linked to designated terrorist organisations.
  • PF: Transactions involving designated persons; persons or entities in countries of WMD-proliferation concern; shipping inconsistent with technical level of the destination; freight forwarders listed as final destinations; possible shell companies in trade chains.
  • Sanctions evasion: WMD-controlled items; dual-nationals lacking technical background dealing with complex equipment; cash or precious metals in industrial transactions; small intermediary trading companies inconsistent with their normal business; use of personal accounts to purchase industrial items; "ledger" arrangements between companies that obviate international financial transactions.
TF, PF, and sanctions evasion are detected primarily through screening (Lesson 4) and through pattern recognition on the corporate vehicle, not through transaction value alone.
Viewed 1 of 5 categoriesClick each tab to explore
SourceACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), Annex A.
Screen 5.4

The Singapore shell-company pattern

ACRA's Annex A documents a specific Singapore-typology pattern — a recognisable sequence of features that frequently appears together in Singapore-incorporated shell companies misused for laundering. Step through the four phases of the pattern below.

The Singapore shell-company pattern
Singapore Pte Ltd Low paid-up capital No real business Foreign directors arrive in Singapore Multiple bank accounts opened concurrently Source A (overseas) Source B (overseas) Source C (overseas) Singapore Pte Ltd Bank accounts receive remittances large in Singapore Pte Ltd Funds rapidly moved out Destination 1 (overseas) Destination 2 (overseas) Destination 3 (overseas) days Singapore Pte Ltd Low end-of-day balances No operating costs No real activity — pattern recognised —
Phase 1 of 4
The setup

A Singapore Pte Ltd is incorporated with low paid-up capital and no apparent business. Foreign directors and shareholders fly into Singapore around the time of incorporation. Multiple bank accounts at different banks are opened concurrently, often during the same Singapore trip.

Each feature alone may have a legitimate explanation. The combination — low capital, no business, foreign directors arriving for setup, multiple bank accounts — is the start of the pattern.
Why this pattern matters. ACRA documents this pattern explicitly because Singapore's openness to foreign investment, combined with its strong financial infrastructure and quick incorporation procedures, makes the pattern attractive to launderers. CSPs see these features at incorporation, at registered-office work, at bank-account-opening assistance — at exactly the touchpoints where the pattern surfaces.
SourceACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), Annex A — "Indicators of Possible Money Laundering Activity".
Knowledge Check 1 of 2

Pattern recognition

Knowledge Check

A customer's profile shows the following: low paid-up capital, foreign directors with no Singapore activity, multiple bank accounts opened in the same week, large overseas remittances received and onward-paid within days, low end-of-day balances. What is the right characterisation?

Choose the best answer.
Screen 5.5

Tipping-off — the discipline that makes recognition work

Recognition only protects the firm if the customer never finds out. If the customer knows or suspects that the firm has flagged them, the firm's response is compromised — and the staff member who told them may have committed a criminal offence.

The hard rule. Once you have recognised something, do not tell the customer. Do not hint. Do not change your manner in a way that signals concern. Do not involve other staff who do not need to know. Silence is the rule.

What you can — and cannot — do

  • You can continue ordinary professional dealings with the customer. The relationship does not pause just because you escalated.
  • You can document what you saw, when, and what you said. Contemporaneous records protect you and the firm.
  • You can — and must — report internally to the CO or MLRO per the IPPC.
  • You cannot tell the customer that you have escalated, that the firm is reviewing them, that an STR is being considered, that authorities have been informed, or that any compliance concern has been raised.
  • You cannot tell anyone outside the firm — friends, family, social contacts — about a customer matter that has been or might be reported.
  • You cannot tell anyone within the firm who does not have a legitimate need to know.

Why this is in Lesson 5

Tipping-off is a criminal offence under section 48 of the CDSA. The full treatment of the offence — what it covers, what the penalties are, how it interacts with the STR process, and how to act in the often-difficult situation where you have flagged a customer but must continue interacting with them — is in Lesson 6.

Lesson 5 introduces tipping-off as a behavioural rule because the rule is part of the recognise-and-escalate principle. Recognition without the discipline of silence is not a complete control.

If in doubt about what you can or cannot say. Say less. The default rule when you are unsure whether something would be tipping-off is silence. The CO will tell you what is permissible. Acting cautiously on this is always the right call.
SourceCorruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992, section 48 — covered in detail in Lesson 6.
Screen 5.6

Spot-the-red-flag — practice scenario

A practice exercise. Below is a fictional onboarding-pack extract for a new corporate customer. Click on the parts of the text that strike you as red flags. The exercise highlights each correct flag as you find it. Five flags are present.

Onboarding pack — Sunlight Trading Pte Ltd Click words or phrases that you recognise as red flags. Five are present in the text below.
Customer name: Sunlight Trading Pte Ltd Proposed paid-up capital: Stated business activity: Investment holding and international trading Proposed directors: Mr A (resident of Cyprus, will travel to Singapore for incorporation), Proposed shareholders: Mr A (60%), Holdco Ltd, BVI (40%) Beneficial ownership disclosure: Source of funds: Initial bank arrangements requested: Customer urgency: Incorporation must complete within 5 working days Provided contact details: One email address; no phone; correspondence to nominee's office only
Why each one is a red flag
Found 0 of 5 red flags Click suspicious phrases in the text
What this exercise is teaching. Recognition is a skill. Real onboarding packs do not announce their red flags — staff have to see them. The features highlighted in the exercise above are drawn from ACRA's Annex A. In real practice, the same recognition-then-escalation discipline applies: see it, document it, escalate to the CO or MLRO per the IPPC.
SourceScenario synthesised from ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), Annex A — "Indicators relating to incorporation", "Indicators relating to appointment of nominee shareholders", and "Indicators of Possible Money Laundering Activity".
Screen 5.7

Terrorism financing red flags

TF red flags differ from ML red flags in three important ways: TF amounts can be small, TF funds can come from legitimate sources, and TF detection often depends on screening more than on transaction analysis.

Indicators worth recognising

  • Adverse news links. Customer or counterparty featured in adverse news or sanctions lists related to terrorism or terrorism financing.
  • Designation list hits. The customer, an agent, a connected party, or a beneficial owner is on the TSOFA First Schedule, the UN Security Council ISIL/Al-Qaida list, the UN Taliban List, or the MHA IMC-TD list.
  • Conflict-zone activity. Transactions linked to entities in conflict zones where terrorism activity is present and the declared purpose does not match the parties' profile.
  • Charitable veneer. Transactions characterised as donations or contributions to humanitarian aid, particularly to NPOs or religious organisations in conflict zones.
  • Dormant-account activation. Dormant accounts with minimal activity show inflows from unknown origins followed by transfers to conflict-zone beneficiaries.
  • Profile mismatch. Customer suddenly procuring or shipping items to conflict zones inconsistent with the customer's line of business.
  • Online-account anomalies. Customer logs in to online banking from locations in conflict zones with no lawful or legitimate purpose.
  • Cash patterns. Frequent cash deposits and withdrawals; counterparties making frequent cash deposits into customer accounts.
The TF detection model. Because TF amounts can be small and TF funds can be legitimate, traditional value-threshold controls miss TF. Detection depends on screening (Lesson 4), profile matching (does this match what the customer says they do?), and recognising patterns specific to TF — particularly conflict-zone exposure and charitable-veneer arrangements.
SourceACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), Annex A — "Indicators of Possible Terrorism Financing".
Screen 5.8

Proliferation financing red flags

PF red flags concentrate around dual-use goods, opaque trade structures, and links to countries of proliferation concern. CSPs see PF most often through the corporate vehicle being used in the chain.

Where CSPs see PF. The CSP rarely sees the dual-use goods themselves. The CSP sees the corporate vehicle — a customer with no apparent commercial activity, instructions to move funds toward jurisdictions of proliferation concern, links to small trading or brokering companies whose pattern of work does not match their stated business. That is where recognition starts.
SourceACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), Annex A — "Indicators of Possible Proliferation Financing".
Screen 5.9

Sanctions evasion patterns

Sanctions evasion is the activity of structuring transactions to avoid detection by the sanctions framework. ACRA's Annex A lists specific evasion patterns. The CSP rarely sees the sanctioned activity itself — but the corporate vehicles used in evasion pass through CSPs.

The patterns to recognise

  • WMD-controlled items. Transactions involving items controlled under WMD export control regimes or national control regimes.
  • Dual-national involvement with technical mismatch. A dual-national connected with a country of proliferation concern is involved in transactions for complex equipment for which they lack the technical background. The mismatch between technical capacity and the goods being handled is the indicator.
  • Cash or precious metals for industrial items. Use of cash or precious metals (e.g. gold) in transactions for industrial items where bank instruments would be normal. Suggests deliberate avoidance of the banking-channel scrutiny that sanctions screening relies on.
  • Small intermediary companies. A small trading, brokering, or intermediary company carrying out business inconsistent with its normal business — a tell that the company is being used as a pass-through.
  • Customer acting as money-remittance. A declared commercial business whose transaction patterns suggest it is acting as a money-remittance service rather than as the business it claims to be.
  • "Ledger" arrangements. Companies dealing on the basis of internal ledger arrangements that obviate the need for international financial transactions. Funds offset across jurisdictions without crossing borders.
  • Linked counterparties. Customers and counterparties sharing common addresses, IP addresses, telephone numbers, or apparent coordination of activity — suggesting the same actor controlling multiple ostensibly independent parties.
  • University involvement. Involvement of a university in a country of proliferation concern — research and procurement vectors are recognised concealment routes.
  • Falsified documentation. Evidence that shipping, customs, or payment documents have been altered or fabricated.
  • Personal-account use for industrial items. Use of personal bank accounts to purchase industrial equipment or goods — separating the transaction from the corporate-account scrutiny it would normally attract.
Sanctions evasion is criminal. Engaging in sanctions evasion, or assisting it, is a criminal offence under the United Nations Act 2001 and the regulations made under it, and carries significant penalties. The CSP that fails to detect sanctions evasion through the screening obligation faces both regulatory action under the CSP Act and criminal exposure under the underlying sanctions law.
SourceACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), Annex A — "Potential Indicators of Sanctions Evasion Activity".
Knowledge Check 2 of 2

Mixed typology recognition

Knowledge Check

A long-standing customer suddenly starts paying suppliers in a country of proliferation concern, the goods description on the trade documents does not match the customer's normal business, and the customer asks the CSP to update the registered office to a co-working space. What is the right characterisation?

Choose the best answer.
Screen 5.10

When red flags are not red flags

Annex A is explicit on a point worth understanding: not every red flag turns out to be a real concern. Many features on the list have legitimate explanations. The discipline of recognise-and-escalate works because the CO/MLRO has the time, the information, and the authority to assess each case — not because every red flag is automatically a confirmed problem.

Common false positives

  • The legitimate offshore holding. A BVI or Cayman holding company is not, by itself, suspicious. Many legitimate businesses use these structures for tax and asset-protection reasons. The structure becomes a flag only when combined with other features — opaque ownership, no commercial logic, unexplained funds, and so on.
  • The wealthy customer with cash exposure. A genuinely wealthy customer may have substantial cash flows that look unusual at first glance. Documented Source of Wealth and Source of Funds may explain them.
  • The high-volume legitimate trader. A real trading business may have rapid in-out flows that look like a pass-through. Trading documents, invoices, and counterparty profiles may explain the pattern.
  • The non-resident director. Many legitimate Singapore companies have non-resident directors. The director becomes a flag only when combined with the other shell-company features.

The principle

Red flags are starting points, not conclusions. The staff member's job is recognition. The CO/MLRO's job is to take recognised red flags, gather context, and decide whether the case is what the pattern suggests or has a legitimate explanation. Even where the assessment concludes the case is legitimate, the firm documents the reasoning — that is the audit trail the regulator inspects.

The default rule when in doubt: escalate anyway. If you are unsure whether what you saw is or is not a red flag, escalate. False positives cost the firm a small amount of CO/MLRO time. Missed positives cost the firm regulatory exposure and — in serious cases — criminal liability. The asymmetry is clear.
SourceACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), Annex A preamble; paragraph 6.27 (documentation requirement).
Screen 5.11

Lesson 5 wrap

The seven things to take from this lesson.

  1. Annex A is the canonical Singapore red-flag list. Five major categories: incorporation/address, nominee, transaction, ML, and TF/PF/sanctions. Not exhaustive — a starting point.
  2. Recognise, document, escalate. Do not investigate. Do not tell the customer. This is the All-Staff discipline that does not change across lessons.
  3. The Singapore shell-company pattern. Low paid-up capital + foreign directors with no Singapore activity + multiple bank accounts + rapid pass-through remittances + low end-of-day balances. Documented in Annex A.
  4. TF red flags differ from ML. Small amounts, legitimate sources, conflict-zone exposure, charitable veneer. Detection depends on screening and profile-matching.
  5. PF surfaces through the corporate vehicle. Dual-use goods, opaque trade chains, designated-person involvement, trade-document inconsistencies.
  6. Sanctions evasion uses concealment patterns. Ledger arrangements, dual-national mismatch, cash for industrial items, small-intermediary use.
  7. Not every red flag is a real concern. The CO/MLRO assesses. The staff member's job is recognition; the firm's documented assessment is what the regulator inspects.
What's next. Lesson 6 covers what happens after recognition — the Suspicious Transaction Report (STR) procedure, tipping-off in detail, and record-keeping.
Lesson 6 of 6

STR, Tipping-Off, and Record-Keeping

What happens after recognition — the response, the criminal offence to avoid, and what gets kept.

Audience
All staff
Duration
~50 minutes
Screens
12 + 2 checks
Knowledge checks
2 (formative)

By the end of this lesson, you will be able to:

  1. Distinguish internal escalation (staff to CO/MLRO) from STR filing (CO/MLRO to STRO via SONAR) — the two-step model.
  2. Identify the standard STR deadline (5 business days) and the higher-risk deadline (1 business day for TFS/sanctions).
  3. Recognise the criminal offence of tipping-off under section 48 of the CDSA, and the equivalent under section 10B of TSOFA.
  4. Recognise what staff can — and cannot — say to a customer the firm has escalated.
  5. Identify the TSOFA reporting obligations under sections 8 and 10.
  6. Recognise the 5-year record-keeping period and the categories of records to be retained.
  7. Recognise the protections for good-faith STR filers under section 39(6) and section 56 of the CDSA.
Screen 6.2

The two-step model — internal escalation, then STR filing

The framework operates in two distinct steps. Conflating them is one of the most common errors. Staff members never file STRs directly. The two steps run through different people and serve different functions.

Step 1 — Internal escalation (staff → CO/MLRO). Where a staff member knows or has reasonable grounds to suspect that a customer's property is connected to ML, PF, or TF, the staff member promptly alerts the Compliance Officer or a member of senior management of the registered CSP. This is the staff member's role. It happens internally and does not involve external authorities.
Step 2 — STR filing (CO/MLRO → STRO via SONAR). The CO or MLRO assesses the internal escalation. If the assessment supports it, the CO/MLRO files a Suspicious Transaction Report with the Suspicious Transaction Reporting Office (STRO) of the Commercial Affairs Department. The filing channel is the STRO Online Notices and Reporting Platform (SONAR) at police.gov.sg/sonar.

Why the separation matters

The CO/MLRO has visibility across the firm's customer base, has seen comparable matters before, and is trained to assess whether a particular concern crosses the suspicion threshold under the CDSA. The staff member is the recognition point — closest to the customer, often the first person to see something odd. The two-step model puts each role where it adds value: recognition at the front, assessment and filing at the centre.

SourceACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraphs 6.81 and 6.82.
Screen 6.3

Internal escalation — what triggers it

The threshold for internal escalation is "knows or has reasonable grounds to suspect." This is a meaningful standard — and it is lower than "knows for certain" or "has proof of."

What "reasonable grounds to suspect" means

The staff member does not need to be certain that a customer's property is connected to ML, PF, or TF. The staff member does not need to have proof. The standard is reasonableness — would a reasonable person in the staff member's position, given what is known, suspect a connection? If the answer is yes, the duty to escalate is triggered.

This is deliberately calibrated. If escalation required certainty, criminals would simply remain ambiguous enough to avoid the trigger. The "reasonable grounds" standard means the framework can act on patterns — recognised typologies, red flag combinations, customer behaviours — without waiting for proof.

What this means for you. If you find yourself asking "should I escalate this?" — that is itself a sign the threshold has likely been met. Reasonable grounds to suspect does not require certainty. Escalating a concern that turns out to have a legitimate explanation costs the firm a small amount of CO/MLRO time. Failing to escalate a concern that turned out to be real costs the firm regulatory exposure and may carry criminal liability.

Recent change — the "rash" and "negligent" offences

The CDSA was amended in February 2024 to add new offences. Among them: continuing with a transaction in the face of red flags that should have prompted further inquiry can itself be an offence — even without proof of actual knowledge. This makes the recognise-and-escalate discipline more important than ever. Doing the work despite obvious concerns is no longer a defence.

SourceACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraph 6.82. Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992, section 39.
Screen 6.4

What a Suspicious Transaction Report is

An STR is the formal report a Singapore-regulated person (or a CSP) files with STRO when there are reasonable grounds to suspect that property is connected to a criminal conduct under the CDSA. Tap each tab to explore — at the All-Staff level, you need to recognise what an STR is and how it works, even though you do not file it yourself.

The statutory basis

An STR is filed under section 39 of the Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act (CDSA). Section 39(1) imposes a duty to disclose to STRO where a person knows or has reasonable grounds to suspect that property represents the proceeds of, or is connected to, criminal conduct.

The duty applies to the CSP through its CO or MLRO. Within the firm, the staff escalation feeds the CO/MLRO's assessment of whether the duty is triggered.

An STR is the formal record of suspicion. STRO uses STRs to build financial intelligence on ML, PF, and TF activity in Singapore. STRs do not by themselves cause arrests or prosecutions — they are inputs to STRO's investigation.

What information goes in

The STR captures the firm's identification of the customer, the nature of the suspicious activity, the supporting facts (transactions, structures, observed behaviours), and the firm's assessment. The IPPC sets out the firm's specific STR template — what fields the firm uses, what evidence is attached, who signs off internally before filing.

The STR is structured: it asks for customer details, suspicious-activity description, supporting documentation. STRO needs enough detail to act on the report, but the firm's job is to report the facts and the suspicion — not to investigate or to draw conclusions about culpability.

How it is filed — SONAR

STRs are filed electronically through the STRO Online Notices and Reporting Platform (SONAR) at police.gov.sg/sonar. SONAR is maintained by the Commercial Affairs Department of the Singapore Police Force. The same channel is used for TSOFA reports under sections 8 and 10.

SONAR is the operational filing channel. The CO or MLRO uses SONAR; the staff member does not need to. The IPPC sets out who in the firm has SONAR access, who signs off, and how filings are documented.

Protections for the filer

Filing an STR in good faith is protected. Under CDSA section 39(6), disclosures made in good faith are not treated as a breach of any restriction on disclosure imposed by law, contract, or rules of professional conduct. The staff member who escalates internally — and the CO/MLRO who files the STR — are protected from liability for the disclosure.

Under CDSA section 56, STRO is required to preserve the secrecy of information obtained, including the identity of the filer. The customer does not see the STR. The customer is not told who escalated. STRs are confidential.

These protections matter. They remove the personal-liability disincentive for escalating a concern. Staff who escalate in good faith are protected from civil liability — and STRO is required to keep their identity confidential.
Viewed 1 of 4 tabsClick each tab to explore
SourceCorruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992, sections 39 and 56. ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraph 6.83.
Knowledge Check 1 of 2

Internal escalation vs direct filing

Knowledge Check

A staff member sees a clear red flag during a customer interaction. What is their first regulatory step?

Choose the best answer.
Screen 6.5

STR timing — two deadlines

ACRA's Guidelines set two STR-filing deadlines depending on the risk type. Both run from the establishment of suspicion — not from when the suspicious feature was first observed.

Standard cases

5 business days

As soon as reasonably practicable, no longer than 5 business days from the establishment of suspicion. This is the standard timing for STRs filed under CDSA section 39 — money-laundering-connected concerns, predicate-offence concerns, and most CSP red-flag escalations.

The clock starts when the CO/MLRO's assessment establishes the suspicion — that is, when the firm crosses the "reasonable grounds to suspect" threshold. It does not start when the staff member first observed something odd.

Higher-risk cases

1 business day, if not immediately

Within 1 business day, if not immediately, for higher-risk cases including TFS/sanctions matters. The Guidelines flag this accelerated timing because designations and sanctions matters carry urgent consequences — including the risk of the firm dealing with sanctioned property.

"If not immediately" signals that even one business day is the outer limit. Sanctions hits and TFS concerns should be treated as same-day matters wherever possible.

Why the timing matters. STRO uses STRs as financial-intelligence inputs. Late STRs lose operational value. The CSP that misses a deadline faces both regulatory consequences under the CSP Act framework and the possibility — in extreme cases — of criminal liability under CDSA section 39 if the failure was a knowing one.
SourceACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraph 6.82.
Screen 6.6

The decision not to file

The CO or MLRO can decide not to file an STR despite an internal escalation. The framework recognises that not every internal escalation crosses the suspicion threshold. But the non-filing decision is itself regulated.

What the framework requires for non-filing

Under ACRA's Guidelines paragraph 6.84, where a decision is made not to file an STR, the reasons for the non-filing must be documented and made available to the Registrar when required. The non-filing decision is part of the firm's audit trail. ACRA inspects the documented reasoning during supervisory reviews.

Why this matters

Non-filing without documentation looks identical to non-filing because of regulatory failure. The firm cannot defend a non-filing decision after the fact unless the reasoning was recorded at the time. The discipline of contemporaneous documentation protects the firm against later second-guessing — by the regulator, by law enforcement, or by the firm's own internal auditors.

What this means at the All-Staff level. Your internal escalation is not "wasted" if the CO/MLRO decides not to file. The escalation creates the audit trail; the non-filing assessment is part of it. Continue to escalate per the IPPC whenever you have reasonable grounds to suspect. The CO/MLRO's job is to assess — not yours.
SourceACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraph 6.84.
Screen 6.7

Tipping-off — the criminal offence

Tipping-off is a criminal offence under section 48 of the CDSA. It carries fines of up to S$250,000 and imprisonment. It applies to anyone — staff, officers, agents, anyone in the firm — who discloses to another person information that is likely to prejudice an investigation by an authorised officer under the CDSA.

The most common scenario. "A banker calling up the customer to inform him of CAD's investigation into his bank account or to inform the customer that the bank's compliance officer has lodged an STR against him" — this is the textbook tipping-off case from Singapore commentary. Replace "banker" with "corporate-secretarial executive" or "compliance officer" and the principle is identical for CSPs.
SourceCorruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992, section 48. Terrorism (Suppression of Financing) Act 2002, section 10B.
Screen 6.8

Tipping-off in the CDD context — the hardest case

Sometimes the CDD measures themselves would tip off the customer. The verification request, the SOW investigation, the document re-request — any of these can signal to the customer that the firm is escalating concerns. The framework provides a specific carve-out.

The carve-out — Guidelines paragraph 6.85

Where the CSP forms knowledge or suspicion of ML/PF/TF, and reasonably believes that performing any of the required CDD measures will tip off the customer (or their agent, connected party, or beneficial owner), the CSP may stop performing those measures, must document the basis for the assessment, and must file an STR without delay.

What this is, and what it is not

  • It is a specific carve-out for the case where CDD itself would tip off. Three conditions must be met: knowledge or suspicion of ML/PF/TF, reasonable belief that CDD would tip off, and immediate STR filing.
  • It is not a general license to skip CDD when it is inconvenient or when the customer pushes back. Customer pushback alone does not trigger the carve-out.
  • It is not a way to onboard a customer without CDD. The carve-out applies after suspicion has formed — typically late in a relationship, not at onboarding.
What this means at the All-Staff level. If you are involved in a CDD step that you think might tip off a customer the firm has flagged, stop and consult the CO/MLRO immediately. Do not perform the measure. Do not communicate the pause to the customer. The CO/MLRO will decide whether the carve-out applies and what the firm's response is.
SourceACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraph 6.85.
Knowledge Check 2 of 2

Tipping-off scenario

Knowledge Check

A customer the firm has just escalated internally calls the corporate-secretarial executive and says, "I just need to know if everything is alright with my account." What is the safest response?

Choose the best answer.
Screen 6.9

TSOFA reporting — sections 8 and 10

The CDSA framework covers ML and predicate-offence reporting. Terrorism-financing reporting runs through the Terrorism (Suppression of Financing) Act (TSOFA) — sections 8 and 10 — using the same SONAR channel.

TSOFA s.8

Possession of terrorist property

Every person in Singapore has a duty to disclose to the police that they have possession, custody, or control of terrorist property — or information about any transaction in terrorist property. The duty is direct; failure to disclose is a criminal offence.

For staff who come across terrorist property or information about terrorist transactions in the course of their work — including bankers, accountants, CSPs — penalties post-2018 amendments are fines of up to S$250,000 and imprisonment of up to 5 years. For corporations, fines of up to S$1 million or twice the value of the property involved.

TSOFA s.10

Information that may help

An additional duty applies where a person has information that may help prevent a terrorism-financing offence or lead to the arrest, prosecution, or conviction of a person for terrorism financing. The duty extends beyond possession of terrorist property to any information that may assist.

Same SONAR channel as CDSA STRs. Same tipping-off framework — TSOFA section 10B mirrors CDSA section 48.

The cross-walk for staff. If you observe something that fits a terrorism-financing red flag from Lesson 5 — designation list match, conflict-zone exposure, charitable veneer, dormant-account activation — escalate it internally just as you would a CDSA-related concern. The CO/MLRO assesses whether to file an STR (under CDSA), a TSOFA section 8 disclosure, a TSOFA section 10 disclosure, or some combination. The internal escalation discipline is the same.
SourceTerrorism (Suppression of Financing) Act 2002, sections 8 and 10. Same SONAR filing channel as CDSA STRs (police.gov.sg/sonar). TSOFA section 10B for the parallel tipping-off offence.
Screen 6.10

Record-keeping — the 5-year rule

Records of CDD, screening, monitoring, and STR-related activity must be kept for a minimum of 5 years from the date the CSP stops providing services to the customer. The clock runs from termination of the relationship — not from individual transactions.

What the rule says

Regulation 30 of the CSP Regulations 2025 sets the minimum at 5 years from termination of the business relationship with the customer. ACRA's Guidelines paragraph 6.55 confirms this. The Guidelines also state that the records may be kept in any format — hard copy or electronic — provided the standard for reconstruction is met.

The reconstruction standard

Guidelines paragraph 6.56 sets the substantive standard: records must be kept in a manner sufficient to permit a reconstruction of individual transactions, including the amounts and types of currency involved. This is the standard the regulator inspects. Records that cannot be reconstructed do not satisfy the requirement, regardless of format.

What this means in practice. The CSP keeps the customer's CDD file (identification, verification, screening), the firm's risk assessment, every refresh, every transaction-monitoring output, every STR filed and every STR not filed, for a minimum of 5 years after the relationship ends. The 5-year clock means a customer the firm parted ways with last year still has 5 years of records ahead of them in the firm's archive.
SourceCorporate Service Providers Regulations 2025, regulation 30. ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraphs 6.55 and 6.56.
Screen 6.11

What records must be kept

ACRA's Guidelines specify the categories of records the CSP must retain. The list is set out in the IPPC sample (paragraph 5.1 of the model IPPC). Tap each card to see the four major groups.

"STRs filed AND not filed" — both go in the file. One of the most overlooked record-keeping requirements. The non-filing decision and its reasoning are part of the firm's compliance trail. The Registrar can require either to be produced.
SourceACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), sample IPPC paragraph 5.1(a)–(l).
Screen 6.12

Lesson 6 wrap

The seven things to take from this lesson.

  1. The two-step model. Internal escalation (staff to CO/MLRO), then STR filing (CO/MLRO to STRO via SONAR). Staff never file directly.
  2. The trigger is "reasonable grounds to suspect." Not certainty, not proof — reasonableness. If you find yourself asking "should I escalate?", the threshold has likely been met.
  3. STR timing. 5 business days standard, 1 business day for higher-risk TFS/sanctions cases.
  4. Tipping-off is criminal. CDSA s.48: fine up to S$250,000 / imprisonment. TSOFA s.10B: parallel offence. Silence on compliance matters is the rule.
  5. The CDD-tipping-off carve-out. Where CDD itself would tip off the customer, the CSP may stop the measure, must document, must file STR without delay. Specific carve-out, not a general license.
  6. 5-year record-keeping from termination of the relationship. Records must permit reconstruction including amounts and types of currency.
  7. Good-faith filers are protected. CDSA s.39(6) protects good-faith disclosures. CDSA s.56 protects filer identity. The framework removes the personal-liability disincentive for escalating.
What's next. The terminal assessment. 20 questions drawn randomly from a 70-question pool covering all six lessons. 80% pass mark. You can retake the assessment as many times as you need.
Terminal assessment · Introduction

Terminal assessment

You have completed the six lessons. The terminal assessment confirms your understanding of the foundational AML/CFT/CPF framework. Read this introduction carefully before beginning.

How the assessment works

The assessment draws 20 questions at random from a pool of 70 questions covering all six lessons. The 20 questions are drawn proportionally from each lesson — so every assessment attempt covers the entire programme.

Each question has three options. One is correct. After you answer all 20 questions, you will see your score and the rationale for every question.

Questions per attempt
20
Pass mark
80%
Time
~25 min
Retakes
Unlimited

What happens if you do not pass

The pass mark is 80% — that is, 16 out of 20 questions correct. If you score below 80%, you can retake the assessment as many times as you need. Each retake draws a fresh random set of 20 questions. The lessons stay completed; only the assessment resets.

What happens if you pass

The certificate becomes available immediately. It will show your name, the date, and your score. You can print or save it as a PDF.

Before you begin

  • You should have completed all six lessons.
  • Set aside roughly 25 minutes uninterrupted.
  • You cannot go back to change an answer once you have submitted it.
  • The assessment will resume your current attempt if you navigate away mid-attempt.
Note. This assessment is part of the firm's training programme. The licensing CSP is responsible for confirming that the assessment, together with any supplemental training, meets its training obligations under regulation 37 of the CSP Regulations 2025 and paragraph 6.72 of the ACRA Guidelines.
Terminal assessment

Ready to begin

When you click Begin, the system will draw 20 questions at random from the pool. The clock does not run automatically — you can take the time you need.

Begin the assessment

You will see one question at a time. Select your answer for each, then click Submit. After all 20, you will see your score.

Already passed? If you have previously passed the assessment, you can retake it for practice. A new attempt does not affect your existing certificate unless your new score is higher.
Programme certificate

Certificate

🔒

Certificate not yet available

The certificate becomes available after you complete the terminal assessment with a passing score (80% or higher). Complete the assessment to unlock the certificate.