View .md

CDD Checklist for Corporate Service Providers (Singapore, 2026)

A practical customer due diligence checklist for registered Singapore CSPs — identify and verify the customer and beneficial owners, understand the relationship, screen, and monitor.

By The CorpSec AI Compliance Team, Singapore corporate secretarial & compliance·Updated 2026-07-11

What is customer due diligence (CDD) for a CSP?

Customer due diligence is the set of checks a CSP performs to know who its customer is, who ultimately owns or controls that customer, and why the relationship exists — before providing a service and continuously afterwards. It is the foundation of a CSP’s AML/CFT programme under the Corporate Service Providers Act 2024.

CDD is not a single onboarding form. It is a lifecycle: identify and verify at the start, screen, judge risk, keep the evidence, and refresh the picture as the relationship and the client’s risk profile change.

When must a CSP perform CDD?

A CSP must perform CDD before or while establishing a business relationship, and again when there is a material change, a suspicion of money laundering or terrorism financing, or doubt about the reliability of information previously obtained.

In practice that means CDD is triggered at onboarding, before acting on a new instruction that changes the risk picture (for example a change of ownership or a new corporate structure), and on a periodic, risk-sensitive cycle for existing clients.

What is the core CDD checklist for a CSP?

At a minimum, standard CDD covers four pillars — identify the customer, identify the beneficial owners, understand the relationship, and monitor it. The checklist below sets out what each pillar means in practice.

CDD pillarWhat the CSP must do
Identify & verify the customerCollect and verify identity details of the customer (and the natural persons acting for it) using reliable, independent source documents or data.
Identify beneficial ownersDetermine the natural persons who ultimately own or control the customer, and take reasonable measures to verify their identity.
Understand the relationshipEstablish the purpose and intended nature of the business relationship and the customer’s ownership and control structure.
ScreenScreen the customer and beneficial owners against sanctions lists and watchlists (including UN and Singapore-designated lists), and check for PEP and adverse-media matches.
Ongoing monitoringKeep the CDD information current and scrutinise activity for consistency with what the CSP knows about the client.
Record-keepingRetain CDD and transaction records for at least five years.

How does a CSP identify the beneficial owners?

A beneficial owner is the natural person who ultimately owns or controls the customer, or on whose behalf a transaction is conducted. For a company that usually means tracing the ownership chain to the individuals holding a controlling interest, and identifying anyone who exercises control by other means.

The CSP must take reasonable measures to verify beneficial-owner identity. Where ownership is layered through holding companies, trusts or nominees, the CSP works through each layer until it reaches the natural persons — and treats an inability to do so as a risk signal in its own right.

What is the difference between simplified, standard and enhanced CDD?

CDD is risk-based. The measures a CSP applies scale with the assessed money-laundering and terrorism-financing risk of the client and the service.

  • Simplified CDD — permitted only for genuinely lower-risk situations, and never where there is any suspicion of ML/TF. It reduces the extent or timing of some measures; it does not remove the duty to identify the customer and beneficial owners.
  • Standard CDD — the default: full identification and verification of the customer and beneficial owners, understanding the relationship, screening and ongoing monitoring.
  • Enhanced due diligence (EDD) — additional measures for higher-risk clients, such as PEPs, high-risk jurisdictions, and complex or opaque structures. EDD typically adds source-of-wealth and source-of-funds enquiries and senior-management sign-off.

Does a CSP have to screen customers, and how often?

Yes. Screening customers and beneficial owners against sanctions lists and watchlists is part of CDD, not a separate optional step. It must happen at onboarding and on an ongoing basis — lists change, and a client who was clear at onboarding can later appear on one.

A potential or positive match must be investigated, documented, and — where warranted — escalated and reported. Screening also covers PEP status and adverse media, which feed the decision on whether EDD is required.

How long must a CSP keep CDD records?

A CSP must keep CDD and transaction records for at least five years. Records must be sufficient to reconstruct the relationship and each transaction, and to demonstrate to ACRA on request that the CSP met its obligations.

Retention runs from the relevant reference point (for example the end of the business relationship). Confirm the exact retention trigger and any longer period required in a specific case with ACRA or your counsel before purging records.

What should a CSP do when CDD cannot be completed?

If a CSP cannot complete CDD — the customer refuses to provide information, beneficial ownership cannot be established, or the information is unreliable — it should not establish or continue the relationship or carry out the transaction, and it must consider whether the circumstances warrant a suspicious transaction report.

This is where CorpSec AI’s CDD dossier and screening help: the platform assembles the identity and beneficial-ownership picture, runs list screening, flags gaps, and holds a hard gate so a service cannot proceed while required CDD is missing — with the analyst making the final call.

Frequently asked questions

What are the four core CDD steps for a CSP?

Identify and verify the customer, identify and take reasonable measures to verify beneficial owners, understand the purpose and nature of the relationship, and conduct ongoing monitoring — with screening and record-keeping running throughout.

How long must a CSP keep CDD records in Singapore?

At least five years. Records must be sufficient to reconstruct the relationship and transactions and to demonstrate compliance to ACRA. Confirm the exact retention trigger with ACRA or counsel.

When can a CSP use simplified due diligence?

Only in genuinely lower-risk situations, and never where there is any suspicion of money laundering or terrorism financing. Simplified CDD reduces the extent or timing of some measures but never removes the duty to identify the customer and beneficial owners.

What happens if a CSP cannot verify the beneficial owner?

The CSP should not establish or continue the relationship or carry out the transaction, and must consider whether a suspicious transaction report is warranted. Inability to establish beneficial ownership is itself a risk signal.

Sources

This article is general information for Singapore corporate service providers, not legal or professional advice. Verify against the primary sources above and your own professional judgement.

Was this helpful?