Introduction
Directors of ordinary companies often ask what AML/CFT obligations they personally need to understand and oversee. AML/CFT Obligations for Ordinary Companies in Singapore: What Directors Should Know explains the key responsibilities, whether your company is a regulated reporting entity or an ordinary commercial business that still faces AML/CFT risk.
This article provides practical guidance on expectations under Singapore’s framework and highlights actions directors should take to meet their oversight duties. The article title reflects the focus on practical compliance measures and governance for directors.
Who this applies to
This guidance is relevant to:
- Directors and senior management of private and public companies incorporated in Singapore under the Companies Act.
- Companies that are designated reporting entities (for example, certain financial institutions and specified non-financial businesses and professions) as well as ordinary companies that engage in higher-risk activities or cross-border transactions.
- Company secretaries and in-house compliance personnel responsible for corporate governance, KYC and record-keeping.
Key rules and requirements in Singapore
Singapore’s AML/CFT framework is overseen by multiple authorities and comprises both sector-specific obligations and general legal requirements. Directors should understand the following elements.
Regulatory framework and authorities
- The Monetary Authority of Singapore (MAS) sets AML/CFT requirements for financial institutions via MAS Notices and Guidelines.
- Suspicious transaction reports are submitted to the Suspicious Transaction Reporting Office (STRO).
- Certain offences and powers under statutes such as the Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act and related regulations are relevant to reporting and confiscation action.
- Other regulatory bodies (for example, ACRA and IRAS) have intersecting compliance and corporate-governance requirements that directors must consider when managing risks.
KYC / Customer Due Diligence (CDD)
Directors should ensure their company has proportionate CDD measures. Common elements include:
- Verifying customer identity and beneficial ownership (including corporate customers).
- Understanding the purpose and intended nature of the business relationship.
- Conducting enhanced due diligence for higher-risk customers (for example, politically exposed persons or complex ownership structures).
Suspicious transaction reporting
Where a company identifies transactions that may be related to criminal activity or terrorism financing, a Suspicious Transaction Report (STR) should be prepared and submitted to STRO. Directors should ensure there are clear internal escalation routes and that staff know how to spot and report suspicious activity.
Record-keeping and retention
Companies should retain relevant customer due diligence records, transaction records and internal reports for an appropriate period. Under MAS notices and common practice, this is typically at least five years from the end of the business relationship, although the exact period may vary by sector.
Governance, policies and training
Directors are responsible for overseeing the establishment and maintenance of AML/CFT policies, appointing an appropriate compliance officer where necessary, and ensuring staff receive adequate training.
Step-by-step process
The following is a practical process directors can adopt to strengthen AML/CFT compliance at their company.
1. Conduct a risk assessment
- Assess products, services, customer types, delivery channels and geographic exposures to identify where money-laundering or terrorist-financing risks are highest.
- Document the assessment and review it periodically, particularly when business activities change.
2. Implement proportionate policies and procedures
- Develop written AML/CFT policies covering CDD, enhanced due diligence, transaction monitoring, record-keeping and STR escalation.
- Tailor controls to the risk profile determined in the risk assessment.
3. Appoint responsibilities
- Appoint a named compliance officer or designate responsibility within the management team for oversight and STRO reporting.
- Ensure that the compliance function has sufficient independence, resources and reporting lines to the board or directors.
4. Conduct training and awareness
- Provide regular training to staff who onboard customers, approve transactions or maintain records.
- Maintain training records and evidence of completion.
5. Monitor, review and report
- Implement transaction monitoring or manual review processes to detect unusual activity.
- Ensure timely escalation and, where appropriate, submission of STRs to STRO.
- Review and update policies based on incidents, regulatory updates or business changes.
6. Maintain records and audit trail
- Keep comprehensive records of CDD, risk assessments, training and internal reports to demonstrate compliance to regulators such as MAS or ACRA if required.
Common mistakes to avoid
- Poor or inconsistent customer identification and failure to verify beneficial ownership of corporate customers.
- Lack of documented policies or failure to apply enhanced checks for higher-risk customers such as PEPs.
- Inadequate staff training or unclear internal escalation procedures for suspicious activity.
- Insufficient record-keeping that prevents effective audits or regulatory responses.
- Assuming AML/CFT obligations never apply because the company is not a financial institution—some commercial activities still attract obligations depending on risk and sector.
Practical examples
These short scenarios illustrate common AML/CFT issues directors should be prepared for.
Example 1: Complex beneficial ownership
A new corporate client is owned through multiple foreign entities and trusts. The company’s onboarding team must identify the ultimate beneficial owner(s) and apply enhanced due diligence before approving transactions. Directors should ensure the company has documented steps to resolve opaque ownership structures.
Example 2: Unusual payment patterns
An account shows frequent high-value transfers to third parties in high-risk jurisdictions inconsistent with the customer’s business profile. Staff should escalate this for review and consider submitting an STR to STRO if suspicions are not resolved.
Example 3: Politically exposed person (PEP)
A proposed client is identified as a PEP. The company must carry out enhanced checks, obtain senior management approval and closely monitor future transactions for unusual activity.
How a corporate secretary can help
A corporate secretary or an external corporate services provider can support directors by:
- Helping to document governance frameworks and board oversight processes in line with Companies Act expectations.
- Advising on the corporate aspects of beneficial ownership and filing requirements with ACRA through BizFile+.
- Assisting with policy templates, board minutes, director resolutions and training records to demonstrate governance and oversight.
- Providing practical support with regulatory filings, accounting, payroll and tax matters where AML/CFT processes intersect with other compliance obligations—Raffles Corporate Services can help with filings, compliance, accounting, tax and payroll support.
Frequently Asked Questions
Do all companies in Singapore need an AML/CFT policy?
Not all companies are regulated by MAS as financial institutions, but all directors should consider whether their business activities create AML/CFT risks. If the company deals with high-risk customers, cross-border funds, or is a designated reporting entity, an AML/CFT policy is necessary. Directors should review sector guidance and obtain tailored advice.
How long should AML/CFT records be retained?
Record-retention periods can vary, but common practice under MAS guidance is to retain records for at least five years from the end of the business relationship. Directors should ensure retention policies meet sector-specific requirements and are consistently applied.
Who should submit an STR and to whom?
Trained staff or the company’s compliance officer should prepare suspicious transaction reports for submission to STRO when there are reasonable grounds for suspicion. Directors should ensure clear internal reporting lines and that STR submission is timely and documented.
Key takeaways
- Directors must oversee proportionate AML/CFT measures tailored to their company’s risk profile.
- Conduct regular risk assessments, implement clear CDD procedures and keep complete records.
- Appoint a compliance officer, maintain training programmes and ensure prompt STRs to STRO where required.
- Failure to maintain adequate controls can result in regulatory action and reputational damage.
- Raffles Corporate Services can assist with governance documentation, filings, and practical compliance support.
Call to action
If you would like to find out more about how Raffles Corporate Services can assist with your company’s compliance and corporate secretarial requirements, please get in touch with the team at [email protected].
Yours sincerely,
The editorial team at Raffles Corporate Services
Requirements may change, so always check the latest guidance from ACRA, IRAS or MOM, or consult a professional adviser.
Disclaimer: This does not constitute legal advice. If you require legal advice, please contact a lawyer.
