In my day-to-day work, I speak with many people responsible for AML/CDD compliance.

One issue comes up repeatedly: many compliance professionals place too much emphasis on AML Screening and sometimes treat it as the centre of the entire AML/CDD framework.

Whenever we discuss CDD compliance, their questions remain focused on screening. Which sanctions lists should they check? Which database should they use? How should they determine whether a result is a True Hit or a False Hit?

I am not suggesting that AML Screening is unimportant.

The problem is that screening is only one part of AML/CDD compliance. A CSP may conduct screening correctly and still fail to meet its wider obligations if it does not have proper customer risk assessments, identity verification, beneficial ownership checks, internal controls, record-keeping and ongoing monitoring.

AML Screening Is Only 1.6%: 8 Compliance Areas CSPs Overlook

1. AML Screening Alone Is Not Enough

Let us first look at how much of the regulatory material is specifically dedicated to AML Screening.

Regulation 22 of the Corporate Service Providers Regulations 2025 sets out the requirements for Customer Screening. The relevant provision contains approximately 204 words, representing about 1.83% of the Regulations’ substantive text.

Paragraphs 6.23 to 6.27 of ACRA’s Guidelines for Registered Corporate Service Providers contain approximately 474 words directly related to AML Screening. This represents around 1.6% of the substantive Guidelines.

Word count alone does not determine the importance of a regulatory obligation. However, these figures make one point clear: AML Screening is not the whole of AML/CDD compliance.

The same conclusion can be drawn from ACRA’s compliance review framework.

ACRA identifies eight areas that a Reviewer will examine. AML Screening is not listed as a standalone review area. It forms part of the broader CDD process and may be examined together with customer identity verification, risk assessment, enhanced checks, record-keeping and ongoing monitoring.

In other words, performing AML Screening every day does not prove that a CSP has a complete and effective AML/CDD compliance framework.

2. Many CSPs Prioritise Screening Without Fully Understanding the Requirements

There is another contradiction I regularly encounter.

Many people place significant importance on AML Screening, but they are still unclear about what proper screening involves and what must happen after a potential match is found.

Based on Regulation 22 of the Corporate Service Providers Regulations 2025 and paragraphs 6.23 to 6.27 of ACRA’s Guidelines, the main screening expectations can be summarised in four areas.

First, screening cannot be limited to one or two sanctions lists

The screening scope extends beyond the customer.

A CSP must also screen the customer’s agents, connected parties and beneficial owners. Where a transaction involves the formation of a corporation or another legal person, the relevant agents, connected parties and beneficial owners of the proposed entity must also be screened.

Relevant information sources include:

  • MAS Targeted Financial Sanctions Lists
  • Lists under the Terrorism (Suppression of Financing) Act
  • Terrorism or terrorism-financing alert lists circulated by ACRA
  • Terrorist designation information published through MHA
  • Other lists and information provided by the Registrar or relevant law enforcement authorities

Connecting to one sanctions list or screening only the customer’s name does not amount to complete AML Screening.

Second, AML Screening includes Adverse News Screening

In addition to sanctions and terrorism-related lists, a CSP should check whether there is adverse information concerning the customer.

This may involve free public search tools such as Google, commercial databases or other relevant AML/CFT information sources.

The purpose is not simply to save a few search results. The screening output should be incorporated into the Customer Risk Assessment and used to determine the customer’s overall risk level and whether Enhanced CDD is required.

Third, screening evidence and decision-making must be documented

Completing a search and marking the customer as “Passed” is not sufficient.

A CSP should retain evidence that the screening was performed. This may include screenshots, printouts, database reports and internal assessment notes.

Where a potential match is identified, the records should clearly explain:

  • Whether the result is a True Hit or a False Hit
  • Why that conclusion was reached
  • The source of the matched information
  • How the result affects the customer’s risk assessment
  • Whether further investigation or Enhanced CDD is required

For a True Hit, the CSP should retain the source evidence, screenshots or reports and document its risk assessment and follow-up actions.

Without these records, it may be difficult to demonstrate during a compliance review that the result was properly investigated.

Fourth, screening is not a one-time exercise

AML Screening should not be performed only when a customer is onboarded.

For an ongoing business relationship, the CSP must repeat the screening periodically based on the customer’s risk profile. Existing customers should also be screened when relevant sanctions lists, terrorism lists or regulatory information are updated.

This forms part of Ongoing Monitoring.

Proper AML Screening therefore involves much more than running a name through a database. It includes managing the screening population, monitoring information sources, reviewing customers periodically, investigating potential matches, assessing risk and retaining evidence.

3. The Compliance Challenges Facing CSPs Go Far Beyond Screening

This is the main reason I am writing this article.

When a CSP’s compliance team focuses only on AML Screening, it can easily overlook the other areas that ACRA will examine.

According to ACRA, a Reviewer will examine the following eight areas:

  1. Risk assessment methods for money laundering, proliferation financing and terrorism financing
  2. Internal policies, procedures and controls, commonly referred to as IPPC
  3. How customer identities are verified and enhanced checks are conducted
  4. How beneficial ownership information is collected
  5. How effectively beneficial ownership information is provided to ACRA
  6. How suspicious transactions are reported
  7. How policies, procedures and controls are communicated to staff
  8. The staff training programme, including its scope and frequency

These eight areas show that ACRA is assessing the complete AML/CDD compliance framework.

AML Screening is part of that framework, but it cannot replace Customer Risk Assessment, identity verification, beneficial ownership checks, Enhanced CDD, suspicious transaction reporting, IPPC, staff training or proper record management.

A professional AML Screening system can improve efficiency, provide access to broader sanctions and adverse news sources, and help maintain records of True Hits, False Hits and Ongoing Monitoring.

However, a screening tool only addresses the execution of one part of the compliance process. It does not replace a complete compliance framework.

4. What CSP Compliance Professionals Should Do

If you are responsible for AML/CDD compliance at a CSP, do not focus only on AML Screening. Using a screening database does not mean that all compliance obligations have been satisfied.

Start by reading the Corporate Service Providers Regulations 2025 in full. This will help you understand the CSP’s legal obligations relating to customer due diligence, risk assessment, record-keeping and ongoing monitoring.

You should also read ACRA’s Guidelines for Registered Corporate Service Providers, particularly the sections covering CDD, beneficial ownership, Enhanced CDD, suspicious transaction reporting, IPPC and staff training.

Finally, review your compliance framework against ACRA’s eight review areas. For each area, check whether the necessary policies, procedures, supporting documents and execution records are available.

AML Screening is important, but it is only the starting point.

The real question is not whether a customer’s name has been checked. The real question is whether the CSP can demonstrate that its entire AML/CDD compliance framework has been properly established and is operating effectively.

Recommended Compliance Resources

ACRA Compliance Review

Understand ACRA’s key review areas and identify possible gaps before a formal compliance review.

Explore the ACRA Compliance Review Guide

AML/CDD Compliance Self-Assessment

Quickly check whether your current compliance procedures cover key AML/CDD requirements.

Start the Free Self-Assessment

Free AML/CDD Compliance Training

Join practical online training covering ACRA requirements, CDD, risk assessment and compliance documentation.

Register for Free Training

Simplify AML/CDD Compliance with AlgoCandy

AlgoCandy connects client onboarding, identity verification, AML Screening, risk assessment, Ongoing Monitoring and compliance reporting in one platform.

It helps Singapore CSPs reduce manual work, maintain clear audit trails and stay ready for compliance reviews.

Book a Demo or Start a Free Trial.

References:

ACRA’s eight compliance review areas

ACRA Guidelines for Registered CSPs

Corporate Service Providers Regulations 2025

Read more

Whatsapp Let’s Talk
SHARE
TOP