Surprising fact: banks and firms flag up to 30% of high-risk profiles during onboarding, showing how much is at stake before a single transaction takes place.
Customer due diligence (CDD) is the practical process of collecting, recording and verifying identity details to assess money laundering and terrorism financing risks.
This guide is written for regulated firms and local teams who must apply CDD as part of AML compliance. It moves from concept to clear steps so staff can act with confidence.
Core idea: CDD is completed before you transact and is a risk-management workflow, not a tick-box exercise. Where higher ML/TF risks appear, Enhanced CDD measures are expected.
By the end you will know what information to collect, how to verify identity, when to escalate checks, and how to keep records and report via STRO/SONAR. The guide flags common pain points: timing, documentation, screening and beneficial ownership.
Key Takeaways
- CDD is a pre-transaction risk process that supports AML compliance.
- Collect and verify identity information, and document verification steps.
- Escalate to enhanced checks when higher ML/TF risks are detected.
- Focus on timing, screening, beneficial ownership and record-keeping.
- Use local reporting channels such as STRO/SONAR for suspected incidents.
Customer due diligence in Singapore: purpose, scope and key concepts
A robust onboarding process is the first line of defence against laundering and financing terrorism.
How CDD helps manage money laundering and terrorism financing risks
Customer due diligence acts as a frontline control that identifies who a person is, why they transact, and whether the activity fits their profile.
By checking identity, verifying documents and assessing risk, teams can block attempts at money laundering and terrorism financing before value moves through an account.
CDD versus Enhanced Customer Due Diligence: when extra measures apply
Standard CDD covers most relationships. Enhanced checks are required when red flags appear: unusual transaction patterns, opaque ownership, or high-risk jurisdictions.
Extra measures include deeper source-of-funds checks, senior approval, and more frequent monitoring.
| Aspect | Standard CDD | Enhanced CDD |
|---|---|---|
| Trigger | Normal onboarding | High-risk profile or transaction |
| Verification | Reliable ID and documents | Independent proof and source checks |
| Controls | Periodic monitoring | Frequent review, senior sign-off |
| Escalation | Record and monitor | Internal review and file STR or alert relevant AML team |
Suspicion differs from proof; where ML, terrorism or proliferation activities are suspected, escalate promptly.
Customer due diligence requirements singapore business must follow in practice
Begin CDD as early as first contact and treat it as a gated control before any legal step proceeds.
When checks must be completed
Complete all checks before any agreement or transaction. For property and other high-risk sectors this means finishing verification before a client signs an acquisition or disposal contract.
Date forms and keep a written acknowledgement that the facts provided are accurate.
Information to collect and how to record it
Capture clear identity data, contact details and a short profile explaining the purpose and expected transactions. For entities, retain incorporation documents and an up-to-date company extract.
Verification standards
Verify identity with reliable, independent sources — NRIC or passport checks, ACRA records for companies. Record what you checked and keep copies of documents and verification steps as evidence.
Entity checks, ownership and beneficial parties
Confirm legal existence with an up-to-date ACRA profile and map ownership and control. Identify beneficial owners and conduct checks on any person who ultimately controls the company.
Mandatory screening and escalation
Screen all relevant parties for PEP status and for designated or terrorist listings. If checks cannot be completed, do not proceed with the transaction and consider filing an STR. If there is a terrorism or designated-person concern, stop activity and report to the police.
| Step | Action | Evidence | When |
|---|---|---|---|
| Initiate | Collect ID, contact, purpose | Signed intake form | At first contact |
| Verify | Check NRIC/passport, ACRA | Copies and check log | Before agreement |
| Screen | PEP and sanctions lists | Screening report | Prior to transaction |
| Escalate | Stop, consider STR, notify police if designated | Escalation notes and report | If checks fail or flag |
Note: Performing checks only after contracts are signed or processing transactions is non-compliant and increases regulatory risk.
Ongoing compliance duties: reporting, record-keeping and non-face-to-face CDD controls
Maintaining vigilance after account opening is essential: monitor transactions, report concerns and keep thorough records. This is the second half of effective cdd — continuous checks that stop laundering and terrorism financing risks as activity unfolds.
Cash Transaction Reports (CTR) apply when cash or cash equivalents hit the S$20,000 threshold. Single payments, or multiple same-day sales, purchases or redemptions that aggregate above this amount must be reported. Designated transactions include sales, second‑hand dealer purchases and token redemptions.
Filing workflow: obtain a SONAR account and e-file the CTR to STRO within 15 business days. Retain a copy of the filed report for five years as part of your record-keeping obligations. See the MAS notice on AML updates for related guidance.
Suspicious transaction (STR) playbook: watch for inconsistent source-of-money stories, unexplained urgency, third‑party activity and unusual structuring. File an STR via SONAR promptly. Handle reports on a need‑to‑know basis and keep all communications neutral to avoid tipping off — an offence under the CDSA.
Keep screening current by subscribing to MAS and MHA watchlist updates. For non-face-to-face onboarding, follow MAS guidance: strengthen identity proofing, enforce tech controls and secure document handling to reduce remote onboarding risk.
Conclusion
The simplest safeguard is to stop activity until identity, ownership and screening are complete and recorded.
In practice, complete checks early, keep clear evidence of identity and profiling, and apply a risk-based approach that escalates to enhanced measures when necessary. A minimum defensible CDD file holds verified ID, a short profile of purpose, ownership maps for any company, and screening results.
Remember CTRs for cash or cash equivalents over S$20,000 in designated transactions and file CTRs and STRs electronically via SONAR to STRO, keeping CTR records for five years. For guidance on source-of-wealth assessments see source of wealth guidance, and check your terms and conditions to align controls.
Act now: review processes, train staff on red flags, and ensure governance so CDD is consistent across every client, company and transaction for long‑term success.
FAQ
What is the purpose and scope of customer due diligence in Singapore?
How does CDD help manage money laundering and terrorism financing risks?
What triggers enhanced measures under Enhanced Customer Due Diligence?
When must CDD be completed before transacting or signing agreements?
What information should be collected about identity, profile and transaction purpose?
What are acceptable verification standards and how should evidence be kept?
How do you verify entity customers and understand ownership and control?
How are beneficial owners and agents identified when others act on behalf of a customer?
What mandatory screening must be performed for PEPs and designated persons?
What steps should be taken if CDD cannot be completed?
When must Cash Transaction Reports be filed and what constitutes a designated transaction?
How is the CTR submission process handled and how long must records be retained?
What are common red flags prompting a Suspicious Transaction Report?
How should firms avoid “tipping off” when filing STRs?
How can organisations stay current with watchlists and designated person updates?
What are MAS good practices for non-face-to-face onboarding and technology-enabled checks?

Dean Cheong is a Singapore-based commercial growth architect and CEO of VOffice, known for helping B2B companies turn fragmented sales efforts into predictable revenue systems. He specializes in sales process optimisation, CRM-driven visibility, and market entry strategy, combining execution discipline with a strong academic grounding in business banking and finance from Nanyang Technological University. His focus is on building repeatable, data-backed growth frameworks that companies can scale with confidence.