An effective Singapore AML/KYC Compliance Checklist isn’t just a list of identification documents to gather. It should include a process of ongoing monitoring, documentation and escalation of risk, identifying the customer, conducting a risk assessment and defining the beneficial owner. This article outlines the content of a checklist in practice, and where firms generally go wrong.

What Is AML/KYC Compliance in Singapore?
As Singapore is a global financial and trading centre, its regulators are keen for firms to conduct controls with real teeth – not just pencil and paper. Anti-money laundering (AML) and know-your-customer (KYC) controls are in place to prevent illegal money laundering through the business and to provide a written justification for the business relationships that the firm has.
Difference Between AML and KYC
All of the policies, internal controls, monitoring and reporting lines fall under the umbrella of AML. KYC is the consumer-facing aspect of that framework: the procedures to identify and verify customers, comprehend who effectively owns or controls them, and evaluate and track their risk. KYC should be an integral part of an overall AML/CFT programme, rather than a programme in itself.
Who Needs AML/KYC Controls?
Not all Singapore business obligations are the same; they vary based on the type of business and the regulatory regime it operates under. The AML/CFT obligations of financial institutions, corporate service providers, public accountants, regulated dealers in precious stones and metals, and licensed moneylenders and other designated businesses are generally different from those imposed by their respective regulators. ACRA’s current guidance for corporate service providers, for instance, prescribes the customer risk assessment parameters and the internal policies and continuous controls that are applicable to this particular sector.
Why a Risk-Based Approach Matters
Not all customers are created equal – treating them as such leads to low controls in both ways – too many controls on low-risk relationships and too few on high-risk. A risk-based approach takes multiple factors into consideration about the customer types; geographic exposure; product and service risk; transaction patterns; delivery channel and ownership complexity – and not just one. Singapore’s 2026 FATF/APG Mutual Evaluation Report highlights that Singapore has a competent and coordinated AML/CFT/CPF regime, but that the results of the risk-based approach are not consistently demonstrated and need to be sharper.
What Should Be on a Singapore AML/KYC Compliance Checklist?
The following checklist outlines some of the key components most AML/KYC frameworks in Singapore should include. This is a starting structure, and it should be modified to suit any sector-specific needs that may relate to the licence, regulator and business of a firm.
Customer Identification and Verification
Firms usually will require at least the customer’s name, identification, date of birth/incorporation, registered or address, and business information, all backed by proper documentation. Depending on the type of customer, the type of regulated activity and the nature of the documents, the exact documents that may be accepted and how they must be verified may vary.
Customer Risk Assessment
A structured risk assessment takes into account the type of customer, geographical location, industry, ownership, the goods/service being utilised, anticipated transaction profile and delivery route. Most schemes categorise customers as low, standard or high risk. It is not the label that is important, but that there is documentation and evidence that the classification is correct, and that this evidence can be produced during a review – an undocumented risk rating is hard to defend.
Beneficial Owner Identification
As ownership structures become more complex, it is necessary to identify who the ultimate owners or controllers of a customer are, and more difficult. Businesses with multi-layered shareholdings, trusts, investment vehicles and multi-jurisdictional corporate structures all need to be examined to understand who is behind the relationship. This is an area that has received special attention in Singapore’s 2026 FATF/APG technical assessment, and it is an area that it is important to get right, rather than do it for form’s sake.
Enhanced Due Diligence
Enhanced due diligence (EDD) should be used for higher-risk customers, complex ownership structures, unusual transactions, exposure to higher-risk jurisdictions, politically exposed persons (PEPs) and other risk factors discovered during onboarding or monitoring. EDD is not just about gathering more documents; it is about tackling the risk that spurred the EDD in the first place – whether source of funds verification, senior management sign-off, or more regular review.
Ongoing Customer Monitoring
KYC is not complete after a customer is onboarded. Ongoing monitoring includes transaction monitoring, ownership and control changes, changes in customer usage, unusual transactions, changes in risk profile, and periodic reviews of the relationship. Regulators or auditors will first ask about customer information that hasn’t been updated, as this could indicate that the risk assessment on record is not current.
Suspicious Transaction Escalation
Firms must have a clear and effective workflow that addresses the identification of red flags, escalation to an internal party, investigation, documentation, reporting if necessary, and confidentiality and tipping-off issues. Singapore Police Force’s Suspicious Transaction Reporting Office (STRO) is the authority for reporting suspicious transactions and industry guidance. This checklist item relates to the availability of a working escalation procedure, and not about when a report is required – this is something that needs to be determined by the firm.
Record Keeping and Documentation
Documentation should be provided in relation to the identification and verification of customers, risk assessment, beneficial ownership checks, the enhanced due diligence process, monitoring activity, escalation, decisions and reviews. In practice, a control that cannot be documented would be difficult to audit or review during a regulatory inspection – documentation is the key to a defensible control.
What Are the Key AML Compliance Requirements Companies Should Review?
Beyond the customer-level checklist, firms should periodically step back and review their broader AML compliance requirements at a programme level. This typically breaks down into four practical categories.
Policies and Procedures
This includes the AML/CFT policy, customer onboarding processes, risk assessment processes, escalation procedures, reporting procedures and records retention rules. It is at this stage that the differences between a policy document and day-to-day practice tend to become apparent when the expectations are converted into working procedures.
Internal Controls
All of these customer screening, approval procedures, segregation of duties, monitoring controls and periodic compliance reviews fall under this category. These controls are the ones that make a policy “doable” and not just “wanted.
Employee Training
Staff should be aware of the AML red flags, KYC procedures, escalation procedures, documentation standards and who is reportable. Highly effective training is more likely to be relevant to the actual roles of the people who need it, than to be a generic AML awareness session repeated year after year.
Independent Review
The key to the loop between design and effectiveness is the regular evaluation of policies and controls in practice – not on paper. This is what a compliance audit usually does.
What Are the Key KYC Compliance Requirements?
An effective framework for meeting KYC compliance requirements typically considers customer identification, identity verification, beneficial ownership, customer risk classification, screening, ongoing monitoring, periodic review and documentation together, rather than treating any one of these as sufficient on its own. This list should be viewed as a starting point for entities rather than a set rule, as the precise requirements that apply are dependent on the entity’s regulatory framework, licence and regulated activities.
Common AML/KYC Compliance Gaps in Singapore Businesses
Incomplete Customer Information
Absent fields at onboarding are like putting weak links in the chain because the information acquired at the beginning of the relationship is used for all kinds of risk assessment, beneficial ownership analysis, and monitoring.
Weak Risk Classification
One of the most frequent gaps identified during reviews is the lack of a generic risk rating without the reasons for determining the rating, which may be appropriate, but cannot be verified without some documentation.
Outdated Customer Profiles
When circumstances change, and when there are any review requirements applicable to the firm, customer information should be reviewed. An easy place to find profiles is from the initial.
Poor Beneficial Ownership Documentation
Ownership structures are complex and must be analysed layer by layer. While beneficial ownership is clear in the case of a single corporate shareholder, if the ownership of a company is transferred via a chain of individuals, the beneficial owner will remain unidentifiable.
Inconsistent Enhanced Due Diligence
Higher risk customers should have controls commensurate with the risk that has been identified. If EDD is applied for different risk profiles when they are comparable, it’s hard to justify and can indicate a lack of focus on the risk assessment process.
Poor Documentation
The firm should be able to demonstrate what was examined, by whom, what was discovered, what was decided and why. Any of these missing will be a source of doubt on the integrity of the entire file.
How to Build an Effective AML/KYC Framework
Establish Clear Policies
Policies outline the overall AML/CFT stance taken by the firm and provide a common benchmark for staff to determine the firm’s expectations in relation to the identification and management of risk.
Create Practical Procedures
Policies must be translated into operational processes including onboarding, risk assessment, monitoring, escalation and reporting – the processes staff use day-to-day.
Define Responsibilities
There needs to be clear accountability throughout compliance, management teams, front office, operations and senior management teams so that nothing is left to chance.
Train Employees
Staff training should be based around what they do in their work, not only on generic AML awareness information that is not linked to their decision-making.
Review and Improve Controls
The framework should be reviewed internally, tested, amended according to regulatory standards, new risks identified, lessons learned from incidents and changes in policies should all be fed back in on an ongoing basis and not a one-off setup exercise.
AML/KYC Compliance Checklist for Internal Review
The table below can be used as an internal review tool that can be used practically by the owner(s) to assign ownership and evidence expectations for each line item.
| Requirement | Responsible Person | Frequency | Evidence Required | Review Status |
| Customer identification | Compliance / Operations | Onboarding | ID documents | ☐ |
| Identity verification | Compliance / Operations | Onboarding | Verification evidence | ☐ |
| Customer risk assessment | Compliance | Onboarding / review | Risk assessment record | ☐ |
| Beneficial owner identification | Compliance | Onboarding / review | Ownership records | ☐ |
| Customer and sanctions screening | Compliance | As applicable | Screening results | ☐ |
| Enhanced due diligence | Compliance | Higher-risk cases | EDD records | ☐ |
| Ongoing monitoring | Compliance | Ongoing | Monitoring records | ☐ |
| Suspicious transaction escalation | Compliance / Management | As required | Escalation records | ☐ |
| Record keeping | Compliance / Operations | Ongoing | Compliance files | ☐ |
| Employee training | Compliance / HR | Periodic | Training records | ☐ |
| Policy review | Compliance / Management | Periodic | Review documentation | ☐ |
This checklist is a practical starting point rather than a substitute for sector-specific legal or regulatory advice. Businesses should confirm the requirements applicable to their entity, licence and regulated activities.
How Does Singapore’s 2026 AML/CFT Context Affect Businesses?
The Mutual Evaluation conducted by the FATF/APG in 2026 has identified strengths in Singapore’s AML/CFT/CPF framework, particularly in terms of the country’s coordination between the authorities, and its understanding of risks, as well as areas where the results may be sharper and more consistently demonstrated in terms of risk. This report does not impose new requirements on all companies. What it does is put at a national level the same expectations as individual regulators already have at firm level: the AML/KYC controls should be risk-based, documented, consistently applied, appropriate to the business, supported by trained staff and regularly reviewed.
When Should a Company Consider External AML/KYC Support?
External support is likely to be most effective at certain stages, not as a long-term replacement for the ability to manage compliance within the business – typically when introducing a new compliance framework, establishing a business within a regulated industry, preparing for a regulatory review, facing complicated customers or ownership, updating AML/CFT policies, controlling gaps which have already been identified, training staff, commissioning an independent review of compliance, or simply unable to keep a framework current without the internal expertise.
This includes AML & KYC Support and MAS Compliance Services provided by RT Compliance, which deals with the regulatory aspect of the above checklist, and Risk Management provided by RT Compliance, which provides the methodology used to assess the risks faced by the customer. Compliance Audits are typically conducted together with these audits, as a means of assessing if the controls are effective in practice for the firm waiting for a review.
Conclusion
The most useful aspect of a Singapore AML/KYC Compliance Checklist will be its function as a working review document to be referred back to by the compliance officer or business owner as the business, customers and regulations evolve. Firms that are unsure whether their current framework holds up against sector-specific AML compliance requirements and KYC compliance requirements may find it useful to have that framework reviewed independently before a regulator does it for them.
Frequently Asked Questions
What is an AML/KYC compliance checklist?
A structured internal control framework for the identification, assessment, monitoring, documentation and escalation of risk when assessing whether a firm’s AML/KYC framework is complete, covering customer identification and assessment of risk, beneficial ownership and monitoring, documentation and escalation. It should be flexible to the specific regulatory context, and not a rigid one-size-fits-all standard.
What are the main AML compliance requirements in Singapore?
AML compliance requirements generally cover risk assessment, customer due diligence, ongoing monitoring, record keeping, reporting and the internal controls that support them, applied according to whichever regulatory framework governs the firm.
What are the main KYC compliance requirements?
KYC compliance requirements typically include customer identification and verification, beneficial ownership identification, customer risk assessment and ongoing monitoring, applied at a level of depth appropriate to the customer’s risk profile.
Who needs AML/KYC controls in Singapore?
Requirements are dependent on the type of entity and sector, as well as the applicable legislation. Singapore businesses are not equally regulated but generally, there are obligations that apply to financial institutions, corporate service providers, public accountants and other regulated or designated businesses.
What is customer due diligence in Singapore?
Customer due diligence (CDD) refers to the identification process of a customer, the verification of an identified customer, the understanding of the ownership and risk profile of a customer, and the collection of sufficient data to assess the relationship throughout the relationship.
When is enhanced due diligence required?
The enhanced due diligence is normally triggered by the higher risk situation, such as complex ownership, unusual transaction, higher risk jurisdictions, politically exposed persons, etc., and is proportionate to the specific risk identified and not as a generic step.
How often should AML/KYC controls be reviewed?
There’s not one universal frequency. Timing of the reviews should correspond to the need under regulatory requirements, the condition of the firms’ business, and the relevant regulatory developments, such as the new guidance following Singapore’s FATF/APG evaluation in 2026.

