Let’s talk

Insights for your business.

AML/CFT Obligations for Ordinary Companies in Singapore: What Directors Should Know

Colleagues discussing documents in a meeting

Introduction

Directors of ordinary companies often ask what AML/CFT obligations they personally need to understand and oversee. AML/CFT Obligations for Ordinary Companies in Singapore: What Directors Should Know explains the key responsibilities, whether your company is a regulated reporting entity or an ordinary commercial business that still faces AML/CFT risk.

This article provides practical guidance on expectations under Singapore’s framework and highlights actions directors should take to meet their oversight duties. The article title reflects the focus on practical compliance measures and governance for directors.

Who this applies to

This guidance is relevant to:

Key rules and requirements in Singapore

Singapore’s AML/CFT framework is overseen by multiple authorities and comprises both sector-specific obligations and general legal requirements. Directors should understand the following elements.

Regulatory framework and authorities

KYC / Customer Due Diligence (CDD)

Directors should ensure their company has proportionate CDD measures. Common elements include:

Suspicious transaction reporting

Where a company identifies transactions that may be related to criminal activity or terrorism financing, a Suspicious Transaction Report (STR) should be prepared and submitted to STRO. Directors should ensure there are clear internal escalation routes and that staff know how to spot and report suspicious activity.

Record-keeping and retention

Companies should retain relevant customer due diligence records, transaction records and internal reports for an appropriate period. Under MAS notices and common practice, this is typically at least five years from the end of the business relationship, although the exact period may vary by sector.

Governance, policies and training

Directors are responsible for overseeing the establishment and maintenance of AML/CFT policies, appointing an appropriate compliance officer where necessary, and ensuring staff receive adequate training.

Step-by-step process

The following is a practical process directors can adopt to strengthen AML/CFT compliance at their company.

1. Conduct a risk assessment

2. Implement proportionate policies and procedures

3. Appoint responsibilities

4. Conduct training and awareness

5. Monitor, review and report

6. Maintain records and audit trail

Common mistakes to avoid

Practical examples

These short scenarios illustrate common AML/CFT issues directors should be prepared for.

Example 1: Complex beneficial ownership

A new corporate client is owned through multiple foreign entities and trusts. The company’s onboarding team must identify the ultimate beneficial owner(s) and apply enhanced due diligence before approving transactions. Directors should ensure the company has documented steps to resolve opaque ownership structures.

Example 2: Unusual payment patterns

An account shows frequent high-value transfers to third parties in high-risk jurisdictions inconsistent with the customer’s business profile. Staff should escalate this for review and consider submitting an STR to STRO if suspicions are not resolved.

Example 3: Politically exposed person (PEP)

A proposed client is identified as a PEP. The company must carry out enhanced checks, obtain senior management approval and closely monitor future transactions for unusual activity.

How a corporate secretary can help

A corporate secretary or an external corporate services provider can support directors by:

Frequently Asked Questions

Do all companies in Singapore need an AML/CFT policy?

Not all companies are regulated by MAS as financial institutions, but all directors should consider whether their business activities create AML/CFT risks. If the company deals with high-risk customers, cross-border funds, or is a designated reporting entity, an AML/CFT policy is necessary. Directors should review sector guidance and obtain tailored advice.

How long should AML/CFT records be retained?

Record-retention periods can vary, but common practice under MAS guidance is to retain records for at least five years from the end of the business relationship. Directors should ensure retention policies meet sector-specific requirements and are consistently applied.

Who should submit an STR and to whom?

Trained staff or the company’s compliance officer should prepare suspicious transaction reports for submission to STRO when there are reasonable grounds for suspicion. Directors should ensure clear internal reporting lines and that STR submission is timely and documented.

Key takeaways

Call to action

If you would like to find out more about how Raffles Corporate Services can assist with your company’s compliance and corporate secretarial requirements, please get in touch with the team at [email protected].

Yours sincerely,
The editorial team at Raffles Corporate Services

Requirements may change, so always check the latest guidance from ACRA, IRAS or MOM, or consult a professional adviser.

Disclaimer: This does not constitute legal advice. If you require legal advice, please contact a lawyer.

Submit a Comment

Your email address will not be published. Required fields are marked *

Real people. Right here in Singapore.

Let’s get to work.

Hop on Raffles Corporate Services