RICHELLE LUGTU · AML/CFT COMPLIANCE SPECIALIST & FORMER MLRO

Compliance training built to the standard of a regulator-supervised framework.

A working capability showcase spanning two Singapore regulatory frameworks — the Corporate Service Provider (CSP) regime under ACRA, and the Capital Markets Services (CMS) Licence Holder regime under MAS. Instructional design, regulatory-content methodology, and policy drafting applied to both. Click through either curriculum, try the working assessment, and view a sample certificate.

Prepared by: Richelle Lugtu · rklugtu@gmail.com · +65 8230 6284 (WhatsApp)

What this showcase is

A capability demonstration, not a delivered course. Two regulatory suites are previewed side by side — Singapore CSP/ACRA and MAS CMS — each with its own topic curriculum in the left sidebar. A small number of screens are unlocked in each to demonstrate instructional and visual quality; the rest open a request-access note. A working sample assessment, sample certificate, and a sample training-records view let you choose which regime to preview.

Full courses are built to include a randomised assessment pool, an 80% pass gate, retake-from-scratch logic, an auto-issued certificate on pass, and a training-records tracking layer.

Two regulatory frameworks, one methodology

The CSP/ACRA suite reflects production-grade work — frameworks built and delivered for registered Corporate Service Providers under the CSP Act 2024 and ACRA's Guidelines for Registered CSPs. The MAS CMS suite applies the same instructional and policy-drafting methodology to the Capital Markets Services Licence Holder framework under MAS Notice SFA 04-N02, as a worked demonstration of cross-framework capability.

What travels between the two: the instructional structure, the citation discipline, and the assessment architecture. What does not travel: the regulatory facts themselves — each suite is verified independently against its own regulator's current statutes, notices, and guidelines.

Navigation hub

Choose what to preview

Two regulatory suites, previewed independently. Pick any subject area to enter its curriculum — each card opens to a course cover and a left-hand topic sidebar showing the full curriculum, with a handful of subsections unlocked.

Singapore CSP / ACRA Compliance Suite

Production-grade framework — Corporate Service Providers under the CSP Act 2024 and ACRA's Guidelines for Registered CSPs.

MAS CMS Compliance Suite

Methodology demonstration — Capital Markets Services Licence Holders under MAS Notice SFA 04-N02.

Working samples — choose your regime

These three samples work across either suite — pick CSP/ACRA or MAS CMS when you open them.

Capability Showcase — Framework Documents

IPPC, Manuals & SOP Suite

Click through the document tree below the way a client would receive it — Master Policy, methodology guides, reference tools, registers and desk cards. Built for a Singapore CSP; structured so the same architecture transfers to any regulated business, sector or jurisdiction.

Previews use the real callout-box design system (colour-coded Policy, Cross-reference, Regulatory Basis, Internal Policy Note and Warning boxes) — but every word of content shown is invented sample text, not the delivered document.
1
Master Policy Manual
11
Annex Groups (A–K)
40+
Component Documents
4
Doc Types: Policy · Guide · Reference · Register
document-suite-preview.local/samples
Previewing: Master Policy Manual
Word · .docx

How Engagement Works

Same architecture, two ways to receive it.

Off-the-Shelf Template Suite

Fixed-price · fastest delivery
  • Full Master Policy + Annex Suite as shown above
  • Generic placeholders throughout ([FIRM NAME], [DATE], [NAME]) — you complete these
  • Regulatory basis lines built for the stated jurisdiction/sector
  • Delivered as editable Word / Excel / PDF files
  • You review, adapt and adopt — template only, not legal advice
Policy architecture · document engineering · regulatory-content methodology
Preview content shown is illustrative sample material only and does not represent the text, figures or structure of any client deliverable. All frameworks are professional template products only — not legal, regulatory or compliance advice. Client is responsible for review, verification, customisation and adoption. Delivery of a document is not compliance.
About the consultant

Compliance training built the way a regulator would want it built

RL
Richelle Lugtu
AML/CFT Compliance Specialist · Former MLRO

8+ years of Singapore-based AML/CFT compliance work, including a former appointed MLRO and Compliance Manager role for a registered corporate service provider and filing agent — owning an AML/CFT framework end-to-end, filing STR/SARs, running internal audits, and delivering staff training across a regulated business. The CSP/ACRA suite in this showcase reflects that production experience directly.

The MAS CMS suite applies the same instructional and policy-drafting methodology to a framework not previously worked in production: the Singapore MAS Capital Markets Services (CMS) Licence Holder regime under MAS Notice SFA 04-N02. Every regulatory fact on the unlocked screens in both suites is drawn and cited directly from the relevant regulator's own statutes, notices, and guidelines — not asserted from memory. That is the point of showing both side by side: the methodology is portable across regulators and sectors, and the regulatory-verification discipline is what makes that portability safe to sell.

What "built the way a regulator would want it built" means in practice

1

Every fact is sourced

Penalty figures, filing timelines, and statutory citations are drawn from the current text of the governing Notice, Guidelines, or Act — never from recollection. Sources are shown in a citation footer on every content screen.

2

Learning outcomes are anchored

Every lesson and every assessment question is built to answer five things: what the learner will know, which obligation it supports, what they should recognise or escalate in real practice, how it's tested, and why the answer is right or wrong.

3

The firm's own procedures still govern

Training teaches the regulatory methodology — it does not prescribe a firm's specific thresholds, escalation timeframes, or operational detail. Where a course and a firm's own policy differ on an operational point, the firm's policy governs. That boundary is stated explicitly, not blurred.

4

Assessment is real, not decorative

A randomised question pool, an 80% pass gate, retake-from-scratch logic, instant rationales on every answer, and an auto-issued certificate — the mechanics a training record actually needs to hold up under review.

Deliverables this methodology produces

Let's talk about what you need built.

Whether it's a full interactive course, a policy and procedures framework, or a review of what you already have — happy to walk through it on a call.

Module disclaimer

What this showcase is, and is not

Training content only

  • This showcase, and the full courses it previews, teach learners what their AML/CFT/CPF, PDPA, and other regulatory obligations are under two separate frameworks — the Singapore CSP regime under ACRA, and the Singapore MAS CMS Licence Holder regime under MAS Notice SFA 04-N02. They do not constitute legal advice, regulatory advice, or compliance advice of any kind.
  • They do not replace a firm's own AML/CFT Policy & Procedures Framework or IPPC, internal controls, or professional advice.
  • Completing a preview screen, a sample assessment, or a full course does not, in itself, satisfy any specific ACRA or MAS training expectation, nor does it guarantee the outcome of an ACRA inspection or a MAS inspection of training records.
  • A firm licensing any full course or policy framework built on this methodology is solely responsible for confirming the content meets its own training and compliance obligations, and for adapting any material to its own regulated-activity mix and risk profile.
  • Regulatory facts in the CSP/ACRA suite are sourced from the CSP Act 2024, the CSP Regulations 2025, ACRA's Guidelines for Registered CSPs, the CDSA, TSOFA, the UN Act 2001, and the PDPA. Regulatory facts in the MAS CMS suite are sourced from MAS Notice SFA 04-N02, its accompanying MAS Guidelines, the Securities and Futures Act, the CDSA, and the PDPA. Both are current as at the date shown on each screen's citation footer. Regulation changes — every regulatory fact should be re-verified at the point any full course is commissioned, and refreshed periodically thereafter.

Methodology, not operational prescription. Each preview screen teaches the regulatory framework, methodology, and recognition skills that a compliance programme should satisfy. It does not prescribe operational specifics — thresholds, scoring weights, escalation timeframes, or procedural detail — because a firm's own adopted policies and procedures set those according to its risk appetite and the applicable regulator's recognised practice. Where a screen's regulatory framing and a firm's adopted procedures differ on an operational point, the firm's procedures govern.

This is a capability showcase prepared for professional review, not a licensed or delivered training product. Regulator framework, citations, and instructional structure shown here demonstrate methodology and are not a substitute for a live regulatory-verification session at the point of a real engagement.

AML / CFT / CPF Foundations

AML / CFT / CPF Foundations for CMI Staff

🔒 Preview — full course not included
Audience
CMI staff with customer contact, onboarding, or dealing duties
Duration
~75 minutes
Assessment
10 questions, 80% pass
Regulator framework
Primary: MAS · Secondary: STRO, MHA

© Richelle Lugtu. Course content, assessment design, and certificate template are proprietary. Online course access is licensed to engaged clients on subscription or licence terms.

Why this course exists

MAS Notice SFA 04-N02 on the Prevention of Money Laundering and Countering the Financing of Terrorism sets direct obligations on Capital Markets Intermediaries (CMIs) and their staff — customer due diligence, screening, ongoing monitoring, and suspicious transaction reporting. The CDSA and the Terrorism (Suppression of Financing) Act 2002 sit alongside it as the statutory basis for reporting and disclosure. This course gives every staff member the working knowledge to recognise, escalate, and document AML/CFT/CPF risk in day-to-day work.

By the end of this course, learners will be able to:
  • Identify a customer, connected parties, and beneficial owners in line with MAS Notice SFA 04-N02.
  • Apply customer due diligence (CDD) at onboarding, including the screening timing and transaction-value triggers.
  • Recognise the higher-risk indicators that escalate a customer to enhanced due diligence (EDD).
  • Apply a risk-based approach to ongoing monitoring and periodic screening.
  • Recognise suspicious transaction indicators and the internal escalation pathway.
  • State the STR filing timeline expectation and why it differs for sanctioned parties.
Important — please read This training is provided for general educational and internal training purposes only. It is not endorsed by, accredited by, affiliated with, or a substitute for any regulator-prescribed certification, examination, licensing, or mandatory training. It does not constitute legal, regulatory, or professional advice.
Lesson 1.3 · Preview

The three stages of money laundering

Money laundering generally moves through three distinct stages: placement, layering, and integration. Each stage has different exposure for a CMI — step through the diagram below to see each in turn.

Placement → Layering → Integration
CASH BANK deposit Shell Co A (Jurisdiction X) Shell Co B (Jurisdiction Y) Shell Co C (Jurisdiction Z) BANK PROPERTY "investment"
Stage 1 of 3
Placement

The physical disposal of the benefits of criminal activity. Cash or assets are introduced into the financial system through deposits, exchanges, or asset purchases.

A CMI rarely sees placement directly, but may see its consequences — for instance, an account funded by an unexplained cash-equivalent deposit shortly before trading begins.
SourceMAS Guidelines to Notice SFA 04-N02, paragraph 13 (Suspicious Transactions Reporting) and Appendix B (Examples of Suspicious Transactions) — placement, layering, and integration are the standard FATF typology these Guidelines apply to CMI red-flag recognition.
Lesson 1.6 · Preview

Why CMIs are gatekeepers

A Capital Markets Intermediary occupies a structural position that financial criminals find useful. The CMI onboards the customer. The CMI holds the dealing or advisory relationship. The CMI executes the transaction. The CMI screens against sanctions and ML/TF risk sources.

That is exactly why MAS regulates CMIs under the Securities and Futures Act and imposes AML/CFT obligations through Notice SFA 04-N02. The Notice exists to detect and prevent money laundering, the financing of terrorism, and the financing of proliferation of weapons of mass destruction through the capital markets channel. The CMI is part of the front line.

The diagram below shows how a CMI-held customer relationship can sit inside a typical layering structure. Click each entity to see what role it plays.

Click each entity to see what it represents in the laundering chain.The CMI-held relationship sits at the centre — that is the structural position MAS cares about.
Criminal source (predicate offence proceeds) Foreign Shell Co (opaque jurisdiction) Trading account, Singapore (onboarded and held by the CMI) ★ Where the CMI sees the customer Apparent legitimate asset (liquidated holdings · property · investment)
Click any entity in the diagram to see what role it plays in the laundering chain — and where the CMI fits in.
Origin

Criminal source

The proceeds of a predicate offence — fraud, corruption, drug trafficking, or other serious crime. The CMI almost never sees the source directly. The CMI sees what comes after.

If funds moving through a customer's account look unusual or unexplained, the source you cannot see is what your suspicion attaches to.
Layering vehicle

Foreign shell company

An offshore entity in a jurisdiction with limited transparency. Used to introduce distance between the criminal source and the apparently legitimate destination. May have opaque ownership, no real activity, and a single funding account.

Foreign shell companies are not illegal — but a customer whose ownership trail leads to an opaque foreign vehicle is a CDD and screening priority under MAS Notice SFA 04-N02 paragraph 8.
Where the CMI works

Trading account, Singapore

The account or dealing relationship the CMI has onboarded and holds. From a launderer's perspective, this relationship adds a layer of respectability — a regulated intermediary, real account documentation, apparently legitimate trading activity.

This is the position that creates the CMI's regulatory exposure. MAS expects the CMI to know who the customer really is, what the trading activity is for, and to recognise when the pattern does not make commercial sense.
Integration destination

Apparently legitimate asset

The end-point of integration. The funds re-enter the legitimate economy as a liquidated holding, a property-linked investment, or a business acquisition that looks ordinary. By this stage the audit trail back to the criminal source is heavily obscured.

A CMI may not see the eventual asset purchase — but may see the account being prepared for it (a large unexplained inflow, a change in trading pattern, a change of settlement instructions).
Examined 0 of 4 entitiesClick any entity to begin
SourceSecurities and Futures Act 2001, Part IV (Capital Markets Services). MAS Notice SFA 04-N02, paragraphs 6 and 8 (Customer Due Diligence, Enhanced Customer Due Diligence).
Lesson 1 · Knowledge Check 1 of 2 · Preview

Identify the stage

Knowledge Check

Which stage of money laundering is best illustrated below?

A customer opened a trading account with the CMI three weeks ago. The account now receives and on-pays funds rapidly between accounts held by three other corporate entities in different jurisdictions. There is no apparent trading activity — money in, money out, no positions taken.
Choose the best answer.

Knowledge checks are formative — they help learners consolidate. Answers are not scored toward the terminal assessment. The full course contains 12 knowledge checks across 6 lessons.

AML preview screens demonstrate the instructional and citation pattern for course CM-A-00 (MAS CMS product range). The full course is designed to contain 6 lessons across approximately 80 screens, with 12 knowledge checks, a 10-question terminal assessment, and certificate.
PDPA & Data Protection

PDPA & Data Protection for CMS Licence Holder Staff

In Progress
🔒 Preview — full course not included
Audience
All staff handling client or counterparty personal data
Duration
~60 minutes
Assessment
10 questions, 80% pass
Regulator framework
Primary: PDPC · Secondary: MAS

© Richelle Lugtu. Course content, assessment design, and certificate template are proprietary. Online course access is licensed to engaged clients on subscription or licence terms.

Why this course exists

A CMS licence holder handles personal data of customers, beneficial owners, representatives, and employees — in volume, and often across borders. The Personal Data Protection Act 2012, as amended in 2020, sets eleven Data Protection Obligations, enforced separately from (and alongside) the record-keeping duties MAS Notice SFA 04-N02 places on CDD data. Failure attracts financial penalties and reputational consequences. This course translates the Act into the daily decisions a licence holder's staff actually make.

By the end of this course, learners will be able to:
  • Identify when the PDPA applies to a piece of work and which obligations engage.
  • Apply the consent, notification, and purpose-limitation obligations at the point of data collection.
  • Recognise the conditions that trigger mandatory data breach notification to the PDPC and to affected individuals.
  • Apply the retention-limitation obligation where it interacts with MAS record-keeping requirements on CDD data.
  • Understand the role and authority of the Data Protection Officer inside a licence holder.
Important — please read This training is provided for general educational and internal training purposes only. It is not endorsed by, accredited by, affiliated with, or a substitute for any regulator-prescribed certification, examination, licensing, or mandatory training. It does not constitute legal, regulatory, or professional advice.
Topic 2 · Preview

The eleven Data Protection Obligations — at a glance

Preview screen — each obligation is treated in depth in the licensed course

The Personal Data Protection Act organises a licence holder's duties around eleven obligations. They apply collectively — a firm that consents correctly but transfers poorly is still in breach. Every member of staff needs the map; the licensed course teaches each obligation in operational detail.

1

Consent

Obtain consent for collection, use, or disclosure of personal data — and respect its withdrawal.

2

Purpose Limitation

Use personal data only for purposes a reasonable person would consider appropriate.

3

Notification

Tell individuals what their data will be used for, before or at the point of collection.

4

Access & Correction

Provide individuals access to their data on request, and correct errors.

5

Accuracy

Make reasonable effort to keep personal data accurate and complete.

6

Protection

Protect personal data with reasonable security arrangements.

7

Retention Limitation

Cease retention when the purpose no longer requires it and no legal duty compels it — noting MAS record-keeping requirements on CDD data as a distinct legal duty.

8

Transfer Limitation

Transfer personal data outside Singapore only if a comparable standard of protection is in place.

9

Accountability

Develop policies and practices, designate a DPO, and make information about both available.

10

Data Breach Notification

Notify the PDPC and affected individuals when a notifiable data breach occurs.

11

Data Portability

On request, transmit an individual's data to another organisation in a commonly-used format. (In force on appointed day.)

Source: Personal Data Protection Act 2012, ss.13–26E; PDPC Advisory Guidelines on Key Concepts in the PDPA.

Topic 8 · Preview

Data Breach Notification — when, who, how fast

Preview screen — full topic includes the decision tree, drafting templates, and case scenarios

Not every data incident is a notifiable breach. The Data Breach Notification Obligation requires assessment, then action, on a tight clock. A firm that gets the timing wrong compounds the original breach with a regulatory one.

The two-part test

A data breach must be notified if it (a) results in, or is likely to result in, significant harm to affected individuals, or (b) is of significant scale — affecting 500 or more individuals. Either limb on its own triggers the obligation.

The notification timeline

StepTimingAction
1On suspicion of a breachAssess expeditiously whether the incident meets the notifiable threshold. Deliberately prolonging the assessment does not defer the clock.
2No later than 3 calendar days after determining the breach is notifiableNotify the Personal Data Protection Commission (PDPC).
3As soon as practicableNotify each affected individual where the breach is likely to result in significant harm — unless a s.26E exception applies (effective remedial action, technological protection already in place, or law-enforcement direction).

Common breach patterns at a CMS licence holder

Misdirected emails carrying client onboarding or CDD packs, lost devices with unencrypted client folders, vendor or platform compromise affecting hosted client data, and access-control failures exposing beneficial-ownership records. Each plays out differently against the two-part test — the licensed course walks scenarios through to the notification decision.

Source: Personal Data Protection Act 2012, ss.26B–26E; PDPC Guide on Managing and Notifying Data Breaches.

Sample knowledge check

Knowledge check — PDPA

One sample question. Full courses use a 10-question randomised pool with 80% pass gate.
Question 1 of 1 (Sample)
A staff member emails a client onboarding pack — including NRIC scans of three directors and one beneficial owner — to the wrong recipient. The error is discovered the same day; the recipient confirms deletion in writing. Which response best reflects the PDPA Data Breach Notification Obligation?
Rationale

Sanctions & Targeted Financial Sanctions

Sanctions & TFS for CMI Staff

In Progress
🔒 Preview — full course not included
Audience
CMI staff with onboarding, screening, or dealing duties
Duration
~45 minutes
Assessment
10 questions, 80% pass
Regulator framework
Primary: MAS · Secondary: MHA, MFA

© Richelle Lugtu. Course content, assessment design, and certificate template are proprietary. Online course access is licensed to engaged clients on subscription or licence terms.

Why this course exists

Targeted financial sanctions in Singapore sit on the United Nations Act 2001 and the regulations made under it, working alongside MAS Notice SFA 04-N02's screening requirements. A sanctions hit is not treated the same way as an ordinary suspicious-transaction concern — the escalation timeline compresses sharply once a sanctioned party is identified. This course teaches CMI staff who must be screened, when, and what happens once a match is confirmed.

By the end of this course, learners will be able to:
  • Identify who must be screened under MAS Notice SFA 04-N02 — the customer, connected parties, natural persons acting on the customer's behalf, and beneficial owners.
  • State the screening triggers: onboarding, the S$20,000 transaction threshold, periodic re-screening, and list-update triggers.
  • Recognise a confirmed sanctions match and distinguish it from an ordinary AML/CFT suspicion.
  • State the compressed STR filing timeline that applies once a sanctioned party is identified, and why it differs from the general timeline.
Important — please read This training is provided for general educational and internal training purposes only. It is not endorsed by, accredited by, affiliated with, or a substitute for any regulator-prescribed certification, examination, licensing, or mandatory training. It does not constitute legal, regulatory, or professional advice.
Topic 2 · Preview

Who gets screened, and when

Preview screen — full topic includes list-source detail and false-positive handling

MAS Notice SFA 04-N02 requires a CMI to screen against money laundering and terrorism financing information sources, and against lists and information provided by MAS or other relevant Singapore authorities. Screening is not a one-time onboarding step — it recurs on defined triggers.

Who must be screened

1

The customer

Every customer, whether a natural person or a legal person or arrangement.

2

Natural persons acting on the customer's behalf

Anyone appointed to operate the account or instruct on the customer's behalf.

3

Connected parties

Directors, partners, and other parties connected to the customer as defined in the Notice.

4

Beneficial owners

The natural person(s) who ultimately own or control the customer.

When screening is triggered

TriggerTiming
Establishing business relations with a new customerWhen, or as soon as reasonably practicable after, business relations are established.
A transaction for a customer without an established relationshipWhere the transaction value exceeds S$20,000 (excluding certain digital CMP token transfers, which have their own trigger).
Ongoing relationshipOn a periodic basis, risk-based.
List or information updatesWhenever MAS or another relevant Singapore authority updates the lists or information the CMI screens against.

Source: MAS Notice SFA 04-N02, paragraphs 6.39–6.40 (Screening).

Topic 5 · Preview

A sanctions hit changes the clock

Preview screen — full topic includes the internal escalation script and false-positive close-out

An ordinary suspicious-transaction concern and a confirmed sanctions match are not filed on the same timeline. Once a party is identified as sanctioned, or acting on behalf of or under the direction of a sanctioned party, the filing window compresses sharply.

General STR timeline

The internal process for deciding whether a matter should be referred to the Suspicious Transaction Reporting Office (STRO) should be completed without delay. Filing should not exceed 5 business days after suspicion was first established, absent exceptional or extraordinary circumstances.

Sanctioned-party timeline

Where the matter involves a sanctioned party, or a party acting on behalf of or under the direction of one, the CMI should file the STR as soon as possible, and no later than 1 business day after suspicion was first established.

An STR filed with STRO on a sanctions-related matter also satisfies the corresponding reporting obligation under the Terrorism (Suppression of Financing) Act 2002, where that obligation applies. Separately, the statutory duty to disclose knowledge or suspicion connected to drug dealing or criminal conduct under CDSA s.45(1) applies "as soon as is reasonably practicable" — failure is a criminal offence carrying a fine of up to S$250,000 or up to 3 years' imprisonment (or both) for an individual, and a fine of up to S$500,000 for an entity.

Source: MAS Guidelines to Notice SFA 04-N02, paragraph 13-1; CDSA 1992, s.45(1) and s.45(3).

Sample knowledge check

Knowledge check — Sanctions & TFS

One sample question. Full courses use a 10-question randomised pool with 80% pass gate.
Question 1 of 1 (Sample)
Periodic screening surfaces a name match between a customer's beneficial owner and a party designated under a UN Act 2001 sanctions list. The match is confirmed, not a false positive. What is the correct filing expectation?
Rationale

Cybersecurity & Cyber Hygiene

Cybersecurity & Cyber Hygiene for CMS Licence Holder Staff

In Progress
🔒 Preview — full course not included · Includes interactive screen
Audience
All staff with email and system access
Duration
~50 minutes
Assessment
10 questions, 80% pass
Regulator framework
Primary: MAS · Secondary: CSA, PDPC

© Richelle Lugtu. Course content, assessment design, and certificate template are proprietary. Online course access is licensed to engaged clients on subscription or licence terms.

Why this course exists

A CMS licence holder is a high-value target. It handles client funds, holds account and beneficial-ownership records, and sits on the trust that lets a fraudster impersonate a client or a director. The threats are not abstract — phishing, business email compromise, credential theft, and ransomware all hit regulated financial firms. This course gives staff the situational awareness and reflexes to be the firm's first line of defence rather than its weakest link.

By the end of this course, learners will be able to:
  • Recognise the dominant threats aimed at regulated financial firms and the vectors they arrive on.
  • Identify phishing and business email compromise indicators in a real email.
  • Apply the first 24 hours of incident response — contain, escalate, preserve, document.
  • Understand reporting duties to the Singapore Police Force, MAS, and the PDPC where personal data is involved.
  • Apply staff-level controls that reduce the firm's overall exposure.
Important — please read This training is provided for general educational and internal training purposes only. It is not endorsed by, accredited by, affiliated with, or a substitute for any regulator-prescribed certification, examination, licensing, or mandatory training. It does not constitute legal, regulatory, or professional advice. Cybersecurity content in the licensed course is verified against the current MAS cyber hygiene expectations and CSA guidance at the point of drafting — this preview keeps to general, well-established practice pending that verification step.
Topic 2 · Interactive preview

Phishing Email Inspector — find five red flags

Interactive screen — click anywhere on the email that looks suspicious

Below is a phishing email impersonating a firm's bank. Five elements are red flags. Click each one to identify it. Each correct hit reveals what the indicator is and why it matters.

Inbox · 1 message Today, 10:42
From: Pacific Crown Bank Singapore <support@pacificcrown-secure-sg.com>
To: finance@yourfirm.com.sg
Subject: URGENT: Account verification required within 24 hours

Dear Valued Customer,

We have detected unusual activity on your corporate account. To prevent suspension, please verify your account details here within the next 24 hours.

Failure to act will result in your account being permanently suspended and all pending transactions cancelled.

Please find attached the verification form: Verification_Form.zip

Yours sincerely,
Pacific Crown Compliance Team

0 of 5 red flags found

All five red flags identified

In a real inbox you may not have five clear signals — sometimes you have one. The discipline is the same: stop, check the sender domain, hover the link, refuse the urgency. When in doubt, escalate to your firm's IT or Compliance Officer before clicking. The licensed course covers business email compromise variants, voice-call follow-ups, and the first-24-hours response if a phishing email has been actioned.

Topic 7 · Preview

Incident response — the first 24 hours

Preview screen — full topic includes decision flows and reporting templates

The first day of a cyber incident shapes the next six months. Most permanent damage — loss of evidence, regulatory non-compliance, customer-trust erosion — happens in the hours immediately after detection, when staff act on instinct rather than procedure. The framework below is what a firm's AML/CFT and IT security policies should already specify; this screen makes it learnable.

1

Contain

Disconnect affected devices from the network. Disable compromised accounts. Stop the spread before investigating the source.

2

Escalate

Notify your Compliance Officer / MLRO and IT lead — by phone, not email, in case email is compromised. Document who was told and when.

3

Preserve

Do not power off, wipe, or "clean up" affected systems. Preserve logs, screenshots, and copies of suspicious messages. Forensic value disappears with each action taken.

4

Document

Run an incident log from minute one. Times, decisions, people. The log becomes the basis of every later report.

External reporting decisions you may need to make

TriggerReport toTiming consideration
Suspected criminal cyber offenceSingapore Police Force / Cybercrime CommandAs soon as practicable; preserve evidence first.
Personal data breach meeting the notifiable thresholdPDPC (and affected individuals)Notify PDPC no later than 3 calendar days after assessing the breach is notifiable.
Suspicious transaction surfacing as part of the incidentSTRO (Suspicious Transaction Reporting Office)Without unreasonable delay — see the AML/CFT course for the specific filing timeline.
Material impact on the firm's regulated operationsMASIn line with the firm's licence conditions and MAS notification requirements.

Source: Personal Data Protection Act 2012, Part IX; SPF Cybercrime Command guidance; MAS licence-condition notification requirements (to be verified against the current MAS Notice at course build).

Sample knowledge check

Knowledge check — Cybersecurity & Cyber Hygiene

One sample question. Full courses use a 10-question randomised pool with 80% pass gate.
Question 1 of 1 (Sample)
A staff member realises they clicked a suspicious link in an email and entered their corporate credentials. They tell you immediately. Which is the correct first action?
Rationale

Sample extract — illustrative structure
The framework below shows the architecture and drafting standard of a full AML/CFT Policy & Procedures document. The complete policy text, annex library, and firm-specific customisation are engagement deliverables, not shown in this showcase.
AML/CFT Policy & Procedures Framework

AML/CFT Policy & Procedures — the written framework, sampled

In Progress
🔒 Sample structure — full drafting delivered on engagement
Format
Drafted policy + supporting annex library
Customisation
White-labelled · Internal Use
Sections
Six thematic Parts
Regulator framework
Primary: MAS · Secondary: STRO, MHA, PDPC

© Richelle Lugtu. This structure is a drafting sample. Full policy text, annexes, and firm-specific customisation are delivered as an engagement deliverable, not licensed under standalone course subscriptions.

What this document is for

MAS Notice SFA 04-N02, paragraph 14, requires a CMI to establish and maintain internal policies, procedures and controls to prevent money laundering and terrorism financing, approved by senior management and kept current with the firm's risk profile. This is not a marketing document — it is the operational framework a MAS inspection would test for whether the firm's controls actually function in practice, in the same way an internal audit or a regulatory review would.

What a drafted framework typically includes

A governing policy for each risk area, customised to the firm's regulated-activity mix (dealing in capital markets products, fund management, advising on corporate finance, and so on), supported by an annex library of registers, screening forms, escalation flows, and training records that turn the policy into day-to-day operating practice.

What an engagement typically produces:
  • A six-Part AML/CFT Policy & Procedures document, drafted to MAS Notice SFA 04-N02 and the Securities and Futures Act framework.
  • A supporting annex library — registers, CDD/EDD forms, screening logs, STR decision guides, training records.
  • Customisation of the documents to the firm's regulated activities, customer base, and risk appetite.
  • Alignment with the firm's PDPA obligations where policy content touches personal-data handling.
  • An annual review and update cycle, and version control discipline.
Important — please read The framework shown here is a template structure provided for illustration. It is not endorsed by, accredited by, affiliated with, or a substitute for any regulator-prescribed framework, and does not constitute legal, regulatory, or professional advice. A firm engaging this methodology for a real policy document is solely responsible for verifying that the customised policy meets MAS's expectations and those of any other applicable regulator for that firm.
Sample extract — illustrative structure
Full section-level policy text is an engagement deliverable, not shown in this showcase.
Section 1 · Preview

The policy framework — six Parts

Preview screen — architecture shown; section-level text delivered on engagement

The framework is organised into six thematic Parts (A–F), each mapped to a distinct group of paragraphs in MAS Notice SFA 04-N02. Each Part answers a different category of question a MAS inspection is likely to ask. The Parts below show the architecture; the section-level policy text is part of the engagement deliverable.

PartCoverageMaps toThe question this Part answers
AFoundation & GovernanceThree Lines of Defence · Senior Management · Compliance Officer · MLRO · DPO · Group-Wide ProgrammeWho is accountable for AML/CFT inside this CMI, and how is that accountability exercised?
BRisk-Based ApproachMAS Notice para 4 (Risk Assessment) · para 5 (New Products & Technologies)How is ML/TF/PF risk identified, scored, refreshed, and turned into onboarding and product decisions?
CCustomer Due DiligenceMAS Notice para 6 (CDD) · para 7 (SCDD) · para 8 (ECDD) · para 9 (Reliance on Third Parties) · para 10 (Correspondent Accounts)How does the CMI know who its customers and beneficial owners actually are — and what enhanced controls apply to higher-risk persons?
DMonitoring & ReportingOngoing monitoring · MAS Notice para 13 (STR) · CDSA s.45 · tipping-offHow does the CMI keep customer risk under continuous view, and how does suspicion get from staff to a filed STR?
EOperational Controls & InfrastructureRecord-keeping · sanctions screening (UN Act 2001) · PDPA & data breach · outsourcingCan the CMI produce records on demand, and are its operational controls fit for a MAS inspection?
FGovernance, Assurance & MaintenanceMAS Notice para 14 (Training, Compliance, Audit) · review & version controlHas the CMI trained, audited, monitored, and updated its compliance framework as required?

What's actually delivered

The full policy document — every Part, every section — plus an embedded staff acknowledgement form and a regulatory reference table mapping each section back to its MAS Notice paragraph. White-labelled to the licensing firm, customised to its regulated-activity mix, and supported by the annex groups previewed in the next screen.

Source: MAS Notice SFA 04-N02 · Securities and Futures Act 2001 · CDSA 1992 · Terrorism (Suppression of Financing) Act 2002 · United Nations Act 2001 · PDPA 2012.

Sample extract — illustrative structure
Full annex text, forms, and registers are engagement deliverables, not shown in this showcase.
Annex library · Preview

The annex library — policy turned into daily practice

Preview list. Full annex text, forms, and registers provided on engagement.

Policy alone does not survive an inspection. The framework is supported by an annex library of live policies, methodology guides, registers, forms, and desk references that staff use day-to-day and that a MAS inspection would sample directly.

GroupCoverageRepresentative annexes
ARisk FrameworkRisk Assessment Policy (Master) · Risk Scoring Methodology · Product & Service Risk Classification Guide
BCDD & ScreeningCDD Policy (Master) · Higher-Risk Persons Policy (PEPs) · Screening Policy & Timing Matrix · Beneficial Ownership Look-Through Guide
COnboarding & Client ManagementOnboarding Policy (Master) · Client Onboarding Pack (forms) · Restricted & Higher-Risk Activity Guide
DMonitoring & ReviewOngoing Monitoring Policy (Master) · Periodic Review Schedule · Trigger-Event Guide
EReporting & EscalationSTR/MLRO Policy (Master) · STR Filing Decision Guide (general vs sanctioned-party timelines) · Tipping-Off & Escalation Policy
FGovernance & OversightGovernance Policy (Master, Three Lines of Defence) · Governance Calendar · Management Reporting Template
GData, Records & TechnologyData & Records Retention Policy · Data Breach Response Plan · PDPA Reference Guide
HTraining & CompetenceTraining Policy (Master) · Annual Training Programme Guide · Training Records Register

What's actually delivered

All annexes — full policy text, methodology guides, forms, registers, and desk cards — white-labelled to the licensing firm for internal use only. Customised to the firm's regulated-activity mix. Reviewed annually and updated against MAS, PDPC, and FATF guidance changes. Not for resale or external distribution.

© Richelle Lugtu. This structure is a drafting sample; full annex text is an engagement deliverable.

Sample extract — illustrative structure
One sample question, drawn from the policy-literacy question style used in the full framework's internal training.
Sample knowledge check

Knowledge check — policy framework literacy

One sample question. Full courses use a 10-question randomised pool with 80% pass gate.
Question 1 of 1 (Sample)
A MAS inspector asks to see how a particular customer's suspicion was escalated and reported. Which combination of Policy Parts and Annex Groups most directly answers that request?
Rationale

AML / CFT / CPF Foundations

AML / CFT / CPF Foundations for CSP Staff

🔒 Preview — full course not included
Audience
All CSP staff with customer contact or onboarding duties
Duration
~75 minutes
Assessment
10 questions, 80% pass
Certificate
Auto-issued on pass

© Richelle Lugtu. Course content, assessment design, and certificate template are proprietary. Online course access is licensed to engaged clients on subscription or licence terms.

Why this course exists

Anti-money-laundering, counter-financing of terrorism, and counter-proliferation-financing duties sit at the centre of an ACRA-registered CSP's regulatory obligations. CDSA, TSOFA, the CSP Act 2024 and the CSP Regulations 2025 place direct obligations on CSPs and their staff. This course gives every staff member the working knowledge to recognise, escalate, and document AML/CFT/CPF risk in their day-to-day work.

By the end of this course, learners will be able to:
  • Identify the customer, beneficial owners, and controllers in line with ACRA's Guidelines for Registered CSPs.
  • Apply customer due diligence (CDD) at onboarding, including verification standards.
  • Recognise the triggers that escalate a customer to enhanced due diligence (EDD).
  • Conduct a four-factor risk assessment — customer, jurisdiction, service, delivery channel.
  • Identify suspicious transaction indicators and the internal escalation pathway.
  • Apply ongoing monitoring and the record-keeping requirement.
Important — please read This training is provided for general educational and internal training purposes only. It is not endorsed by, accredited by, affiliated with, or a substitute for any regulator-prescribed certification, examination, licensing, or mandatory training. It does not constitute legal, regulatory, or professional advice.
Lesson 1.4 · Preview

The three stages of money laundering

Money laundering generally moves through three distinct stages: placement, layering, and integration. Each stage has different exposure for a CSP — step through the diagram below to see each in turn.

Placement → Layering → Integration
CASH BANK deposit Shell Co A (Jurisdiction X) Shell Co B (Jurisdiction Y) Shell Co C (Jurisdiction Z) BANK PROPERTY "investment"
Stage 1 of 3
Placement

The physical disposal of the benefits of criminal activity. Cash or assets are introduced into the financial system through deposits, exchanges, or asset purchases.

A CSP is rarely the entry point for placement directly, but may see its consequences — for instance, an unexplained large initial deposit into a newly-incorporated structure.
SourceACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), paragraph 5.2.
Lesson 1.7 · Preview

Why CSPs are gatekeepers

Corporate service providers occupy a structural position in the financial system that financial criminals find useful. The CSP incorporates the company. The CSP provides the registered office. The CSP files with ACRA. The CSP holds the relationship.

That is exactly why ACRA regulates CSPs. The CSP Act 2024 was enacted to regulate persons who carry on a business of providing corporate services and to impose requirements on those persons so as to detect or prevent money laundering, the financing of the proliferation of weapons of mass destruction, and terrorism financing. The CSP is part of the front line.

The diagram below shows how a CSP-incorporated entity sits inside a typical layering structure. Click each entity to see what role it plays.

Click each entity to see what it represents in the laundering chain.The CSP-incorporated company sits at the centre — that is the structural position regulators care about.
Criminal source (predicate offence proceeds) Foreign Shell Co (opaque jurisdiction) Singapore Pte Ltd (CSP-incorporated · CSP-served) ★ Where the CSP sees the customer Apparent legitimate asset (property · business · investment)
Click any entity in the diagram to see what role it plays in the laundering chain — and where the CSP fits in.
Origin

Criminal source

The proceeds of a predicate offence — fraud, drug trafficking, corruption, or other serious crime. The CSP almost never sees the source directly. The CSP sees what comes after.

If you see funds moving through your customer's structure that look unusual or unexplained, the source you cannot see is what your suspicion attaches to.
Layering vehicle

Foreign shell company

An offshore entity in a jurisdiction with limited transparency. Used to introduce distance between the criminal source and the apparently legitimate destination. May have opaque ownership, no real activity, and a single bank account.

Foreign shell companies are not illegal — but a Singapore customer whose ownership trail leads to an opaque foreign vehicle is a CDD priority.
Where the CSP works

Singapore Pte Ltd

The Singapore-incorporated entity that the CSP has been engaged to set up and service. From a launderer's perspective, this entity adds a layer of respectability — Singapore registration, real corporate documents, a real registered office.

This is the position that creates the CSP's regulatory exposure. ACRA expects the CSP to know who the customer really is, what the structure is for, and to recognise when the structure does not make commercial sense.
Integration destination

Apparently legitimate asset

The end-point of integration. The funds re-enter the legitimate economy as property, a business acquisition, or an investment that looks ordinary. By this stage the audit trail back to the criminal source is heavily obscured.

CSPs may not see the asset purchase itself — but they may see the corporate vehicle being prepared for it (capital injection, change of activity, change of bank instructions).
Examined 0 of 4 entitiesClick any entity to begin
SourceCorporate Service Providers Act 2024, long title and Part 1. ACRA Guidelines for Registered Corporate Service Providers (9 May 2025, v2.0), Section 2.
Lesson 1 · Knowledge Check 1 of 2 · Preview

Identify the stage

Knowledge Check

Which stage of money laundering is best illustrated below?

A customer has incorporated a Singapore private limited company through the CSP three weeks ago. The customer now uses that company to receive and on-pay funds rapidly between three other corporate entities in different jurisdictions. There is no apparent commercial activity — money in, money out, no trading.
Choose the best answer.

Knowledge checks are formative — they help learners consolidate. Answers are not scored toward the terminal assessment. The full course contains 12 knowledge checks across 6 lessons.

AML preview screens are lifted from production course AC-A-00 v1.3 (snapshot May 2026). The full course contains 6 lessons across approximately 80 screens, with 12 knowledge checks, a 10-question terminal assessment, and certificate.
PDPA & Data Protection

PDPA & Data Protection for CSP Staff

In Progress
🔒 Preview — full course not included
Audience
All CSP staff handling personal data
Duration
~60 minutes
Assessment
10 questions, 80% pass
Certificate
Auto-issued on pass

© Richelle Lugtu. Course content, assessment design, and certificate template are proprietary. Online course access is licensed to engaged clients on subscription or licence terms.

Why this course exists

CSPs handle personal data of directors, shareholders, beneficial owners, employees, and counterparties — by definition, in volume, and across borders. The Personal Data Protection Act 2012, as amended in 2020, sets eleven Data Protection Obligations. Failure attracts financial penalties, reputational damage, and ACRA inspection consequences. This course translates the Act into the daily decisions a CSP staff member actually makes.

By the end of this course, learners will be able to:
  • Identify when the PDPA applies to a piece of work and which obligations engage.
  • Apply the consent, notification, and purpose-limitation obligations at the point of data collection.
  • Recognise the conditions that trigger mandatory data breach notification to the PDPC and to affected individuals.
  • Apply the transfer-limitation obligation when sending personal data outside Singapore.
  • Understand the role and authority of the Data Protection Officer inside a CSP.
Important — please read This training is provided for general educational and internal training purposes only. It is not endorsed by, accredited by, affiliated with, or a substitute for any regulator-prescribed certification, examination, licensing, or mandatory training. It does not constitute legal, regulatory, or professional advice.
Topic 2 · Preview

The eleven Data Protection Obligations — at a glance

Preview screen — each obligation is treated in depth in the licensed course

The Personal Data Protection Act organises CSP duties around eleven obligations. They apply collectively — a CSP that consents-correctly but transfers-poorly is still in breach. Every CSP staff member needs the map; the licensed course teaches each obligation in operational detail.

1

Consent

Obtain consent for collection, use, or disclosure of personal data — and respect its withdrawal.

2

Purpose Limitation

Use personal data only for purposes a reasonable person would consider appropriate.

3

Notification

Tell individuals what their data will be used for, before or at the point of collection.

4

Access & Correction

Provide individuals access to their data on request, and correct errors.

5

Accuracy

Make reasonable effort to keep personal data accurate and complete.

6

Protection

Protect personal data with reasonable security arrangements.

7

Retention Limitation

Cease retention when the purpose no longer requires it and no legal duty compels it.

8

Transfer Limitation

Transfer personal data outside Singapore only if a comparable standard of protection is in place.

9

Accountability

Develop policies and practices, designate a DPO, and make information about both available.

10

Data Breach Notification

Notify the PDPC and affected individuals when a notifiable data breach occurs.

11

Data Portability

On request, transmit an individual's data to another organisation in a commonly-used format. (In force on appointed day.)

Source: Personal Data Protection Act 2012; PDPC Advisory Guidelines.

Topic 8 · Preview

Data Breach Notification — when, who, how fast

Preview screen — full topic includes the decision tree, drafting templates, and case scenarios

Not every data incident is a notifiable breach. The Data Breach Notification Obligation requires assessment, then action, on a tight clock. A CSP that gets the timing wrong compounds the original breach with a regulatory one.

The two-part test

A data breach must be notified if it (a) results in, or is likely to result in, significant harm to affected individuals, or (b) is of significant scale — affecting 500 or more individuals.

The notification timeline

StepTimingAction
1On suspicion of a breachAssess promptly — generally not more than 30 calendar days — whether the incident meets the notifiable threshold.
2Within 3 calendar days of assessment that it is notifiableNotify the Personal Data Protection Commission (PDPC).
3As soon as practicableNotify each affected individual where the breach is likely to result in significant harm — unless an exemption applies (remedial action taken, prejudice to investigations, PDPC waiver).

Common CSP breach patterns

Misdirected emails carrying client KYC packs, lost laptops with unencrypted client folders, vendor compromise affecting CSP-hosted client data, and access-control failures exposing beneficial-ownership records. Each plays out differently against the two-part test — the licensed course walks scenarios through to the notification decision.

Source: Personal Data Protection Act 2012, Part VIA; PDPC Advisory Guidelines on Data Breach Notification.

Sample knowledge check

Knowledge check — PDPA

One sample question. Full courses use a 10-question randomised pool with 80% pass gate.
Question 1 of 1 (Sample)
A staff member emails a client onboarding pack — including NRIC scans of three directors and one beneficial owner — to the wrong recipient. The error is discovered the same day; the recipient confirms deletion in writing. Which response best reflects the PDPA Data Breach Notification Obligation?
Rationale

Cybercrime & Cybersecurity

Cybercrime & Cybersecurity for CSPs

In Progress
🔒 Preview — full course not included · Includes interactive screen
Audience
All CSP staff with email and system access
Duration
~50 minutes
Assessment
10 questions, 80% pass
Certificate
Auto-issued on pass

© Richelle Lugtu. Course content, assessment design, and certificate template are proprietary. Online course access is licensed to engaged clients on subscription or licence terms.

Why this course exists

CSPs are a high-value target. They hold beneficial-ownership records, handle high-value transactions, sit on the trust that lets a fraudster impersonate a director. The threats are not abstract — phishing, business email compromise, credential theft, and ransomware all hit Singapore CSPs. This course gives staff the situational awareness and reflexes to be the firm's first defence rather than its weakest link.

By the end of this course, learners will be able to:
  • Recognise the dominant CSP-targeted threats and the vectors they arrive on.
  • Identify phishing and business email compromise indicators in a real email.
  • Apply the first 24 hours of incident response — contain, escalate, preserve, document.
  • Understand reporting duties to the Singapore Police Force, ACRA, and the PDPC where data is involved.
  • Apply staff-level controls that reduce the firm's overall exposure.
Important — please read This training is provided for general educational and internal training purposes only. It is not endorsed by, accredited by, affiliated with, or a substitute for any regulator-prescribed certification, examination, licensing, or mandatory training. It does not constitute legal, regulatory, or professional advice.
Topic 2 · Interactive preview

Phishing Email Inspector — find five red flags

Interactive screen — click anywhere on the email that looks suspicious

Below is a phishing email impersonating a CSP's bank. Five elements are red flags. Click each one to identify it. Each correct hit reveals what the indicator is and why it matters.

Inbox · 1 message Today, 10:42
From: Pacific Crown Bank Singapore <support@pacificcrown-secure-sg.com>
To: finance@yourcsp.com.sg
Subject: URGENT: Account verification required within 24 hours

Dear Valued Customer,

We have detected unusual activity on your corporate account. To prevent suspension, please verify your account details here within the next 24 hours.

Failure to act will result in your account being permanently suspended and all pending transactions cancelled.

Please find attached the verification form: Verification_Form.zip

Yours sincerely,
Pacific Crown Compliance Team

0 of 5 red flags found

All five red flags identified

In a real inbox you may not have five clear signals — sometimes you have one. The discipline is the same: stop, check the sender domain, hover the link, refuse the urgency. When in doubt, escalate to your firm's IT or MLRO before clicking. The licensed course covers business email compromise variants, voice-call follow-ups, and the first-24-hours response if a phishing email has been actioned.

Topic 7 · Preview

Incident response — the first 24 hours

Preview screen — full topic includes decision flows and reporting templates

The first day of a cyber incident shapes the next six months. Most permanent damage — loss of evidence, regulatory non-compliance, customer-trust erosion — happens in the hours immediately after detection, when staff act on instinct rather than procedure. The framework below is what a CSP's IPPC should already specify; this screen makes it learnable.

1

Contain

Disconnect affected devices from the network. Disable compromised accounts. Stop the spread before investigating the source.

2

Escalate

Notify your MLRO, Compliance Officer, and IT lead — by phone, not email, in case email is compromised. Document who was told and when.

3

Preserve

Do not power off, wipe, or "clean up" affected systems. Preserve logs, screenshots, and copies of suspicious messages. Forensic value disappears with each action taken.

4

Document

Run an incident log from minute one. Times, decisions, people. The log becomes the basis of every later report.

External reporting decisions you may need to make

TriggerReport toTiming consideration
Suspected criminal cyber offenceSingapore Police Force / Cybercrime CommandAs soon as practicable; preserve evidence first.
Personal data breach meeting the notifiable thresholdPDPC (and affected individuals)Notify PDPC within 3 calendar days of assessing the breach is notifiable.
Suspicious transaction surfacing as part of the incidentSTRO (Suspicious Transaction Reporting Office)Without delay once a reasonable basis for suspicion is formed.
Material impact on the CSP's regulated operationsACRAIn line with the CSP's licence conditions and CSP Regulations 2025.

Source: PDPA 2012, Part VIA; CSP Regulations 2025; SPF Cybercrime Command guidance.

Sample knowledge check

Knowledge check — Cybercrime & Cybersecurity

One sample question. Full courses use a 10-question randomised pool with 80% pass gate.
Question 1 of 1 (Sample)
A staff member realises they clicked a suspicious link in an email and entered their corporate credentials. They tell you immediately. Which is the correct first action?
Rationale

Package only — not a standalone
The IPPC document, the 40+ annexes, and the IPPC interactive course are licensed exclusively as part of the IPPC + Annexes Package. They are not available as standalone products and are not bundled into the Course-Only Licence or the Per-User Subscription.
IPPC + Annexes Package

IPPC + Annexes — the policy product, previewed

In Progress
🔒 Preview — full IPPC suite available under the suite licence
Format
Drafted IPPC + annex library
Customisation
White-labelled · Internal Use
Sections
Eight policy sections
Annexes
40+ supporting annexes

© Richelle Lugtu. The IPPC document, all 40+ annexes, the editable training material set (AML, PDPA, and other modules in Word and PowerPoint), and the IPPC interactive course are proprietary. Available only as part of the IPPC + Annexes package; not licensed under standalone course subscriptions.

What the IPPC product is

A complete IPPC suite + annex library for Singapore registered CSPs — modular, customisable per firm. White-labelled · Internal Use Only.

ACRA's Guidelines for Registered CSPs require every CSP to develop, implement, and maintain Internal Policies, Procedures and Controls proportionate to its size and complexity. The IPPC is not a marketing document — it is the operational framework that an ACRA Reviewer will read to assess whether the CSP's controls work in practice.

Documents — customised to your firm

The IPPC and 40+ annexes are delivered modular and customised to the licensing CSP's service mix and risk appetite. White-labelled for the firm's internal use only — not for resale or external distribution.

Interactive courses — delivered ready-to-deploy

The interactive courses (AML/CFT/CPF, PDPA, Cybercrime, IPPC) are delivered ready-to-deploy. Built to ACRA-aligned methodology and refreshed against regulatory updates so all licensees benefit from the same maintained standard.

What the licensing CSP receives:
  • The eight-section IPPC, drafted to ACRA's expectations and the CSP Act 2024 / CSP Regulations 2025 framework.
  • The 40+ annex library — registers, templates, screening forms, escalation flows, training records.
  • Customisation of the documents to the firm's services, structure, and risk appetite.
  • The interactive course suite (AML, PDPA, Cybercrime, IPPC) deployed for all users.
  • One annual review and update cycle covering both documents and course content.
  • Twelve months' course access in Year 1; renewable annually thereafter.
Important — please read The IPPC document and 40+ annexes are template internal compliance materials provided for general use within the licensing CSP. They are not endorsed by, accredited by, affiliated with, or a substitute for any regulator-prescribed framework. They do not constitute legal, regulatory, or professional advice. The licensee CSP is solely responsible for verifying that the customised IPPC and annexes meet the specific expectations of ACRA and any other applicable regulator for that firm.
Package only — not a standalone
The IPPC document, the 40+ annexes, and the IPPC interactive course are licensed exclusively as part of the IPPC + Annexes Package. They are not available as standalone products and are not bundled into the Course-Only Licence or the Per-User Subscription.
Section 1 · Preview

The IPPC framework — six Parts, thirty-one sections

Preview screen — full IPPC v4.21 (every section, every clause) provided on engagement

The IPPC is organised into six thematic Parts (A–F) covering thirty-one sections. Each Part answers a different category of question an ACRA Reviewer is likely to ask. The Parts below show the architecture; the section-level policy text is part of the engagement deliverable.

PartCoverageSectionsThe question this Part answers
AFoundation & GovernanceThree Lines of Defence · Senior Management · Board · CO · MLRO · QIs · DPO · Group-Wide Programme (7 sections)Who is accountable for AML/CFT/CPF inside this CSP, and how is that accountability exercised?
BRisk FrameworkRisk-Based Approach · EWRA · Four-Dimension CRA · National & Sectoral Risk · PF Risk · Service Classification · Designated Activities · Customer Acceptance (4 sections)How is risk identified, scored, refreshed, and turned into onboarding and acceptance decisions?
CCustomer Due DiligenceCDD tiers (SDD, Standard, EDD) · UBO · NFF CDD · SOF/SOW · CDD reliance · PEPs · HNWI/UHNWI · Sanctions · Fit & Proper · Nominee Director / Shareholder (5 sections)How does the CSP know who its customers and beneficial owners actually are — and what enhanced controls apply to higher-risk persons?
DMonitoring & ReportingOngoing monitoring · Periodic review · Trigger events · Transaction monitoring · STR/SAR & MLRO functions · Tipping off · SONAR (3 sections)How does the CSP keep customer risk under continuous view, and how does suspicion get from staff to a filed STR?
EOperational Controls & InfrastructureRecord-keeping · Statutory registers (RORC, RND, RNS) · ACRA ETS controls · Data Protection & Breach · Anti-Bribery / COI / Whistleblowing · Outsourcing · New Products & Tech (7 sections)Can the CSP produce records on demand, and are its operational controls fit for an inspection?
FGovernance, Assurance & MaintenanceStaff training · BCP · Notifications · Internal audit · Compliance Monitoring Plan · Governance reporting · Internal registers · Breach management · Review & version control · Annex Directory (10 sections)Has the CSP trained, audited, monitored, reported, and updated its compliance framework as required?

What's actually delivered

The full IPPC document — every Part, every section, every sub-section — plus the embedded staff acknowledgement form (ED-01) and regulatory reference table (ED-02). White-labelled to the licensing CSP, customised to its service mix, and supported by the eleven Annex Groups previewed in the next screen.

Source: CSP Act 2024 · CSP Regulations 2025 · ACRA Guidelines for Registered CSPs (May 2025, v2.0) · CDSA · TSOFA · UN Act 2001 · Companies Act 1967 · CLLPMA Act 2024 · PDPA 2012 · TF NRA 2024 · PF NRA 2024.

Package only — not a standalone
The IPPC document, the 40+ annexes, and the IPPC interactive course are licensed exclusively as part of the IPPC + Annexes Package. They are not available as standalone products and are not bundled into the Course-Only Licence or the Per-User Subscription.
Annex library · Preview

The annex library — eleven Groups, 40+ annexes

Preview list. Every annex (full text, forms, registers, guides) provided on engagement.

Policy alone does not survive an inspection. The IPPC is supported by eleven Annex Groups (A–K) containing 40+ individual annexes — the live policies, methodology guides, registers, forms, and desk references that staff use day-to-day and that an ACRA Reviewer will sample. Each Group follows a disciplined three-layer structure: Master Policy → Methodology and Operational Guide → Concepts and Reference Guide → Supporting forms, registers, and desk cards.

GroupCoverageAnnexesRepresentative annexes
ARisk Framework10Risk Policy (Master) · Four-Dimension CRA Scoring Tables (1–10 pick-list) · Comprehensive Country Risk Rating Guide · EWRA Completion Guide · CRA Quick-Reference Card
BCDD & KYC/KYB6CDD Policy (Master) · Higher Risk Persons Policy (PEPs · HNWI/UHNWI) · Screening Policy · KYC/KYB Document Matrix & Certification
COnboarding & Client Management8Onboarding Policy (Master, 13-step) · Client Onboarding Pack (Forms D-01 to D-19) · Sensitive & Unacceptable Business Activities Policy · Designated Activity Guide (DA(a)–DA(e))
DMonitoring & Review6Monitoring Policy (Master) · Bank Account Management & Control Policy — multi-model framework · Compliance Monitoring Plan Guide · Client Filing Deadline Guide
EReporting & Escalation4STR/SAR/MLRO Policy (Master) · STR Filing Methodology & Decision Guide · Compliance Breach Escalation Policy
FGovernance & Oversight4Governance Policy (Master, 3LoD) · Governance Methodology & Calendar Guide · Quarterly & Annual Management Report Template
GData, Records & Technology4Data & Records Policy (Master, 5-year retention) · Technology & BCP Policy · Data Concepts & PDPA Reference Guide
HFit & Proper and Nominee5Fit & Proper Policy (Master) · Nominee Director Policy (CLLPMA Act 2024) · Nominee Shareholder Policy (broadened definition)
IOperational Policies4Internal Operational Policies (Master) · Sales & Business Development Policy · Complaints & Outsourcing Policy
JTraining3Training Policy (Master) · Training Programme Guide · Training Modules & Assessments (T-01 to T-05)
KStatutory Registers & Compliance Checklists5Statutory Register Policy (Master, RORC/RND/RNS) · Register Completion Methodology Guide · Internal Compliance Registers — multi-register tracking system

What's actually delivered

All 40+ annexes — full policy text, methodology guides, concepts references, forms, registers, and desk cards — white-labelled to the licensing CSP for internal use only. Customised to the firm's service mix. Reviewed annually and updated against ACRA, MAS, PDPC, and FATF guidance changes. Not for resale or external distribution.

© Richelle Lugtu. The IPPC document, all 40+ annexes, the editable training material set (AML, PDPA, and other modules in Word and PowerPoint), and the IPPC interactive course are proprietary. Available only as part of the IPPC + Annexes package; not licensed under standalone course subscriptions.

Package only — not a standalone
The IPPC document, the 40+ annexes, and the IPPC interactive course are licensed exclusively as part of the IPPC + Annexes Package. They are not available as standalone products and are not bundled into the Course-Only Licence or the Per-User Subscription.
Sample knowledge check

Knowledge check — IPPC literacy

One sample question. Full courses use a 10-question randomised pool with 80% pass gate.
Question 1 of 1 (Sample)
An ACRA Reviewer asks to see how a particular high-risk customer's risk rating is supported, refreshed, and translated into ongoing monitoring. Which combination of IPPC Parts and Annex Groups most directly answers that request?
Rationale

Sample assessment

Working sample — five-question assessment with instant rationales

Demonstration of the assessment pattern used in every full course — choose a regime below

Each suite draws five questions from its own pool of ten, in random order. The pass mark is 80%. Failed attempts can be retaken — the question set is reshuffled each time. In a full course, passing this gate triggers an auto-issued certificate and the result is written to the training-records layer.

Question 1 of 5 Pass mark: 80%

© Richelle Lugtu. Course content, assessment design, and certificate template are proprietary. Online course access is licensed to engaged clients on subscription or licence terms.

Sample certificate

Certificate template — issued automatically on assessment pass

In a full course, this certificate generates on passing the 80% assessment gate, opens in a printable window, and the result is written to the training-records layer. Choose which suite's course name to preview.

How this works in production: On passing the full course assessment, the certificate generates automatically in a print-ready window (via window.open) with the learner's name, the live date, and the actual score. The pass result is written to the training-records layer so inspection-ready training records can be produced on request. Failed attempts trigger a retake-from-scratch with the question pool reshuffled.
Training records

What your compliance officer sees in the LMS

⚠ Sample illustration only — all learner names, dates, and scores below are fictitious and do not represent real individuals or training records

This is the type of report a compliance officer pulls from the LMS to evidence training was delivered and completed. The table below spans both suites — filter by course to see either the CSP/ACRA or the MAS CMS records. Every full course in this suite reports the same data fields, regardless of which firm licenses it.

The screen below is styled to reflect a typical LMS reporting view. The exact look will vary by LMS and theme — the underlying data is what matters.

Dashboard Compliance Training Reports Course activity report

Course activity report

Compliance Staff Training Suite · CSP/ACRA and MAS CMS · Attempts by user
First name / Surname Course Started on Last access Score Status
Download table data as:

What the data captures

Every course in this suite returns a standard learner-activity dataset to whichever LMS the firm runs — learner identity, lesson status, score, total session time, and attempt history. From that data the LMS produces its built-in reports, exports CSV/Excel/PDF, and feeds its activity completion tracking. Data retention follows the firm's own Record Retention Schedule.