Compliance PracticeSingaporeTrust & Company Services

FATF Evaluation Sets a Clear Roadmap for Stronger CSP Regulation in Singapore

Singapore achieved a strong outcome in the Financial Action Task Force’s (FATF) 2026 Mutual Evaluation and was placed under Regular Follow-up. This is the most favourable follow-up category under the FATF’s fifth-round evaluation framework and applies to members that have performed well overall.

Compared with the Enhanced Follow-up status Singapore received in 2016, the latest result represents a clear improvement. The fifth-round methodology applies more rigorous standards, examining not only whether the necessary laws and frameworks are in place, but also whether regulatory measures are effective in practice. The evaluation recognised the strength of Singapore’s framework and enforcement capabilities in combating money laundering, terrorism financing and proliferation financing.

At the same time, FATF identified Key Recommended Actions and areas where Singapore should further strengthen its framework. For Corporate Service Providers (CSPs), these recommendations could directly influence the focus and depth of future compliance reviews conducted by the Accounting and Corporate Regulatory Authority (ACRA).

Areas FATF Identified for Further Improvement

FATF highlighted several matters that are particularly relevant to CSPs:

  • Strengthening the verification and cross-checking of beneficial ownership and nominee information;
  • Improving the identification and analysis of complex structures involving multiple legal persons or legal arrangements;
  • Strengthening the investigation and prosecution of professional intermediaries and other persons who facilitate money laundering;
  • Expanding supervisory coverage of targeted financial sanctions relating to proliferation financing, particularly for higher-risk sectors such as CSPs and virtual asset service providers.

These recommendations send a clear signal: regulatory scrutiny will no longer focus only on whether a CSP collected the required information or completed the prescribed procedures. Regulators will increasingly examine whether customer due diligence measures are genuinely effective and whether each conclusion is supported by sufficient evidence.

ACRA Translates the FATF Findings into Priorities for the CSP Sector

More importantly for the industry, ACRA has already translated the FATF evaluation findings into practical messages for CSPs.

At the Corporate Service Providers Conference on 13 July 2026, ACRA Chief Executive Mrs Chia-Tern Huey Min identified three priorities:

  1. Keeping beneficial ownership records accurate and up to date;
  2. Promptly identifying and reporting suspicious transactions through Suspicious Transaction Reports (STRs);
  3. Strengthening the sector’s understanding of how complex structures may be misused for illicit purposes.

These are not market assumptions about the FATF report. They are official messages delivered by ACRA directly to the CSP sector. They connect FATF’s international evaluation findings with the day-to-day compliance responsibilities of CSPs and provide a clear indication of future regulatory priorities.

AI Can Improve Efficiency, but It Cannot Replace Professional Judgement

Mrs Chia-Tern also addressed the impact of artificial intelligence on the CSP sector.

On the one hand, AI can support client onboarding, KYC screening, document review, anomaly detection and regulatory filings, improving the efficiency of compliance work. On the other hand, criminals are also using AI to create synthetic identities, convincing falsified documents and deepfakes.

ACRA also warned that AI could make it easier to establish layered legal persons and legal arrangements, further complicating the identification of ultimate beneficial owners.

ACRA’s position is clear: AI can process information and flag risks, but it cannot replace the professional judgement of CSPs or assume ultimate responsibility for compliance decisions.

An appropriate operating model for CSPs should therefore be:

System-generated result → Risk indicators and supporting rationale → Human review → Documented final decision

Human judgement remains essential when deciding whether a complex structure has a legitimate commercial rationale, whether a transaction is suspicious, whether a client’s risk rating is appropriate, and whether an STR should be filed.

Four Capabilities CSPs Should Strengthen

Based on FATF’s findings and ACRA’s stated priorities, AlgoCandy believes CSPs should focus on strengthening four core compliance capabilities.

1. Verify Ownership—Do Not Merely Collect Information

Beneficial ownership compliance should not stop at recording information declared by the client.

CSPs should retain evidence supporting ownership and control relationships and verify the information against corporate registry records, shareholding documents and reliable independent sources. Where discrepancies are identified, CSPs should document the differences, the investigation performed, the client’s explanation and the final conclusion.

The key regulatory question will be whether a CSP can demonstrate that its beneficial ownership information is accurate, current and reasonably verified.

2. Identify and Analyse Complex Structures

A complex structure is not necessarily suspicious. However, a structure without a reasonable commercial or legal purpose should trigger further review.

CSPs should be able to identify multi-layered corporate shareholders, cross-border structures, trusts, nominee arrangements, unexplained intermediary entities, and situations where legal ownership differs from actual control.

Identifying the structure is only the first step. The CSP must also assess whether it has a legitimate commercial or legal rationale and document the risk assessment, the measures taken, and the basis for establishing or continuing the business relationship.

3. Maintain a Complete STR Decision Record

STR management should not be limited to recording whether a report was filed.

CSPs should retain records of the risk indicators identified, internal escalations, compliance reviews, supporting evidence, final decisions and the reasons for not filing an STR where applicable.

The entire decision-making process should be traceable and capable of being reasonably explained during an ACRA compliance review.

4. Assess Proliferation Financing Risk Explicitly

CSPs should not treat proliferation financing as equivalent to general sanctions-list screening.

Risk assessments should also consider connections to high-risk jurisdictions, shipping and international trade activities, dual-use goods, complex cross-border intermediary companies, opaque ownership structures, and nominee or third-party relationships that could be used to circumvent sanctions.

Proliferation financing controls may be integrated into existing CDD processes, but they should remain a clear, identifiable and separately explainable risk dimension.

Compliance Cannot Be Treated as a Box-Ticking Exercise

CSPs must treat compliance as a substantive responsibility rather than a documentation exercise performed simply to satisfy an inspection.

While FATF recognised the overall strength of Singapore’s framework, it also noted that certain penalties and sanctions should become more effective, proportionate and dissuasive. ACRA subsequently identified beneficial ownership, STR reporting and complex structures as clear priorities for the CSP sector.

Taken together, these signals make continued regulatory strengthening highly foreseeable:

  • Reviews will focus more closely on practical effectiveness;
  • Beneficial ownership verification will become more rigorous;
  • Complex structures will require stronger explanations and supporting evidence;
  • STR decisions will require more complete audit trails;
  • Enforcement and accountability for non-compliance may become more dissuasive;
  • Technology may support compliance, but responsibility will remain with CSPs and the relevant professionals.

AlgoCandy helps CSPs integrate beneficial ownership verification, complex structure analysis, risk assessment, human review and evidence management into a single compliance workflow.

The key question for future regulatory reviews will not simply be what checks a CSP completed, but:

Can the CSP produce complete and reliable evidence showing how each compliance conclusion was reached?

This will be critical to managing compliance risk, meeting increasingly rigorous regulatory expectations and maintaining professional competitiveness.

By AlgoCandy

Adminrichie

AML Observatory Webmaster, responsible for the website's operations.

Related Articles

Leave a Reply

Back to top button