Compliance training built to the standard of a regulator-supervised framework.
A working capability showcase spanning two Singapore regulatory frameworks — the Corporate Service Provider (CSP) regime under ACRA, and the Capital Markets Services (CMS) Licence Holder regime under MAS. Instructional design, regulatory-content methodology, and policy drafting applied to both. Click through either curriculum, try the working assessment, and view a sample certificate.
Prepared by: Richelle Lugtu · rklugtu@gmail.com · +65 8230 6284 (WhatsApp)
What this showcase is
A capability demonstration, not a delivered course. Two regulatory suites are previewed side by side — Singapore CSP/ACRA and MAS CMS — each with its own topic curriculum in the left sidebar. A small number of screens are unlocked in each to demonstrate instructional and visual quality; the rest open a request-access note. A working sample assessment, sample certificate, and a sample training-records view let you choose which regime to preview.
Full courses are built to include a randomised assessment pool, an 80% pass gate, retake-from-scratch logic, an auto-issued certificate on pass, and a training-records tracking layer.
Two regulatory frameworks, one methodology
The CSP/ACRA suite reflects production-grade work — frameworks built and delivered for registered Corporate Service Providers under the CSP Act 2024 and ACRA's Guidelines for Registered CSPs. The MAS CMS suite applies the same instructional and policy-drafting methodology to the Capital Markets Services Licence Holder framework under MAS Notice SFA 04-N02, as a worked demonstration of cross-framework capability.
What travels between the two: the instructional structure, the citation discipline, and the assessment architecture. What does not travel: the regulatory facts themselves — each suite is verified independently against its own regulator's current statutes, notices, and guidelines.
Choose what to preview
Two regulatory suites, previewed independently. Pick any subject area to enter its curriculum — each card opens to a course cover and a left-hand topic sidebar showing the full curriculum, with a handful of subsections unlocked.
Singapore CSP / ACRA Compliance Suite
Production-grade framework — Corporate Service Providers under the CSP Act 2024 and ACRA's Guidelines for Registered CSPs.
MAS CMS Compliance Suite
Methodology demonstration — Capital Markets Services Licence Holders under MAS Notice SFA 04-N02.
Working samples — choose your regime
These three samples work across either suite — pick CSP/ACRA or MAS CMS when you open them.
IPPC, Manuals & SOP Suite
Click through the document tree below the way a client would receive it — Master Policy, methodology guides, reference tools, registers and desk cards. Built for a Singapore CSP; structured so the same architecture transfers to any regulated business, sector or jurisdiction.
How Engagement Works
Same architecture, two ways to receive it.
Off-the-Shelf Template Suite
- Full Master Policy + Annex Suite as shown above
- Generic placeholders throughout ([FIRM NAME], [DATE], [NAME]) — you complete these
- Regulatory basis lines built for the stated jurisdiction/sector
- Delivered as editable Word / Excel / PDF files
- You review, adapt and adopt — template only, not legal advice
Fully Customised Build
- Everything in the template suite, plus:
- Placeholders resolved to your actual entity, roles and governance structure
- Reworked for your specific industry, jurisdiction or regulatory regime
- Annex suite scoped to the services/products you actually offer
- Pre-delivery audit pass — markers, citations, version control checked before handover
Compliance training built the way a regulator would want it built
8+ years of Singapore-based AML/CFT compliance work, including a former appointed MLRO and Compliance Manager role for a registered corporate service provider and filing agent — owning an AML/CFT framework end-to-end, filing STR/SARs, running internal audits, and delivering staff training across a regulated business. The CSP/ACRA suite in this showcase reflects that production experience directly.
The MAS CMS suite applies the same instructional and policy-drafting methodology to a framework not previously worked in production: the Singapore MAS Capital Markets Services (CMS) Licence Holder regime under MAS Notice SFA 04-N02. Every regulatory fact on the unlocked screens in both suites is drawn and cited directly from the relevant regulator's own statutes, notices, and guidelines — not asserted from memory. That is the point of showing both side by side: the methodology is portable across regulators and sectors, and the regulatory-verification discipline is what makes that portability safe to sell.
What "built the way a regulator would want it built" means in practice
Every fact is sourced
Penalty figures, filing timelines, and statutory citations are drawn from the current text of the governing Notice, Guidelines, or Act — never from recollection. Sources are shown in a citation footer on every content screen.
Learning outcomes are anchored
Every lesson and every assessment question is built to answer five things: what the learner will know, which obligation it supports, what they should recognise or escalate in real practice, how it's tested, and why the answer is right or wrong.
The firm's own procedures still govern
Training teaches the regulatory methodology — it does not prescribe a firm's specific thresholds, escalation timeframes, or operational detail. Where a course and a firm's own policy differ on an operational point, the firm's policy governs. That boundary is stated explicitly, not blurred.
Assessment is real, not decorative
A randomised question pool, an 80% pass gate, retake-from-scratch logic, instant rationales on every answer, and an auto-issued certificate — the mechanics a training record actually needs to hold up under review.
Deliverables this methodology produces
Interactive e-learning courses
Self-paced · assessment and certificate built in
Regulatory obligations translated into role-based, scenario-led training — the kind staff actually remember, not a slide deck read aloud.
Governing policy documents
AML/CFT policy · CDD/EDD procedures · STR workflow · record-keeping
The written framework a compliance programme is actually assessed against — drafted to the firm's regulated-activity mix, not a generic template.
Fractional compliance & review support
Risk assessment · gap analysis · audit preparation
Independent second-line review, control testing, and remediation planning — for firms that need the function without a full-time hire.
Let's talk about what you need built.
Whether it's a full interactive course, a policy and procedures framework, or a review of what you already have — happy to walk through it on a call.
What this showcase is, and is not
Training content only
- This showcase, and the full courses it previews, teach learners what their AML/CFT/CPF, PDPA, and other regulatory obligations are under two separate frameworks — the Singapore CSP regime under ACRA, and the Singapore MAS CMS Licence Holder regime under MAS Notice SFA 04-N02. They do not constitute legal advice, regulatory advice, or compliance advice of any kind.
- They do not replace a firm's own AML/CFT Policy & Procedures Framework or IPPC, internal controls, or professional advice.
- Completing a preview screen, a sample assessment, or a full course does not, in itself, satisfy any specific ACRA or MAS training expectation, nor does it guarantee the outcome of an ACRA inspection or a MAS inspection of training records.
- A firm licensing any full course or policy framework built on this methodology is solely responsible for confirming the content meets its own training and compliance obligations, and for adapting any material to its own regulated-activity mix and risk profile.
- Regulatory facts in the CSP/ACRA suite are sourced from the CSP Act 2024, the CSP Regulations 2025, ACRA's Guidelines for Registered CSPs, the CDSA, TSOFA, the UN Act 2001, and the PDPA. Regulatory facts in the MAS CMS suite are sourced from MAS Notice SFA 04-N02, its accompanying MAS Guidelines, the Securities and Futures Act, the CDSA, and the PDPA. Both are current as at the date shown on each screen's citation footer. Regulation changes — every regulatory fact should be re-verified at the point any full course is commissioned, and refreshed periodically thereafter.
Methodology, not operational prescription. Each preview screen teaches the regulatory framework, methodology, and recognition skills that a compliance programme should satisfy. It does not prescribe operational specifics — thresholds, scoring weights, escalation timeframes, or procedural detail — because a firm's own adopted policies and procedures set those according to its risk appetite and the applicable regulator's recognised practice. Where a screen's regulatory framing and a firm's adopted procedures differ on an operational point, the firm's procedures govern.
This is a capability showcase prepared for professional review, not a licensed or delivered training product. Regulator framework, citations, and instructional structure shown here demonstrate methodology and are not a substitute for a live regulatory-verification session at the point of a real engagement.
AML / CFT / CPF Foundations for CMI Staff
🔒 Preview — full course not included© Richelle Lugtu. Course content, assessment design, and certificate template are proprietary. Online course access is licensed to engaged clients on subscription or licence terms.
Why this course exists
MAS Notice SFA 04-N02 on the Prevention of Money Laundering and Countering the Financing of Terrorism sets direct obligations on Capital Markets Intermediaries (CMIs) and their staff — customer due diligence, screening, ongoing monitoring, and suspicious transaction reporting. The CDSA and the Terrorism (Suppression of Financing) Act 2002 sit alongside it as the statutory basis for reporting and disclosure. This course gives every staff member the working knowledge to recognise, escalate, and document AML/CFT/CPF risk in day-to-day work.
- Identify a customer, connected parties, and beneficial owners in line with MAS Notice SFA 04-N02.
- Apply customer due diligence (CDD) at onboarding, including the screening timing and transaction-value triggers.
- Recognise the higher-risk indicators that escalate a customer to enhanced due diligence (EDD).
- Apply a risk-based approach to ongoing monitoring and periodic screening.
- Recognise suspicious transaction indicators and the internal escalation pathway.
- State the STR filing timeline expectation and why it differs for sanctioned parties.
The three stages of money laundering
Money laundering generally moves through three distinct stages: placement, layering, and integration. Each stage has different exposure for a CMI — step through the diagram below to see each in turn.
The physical disposal of the benefits of criminal activity. Cash or assets are introduced into the financial system through deposits, exchanges, or asset purchases.
The separation of the benefits from their source by creating intervening layers of financial transactions. Funds move through entities, jurisdictions, and accounts to obscure the audit trail.
The laundered benefits are placed back into the economy so that they re-enter the financial system appearing to be legitimate business funds.
Why CMIs are gatekeepers
A Capital Markets Intermediary occupies a structural position that financial criminals find useful. The CMI onboards the customer. The CMI holds the dealing or advisory relationship. The CMI executes the transaction. The CMI screens against sanctions and ML/TF risk sources.
That is exactly why MAS regulates CMIs under the Securities and Futures Act and imposes AML/CFT obligations through Notice SFA 04-N02. The Notice exists to detect and prevent money laundering, the financing of terrorism, and the financing of proliferation of weapons of mass destruction through the capital markets channel. The CMI is part of the front line.
The diagram below shows how a CMI-held customer relationship can sit inside a typical layering structure. Click each entity to see what role it plays.
Criminal source
The proceeds of a predicate offence — fraud, corruption, drug trafficking, or other serious crime. The CMI almost never sees the source directly. The CMI sees what comes after.
Foreign shell company
An offshore entity in a jurisdiction with limited transparency. Used to introduce distance between the criminal source and the apparently legitimate destination. May have opaque ownership, no real activity, and a single funding account.
Trading account, Singapore
The account or dealing relationship the CMI has onboarded and holds. From a launderer's perspective, this relationship adds a layer of respectability — a regulated intermediary, real account documentation, apparently legitimate trading activity.
Apparently legitimate asset
The end-point of integration. The funds re-enter the legitimate economy as a liquidated holding, a property-linked investment, or a business acquisition that looks ordinary. By this stage the audit trail back to the criminal source is heavily obscured.
Identify the stage
Which stage of money laundering is best illustrated below?
Knowledge checks are formative — they help learners consolidate. Answers are not scored toward the terminal assessment. The full course contains 12 knowledge checks across 6 lessons.
PDPA & Data Protection for CMS Licence Holder Staff
© Richelle Lugtu. Course content, assessment design, and certificate template are proprietary. Online course access is licensed to engaged clients on subscription or licence terms.
Why this course exists
A CMS licence holder handles personal data of customers, beneficial owners, representatives, and employees — in volume, and often across borders. The Personal Data Protection Act 2012, as amended in 2020, sets eleven Data Protection Obligations, enforced separately from (and alongside) the record-keeping duties MAS Notice SFA 04-N02 places on CDD data. Failure attracts financial penalties and reputational consequences. This course translates the Act into the daily decisions a licence holder's staff actually make.
- Identify when the PDPA applies to a piece of work and which obligations engage.
- Apply the consent, notification, and purpose-limitation obligations at the point of data collection.
- Recognise the conditions that trigger mandatory data breach notification to the PDPC and to affected individuals.
- Apply the retention-limitation obligation where it interacts with MAS record-keeping requirements on CDD data.
- Understand the role and authority of the Data Protection Officer inside a licence holder.
The eleven Data Protection Obligations — at a glance
Preview screen — each obligation is treated in depth in the licensed courseThe Personal Data Protection Act organises a licence holder's duties around eleven obligations. They apply collectively — a firm that consents correctly but transfers poorly is still in breach. Every member of staff needs the map; the licensed course teaches each obligation in operational detail.
Consent
Obtain consent for collection, use, or disclosure of personal data — and respect its withdrawal.
Purpose Limitation
Use personal data only for purposes a reasonable person would consider appropriate.
Notification
Tell individuals what their data will be used for, before or at the point of collection.
Access & Correction
Provide individuals access to their data on request, and correct errors.
Accuracy
Make reasonable effort to keep personal data accurate and complete.
Protection
Protect personal data with reasonable security arrangements.
Retention Limitation
Cease retention when the purpose no longer requires it and no legal duty compels it — noting MAS record-keeping requirements on CDD data as a distinct legal duty.
Transfer Limitation
Transfer personal data outside Singapore only if a comparable standard of protection is in place.
Accountability
Develop policies and practices, designate a DPO, and make information about both available.
Data Breach Notification
Notify the PDPC and affected individuals when a notifiable data breach occurs.
Data Portability
On request, transmit an individual's data to another organisation in a commonly-used format. (In force on appointed day.)
Source: Personal Data Protection Act 2012, ss.13–26E; PDPC Advisory Guidelines on Key Concepts in the PDPA.
Data Breach Notification — when, who, how fast
Preview screen — full topic includes the decision tree, drafting templates, and case scenariosNot every data incident is a notifiable breach. The Data Breach Notification Obligation requires assessment, then action, on a tight clock. A firm that gets the timing wrong compounds the original breach with a regulatory one.
The two-part test
A data breach must be notified if it (a) results in, or is likely to result in, significant harm to affected individuals, or (b) is of significant scale — affecting 500 or more individuals. Either limb on its own triggers the obligation.
The notification timeline
| Step | Timing | Action |
|---|---|---|
| 1 | On suspicion of a breach | Assess expeditiously whether the incident meets the notifiable threshold. Deliberately prolonging the assessment does not defer the clock. |
| 2 | No later than 3 calendar days after determining the breach is notifiable | Notify the Personal Data Protection Commission (PDPC). |
| 3 | As soon as practicable | Notify each affected individual where the breach is likely to result in significant harm — unless a s.26E exception applies (effective remedial action, technological protection already in place, or law-enforcement direction). |
Common breach patterns at a CMS licence holder
Misdirected emails carrying client onboarding or CDD packs, lost devices with unencrypted client folders, vendor or platform compromise affecting hosted client data, and access-control failures exposing beneficial-ownership records. Each plays out differently against the two-part test — the licensed course walks scenarios through to the notification decision.
Source: Personal Data Protection Act 2012, ss.26B–26E; PDPC Guide on Managing and Notifying Data Breaches.
Knowledge check — PDPA
One sample question. Full courses use a 10-question randomised pool with 80% pass gate.Sanctions & TFS for CMI Staff
© Richelle Lugtu. Course content, assessment design, and certificate template are proprietary. Online course access is licensed to engaged clients on subscription or licence terms.
Why this course exists
Targeted financial sanctions in Singapore sit on the United Nations Act 2001 and the regulations made under it, working alongside MAS Notice SFA 04-N02's screening requirements. A sanctions hit is not treated the same way as an ordinary suspicious-transaction concern — the escalation timeline compresses sharply once a sanctioned party is identified. This course teaches CMI staff who must be screened, when, and what happens once a match is confirmed.
- Identify who must be screened under MAS Notice SFA 04-N02 — the customer, connected parties, natural persons acting on the customer's behalf, and beneficial owners.
- State the screening triggers: onboarding, the S$20,000 transaction threshold, periodic re-screening, and list-update triggers.
- Recognise a confirmed sanctions match and distinguish it from an ordinary AML/CFT suspicion.
- State the compressed STR filing timeline that applies once a sanctioned party is identified, and why it differs from the general timeline.
Who gets screened, and when
Preview screen — full topic includes list-source detail and false-positive handlingMAS Notice SFA 04-N02 requires a CMI to screen against money laundering and terrorism financing information sources, and against lists and information provided by MAS or other relevant Singapore authorities. Screening is not a one-time onboarding step — it recurs on defined triggers.
Who must be screened
The customer
Every customer, whether a natural person or a legal person or arrangement.
Natural persons acting on the customer's behalf
Anyone appointed to operate the account or instruct on the customer's behalf.
Connected parties
Directors, partners, and other parties connected to the customer as defined in the Notice.
Beneficial owners
The natural person(s) who ultimately own or control the customer.
When screening is triggered
| Trigger | Timing |
|---|---|
| Establishing business relations with a new customer | When, or as soon as reasonably practicable after, business relations are established. |
| A transaction for a customer without an established relationship | Where the transaction value exceeds S$20,000 (excluding certain digital CMP token transfers, which have their own trigger). |
| Ongoing relationship | On a periodic basis, risk-based. |
| List or information updates | Whenever MAS or another relevant Singapore authority updates the lists or information the CMI screens against. |
Source: MAS Notice SFA 04-N02, paragraphs 6.39–6.40 (Screening).
A sanctions hit changes the clock
Preview screen — full topic includes the internal escalation script and false-positive close-outAn ordinary suspicious-transaction concern and a confirmed sanctions match are not filed on the same timeline. Once a party is identified as sanctioned, or acting on behalf of or under the direction of a sanctioned party, the filing window compresses sharply.
General STR timeline
The internal process for deciding whether a matter should be referred to the Suspicious Transaction Reporting Office (STRO) should be completed without delay. Filing should not exceed 5 business days after suspicion was first established, absent exceptional or extraordinary circumstances.
Sanctioned-party timeline
Where the matter involves a sanctioned party, or a party acting on behalf of or under the direction of one, the CMI should file the STR as soon as possible, and no later than 1 business day after suspicion was first established.
An STR filed with STRO on a sanctions-related matter also satisfies the corresponding reporting obligation under the Terrorism (Suppression of Financing) Act 2002, where that obligation applies. Separately, the statutory duty to disclose knowledge or suspicion connected to drug dealing or criminal conduct under CDSA s.45(1) applies "as soon as is reasonably practicable" — failure is a criminal offence carrying a fine of up to S$250,000 or up to 3 years' imprisonment (or both) for an individual, and a fine of up to S$500,000 for an entity.
Source: MAS Guidelines to Notice SFA 04-N02, paragraph 13-1; CDSA 1992, s.45(1) and s.45(3).
Knowledge check — Sanctions & TFS
One sample question. Full courses use a 10-question randomised pool with 80% pass gate.Cybersecurity & Cyber Hygiene for CMS Licence Holder Staff
© Richelle Lugtu. Course content, assessment design, and certificate template are proprietary. Online course access is licensed to engaged clients on subscription or licence terms.
Why this course exists
A CMS licence holder is a high-value target. It handles client funds, holds account and beneficial-ownership records, and sits on the trust that lets a fraudster impersonate a client or a director. The threats are not abstract — phishing, business email compromise, credential theft, and ransomware all hit regulated financial firms. This course gives staff the situational awareness and reflexes to be the firm's first line of defence rather than its weakest link.
- Recognise the dominant threats aimed at regulated financial firms and the vectors they arrive on.
- Identify phishing and business email compromise indicators in a real email.
- Apply the first 24 hours of incident response — contain, escalate, preserve, document.
- Understand reporting duties to the Singapore Police Force, MAS, and the PDPC where personal data is involved.
- Apply staff-level controls that reduce the firm's overall exposure.
Phishing Email Inspector — find five red flags
Interactive screen — click anywhere on the email that looks suspiciousBelow is a phishing email impersonating a firm's bank. Five elements are red flags. Click each one to identify it. Each correct hit reveals what the indicator is and why it matters.
Dear Valued Customer,
We have detected unusual activity on your corporate account. To prevent suspension, please verify your account details here within the next 24 hours.
Failure to act will result in your account being permanently suspended and all pending transactions cancelled.
Please find attached the verification form: Verification_Form.zip
Yours sincerely,
Pacific Crown Compliance Team
All five red flags identified
In a real inbox you may not have five clear signals — sometimes you have one. The discipline is the same: stop, check the sender domain, hover the link, refuse the urgency. When in doubt, escalate to your firm's IT or Compliance Officer before clicking. The licensed course covers business email compromise variants, voice-call follow-ups, and the first-24-hours response if a phishing email has been actioned.
Incident response — the first 24 hours
Preview screen — full topic includes decision flows and reporting templatesThe first day of a cyber incident shapes the next six months. Most permanent damage — loss of evidence, regulatory non-compliance, customer-trust erosion — happens in the hours immediately after detection, when staff act on instinct rather than procedure. The framework below is what a firm's AML/CFT and IT security policies should already specify; this screen makes it learnable.
Contain
Disconnect affected devices from the network. Disable compromised accounts. Stop the spread before investigating the source.
Escalate
Notify your Compliance Officer / MLRO and IT lead — by phone, not email, in case email is compromised. Document who was told and when.
Preserve
Do not power off, wipe, or "clean up" affected systems. Preserve logs, screenshots, and copies of suspicious messages. Forensic value disappears with each action taken.
Document
Run an incident log from minute one. Times, decisions, people. The log becomes the basis of every later report.
External reporting decisions you may need to make
| Trigger | Report to | Timing consideration |
|---|---|---|
| Suspected criminal cyber offence | Singapore Police Force / Cybercrime Command | As soon as practicable; preserve evidence first. |
| Personal data breach meeting the notifiable threshold | PDPC (and affected individuals) | Notify PDPC no later than 3 calendar days after assessing the breach is notifiable. |
| Suspicious transaction surfacing as part of the incident | STRO (Suspicious Transaction Reporting Office) | Without unreasonable delay — see the AML/CFT course for the specific filing timeline. |
| Material impact on the firm's regulated operations | MAS | In line with the firm's licence conditions and MAS notification requirements. |
Source: Personal Data Protection Act 2012, Part IX; SPF Cybercrime Command guidance; MAS licence-condition notification requirements (to be verified against the current MAS Notice at course build).
Knowledge check — Cybersecurity & Cyber Hygiene
One sample question. Full courses use a 10-question randomised pool with 80% pass gate.AML/CFT Policy & Procedures — the written framework, sampled
© Richelle Lugtu. This structure is a drafting sample. Full policy text, annexes, and firm-specific customisation are delivered as an engagement deliverable, not licensed under standalone course subscriptions.
What this document is for
MAS Notice SFA 04-N02, paragraph 14, requires a CMI to establish and maintain internal policies, procedures and controls to prevent money laundering and terrorism financing, approved by senior management and kept current with the firm's risk profile. This is not a marketing document — it is the operational framework a MAS inspection would test for whether the firm's controls actually function in practice, in the same way an internal audit or a regulatory review would.
What a drafted framework typically includes
A governing policy for each risk area, customised to the firm's regulated-activity mix (dealing in capital markets products, fund management, advising on corporate finance, and so on), supported by an annex library of registers, screening forms, escalation flows, and training records that turn the policy into day-to-day operating practice.
- A six-Part AML/CFT Policy & Procedures document, drafted to MAS Notice SFA 04-N02 and the Securities and Futures Act framework.
- A supporting annex library — registers, CDD/EDD forms, screening logs, STR decision guides, training records.
- Customisation of the documents to the firm's regulated activities, customer base, and risk appetite.
- Alignment with the firm's PDPA obligations where policy content touches personal-data handling.
- An annual review and update cycle, and version control discipline.
The policy framework — six Parts
Preview screen — architecture shown; section-level text delivered on engagementThe framework is organised into six thematic Parts (A–F), each mapped to a distinct group of paragraphs in MAS Notice SFA 04-N02. Each Part answers a different category of question a MAS inspection is likely to ask. The Parts below show the architecture; the section-level policy text is part of the engagement deliverable.
| Part | Coverage | Maps to | The question this Part answers |
|---|---|---|---|
| A | Foundation & Governance | Three Lines of Defence · Senior Management · Compliance Officer · MLRO · DPO · Group-Wide Programme | Who is accountable for AML/CFT inside this CMI, and how is that accountability exercised? |
| B | Risk-Based Approach | MAS Notice para 4 (Risk Assessment) · para 5 (New Products & Technologies) | How is ML/TF/PF risk identified, scored, refreshed, and turned into onboarding and product decisions? |
| C | Customer Due Diligence | MAS Notice para 6 (CDD) · para 7 (SCDD) · para 8 (ECDD) · para 9 (Reliance on Third Parties) · para 10 (Correspondent Accounts) | How does the CMI know who its customers and beneficial owners actually are — and what enhanced controls apply to higher-risk persons? |
| D | Monitoring & Reporting | Ongoing monitoring · MAS Notice para 13 (STR) · CDSA s.45 · tipping-off | How does the CMI keep customer risk under continuous view, and how does suspicion get from staff to a filed STR? |
| E | Operational Controls & Infrastructure | Record-keeping · sanctions screening (UN Act 2001) · PDPA & data breach · outsourcing | Can the CMI produce records on demand, and are its operational controls fit for a MAS inspection? |
| F | Governance, Assurance & Maintenance | MAS Notice para 14 (Training, Compliance, Audit) · review & version control | Has the CMI trained, audited, monitored, and updated its compliance framework as required? |
What's actually delivered
The full policy document — every Part, every section — plus an embedded staff acknowledgement form and a regulatory reference table mapping each section back to its MAS Notice paragraph. White-labelled to the licensing firm, customised to its regulated-activity mix, and supported by the annex groups previewed in the next screen.
Source: MAS Notice SFA 04-N02 · Securities and Futures Act 2001 · CDSA 1992 · Terrorism (Suppression of Financing) Act 2002 · United Nations Act 2001 · PDPA 2012.
The annex library — policy turned into daily practice
Preview list. Full annex text, forms, and registers provided on engagement.Policy alone does not survive an inspection. The framework is supported by an annex library of live policies, methodology guides, registers, forms, and desk references that staff use day-to-day and that a MAS inspection would sample directly.
| Group | Coverage | Representative annexes |
|---|---|---|
| A | Risk Framework | Risk Assessment Policy (Master) · Risk Scoring Methodology · Product & Service Risk Classification Guide |
| B | CDD & Screening | CDD Policy (Master) · Higher-Risk Persons Policy (PEPs) · Screening Policy & Timing Matrix · Beneficial Ownership Look-Through Guide |
| C | Onboarding & Client Management | Onboarding Policy (Master) · Client Onboarding Pack (forms) · Restricted & Higher-Risk Activity Guide |
| D | Monitoring & Review | Ongoing Monitoring Policy (Master) · Periodic Review Schedule · Trigger-Event Guide |
| E | Reporting & Escalation | STR/MLRO Policy (Master) · STR Filing Decision Guide (general vs sanctioned-party timelines) · Tipping-Off & Escalation Policy |
| F | Governance & Oversight | Governance Policy (Master, Three Lines of Defence) · Governance Calendar · Management Reporting Template |
| G | Data, Records & Technology | Data & Records Retention Policy · Data Breach Response Plan · PDPA Reference Guide |
| H | Training & Competence | Training Policy (Master) · Annual Training Programme Guide · Training Records Register |
What's actually delivered
All annexes — full policy text, methodology guides, forms, registers, and desk cards — white-labelled to the licensing firm for internal use only. Customised to the firm's regulated-activity mix. Reviewed annually and updated against MAS, PDPC, and FATF guidance changes. Not for resale or external distribution.
© Richelle Lugtu. This structure is a drafting sample; full annex text is an engagement deliverable.
Knowledge check — policy framework literacy
One sample question. Full courses use a 10-question randomised pool with 80% pass gate.AML / CFT / CPF Foundations for CSP Staff
🔒 Preview — full course not included© Richelle Lugtu. Course content, assessment design, and certificate template are proprietary. Online course access is licensed to engaged clients on subscription or licence terms.
Why this course exists
Anti-money-laundering, counter-financing of terrorism, and counter-proliferation-financing duties sit at the centre of an ACRA-registered CSP's regulatory obligations. CDSA, TSOFA, the CSP Act 2024 and the CSP Regulations 2025 place direct obligations on CSPs and their staff. This course gives every staff member the working knowledge to recognise, escalate, and document AML/CFT/CPF risk in their day-to-day work.
- Identify the customer, beneficial owners, and controllers in line with ACRA's Guidelines for Registered CSPs.
- Apply customer due diligence (CDD) at onboarding, including verification standards.
- Recognise the triggers that escalate a customer to enhanced due diligence (EDD).
- Conduct a four-factor risk assessment — customer, jurisdiction, service, delivery channel.
- Identify suspicious transaction indicators and the internal escalation pathway.
- Apply ongoing monitoring and the record-keeping requirement.
The three stages of money laundering
Money laundering generally moves through three distinct stages: placement, layering, and integration. Each stage has different exposure for a CSP — step through the diagram below to see each in turn.
The physical disposal of the benefits of criminal activity. Cash or assets are introduced into the financial system through deposits, exchanges, or asset purchases.
The separation of the benefits from their source by creating intervening layers of financial transactions. Funds move through entities, jurisdictions, and accounts to obscure the audit trail.
The laundered benefits are placed back into the economy so that they re-enter the financial system by appearing to be legitimate business funds.
Why CSPs are gatekeepers
Corporate service providers occupy a structural position in the financial system that financial criminals find useful. The CSP incorporates the company. The CSP provides the registered office. The CSP files with ACRA. The CSP holds the relationship.
That is exactly why ACRA regulates CSPs. The CSP Act 2024 was enacted to regulate persons who carry on a business of providing corporate services and to impose requirements on those persons so as to detect or prevent money laundering, the financing of the proliferation of weapons of mass destruction, and terrorism financing. The CSP is part of the front line.
The diagram below shows how a CSP-incorporated entity sits inside a typical layering structure. Click each entity to see what role it plays.
Criminal source
The proceeds of a predicate offence — fraud, drug trafficking, corruption, or other serious crime. The CSP almost never sees the source directly. The CSP sees what comes after.
Foreign shell company
An offshore entity in a jurisdiction with limited transparency. Used to introduce distance between the criminal source and the apparently legitimate destination. May have opaque ownership, no real activity, and a single bank account.
Singapore Pte Ltd
The Singapore-incorporated entity that the CSP has been engaged to set up and service. From a launderer's perspective, this entity adds a layer of respectability — Singapore registration, real corporate documents, a real registered office.
Apparently legitimate asset
The end-point of integration. The funds re-enter the legitimate economy as property, a business acquisition, or an investment that looks ordinary. By this stage the audit trail back to the criminal source is heavily obscured.
Identify the stage
Which stage of money laundering is best illustrated below?
Knowledge checks are formative — they help learners consolidate. Answers are not scored toward the terminal assessment. The full course contains 12 knowledge checks across 6 lessons.
PDPA & Data Protection for CSP Staff
© Richelle Lugtu. Course content, assessment design, and certificate template are proprietary. Online course access is licensed to engaged clients on subscription or licence terms.
Why this course exists
CSPs handle personal data of directors, shareholders, beneficial owners, employees, and counterparties — by definition, in volume, and across borders. The Personal Data Protection Act 2012, as amended in 2020, sets eleven Data Protection Obligations. Failure attracts financial penalties, reputational damage, and ACRA inspection consequences. This course translates the Act into the daily decisions a CSP staff member actually makes.
- Identify when the PDPA applies to a piece of work and which obligations engage.
- Apply the consent, notification, and purpose-limitation obligations at the point of data collection.
- Recognise the conditions that trigger mandatory data breach notification to the PDPC and to affected individuals.
- Apply the transfer-limitation obligation when sending personal data outside Singapore.
- Understand the role and authority of the Data Protection Officer inside a CSP.
The eleven Data Protection Obligations — at a glance
Preview screen — each obligation is treated in depth in the licensed courseThe Personal Data Protection Act organises CSP duties around eleven obligations. They apply collectively — a CSP that consents-correctly but transfers-poorly is still in breach. Every CSP staff member needs the map; the licensed course teaches each obligation in operational detail.
Consent
Obtain consent for collection, use, or disclosure of personal data — and respect its withdrawal.
Purpose Limitation
Use personal data only for purposes a reasonable person would consider appropriate.
Notification
Tell individuals what their data will be used for, before or at the point of collection.
Access & Correction
Provide individuals access to their data on request, and correct errors.
Accuracy
Make reasonable effort to keep personal data accurate and complete.
Protection
Protect personal data with reasonable security arrangements.
Retention Limitation
Cease retention when the purpose no longer requires it and no legal duty compels it.
Transfer Limitation
Transfer personal data outside Singapore only if a comparable standard of protection is in place.
Accountability
Develop policies and practices, designate a DPO, and make information about both available.
Data Breach Notification
Notify the PDPC and affected individuals when a notifiable data breach occurs.
Data Portability
On request, transmit an individual's data to another organisation in a commonly-used format. (In force on appointed day.)
Source: Personal Data Protection Act 2012; PDPC Advisory Guidelines.
Data Breach Notification — when, who, how fast
Preview screen — full topic includes the decision tree, drafting templates, and case scenariosNot every data incident is a notifiable breach. The Data Breach Notification Obligation requires assessment, then action, on a tight clock. A CSP that gets the timing wrong compounds the original breach with a regulatory one.
The two-part test
A data breach must be notified if it (a) results in, or is likely to result in, significant harm to affected individuals, or (b) is of significant scale — affecting 500 or more individuals.
The notification timeline
| Step | Timing | Action |
|---|---|---|
| 1 | On suspicion of a breach | Assess promptly — generally not more than 30 calendar days — whether the incident meets the notifiable threshold. |
| 2 | Within 3 calendar days of assessment that it is notifiable | Notify the Personal Data Protection Commission (PDPC). |
| 3 | As soon as practicable | Notify each affected individual where the breach is likely to result in significant harm — unless an exemption applies (remedial action taken, prejudice to investigations, PDPC waiver). |
Common CSP breach patterns
Misdirected emails carrying client KYC packs, lost laptops with unencrypted client folders, vendor compromise affecting CSP-hosted client data, and access-control failures exposing beneficial-ownership records. Each plays out differently against the two-part test — the licensed course walks scenarios through to the notification decision.
Source: Personal Data Protection Act 2012, Part VIA; PDPC Advisory Guidelines on Data Breach Notification.
Knowledge check — PDPA
One sample question. Full courses use a 10-question randomised pool with 80% pass gate.Cybercrime & Cybersecurity for CSPs
© Richelle Lugtu. Course content, assessment design, and certificate template are proprietary. Online course access is licensed to engaged clients on subscription or licence terms.
Why this course exists
CSPs are a high-value target. They hold beneficial-ownership records, handle high-value transactions, sit on the trust that lets a fraudster impersonate a director. The threats are not abstract — phishing, business email compromise, credential theft, and ransomware all hit Singapore CSPs. This course gives staff the situational awareness and reflexes to be the firm's first defence rather than its weakest link.
- Recognise the dominant CSP-targeted threats and the vectors they arrive on.
- Identify phishing and business email compromise indicators in a real email.
- Apply the first 24 hours of incident response — contain, escalate, preserve, document.
- Understand reporting duties to the Singapore Police Force, ACRA, and the PDPC where data is involved.
- Apply staff-level controls that reduce the firm's overall exposure.
Phishing Email Inspector — find five red flags
Interactive screen — click anywhere on the email that looks suspiciousBelow is a phishing email impersonating a CSP's bank. Five elements are red flags. Click each one to identify it. Each correct hit reveals what the indicator is and why it matters.
Dear Valued Customer,
We have detected unusual activity on your corporate account. To prevent suspension, please verify your account details here within the next 24 hours.
Failure to act will result in your account being permanently suspended and all pending transactions cancelled.
Please find attached the verification form: Verification_Form.zip
Yours sincerely,
Pacific Crown Compliance Team
All five red flags identified
In a real inbox you may not have five clear signals — sometimes you have one. The discipline is the same: stop, check the sender domain, hover the link, refuse the urgency. When in doubt, escalate to your firm's IT or MLRO before clicking. The licensed course covers business email compromise variants, voice-call follow-ups, and the first-24-hours response if a phishing email has been actioned.
Incident response — the first 24 hours
Preview screen — full topic includes decision flows and reporting templatesThe first day of a cyber incident shapes the next six months. Most permanent damage — loss of evidence, regulatory non-compliance, customer-trust erosion — happens in the hours immediately after detection, when staff act on instinct rather than procedure. The framework below is what a CSP's IPPC should already specify; this screen makes it learnable.
Contain
Disconnect affected devices from the network. Disable compromised accounts. Stop the spread before investigating the source.
Escalate
Notify your MLRO, Compliance Officer, and IT lead — by phone, not email, in case email is compromised. Document who was told and when.
Preserve
Do not power off, wipe, or "clean up" affected systems. Preserve logs, screenshots, and copies of suspicious messages. Forensic value disappears with each action taken.
Document
Run an incident log from minute one. Times, decisions, people. The log becomes the basis of every later report.
External reporting decisions you may need to make
| Trigger | Report to | Timing consideration |
|---|---|---|
| Suspected criminal cyber offence | Singapore Police Force / Cybercrime Command | As soon as practicable; preserve evidence first. |
| Personal data breach meeting the notifiable threshold | PDPC (and affected individuals) | Notify PDPC within 3 calendar days of assessing the breach is notifiable. |
| Suspicious transaction surfacing as part of the incident | STRO (Suspicious Transaction Reporting Office) | Without delay once a reasonable basis for suspicion is formed. |
| Material impact on the CSP's regulated operations | ACRA | In line with the CSP's licence conditions and CSP Regulations 2025. |
Source: PDPA 2012, Part VIA; CSP Regulations 2025; SPF Cybercrime Command guidance.
Knowledge check — Cybercrime & Cybersecurity
One sample question. Full courses use a 10-question randomised pool with 80% pass gate.IPPC + Annexes — the policy product, previewed
© Richelle Lugtu. The IPPC document, all 40+ annexes, the editable training material set (AML, PDPA, and other modules in Word and PowerPoint), and the IPPC interactive course are proprietary. Available only as part of the IPPC + Annexes package; not licensed under standalone course subscriptions.
What the IPPC product is
A complete IPPC suite + annex library for Singapore registered CSPs — modular, customisable per firm. White-labelled · Internal Use Only.
ACRA's Guidelines for Registered CSPs require every CSP to develop, implement, and maintain Internal Policies, Procedures and Controls proportionate to its size and complexity. The IPPC is not a marketing document — it is the operational framework that an ACRA Reviewer will read to assess whether the CSP's controls work in practice.
Documents — customised to your firm
The IPPC and 40+ annexes are delivered modular and customised to the licensing CSP's service mix and risk appetite. White-labelled for the firm's internal use only — not for resale or external distribution.
Interactive courses — delivered ready-to-deploy
The interactive courses (AML/CFT/CPF, PDPA, Cybercrime, IPPC) are delivered ready-to-deploy. Built to ACRA-aligned methodology and refreshed against regulatory updates so all licensees benefit from the same maintained standard.
- The eight-section IPPC, drafted to ACRA's expectations and the CSP Act 2024 / CSP Regulations 2025 framework.
- The 40+ annex library — registers, templates, screening forms, escalation flows, training records.
- Customisation of the documents to the firm's services, structure, and risk appetite.
- The interactive course suite (AML, PDPA, Cybercrime, IPPC) deployed for all users.
- One annual review and update cycle covering both documents and course content.
- Twelve months' course access in Year 1; renewable annually thereafter.
The IPPC framework — six Parts, thirty-one sections
Preview screen — full IPPC v4.21 (every section, every clause) provided on engagementThe IPPC is organised into six thematic Parts (A–F) covering thirty-one sections. Each Part answers a different category of question an ACRA Reviewer is likely to ask. The Parts below show the architecture; the section-level policy text is part of the engagement deliverable.
| Part | Coverage | Sections | The question this Part answers |
|---|---|---|---|
| A | Foundation & Governance | Three Lines of Defence · Senior Management · Board · CO · MLRO · QIs · DPO · Group-Wide Programme (7 sections) | Who is accountable for AML/CFT/CPF inside this CSP, and how is that accountability exercised? |
| B | Risk Framework | Risk-Based Approach · EWRA · Four-Dimension CRA · National & Sectoral Risk · PF Risk · Service Classification · Designated Activities · Customer Acceptance (4 sections) | How is risk identified, scored, refreshed, and turned into onboarding and acceptance decisions? |
| C | Customer Due Diligence | CDD tiers (SDD, Standard, EDD) · UBO · NFF CDD · SOF/SOW · CDD reliance · PEPs · HNWI/UHNWI · Sanctions · Fit & Proper · Nominee Director / Shareholder (5 sections) | How does the CSP know who its customers and beneficial owners actually are — and what enhanced controls apply to higher-risk persons? |
| D | Monitoring & Reporting | Ongoing monitoring · Periodic review · Trigger events · Transaction monitoring · STR/SAR & MLRO functions · Tipping off · SONAR (3 sections) | How does the CSP keep customer risk under continuous view, and how does suspicion get from staff to a filed STR? |
| E | Operational Controls & Infrastructure | Record-keeping · Statutory registers (RORC, RND, RNS) · ACRA ETS controls · Data Protection & Breach · Anti-Bribery / COI / Whistleblowing · Outsourcing · New Products & Tech (7 sections) | Can the CSP produce records on demand, and are its operational controls fit for an inspection? |
| F | Governance, Assurance & Maintenance | Staff training · BCP · Notifications · Internal audit · Compliance Monitoring Plan · Governance reporting · Internal registers · Breach management · Review & version control · Annex Directory (10 sections) | Has the CSP trained, audited, monitored, reported, and updated its compliance framework as required? |
What's actually delivered
The full IPPC document — every Part, every section, every sub-section — plus the embedded staff acknowledgement form (ED-01) and regulatory reference table (ED-02). White-labelled to the licensing CSP, customised to its service mix, and supported by the eleven Annex Groups previewed in the next screen.
Source: CSP Act 2024 · CSP Regulations 2025 · ACRA Guidelines for Registered CSPs (May 2025, v2.0) · CDSA · TSOFA · UN Act 2001 · Companies Act 1967 · CLLPMA Act 2024 · PDPA 2012 · TF NRA 2024 · PF NRA 2024.
The annex library — eleven Groups, 40+ annexes
Preview list. Every annex (full text, forms, registers, guides) provided on engagement.Policy alone does not survive an inspection. The IPPC is supported by eleven Annex Groups (A–K) containing 40+ individual annexes — the live policies, methodology guides, registers, forms, and desk references that staff use day-to-day and that an ACRA Reviewer will sample. Each Group follows a disciplined three-layer structure: Master Policy → Methodology and Operational Guide → Concepts and Reference Guide → Supporting forms, registers, and desk cards.
| Group | Coverage | Annexes | Representative annexes |
|---|---|---|---|
| A | Risk Framework | 10 | Risk Policy (Master) · Four-Dimension CRA Scoring Tables (1–10 pick-list) · Comprehensive Country Risk Rating Guide · EWRA Completion Guide · CRA Quick-Reference Card |
| B | CDD & KYC/KYB | 6 | CDD Policy (Master) · Higher Risk Persons Policy (PEPs · HNWI/UHNWI) · Screening Policy · KYC/KYB Document Matrix & Certification |
| C | Onboarding & Client Management | 8 | Onboarding Policy (Master, 13-step) · Client Onboarding Pack (Forms D-01 to D-19) · Sensitive & Unacceptable Business Activities Policy · Designated Activity Guide (DA(a)–DA(e)) |
| D | Monitoring & Review | 6 | Monitoring Policy (Master) · Bank Account Management & Control Policy — multi-model framework · Compliance Monitoring Plan Guide · Client Filing Deadline Guide |
| E | Reporting & Escalation | 4 | STR/SAR/MLRO Policy (Master) · STR Filing Methodology & Decision Guide · Compliance Breach Escalation Policy |
| F | Governance & Oversight | 4 | Governance Policy (Master, 3LoD) · Governance Methodology & Calendar Guide · Quarterly & Annual Management Report Template |
| G | Data, Records & Technology | 4 | Data & Records Policy (Master, 5-year retention) · Technology & BCP Policy · Data Concepts & PDPA Reference Guide |
| H | Fit & Proper and Nominee | 5 | Fit & Proper Policy (Master) · Nominee Director Policy (CLLPMA Act 2024) · Nominee Shareholder Policy (broadened definition) |
| I | Operational Policies | 4 | Internal Operational Policies (Master) · Sales & Business Development Policy · Complaints & Outsourcing Policy |
| J | Training | 3 | Training Policy (Master) · Training Programme Guide · Training Modules & Assessments (T-01 to T-05) |
| K | Statutory Registers & Compliance Checklists | 5 | Statutory Register Policy (Master, RORC/RND/RNS) · Register Completion Methodology Guide · Internal Compliance Registers — multi-register tracking system |
What's actually delivered
All 40+ annexes — full policy text, methodology guides, concepts references, forms, registers, and desk cards — white-labelled to the licensing CSP for internal use only. Customised to the firm's service mix. Reviewed annually and updated against ACRA, MAS, PDPC, and FATF guidance changes. Not for resale or external distribution.
© Richelle Lugtu. The IPPC document, all 40+ annexes, the editable training material set (AML, PDPA, and other modules in Word and PowerPoint), and the IPPC interactive course are proprietary. Available only as part of the IPPC + Annexes package; not licensed under standalone course subscriptions.
Knowledge check — IPPC literacy
One sample question. Full courses use a 10-question randomised pool with 80% pass gate.Working sample — five-question assessment with instant rationales
Demonstration of the assessment pattern used in every full course — choose a regime belowEach suite draws five questions from its own pool of ten, in random order. The pass mark is 80%. Failed attempts can be retaken — the question set is reshuffled each time. In a full course, passing this gate triggers an auto-issued certificate and the result is written to the training-records layer.
© Richelle Lugtu. Course content, assessment design, and certificate template are proprietary. Online course access is licensed to engaged clients on subscription or licence terms.
Certificate template — issued automatically on assessment pass
In a full course, this certificate generates on passing the 80% assessment gate, opens in a printable window, and the result is written to the training-records layer. Choose which suite's course name to preview.
Certificate of Completion
This is to certify that
has successfully completed the course
"AML / CFT / CPF Foundations for CSP Staff"
attaining a passing score against the standard set out in the Course Assessment.
© Richelle Lugtu. Course content, assessment design, and certificate template are proprietary. Online course access is licensed to engaged clients on subscription or licence terms.
window.open) with the learner's name, the live date, and the actual score. The pass result is written to the training-records layer so inspection-ready training records can be produced on request. Failed attempts trigger a retake-from-scratch with the question pool reshuffled.
What your compliance officer sees in the LMS
⚠ Sample illustration only — all learner names, dates, and scores below are fictitious and do not represent real individuals or training recordsThis is the type of report a compliance officer pulls from the LMS to evidence training was delivered and completed. The table below spans both suites — filter by course to see either the CSP/ACRA or the MAS CMS records. Every full course in this suite reports the same data fields, regardless of which firm licenses it.
The screen below is styled to reflect a typical LMS reporting view. The exact look will vary by LMS and theme — the underlying data is what matters.
Course activity report
| First name / Surname▼ | Course | Started on | Last access | Score | Status |
|---|
What the data captures
Every course in this suite returns a standard learner-activity dataset to whichever LMS the firm runs — learner identity, lesson status, score, total session time, and attempt history. From that data the LMS produces its built-in reports, exports CSV/Excel/PDF, and feeds its activity completion tracking. Data retention follows the firm's own Record Retention Schedule.