AML Laws and Regulations for Corporate Service Providers in Singapore

Table of Contents

In a Nutshell

A corporate service provider in Singapore is the business that incorporates companies, provides registered offices, files with the authorities and, in many cases, supplies or arranges nominee directors. Because it is the gateway through which a company comes into being, it sits at a sensitive point in the anti-money laundering system, and it is supervised by the Accounting and Corporate Regulatory Authority.

The framework consists of the Corporate Service Providers Act 2024 which created a registration regime that makes it an offence to carry on corporate service work without being registered, and the Corporate Service Providers Regulations 2025 set out binding anti money laundering duties, from risk assessment and customer due diligence to fit and proper test for a nominee director. The Guidelines for Registered Corporate Service Providers, issued on 9 May 2025, explain how the Registrar expects those duties to be met.

Singapore’s national assessments treat the corporate service sector as one of the high-risk gatekeepers, because a shell company with a hidden owner is a classic laundering vehicle and a corporate service provider is often the person who could have seen the truth.

Companies are the most heavily used legal person in Singapore and carry a higher residual money laundering risk, which places real weight on the provider that forms and administers them.

This core has the criminal and sanctions statutes that bind every business, the national risk assessments, the Companies and partnership laws a provider works within, and the FATF standards on beneficial ownership.

AML Laws and Regulations for Corporate Service Providers in Singapore

Corporate service providers stand at the front door of the corporate world. They form companies, act as or arrange nominee directors, provide registered addresses and file documents with the register. This gatekeeper role is exactly why it matters to anti-money laundering. This guide sets out the laws and regulations that apply to a registered corporate service provider in Singapore, from the criminal statutes that make money laundering an offence to the detailed rulebook the Accounting and Corporate Regulatory Authority now enforces on corporate service work.

The framework is best read in layers. The criminal and sanctions laws sit at the base. Above them is the instrument a provider works with every day, the Corporate Service Providers Regulations 2025, together with the Registrar’s Guidelines. Alongside these run Singapore’s national risk assessments, the Corporate Service Providers Act that licenses the sector, the Companies and partnership laws a provider operates within, and the FATF standards behind the whole regime.

Because a provider brings legal persons into existence and can put a nominee at their head, its exposure is less about the movement of cash than the placement of criminal control inside an opaque structure, for example, a shell company whose real owner may never appear on any record. That shapes much of what follows, from how a provider looks through to the beneficial owner to how it vets anyone it arranges to serve as a nominee director.

Singapore's corporate service sector at a glance

Companies are the most widely used legal person in Singapore, numbering 428,314 as at the end of 2023 and making up about 71.5 percent of all registered legal persons; a corporate service provider is usually the party that forms and administers them (Money Laundering and Terrorism Financing Risk Assessment of Legal Persons 2024, Table 4).

Since the AML/CFT regime for corporate service providers began in May 2015, ACRA has completed more than 2,900 inspections of the sector, focused on risk assessment, identification and verification, screening and record keeping (Legal Persons Risk Assessment 2024, paragraph 5.2.28).

Risk rating: corporate service providers are treated as high-risk gatekeepers among the non-financial professions, and companies carry a higher residual money laundering risk; from January 2021 to August 2024 ACRA cancelled the registrations of 36 providers and registered qualified individuals (Legal Persons Risk Assessment 2024, paragraphs 1.6 and 5.2.29).

Core AML Laws and Regulations for Corporate Service Providers in Singapore

These statutes and sanctions regulations establish money laundering, terrorism financing and proliferation financing as offences and require every corporate service provider to detect and report them. They bind a provider directly, whatever its own sector rules say, and the Corporate Service Providers Regulations are built on top of them.

The Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992

The CDSA provides the statutory foundation for Singapore’s money laundering offences and empowers the courts to confiscate the benefits of criminal conduct. For corporate service providers, its relevance is most immediate where they know or have reasonable grounds to suspect that property is connected with criminal activity, or that a transaction may be related to illicit proceeds. In such circumstances, the provider must file a suspicious transaction report with the Suspicious Transaction Reporting Office (Section 45) and must not disclose that a report has been filed or otherwise tip off the client (Section 57). This is particularly important where a provider is assessing a proposed incorporation or corporate structure that raises unexplained or suspicious links to criminal proceeds.

The Terrorism (Suppression of Financing) Act 2002

The TSOFA makes it an offence to provide or collect property for the purposes of terrorism and prohibits dealing with property owned or controlled by terrorists. For providers, this means it must not provide its services to facilitate terrorism financing and must take appropriate action where it knows or has reasonable grounds to suspect that a customer or transaction is connected to a terrorist entity. In practice, this makes screening customers, their agents and beneficial owners against applicable designated lists an important part of the provider’s controls, but screening does not replace the need to assess and act on other indicators of terrorism financing.

The United Nations Act 2001

This Act empowers the Minister to make regulations giving United Nations Security Council sanctions the force of domestic law, and it is the foundation for Singapore’s country-specific measures. Corporate service providers work not from the Act itself but from the sanctions regulations made under it, screening every customer, connected party and beneficial owner against the designated person lists those regulations carry.

The United Nations (Sanctions, Democratic People's Republic of Korea) Regulations 2010

Made under the United Nations Act, these regulations bring the Security Council’s North Korea sanctions into domestic force and reach a corporate service provider directly. The Corporate Service Providers Regulations require providers to screen for any person designated under regulations made under the United Nations Act, so providers must not form or administer a company for a designated person and must freeze and report a match.

The United Nations (Sanctions, Iran) Regulations 2019

The Iran regulations carry the Security Council’s Iran measures into Singapore law and bind providers in the same way. Because the screening duty in the Corporate Service Providers Regulations expressly reaches designations made under the United Nations Act, providers must check their customers and their beneficial owners against these lists before they act and must escalate rather than quietly clearing any hit.

Overarching AML Laws and Regulations Applicable to Corporate Service Providers in Singapore

These instruments cut across the whole regime and give a provider the practical means to discharge its reporting duty and to recognise terrorism financing when it surfaces in an incorporation or a filing.

Getting Started with SONAR, for STR Filers (2025)

SONAR is the STRO Online Notices and Reporting platform through which corporate service providers lodge their suspicious transaction reports electronically. It guides the providers on registration, user roles and submission, as it is the channel through which the reporting duty under section 45 of the CDSA is actually met. A provider’s compliance staff use it to file without delay and to retain proof of every report.

Form Guide for the STR Form (Version 12 August 2025)

A field-by-field guide to completing the current suspicious transaction report form. It sets out what each part requires, from the reporting firm’s particulars to the grounds for suspicion and asks for a unique internal reference on each filing. For providers, it is the reference the staff turn to when reporting a suspicious client or a company that looks designed to conceal its owner.

Terrorism Financing Indicators

STRO’s red flag indicators group terrorism financing risks into due diligence anomalies, unusual fund flows, and transactions lacking an apparent economic purpose. For corporate service providers, these indicators strengthen the ability to detect terrorism financing risks at onboarding and during the provision of corporate services, including situations where a company is established without clear or legitimate business rationale. They also provide a practical basis for assessing whether observed activity warrants the submission of a suspicious transaction report involving terrorism financing.

National Risk Assessments Applicable to Corporate Service Providers in Singapore

Singapore publishes formal assessments of where its money laundering, terrorism financing and proliferation financing risks lie, and the Corporate Service Providers Regulations require providers to feed their findings into their own risk assessment. For this sector, the assessments are pointed: providers are gatekeepers to legal persons, and legal persons are where much of the country’s laundering risk is concentrated.

Money Laundering National Risk Assessment Singapore 2024

The national money laundering assessment identifies corporate service providers among the high-risk non-financial professions, precisely because they act as gatekeepers to company formation and can be misused to build shell companies. Providers should read this finding into their sector risk assessment and treat the concealment of ownership, not the movement of cash, as their central exposure.

Terrorism Financing National Risk Assessment 2024

The terrorism financing assessment concentrates on banks, remittance and cross-border channels, but its typologies still reach providers, since a company formed to look legitimate can be used to raise or move terrorist funds. Corporate service providers apply the assessment’s indicators when it screens a customer and when it questions why a company with no real activity is being incorporated.

Proliferation Financing National Risk Assessment and Counter PF Strategy 2024

This assessment names sanctions evasion, the abuse of legal persons and dual-use trade as the principal proliferation channels, and the abuse of legal persons puts corporate service providers squarely in view. A front company incorporated in Singapore can be used to disguise procurement, so a provider’s screening and its scrutiny of a company’s stated purpose carry real counter-proliferation weight.

Environmental Crimes Money Laundering National Risk Assessment (May 2024)

A study of how the proceeds of environmental crime, from illegal wildlife trade to illegal logging, are laundered. It rates banks and remittance agents as the high-risk sectors, and its relevance to providers arises where a company it forms or administers is used to channel or hold the proceeds of such activity behind a legitimate corporate face.

Money Laundering and Terrorism Financing Risk Assessment of Legal Persons (2024)

This is the assessment closest to the sector. It rates companies as carrying a higher residual money laundering risk, records how shell companies with hidden owners have been misused and describes ACRA’s supervision of corporate service providers and its enforcement against them. Providers should treat it as the definitive account of the risk it manages and of the beneficial ownership transparency it is expected to secure.

Money Laundering and Terrorism Financing Risk Assessment of Legal Arrangements (2024)

This companion assessment covers express trusts and similar arrangements, the structures a provider may encounter behind a corporate customer. It explains how a trust can obscure ultimate ownership and control, which is why the Corporate Service Providers Regulations require providers to identify the settlor, trustees, protector and beneficiaries when a legal arrangement stands behind the customer.

Virtual Assets (Digital Payment Tokens) Risk Assessment (2024)

This assessment gauges how far Singapore is exposed to activity in digital payment tokens. For providers, the link is indirect yet increasingly live: a company set up to trade in such tokens, or one whose beneficial owner made their money in them, warrants sharper scrutiny when the provider weighs risk and pins down where the funds came from.

Corporate service provider sector ML/TF risk snapshot

Money laundering: high-risk gatekeeper profile, because a shell company with a concealed owner is a classic laundering vehicle and the provider is often the party that could have seen the truth (ML NRA 2024; Legal Persons Risk Assessment 2024).

Main feature to watch: concealment of beneficial ownership and the misuse of nominee directors and shareholders to hide the real controller of a company (Legal Persons Risk Assessment 2024).

Terrorism and proliferation financing: present through the abuse of legal persons as front companies, mitigated by screening and by scrutiny of a company’s stated purpose (TF NRA 2024; PF NRA 2024).

Controls: ACRA registers and inspects providers and has cancelled registrations for serious breaches, with beneficial ownership and nominee filings now centralised (Legal Persons Risk Assessment 2024).

Sector-Specific Guidance Applicable to Corporate Service Providers in Singapore

This forms the core of CSPs AML, CFT and CPF obligations. The framework is supervised by ACRA, is set out in the Corporate Service Providers Regulations and supported by the Registrar’s Guidelines, both of which are covered below.

The Corporate Service Providers Regulations 2025

The Corporate Service Providers Regulations 2025 are the binding AML, CFT and CPF rulebook for registered corporate service providers. Made under the Corporate Service Providers Act 2024 and in force from 9 June 2025, it sets out, in Part 4, the anti-money laundering duties providers must perform, and in Part 5 the controls over nominee directors and authorised employees. Throughout, the providers are referred to as the person carrying on the corporate service business, and its customer is whoever engages it to form or administer a legal person or to provide related services.

The Regulations open with the risk assessment. The providers must identify, assess and understand the money laundering, proliferation financing and terrorism financing risk across their customers, the countries they come from or operate in, and the corporate services and transactions they undertake, then document those assessments, keep them current and produce them to the Registrar on request. On that basis, they build the customer due diligence the providers must carry out. CSPs must establish and verify the identity of each customer and each customer’s agent, and where they form a company, must identify the proposed directors, use reliable and independent sources and retain copies of what is relied upon.

The heart of the Regulations is beneficial ownership. The providers must inquire whether any beneficial owner stands behind the customer and, where one does, identify that person and take reasonable measures to verify the identity from independent sources. For a body corporate, this means tracing the natural persons who ultimately own all its assets or undertakings, then, where ownership is unclear, those with ultimate control, and finally those holding executive authority. For a trust, it means identifying the settlor, trustees, protector and beneficiaries. The providers must screen the customer, its agents, connected parties and beneficial owners against the lists issued by the Registrar and law enforcement and against designations under the United Nations Act and the Terrorism (Suppression of Financing) Act, and must document each result.

The Regulations are precise about the information providers must collect. For every customer and agent, they must record the full name and any alias, an identification or incorporation number, a residential or registered office address and contact number, a date of birth or incorporation and a nationality or place of incorporation. Where the customer is a company, it must record the identities of all the directors; where the customer is a partnership or limited liability partnership, the identities of the partners and managers; and where a company is being formed, the identities of the proposed directors. The providers may in narrow circumstances begin a corporate service before verification is complete, but only where deferral is essential to avoid interrupting normal business and the risk can be managed, and it must finish verification as soon as is reasonably practicable. Reliance on a third party never shifts responsibility, so the providers must obtain the underlying due diligence records without delay and remain answerable for them.

The Regulations then scale the work to risk. Simplified due diligence is available only where providers have assessed and documented that the risk is low, and never where the customer is from a high-risk country or where suspicion exists. Enhanced due diligence is required for complex or unusual arrangements, for customers connected to high-risk countries, for a company that has no visible business or economic purpose, and for a politically exposed person, calling for senior management approval, steps to establish the source of wealth and funds and closer monitoring. Providers may rely on a third party, such as a Singapore financial institution, an advocate and solicitor or a public accountant, for elements of due diligence, but it remains responsible for its own compliance.

The remaining duties complete the framework. The providers must conduct ongoing monitoring of every business relationship, with enhanced monitoring for high-risk cases, and must keep their records, including due diligence, for at least five years after it stops serving the customer. They must maintain written internal policies, procedures and controls, extend a group policy where it belongs to a group, run an independent audit function, appoint a compliance officer at management level, and screen and train their employees. Part 5 sets the fit and proper factors providers must weigh before they arrange a person to act as a nominee director, and the controls over the authorised employees who may transact with the Registrar on its behalf.

Guidelines for Registered Corporate Service Providers (9 May 2025)

The Guidelines for Registered Corporate Service Providers, issued by ACRA on 9 May 2025, are the primary guidance providers alongside the Regulations. They replaced the earlier AML, CFT and CPF guidelines for registered filing agents and were issued under the new Corporate Service Providers Act and Regulations. Although the guidelines are guidance rather than legislation, they explain how ACRA expects providers to understand and implement their regulatory obligations and therefore serve as the sector’s practical compliance manual.

The Guidelines begin with the structure of the regime. They explain the scope of the Corporate Service Providers Act, who must register as a provider and the requirements applicable to a registered qualified individual, including fit and proper requirements and the relevant proficiency requirements. They also identify the corporate services that bring a business within the Act, including company formation, address services, acting as or arranging for others to act in specified roles, and nominee shareholder services, while explaining the applicable exemptions.

On the risk-based approach, the Guidelines take providers through assessing risks arising from their customers, countries and services, and establishing policies and controls proportionate to those risks. They then address customer due diligence in practical terms: identifying and verifying customers and their agents, establishing beneficial ownership and control, and applying appropriate measures to companies, partnerships and trusts. They explain when simplified measures may be appropriate and when enhanced measures are required, including in high-risk relationships such as those involving politically exposed persons. They also address remote onboarding and safeguards for non-face-to-face interactions.

The Guidelines are particularly important in relation to nominee director arrangements, a key risk within the CSP sector. They explain that a person acting as a nominee director by way of business must have the appointment arranged by a registered CSP, and that the providers must be satisfied that the proposed nominee is fit and proper before arranging the appointment. The assessment also includes the nominee’s capacity to discharge the responsibilities of the directorships held. The guidelines address ongoing monitoring, suspicious transaction reporting to the STRO through SONAR, the prohibition on tipping off, and the records providers must maintain to evidence their compliance.

The Guidelines also cover the wider compliance framework surrounding the AML, CFT and CPF duties. They explain the role and requirements of registered qualified individuals and authorised employees, together with the relevant registration and notification requirements. They also address the internal policies, procedures and controls that providers must maintain and keep current, including arrangements for group-wide controls and independent testing and audit. The emphasis throughout is on ensuring that compliance measures operate in practice rather than merely existing on paper.

The Guidelines are also clear about the consequences of non-compliance. They outline offences and enforcement consequences arising from failures such as operating without registration, breaching AML, CFT and CPF obligations, failing to conduct required due diligence or failing to report suspicious activity. They reinforce the importance of training, effective internal controls, and proper record-keeping, which provide evidence of compliance when ACRA conducts supervisory reviews or enforcement action. Read together with the Regulations, the guidelines translate the statutory framework into the practical compliance obligations that govern registered corporate service providers.

How a provider establishes the beneficial owner

Seeing through a company to the natural person who really owns or controls it is the sector’s central task. The table below sets out the steps in the Regulation 21 requirements; providers should build the full test into their onboarding.

Step

How a corporate service provider establishes the beneficial owner (regulation 21)

Make the inquiry

Ask whether any beneficial owner exists behind the customer, then identify and verify each one using reliable and independent sources

Apply the ownership test

Trace the natural persons who ultimately own all the assets or undertakings of the body corporate the CSP is forming or serving

Apply the control test

Where ownership is unclear, or no natural person owns it, find the persons who exercise ultimate or ultimate effective control

Use the fallback

Where neither owner nor controller can be pinned down, record the natural persons who hold executive authority in the entity

Look through trusts

For a trust, identify the settlor, the trustees, any protector, the beneficiaries and any person with ultimate control

Relax only by exception

The inquiry may be eased for a listed company, a supervised financial institution or a Singapore government body, unless doubt or suspicion arises

The controls on arranging a nominee director

The nominee director is where corporate service providers can most easily be misused, so the Act and Regulations set an explicit fit and proper gate. The table below distils it.

Control

What a corporate service provider must check before arranging a nominee director

The statutory gate

Under section 16 of the CSP Act, a CSP must not arrange a nominee director unless satisfied the person is fit and proper; a breach draws a fine of up to SGD 100,000

Honesty

Whether the candidate carries any conviction for fraud, dishonesty or a relevant offence, whether committed in Singapore or abroad

Solvency

Whether the candidate is an undischarged bankrupt, in Singapore or in any other jurisdiction

Past conduct

Whether the compliance record of the companies the candidate has previously directed has been satisfactory

Capacity

The candidate’s competency and existing load; a person holding more than 50 nominee directorships must be assessed on the capacity to take on more

Transparency

Nominee status and the identity of the nominator are filed centrally with ACRA, so a hidden controller cannot sit behind the appointment

Allied Laws Applicable to Corporate Service Providers in Singapore

These statutes and instruments are not primarily AML rules, but each supports the regime: A few constitute and license the sector, the remaining govern the legal persons and give investigators their powers or create the offences providers screen against.

The Corporate Service Providers Act 2024

The statute that establishes the sector. It creates the registration regime, makes it an offence to provide corporate services without registration, subjects nominee director arrangements to fit and proper requirements, and appoints ACRA’s Registrar of Corporate Service Providers as the sector’s supervisor. Registration under the Act brings the firm within the scope of the regulations and the Registrar’s regulatory oversight.

The Corporate Service Providers (Exemption) Order 2025

The order that marks the edges of the registration regime, exempting defined persons or activities from the requirement to register under the Act. It matters because it tells a firm whether a given piece of corporate service work brings it within the regime, and providers rely on it to scope their own obligations correctly.

Corporate Service Providers (Exemption for Banks, etc.) Order 2025

A companion order addressing banks that carry out corporate service activity, exempting them from the CSP registration requirement because they are already supervised for AML purposes by MAS. It prevents duplicate supervision while keeping the underlying anti-money laundering duties intact for the institution concerned.

The Companies Act 1967

The principal statute governing companies, the legal persons providers most often form and administer. Its reforms on beneficial ownership registers, nominee directors and nominee shareholders, including the central filing of nominee status, are the transparency backbone a provider’s due diligence both relies on and feeds.

The Limited Liability Partnerships Act 2005

The statute constituting limited liability partnerships, another legal person providers may form or serve. It sets the registration, management and disclosure rules for LLPs, and providers apply its beneficial ownership and identification duties to the partners and managers behind such a structure.

The Prevention of Corruption Act 1960

Singapore’s principal anti-corruption law. Because corruption is a predicate offence for money laundering, the proceeds of offences under it are part of what providers watch for when it checks a customer’s source of funds, and its presumption on unexplained wealth reinforces scrutiny where a customer’s means cannot be explained.

The Criminal Procedure Code 2010

The code of criminal procedure that arms investigators with powers of production, search and seizure. Served with a production order relating to a company it formed or a customer it served, providers must comply, preserve their records and avoid tipping off, which is how an AML investigation reaches into the corporate service file.

The Strategic Goods (Control) Act 2002

It governs the transfer and brokering of strategic and dual-use goods; the proliferation financing nexus arises where a customer’s funds derive from a business involved in such trade, adding another strand to the source of funds enquiry for a high-risk customer.

The Biological Agents and Toxins Act 2005

A Singapore weapons of mass destruction statute that prohibits the hostile use, production or transfer of scheduled biological agents and toxins. For corporate service providers, it forms part of the predicate offences relevant to proliferation screening where a customer is linked to such activity.

The Chemical Weapons (Prohibition) Act 2000

Singapore’s law giving effect to the Chemical Weapons Convention. It criminalises the use, development, acquisition or transfer of chemical weapons and supports proliferation screening by corporate service providers where a customer is linked to such activity.

Miscellaneous Laws and Regulations Applicable to Corporate Service Providers in Singapore

These national strategies, committee reports and typologies set the direction of Singapore’s regime and the public-private partnership a provider operates within. They carry no binding force, but they steer how supervisors act and supply many of the typologies providers build into their checks on companies and their owners.

National Anti Money Laundering Strategy 2024

Singapore’s national AML blueprint, resting on the pillars of Prevention, Detection and Enforcement. Corporate service providers sit at the heart of the Prevention pillar, where the authorities commit to gatekeeper accountability and to the beneficial ownership transparency providers are expected to secure when they form a company.

National Strategy for Countering the Financing of Terrorism 2024

Issued alongside the terrorism financing risk assessment, the strategy advances along five lines at once, joining up how risk is identified, hardening the legal and sanctions architecture, keeping supervision robust, pressing enforcement and deepening cross-border cooperation. It signals the direction provider’s terrorism financing controls and screening should take.

National Asset Recovery Strategy 2024

Singapore’s strategy for tracing, seizing and returning the proceeds of crime, noting the sums recovered in recent years. Providers support it mainly through their reporting and their cooperation with production orders, since a company they formed can be the vehicle holding assets subject to restraint.

Singapore Law Enforcement Strategy to Combat Money Laundering (October 2024)

A joint strategy of Singapore’s money laundering investigation agencies that sets focus areas and key actions and depends on two-way information flows with the private sector. It frames the enforcement backdrop providers support through its reporting on suspicious clients and incorporations.

Inter Ministerial Committee on Anti Money Laundering Report (October 2024)

Produced in the wake of a major laundering case, this review put forward recommendations on curbing the abuse of corporate structures, sharpening the responsibilities of gatekeepers and improving the flow of information between agencies and firms. Its conclusions land squarely on corporate service providers, and much of the sector’s recent tightening, the new Act among it, can be traced back to this report.

Legal Persons: Misuse Typologies and Best Practices (2018)

A typologies paper on the ways companies and partnerships are misused, giving providers the red flags for beneficial ownership and nominee checks. It is directly on point for corporate service providers, whose day-to-day work is the formation and administration of exactly these structures.

International Standards Applicable to Corporate Service Providers in Singapore

Singapore’s regime is built to meet the FATF standards, and the Corporate Service Providers Regulations track them, in particular the standards on beneficial ownership that bear so heavily on this sector. Of everything in this guide, these sit furthest from the day-to-day of the sector, but they are the source of the domestic rules and the origin of the typologies and techniques that ACRA expects a provider to keep abreast of.

The FATF Recommendations (updated June 2026)

The 40 Recommendations form the global AML, CFT and CPF standard underpinning the obligations imposed on corporate service providers. Recommendations 24 and 25, which address the beneficial ownership and control of legal persons and legal arrangements, are particularly relevant to providers because their gatekeeping role is establishing and administering corporate structures.

Mutual Evaluation Report of Singapore (May 2026)

The FATF and the Asia/Pacific Group’s mutual evaluation assesses the effectiveness of Singapore’s AML, CFT and CPF framework, with the transparency of legal persons and beneficial ownership emerging as key areas of focus. It provides important context for ACRA’s supervisory expectations, particularly in overseeing corporate service providers and ensuring that corporate structures cannot be misused to conceal ownership, control or illicit activity.  

Methodology for Assessing Technical Compliance and Effectiveness (updated June 2026)

The tool the FATF uses to judge technical compliance with the Recommendations and how well a country’s system performs in practice. It defines the yardstick by which Singapore, and by extension its corporate service providers, are measured, and it shapes supervisory expectations of the sector.

FATF Guidance on Politically Exposed Persons (Recommendations 12 and 22, 2013)

Explains how a firm should identify politically exposed persons and apply enhanced due diligence: senior approval, establishing source of wealth and funds, and closer ongoing monitoring, which providers apply when a PEP sits behind a company it is asked to form or administer.

Guidance on Beneficial Ownership of Legal Persons (March 2023)

Guidance issued under the revised Recommendation 24 on how to obtain and verify beneficial ownership information. It is the international counterpart to providers’ central duty, shaping how it pins down the natural person who really owns or controls a company.

Best Practices on Beneficial Ownership for Legal Persons (October 2019)

A collection of country best practices for keeping beneficial ownership information adequate, accurate and up to date, backing providers’ use of registries and multiple independent sources when they identify the owner behind a corporate customer.

Concealment of Beneficial Ownership (July 2018)

The joint FATF and Egmont Group typologies report examines how criminals conceal beneficial ownership through nominees, intermediaries, complex ownership chains and layered legal structures. It is particularly relevant to providers because the services they provide can themselves be exploited to create or obscure such structures.

Risk Based Approach: Beneficial Ownership and Transparency of Legal Arrangements (March 2024)

Guidance focused on Recommendation 25 and trusts and similar arrangements, helping a provider assess and mitigate risk where a trust or similar structure stands behind a corporate customer it forms or serves.

FATF Guidance on Counter Proliferation Financing (February 2018)

Guidance on carrying out the financial provisions of Security Council resolutions against weapons of mass destruction proliferation, under which providers must screen and freeze without delay in line with Recommendation 7, watching for front companies used to disguise procurement.

Guidance on Proliferation Financing Risk Assessment and Mitigation (June 2021)

Describes how a firm should assess and reduce proliferation financing risk once the changes to Recommendations 1 and 2 brought it within the risk-assessment duty that providers now discharge as part of their enterprise risk assessment.

Money Laundering from Environmental Crime (July 2021)

A FATF examination of the routes by which money made from environmental crime is washed through the financial system. It speaks to providers chiefly where a company it has set up becomes the respectable-looking vehicle used to park or move those proceeds, which is one more indicator a provider factors into its risk view.

Guidance on Digital Identity (March 2020)

Helps providers judge whether a digital identity system is reliable and independent enough for customer due diligence under a risk-based approach, a live question as providers onboard customers remotely and rely on video verification.

Artificial Intelligence and Deepfakes: Impacts on ML/TF/PF

A forward-looking FATF scan of how artificial intelligence and deepfakes threaten preventive systems, for example, synthetic identities defeating remote checks, alongside AI’s uses in screening and monitoring that providers can turn to their advantage.

Summary of Key Instruments

The table below distils the instruments registered corporate service providers rely on most, what type each is, whom it binds, and the core obligation it places on the provider.

Instrument

Type

Binds

Core obligation for a corporate service provider

CDSA 1992

Statute

Everyone

Report suspected criminal proceeds; do not tip off

TSOFA 2002

Statute

Everyone

Do not deal in terrorist property; screen and report

UN Act sanctions regulations (DPRK, Iran)

Regulations

All persons

Screen for and freeze designated persons without delay

CSP Regulations 2025

Regulations (binding)

CSPs

Risk-based CDD, beneficial ownership tracing, records, STR

Guidelines for Registered CSPs (2025)

Guidance

CSPs

Primary guidance; how to apply the Regulations

CSP Act 2024

Statute

CSPs

Register the provider; control nominee director arrangements

FATF Recommendations

Standard

Everyone

The global standard, including beneficial ownership

Conclusion

For registered corporate service providers in Singapore, the anti-money laundering framework is demanding because the sector acts as a gatekeeper to the corporate system and is subject to dedicated supervision by ACRA.  The criminal statutes establish money laundering and terrorism financing offences and require suspicious activity to be reported; the sanctions regulations require designated persons and entities to be screened; and the Corporate Service Providers Regulations, supported by ACRA’s Guidelines, translate these obligations into a practical system of risk assessment, customer due diligence, beneficial ownership verification, enhanced measures for high-risk cases, controls over nominee directors, and suspicious transaction reporting. Because the principal risk lies in concealed ownership and control rather than simply in the movement of cash, a provider’s controls must be designed to establish who ultimately owns, controls or benefits from a company.

The instruments work together as a single regulatory framework. A provider’s risk assessment should be informed by Singapore’s national risk assessments, particularly its assessment of risks arising from legal persons; its customer due diligence and ongoing monitoring obligations arise from the Regulations and Guidelines; registration and fit and proper requirements are established under the Corporate Service Providers Act; and its beneficial ownership obligations are reinforced by the Companies Act reforms and the FATF standards. Understanding how these requirements connect and recognising ACRA as the sector’s supervisor is essential for turning the rulebook into a defensible, risk-based compliance framework.

The corporate service regime also applies to professional firms when they provide corporate services. Our companion guides cover accountants and the accountants, lawyers and law practices that provide corporate services, which are subject to the same ACRA administered requirements when carrying out regulated corporate service activities.

Frequently Asked Questions

The binding rules are the Corporate Service Providers Regulations 2025, which set out the risk assessment, customer due diligence, beneficial ownership identification, screening, enhanced measures for politically exposed persons and high-risk cases, ongoing monitoring, record-keeping, and fit and proper test for a nominee director. They are read together with ACRA’s Guidelines for Registered Corporate Service Providers, issued on 9 May 2025.

The binding rules are the Corporate Service Providers Regulations 2025, which set out the risk assessment, customer due diligence, beneficial ownership identification, screening, enhanced measures for politically exposed persons and high-risk cases, ongoing monitoring, record-keeping, and fit and proper test for a nominee director. They are read together with ACRA’s Guidelines for Registered Corporate Service Providers, issued on 9 May 2025.

Because they are gatekeepers to company formation. A shell company with a concealed owner is a classic laundering vehicle, and the provider is often the party that could have identified the real owner, or that supplied the nominee director used to hide them.

Under Regulation 21, it must inquire whether a beneficial owner exists, then identify and verify that person from reliable and independent sources. It traces the natural persons who ultimately own all the company’s assets or undertakings, then those with ultimate control, and finally those with executive authority. This look-through is the sector’s defining due diligence task and sits at the centre of a provider’s onboarding process.

Under section 16 of the CSP Act, a provider must be satisfied the person is fit and proper. It checks for convictions involving fraud or dishonesty, for bankruptcy, and the compliance record of the person’s past directorships, and it weighs their capacity, with more than fifty nominee directorships flagged for closer assessment. A breach carries a fine of up to SGD 100,000.

Whenever it has reasonable grounds to suspect money laundering or terrorism financing. The report goes to the Suspicious Transaction Reporting Office through SONAR, no later than five business days after the suspicion arises, and the provider must not tip off the customer. Our guide to STR red flags explains common triggers, such as a company formed with no visible business.

About the Author

Pathik Shah

FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)

Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.