Can a checklist truly protect a financial system, or does effective control need to be a continuous habit?
Singapore is a global financial hub with firm AML expectations from the Monetary Authority of Singapore. This guide explains practical customer due diligence requirements singapore business teams must meet across onboarding, screening, monitoring and reporting.
The content is aimed at compliance officers, operations leaders, founders and front‑line staff who handle onboarding and account servicing. You will learn why due diligence is not a one‑off task but a lifecycle discipline that begins before a relationship starts and continues through monitoring and review.
Expect clear comparisons of CDD, KYC and AML, plus guidance on risk‑based controls, sanctions and PEP screening, enhanced measures for higher risk profiles, and how to report suspicious activity without tipping off the subject.
Key Takeaways
- Understand the lifecycle approach to CDD and how it differs from KYC.
- Know which sectors face exposure beyond banks, including payments and real estate.
- Adopt risk‑based controls and enhanced screening for high risk profiles.
- Build a defensible evidence trail to reduce regulator findings.
- Learn practical reporting steps and operational artefacts referenced to MAS and local regulators.
What customer due diligence requirements singapore business must meet in Singapore today
Regulators expect firms to verify identities, understand activity purpose, and spot risk before accounts are opened.
Why this matters for AML and preventing financial crime
Customer due diligence is the frontline defence against money laundering and broader financial crime. Verifying identity and the nature of a relationship makes it harder for criminals to hide behind false names or opaque entities.
How AML, KYC and CDD fit together in practice
Think of AML as the framework. KYC is the process of knowing who you deal with. CDD are the specific steps to identify, verify and assess beneficial ownership.
Who falls in scope beyond banks
Rules extend to many sectors. Typical groups include:
- Payment service and digital token providers
- Insurance, securities firms and brokers
- Casinos, real estate agents and dealers of precious metals
- Trust companies, corporate service providers, lawyers and accountants
Obligations follow a risk-based model: higher-risk relationships need deeper checks, more approvals and tighter monitoring. Even when tasks are outsourced, the regulated entity remains accountable for outcomes and evidence.
The next sections explain how regulators test effectiveness through audits, inspections and enforcement.
Singapore’s AML/CFT framework that drives due diligence obligations
Law and policy set clear expectations for how firms must prevent, detect and report illicit finance.

Core legislation forms the legal backbone. The Corruption, Drug Trafficking and Other Serious Crimes Act 1992 (CDSA) criminalises laundering and requires reporting of suspicious transactions and behaviours.
The National Anti‑Money Laundering Strategy (October 2024) raises the bar on system resilience. It focuses on prevention, detection, enforcement and stronger international cooperation.
What recent law changes mean in practice
The Anti‑Money Laundering and Other Matters Act (November 2024) equips authorities with sharper enforcement tools. It clarifies how property linked to suspected crime is handled and aligns casino AML/CFT with FATF expectations.
- Operational duties: identify and verify parties, assess risk, monitor transactions, keep records and escalate suspicious activities promptly.
- Why process matters: weak onboarding, unclear beneficial ownership or poor monitoring turn compliance into a paper exercise and invite enforcement.
- Enforcement focus: inspectors often pursue process failures — late checks, weak documentation or missed alerts — even if no proven money laundering occurred.
Regulatory expectations reach into guidance, notices, inspections and sector rulebooks; the next section covers the regulators you will interact with.
Regulators and oversight bodies you may interact with
Knowing which regulator to engage with is the first practical step in building a defensible AML framework.
Monetary Authority of Singapore as integrated regulator
The Monetary Authority is the central bank and integrated regulator. It issues licensing, supervises financial institutions and publishes AML/CFT notices and guidance.
MAS can take enforcement action when firms fall short. Firms must keep dated forms, screening logs and escalation records that show how decisions were made.
Sector regulators that extend oversight
Oversight reaches beyond banks. Casinos, estate agents and corporate service providers are in scope because they can be misused for illicit flows.
- Casino Regulatory Authority — casino AML/CFT controls and inspections.
- Council for Estate Agencies (CEA) — real estate CDD rules and checks.
- ACRA — oversight of corporate service providers, accountants and entity integrity.
Practical lens: identify your sector regulator first, map its rules to internal policy and ensure senior management owns governance and resourcing. That approach helps demonstrate compliance rather than assertions when inspectors review your audit trails.
Risk-based approach and Singapore’s National Risk Assessment
Singapore’s country-wide risk study gives practical signals for how to shape your onboarding and monitoring.
What the NRA is and how it guides your assessment
The National Risk Assessment (NRA) is MAS’s summary of country‑level threats from money laundering and terrorism financing. Use its findings to calibrate your risk assessment and set how deep identity checks and monitoring should be.

Key themes from recent assessments
The 2024 NRA called out digital payment rails, fast cross‑border transfers, organised fraud and misuse of legal persons. These themes increase velocity and layering risk and can hide true ownership.
Turning NRA signals into controls and resourcing
Translate national themes into product, channel and geography mappings. Document why a product scores higher and which triggers require enhanced review.
| Risk theme | Operational impact | Example control |
|---|---|---|
| Digital payments | High transaction speed increases layering | Real‑time monitoring for rapid in/out flows |
| Cross‑border transfers | Higher AML exposure from foreign corridors | Stronger originator checks and geofencing |
| Misuse of legal persons | Obscured beneficial ownership | Deeper BO verification and corporate onboarding |
Escalate profiles that match multiple NRA flags to higher tiers and require enhanced due diligence and more frequent reviews. Record inputs and outputs clearly so regulators can follow your rationale for resourcing, controls and testing cadence.
Core CDD steps: collecting and verifying customer information
Effective onboarding begins with clear identity and entity checks that can be defended under audit.
Minimum identification data
Individuals: full name, ID or passport number, residential address and nationality.
Entities: registered name, registration number, registered address, directors and authorised signatories. For companies, an up‑to‑date ACRA profile or certificate of incorporation is typical evidence.
Verification standards and evidence
Use reliable, independent sources to verify identity. Examples include NRIC/passport checks for individuals and registry extracts for entities.
Record what was validated, when and by whom. This makes the cdd process transparent and auditable.
Purpose, beneficial owners and documentation
Capture the intended nature of the relationship so future activity can be assessed against expectations.
Map ownership and verify beneficial owners and controllers to mitigate shell‑company risk. Keep copies, screenshots or references to databases, note any discrepancies and save approvals.
Timing and quality controls
Complete customer due diligence before the relationship starts, except where documented, controlled exceptions apply.
- Periodic file reviews and second‑line checks for higher risk profiles.
- Regular testing to ensure the cdd process works in practice.
For related privacy handling, see our privacy policy.
Screening requirements: sanctions, politically exposed persons and adverse information
Screening is a continuous control that catches sanctions hits, PEP linkages and adverse media before risk crystallises.

Sanctions screening is an operational must. Organisations must screen records and related parties at onboarding and on a recurring basis against global lists and national designations. Document matches, false positives and final decisions so an auditor can follow the trail.
Sanctions list coverage in practice
Coverage should include consolidated international lists, local designations and sector‑specific watchlists. Run matches for beneficial owners, directors and authorised signatories as well as primary profiles.
Politically exposed persons and connected parties
Identify whether the individual, beneficial owner or key controller is a politically exposed person. Extend checks to close associates and family where policy dictates.
For PEP relationships, firms must obtain senior management approval to onboard or continue the relationship. Reasonable measures to establish source of wealth and source of funds are required, with enhanced monitoring for unusual activity and prompt reporting of suspicious activities without tipping‑off.
When senior management approval is required
Triggers include onboarding a PEP, maintaining a relationship with an exposed person, high‑risk corporate structures, or exception requests to risk appetite. Record the approval, the rationale and any monitoring uplift applied.
Practical workflow for potential hits:
- Triage the match and corroborate identifiers (DOB, ID, address).
- Check adverse media and law enforcement‑relevant indicators from credible sources.
- Escalate confirmed concerns to compliance for decision: accept with controls, reject or exit.
- Document rationale, approvals and monitoring steps taken.
| Screening element | Who to screen | Operational action |
|---|---|---|
| Sanctions lists | Primary profile, BOs, signatories, counterparties | Automated matches, manual review, record decisions |
| PEP databases | Individuals and connected persons | Enhanced checks, source of wealth checks, senior approval |
| Adverse media | Applicants and related parties | Corroborate with reliable sources, adjust risk score |
Screening is integral to broader cdd and aml controls. It informs whether standard measures suffice or if enhanced due diligence must conduct. For regional coverage and guidance, see local monitoring resources.
Enhanced due diligence and higher-risk scenarios
When risk elevates, firms must move beyond basic checks to targeted, evidence‑based verification.
What enhanced measures mean: enhanced due diligence (EDD) requires additional checks and deeper verification beyond standard customer due processes. It helps manage elevated money laundering and terrorism financing risk and is expected for high‑risk profiles and non‑face‑to‑face channels.
Common triggers for extra scrutiny
- Connections to higher‑risk jurisdictions or opaque ownership structures.
- Rapid cross‑border flows, cash‑intensive activity or layered holding entities.
- PEP links, adverse media, or an unclear purpose for the relationship.
Source of funds versus source of wealth
Source of funds explains where specific money originated; reasonable measures include bank statements, payment receipts or contract copies.
Source of wealth explains overall means of accumulation; reasonable measures include tax returns, sale agreements or audited accounts that corroborate the profile and activity.
Controls for non‑face‑to‑face and digital onboarding
Apply stronger identity verification, device and behavioural checks, and fraud‑resistant KYC flows. Add monitoring rules for synthetic IDs and account takeover indicators.
EDD raises approval thresholds, mandates more frequent reviews and tighter alerting. If residual risk cannot be mitigated, clear exit criteria should apply. For practical references on enhanced due processes see enhanced due diligence guidance and review your terms and conditions to align approval workflows.
Ongoing monitoring, suspicious activities and reporting obligations
Sustained oversight of relationships helps detect evolving risk and prevents escalation.

Keeping CDD current and operational monitoring
Ongoing monitoring is a continuous control. Keep profiles up to date, refresh documents by risk tier and rerate when triggers occur — for example new owners, products or unusual transactions.
Operationalise monitoring with scenario alerts, periodic reviews and a clear investigation playbook. That turns noise into decisions supported by evidence rather than unchecked alerts.
Red flags for suspicious transactions and behaviours
Watch for activity that conflicts with the stated purpose, rapid in‑and‑out movements, unexplained third‑party flows or sudden counterparty changes.
- Layering via multiple entities or complex routing.
- Repeated large value transactions inconsistent with profile.
- Unusual payment patterns or frequent cash‑like transfers.
When and how to report suspicious activity to the STRO
If an alert uncovers credible concern, file an STR promptly to the Suspicious Transaction Reporting Office with clear context: identifiers, transactions, rationale and supporting evidence.
Ensure internal escalation timelines are defined so compliance teams can decide and act without delay.
Avoiding tipping-off and managing retain vs exit choices
Do not inform the subject that an STR is under consideration or filed. Control communications to prevent tipping‑off and preserve investigative integrity.
If the relationship is retained, require enhanced scrutiny: transaction limits, more frequent reviews and senior approval. Record the rationale and mitigation so auditors can trace the decision.
Sector-specific expectations for Singapore businesses
Sector rules shape how controls are applied day to day and change the detail behind a standard policy.
Financial institutions and payment providers
Monetary Authority Singapore issues sector notices that firms must follow. Examples include MAS Notice 626, 1014 and 824 for banks and finance firms, plus PSN01 and PSN02 for payment and digital token services.
Expect robust onboarding controls, continuous monitoring, screening and clear governance for higher‑risk profiles. Align product rules to formal notices and record decisions.
Insurance, securities and other regulated firms
For insurance companies and securities firms, identity checks and BO verification must suit policy types and distribution channels.
Tailor monitoring to portfolio behaviour rather than treating every account the same.
Real estate, casinos and trust services
Real estate salespersons must complete cdd before any property agreement is signed. Date the Customer’s Particulars Form and obtain written acknowledgement.
Common lapses include late screening and missing beneficial owner identification for company clients.
Casinos and designated dealers now face a S$4,000 CDD threshold. That lower trigger increases the number of transactions needing fast, consistent checks.
Trust companies and corporate service providers must verify company existence (for example, an ACRA profile) and map ownership to prevent misuse of legal persons.
Building a defensible compliance programme: policies, training, recordkeeping and technology
A defensible compliance programme starts with policies that map to how work actually gets done across teams.
Policy, governance and the compliance lead
Clear policies must reflect sector rules and everyday workflows. Procedures should be testable and produce traceable outcomes for audits.
The compliance officer owns the AML framework, approves exceptions, oversees investigations and handles regulator interactions.
Training and culture
Train staff at onboarding and run annual refreshers. Focus on KYC steps, red flags, escalation routes and tipping‑off risks.
Records and retention
Keep identification files, account records, screening logs and analysis outputs. Retain records for at least five years after the relationship ends or the last transaction.
Automation, monitoring and outsourcing
Automate screening and transaction monitoring where volumes justify it. Tune rules to lower false positives and document testing results.
Operational tasks may be delegated, but institutions retain final accountability for adequacy, decisions and regulator‑facing evidence.
“Policies, people and tech must create a coherent know customer view that supports ongoing risk decisions.”
Conclusion
Clear identity checks and ongoing monitoring form the backbone of any resilient anti‑money laundering programme.
Customer due diligence must be risk‑based and practical. Effective cdd combines identity verification, beneficial ownership clarity, screening and continuous review. Strong controls help institutions spot money laundering early and protect reputation and revenue.
Good practice means onboarding completed at the right time, evidence retained, and monitoring aligned to expected activity. Investigate suspicious patterns quickly, escalate consistently and report to STRO without tipping‑off.
Operationalise this guide: review workflows, map obligations to sector regulators, update policies and training, validate vendors, and schedule periodic testing so safeguards remain effective as risks evolve.
FAQ
What are the key legal instruments that shape anti‑money laundering obligations in Singapore?
Why does robust identification and verification matter for preventing financial crime?
How do KYC, AML and CDD relate in practice?
Which sectors beyond banks must apply these controls?
What role does the Monetary Authority of Singapore play in oversight?
How does the National Risk Assessment (NRA) affect internal risk frameworks?
What minimum identification data should be collected for individuals and legal entities?
What counts as reliable verification evidence?
How should beneficial owners and controllers be identified?
When must sanctions and adverse media screening be performed?
Who is considered a politically exposed person (PEP) and what extra measures apply?
What triggers enhanced measures for higher‑risk relationships?
What are practical expectations for confirming source of wealth and source of funds?
How should firms manage non‑face‑to‑face onboarding and digital channels?
What does ongoing monitoring involve?
What are common red flags for suspicious transactions?
How and when should suspicious activity be reported to STRO?
What is tipping‑off and how should it be avoided?
What sector‑specific rules should payment service providers and banks follow?
What particular expectations apply to real estate agencies and salespersons?
How should trust companies and corporate service providers guard against misuse of legal persons?
What elements make a defensible compliance programme?
What are best practices for staff training and culture of compliance?
How long should records be retained and what must be preserved?
Can firms outsource parts of the verification process and what remains their responsibility?
How can automation reduce false positives without missing genuine risks?

Dean Cheong is a Singapore-based B2B growth strategist and the CEO of VOffice. He helps companies scale revenue through sharper sales execution, CRM implementation, and go-to-market strategy, backed by a strong foundation in business banking and finance from Nanyang Technological University and a track record of driving sustainable, performance-led growth.