Eltoma Corporate Services — Authorised Corporate Services Provider
Articles are provided for general informational purposes by an authorised corporate services provider and do not constitute legal advice.

Why higher-risk classification requires structured review, not automatic rejection
Customer onboarding for a Singapore corporate service provider does not end with collecting identity documents and recording beneficial ownership. Once the client, ownership structure and proposed services are understood, the provider must consider whether the relationship presents a higher risk of money laundering, proliferation financing or terrorism financing. This assessment is especially important where the client involves politically exposed persons, higher-risk jurisdictions, sanctions concerns, adverse information, unusual business models or opaque funding arrangements.
A higher-risk classification should not be treated as a commercial insult or an automatic refusal. In a properly designed compliance framework, it is a risk-management conclusion. It tells the corporate service provider that ordinary due diligence may not be enough and that the file may require additional evidence, enhanced review, senior-management approval and closer ongoing monitoring.
This article explains, in practical terms, how Singapore corporate service providers should think about higher-risk customers, politically exposed persons, sanctions screening and enhanced due diligence under the current Singapore corporate service provider framework.
Singapore’s current corporate service provider framework places registered providers within a supervised anti-money laundering, counter-proliferation financing and counter-terrorism financing environment. The provider is not merely an incorporation processor. It must decide whether the client can be understood, documented and serviced responsibly.
ACRA’s guidance requires customer due diligence to be performed on a risk-sensitive basis. Where higher risks are identified, the provider must apply enhanced controls that are proportionate to those risks. This is why the onboarding file should record not only the documents received, but also the reasoning behind the risk classification.
For a professional provider, the central question is not simply whether a client can be incorporated. The more important question is whether the client relationship can be accepted and maintained with a clear understanding of ownership, control, commercial purpose, jurisdictions, funding and expected activity.
A customer may be higher risk because of who the customer is, how the structure is owned or controlled, where the parties are located, what activity is proposed, how the business will be funded, or how the customer behaves during onboarding.
Typical higher-risk factors may include:
No single factor should be read mechanically. A foreign-owned company is not automatically unacceptable. A complex holding structure is not automatically suspicious. However, each factor should be understood, evidenced and considered in context.
Politically exposed persons require particular attention because public office can create exposure to corruption, bribery, misuse of public resources or reputational concerns. Under the Singapore CSP guidance, a politically exposed person includes an individual who is or has been entrusted with a prominent public function in Singapore, in a foreign country or territory, or by an international organisation. The concept also extends to immediate family members and close associates.
For practical purposes, the provider should consider not only whether the client personally holds public office, but also whether the beneficial owner, director, authorised representative, agent or connected party is a politically exposed person, a family member of such a person or a close associate.
The existence of a politically exposed person does not automatically mean that the relationship must be rejected. The correct approach is to understand the nature of the public function, the individual’s role in the structure, the level of influence, the source of funds and wealth, and whether the proposed activity is consistent with the customer’s profile. Foreign politically exposed persons will generally require enhanced due diligence.
Jurisdictional risk is a core part of customer assessment. A Singapore provider should consider where the customer is incorporated, where beneficial owners are resident or citizens, where the business operates, where funds originate, and where customers, suppliers or counterparties are located.
Higher-risk jurisdictional factors may include countries or territories identified by credible sources as having weak anti-money laundering, counter-proliferation financing or counter-terrorism financing frameworks; jurisdictions subject to calls for countermeasures or enhanced due diligence by FATF; jurisdictions under increased monitoring; conflict zones; jurisdictions associated with terrorism financing, proliferation financing, corruption, serious organised crime, sanctions evasion or limited transparency.
A connection with a higher-risk jurisdiction does not automatically prohibit the relationship, unless a legal restriction or sanctions prohibition applies. However, it will usually require closer analysis of commercial rationale, source of funds, counterparties, expected transactions and the customer’s ability to provide reliable supporting evidence.
Sanctions screening is not a box-ticking exercise. The provider should screen customers, beneficial owners, agents, connected parties and relevant persons against applicable sanctions and targeted-financial-sanctions sources, as well as other lists and information sources required by the regulatory framework and the provider’s internal policy.
Screening should normally be performed before acceptance and then repeated when there is a material change, a periodic review, a new relevant party or a trigger event. The file should evidence the search parameters used, the date of screening, the sources checked, the results, and how possible matches were resolved.
A possible name match is not the same as a confirmed sanctions match. Names, dates of birth, nationality, passport details, addresses, company registration details and other identifiers should be compared carefully. Where a true match or sanctions concern exists, the provider must not treat the matter as ordinary onboarding. The case should be escalated immediately in accordance with internal policy and applicable law.
Adverse information may arise from media reports, public enforcement notices, litigation records, regulatory publications, insolvency information, criminal allegations, civil fraud disputes, sanctions-related reports or credible industry intelligence.
Not every negative search result makes a client unacceptable. Some information may be old, irrelevant, inaccurate or linked to a different person. The provider should assess credibility, relevance, recency, seriousness and whether the information is consistent with the customer’s explanation.
The important point is that adverse information should be documented and dispositioned. A compliance file should show whether the adverse information was reviewed, whether further explanation or evidence was requested, whether senior approval was obtained, and why the relationship was accepted, escalated or declined.
Certain business models may present higher risk because they involve rapid movement of funds, limited visibility over counterparties, high-value goods, digital or intangible assets, international intermediation, complex trading chains or regulated activity.
Examples may include high-value trading, commodity or energy trading, virtual-asset related activity, payment or remittance-like models, cross-border consultancy with unclear deliverables, import-export structures involving sensitive goods, businesses with frequent third-party payments, charities or non-profit structures operating in conflict areas, or companies whose expected transactions do not match their stated activity.
The provider does not need to reject a customer merely because the business is commercially complex. However, the provider should understand what the customer actually does, how revenue is generated, who the counterparties are, which countries are involved, whether licences or other approvals are required, and whether the expected transactions are consistent with the business description.
Enhanced due diligence means applying additional measures where ordinary due diligence is insufficient for the risk identified. It is not a punishment; it is a proportionate control.
Enhanced measures may include obtaining additional information about the customer, beneficial owners and connected parties; verifying information through independent sources; obtaining more detailed information on the intended nature of the business relationship; understanding source of funds and source of wealth; reviewing the reasons for intended or performed transactions; obtaining senior-management approval to commence or continue the relationship; and applying enhanced ongoing monitoring.
Senior-management approval is particularly important where the provider is asked to accept a higher-risk client, continue a relationship after adverse information emerges, or proceed where significant wealth or funding cannot be fully corroborated. The approval record should be meaningful. It should explain what risk was identified, what additional evidence was obtained, what conditions or mitigants were imposed, and why the relationship remains acceptable.
A risk-based framework does not require every higher-risk customer to be rejected. It requires the provider to identify risk, understand it, mitigate it where possible, and decline the relationship where the risk cannot be managed responsibly.
There are many situations where a higher-risk classification can be addressed through enhanced due diligence. For example, a politically exposed person may have a transparent source of wealth, a legitimate commercial rationale and a low-risk operating model. A non-resident client may have a clear Singapore business purpose and reliable documentation. A complex group may be entirely legitimate if the ownership and control structure can be verified.
Conversely, some cases should be refused even if the client is commercially attractive. Refusal may be appropriate where the provider cannot identify beneficial ownership, source of funds is unexplained, documents are inconsistent, sanctions concerns cannot be resolved, the client is evasive, the business purpose appears artificial, or suspicious circumstances cannot be adequately mitigated.
Higher-risk customer management is one of the areas where a Singapore corporate service provider demonstrates the difference between routine administration and professional governance. A responsible provider does not accept or reject clients by label alone. It assesses the facts, documents the reasoning and applies controls that correspond to the risk.
Politically exposed persons, higher-risk jurisdictions, sanctions concerns, adverse information and unusual business models should all be approached with structured analysis. Some cases can be accepted with enhanced controls. Others should be escalated, refused or reported where suspicion arises.
For clients, this means that additional questions from a provider should not be treated as an obstacle to business. They are part of Singapore’s regulated corporate-services environment. For CSPs, a clear risk-assessment and enhanced-review process protects the provider, the client, the nominee director where relevant, and the integrity of the Singapore corporate structure.
No. It means the relationship requires enhanced review, additional evidence, senior-management approval where required and closer ongoing monitoring. Rejection may be appropriate only where the risk cannot be understood, mitigated or lawfully serviced.
A CSP should screen the customer, beneficial owners, agents, authorised representatives, connected parties and other relevant persons according to the regulatory framework and the provider’s internal policy.
Are politically exposed persons prohibited customers?
Not automatically. A PEP connection requires analysis of the public function, role in the structure, source of funds, source of wealth, commercial rationale and whether enhanced controls can manage the risk.
The file should record the screening date, search parameters, sources used, parties screened, results, possible-match analysis and final disposition.
Jurisdictional exposure may affect AML, CPF, CFT, sanctions and transaction-risk analysis. The provider should consider incorporation, residence, operating countries, source of funds and counterparty locations.
Enhanced due diligence should respond to identified risks. It may include independent verification, additional source-of-funds and source-of-wealth evidence, senior approval, conditions and enhanced monitoring.
Not automatically. The provider should assess credibility, relevance, seriousness and recency, and document why the information does or does not affect the relationship.
Articles are provided for general informational purposes by an authorised corporate services provider and do not constitute legal advice.

Receive updates with practical insights on international business, law, tax, accounting, and compliance.
Be the first to hear about our latest discounts and special offers!
Follow our Telegram channel for offshore industry news:
Want updates by e-mail?
Enter your email address below to subscribe to our newsletter!