Maintaining the Register of Controllers: ACRA Requirements and Practical Tips

A professionally composed photo of a corporate secretary at a desk reviewing a statutory register with a Singapore skyli
Published on: 15 May, 2026

Introduction

Maintaining an accurate Register of Controllers is a core compliance obligation for companies in Singapore. This article explains what a Register of Controllers is, summarises ACRA and Companies Act requirements, and gives practical steps for maintaining the register.

Maintaining the Register of Controllers: ACRA Requirements and Practical Tips addresses common questions companies face and how to avoid pitfalls. The guidance below is general in nature — please contact Raffles Corporate Services for tailored support with filings, compliance, accounting, tax and payroll.

Who this applies to

This guidance applies to limited companies and other entities required under the Companies Act to keep a Register of Controllers. It is particularly relevant to:

  • Directors and company officers responsible for statutory registers;
  • Company secretaries and in-house compliance teams;
  • Newly incorporated companies and companies with changes in ownership or control;
  • Service providers performing KYC, accounting and AML/CFT checks.

Key rules and requirements in Singapore

The Companies Act requires companies to identify and keep records of people who have significant control or influence. The Register of Controllers (sometimes called the register of registrable controllers) is an internal statutory register that documents these individuals and entities.

  • A registrable controller is generally someone who: holds a substantial interest (for example, by shareholding or voting power), has the right to appoint or remove a majority of directors, or otherwise exercises significant influence or control as defined in the Companies Act.
  • The register must contain prescribed particulars, such as name, national identification or passport number, nationality, date on which the person became a controller, and the nature and extent of control.
  • Companies must take reasonable steps to identify controllers. This includes issuing notices to persons who appear to be controllers to obtain required information and evidence.
  • The Register of Controllers is not a public document. However, regulators (including ACRA and other authorised bodies) have rights to access the register. Companies may need to produce the register during regulatory reviews, bank account opening processes or AML/CFT checks.
  • Personal data in the register is subject to the Personal Data Protection Act (PDPA). Companies must handle this information securely and for legitimate purposes only.
  • Non-compliance can lead to penalties and difficulties with banking, licensing or regulatory approvals.

Step-by-step process

Follow these practical steps to create and maintain a compliant Register of Controllers in Singapore.

  • 1. Establish responsibility: Assign responsibility to the company secretary or a named officer to maintain the register and manage communications.
  • 2. Identify potential controllers: Review the share register, constitutional documents, shareholder agreements, trusts and contractual arrangements to identify individuals or entities with significant control or influence (eg. substantial shareholding, appointment rights).
  • 3. Issue formal notices: Where a person is believed to be a controller, issue a written notice requesting prescribed information and supporting documents. Keep records of all correspondence.
  • 4. Record prescribed particulars: Once a controller is identified, enter the required particulars into the register — name, identification number, nationality, residential or business address, nature of control and date of entry.
  • 5. Securely store the register: Keep the register at the registered office or another authorised location (eg. the corporate secretary’s address). Ensure access controls and PDPA safeguards are in place.
  • 6. Update promptly: Monitor changes in ownership and control and update the register without undue delay. Record the date of any change and retain historical entries as required by law.
  • 7. Make the register available to authorised parties: Be prepared to produce the register to ACRA, law enforcement or other authorised agencies on request. Have processes for responding to bona fide requests from banks and regulators.
  • 8. Retain records: Keep correspondence, notices issued, evidence collected and past register entries for the statutory retention period and for audit purposes.

Common mistakes to avoid

  • Assuming shareholders listed on the share register are the only controllers — indirect control through arrangements, trusts or nominee arrangements must be examined.
  • Failing to issue a formal notice or to retain evidence showing reasonable steps were taken to identify controllers.
  • Keeping the register in an insecure manner or sharing personal data without PDPA-compliant safeguards.
  • Delaying updates after ownership or governance changes — prompt updates reduce regulatory and commercial risk.
  • Confusing public filing obligations with the internal register — the register is generally not published on ACRA’s BizFile+ portal, though other company particulars may still require filing via BizFile+ when applicable.

Practical examples

Two brief scenarios illustrate how to approach common situations when maintaining a Register of Controllers.

  • Example 1 — Shareholding change: A private company issues new shares and an individual’s stake increases to a level that may give significant influence. The company secretary issues a notice to confirm controller status, records the particulars, and updates the register with the effective date of change.
  • Example 2 — Trust arrangement: A family trust holds shares in the company. The trustee appears on the share register but the settlor or beneficiaries exercise effective control. The company evaluates the arrangement, issues notices where appropriate, and records the person(s) who ultimately exercise control with supporting documentation.

How a corporate secretary can help

A corporate secretary plays a central role in ensuring the Register of Controllers is accurate and compliant.

  • Identifying potential controllers through document reviews and KYC checks.
  • Drafting and issuing statutory notices to obtain required information and evidence.
  • Maintaining the register, securing personal data and updating records after changes.
  • Co-ordinating responses to regulator or bank requests, and assisting with AML/CFT and PDPA compliance.
  • Advising on practical implications for corporate governance, filings via ACRA BizFile+ and interactions with other compliance functions (eg. accounting, tax and payroll).

Raffles Corporate Services can assist with preparing the register, issuing notices, and ongoing compliance support, including accounting and payroll coordination.

Frequently Asked Questions

Who exactly counts as a registrable controller?

A registrable controller is someone who has significant control or influence over the company. This typically includes persons holding substantial share or voting rights, those with the right to appoint or remove a majority of directors, or those who otherwise exercise significant influence — including through trusts or contractual arrangements. Check the Companies Act for the precise definitions.

Is the Register of Controllers publicly available?

No. The register is not generally open to the public. However, authorised regulatory bodies (such as ACRA and other competent authorities) may request access. Companies should also be prepared to produce the register to banks and other authorised parties for legitimate compliance reasons.

What if a person refuses to provide information?

If a person appears to be a controller but refuses to provide the requested information, the company must document the steps taken to obtain the information. There are statutory remedies available under the Companies Act for persistent non-cooperation; consult a professional adviser for specific actions.

How does PDPA affect the register?

Personal data in the register is subject to the PDPA. Companies must collect, use and disclose personal data lawfully and protect it with appropriate security measures. Keep data only for legitimate purposes and retain records for the required periods.

Key takeaways

  • Maintain an accurate Register of Controllers to meet Companies Act and ACRA expectations.
  • Identify controllers through share registers, governance documents and KYC checks; issue statutory notices where needed.
  • Keep prescribed particulars, secure the register under PDPA, and update promptly after changes.
  • Prepare to produce the register to ACRA, banks and authorised parties; poor record-keeping can hinder banking and regulatory processes.
  • A corporate secretary can manage notices, updates and secure storage, and co‑ordinate with accounting, tax and payroll functions.

If you would like to find out more about how Raffles Corporate Services can assist with your company’s compliance and corporate secretarial requirements, please get in touch with the team at [email protected].

Yours sincerely,
The editorial team at Raffles Corporate Services

Requirements may change, so always check the latest guidance from ACRA, IRAS or MOM, or consult a professional adviser.

Disclaimer: This does not constitute legal advice. If you require legal advice, please contact a lawyer.