AML Laws and Regulations for Accountants, Lawyers and Law Practices Providing CSP Services in Singapore
In a Nutshell
Many accountants, lawyers and law practices do more than audit or advise. They also incorporate companies for clients, supply registered offices, act as or arrange nominee directors and shareholders, and file with the register. When a professional firm carries out that kind of work, it is providing a corporate service, and Singapore’s corporate service provider regime applies to those activities just as it applies to a dedicated corporate services firm.
The regime is administered by the Accounting and Corporate Regulatory Authority. Its primary rulebook is the Corporate Service Providers Act 2024 and the Corporate Service Providers Regulations 2025, read with the Guidelines for Registered Corporate Service Providers issued on 9 May 2025. For an accounting entity, registration is deemed under the Act when it carries on corporate service work, so the applicable AML, CFT and CPF duties arise without a separate registration application.
This matters because a professional firm’s letterhead lends legitimacy. A company incorporated through a respected accountancy or law practice may appear legitimate, which is exactly why the misuse of these gatekeepers is a recognised laundering risk. The regime therefore imposes set of obligations on providers, including risk assessment, customer due diligence, beneficial ownership identification, screening, the fit and proper test for a nominee director, and suspicious transaction reporting.
Around this core sit the criminal and sanctions statutes that apply across businesses, the national risk assessments, the professional and corporate laws these firms already work within, and the FATF standards on beneficial ownership. Each instrument below is considered in turn, in plain words, with the exact source it is based on.
AML Laws and Regulations for Accountants, Lawyers and Law Practices Providing CSP Services in Singapore
Professionals who incorporate a company or supply a director wear two hats. They remain an accountancy or law practice but become a corporate service provider for those activities. This guide sets out the laws and regulations that apply when accountants, lawyers and law practices provide corporate services in Singapore, from the criminal statutes that make money laundering an offence to the specific rulebook the Accounting and Corporate Regulatory Authority applies to designated activities.
The framework is best read in layers. The criminal and sanctions laws sit at the base. Above them is the regulatory framework governing firms’ corporate service activities: the Corporate Service Providers Act 2024 and Corporate Service Providers Regulations 2025, read with the Registrar’s Guidelines. Alongside these sit Singapore’s national risk assessments, the professional and corporate legislation the firm remains subject to, and the FATF standards that underpin the framework.
Because such professionals and professional firms create and administer legal persons and can put a nominee at their head, their exposure is less about the movement of cash than the placement of criminal control inside a structure that borrows the firm’s good name. That shapes much of what follows, from how the firm looks through to the beneficial owner to how it vets anyone it arranges to sit as a nominee director on a client’s board.
Professional firms in the corporate service regime at a glance
An accounting entity that provides corporate services is a deemed registered corporate service provider under section 7(2) of the Corporate Service Providers Act 2024, so its AML/CFT/CPF duties attach automatically rather than by separate application (CSP Act 2024, section 7).
Companies are the most widely used legal person in Singapore, 428,314 as at the end of 2023, and a professional firm is often the party that forms and administers them (Money Laundering and Terrorism Financing Risk Assessment of Legal Persons 2024, Table 4).
Risk rating: corporate service providers are treated as high-risk gatekeepers, and a professional firm’s involvement can add a veneer of legitimacy to a company set up to conceal its true owner (ML NRA 2024; Legal Persons Risk Assessment 2024).
Core AML Laws and Regulations for Accountants, Lawyers and Law Practices Providing CSP Services in Singapore
These statutes and sanctions regulations establish offences relating to money laundering, terrorism financing and proliferation financing, and impose relevant control obligations on firms providing corporate services. They bind the firms directly, alongside the professional rules to which they are subject.
The Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992
The CDSA establishes Singapore’s money laundering offences and provides for confiscation of criminal proceeds. Sections 50 and 51 criminalise assisting another person to retain benefits from drug dealing or other criminal conduct. Section 55A (1)(b)(ii)(B) and (iii)(B) criminalises enabling a client to perform a money laundering offence after failing to ascertain the transaction’s purpose or source. Section 62 requires reports on the receipt of cash of SGD 20,000 or more from outside Singapore. Professionals and Firms must also report suspicious transactions under section 45 and must not tip off clients about it under section 57.
The Terrorism (Suppression of Financing) Act 2002
The TSOFA under section 3 criminalises the collection, provision or handling of property meant for terrorism and dealings in property terrorists own or control. Professionals and firms must decline to incorporate for, or to continue serving, anyone they know or reasonably believe to be a terrorist entity, and they must notify the suspicion to authorities. That duty is discharged by screening the client, its agents and its beneficial owners against the terrorism designations.
The United Nations Act 2001
This Act gives the Minister power to translate United Nations Security Council sanctions into binding domestic law and underpins the country-specific regimes. Professionals and firms providing corporate services rely not on the Act itself but on the regulations issued under it, testing every client, connected party and beneficial owner against the designated persons and entities list those regulations carry.
The United Nations (Sanctions, Democratic People's Republic of Korea) Regulations 2010
These regulations put the Security Council’s North Korea measures into Singapore law. Because the Corporate Service Providers Regulations require screening against persons designated under the United Nations Act, Professionals and firms must not form or administer a structure for a designated person and must freeze and report a match rather than complete the engagement.
The United Nations (Sanctions, Iran) Regulations 2019
These regulations give the Security Council’s Iran measures domestic effect and reach professionals and firms in the same way. Since the corporate service screening duty extends to designations under the United Nations Act, they shall check their clients and their beneficial owners against these lists at the outset and escalate any hit instead of clearing it.
Overarching AML Laws and Regulations Applicable to Professionals and Firms Providing Corporate Services in Singapore
These instruments run across the whole regime and give a firm the practical means to discharge its reporting duty and to spot terrorism financing when it appears in an incorporation or a filing.
Getting Started with SONAR, for STR Filers (2025)
SONAR is the STRO Online Notices and Reporting platform through which a firm submits its suspicious transaction reports online. The guide takes professionals and firms through registration, the assignment of user roles and the act of submission, and it is the route by which the CDSA reporting duty is met. Professionals and the firm’s compliance staff depend on it to file promptly and to retain evidence of each report.
Form Guide for the STR Form (Version 12 August 2025)
A step-by-step guide for submission of the current suspicious transaction report form. It shows what belongs in each section, from the filer’s own details to the basis for the suspicion and requires a distinct internal reference on every report. Professionals and firm staff keep it close when they report a questionable client or a company that appears built only to obscure ownership.
Terrorism Financing Indicators
A STRO red-flag reference that arranges terrorism financing indicators into due diligence anomalies, unusual fund movements and transactions without economic sense. It helps professionals and firms providing corporate services catch terrorism financing when a company is formed with no discernible purpose, and it supports the filing of a terrorism financing report.
National Risk Assessments Applicable to Professionals and Firms Providing Corporate Services in Singapore
Singapore publishes formal assessments of where its money laundering, terrorism financing and proliferation financing risks sit, and the Corporate Service Providers Regulations require the service providers to build their findings into their own risk assessment. For this activity, the assessments are pointed, because the misuse of legal persons is a central national concern and a professional firm is often the maker of those legal persons.
Money Laundering National Risk Assessment Singapore 2024
The national money laundering assessment places corporate service providers among the high-risk sectors, because they open the door to company formation and can be turned to building shell companies. Professionals and firms providing corporate services should carry this finding into their sector risk assessment and treat the concealment of ownership, rather than the movement of cash, as the principal exposure.
Terrorism Financing National Risk Assessment 2024
The terrorism financing assessment focuses on banks, remittance and cross-border channels, yet its typologies still touch the corporate services provider, since a company dressed up to look legitimate can raise or move terrorist funds. Professionals and firms apply the assessment’s indicators when it screens a client and when it asks why a company with no real activity is being set up.
Proliferation Financing National Risk Assessment and Counter PF Strategy 2024
This assessment identifies sanctions evasion, the abuse of legal persons and dual-use trade as the leading proliferation channels, and the abuse of legal persons puts service providers in the frame. A front company incorporated through a professional firm can disguise procurement, so screening and scrutiny of a company’s stated purpose carry countering proliferation weight.
Environmental Crimes Money Laundering National Risk Assessment (May 2024)
An assessment of the laundering routes for money made from environmental offences, from wildlife trafficking to unlawful logging. It ranks banks and remittance agents as the highest-risk sectors, and it touches on corporate service providers when a company they set up or run is used to hold or shift those proceeds behind a respectable facade.
Money Laundering and Terrorism Financing Risk Assessment of Legal Persons (2024)
This is the assessment nearest to the activity. It rates companies as carrying a higher residual money laundering risk, records how shell companies with hidden owners are misused, and describes ACRA’s supervision of corporate service providers. Professionals and firms providing corporate services should treat it as the authoritative account of the risk it manages and of the ownership transparency it must secure.
Money Laundering and Terrorism Financing Risk Assessment of Legal Arrangements (2024)
This companion assessment addresses express trusts and similar arrangements; structures service providers may set up or administer for a client. It shows how a trust can hide ultimate ownership and control, which is why the Corporate Service Providers Regulations require the firm to identify the settlor, trustees, protector and beneficiaries when a legal arrangement stands behind the client.
Virtual Assets (Digital Payment Tokens) Risk Assessment (2024)
This assessment measures Singapore’s exposure to activity in digital payment tokens. It touches corporate service providers where a company they form will deal in such tokens, or where a client’s wealth stems from them, calling for sharper attention when the firm assesses risk and works out the source of funds.
Corporate service activity ML/TF risk snapshot
Money laundering: high-risk gatekeeper profile, sharpened when a professional firm’s standing lends unwarranted credibility to a company created to hide its owner (ML NRA 2024; Legal Persons Risk Assessment 2024).
Main feature to watch: concealment of beneficial ownership and the misuse of nominee directors and shareholders arranged through the firm (Legal Persons Risk Assessment 2024).
Terrorism and proliferation financing: present through the abuse of legal persons as front companies, mitigated by screening and scrutiny of a company’s stated purpose (TF NRA 2024; PF NRA 2024).
Controls: ACRA supervises the corporate service work of professional and firms. (CSP Act 2024).
Sector-Specific Guidance Applicable to Professionals and Firms Providing Corporate Services in Singapore
This is the core of the obligations that attach to corporate service work. Because the regime is administered by ACRA, the rulebook is the Corporate Service Providers Regulations, read with the Registrar’s Guidelines.
The Corporate Service Providers Regulations 2025
The Corporate Service Providers Regulations 2025 are the binding AML/CFT/CPF rulebook for any person who provides corporate services, and that expressly includes an accounting entity, a law practice and a lawyer who does this work. Made under the Corporate Service Providers Act 2024 and in force from 9 June 2025, they set the duties in Part 4 and the controls over nominee directors and authorised employees in Part 5. The trigger is the corporate service itself, defined in section 2 of the Act, so a firm applies these Regulations to the incorporation, nominee, registered office and filing work it does, while its ordinary professional services fall outside them.
The Regulations begin with the risk assessment. A firm must identify, assess and understand the money laundering, proliferation financing and terrorism financing risk across its clients, the countries they are from or operate in, and the corporate services and transactions they provide, then record that assessment, keep it current and hand it to the Registrar on request. On that basis, they build the customer due diligence the firm must perform. It must establish and verify the identity of each client and each client’s agent, and where it forms a company it must identify the proposed directors, drawing on reliable and independent sources and keeping copies of what it relied on.
Beneficial ownership is the centre of gravity. A firm must ask whether a beneficial owner stands behind the client and, where one does, identify that person and take reasonable steps to verify the identity independently. For a body corporate this means finding the natural persons who ultimately own it, then, where that is unclear, those with ultimate control, and finally those with executive authority; for a trust it means identifying the settlor, trustees, protector and beneficiaries. The client, its agents, connected parties and beneficial owners must be screened against the lists issued by the Registrar and law enforcement and against designations under the United Nations Act and the Terrorism (Suppression of Financing) Act, with every result documented.
The Regulations are exact about the particulars a firm must record and when the beneficial ownership inquiry may be relaxed. For each client and agent, the firm must capture a full name and any alias, an identification or incorporation number, an address and contact details, a date of birth or incorporation and a nationality or place of incorporation, and for a company being formed the identities of its proposed directors. The inquiry may be eased where the client is a listed company, a regulated financial institution or a Singapore government entity, unless doubt or suspicion arises, and the basis for that view must be recorded. A firm may in narrow cases begin the corporate service before verification is finished, but only where deferral is essential to avoid disrupting normal business and the risk can be managed, and it must complete verification as soon as is reasonably practicable.
The Regulations then match the effort to the risk. Simplified due diligence is open only where the firm has assessed and recorded that the risk is low, and never for a client from a high-risk country or where suspicion exists. Enhanced due diligence is required for complex or unusual arrangements, for clients linked to high-risk countries, for a company with no visible business, and for a politically exposed person, demanding senior sign off, work to establish the source of wealth and funds and closer monitoring. A firm may rely on a third party, such as a bank, an advocate and solicitor or a public accountant, for parts of due diligence, but it keeps responsibility for its own compliance and must obtain the underlying records at once.
The rest of the framework tracks the corporate service lifecycle. A firm must monitor every business relationship on an ongoing basis, with enhanced monitoring for high-risk cases, and keep its records, including due diligence, for at least five years after it stops serving the client. It must maintain written internal policies, procedures and controls, extend a group policy where it belongs to a group, run an independent audit function, appoint a compliance officer at management level, and screen and train its people. Part 5 fixes the fit and proper factors a firm must weigh before it arranges a person to act as a nominee director, and the position of the authorised employees who may transact with the Registrar on its behalf.
Guidelines for Registered Corporate Service Providers (9 May 2025)
The Guidelines for Registered Corporate Service Providers, issued by ACRA on 9 May 2025, are the primary guidance a professional firm reads alongside the Regulations, and they receive the fullest treatment here. They replace the earlier guidelines for registered filing agents, reflecting the shift from a filing agent regime to the broader corporate service provider regime, and they explain how the Registrar expects the duties to be met. They are guidance rather than a binding instrument, but in practice they are the working manual for the corporate service work of an accounting entity or a law practice and lawyer.
The Guidelines start with who the regime catches and how. They explain which activities count as corporate services, so that a firm can tell which parts of its work are in scope, and they describe the registration architecture, including the deemed registration by which an accounting entity is treated as a registered provider without applying, and the registered qualified individual who actually carries out or supervises the work. They set out the fit and proper conditions, the mandatory anti-money laundering proficiency test and the registration fee, and they mark the exemptions, so a firm knows when the regime does not apply.
On the risk-based approach, the Guidelines lead a firm through assessing the risk of its clients, the countries it deals with and the corporate services it offers, and through building controls to match. They then work through customer due diligence in practical terms: identifying and verifying a client and its agents, inquiring into and verifying the beneficial owner behind a company, and handling a client that is itself a company, a partnership or a trust. They explain when simplified measures suffice and when enhanced measures, including for a politically exposed person or a company with no genuine business, are needed, and they address remote onboarding and the video call safeguards a firm should use when it never meets the client.
The Guidelines are most valuable on the nominee director, the point at which a professional firm is most exposed. They explain that a person may act as a nominee director only through a registered provider, that the firm must satisfy itself the person is fit and proper before arranging the appointment, and that a nominee holding many directorships must be assessed on the capacity to discharge them, with more than fifty directorships flagged for closer scrutiny. They describe the enhanced ongoing monitoring owed, the way a suspicion becomes a suspicious transaction report to the Suspicious Transaction Reporting Office through SONAR without tipping off the client, and the records a firm must keep evidencing its work.
The Guidelines are also alert to the professional firm’s particular position. Because an accounting entity is a deemed registered provider, the Guidelines make clear that the corporate service duties bind it from the moment it takes on this work, without waiting for any application, and that its key appointment holders carry the individual duties of a qualified individual. They remind a firm that its corporate service obligations sit alongside, and do not displace, the professional standards it already answers to, so that the same engagement may be measured against both the Regulations and the firm’s professional code. In this way the Guidelines help a firm that runs corporate services within a wider practice keep the two streams of duty distinct in its policies, its records and its training, rather than letting the corporate service work fall through the gap between them. That separation matters most at review time, when the firm must be able to show ACRA a discrete corporate service compliance trail even though the client sits within a broader professional relationship.
The Guidelines do not shy from consequences. They set out the offences a firm and its officers can commit, from carrying on corporate service work outside the regime through failing to perform due diligence or to report a suspicion, and the penalties that follow, so that a professional firm sees the regime is enforced. They stress that the duty to report a suspicion rests with whoever forms it and cannot be delegated, that authorised employees and qualified individuals need training, and that record keeping is the evidence a firm relies on when ACRA reviews it. Read with the Regulations, they turn the corporate service duties into a routine a professional firm can run alongside its core practice.
The corporate services that bring a firm into the regime
The regime turns on the service, not on whether the firm calls itself a corporate services provider. The table below lists the corporate services defined in section 2 of the CSP Act; doing any of them for a client engages the duties.
|
Corporate service (section 2 CSP Act) |
The work that pulls a professional firm into the CSP regime |
|
Forming a legal person |
Incorporating a company or forming another legal person on a client’s behalf |
|
Acting as or arranging a director or secretary |
Supplying, or arranging another to act as, a director or company secretary, including a nominee director |
|
Providing a registered office or address |
Offering a registered office, business, correspondence or administrative address for a corporation, partnership or other legal person |
|
Acting as or arranging a nominee shareholder |
Holding, or arranging another to hold, shares as nominee, except for a company listed on an approved exchange |
|
Accounting service designated activity |
Carrying out a designated activity connected to the provision of an accounting service |
|
Filing with ACRA as an agent |
Carrying out ACRA transactions through the electronic system on another person’s behalf, the classic filing agent role |
How a professional firm enters the corporate service regime
Entry differs by the kind of provider, and for an accounting entity it is automatic. The table below sets out the routes.
|
Type of provider |
How it enters the CSP regime |
|
Accounting entity |
Treated as registered, a deemed registered CSP, under section 7(2) of the CSP Act the moment it carries on corporate service work; no separate application is needed |
|
Key appointment holder of that entity |
Treated as a deemed registered qualified individual, carrying the individual duties that go with the firm’s deemed registration |
|
Law practice or lawyer providing corporate services |
Brought within the corporate service regime for that work, alongside the profession’s own regulation under the Legal Profession Act |
|
A standalone corporate service provider |
Must apply to ACRA and be registered under section 8 before it may carry on the business at all |
|
A bank or exempt person |
Relieved of the registration requirement by the CSP exemption orders, because it is already supervised for AML purposes |
Allied Laws Applicable to Professionals and Firms Providing Corporate Services in Singapore
These statutes are not primarily AML rules, but each supports the regime: some define the corporate service regime and its edges, while others govern the companies’ service providers’ form.
The Corporate Service Providers Act 2024
The Corporate Service Providers Act 2024 regulates corporate service providers in Singapore and establishes requirements relating to AML, CFT and CPF. It is relevant to accountants, lawyers and law practices when they provide regulated CSP services, such as company formation, registered-office services and nominee director arrangements.
The Corporate Service Providers (Exemption) Order 2025
The order that draws the boundary of the regime, exempting defined persons or activities from the requirement to register as a corporate service provider. It tells professionals and firms whether a given piece of corporate service work brings it within the regime, and a firm relies on it to scope its own duties correctly.
The Corporate Service Providers (Exemption for Banks, etc.) Order 2025
A companion order that relieves banks carrying out corporate service work from the registration requirement, because MAS already supervises them for AML purposes. It prevents duplicated supervision while leaving the substantive anti-money laundering duties in place for the institution concerned.
The Companies Act 1967
The principal statute governing companies, the legal persons professionals and firms most often form and administer. Its reforms on beneficial ownership registers and the central filing of nominee status are the transparency backbone that service providers’ due diligence both draws on and feeds when they form a company for a client.
The Limited Liability Partnerships Act 2005
The statute constituting limited liability partnerships, both a common form for professional firms themselves and a structure they set up for clients. It fixes the registration, management and disclosure rules for LLPs, and service providers apply their beneficial ownership duties to the partners and managers behind such a vehicle.
The Public Accountants (Public Accountants) Rules 2006
The rules governing the registration and practice of public accountants. They frame the professional standing of an accounting entity that provides corporate services, and they sit alongside the corporate service duties that entity carries as a deemed registered provider.
The Accountants’ Prescribed Standards and Code of Professional Conduct and Ethics Order 2023
The order prescribes the professional standards and ethical requirements applicable to accountants. It complements the CSP AML, CFT and CPF framework by requiring accountants to uphold professional integrity, exercise due care and comply with applicable legal and regulatory obligations when providing corporate services.
The Prevention of Corruption Act 1960
Singapore’s principal anti-corruption law. Because corruption is a predicate offence for money laundering, the proceeds of offences under it are among the things service providers watch for when it checks a client’s source of funds, and its presumption on unexplained wealth sharpens scrutiny where a client’s means cannot be explained.
The Criminal Procedure Code 2010
Singapore’s procedural code for criminal cases, giving investigators the power to compel production and to search and seize. When a production order arrives concerning a company the firm incorporated, or a client it acted for, the service provider must produce what is sought, keep its records intact and say nothing to the client, and that is how an investigation opens up the corporate service file.
The Strategic Goods (Control) Act 2002
Governs the transfer and brokering of strategic and dual-use goods; the proliferation financing nexus service providers may meet where a client company trades in such goods. Its controls flag exposure that a firm weighs when it forms or administers a company with that kind of business.
The Biological Agents and Toxins Act 2005
The Statute regulates the possession, use, import, transfer and handling of specified biological agents and toxins, helping prevent misuse. It supports Singapore’s proliferation financing framework, requiring service providers to remain alert where corporate structures or transactions may facilitate dealings involving controlled biological agents and toxins.
The Chemical Weapons (Prohibition) Act 2000
It implements Singapore’s obligations under the Chemical Weapons Convention by prohibiting and regulating activities involving chemical weapons and specified toxic chemicals. It supports the counter-proliferation framework by requiring service providers to remain alert to transaction or corporate structures that could facilitate prohibited chemical weapons activities.
Miscellaneous Laws and Regulations Applicable to Professionals and Firms Providing Corporate Services in Singapore
These national strategies, committee reports and typologies set the direction of Singapore’s regime service providers operate within. They carry no binding force, but they steer how supervisors act and supply many of the typologies service providers build into their checks on companies and their owners.
National Anti Money Laundering Strategy 2024
Singapore’s overarching AML plan, organised around Prevent, Detect and Enforce. Corporate service providers belong to the Prevent pillar as a gatekeeper, where the authorities emphasise gatekeeper accountability and beneficial ownership transparency in the companies the firm helps establish and administer.
National Strategy for Countering the Financing of Terrorism 2024
Refreshed in 2024 with the terrorism financing risk assessment, this strategy advances on five fronts, joining up risk identification, hardening the legal and sanctions framework, keeping supervision robust, pressing enforcement and deepening cooperation. It points the direction a firm’s terrorism financing controls should take.
National Asset Recovery Strategy 2024
Singapore’s plan for following, freezing and returning criminal proceeds, noting the value recovered of late. Service Providers contribute chiefly through their reporting and their compliance with production orders, since a company they formed can be the vehicle holding assets that fall to be restrained.
Singapore Law Enforcement Strategy to Combat Money Laundering (October 2024)
A joint strategy of Singapore’s money laundering investigation agencies, setting focus areas and key actions and depending on two-way information flows with the private sector. It frames the enforcement backdrop that service providers support through their reporting on suspicious clients and incorporations.
Inter Ministerial Committee on Anti Money Laundering Report (October 2024)
The review was conducted after a large money laundering case, recommending action on the misuse of corporate structures, the duties of gatekeepers and better information sharing. Its conclusions bear directly on professional firms that provide corporate services, and much of the recent tightening, including the new Act, flows from it.
Legal Persons: Misuse Typologies and Best Practices (2018)
A typologies paper on the ways companies and partnerships are misused, giving a firm the red flags for beneficial ownership and nominee checks. It is squarely on point for a professional firm whose corporate service work is the formation and administration of exactly these structures.
International Standards Applicable to Professionals and Firms Providing Corporate Services in Singapore
Singapore’s regime is built to meet these standards, and the Corporate Service Providers Regulations track them, above all the standards on beneficial ownership that bear so heavily on this work. They are the source of the domestic rules and the origin of the typologies a firm is expected to follow.
The FATF Recommendations (updated June 2026)
The Recommendations are the global AML, CFT and CPF standard underpinning corporate service duties, with Recommendations 24 and 25 on the beneficial ownership of legal persons and arrangements directly relevant to the sector’s gatekeeper role in forming and administering them.
Mutual Evaluation Report of Singapore (May 2026)
The 2026 review by the FATF and the Asia/Pacific Group assesses how well Singapore’s regime works in practice, with the transparency of legal persons a running theme. It sets the tone for how ACRA supervises those who provide corporate services, professional firms included.
Methodology for Assessing Technical Compliance and Effectiveness (updated June 2026)
The FATF’s framework for assessing technical compliance with the recommendations and the effectiveness of a country’s AML, CFT and CPF framework. It sets the yardstick against which Singapore, and indirectly the corporate service work of its professional firm, is assessed.
FATF Guidance on Politically Exposed Persons (Recommendations 12 and 22, 2013)
Sets out how to identify politically exposed persons and apply enhanced due diligence, senior approval, establishing source of wealth and funds, and closer monitoring, which a firm brings to bear when a PEP sits behind a company it is asked to form or administer.
Guidance on Beneficial Ownership of Legal Persons (March 2023)
Guidance under the revised Recommendation 24 on obtaining and verifying beneficial ownership information. It is the international counterpart to a firm’s central duty, shaping how it identifies the natural person who really owns or controls a company.
Best Practices on Beneficial Ownership for Legal Persons (October 2019)
A set of country best practices for keeping beneficial ownership information adequate, accurate and up to date, supporting a firm’s use of registries and multiple independent sources when it identifies the owner behind a corporate client.
Concealment of Beneficial Ownership (July 2018)
A FATF and Egmont Group typologies study on how criminals bury beneficial ownership through nominees, intermediaries and layered structures. It is directly relevant to a professional firm, whose services, if misused, are among the very devices the study describes.
Risk Based Approach: Beneficial Ownership and Transparency of Legal Arrangements (March 2024)
Guidance under Recommendation 25 on trusts and similar arrangements, helping a firm assess and mitigate risk where a trust or similar structure stands behind a corporate client it forms, administers or advises.
FATF Guidance on Counter Proliferation Financing (February 2018)
Guidance on applying the financial provisions of Security Council resolutions against weapons of mass destruction proliferation, under which a firm must screen and freeze without delay in line with Recommendation 7, alert to front companies used to disguise procurement.
Guidance on Proliferation Financing Risk Assessment and Mitigation (June 2021)
Describes how a firm should assess and reduce proliferation financing risk after the changes to Recommendations 1 and 2 brought it within the risk assessment duty, which a firm now discharges as part of its enterprise risk assessment.
Money Laundering from Environmental Crime (July 2021)
A FATF examination of how money earned from environmental crime travels through the financial system. It becomes relevant to a firm when a company it has formed ends up holding or routing those proceeds behind a lawful-looking corporate front, one more signal for the firm to weigh.
Guidance on Digital Identity (March 2020)
Helps a firm judge whether a digital identity system is reliable and independent enough for customer due diligence under a risk-based approach, a live question as firms onboard clients remotely and rely on video verification.
Artificial Intelligence and Deepfakes: Impacts on ML/TF/PF
A forward-looking FATF scan of how artificial intelligence and deepfakes threaten preventive systems, for example, synthetic identities defeating remote checks, alongside the uses of such tools in screening that a firm can turn to advantage.
Summary of Key Instruments
The table below distils the instruments a firm providing corporate services relies on most, what type each is, whom it binds, and the core obligation it places on the firm. It is a fast reference to read beside the discussion, and the detailed sections above remain the controlling text.
|
Instrument |
Type |
Binds |
Core obligation for a firm providing corporate services |
|
CDSA 1992 |
Statute |
Everyone |
Report suspected criminal proceeds; do not tip off |
|
TSOFA 2002 |
Statute |
Everyone |
Do not deal in terrorist property; screen and report |
|
UN Act sanctions regulations (DPRK, Iran) |
Regulations |
All persons |
Screen for and freeze designated persons without delay |
|
CSP Regulations 2025 |
Regulations (binding) |
CSPs and deemed CSPs |
Risk-based CDD, beneficial ownership tracing, records, STR |
|
Guidelines for Registered CSPs (2025) |
Guidance |
CSPs and deemed CSPs |
Primary guidance; how to apply the Regulations |
|
CSP Act 2024 |
Statute |
Providers, incl. accounting entities |
Registration and deemed registration; nominee director control |
|
FATF Recommendations |
Standard |
Everyone |
The global standard, including beneficial ownership |
Conclusion
For accounting entities, law practices, or lawyers that provide corporate services in Singapore, the anti-money laundering framework attaches to the corporate service activity, not to the profession at large, and ACRA administers it. The criminal statutes establish money laundering and terrorism financing offences and require suspicious transactions to be reported; the sanctions regulations require designated parties to be screened out; and the Corporate Service Providers Regulations, read with the Guidelines, translate these requirements into a working system of risk assessment, customer due diligence, beneficial ownership verification, enhanced measures for high-risk cases, controls over nominee directors and suspicious transaction reporting. Because the risk lies in concealed ownership operating behind the firm’s good name, the controls focus on identifying who ultimately stands behind a company.
The instruments interlock. The firm’s risk assessment draws on the national risk assessments, particularly the assessment of legal persons; its due diligence flows from the Regulations and Guidelines; its place in the regime comes from deemed registration under the Corporate Service Providers Act; and its beneficial ownership identification is anchored in the Companies Act reforms and the FATF standards. Understanding how these pieces connect, while recognising that these duties operate alongside the firm’s professional regulation, turns a second hat into a framework the firm can defend.
The corporate service provider regime, together with the anti-money laundering duties borne by the accountancy profession itself, is covered in full in our companion guides to corporate service providers and to accountants.
Frequently Asked Questions
Yes, for their corporate service work. When an accounting entity, a law practice or a lawyer forms companies, acts as or arranges a nominee director or shareholder, provides a registered office or files with ACRA as an agent, it is providing a corporate service, and the Corporate Service Providers Act 2024 and Regulations 2025 apply. Their ordinary professional services fall outside the regime.
Under section 7(2) of the CSP Act, an accounting entity that carries on corporate service work is deemed registered as a corporate service provider without making a separate application. Its key appointment holders are correspondingly deemed registered qualified individuals, and its AML, CFT and CPF duties apply automatically for the relevant corporate service activities until the deemed registration is suspended or cancelled. i
ACRA administers and regulates the corporate service provider regime, so it supervises the corporate service work of accountants, lawyers and law practices when they act as corporate service providers. This operates alongside the firm’s professional regulation: accountants under the Accountants Act and for lawyers and law practices under the Legal Profession Act. Accordingly, a firm must comply with both the CSP regime and the professional rules applicable to it.
Under regulation 21, the firm must first inquire whether a beneficial owner exists and, where one exists, identify and verify that person using reliable and independent sources. It must look through the corporate structure to identify the natural person who ultimately owns or controls the company and, where no such person can be identified, the person exercising executive authority. This look-through process is central to the due diligence a firm must perform on a corporate client.
Under section 16 of the CSP Act, the firm must be satisfied the person is fit and proper to act as a nominee director. It must consider matters including fraud or dishonesty convictions, bankruptcy, and the compliance record of companies previously directed by the person. It must also assess the person’s capacity to act effectively, with more than fifty nominee directorships warranting closer assessment. Failure to comply may attract a fine of up to SGD 100,000.
Whenever the firm has reasonable grounds to suspect money laundering or terrorism financing in its corporate service work. The report is filed with the Suspicious Transaction Reporting Office through SONAR within five business days of the suspicion forming, and the firm must keep it from the client. Our guide to STR red flags sets out the sort of triggers that recur, among them a client asking the firm to incorporate a company that will carry on no real activity.
About the Author
Pathik Shah
FCA, CAMS, CISA, CS, DISA (ICAI), FAFP (ICAI)
Pathik is a Chartered Accountant with more than 26 years of experience in governance, risk, and compliance. He helps companies with end-to-end AML compliance services, from conducting Enterprise- Wide Risk Assessments to implementing the robust AML Compliance framework. He has played a pivotal role as a functional expert in developing and implementing RegTech solutions for streamlined compliance.

