Anti-money laundering (AML) compliance is not just a concern for banks and financial institutions. Singapore companies across all sectors face obligations under the Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act (CDSA) and sector-specific regulations to detect, prevent, and report suspicious transactions. Non-compliance can result in criminal prosecution, substantial fines, and reputational damage.
This guide explains what AML compliance means for Singapore companies in 2026, which obligations apply, and the practical steps your business should take.
The AML Framework in Singapore
Singapore’s AML regime is built on a foundation of legislation and regulatory guidelines enforced by multiple authorities:
- Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act (CDSA): Criminalises money laundering and requires all persons (not just financial institutions) to file Suspicious Transaction Reports (STRs).
- Terrorism (Suppression of Financing) Act (TSOFA): Addresses terrorist financing, which is treated alongside money laundering in most compliance frameworks.
- MAS Notice and Guidelines: Financial institutions and regulated entities receive sector-specific AML/CFT (Counter-Financing of Terrorism) requirements from the Monetary Authority of Singapore.
- Financial Action Task Force (FATF) Standards: Singapore aligns its AML framework with FATF’s 40 Recommendations, contributing to its “largely compliant” FATF ratings.
- Corporate Service Providers (CSPs): Regulated under the Singapore Accounting and Corporate Regulatory Authority (ACRA), CSPs must comply with AML/CFT guidelines under the Accounting and Corporate Regulatory Authority Act.
Who Must Comply with AML Obligations?
All Singapore Companies
Under the CDSA, every person in Singapore — including all companies and their officers — has a duty to file a Suspicious Transaction Report (STR) with the Suspicious Transaction Reporting Office (STRO) if they know or have reasonable grounds to suspect that a transaction involves the proceeds of a criminal offence. This obligation applies regardless of industry sector.
Regulated Sectors with Enhanced Obligations
Certain sectors face more detailed AML/CFT requirements, including formal Customer Due Diligence (CDD), record-keeping, and internal controls:
- Financial institutions (banks, capital market intermediaries, payment service providers)
- Corporate service providers and registered filing agents
- Precious metals and stones dealers (regulated under the Precious Stones and Precious Metals (Prevention of Money Laundering and Terrorism Financing) Act)
- Legal professionals and accountants (subject to professional body guidelines)
- Real estate agents
- Moneylenders
Key AML Obligations for Singapore Companies
1. Suspicious Transaction Reporting (STR)
Any company that encounters a transaction where it knows or suspects the funds involved are proceeds of crime must file an STR with STRO at the Commercial Affairs Department (CAD) of the Singapore Police Force. Key points:
- The obligation applies as soon as reasonable grounds for suspicion exist
- Tipping off — alerting the subject that an STR has been filed — is itself a criminal offence
- There is no minimum transaction amount threshold for filing
- Protection from civil or criminal liability is available to good-faith STR filers
2. Know Your Customer (KYC) and Customer Due Diligence (CDD)
For regulated sectors, formal CDD processes must be in place before establishing a business relationship or conducting a transaction. CDD involves:
- Identity verification: Confirming the identity of customers and beneficial owners using reliable, independent documents
- Beneficial ownership: Identifying natural persons who ultimately own or control a company (typically those with 25% or more ownership or voting rights)
- Purpose and nature: Understanding the purpose of the business relationship and expected transaction patterns
- Ongoing monitoring: Reviewing customer accounts and transactions continuously for unusual activity
Enhanced Due Diligence (EDD) is required for higher-risk customers, including Politically Exposed Persons (PEPs) and customers from high-risk jurisdictions identified by FATF.
3. Record-Keeping Requirements
Companies in regulated sectors must retain CDD documents and transaction records for a minimum of five years. These records must be made available to authorities upon request. The five-year period generally runs from the end of the business relationship or the date of the transaction.
4. Internal Controls and Compliance Programme
Regulated entities are required to implement an AML/CFT compliance programme that includes:
- Appointment of a Compliance Officer or Money Laundering Reporting Officer (MLRO)
- Written AML/CFT policies and procedures
- Regular staff training on AML obligations and red flags
- An internal STR reporting mechanism (staff must be able to report suspicions to the MLRO)
- Independent audits or reviews of the AML/CFT programme
Register of Registrable Controllers (RORC)
Since 31 March 2017, all Singapore companies and LLPs are required to maintain a Register of Registrable Controllers (RORC). The RORC records the details of individuals and legal entities that have significant interest or significant control over the company.
Key obligations:
- Maintain the RORC and update it within two business days of any change
- Lodge the RORC with ACRA (the register is not public-facing but is accessible to public authorities)
- Retain RORC records for five years after a controller ceases to be a controller
The RORC requirement supports Singapore’s beneficial ownership transparency efforts, aligned with FATF recommendations. Failure to maintain the RORC or lodge it with ACRA is an offence under the Companies Act.
Red Flags: Transactions That Should Raise Concerns
Singapore companies should be alert to the following indicators of potential money laundering:
- Customers who are reluctant to provide identification or beneficial ownership information
- Transactions that are inconsistent with the customer’s stated business activity
- Large cash payments or frequent high-value transactions with no clear commercial rationale
- Customers with addresses or transactions linked to high-risk or sanctioned jurisdictions
- Complex corporate structures with multiple layers of ownership across different jurisdictions
- Requests to pay or receive funds through third parties not directly involved in the transaction
- Customers who change transaction instructions at the last moment without explanation
- Transactions that are split into smaller amounts to avoid reporting thresholds
Penalties for AML Non-Compliance
The consequences of AML non-compliance in Singapore are severe:
- Failure to file an STR (CDSA offence): Fine of up to S$250,000 and/or imprisonment of up to 3 years
- Tipping off: Fine of up to S$30,000 and/or imprisonment of up to 3 years
- Assisting money laundering (CDSA): Fine up to S$500,000 and/or imprisonment up to 10 years
- Regulatory breaches (regulated sectors): MAS or ACRA may impose directions, restrictions, financial penalties, or revoke licences/registrations
Directors and officers of companies may also face personal liability for AML offences committed by the company.
Practical Steps: Building AML Compliance for Your Singapore Company
Whether or not your company operates in a regulated sector, here are the essential steps to build a defensible AML posture:
- Conduct a risk assessment: Identify the money laundering risks specific to your industry, customer base, and transaction types.
- Implement KYC procedures: Verify the identity and beneficial ownership of customers and counterparties before transacting.
- Maintain your RORC: Keep the Register of Registrable Controllers current and lodge it with ACRA.
- Train your team: Ensure all staff understand the duty to report suspicious transactions and can identify AML red flags.
- Designate an MLRO: Appoint a responsible officer to receive internal STR disclosures and make STR filings.
- Document everything: Retain CDD records and transaction documentation for at least five years.
- Review and update regularly: AML risks evolve; review your policies annually or when your business model changes.
How Raffles Corporate Services Can Help
Raffles Corporate Services assists Singapore companies with AML compliance, including:
- Setting up and maintaining the Register of Registrable Controllers (RORC)
- Advising on KYC and CDD procedures appropriate to your business
- Drafting AML/CFT policies and internal procedures
- Providing corporate secretarial support to ensure ongoing compliance with ACRA requirements
Our team stays current with ACRA, MAS, and CAD regulatory updates so that your company’s compliance framework remains robust. Contact us to learn how we can support your AML compliance needs.
