Singapore AML Compliance — MAS AML/CFT Notice, PSA & KYC
We hold compliance with the MAS AML/CFT Notices, PSA requirements and KYC for Singapore-incorporated entities. We set up the program, document the procedures and run corporate governance.
What Compliance & AML includes in Singapore
What you receive
How it works
Where to register and how we differ
Compliance & AML in Singapore — frequently asked questions
Singapore's AML/CFT framework rests on the Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act (CDSA) and the Terrorism (Suppression of Financing) Act. The Monetary Authority of Singapore (MAS) supervises financial institutions; Corporate Service Providers, accountants, and other Designated Non-Financial Businesses and Professions (DNFBPs) fall under sector regulators such as ACRA and ISCA. Obligations: customer due diligence (CDD), beneficial-ownership identification, ongoing transaction monitoring, and filing Suspicious Transaction Reports (STRs) with the Suspicious Transaction Reporting Office (STRO) via the SONAR system. We build the programme around your profile.
AML/CFT supervision in Singapore is split across regulators. MAS supervises banks, payment institutions, capital markets entities, and digital token service providers, issuing binding Notices (such as MAS Notice 626 for banks). ACRA regulates Corporate Service Providers and company secretaries. The Suspicious Transaction Reporting Office (STRO) — Singapore's financial intelligence unit, housed in the Police Force's Commercial Affairs Department (CAD) — receives every STR. Singapore is a founding member of the FATF and was rated largely compliant at its most recent mutual evaluation.
Yes. Since 2017, a Singapore company must keep a Register of Registrable Controllers (RORC) identifying individuals with significant control or ownership — generally 25% or more of shares or voting rights. The RORC sits at the registered office or with a Corporate Service Provider, and the data is also filed with ACRA's central register. Nominee directors and shareholders must disclose their nominee status. Fail to keep it accurate, and it's an offence under the Companies Act.
An STR is a mandatory report filed when a person knows or has reasonable grounds to suspect that property is connected to criminal conduct or terrorism financing. Under the CDSA, it must reach the STRO as soon as reasonably practicable, through the online SONAR portal. The duty falls on everyone, not only regulated entities, and 'tipping off' the subject of a report is a separate criminal offence. INNOVA prepares STR documentation and holds the filing threshold for DNFBP clients.
Penalties are among the most stringent in Asia. Failing to file an STR under the CDSA can bring a fine of up to S$250,000 and/or imprisonment. MAS has imposed composition and financial penalties running into the tens of millions of dollars on financial institutions for AML control failures. ACRA strips Corporate Service Providers of their licence. Directors are personally liable for systemic compliance failures. So a documented AML programme is not optional.
