Country-specific guidance Current

Verifying identity documents against a reliable, independent source

Holding a copy of a document isn't the same as verifying it.

Collecting a copy of a client's identity document is only the first step. Where a specific customer due diligence duty applies, because your firm is a registered corporate service provider (CSP) doing in-scope work, or another specific basis applies, verifying it means checking that its details actually came from a reliable, independent source, not just accepting the copy on its face. This guide sets out a practical approach to that check. It is general information, not legal or compliance advice.

Action plan

1 Confirm a specific basis applies before applying this verification standard The reliable-independent-source standard comes from the CSP Act's CDD duty, which is scoped to in-scope CSP work.

The reliable, independent source standard described below comes from the Corporate Service Providers Act 2024's customer due diligence duty, which applies where your firm is a registered CSP and the engagement involves an in-scope corporate service. Where that basis doesn't apply, rely on another specifically identified basis for verifying identity rather than treating this standard as a universal requirement for every Singapore engagement.

  • Check whether this engagement involves an in-scope CSP service before applying the CSP Act's verification standard
  • Identify the specific basis relied on when the CSP Act doesn't apply
  • Don't apply CSP-level verification rigor to an engagement with no specific basis requiring it

Done when: A specific basis for applying this verification standard was confirmed before it was applied

See CDD obligations for corporate service providers
2 Confirm the document itself is government-issued and independent of the client Verification means the source is independent of the person being identified, not just official-looking.

Once a specific basis for verification applies, the standard calls for documents, data, or information from a reliable, independent source, rather than a client's own unverified statement. A government-issued NRIC, FIN-bearing pass, or passport meets that description; a self-declared form filled in by the client does not, on its own.

  • Treat a government-issued NRIC, FIN-bearing pass, or passport as a reliable, independent source
  • Don't treat a client's own unverified statement of their details as sufficient on its own
  • Check the document's format and security features look consistent with a genuine government-issued document

Done when: The identity document relied on came from a reliable, independent source, not the client's own unverified statement

ACRA: Corporate Service Providers Act 2024
3 Cross-check the details against a second independent source where you can A second, unrelated source of confirmation strengthens a verification a single document can't provide alone.

Where practical, cross-check the details on the identity document against a second, independent source, for example an ACRA Bizfile search where the individual is also a company officeholder. A second consistent source strengthens the verification; a mismatch is a reason to ask further questions before proceeding.

  • Cross-check details against a second independent source where one is available
  • Follow up on any mismatch between sources before proceeding
  • Don't treat a single document as sufficient where a practical second check is available

Done when: Details were cross-checked against a second independent source where one was practically available

See verifying company registration details
4 Record how, and against what, verification was carried out A verification that isn't recorded is hard to demonstrate later, even if it was done properly at the time.

Keep a record of what document was checked, what it was checked against, and when. This turns a one-off check into evidence you can point to later, rather than something that has to be reconstructed from memory.

  • Record which document was checked and when
  • Record what it was cross-checked against, if anything
  • Store this record alongside the client's file, not separately from it

Done when: A record of what was verified, against what, and when, was kept with the client's file

See storing client identity evidence securely