AppTech System

Blog / Compliance & Security

What Is KYC, and Does Your Singapore Business Need It?

13 Jun 2026 · AppTech System

Know Your Customer onboarding for a Singapore business

KYC — Know Your Customer — is the process of verifying who your customers actually are before, and while, you do business with them. It started in finance, but the idea now touches far more Singapore businesses than people realise. Get it wrong and you risk regulatory penalties, fraud and a PDPA breach all at once. This is the plain-English version: what KYC involves, whether your business is on the hook, how it ties into the PDPA and AML rules, and how to do it securely with SingPass and Myinfo.

What does KYC actually involve?

KYC is four jobs done together: verify identity, collect only the data you need, screen for risk where your sector demands it, and keep records current. For regulated firms it is formalised as customer due diligence (CDD) under MAS Notice 626, which requires record-keeping for at least five years. The building blocks are the same whether you are a bank or a clinic.

  • Identity verification — confirming a customer is who they claim to be, using ID documents or, increasingly, SingPass and Myinfo.
  • Collecting the right details — the information you legitimately need, captured once and stored properly, not everything you could possibly ask for.
  • Risk and sanctions screening — checking customers against watchlists and assessing risk where your industry requires it.
  • Ongoing monitoring and record-keeping — keeping records current and, for MAS-regulated firms, retaining them for at least five years rather than verifying once and forgetting.

For companies, KYC also reaches the people behind the customer. Under ACRA rules, a beneficial owner is broadly anyone holding more than 25% of shares or voting rights, or who exercises significant control. CDD means identifying those controllers, not just the person signing the form, which is why national company data matters so much later in this guide.

Does your business actually need it?

It depends on whether you are legally obligated or doing KYC by necessity. MAS-regulated financial institutions must do formal KYC under binding notices such as Notice 626. Everyone else who collects identity documents or sensitive data at sign-up is effectively doing a lighter version, and the PDPA still applies. The split below is the quickest way to place yourself.

Legally obligated under AML/CFT

If you are a regulated financial institution, KYC is mandatory and prescriptive. The clearest examples:

  • Banks, finance companies and credit-card issuers
  • Payment-service providers and remittance businesses
  • Fund managers, capital-markets and insurance intermediaries
  • Corporate service providers, and certain precious-stones and precious-metals dealers

These firms must run CDD at onboarding and on an ongoing basis, apply enhanced due diligence for higher-risk customers and politically exposed persons, monitor transactions, file suspicious-transaction reports, and keep records for at least five years.

Light KYC by necessity

Plenty of businesses outside finance verify identity every day without calling it KYC. Clinics, education providers, property and rental businesses, and B2B platforms all collect identity documents or personal data at sign-up. A medical practice running clinic management software, for instance, captures NRIC and contact details before the first consult. If you collect identity data, you are effectively doing KYC, and it should be done properly under the PDPA.

A quick self-check: do you onboard customers, verify identity, or collect sensitive personal data such as NRIC, passport or financial details? If yes to any, you have a KYC-shaped responsibility, even if MAS rules do not apply to you. The depth required scales with your sector and your risk, not with whether anyone calls it KYC.

Why does this matter now?

Because Singapore has shown it will enforce. On 4 July 2025, MAS imposed S$27.45 million in composition penalties on nine financial institutions for anti-money-laundering control failures, and banned four individuals. The failures named were ordinary KYC gaps: weak customer risk assessment, failure to corroborate source of wealth, and inadequate transaction monitoring.

Those penalties traced back to the 2023 money-laundering case, in which roughly S$3 billion in cash, property, cryptocurrency and luxury goods was seized or surrendered (background). Perpetrators had falsified documents to verify their source of funds, which is exactly the failure point KYC is meant to catch. The lesson for any business: identity and source-of-funds checks are not box-ticking, and regulators read the records after the fact.

MAS figures cited above (S$27.45m, nine institutions, four individuals) are from the official MAS enforcement action dated 4 July 2025. Per-bank breakdowns reported in the press are secondary and not reproduced here.

Are KYC and PDPA the same job?

Effectively, yes. KYC means collecting more sensitive personal data, which means the PDPA applies in full: consent, purpose limitation, retention limits and reasonable security. The PDPC NRIC guidelines allow NRIC collection only where the law requires it or where you must verify identity to a high degree of fidelity. Even a partial NRIC counts as personal data.

The biggest near-term change is authentication. The PDPC has announced that organisations must stop using NRIC numbers as a password or authenticator by 31 December 2026, with stepped-up enforcement, including directions and financial penalties, from 1 January 2027. If your sign-up flow uses the last few NRIC digits as a login check, that design needs to change.

The simplest way to see the overlap is side by side: the same data, two duties.

Same customer data KYC / AML duty PDPA duty
Identity (name, NRIC, ID) Verify the customer is who they claim Collect only with consent and a clear purpose
Beneficial owners Identify controllers above 25% (CDD) Limit use to the verification purpose
NRIC number Used to verify identity to high fidelity Not for authentication after 31 Dec 2026
Transaction history Monitor for suspicious activity Secure with reasonable safeguards
The records Keep at least 5 years (MAS Notice 626) Do not retain beyond the stated purpose

Sources: MAS Notice 626 (record-keeping and CDD); ACRA (beneficial-owner threshold); PDPC NRIC Advisory Guidelines and the PDPC 31 Dec 2026 authentication deadline. Confirm current wording on each authority's site.

How do you do KYC securely with SingPass and Myinfo?

Through Singapore's national digital-identity rails. Individuals authenticate with SingPass, and with consent Myinfo returns verified government data: name, NRIC, registered address and more. MAS recognises Myinfo as a reliable, independent verification source, which reduces the need to collect and re-check separate identity documents. That is electronic KYC, or e-KYC, and it is faster and harder to forge than email attachments.

For verifying companies rather than individuals, Myinfo business does the same job. Businesses authenticate with Corppass, and Myinfo business returns official ACRA data: registered company name, UEN, registered address, business activities, incorporation date and company officers. For CDD that needs beneficial-owner checks, pulling authoritative company data straight from source beats keying it in by hand.

[UNIQUE INSIGHT] The e-KYC happy path is short: customer consents, authenticates with SingPass or Corppass, Myinfo returns verified fields, and your system stores a time-stamped, consented record. In our experience building onboarding flows, the value is not just speed. Because the data arrives pre-verified and consented, you also get a cleaner PDPA story: clear purpose, minimal collection, and an audit trail of exactly what the customer agreed to.

Manual KYC versus a compliant system

Manual KYC, collecting documents over email and storing them on shared drives, is the single most common way Singapore SMEs drift into a PDPA breach. The 2025 MAS penalties were partly about weak monitoring and record-keeping, and you cannot monitor or evidence what lives in someone's inbox. A purpose-built flow turns those obligations into defaults rather than good intentions.

What good looks like Manual KYC System-based KYC
Identity check Emailed ID photos, manually eyeballed SingPass / Myinfo, pre-verified
Storage Shared drive or inbox Encrypted, access-controlled store
Audit trail None, or scattered email threads Full log of who saw and changed what
Access control Open to anyone with the folder link Role-based access (RBAC)
Retention Files kept forever, deleted ad hoc Retention rules applied automatically
PDPA risk High and hard to evidence Managed and demonstrable

The better approach is software that handles onboarding, verification and secure storage in one compliant flow, with audit trails and role-based access. That is what our Automiq platform does: it manages customer data and KYC in a secure, PDPA-aligned environment, so verification and compliance happen together. If you are unsure where you stand today, our PDPA Readiness Check is a quick gut-check, and our guide on handling customer data securely goes deeper on storage and access.

When should you build custom instead?

[PERSONAL EXPERIENCE] For most businesses, a configured off-the-shelf tool covers KYC well, and you should not build what you can buy. The cases where custom wins are specific: unusual onboarding journeys that no product models, deep integration between verification, your core system and a regulator's API, or multi-entity groups whose risk rules differ by branch. That is the work we do.

If your KYC needs to plug SingPass, Myinfo and screening into a workflow you already run, a tailored build or a platform extension is usually the cleaner answer. Our software development services and workflow automation work cover exactly this, and you can scope it with us on the contact page. For the broader buy-versus-build decision, our guide on choosing a software development company walks through the trade-offs.

Disclaimer: This is a general explainer, not legal or regulatory advice. KYC, AML/CFT and PDPA obligations vary by sector and are set by the relevant Singapore authorities — MAS for financial services, the PDPC for data protection, and ACRA for company controller registers. Rules, notices and deadlines change; confirm your specific obligations on the official MAS, PDPC and ACRA sites and with a qualified advisor before acting.

About AppTech System — AppTech System is a Singapore custom-software team and the people behind the Automiq and BooknGo platforms, building web, mobile, AI and enterprise software for businesses in regulated industries. Talk to us.

Need to collect and verify customer data — compliantly?

See Automiq

All articles