+65 64600199

Surprising fact: banks and firms flag up to 30% of high-risk profiles during onboarding, showing how much is at stake before a single transaction takes place.

Customer due diligence (CDD) is the practical process of collecting, recording and verifying identity details to assess money laundering and terrorism financing risks.

This guide is written for regulated firms and local teams who must apply CDD as part of AML compliance. It moves from concept to clear steps so staff can act with confidence.

Core idea: CDD is completed before you transact and is a risk-management workflow, not a tick-box exercise. Where higher ML/TF risks appear, Enhanced CDD measures are expected.

By the end you will know what information to collect, how to verify identity, when to escalate checks, and how to keep records and report via STRO/SONAR. The guide flags common pain points: timing, documentation, screening and beneficial ownership.

Key Takeaways

  • CDD is a pre-transaction risk process that supports AML compliance.
  • Collect and verify identity information, and document verification steps.
  • Escalate to enhanced checks when higher ML/TF risks are detected.
  • Focus on timing, screening, beneficial ownership and record-keeping.
  • Use local reporting channels such as STRO/SONAR for suspected incidents.

Customer due diligence in Singapore: purpose, scope and key concepts

A robust onboarding process is the first line of defence against laundering and financing terrorism.

How CDD helps manage money laundering and terrorism financing risks

Customer due diligence acts as a frontline control that identifies who a person is, why they transact, and whether the activity fits their profile.

By checking identity, verifying documents and assessing risk, teams can block attempts at money laundering and terrorism financing before value moves through an account.

CDD versus Enhanced Customer Due Diligence: when extra measures apply

Standard CDD covers most relationships. Enhanced checks are required when red flags appear: unusual transaction patterns, opaque ownership, or high-risk jurisdictions.

Extra measures include deeper source-of-funds checks, senior approval, and more frequent monitoring.

Aspect Standard CDD Enhanced CDD
Trigger Normal onboarding High-risk profile or transaction
Verification Reliable ID and documents Independent proof and source checks
Controls Periodic monitoring Frequent review, senior sign-off
Escalation Record and monitor Internal review and file STR or alert relevant AML team

Suspicion differs from proof; where ML, terrorism or proliferation activities are suspected, escalate promptly.

Customer due diligence requirements singapore business must follow in practice

Begin CDD as early as first contact and treat it as a gated control before any legal step proceeds.

When checks must be completed

Complete all checks before any agreement or transaction. For property and other high-risk sectors this means finishing verification before a client signs an acquisition or disposal contract.

Date forms and keep a written acknowledgement that the facts provided are accurate.

Information to collect and how to record it

Capture clear identity data, contact details and a short profile explaining the purpose and expected transactions. For entities, retain incorporation documents and an up-to-date company extract.

Verification standards

Verify identity with reliable, independent sources — NRIC or passport checks, ACRA records for companies. Record what you checked and keep copies of documents and verification steps as evidence.

Entity checks, ownership and beneficial parties

Confirm legal existence with an up-to-date ACRA profile and map ownership and control. Identify beneficial owners and conduct checks on any person who ultimately controls the company.

Mandatory screening and escalation

Screen all relevant parties for PEP status and for designated or terrorist listings. If checks cannot be completed, do not proceed with the transaction and consider filing an STR. If there is a terrorism or designated-person concern, stop activity and report to the police.

Step Action Evidence When
Initiate Collect ID, contact, purpose Signed intake form At first contact
Verify Check NRIC/passport, ACRA Copies and check log Before agreement
Screen PEP and sanctions lists Screening report Prior to transaction
Escalate Stop, consider STR, notify police if designated Escalation notes and report If checks fail or flag

Note: Performing checks only after contracts are signed or processing transactions is non-compliant and increases regulatory risk.

Ongoing compliance duties: reporting, record-keeping and non-face-to-face CDD controls

Maintaining vigilance after account opening is essential: monitor transactions, report concerns and keep thorough records. This is the second half of effective cdd — continuous checks that stop laundering and terrorism financing risks as activity unfolds.

Cash Transaction Reports (CTR) apply when cash or cash equivalents hit the S$20,000 threshold. Single payments, or multiple same-day sales, purchases or redemptions that aggregate above this amount must be reported. Designated transactions include sales, second‑hand dealer purchases and token redemptions.

Filing workflow: obtain a SONAR account and e-file the CTR to STRO within 15 business days. Retain a copy of the filed report for five years as part of your record-keeping obligations. See the MAS notice on AML updates for related guidance.

Suspicious transaction (STR) playbook: watch for inconsistent source-of-money stories, unexplained urgency, third‑party activity and unusual structuring. File an STR via SONAR promptly. Handle reports on a need‑to‑know basis and keep all communications neutral to avoid tipping off — an offence under the CDSA.

Keep screening current by subscribing to MAS and MHA watchlist updates. For non-face-to-face onboarding, follow MAS guidance: strengthen identity proofing, enforce tech controls and secure document handling to reduce remote onboarding risk.

Conclusion

The simplest safeguard is to stop activity until identity, ownership and screening are complete and recorded.

In practice, complete checks early, keep clear evidence of identity and profiling, and apply a risk-based approach that escalates to enhanced measures when necessary. A minimum defensible CDD file holds verified ID, a short profile of purpose, ownership maps for any company, and screening results.

Remember CTRs for cash or cash equivalents over S$20,000 in designated transactions and file CTRs and STRs electronically via SONAR to STRO, keeping CTR records for five years. For guidance on source-of-wealth assessments see source of wealth guidance, and check your terms and conditions to align controls.

Act now: review processes, train staff on red flags, and ensure governance so CDD is consistent across every client, company and transaction for long‑term success.

FAQ

What is the purpose and scope of customer due diligence in Singapore?

The aim is to reduce the risk of money laundering, terrorism financing and proliferation financing by verifying identities, understanding customer profiles and monitoring transactions. It applies to financial institutions, remittance firms, casinos, and other regulated entities under the Monetary Authority of Singapore (MAS) rules and the Terrorism (Suppression of Financing) Act.

How does CDD help manage money laundering and terrorism financing risks?

CDD ensures firms know who they are dealing with, the source of funds and the intended use of services. By collecting identity documents, assessing risk and conducting ongoing monitoring, organisations can detect suspicious activity early and file Suspicious Transaction Reports (STRs) to the Suspicious Transaction Reporting Office (STRO).

What triggers enhanced measures under Enhanced Customer Due Diligence?

Enhanced measures apply where risk is higher — for example, politically exposed persons (PEPs), complex ownership structures, high-value or unusual transactions, and jurisdictions with weak AML/CFT controls. Enhanced checks include deeper verification, senior approval and increased transaction monitoring.

When must CDD be completed before transacting or signing agreements?

CDD should be done prior to establishing a business relationship, executing significant transactions or when doubt arises about previously obtained information. Firms should not proceed if they cannot satisfactorily verify identity or understand the purpose of the relationship.

What information should be collected about identity, profile and transaction purpose?

Collect full name, identification number, date of birth, residential address, contact details, source of funds, nature of business, expected transaction activity and the purpose of the account or service. For legal persons, collect incorporation details, constitutive documents and details of directors.

What are acceptable verification standards and how should evidence be kept?

Use reliable, independent sources such as government ID, passport, corporate registries and bank references. Maintain copies or records of documents, electronic verification logs and the rationale for risk assessments. Retain records for the statutory period and ensure secure storage for audits.

How do you verify entity customers and understand ownership and control?

Confirm legal existence through official registries and review constitutive documents, shareholder registers and board minutes. Map the ownership and control chain to identify individuals with significant control, including beneficial owners with a direct or indirect stake above the applicable threshold.

How are beneficial owners and agents identified when others act on behalf of a customer?

Identify natural persons who ultimately own or control the legal entity, and those authorised to act on its behalf. Request proof of authority such as powers of attorney, corporate resolutions and ID documents of authorised signatories. Apply enhanced scrutiny where ownership is obscured.

What mandatory screening must be performed for PEPs and designated persons?

Screen all clients against MAS and Ministry of Home Affairs (MHA) watchlists, United Nations and other international sanctions, and maintain up-to-date lists for designated persons and entities. Apply enhanced monitoring, senior management approval and consider declining or terminating the relationship where risks are unacceptable.

What steps should be taken if CDD cannot be completed?

If verification fails, refuse to open the account or suspend transactions, escalate to compliance and consider filing an STR. Document the reasons for inability to complete checks and follow internal escalation and reporting protocols to STRO where required.

When must Cash Transaction Reports be filed and what constitutes a designated transaction?

File a Cash Transaction Report for transactions in Singapore dollars or foreign currency equal to or above S,000, whether a single or linked series. Designated transactions include cash deposits, withdrawals and exchanges that meet the threshold within regulated sectors.

How is the CTR submission process handled and how long must records be retained?

CTRs and STRs are filed electronically to STRO via the SONAR platform. Regulated entities must retain supporting records, transaction logs and reporting evidence for at least five years from the date of the transaction or termination of the relationship.

What are common red flags prompting a Suspicious Transaction Report?

Red flags include rapid movement of funds through multiple accounts, inconsistent source-of-funds explanations, use of shell companies, frequent transactions just below reporting thresholds and clients reluctant to provide documentation. Report promptly via SONAR when suspicion arises.

How should firms avoid “tipping off” when filing STRs?

Do not disclose to the subject of the report that a suspicion has been raised or that an STR has been filed. Limit internal disclosure to staff with a legitimate need to know and follow legal protections under Singapore law to prevent compromising investigations.

How can organisations stay current with watchlists and designated person updates?

Subscribe to MAS and MHA circulars, UN sanctions updates and international watchlists. Use screening software with automated refreshes and audit trails, and conduct periodic manual reviews to capture changes to lists or a client’s risk profile.

What are MAS good practices for non-face-to-face onboarding and technology-enabled checks?

Employ strong electronic identity verification, biometric checks, multi-factor authentication and transaction monitoring tailored to digital channels. Implement risk-based thresholds, enhanced controls for remote onboarding and periodic re-verification where reliance is placed on digital methods.