Let’s talk

Insights for your business.

NRIC as Authentication: What the 2026 Phase-Out Means for Singapore Company KYC and Onboarding

The NRIC Rule Every Singapore Company Needs to Act On Before 2027

From 31 December 2026, private sector organisations in Singapore, including every ACRA-registered company, must stop using NRIC numbers (or partial NRIC numbers) as an authentication factor. From 1 January 2027, the Personal Data Protection Commission (PDPC) will step up enforcement against organisations that continue to do so, including financial penalties where appropriate. For corporate secretarial practices and the companies they serve, this is not a minor IT housekeeping item. NRIC numbers sit at the centre of how most Singapore companies verify the identity of directors, shareholders and employees during onboarding, and how many internal systems have, for years, quietly used them as a default password, login ID or one-time-password seed.

This article sets out what is actually changing, what is still permitted, and what a company secretary or company director should be reviewing in KYC and onboarding processes before the end of 2026.

What the Rule Actually Prohibits

The prohibition is narrower than the headlines suggest. It targets the use of a full or partial NRIC number as an authentication factor: for example, as a default password, a login credential, a One-Time Password (OTP) seed, or any other mechanism used to verify that someone accessing a system is who they claim to be. It does not prohibit collecting and recording an NRIC number in the first place for identity verification purposes, such as confirming who a new director, shareholder or employee is when they are onboarded. Identity verification (confirming identity) and authentication (proving identity on an ongoing basis to access a system) are treated as legally distinct functions under this framework, and only the second is affected.

In practice, this means a company secretarial firm or in-house HR team can, and still must, collect NRIC numbers as part of standard KYC and onboarding checks under existing Companies Act and anti-money laundering obligations. What has to change is any system that has been using that same NRIC number afterwards as a password, portal login ID, or default PIN.

Where This Shows Up in a Typical Singapore Company’s Onboarding Process

Corporate Secretarial and Company Onboarding Systems

Many corporate services providers, banks and HR platforms historically defaulted new user accounts to a password or PIN derived from an NRIC number, on the assumption that only the individual and the company would know it. This is precisely the practice the new rule targets, because an NRIC number is not actually secret: it appears on many documents an employer, landlord or bank already holds. Companies should audit any client portal, HR system, or CRM that issues default credentials to directors, shareholders or employees and confirm none of them are NRIC-derived.

Director and Shareholder KYC at Incorporation and Annual Review

Collecting a director’s or shareholder’s NRIC (or, for foreigners, passport and FIN) remains a standard and necessary part of incorporation, annual KYC refreshes, and corporate bank account opening, as it always has been. What corporate secretaries should review is whether that same number is then re-used anywhere downstream as a login credential for the client’s self-service portal, e-signing platform, or statutory register access. If it is, that system needs a genuine authentication factor: a proper password policy, multi-factor authentication, a token, or biometrics, none of which should default to or embed the NRIC.

Employee Self-Service and Payroll Systems

Payroll and HR systems are a particularly common offender, since many were configured years ago with an NRIC-based default password for first login. Employers should treat this as part of the same review cycle as their payroll and CPF compliance obligations, since MOM and IRAS both expect payroll systems to hold accurate personal data securely, and a weak or predictable authentication scheme undermines that regardless of the NRIC-specific rule.

What Companies Should Do Before 31 December 2026

Step Action
1. Inventory List every system (portal, HR, CRM, e-signing, banking) that uses NRIC as a login ID, password or OTP seed.
2. Replace Move to a proper authentication factor: strong password policy, MFA, token or biometrics.
3. Update SOPs Revise onboarding checklists and internal procedures so new hires or new client accounts are never issued NRIC-based defaults going forward.
4. Retain KYC collection Continue collecting NRIC/FIN for identity verification at onboarding; this obligation is unaffected.
5. Train staff Make sure HR, finance and front-line staff understand the distinction between identity verification and authentication.

Why This Matters More for Corporate Service Providers

Corporate secretarial firms, accounting firms and employment agencies handle a disproportionate volume of NRIC and FIN data compared with an average SME, because they process onboarding for many client companies at once. A firm that has not reviewed its own client portal, e-signing workflow, or internal case management system risks being an outlier once the phase-out deadline passes and PDPC enforcement begins in January 2027. It is also worth checking any PDPA compliance review your company already has scheduled and folding this specific check into it, rather than treating it as a separate project.

For companies going through a bank account opening or refresh of their corporate bank account documentation, this is also a good moment to ask the bank directly what authentication factors it uses for corporate internet banking access, since banks are subject to the same phase-out.

Frequently Asked Questions

Can we still ask for a copy of an employee’s NRIC when they join?
Yes. Collecting NRIC for identity verification during onboarding is unaffected. The prohibition is on using the NRIC number itself as an ongoing authentication credential.

What is the actual enforcement date?
Organisations have until 31 December 2026 to phase out NRIC-based authentication. From 1 January 2027, PDPC enforcement action, including financial penalties, becomes available against organisations still using it.

Does this apply to government systems like Singpass?
The phase-out is aimed at private sector organisations using NRIC as an authentication factor in their own systems; government-run national digital identity infrastructure such as Singpass operates under its own separate framework.

Do we need to notify PDPC that we have completed the transition?
There is no general notification requirement; the obligation is to have stopped the practice by the deadline and be able to demonstrate this if reviewed.

How Raffles Corporate Services Can Help

We help Singapore companies review their onboarding and KYC workflows, including corporate secretarial, HR and client-facing systems, to identify NRIC-dependent authentication practices and bring them in line with the 2026 phase-out. If your annual compliance review is coming up, this is a natural item to add to the agenda.

This article is for general information only and does not constitute legal advice. For advice specific to your organisation’s systems, please consult the PDPC’s guidance or a qualified data protection adviser.

The Editorial Team, Raffles Corporate Services

Submit a Comment

Your email address will not be published. Required fields are marked *

Real people. Right here in Singapore.

Let’s get to work.

Hop on Raffles Corporate Services