Corporate Service Providers Act 2024 compliance — Documents required and templates
Corporate service providers act 2024 compliance means every firm that incorporates companies, files with ACRA or acts as a nominee must register with the Registrar, appoint a fit-and-proper compliance officer and keep a documented anti-money-laundering programme. This guide sets out the documents, templates and timelines Singapore providers and their clients now need.
Raffles Corporate Services works with a panel of corporate and employment law firms; this article is general information, not legal advice.
What the Corporate Service Providers Act 2024 changes
The Corporate Service Providers Act 2024 replaced the older registered filing agent regime with a single, licence-style registration administered by the Accounting and Corporate Regulatory Authority (ACRA). It brings every corporate service provider, whether a large firm or a sole practitioner, under one supervised framework, with direct penalties for the provider and, in some cases, for named senior managers personally.
The Act also tightens the rules around nominee directors. A provider that arranges a nominee director must satisfy itself that the nominee is fit and proper and must keep records showing who ultimately controls the company. This sits alongside the long-standing duty in Section 157A(1) of the Companies Act 1967, under which the business of a company is managed by, or under the direction of, its directors, so a nominee cannot simply be a name on a form.
Who must register and comply
Registration is required of any person who, by way of business, carries out corporate services such as forming companies, filing transactions with the Registrar, providing a registered office, or arranging for a person to act as director or shareholder. Accounting firms, law practices and secretarial houses that offer these services all fall within scope. If your firm touches BizFile+ on behalf of clients for a fee, assume you are in scope and register.
Documents required — the core compliance file
Providers should maintain a single compliance file that an ACRA inspector could read end to end. In practice it contains: the registration confirmation and any conditions; the appointment letter for the compliance officer; the firm’s written AML/CFT policy; the customer due diligence (CDD) records for each client, including identity documents and beneficial-ownership declarations; ongoing screening logs against sanctions and politically-exposed-person lists; and the suspicious-transaction-report register. For nominee arrangements, add the nominee consent, the indemnity, and the record of the true controller.
Client-side, the register of registrable controllers is now a routine request. Providers should hold a completed controller declaration for each entity, cross-checked against the ownership chain. Part XIA of the Companies Act 1967 establishes the obligation to keep this register of registrable controllers, and the CSP framework expects the provider to have verified it rather than merely collected it.
Templates worth standardising
Firms save the most time by standardising five templates: a CDD intake form, a beneficial-ownership declaration, a nominee-director consent and indemnity, a risk-assessment worksheet (low / medium / high with the reason recorded), and an annual compliance-review checklist. Each template should have a version number and a date so that you can prove which version was in force when a file was opened.
Cost and timeline
Budget realistically. First-time registration typically runs to a few hundred Singapore dollars in ACRA fees, but the larger cost is internal: expect roughly two to four weeks to write or refresh the AML/CFT policy, train staff and clean up legacy client files. Ongoing, a small firm should plan for one to two days a month of dedicated compliance time, and an annual independent review that can cost S$2,000 to S$8,000 depending on client numbers and risk profile.
Common mistakes and gotchas
The recurring failures are documentary rather than intentional. Files opened before the new regime are often missing a dated risk assessment. Screening is done once at onboarding and never repeated. Nominee arrangements are papered with a consent but no record of the real controller. And the compliance officer is named on paper but has no evidence of actually reviewing anything. Each of these is easy to fix before an inspection and expensive to explain afterwards. For a plain-English refresher on the controller obligations, see our note on the register of registrable controllers.
How this interacts with company changes and hiring
Corporate service provider compliance rarely sits still, because client companies keep changing. A change of director, a share transfer or a new beneficial owner all trigger fresh due diligence. Our sister guide on a change of director in Singapore walks through the ACRA filing side. Where clients are also hiring foreign talent, the same controller and identity records feed into work-pass applications, so it is worth reading alongside guidance on financial-services sector hiring and Employment Pass planning.
Official sources to check
Read the primary materials rather than summaries: the Singapore statutes on the Singapore Statutes Online portal maintained by the Attorney-General’s Chambers, the registration and filing-agent guidance from the Accounting and Corporate Regulatory Authority, and the anti-money-laundering expectations published by the Monetary Authority of Singapore.
Corporate Service Providers Act 2024 compliance: a practical summary
In short, corporate service providers act 2024 compliance is a documentation discipline: register with ACRA, appoint and empower a compliance officer, keep a current AML/CFT policy, and hold verified due-diligence and controller records for every client and nominee arrangement. Get the file right before an inspection, not after.
FAQs
Does a sole practitioner need to register under the Corporate Service Providers Act 2024? Yes. Scope is defined by activity, not firm size. If you provide corporate services by way of business, you register.
How long must due-diligence records be kept? Plan for at least five years after the business relationship ends, in line with standard AML record-keeping expectations.
Is the register of registrable controllers public? No. It is kept privately by the company and made available to ACRA and specified authorities on request.
Can a nominee director be provided informally? No. The arrangement must be documented, the nominee must be fit and proper, and the true controller must be recorded.
What triggers a fresh customer due-diligence review? Any material change: new owner, new director, change of activity, or a screening hit. Periodic reviews are also expected for higher-risk clients.
Need help with this? Call, SMS or WhatsApp +65 8501 7133, or email [email protected]. Raffles Corporate Services works with a panel of corporate and employment law firms; this article is general information, not legal advice.