Profession-specific playbook Current
Operating playbook for Singapore accounting and corporate-secretarial firms
Three separate regimes apply to the same firm, depending on the service in front of you.
A Singapore accounting or corporate-secretarial firm can sit under audit oversight, data protection law, and anti-money laundering obligations at the same time, and which one governs a given piece of work depends on the service being provided. This playbook sets out how the core obligations fit together. It is general information, not legal, tax, or compliance advice.
Action plan
1 Confirm whether the firm or its practitioners are regulated as public accountants Audit sign-off carries its own registration and oversight regime, separate from general accounting work.
A public accountant is a licensed individual who signs off on audits and gives an independent opinion on financial statements, conducting audits under Singapore Standards on Auditing. ACRA registers and oversees public accountants and accounting entities under the Accountants Act, including annual registration renewal, the Code of Professional Conduct and Ethics, and practice monitoring and quality control reviews.
- Confirm which individuals in the firm hold public accountant registration
- Follow the ACRA Code of Professional Conduct and Ethics for any registered public accountant
- Keep annual registration renewal and practice monitoring obligations current
Done when: Public accountant registration and ACRA oversight obligations are confirmed for the individuals who need them
ACRA: audit regulation in Singapore2 Meet PDPA obligations for every client's personal data the firm holds This applies to the firm generally, not only to work captured by AML/CFT rules.
Separately from audit or corporate-service work, the firm handles client personal data in the ordinary course of onboarding and engagement. The PDPA's Consent, Notification, Purpose Limitation, Protection, and Retention Limitation Obligations apply to that data across the firm's work, not only to services that also trigger AML/CFT rules.
- Apply PDPA consent and notification obligations at the point personal data is collected
- Apply reasonable security arrangements to personal data the firm stores
- Review retention of personal data against the Retention Limitation Obligation, not only against AML minimums
Done when: PDPA obligations are applied to client personal data across the firm's work, not limited to AML-captured services
See PDPA obligations when collecting client personal data3 Check CDD obligations separately where the firm acts as a corporate service provider This is a third, distinct regime, triggered by the specific service, not by the firm's profession title.
Where a firm provides corporate services, such as company incorporation, company secretarial work, or nominee arrangements, it is likely to fall within the Corporate Service Providers Act 2024's registration and customer due diligence framework, on top of any audit or general accounting obligations. Check each service line against that framework rather than assuming accounting work generally is captured or excluded.
- Check company secretarial, incorporation, and nominee services against the CSP Act framework specifically
- Register as a corporate service provider where the firm's activities require it
- Apply CDD to corporate-service clients even where the same client's audit work doesn't independently trigger it
Done when: Corporate-service lines were checked individually against the CSP Act framework, not assumed in or out of scope
See CDD obligations for corporate service providersDesignated services
Audit and assurance
Statutory audit and assurance engagements
Audit sign-off requires a registered public accountant and sits under ACRA's Accountants Act oversight, including the Code of Professional Conduct and Ethics and ACRA's practice monitoring programme.
Corporate services
Company secretarial and incorporation services
Company secretarial work, incorporation assistance, and nominee arrangements are the kind of services the Corporate Service Providers Act 2024 framework is aimed at, and are worth checking individually for CSP registration and CDD obligations.
Client data handling
Onboarding and holding client personal data
Every client relationship involves collecting and holding personal data, which brings the PDPA's Consent, Notification, Purpose Limitation, Protection, and Retention Limitation Obligations into play regardless of which other regime also applies to the engagement.