Eltoma Corporate Services — Authorised Corporate Services Provider
Articles are provided for general informational purposes by an authorised corporate services provider and do not constitute legal advice.

Singapore corporate service work frequently involves several advisers. A foreign founder may be introduced by an overseas lawyer, a group structure may be explained by an accountant, identity documents may be certified by a notary, and an existing bank or tax adviser may already hold information about the client. In cross-border corporate administration, this cooperation is normal and often useful.
For a Singapore Corporate Service Provider, however, third-party involvement must be handled carefully. A referral from another professional does not mean that the customer has already been accepted. Documents prepared by another adviser do not automatically satisfy the Singapore CSP’s own customer due diligence obligations. Even where reliance on another party is permitted, the CSP must still understand the customer, assess the risk and retain responsibility for its own compliance decision.
The practical question is not whether third-party information can be useful. It often can. The real question is when the CSP may rely on it, what evidence should be obtained, and how the CSP should document its own acceptance decision.
A referral occurs where another person introduces a potential customer to a registered CSP. The introducer may be a lawyer, accountant, business consultant, overseas corporate agent or existing client. ACRA’s registration guidance recognises that an intermediary who only refers customers to registered CSPs does not need CSP registration. That does not mean that the Singapore CSP can treat the customer as already reviewed or accepted.
Third-party reliance is different. It arises where the CSP relies on customer due diligence measures performed by another party. Under ACRA’s Guidelines for Registered Corporate Service Providers, reliance on third-party CDD is subject to conditions. It is not a casual handover of documents.
Outsourcing or delegation is different again. A CSP may ask another person to assist with administrative or verification work, but outsourcing does not transfer regulatory responsibility. The CSP remains responsible for the customer relationship, risk assessment, escalation and final acceptance decision.
Third-party information can be valuable where it is reliable, current and relevant to the service requested. It may help the CSP understand the customer more efficiently and reduce unnecessary duplication.
Useful material may include certified identity documents from a lawyer or notary, corporate documents from a registered agent in another jurisdiction, beneficial ownership information prepared by a group adviser, audited financial statements from an accountant, source-of-funds evidence prepared for a bank, or tax-residency information prepared by a tax adviser.
Such material may support the onboarding file and help explain the ownership chain, the commercial rationale for the Singapore structure, the source of funds and the background of the persons involved. Nevertheless, third-party information is an input into the CSP’s own review. It is not a substitute for the CSP’s judgement.
Reliance is most defensible where the third party is itself a properly regulated professional or institution, is subject to appropriate AML, counter-proliferation financing and counter-terrorism financing obligations, is supervised in a jurisdiction with adequate standards, and is willing and able to provide the underlying customer due diligence information promptly.
ACRA’s Guidelines state that a registered CSP may rely on a third party to perform customer due diligence measures, including simplified or enhanced CDD, only where the applicable requirements are met. The CSP must be satisfied as to the third party’s status, supervision and controls, and must obtain the relevant CDD information without delay.
The key compliance test is not whether the third party is familiar or commercially reputable. The test is whether the third party is eligible, supervised, reliable and cooperative enough for the CSP to justify reliance in its own file.
Reliance should be approached carefully where the third party is unregulated, is only an introducer, cannot explain how documents were verified, refuses to share underlying CDD information, or has a commercial interest in completing the transaction quickly.
Additional caution is appropriate where the customer has complex ownership, nominee directors or nominee shareholders, connections with higher-risk jurisdictions, politically exposed persons, adverse information, unclear source of funds, sensitive business activities or an unusual commercial rationale.
The more complex or higher-risk the customer, the less appropriate it is for the CSP to rely passively on another person’s work. A higher-risk file may still be accepted, but it should usually involve additional information, enhanced review, internal escalation and a documented rationale for acceptance.
Reliance does not mean that the CSP merely receives a short confirmation saying that another professional has completed checks. The CSP should obtain the information necessary to understand and evidence the CDD measures performed.
Relevant information may include identity details, verification evidence, beneficial ownership information, ownership structure charts, details of authorised representatives, purpose and intended nature of the relationship, risk assessment information, source-of-funds information where relevant, and screening results where appropriate.
A practical rule follows: if the third party cannot produce the underlying information when needed, reliance is unsafe. The CSP should not build its customer file around assurances that cannot be evidenced.
This is the central compliance point. Despite reliance upon a third party, the registered CSP remains responsible for its own obligations.
In practical terms, the CSP cannot defend a deficient file merely by saying that an accountant, lawyer, bank or introducer had already reviewed the client. If beneficial ownership remains unclear, the CSP must address it. If documents are incomplete, the CSP must request further evidence. If the commercial rationale is inconsistent, the CSP must ask questions. If risk indicators remain unresolved, the CSP must escalate or decline the engagement as appropriate.
Reliance may support the customer due diligence process, but it does not transfer accountability for the client relationship. The CSP must still decide whether to accept the customer, accept with conditions, obtain further information, escalate or decline.
Professional referrals require particular attention where the introducer moves beyond introduction and begins arranging corporate services. ACRA’s registration guidance states that role services include acting as, or arranging for others to act as, company directors, company secretaries, partners or similar roles. It gives examples such as providing a shortlist of proposed company directors for the customer to choose from, or acting as an intermediary by introducing persons to act as directors and billing the customer for that service.
This distinction matters. A person who merely refers a customer to a registered CSP may fall outside CSP registration. A person who arranges directors, nominee shareholders, address services or filing services may be much closer to the regulated perimeter. The position should be assessed by reference to the substance of the activity, not merely the label used in correspondence or invoices.
For the Singapore CSP, the practical question is whether the introducer is only facilitating contact or whether the introducer is participating in the arrangement of regulated corporate services. Where the latter is possible, the file should record how the arrangement has been analysed.
Third-party information does not replace the CSP’s own customer risk assessment. It may form part of the evidence base, but the Singapore CSP should still classify the customer’s risk using its own methodology.
Relevant factors may include the type of customer, ownership complexity, jurisdictions involved, service requested, source of funds, nominee arrangements, politically exposed persons, sanctions concerns, adverse information, unusual business purpose, remote onboarding and whether the customer operates in a sensitive sector.
Where reliance is used, the risk assessment should explain how the third-party material was considered and whether it was sufficient. If gaps remain, the CSP should identify them and record the follow-up steps taken.
A defensible reliance file should show not only that documents were received, but why the CSP considered reliance appropriate.
The file should normally record the identity of the third party, its professional or regulatory status, its jurisdiction and supervisory authority, the customer due diligence measures it performed, the information obtained from it, the date on which information was received, the CSP’s assessment of adequacy, any gaps or follow-up questions, the customer risk rating and the final acceptance decision.
Where the matter is higher risk, the file should also record escalation, enhanced due diligence, senior-management approval where applicable and the reasons for proceeding or declining. This is important because ACRA compliance reviews examine risk assessment methods, internal policies and controls, identity verification, enhanced checks, beneficial ownership information, suspicious transaction reporting and staff training.
Clients sometimes ask why a Singapore CSP requests documents when another lawyer, accountant or bank has already reviewed them. The answer is straightforward: the Singapore CSP has its own regulatory obligations and its own acceptance decision to make.
Another professional’s file may have been prepared for a different purpose. A bank may have assessed the client for banking. A foreign lawyer may have verified documents for a transaction in another jurisdiction. An accountant may have prepared tax or financial information. The Singapore CSP must consider whether those documents are sufficient for the corporate services it is being asked to provide.
In practice, the CSP may need updated documents, Singapore-specific information, evidence of beneficial ownership, clarification of nominee arrangements, or further explanation of commercial rationale and source of funds. Asking again is not duplication for its own sake; it is part of the CSP’s own regulated review.
Pure referral: a foreign lawyer introduces a founder to a Singapore CSP. The lawyer does not arrange directors, nominee shareholders, address services or filing services. The Singapore CSP performs its own onboarding before accepting the customer.
Professional reliance: a regulated overseas accounting firm provides verified identity documents, beneficial ownership information and a source-of-funds explanation. The Singapore CSP assesses whether the firm is properly supervised, obtains the relevant CDD information and documents the basis for reliance. The CSP still completes its own risk rating and acceptance decision.
Improper reliance: an unregulated introducer sends a corporate chart and asks the CSP to incorporate a company urgently. The beneficial owner is not clearly identified and the business purpose is vague. The CSP should not rely passively on the introducer’s material.
Referral becomes regulated activity: an intermediary provides a list of persons willing to act as nominee directors and charges the customer for arranging the appointment. This may go beyond a mere introduction and should be analysed against the CSP service perimeter.
Before relying on third-party information, a Singapore CSP should ask whether the third party is regulated or supervised, which jurisdiction it operates in, whether the AML/CFT framework is broadly consistent with FATF standards, what CDD measures were performed, and whether the CSP has obtained the relevant CDD information without delay.
The CSP should also ask whether the documents are current and complete, whether beneficial ownership is clear, whether nominee arrangements are disclosed, whether any high-risk indicators are present, whether enhanced due diligence or senior approval is required, and whether the basis for reliance has been documented.
Finally, the CSP should confirm that it has completed its own risk assessment and recorded the final acceptance decision. Reliance is not complete until the CSP’s own file explains the relationship clearly.
Third-party information can be useful in Singapore corporate service work. It may reduce duplication, assist with identity verification and help the CSP understand the customer more efficiently. However, it must be handled with care.
A referral is not the same as reliance. Reliance is not the same as outsourcing. Outsourcing is not a transfer of responsibility. A Singapore CSP may use third-party information to support its review, but it should not outsource its judgement.
A professional CSP must still understand the customer, assess the risk, obtain sufficient evidence, document the basis for reliance and make its own acceptance decision. That approach protects the CSP, the client, the director, the banking process and the integrity of the Singapore corporate structure.
A referral alone is not enough. The Singapore CSP must still complete its own onboarding, risk assessment and acceptance decision.
It is the use of customer due diligence measures performed by an eligible third party, subject to regulatory conditions and proper documentation.
No. The CSP remains responsible for its customer due diligence obligations and its final decision to accept, continue, escalate or decline the relationship.
A suitable third party is usually a regulated professional or institution subject to appropriate AML/CPF/CFT obligations and supervision, and able to provide CDD information without delay.
Another professional may have checked the information for a different purpose. The CSP must decide whether the information is sufficient for the corporate services requested in Singapore.
Reliance should be avoided or treated with caution where the third party is unregulated, refuses to share information, cannot explain verification, or the customer presents unresolved higher-risk indicators.
The file should record the third party’s identity, regulatory status, supervisory jurisdiction, CDD measures performed, information obtained, adequacy assessment, gaps, risk rating and acceptance decision.
Articles are provided for general informational purposes by an authorised corporate services provider and do not constitute legal advice.

Receive updates with practical insights on international business, law, tax, accounting, and compliance.
Be the first to hear about our latest discounts and special offers!
Follow our Telegram channel for offshore industry news:
Want updates by e-mail?
Enter your email address below to subscribe to our newsletter!