Anti-Money Laundering Risk Management for Singapore Legal Firms: Developments,Duties, and Practical Safeguards

By

|

Singapore’s post-FATF regulatory environment makes AML compliance a front-line professional obligation for lawyers. This guide covers suspicious transaction reporting duties, customer due diligence standards, record-keeping requirements, and the training expectations regulators now apply to legal professionals.

Default Insights post featured image

I. Introduction

For many lawyers, anti-money laundering (AML) compliance is often perceived as a regulatory burden; an administrative exercise imposed by regulators that competes with the pressures of client work and billable hours. Yet the regulatory trajectory in Singapore suggests that this perception is increasingly untenable. AML compliance is no longer a peripheral compliance function. It is now central to professional risk management and to the integrity of the legal profession itself.

The core issue is straightforward. Lawyers occupy a unique position within the financial and commercial ecosystem. Legal professionals structure transactions, manage client monies, establish corporate entities, facilitate property transfers, and provide the legal legitimacy required for complex financial arrangements. These legitimate services are precisely what make law firms attractive to criminals seeking to introduce illicit funds into the legitimate economy.

The reality is that criminals rarely require lawyers to be complicit in wrongdoing. In many cases, they merely require lawyers to be busy, trusting, or insufficiently vigilant.

In recent years, the regulatory direction has become increasingly clear. Regulators are moving away from the question of whether firms possess written AML policies toward a more demanding inquiry: whether those policies are actually implemented, whether staff follow them consistently, and whether firms can demonstrate compliance through documentation and records.

This article examines the evolving AML obligations of lawyers in Singapore, the regulatory developments shaping the current landscape, and the practical steps law firms can adopt to manage their exposure. It is written specifically for practicing lawyers and focuses on operational approaches that can be implemented within real legal practices.

In this article, the term “AML” is used to cover all 3 anti-financial crimes areas, namely Anti-Money Laundering (AML), Countering Financing of Terrorism (CFT), and Countering Proliferation Financing (CPF)

  • AML refers to the steps taken to prevent criminals from disguising illegally obtained funds as legitimate income.
  • CFT targets the financial support systems of terrorists and extremist organisations.
  • CPF focuses on preventing the raising, moving, or using of funds to develop weapons of mass destruction.

Generally, money laundering concerns the source of where the funds are from, proliferation financing is about where the money is going to, and the countering of terrorism financing covers both.

II. The Regulatory Environment: Increasing Expectations for Legal Gatekeepers

The global AML framework is heavily influenced by the standards established by the Financial Action Task Force (FATF), the international body responsible for setting recommendations on combating money laundering, terrorism financing, and proliferation financing. Singapore, as a major international financial centre, is subject to periodic FATF inspections that assess its compliance with these standards.

These inspections have significant implications for domestic regulatory frameworks. No country wishes to receive a negative FATF assessment, and governments typically strengthen their regulatory regimes in preparation for these inspections. Singapore is no exception.

The 2025 FATF inspection prompted several updates to Singapore’s AML framework, including changes that directly affect the legal profession. These updates reinforce the expectation that law firms act as professional gatekeepers within the financial system.

Historically, AML obligations in the legal sector were often interpreted by many lawyers as a one-time exercise at the onboarding stage: conduct client due diligence, open the file, and proceed with the matter.

Regulators now take a very different view.

Today, AML obligations are increasingly framed around a lifecycle model that encompasses three continuous responsibilities:

  • Detect suspicious risks or patterns.
  • Report suspicious activities to the authorities.
  • Monitor the client relationship throughout the duration of the engagement.

This detect-report-monitor obligation fundamentally changes how AML compliance operates within legal practice. Compliance is no longer limited to file opening. It now extends across the entire life cycle of a legal matter.

III. Lessons from the S$3 Billion Money Laundering Cases

The seriousness of these expectations became particularly evident following Singapore’s widely publicised S$3 billion money laundering investigations. Several law firms were fined between S$30,000 and S$100,000 in connection with AML regulatory breaches.

While the financial penalties themselves attracted attention, the broader message from regulators was far more significant.

The authorities emphasised that law firms are expected to operate as professional gatekeepers. Lawyers cannot simply rely on formal compliance processes while remaining passive participants in suspicious transactions. Instead, they must actively assess risks, question unusual circumstances, and monitor client relationships throughout the engagement.

A key misunderstanding exposed by these cases concerned Suspicious Transaction Reports (STRs). Some firms believed that filing an STR would automatically shield them from further regulatory scrutiny. However, regulators made it clear that reporting suspicion is only one part of a lawyer’s responsibilities.

If a firm identifies a high-risk client or transaction and files an STR, it must still consider whether enhanced monitoring or additional due diligence is necessary. Filing an STR does not absolve the firm from continuing responsibilities.

In other words, compliance cannot be reduced to a procedural step. It requires ongoing professional judgment.

A slip by a law firm or a lawyer can result in significant adverse impact. For law firms, compliance failures pose significant risks of financial penalties against the law firm. The individual lawyer may face disciplinary action. Both will suffer reputational damage. 

IV. The Legal Architecture: Act, Rules, and Practice Directions

There are three layers of AML regulations:

A. The Legal Profession Act (LPA), Part 5A

Part 5A provides the statutory framework for AML obligations for lawyers. It empowers the Council of the Law Society to make rules and issue practice directions. Crucially, it establishes that a failure to comply with these rules can lead to disciplinary proceedings under the Act. The Act also defines what a relevant matter is for the purposes of anti-money laundering processes. 

B. The Legal Profession (Prevention of Money Laundering, Financing of Terrorism and Proliferation Financing) Rules 2015 (The Rules)

The Rules set out the “What.” They define:

  • CDD Requirements (Rules 6-15): The mandatory steps for identifying and verifying clients and beneficial owners when carrying out client due diligence (CDD).
  • Internal Programmes (Rule 18): The requirement for firms to have Internal Policies, Procedures, and Controls (IPPC).
  • Keeping of Records (Rules 19 to 22): The obligation for firms to keep AML-relevant records.

C. Practice Direction 3.2.1 (PD 3.2.1)

Updated significantly on 6 October 2025, PD 3.2.1 provides the granular detail required for the “How”, how the Rules can be implemented. It includes specific requirements for conducting Firm-Wide Risk Assessments (FWRA), the mandatory appointment of a Money Laundering Reporting Officer (MLRO), and the steps required to carry out the necessary client due diligence.

V. The Three Stages of Money Laundering and the Lawyer

A. Placement, Layering, and Integration

At its core, money laundering is the process of making “dirty” money—wealth obtained from illegal activities like fraud, drug trafficking, or corruption—appear “clean” and legitimate. By funnelling the funds through a complex series of bank transfers or commercial transactions, criminals disguise the original source of the money so they can use it without triggering red flags from law enforcement or tax authorities.

The process typically follows three stages:

  • Placement: The initial entry of “dirty money” into the financial system — for example, with cash deposits or smurfing. Smurfing is when the money is broken down into smaller sums, below regulatory reporting thresholds, and then have the ‘little smurfs’ deposit them into multiple bank accounts. 
  • Layering: Disguising the audit trail through complex transactions — for example, multiple transfers, shell companies, or cross-border movements.
  • Integration: Where laundered funds re-enter the economy as apparently legitimate wealth, such as buying property, luxury goods, or investing in businesses.

B. Why Lawyers Are Attractive to Money Launderers

Lawyers rarely participate in the Placement stage. 

However, lawyers frequently become involved in the second and third stages. During Layering and Integration, criminals may seek legal assistance to:

  • establish companies or trusts,
  • structure cross-border investments,
  • purchase real estate,
  • manage escrow arrangements, or
  • create complex contractual relationships.

These activities are legitimate in themselves. However, they can also be used to disguise the origin or destination of illicit funds.

The professional characteristics of lawyers—confidentiality, legitimacy, and expertise—can unintentionally provide credibility to financial structures that conceal criminal activity. Consequently, criminals view legal services as valuable tools for laundering funds.

The role of lawyers is therefore not to act as investigators or enforcement agents. Rather, their role is to introduce friction into transactions by asking appropriate questions, verifying information, documenting decisions, and escalating concerns where necessary.

Criminals prefer smooth and unquestioned processes. Effective AML controls make legal services less attractive to those seeking to launder funds.

C. Relevant Matters

The requirement to keep AML records does not apply to all legal work. Under Singapore law, these obligations are triggered when lawyers engage in defined “relevant matters” (LPA section 70A(2)).

Relevant matters generally include:

  • real estate transactions,
  • management of client monies,
  • creation or management of companies and trusts,
  • mergers and acquisitions, and
  • financial or corporate structuring.

However, the statutory framework also contains a broad “catch-all” provision covering matters that are unusual given their complexity, value, purpose, or client profile.

This provision often surprises litigators who assume AML obligations apply only to transactional practice. In reality, unusual litigation matters can also fall within the AML regime. For example:

  • disputes involving large or unexplained financial transfers,
  • unusually rapid settlements, or
  • litigation involving complex cross-border structures that makes no commercial sense.

As a result, AML assessment should be embedded into the file-opening process across all practice areas.

Another little-known requirement (Rule 18(2)(c)) is that AML checks have to be carried out for new hires within the firm as well. 

VI. A Practical Framework: The Five Pillars of AML Compliance

For law firms seeking to operationalise AML compliance, it is helpful to view the processes through five interconnected pillars:

Pillar One: Proactive risk assessment

Pillar Two: Consistent client due diligence

Pillar Three: Ongoing monitoring

Pillar Four: Record-keeping and reporting

Pillar Five: Continuous reviews and audits

These pillars form a practical operating system for managing AML risks across the life cycle of a legal engagement.

VII. Pillar One: Proactive Risk Assessment

The cornerstone of Singapore’s AML regime is the Risk-Based Approach or RBA (Rule 12). This means the law firm should focus its most intensive resources on the areas where it is most vulnerable. To borrow a term from the cybersecurity space, think of this as the law firm’s threat model. Without a clear understanding of risk exposure, firms cannot allocate their compliance resources effectively.

Risk assessment operates at two levels.

A. Firm-Wide Risk Assessment (FWRA)

Under Rule 18(2)(a) and PD 3.2.1 Para 46 to 51, every law firm must conduct and document a firm-wide assessment of its AML exposure. This assessment examines the firm’s overall risk profile by analysing factors such as:

  • the firm’s practice areas,
  • the types of clients served,
  • the frequency of cross-border transactions,
  • the handling of client funds, and
  • the jurisdictions involved in the firm’s work.

For example, a firm specialising in conveyancing or corporate structuring may face different AML risks compared with a litigation-focused practice.

Firm-wide risk assessments must be reviewed periodically (usually once a year) and updated whenever the firm’s practice profile changes.

When carrying out an FWRA, the law firm’s senior management should ask:

  • Determining High-Risk Indicators: What practice areas are we doing? What client types do we accept: domestic or foreign; heartlanders or high net worth? How often do we hold large sums of client money? Do we frequently handle high-value real estate for non-residents? Do we set up complex offshore structures? How much cross-border work do we do? How much corporate services work do we do? Are we advising in higher-risk areas such as digital assets or family offices? 
  • Determining Mitigation: If the firm’s risk profile is high in certain practice areas, what are the corresponding robust internal controls that we have put in place to mitigate the risk?

The Law Society has a risk-assessment template on its website. It is a good starting point to understand what is required when carrying out an FWRA.

B. Matter-Specific Client Risk Assessment (CRA)

In addition to the firm-level assessment, every new client or matter should undergo a documented risk evaluation. PD 3.2.1 Annex B4 and B5 provide a list of risk factors, including Customer, Country, and Business Relationship risks. This assessment need not be lengthy. What matters is that the reasoning is clearly recorded.

Standardised forms or practice management systems can help ensure that risk assessments are conducted consistently across the firm.

As an initial step, the new matter or client can get a “light-weight” risk assessment before onboarding the client. However, if any risk factors exist, a detailed assessment should be carried out before onboarding.

Practical note 1. The best approach is to standardise the firm’s client risk assessment form whenever a matter is opened, so that it can be completed consistently across the firm. The form should be reviewed annually at the same time as the firm-wide annual risk assessment review. If the firm’s risk profile changes, consider whether there is a need to update the form. The Law Society has a sample client risk-assessment form on its website.

Practical note 2. Nowadays, banks actively monitor a law firm’s account, both the office and the clients’ accounts, for unusually large deposits or withdrawals. The banks have systems that understand money movements that are ordinary in the course of a law firm’s business, and if there is any transaction that exceeds a predetermined limit, the bank calls the law firm for an explanation. If there is no clear explanation, the banks have been known to suspend or close the firm’s accounts. One important point to remember is that when providing the explanation, do not disclose confidential client information.

C. Internal Policies, Procedures, and Controls (IPPC)

Rule 18(2)(c) requires all law firms to have an IPPC. IPPC is a document that sets out how a law firm will implement the various AML processes within the firm. 

Rule 18(2)(d) and PD 3.2.1 Para 3(D) require that a firm’s IPPC be reviewed by an independent party.

  • Internal Review: For smaller firms, this can be a lawyer within the firm who was not involved in creating the policies.
  • External Review: For high-risk or larger firms, it is recommended that the review be carried out by an external consultant.

Management must document these reviews and any remediation steps taken to address gaps.

VIII. Risk Factors

Risk factors are usually classified into 5 categories or areas: (a) Customer risk, (b) Country risk, (c) Funding risk, (d) Channel risk, and (e) Transaction risk. The line whether a risk factor falls within one or another category is not clear, but that is not important. In fact, a factor can fall within multiple categories. What is important is that the firm’s staff are aware of the risk factors and keep a lookout for them. 

A. Customer risk

Customer Risk is the specific level of “danger” a client poses to a law firm regarding the potential for money laundering. It is an assessment of how likely it is that the client—or the work they are asking the firm to do—is a front for criminal activity.

A long-standing local business is generally lower risk. Higher risks are new clients with no clear history, “politically exposed persons” (PEPs) (the correct modern term is “politically exposed individuals” to differentiate from “corporate persons”) who have access to public funds, or companies with overly complex “Russian doll” ownership structures designed to hide the real owner. The “Russian doll” is a metaphor for Matryoshka dolls, where after one doll is opened, there is another identical one inside. 

When the firm encounters a “Russian Doll” structure, it cannot stop at the first layer. AML regulations require the firm to “look through” the entire chain of entities until the firm identifies the individual/s who is/are the ultimate beneficial owner/s (UBOs). If the client refuses to provide the full map of the structure, it is usually grounds to decline the instruction and consider filing a Suspicious Transaction Report.

Some of the red flags relevant to Client risks include clients who:

  • have no address, or have multiple addresses, 
  • avoid personal contact without good reason,
  • are willing to pay fees without legal work or show no interest in the outcome,
  • cannot provide documentation to support their narrative, or 
  • change lawyers frequently, or engage multiple lawyers without a legitimate reason.

Finally, under PD 3.2.1 Para 27 to 29 and Para 59, law firms must screen clients against the UN Security Council Resolutions and Singapore’s MAS Regulations. This is to determine if the client is on their sanctions list.

B. Country risk

Country risk is the assessment of how likely a specific country is to facilitate money laundering, terrorism financing, proliferation financing, or corruption. In assessing Country risk, the firm does not just look at where the client is from. The firm also looks at where the counterparty is from, where the transaction relates to, and where the source or destination of the funds is. 

In general, high-risk countries are those listed in the FATF black or grey list or on the MAS lists. 

Practical Note 3. The Rules don’t specify any lists. Thus, a country not on the list can still be considered high risk. One clear example in the context of 2026 is Russia. 

C. Funding risk

For convenience, two concepts are sometimes conflated into the term “Funding Risk”. They are Source of Funds (SoF), which refers to the specific money being used for a particular transaction, and Source of Wealth (SoW), which looks at a person’s entire financial history (their “life story” of wealth).

Source of Funds risk is laser-focused on the origin of the actual “pot of money” hitting the firm’s client account. So, questions a lawyer should ask include:

Did the money for the transaction come from illegal activities? Or is it unclear, and the client is being evasive about it? 

Practical Note 4. This is really the core of AML checks. If the funds are from illegal activities, this will be the clearest red flag, and the instructions should be declined. 

Source of Wealth risk involves a much wider inquiry. Possible sources of wealth include a client’s current income, wealth, or funds obtained from his current and previous positions, business undertakings, and family assets. 

It may be possible to gather general information on the source of wealth or funds from publicly disclosed assets, any other publicly available sources, commercial databases, or other open sources. An internet search (including social media) may also reveal useful information about the client’s wealth and lifestyle and about their official income. 

A lawyer may rely on self-declarations of the client. If a lawyer does so, any inability to verify the information should be taken into account in establishing its reliability. Discrepancies between client declarations and reliable information from other sources may be suspicious if such discrepancies cannot be satisfactorily explained.

D. Channel risk 

Channel Risk (also known as Delivery Channel Risk) refers to the danger associated with how a client and a law firm communicate or interact and how services are delivered. It focuses on the “plumbing” of the relationship rather than the person or the country. 

In the digital age, it is easy for a criminal to hide behind a screen or a third party. 

If the lawyer has never physically met the client, the risk of identity fraud increases significantly. A criminal could contact and communicate with the lawyer online or via video conferencing by using a stolen identity and “deepfake” technology (a growing concern in 2026) to pass off as someone else. To mitigate this risk, do a liveness test, which is really a sophisticated way of saying observe the image on the screen and look for inconsistent images in the video, bad lighting that makes it difficult to see the client’s face, or jerky video. It is to ensure that the person on the screen is alive and not an avatar.

Similarly, when a client doesn’t come to the lawyer directly but is brought to the firm by a third party (like an unregulated consultant or an offshore agent), and the lawyer is relying on that third person’s “word” that the client is legitimate. The risk is that the intermediary might be complicit in the money laundering scheme or simply lazy with their own checks. In such situations, to mitigate the risk, a law firm should perform due diligence on the introducer as well as the client.

Instructions received through apps like Telegram or WhatsApp should be viewed with caution. These channels are designed for anonymity, making it nearly impossible to create a clear audit trail. Many of these channels also have auto-delete functions, making it difficult to confirm clients’ instructions. 

But this channel risk must be calibrated to today’s business environment. An overseas client wanting meetings via video conferencing is not a channel risk. 

Practical Note 5. A clear low channel risk is when a client physically walks into the office of a law firm and produces to the lawyer his or her original NRIC, and the photograph on the NRIC corresponds with the face of the person before the lawyer. 

E. Transaction risk

Transaction Risk concerns the transaction that the lawyer is undertaking for the client, that is, what the client or the counterparty is doing. Even a “low risk” client (like a local business owner) can trigger high transaction risk if they suddenly request an unusual or overly complex cross-border payment. Or that the transaction involves high-risk assets like cryptocurrency.

F. Application of the Risk-Based Approach

A risk-based approach does not mean refusing all high-risk clients. It means identifying the risks and applying controls that match the risk. Then document the rationale for continuing with the engagement. 

At the opposite end of the spectrum, the fact that a client or a transaction raises no red flags does not mean that the AML risk is low. It can be quite the opposite if the money launderer is experienced and able to ‘hide’ the usual red flags. 

Practical Note 6. When multiple red flags stack together, move from general CDD to EDD, and consider whether an internal report to the MLRO is needed.

The red flags are listed by the Law Society, the Singapore Police Force, and FATF. The Resource Section of this article has references to them. 

G. An Example of its Application 

Here is an example of its practical application. It is a foreign joint venture. The client is local. The counterparty is a relative of a foreign PEP. The joint venture is in one of the high-risk jurisdictions. Therefore, while the client is not high risk, the counterparty, the country, and the transaction are all classified as high risk. 

However, the funds movement is from the client in Singapore to the JV in that high-risk country. Both the client and the counterparty are involved in the same type of business as the JV. There is a lot of commercial rationale for both parties for the JV. Other than the risk factors highlighted, everything else seemed legitimate. 

So, can the firm take this retainer? And if the firm does so, what sort of controls need to be implemented? 

This is probably a retainer that a lawyer can take on, but with the appropriate risk mitigation controls or safeguards. First, ensure that the counterparty is not a ‘nominee’ for the PEP. The lawyer can do this with heightened scrutiny of the correspondence moving between the parties, as well as from the counterparty’s lawyers. Monitor the correspondence for hints of direct PEP involvement. Second, ensure that fund flows do not involve funds from illegal activities or are not moving to illegal activities. Again, the lawyer can do this by monitoring the correspondence and asking questions about unusual funds, if any. Third, document the assessment, the considerations, and the steps for heightened monitoring. 

Of course, if parties want to hide things from their lawyers, they can. In AML checks and monitoring, the lawyer is not the bloodhound trying to find evidence of money laundering. The lawyer is just the guard dog. 

The only situation I strongly advise against continuing or taking a retainer is when the funds clearly are from illegal activities. In such a situation, even the lawyer’s fees may have to be disgorged. So, the lawyer may end up doing work for no fees and lots of headaches.

IX. Pillar Two: Consistent Client Due Diligence

The transition from understanding risk categories to active implementation brings us to Client Due Diligence (CDD), often referred to as “Know Your Client” (KYC). It is the most familiar component of AML compliance. The CDD must be both consistent and effective.

CDD must be consistent in that: 

  • First, it must be consistently and uniformly applied across the entire law firm to every client and every matter. Regulatory audits frequently identify inconsistency across files as a major compliance weakness. 
  • Second, the transaction or instructions must be consistent with what the lawyer knows of the client and of the client’s business. 

Practical Note 7. Standardised forms, centralised AML procedures, and training across the firm help minimise these inconsistencies and ensure that general CDD is applied uniformly.

Effective CDD involves three fundamental steps:

  • Identify: Determine the identity of the client and any ultimate beneficial owners.
  • Verify: Confirm identity using reliable documents or independent sources.
  • Rate: Assess the client’s AML risk level based on relevant factors.

A. Identify: Unmasking the “Real” Client

The first step is a fundamental inquiry: Who is the client, and who is the Ultimate Beneficial Owner (UBO)? The lawyer must determine if the individual in front of the lawyer is the true principal or merely a front for a party behind the scenes.

Identification must occur before a file is opened. Often, scrutinising the Source of Funds acts as a trail of breadcrumbs leading to the “ultimate client” who might otherwise remain hidden. 

For individual clients, this typically requires collecting identifying information such as:

  • full name,
  • identification number (NRIC, FIN, or passport),
  • date of birth,
  • nationality,
  • residential address.

For corporate clients, the process becomes more complex. The lawyer must identify:

  • the company itself,
  • its directors,
  • its shareholders,
  • and any ultimate beneficial owners (UBOs) who control the entity.

In many cases, beneficial ownership may involve multiple layers of corporate shareholding structures. Remember the “Russian doll” example. Lawyers must therefore examine the ownership chain until they reach the individuals who ultimately exercise control.

This exercise is not merely formalistic. Corporate structures are often used precisely because they can obscure beneficial ownership. Accordingly, the identification process should not stop at the first corporate layer.

Practical Note 8. In smaller practices, often new or potential clients first come to the lawyer for an initial consultation, especially if the client comes to know of the firm through social media or similar channels. The client may or may not subsequently engage the firm after such first consult. Sometimes that first consult is free or for a low fee. While firms differ on the depth of checks required before the first consult, the best practice is to at least establish a basic identity profile of that new client.

B. Verify: The Search for Independent Truth

Identification is merely a claim; verification is the proof. Further, the lawyer must not only verify the client’s identity but also the client’s story. 

The lawyer must verify the clients’ identities and their stories using reliable and independent sources:

  • For Individuals, this often means valid government-issued photo identification (e.g., NRIC or Passport).
  • For Entities, this means: (a) official registry records (e.g., ACRA in Singapore or equivalents in other countries or equivalent registries for types of entities), (b) the certificates of incorporation or registration, (c) the latest annual returns or accounts, and (d) the registers (or records) of directors, shareholders and ultimate beneficial owners. The lawyer should inspect the original document where possible and retain a copy for the firm’s records.
  • Newspapers & Independent News Sources: The lawyer can use these sources to check and verify the client’s story. 

The lawyer should inspect the original document where possible and retain a copy for the firm’s records.

Many Practice Management Systems offer integrated AML electronic verification or screening. If the firm does not, it should utilise commercial AML screening databases. These services vary from annual subscriptions to “pay-as-you-go” models. They assist in identifying politically exposed persons, sanctioned individuals or entities, and adverse media. Their value lies in providing an objective audit trail, where appropriate verification of the client and the client’s story has been carried out. Note that entities require significantly more effort and expenses; identifying the UBO through multi-layered, nominee-based, or foreign structures often necessitates a complex “drill-down” through several jurisdictions.

C. Rate: Justifying the Risk Profile

Once the lawyer has identified and verified the party, the lawyer must rate their AML risk. Risk ratings typically fall into three categories:

  • Low risk
  • Medium risk
  • High risk

The risk rating typically considers factors such as:

  • the client’s background,
  • the jurisdictions involved,
  • the nature of the transaction,
  • the source of funds, and
  • the complexity of the structure.

This rating cannot be arbitrary; it must be a justifiable conclusion based on the firm’s risk factors. Consider the “soft” data:

  • Was the client forthright during the intake?
  • Does their story tally with independent records?

Any discrepancy between a client’s narrative and the verified data should immediately influence and escalate the risk rating. The level of due diligence required depends on this risk assessment.

A key practical point is that the reasoning behind the risk rating must be documented. Regulators and auditors will often focus less on the ultimate rating and more on whether the firm has recorded the basis for its decision.

A short but clear explanation is usually sufficient. For example:

“Client is a Singapore-based company with a straightforward ownership structure. Directors and shareholders verified through ACRA records. The transaction is consistent with the client’s stated business activities. No adverse information identified.”

Such documentation demonstrates that the lawyer has applied professional judgment rather than simply completing a checklist.

D. Documentation and Record Keeping

All documents obtained during CDD must be retained as part of the client file or within the firm’s designated AML record system.

AML regulations require records to be retained for at least five years after the end of the retainer (Rule 19).

This includes:

  • identity documents,
  • corporate records,
  • risk assessments,
  • due diligence checklists,
  • notes relating to the verification process.

In practice, it is advisable for firms to store AML documentation in a consistent and easily retrievable format. During regulatory audits, the ability to produce complete documentation quickly often determines whether the firm’s compliance processes are viewed favourably.

X. General Client Due Diligence (General CDD)

The majority of legal matters fall within the category of general client due diligence (general CDD). General CDD represents the level of verification and risk assessment that must be performed whenever a law firm takes on a client, and the risk profile is neither clearly low enough for simplified checks nor elevated enough to trigger enhanced measures.

In practice, most corporate, property, commercial, and advisory matters will fall into this category.

The objective of general CDD is straightforward: the lawyer must obtain sufficient information to understand (Rule 6) who the client is, who ultimately controls the client, and whether the proposed transaction or engagement makes sense in light of the client’s profile.

Under Rule 8, if the client is a company or a trust, the practice must identify the natural person who ultimately owns or controls it. Under AML regulations, references to “legal arrangements” is a reference that includes trusts.

XI. Enhanced Client Due Diligence

When risk factors are elevated, firms must conduct Enhanced Client Due Diligence (EDD) (Rule 13) or “Know Your Client’s Business” checks. EDD involves a deeper inquiry into the client’s financial background and business activities. Typically:

  • SOW & SOF: EDD requires establishing the Source of Wealth (the origin of the client’s entire body of wealth) and the Source of Funds (the origin of the specific money for the transaction).
  • Management Approval:PD 3.2.1 requires senior management to sign off on any business relationship, i.e., retainer, that requires EDD.

EDD is typically required for:

  • politically exposed persons (PEPs),
  • clients from high-risk jurisdictions,
  • complex corporate structures,
  • transactions involving unusually large sums.

For higher-risk matters, lawyers should obtain both a narrative explanation from the client and supporting documentation about the client’s business and background.

If there are no other suspicious circumstances, self-declaration as to source of funds and of wealth may be sufficient — but be careful: if something feels off, a lawyer should ask for independent supporting evidence. Always better to be safe than sorry.

Across Singapore’s broader AML regime, there is an increasing emphasis on independent corroboration and plausibility checks for the source of wealth and the source of funds, beyond mere document collection. 

In a law firm, it is necessary to translate that into a manageable practice. As such, for higher-risk files, get a Source of Funds and a Source of Wealth narrative from the client, plus one or two independent documents that the client says support the narrative. 

Then document the reasoning why the retainer is accepted, what documents were reviewed, the conclusions, and what controls are applied to the matter to justify continuing to act for the client. 

Examples of acceptable documents include one-year audited accounts, three months’ bank statements, or a bank’s recommendation letter. If a lawyer is suspicious of the authenticity of any of the documents, have them certified by a lawyer or notary. And if necessary, call or email the lawyer or notary to confirm that certification.

Can a law firm charge clients for CDD or EDD work? If the matter involves complex multi-party transactions or involves a chain of corporations, the cost of EDD can be high, especially if there is a need to verify overseas documents and do searches. There is no rule prohibiting such charges. However, clients will ask: Isn’t this part of a firm’s cost of doing business? After all, such checks are to protect the firm. 

Practical Note 9. Low risk gets general CDD or even simplified CDD; medium risk gets additional questions; high risk gets Enhanced CDD plus senior management sign-off plus tighter monitoring. 

Practical Note 10. If you had to explain the structure to an auditor in two minutes, could you? If you cannot, you probably need to do Enhanced CDD and seek out more information from the client.

XII. Simplified Client Due Diligence

At the opposite end of the spectrum lies Simplified CDD (SCDD). This approach is permitted only where AML risk is genuinely low based on the documented risk assessment.

Under Rule 13A and PD 3.2.1 Para 136 to 139, SCDD is permitted only when the money laundering or financing of terrorism risk is assessed as low.

  • Eligibility: Typically applies to Singapore Government entities, statutory boards, or companies listed on the SGX (which are already subject to stringent disclosure requirements).
  • Limitations: SCDD does not mean “no due diligence.” The lawyer must still identify the client and verify that they meet the SCDD criteria. SCDD is strictly prohibited if there is any suspicion of ML/FT or if a specific high-risk factor is present.

The scenarios where SCDD is suitable are narrow. The recommendation — and this is a practical, risk-based suggestion — is to reserve simplified CDD only for individual Singapore clients who satisfy all of the following:

  • They are easily contactable and willing to meet physically.
  • They produce proper Singapore identification, such as an NRIC, without hesitation.
  • There are no red flags relating to their identity, source of funds, behaviour, or transaction.
  • The matter itself is ordinary, small in quantum, and consistent with the lawyer’s typical work. ‘Consistent with the lawyer’s typical work’ is important because with his or her experience, the lawyer will be able to spot changes immediately.

If any of these elements are missing, then simplified CDD is not the appropriate level of due diligence.

At a minimum, SCDD should include:

a) A physical face-to-face meeting. This is the strongest low-risk indicator. Meeting the client in person allows the lawyer to verify that:

  • The person matches the identification document.
  • Their story is coherent.
  • Their purpose for engaging the lawyer makes sense.
  • There are no behavioural red flags (evasive answers, inconsistencies, unwillingness to talk about the transaction, and so on).

A video call is helpful, but should not replace a face-to-face meeting when the lawyer is relying on SCDD. Physical interaction decreases impersonation risk and ensures the lawyer has genuine contact with a client.

b) Inspecting and copying the NRIC. During the meeting, the lawyer should:

  • Inspect the NRIC directly — not just accept a scanned copy.
  • Ensure the photo and physical description match the person.
  • Make a photocopy or scanned copy of the file.

This satisfies the requirement of using objective, reliable, independent source documents and provides a record for future audits.

c) A brief, documented risk assessment. Even though the client appears low-risk, the lawyer must still write down why, because the regulator will ask for evidence if the file is sampled.

A simple 3-line assessment is usually enough:

  • “Client is a Singapore individual.”
  • “Matter is low value and consistent with the client’s stated purpose.”
  • “No red flags detected at onboarding.”

No long form needed — just clear reasoning.

Remember that SCDD cannot be used simply because the client is familiar, pleasant, or recommended by someone.

A few dangers to avoid:

Danger #1: Assuming that Singapore clients are always low-risk

This is not the case. A Singapore address or NRIC does not automatically make a client low risk. If the transaction is unusual, the source of funds is unclear, or the client appears evasive, then the lawyer must move to general or enhanced CDD.

Danger #2: Using simplified CDD when the matter itself is risky

A low-risk client can still present a high-risk matter. For example, a simple Singapore client wanting to move money overseas for unclear purposes is not a simplified CDD scenario. The lawyer will need to carry out full CDD and possibly enhanced CDD.

Danger #3: Using simplified CDD for corporate clients

Simplified CDD is almost never appropriate for entities because:

  • Beneficial ownership must be identified and verified;
  • The structure may hide higher-risk individuals;
  • The lawyer may not know who is truly behind the company.

Perhaps the only exception is a long-standing Singapore company with individual shareholders and a long-running domestic business. So, practically, simplified CDD is for individuals, and specifically, individuals who are Singapore-based and low risk.

Practical Note 11.A simple rule-of-thumb you can adopt in your firm. “If you hesitate, even a little, do not use SCDD.” Hesitation means the risk is not low. And remember, if simplified CDD is applied wrongly, the firm may be criticised for under-checking, and this is one of the findings regulators often highlight in audits.

XIII. Reliance on Due Diligence Performed by Third Parties

Another issue that frequently arises in legal practice is whether AML due diligence can be performed by another professional.

In Singapore, the rules (Rule 17) allow lawyers to rely on client due diligence measures performed by third parties, subject to important safeguards. This provision is particularly relevant in situations where multiple professionals are involved in the same transaction—for example, when accountants, corporate service providers, or financial institutions have already conducted due diligence on the client.

However, it is crucial to understand the underlying principle: the lawyer remains ultimately responsible for AML compliance. Reliance on third parties does not transfer responsibility away from the law firm.

A. Scope of Third-Party Reliance

Under the relevant AML rules, lawyers may rely on third parties to perform certain CDD measures, provided that:

  1. Regulated Entities: The third party must be a regulated financial institution or a professional (like another law firm) that is subject to AML/CFT requirements consistent with FATF standards.
  2. Immediate Access: The lawyer must be able to obtain the CDD data/documents from the third party “without delay.”
  3. Jurisdiction Check: If the third party is overseas, the lawyer must ensure that the country has adequate AML/CFT regulations.
  4. Third Party has Adequate AML Compliance Measures: The lawyer must be satisfied that the third party actually has and practices adequate AML compliance measures. This may involve considering the third party’s regulatory status, reputation, and internal compliance procedures.
  5. No Delegation of Risk Assessment: While the lawyer can outsource the collection of documents, the lawyer remains responsible for the risk assessment and the final decision to act.
  6. Document:As always, document the reason why the decision to rely on third-party CDD was made, together with the usual risk assessment and supporting documents.

This arrangement can be practical in situations such as:

  • corporate structuring work involving corporate service providers,
  • transactions where banks have already conducted detailed client verification,
  • matters involving accountants or financial advisers who have completed due diligence.

Nevertheless, reliance must be approached carefully.

The lawyer must ensure that the third party has actually conducted appropriate due diligence and that the information obtained is accessible to the law firm.

While there are no specific rules concerning the outsourcing of AML obligations, Rule 17 suggests that it is possible with the aforementioned safeguards. Since AML will involve clients’ confidential information, the client’s consent is required. The only exception is ongoing due diligence, which has to be performed by the law firm. 

B. Ongoing Due Diligence Cannot Be Performed by Third Parties Nor Outsourced

A particularly important limitation is that ongoing client due diligence cannot be performed by third parties nor outsourced.

While a law firm may rely on another professional to perform initial CDD checks, the responsibility for ongoing monitoring of the client relationship remains with the law firm.

This restriction reflects the practical reality that ongoing monitoring requires familiarity with the legal matter itself. Only the lawyer handling the file will typically have sufficient knowledge of the client’s activities, instructions, and transactions to detect unusual developments.

C. Documenting Third-Party Reliance

Whenever a firm relies on due diligence conducted by a third party, the decision should be documented.

The record should state:

  • which third party performed the due diligence,
  • what checks were performed,
  • why reliance on that party is considered appropriate,
  • confirmation that relevant documentation can be obtained.

This documentation ensures that the firm can demonstrate to regulators that the decision to rely on the third party was made deliberately and with proper consideration of the regulatory safeguards.

D. Practical Considerations

In practice, reliance on third-party due diligence should be treated as a supplementary measure rather than a substitute for internal compliance processes.

Lawyers should remain alert to situations where third-party checks may be incomplete or outdated. If circumstances raise concerns about the adequacy of the information provided, the firm should conduct its own verification.

Ultimately, reliance provisions exist to facilitate efficiency in legitimate transactions. They are not intended to reduce the professional responsibility of lawyers to understand their clients and the matters on which they act.

XIV. CDD Examples

Example one: Conveyancing or Mergers & Acquisition Scenarios.

When onboarding individuals, meet the clients and obtain copies of their NRICs, FIN, or passports. 

When onboarding corporates or entities, run ACRA (or equivalent) searches to identify key directors, shareholders, and the Ultimate Beneficial Owner, if any. 

Collect identification documents of the directors, shareholders, and the Ultimate Beneficial Owner. 

Keep a copy of the entity’s constitution and latest annual returns. 

Do PEP checks for all the individuals identified. Where a company is concerned, this will include the directors, the individual shareholders, and, if the person giving the instructions is not a director, that person. If any of the shareholders is another company, the same exercise will need to be done for that company and so on until everyone in the chain is covered. 

Document the source of funds, complete the records for both the entity and relevant individuals, all the way up the chain, and store the documentation properly. 

Example two: High Net Worth Divorce Scenarios. 

Things to do: meet the client and verify his or her identity from their NRICs or any other photo identity documents. 

Do PEP searches on the client and the spouse. 

Document the source of wealth. Note that this is because there is no transaction involved, so the source of funds checks are not relevant. 

Because the divorce is likely to involve the division of matrimonial assets, a lawyer may need to do ‘know your clients’ business’ checks on both parties. In practice, many such documents are needed anyway for asset tracing and standard matrimonial case disclosures. 

It may become a little difficult if it is a consent divorce where the division of matrimonial assets is agreed upon, and no such documents are exchanged. In such a situation, a lawyer will probably have to ask the client for the documents and explain why they are needed. 

Record and store identity documents and the key source of wealth documentation. 

Example three: Foreign Clients Scenarios. 

For foreign clients, there are additional checks. There is a need to check whether the client is from a high-risk country or is a foreign PEP. 

Onboard foreign individuals by meeting the client (as previously explained, it can be via video) and obtaining copies of their passports. Where the documents are in a foreign language, obtain office translations. Generally, there is no need to obtain official translations unless the lawyer suspects something is amiss.

For foreign corporate clients, meet the client representatives (again, can be online) and obtain:

The certificate of incorporation of the foreign entity, its constitution, its latest annual returns, and the equivalent of an ACRA search to identify directors, shareholders, and the Ultimate Beneficial Owner. 

Remember to do this for all the entities in the entire chain of shareholders. 

Collect copies of their passports. 

Complete the client records for all the entities involved and all the individuals involved, and store all documentation with the file. 

Very often, because there may be a large number of individuals involved, some may question why copies of their NRICs or passports are needed, and they will claim that the Personal Data Protection Act (PDPA) prohibits the making and storage of such copies. Such situations have to be dealt with sensitively. And if a shareholder or director is adamant, the lawyer will have to make an assessment as to the AML risk involved. It helps that usually the full particulars of directors or shareholders are already in the public records of the company. 

On the PDPA point, section 13(b) of the Personal Data Protection Act allows collection, use, and disclosure of personal data (which includes NRIC numbers or equivalent) if authorised by any written law. AML Rule 6(1) requires lawyers to identify and verify the identity of clients and other individuals “using objectively reliable and independent source documents”. PD 3.2.1 in Annex B2 states that identity cards are one of such reliable and independent source documents. Further, in the 1st Schedule Part 3 paragraph 5 of PDPA, specifically states that an organisation (i.e., a law firm) can collect, use, and disclose personal data that is necessary for the provision of legal services.

In short, the PDPA itself allows law firms to collect personal data for the purpose of providing legal services, and the Rules require law firms to collect and make copies of NRICs or equivalent documents.

XV. Pillar Three: Ongoing Monitoring

One of the most important recent developments in Singapore’s AML framework is the formal introduction of ongoing client due diligence under Rule 9.

Many firms historically treated onboarding as the primary compliance checkpoint. Regulators now emphasise that risk can evolve during the course of a matter.

Ongoing monitoring requires firms to review client risk profiles when:

  • new instructions arise,
  • new counterparties appear,
  • payment arrangements change, 
  • transactions deviate from expected patterns, 
  • transactions no longer consistent with the client’s business, or
  • the lawyer comes to know of material changes in the clients’ circumstances.

Triggers should be built into the firm’s processes so that once such events occur, a review of the relationship plus escalation to senior management takes place. 

With ongoing monitoring, a law firm can continue to act for a client suspected of money laundering if certain conditions are met. In the past, it was an absolute prohibition. The three conditions are:

(a) An STR must be made.

(b) The lawyer must substantiate and document the reasons for the continuing engagement notwithstanding the suspicion. The reasons must be set out clearly because, for most firms, the default position is to decline the retainer. 

(c) The law firm must implement commensurate risk mitigation measures, including enhanced ongoing monitoring. It must be something more than the ‘usual’ measures because the lawyer is now acting for a client whom the lawyer suspects of being involved in money laundering.

Periodic reviews are also advisable, particularly for long-running engagements. Some suggested intervals:

  • Clients where STR was lodged: Every 3 months.
  • Other high-risk Clients: Every 6 months.
  • Low-risk Clients: Every 12 months.

The suggested period of 3 months for clients with a STR lodged is “defensive” in nature. With an STR already filed, the law firm potentially has the authorities looking over its shoulders and asking why only annual reviews or half-yearly reviews. To expect monthly reviews is perhaps not reasonable. A 3-month review period is perhaps a safe balance. 

XVI. Pillar Four: Record-Keeping and Reporting

As emphasised a number of times, record keeping is critical to demonstrate that a law firm has complied with its AML obligations. 

A. Documentation and Record Retention

Regulations (Rule 19) require firms to retain AML records for at least five years after the end of the client relationship. These records should be stored in a consistent location and be easily retrievable during regulatory audits.

In practice, the speed with which firms can produce documentation during an audit often influences regulatory assessments.

All documents obtained during general CDD must be retained as part of the client file or within the firm’s designated AML record system. This includes:

  • identity documents,
  • corporate records,
  • risk assessments,
  • due diligence checklists,
  • notes relating to the verification process.

B. Suspicious Transaction Reports (STR)

When lawyers encounter suspicious circumstances, internal reporting procedures should allow the lawyer to escalate concerns to the firm’s Money Laundering Reporting Officer (MLRO). The MLRO then determines whether an external Suspicious Transaction Report should be filed. 

To assist the MLRO, the internal reports should include:

  • the client’s identity,
  • details of the suspicious activity,
  • supporting documentation,
  • the reporting lawyer’s assessment.

Practical Note 12. There is a Simple test. If a lawyer cannot explain clearly on paper why the transaction is still consistent with the client’s circumstances, it’s time to ask further questions and to consider escalation to the MLRO. This is also where documenting the reasons and justifications helps. There is nothing like writing things down to help focus your thoughts.

Every firm must appoint an MLRO (PD 3.2.1 Para 15). The MLRO must have the autonomy to file an STR to CAD, Singapore’s Suspicious Transaction Reporting Office. The filing is made via the SONAR system. SingPass is needed to log in to SONAR.

The duty to report is a personal legal obligation under the Corruption, Drug Trafficking and Other Serious Crimes Act (CDSA).

Lawyers must also observe the no tipping-off rule, which prohibits informing clients that a suspicious transaction report has been filed. Under section 57 of the CDSA, alerting the client that an STR has been filed is a criminal offense. Management must train staff to use neutral language when exiting a high-risk matter. 

So, if the firm is terminating the retainer, use some neutral language. Some suggestions are: 

“Risk Management or Compliance department instructs to decline representation. We are unable to give details.” 

Or 

“The matter did not accord with internal risk management policies. We are unable to give details.”

XVII. Pillar Five: Continuous Reviews and Audits

The final pillar concerns internal oversight and reviews.

Law firms should conduct periodic independent reviews of their AML systems to ensure that policies remain effective and up to date. The purpose is to ensure compliance and keep processes updated. Independent here does not necessarily mean someone from outside the firm, but someone not involved in setting up or carrying out the AML due process. So, it can be another senior partner within the firm.

Since 2024, AML audits by Singapore’s Ministry of Law (“MinLaw”) have increasingly been risk-based. Firms may be selected for audit based on their risk profile, and external auditors are often engaged to conduct these reviews. It is important to note that MinLaw’s AML audit is not only a process audit; it is a compliance audit. So, MinLaw not only checks whether processes are in place but also that they are carried out properly, such that if there is any AML situation, it can likely be detected. 

Preparing for audits should not be an ad-hoc exercise. The firm should develop an AML Audit Preparation Checklist summarising key actions for audit preparation. Firms should also maintain a standing Audit Pack containing key documents such as:

  • internal AML policies such as the IPPC,
  • firm-wide risk assessments,
  • MLRO appointment records,
  • sample forms used for client and matter assessment, and
  • training documentation.

Carry out regular internal “dry runs” to ensure that the checklist suits the firm’s situation. It can also help identify gaps before regulators do. The worst possible moment to discover such gaps is during an actual audit. 

For a ‘dry run’, pick sample files and check for risk assessment, CDD, EDD, where needed, monitoring notes, and record retention. AML audit readiness is not something that can be prepared one week before an audit. Treat it as a part of the firm’s processes, and audits become manageable.

Finally, having the checklist ensures knowledge transfer should key staff involved in AML leave the firm.

XVII. The AML Culture

A. The Importance of Professional Judgment

While AML frameworks provide structured processes, effective compliance ultimately depends on professional judgment.

Red flags—such as unusual transactions, evasive clients, or unexplained funding sources—do not automatically prove wrongdoing. However, they indicate situations where deeper scrutiny is necessary.

Conversely, the absence of obvious red flags does not guarantee that a transaction is legitimate. Sophisticated criminals often design structures specifically to avoid triggering standard compliance checks.

For this reason, lawyers should approach AML compliance as an exercise in critical thinking rather than a checklist.

B. Building an Effective AML Culture

AML compliance cannot be confined to a single compliance officer or department. It requires firm-wide participation.

Junior lawyers and administrative staff are often the first to encounter unusual instructions or suspicious behaviour. Firms should therefore foster a culture in which staff feel comfortable raising concerns without fear of negative consequences.

Encouraging open communication is essential. In many regulatory investigations, problems arise not because suspicious activity went unnoticed, but because individuals hesitated to escalate their concerns.If the junior lawyer or staff, for whatever reason, does not wish to raise an issue with a file or a client, then if things go wrong, the partners or senior management will end up with the ultimate responsibility. The junior lawyer may not want to raise a concern because he or she may not want to appear trivial, trigger-happy, inexperienced, overly cautious, or stupid before their bosses. To encourage openness, tell the lawyers and staff to “trust their instinct”. If they smell something fishy, it probably is. So raise it.

C. Practical Operating Models for Law Firms

Regardless of size, every law firm should aim to implement a practical AML operating model incorporating:

  • clear MLRO responsibilities and escalation pathways,
  • standardised risk assessment forms,
  • structured approval processes for high-risk matters,
  • monitoring triggers within file management systems, and
  • regular staff training.

These measures transform AML compliance from a reactive process into an integrated component of professional practice.

XVIII. Conclusion

AML compliance in Singapore’s legal profession is becoming increasingly demanding. The regulatory framework now requires not only formal policies but demonstrable implementation across all levels of a firm.

Lawyers must conduct structured risk assessments, apply consistent due diligence, monitor client relationships, document decisions carefully, and escalate concerns where appropriate.

These obligations may appear daunting, particularly for smaller firms with limited resources. However, when approached as a structured system rather than a collection of isolated rules, AML compliance becomes manageable.

Ultimately, the objective is not to transform lawyers into investigators. Rather, it is to ensure that the legal profession does not inadvertently provide channels through which illicit funds enter the legitimate economy.

By adopting disciplined procedures, documenting decisions, and fostering a culture of vigilance, law firms can meet their regulatory obligations while continuing to serve clients effectively in a cost-efficient manner.

In the modern legal landscape, AML compliance is no longer a peripheral administrative task. It is an essential component of responsible and professional legal practice.

XIX. Resources

A. Websites

B. Regulations

  • Legal Profession Act 1967 (“LPA”) Part 5A
    • Legal Profession (Prevention of Money Laundering and Financing of Terrorism) Rules (“AML Rules”)
    • Practice Direction on Prevention of Money Laundering & Financing of Terrorism (PD 3.2.1) (“AML PD”)
  • Corruption, Drug Trafficking and Other Serious Crimes (Confiscation of Benefits) Act 1992 (“CDSA”)
  • Terrorism (Suppression of Financing) Act 2022 (“TSFA”) 
  • Regulations under the United Nations Act 2001

By