During my first four months at WIDTH, one thing became clear from my conversations with Corporate Service Providers in Singapore.
Most CSP teams are not careless about compliance. In fact, many are extremely cautious. They understand that a weak customer due diligence decision can expose the firm, its management and Singapore’s wider business ecosystem to risk.
The problem is often operational.
The teams I spoke with repeatedly raised the same operational pressures: limited manpower, time-consuming administration and fragmented records. Documents sit in spreadsheets, email threads and shared folders. Screening results require manual review. Periodic checks compete with new applications. Meanwhile, legitimate clients expect their companies to be registered promptly.
This creates a difficult balance. A CSP must complete and evidence the right checks without turning every application into a long, expensive manual investigation.
From what I have seen, the biggest mistake is treating company-registration due diligence as a collection of administrative tasks. It should be managed as one controlled workflow, from client intake to approval and ongoing monitoring.
The following seven mistakes explain where that larger problem usually appears.
Direct answer: Before registering a company for a client, a Singapore CSP should avoid incomplete identity and beneficial-owner checks, weak screening, undocumented risk decisions, fragmented record-keeping and a process that stops after onboarding. Due diligence should be risk-sensitive, properly supervised and supported by evidence that can be retrieved when required.
Why Company Registration Requires More Than Collecting Documents
The regulatory position is now clear. The Corporate Service Providers Act 2024 took effect on 9 June 2025. Registered CSPs must comply with obligations concerning anti-money laundering, countering the financing of terrorism and countering proliferation financing.
ACRA’s current guidelines cover risk assessment, identity verification, beneficial ownership, customer screening, record-keeping, ongoing monitoring and internal controls. ACRA can also examine a CSP’s customer-verification methods, beneficial-ownership information, reporting processes, staff communication and training during a CSP compliance review.
These duties are not satisfied merely because a passport copy and incorporation form are on file. A CSP must understand who the customer is, who ultimately owns or controls the structure, what risks are present and why the relationship was accepted.
ACRA’s enforcement history shows why this matters. In January 2024, ACRA cancelled the registrations of a filing agent and qualified individual after identifying failures involving additional checks for non-face-to-face onboarding, beneficial-owner inquiries, customer risk assessments and employee supervision. ACRA also reported that it had cancelled or suspended 17 registered qualified individuals and filing agents between 2021 and 2023. Although that enforcement preceded the current CSP regime, the operational lessons remain relevant.
The current regime carries serious consequences. ACRA’s enforcement guidance states that breaches can lead to restricted filing access, suspension or cancellation, regulatory financial penalties, and criminal fines of up to S$100,000 for specified failures.
This does not mean every client should be treated as suspicious. It means every decision should follow a defensible process.
Mistake 1: Using Manpower to Compensate for a Weak Process
The first problem I hear about is manpower. Small teams can spend substantial time requesting documents, copying information between systems, checking whether screening was completed and chasing internal approval.
Hiring another administrator may provide short-term relief. However, it does not correct an unclear process.
When the workflow is fragmented, every new client creates more coordination work. Staff may repeat the same data entry, use different file names or follow different review steps. A registered qualified individual may then spend valuable time finding evidence rather than reviewing risk.
The better approach is to define the process before adding headcount:
- Collect the required customer, agent, director and ownership information.
- Verify identities and supporting documents.
- Establish and verify beneficial ownership where required.
- Screen the relevant people and entities.
- Assess and document customer risk.
- Escalate exceptions and higher-risk cases.
- Record the acceptance or rejection decision.
- Schedule the appropriate ongoing monitoring.
Technology can reduce repetitive work, but it does not replace qualified supervision or judgement. The objective is to give each person a clear task, decision point and record.
Mistake 2: Treating Excel as the Compliance Record
Excel is useful for tracking a client list or review schedule. It becomes a problem when the spreadsheet is expected to function as the complete compliance record.
A spreadsheet may show that screening was completed. It may not show which sources were checked, what possible matches appeared, who reviewed them, why a result was cleared or which supporting documents were used.
The same issue appears when evidence is split between:
- spreadsheets;
- shared drives;
- individual email accounts;
- messaging applications;
- downloaded screening reports;
- screenshots; and
- handwritten or separate approval notes.
ACRA’s guidelines for registered CSPs require CDD records to be retained for five years after the CSP stops providing corporate services to the customer. The records must also be sufficient to reconstruct individual transactions where relevant. The guidelines specifically refer to keeping identity-verification documents, screening records and the documentation supporting risk assessments.
The lesson is not that CSPs must stop using Excel entirely. The mistake is relying on it without a controlled client record.
A stronger record should answer five questions quickly:
- What information and evidence did we obtain?
- What checks did we perform?
- What did we find?
- Who reviewed and approved the decision?
- What must happen next?
If a team needs hours to reconstruct one customer file, the process is already consuming more capacity than it should.
Mistake 3: Stopping Due Diligence After Company Registration
Onboarding receives the most attention because it stands between the client and incorporation. Once the company is registered, urgent work shifts to the next application.
That is where ongoing due diligence can be missed.
ACRA’s guidelines state that a registered CSP must conduct ongoing monitoring of every business relationship with a customer. Monitoring should consider the customer’s risk profile and keep relevant CDD information up to date. Enhanced monitoring applies in specified higher-risk circumstances, including certain unusual transactions, higher-risk relationships and politically exposed persons.
A client’s risk does not remain fixed after approval. Directors, shareholders or beneficial owners may change. The business may enter a new market. Adverse information may emerge. A previously low-risk structure may become more complex.
Therefore, CSPs should define both periodic and event-driven reviews.
Periodic reviews occur according to the firm’s risk-based schedule. Event-driven reviews respond to a relevant change, alert or new piece of information.
A monitoring process should make the following visible:
- the current customer risk rating;
- the next review date;
- changes in directors, shareholders or beneficial owners;
- new screening alerts or adverse information;
- outstanding documents;
- the person responsible for review; and
- the resulting decision and evidence.
Ongoing monitoring should not depend on someone remembering to update a spreadsheet.
Mistake 4: Choosing Screening Only by Price
Screening costs matter, especially to a smaller CSP. However, the cheapest database can become expensive if it produces incomplete coverage, outdated information or alerts that take too long to investigate.
It is important to be precise here. ACRA does not say that every CSP must purchase the most expensive commercial database. Its guidelines recognise free public search tools, commercial databases and other relevant sources for adverse-news checks.
The regulatory and operational questions are more practical:
- Does the process screen every person and entity required by the regulations?
- Does it cover the lists and information required by ACRA and relevant authorities?
- Is the information current enough for the firm’s purpose and risk profile?
- Can the team investigate name matches using sufficient identifiers?
- Are screening results and risk decisions documented?
- Can existing relationships be rescreened when relevant information changes?
A weak screening process can create two different problems. It may miss relevant information, or it may return so many poor-quality matches that staff spend hours clearing false positives.
The database is only one component. A CSP also needs clear matching criteria, investigation steps, escalation rules and a record of how each alert was resolved.
Mistake 5: Confusing an Identity Document With Identity Verification
Collecting an image of an NRIC or passport does not, by itself, establish that the person presenting it is the genuine holder.
ACRA’s guidelines require CSPs to establish and verify the identities of customers and agents. They also address beneficial owners, proposed directors and other relevant persons. For higher-risk foreign customers, the guidelines discuss measures such as certified true copies, statutory declarations or corroborating information.
For remote onboarding, the risk is straightforward. A team may receive a clear document but still lack confidence that:
- the document is authentic;
- it has not expired or been altered;
- the person is present and matches the document;
- the person’s details agree with reliable sources; and
- the individual is acting in the declared capacity.
ACRA notes that MyInfo business can be used to establish and verify identities with the customer’s consent. Depending on the customer and risk level, CSPs may also consider appropriate document-authenticity and biometric controls.
The law does not prescribe one particular identity-verification product for every case. Therefore, the real mistake is not simply “having no tool”. It is using a verification method that does not adequately address the customer’s risk or produce reliable evidence.
Mistake 6: Making Every Due Diligence Review Equally Slow
Several CSP teams I have encountered are cautious because they do not want to register a company that later creates legal or regulatory problems. That concern is understandable.
However, caution should not mean placing every customer into the same long manual process.
ACRA’s framework is risk-sensitive. The required depth of due diligence should reflect the customer’s risk, the structure, the jurisdictions involved, the quality of available evidence and any relevant warning signs. Simplified measures may be appropriate in defined lower-risk situations, while enhanced measures are required for specified higher-risk cases.
The mistake is operating without a clear triage model.
A better workflow separates cases into practical paths:
| Review path | Typical operational treatment |
|---|---|
| Standard | Complete required checks through a consistent workflow and approve when no exception remains |
| Information required | Pause the case and request specific missing or inconsistent evidence |
| Enhanced review | Obtain additional information, apply deeper verification and secure the required approval |
| Decline or report | Follow internal policy and applicable reporting obligations when the risk cannot be accepted or suspicion arises |
Risk-based triage does not mean cutting corners for “easy” clients. Every required measure must still be completed. It means allowing the team to concentrate time and senior attention where the evidence and risk justify it.
That improves both control and turnaround time.
Mistake 7: Letting Compliance Work Crowd Out Business Growth
The final mistake is commercial, but it is closely connected to the first six.
When experienced staff spend most of their day copying information, locating documents and clearing avoidable alerts, the firm has less capacity to serve existing clients or win new ones.
Some CSPs then face an unhealthy choice: delay new business, hire faster than revenue grows, or shorten checks without a controlled basis. None is a sustainable operating model.
I do not believe compliance and growth should be treated as opposing goals. A well-designed compliance workflow can protect both.
The CSP can create a better client experience by showing applicants exactly what information is required. The team can reduce rework through standardised intake. Reviewers can focus on exceptions instead of repeating administrative tasks. Management can see where cases are delayed and why.
This matters because speed without control is dangerous, but control without operational efficiency can make the business uncompetitive.
What Enforcement Tells Singapore CSPs
The warning is not theoretical. In a 2021 enforcement action, ACRA identified failures involving beneficial-owner inquiries, documented risk assessments, ongoing monitoring and risk-sensitive internal controls. More recently, a June 2026 CNA report described a former corporate service provider director linked to Singapore’s S$3 billion money-laundering case. He pleaded guilty to making false representations to IRAS and breaching his duties as a company director. Prosecutors said he knew a client company lacked legitimate business operations and did not conduct further due diligence.
The latter case involved alleged and admitted conduct far beyond an inefficient workflow. It should not be used to suggest that ordinary CSP teams act in the same way. However, it reinforces a basic principle: a CSP cannot accept documents or client explanations at face value when the surrounding facts require further inquiry.
ACRA’s current enforcement guidance makes the accountability clear. CSPs need controls that operate in practice and evidence that shows those controls were followed.
A Practical Pre-Registration Checklist
Before a company is registered for a client, the CSP should be able to answer the following questions:
- Have we identified and verified the customer and any authorised agent?
- Have we identified the proposed directors and other relevant connected parties?
- Have we established and taken reasonable measures to verify the beneficial owner where required?
- Do we understand the intended nature and purpose of the relationship and company structure?
- Have we screened all required people and entities against the relevant sources?
- Have we investigated and documented possible matches?
- Have we assessed the customer’s risk using consistent criteria?
- Have we obtained additional evidence and approval where enhanced due diligence is required?
- Is the acceptance decision, reviewer and supporting reasoning recorded?
- Have we defined the ongoing monitoring and review requirements?
This is not a substitute for the CSP’s policies, professional judgement or legal advice. It is a practical way to test whether the file is ready to move forward.
Moving From Administrative Work to Controlled Compliance
The seven mistakes share one cause: the compliance process is spread across too many people, files and tools.
WIDTH’s guide to compliance challenges for Singapore CSPs explains the broader operating model. The goal is to connect customer onboarding, KYC and KYB, beneficial-ownership information, screening, risk assessment, approval, case management and ongoing monitoring in one controlled workflow.
WIDTH does not replace a CSP’s judgement, registered qualified individual or legal responsibilities. It helps teams organise the work, make ownership clearer and retain the evidence supporting each decision.
For the CSP teams I have met during my first four months at WIDTH, that operational shift is the real opportunity. They do not need compliance to become weaker or faster at any cost. They need a process that is thorough where risk demands it, efficient where the evidence is clear and defensible throughout the client relationship.
Frequently Asked Questions
The biggest mistake is treating due diligence as disconnected administrative work. This often leads to incomplete checks, inconsistent decisions, missed monitoring and evidence that is difficult to retrieve.
ACRA’s guidelines do not prescribe one commercial screening product for every CSP. They refer to required official sources and recognise free public tools, commercial databases and other relevant sources for adverse-news checks. Whatever sources are used, the CSP must perform the required screening and document its results and decisions.
The regulations focus on establishing and verifying identity rather than mandating one named product. The method should be appropriate to the customer’s circumstances and risk. Remote or higher-risk onboarding may require additional measures.
Excel can support tracking, but it should not be the only evidence repository where decisions, documents, screening results and approvals are stored separately. The CSP must retain sufficient, retrievable records in accordance with its obligations.
No. ACRA’s guidelines state that CSPs must conduct ongoing monitoring of every business relationship with a customer. The intensity of monitoring should reflect risk and relevant changes.
Standardise data collection, verify information through appropriate sources, apply consistent risk criteria and route exceptions for enhanced review. Automation can reduce repetitive administration, but final decisions still require proper oversight and judgement.
Conclusion
The strongest CSPs will not be the firms that process every application fastest. They will be the firms that know when a case can proceed, when it needs more evidence and when it should be escalated or declined.
That requires more than a checklist. It requires a connected operating process that gives the team visibility from the first document request through ongoing monitoring.
For Singapore CSPs, this is how compliance becomes more defensible without consuming the capacity needed to grow.
Sources
- ACRA — Corporate Service Providers Act 2024
- ACRA — Guidelines for Registered Corporate Service Providers
- ACRA — Undergoing a CSP Compliance Review
- ACRA — Enforcement Action on CSPs and RQIs
- ACRA — Cancellation of LW Business Consultancy and its Qualified Individual
- ACRA — MEA Business Consultancy Enforcement Action
- CNA — Former CSP Director Linked to S$3 Billion Money-Laundering Case
