Purpose, obligations and governing sources
The second edition, dated 31 October 2025, explains how IRAS reviews CRS compliance and what Reporting Singapore Financial Institutions (SGFIs) and their service providers should demonstrate. Reporting SGFIs register with IRAS, perform due diligence on all maintained Financial Accounts and report Reportable Accounts or file a Nil Return. Follow the 2016 CRS Regulations, IRAS guidance and OECD resources, subject to Singapore’s Wider Approach. This compliance guide complements rather than overrides those requirements. Its focus is controls, review evidence and remediation, not a replacement for the substantive CRS account-classification guide.
Risk-based oversight and proportionate controls
IRAS concentrates higher-intensity reviews on higher-risk institutions. It considers business characteristics, FATCA/CRS performance, other tax/regulatory compliance and exchange-partner feedback. Controls and resources should fit the institution’s size, complexity, products, clients and CRS exposure rather than follow one uniform model. Integrate CRS into existing risk-management systems and coordinate regulatory standards where possible to reduce duplication. IRAS supports voluntary compliance through clear information and outreach, while warnings and penalties remain available for institutions choosing non-compliance.
Four expectations for demonstrating compliance
Maintain robust entity-, process- and reporting-level controls; preserve evidence, information and records of the steps taken for at least five years under Regulation 14(6); run periodic independent reviews of controls and sample Financial Accounts; and correct systemic gaps with clear action plans. Reviewers should not formulate the institution’s CRS policies or perform its daily CRS operations. Internal compliance/audit teams or external auditors may qualify if independent. Track remediation progress and test effectiveness; IRAS monitors its own recommendations and expects cooperation.
Outsourcing and Reporting SGFI trusts
Outsourcing registration, due diligence or reporting does not transfer the institution’s responsibility. Retain oversight and governance, control outsourcing risks, and secure access to all records/evidence/information held, controlled or obtained by the provider in performing the institution’s functions. A trustee normally carries out the CRS work for a trust that is a Reporting SGFI, and is expected to apply this same compliance approach.
How to use the 23-outcome self-review toolkit
The framework contains six entity outcomes, fourteen process outcomes and three reporting outcomes. Assess each recommended control as Yes, No or Not Applicable. The toolkit is outcome-based: different controls may achieve the same outcome, but document the alternative basis. For NA, document why the control does not apply and any equivalent control. The annex contains 19 entity checks, 9 new-account checks, 13 preexisting-account checks, 11 monitoring checks, 5 closure checks and 10 reporting checks: 67 recommended checks in total. A count of positive answers does not replace demonstrating all relevant outcomes.
Entity outcomes 1–2: governance and risk control — checks 1–10
Outcome 1 calls for a supportive compliance environment: define roles/responsibilities, management oversight, a risk framework addressing major business/process changes, and skills/experience supported by training. Outcome 2 calls for preventive, detective and corrective risk controls: identify/evaluate/manage risks promptly; prevent and detect schemes circumventing reporting or due diligence; ensure outsourced-record access and provider governance; document CRS treatment of all Financial Accounts, including undocumented, dormant and excluded accounts; and correctly document balance aggregation and currency translation. These ten checks address both internal teams and outsourced work.
Entity outcomes 3–6: systems, change, information and monitoring — checks 11–19
Outcome 3 requires accurate/complete data throughout onboarding, due diligence and report production, with documentation and an audit trail. It applies to IT, Excel and manual processes alike. Outcome 4 requires managing changes in business, staff responsibilities, IT systems, acquired entities/accounts and IRAS registration details, with Regulation 13(5) notification where required; monitor legislative and IRAS/OECD updates and assess impact. Outcome 5 requires timely communication and documentation standards meeting the retention rule. Outcome 6 requires checking that policies/controls operate and stay current, periodic reporting tests, and an escalation channel documenting and resolving difficult matters.
New-account outcomes 7–10 — all nine checks
Define, identify and document New Accounts in the business context. Obtain valid self-certifications promptly, design forms capturing all required information, and identify Controlling Persons where required. Apply a reasonableness review of the Account Holder and Controlling Person using account-opening information and AML/KYC documents. Where the narrowly permitted day-two process is used for a transaction or sector, document its CRS-consistent basis and follow up promptly if the reasonableness test fails; it must be understood through IRAS/OECD FAQs, not treated as a blanket delay permission. Prevent accounts being opened when CRS requirements are unmet.
Preexisting-account outcomes 11–14 — all thirteen checks
Identify and document preexisting entity, high-value individual and lower-value individual accounts; document accounts exempt from review before starting diligence. If treating a new account as preexisting, verify every Regulation 15(13)(b) condition. Record elections to treat preexisting accounts as new or apply high-value procedures to lower-value accounts. Use procedures specific to each account category, apply the residence-address test only when eligible, and conduct applicable electronic searches, paper searches and Relationship Manager enquiries. Identify Controlling Persons of passive-NFE entity holders. Define undocumented accounts correctly and track follow-up, including high-value cases.
Monitoring outcomes 15–17 — all eleven checks
Define and detect changes in circumstances consistently with CRS; record information from operations staff or relationship managers, trigger diligence when balances cross thresholds, and address information known or reasonably believed to be unreliable/incorrect. Track changes, notify the responsible teams and record follow-up outcomes. The toolkit specifies outreach, treatment and new documentation by the later of 90 days or the calendar-year end following notice/discovery of the change. For preexisting lower-value accounts using the residence-address test, run an electronic search if self-certification and new Documentary Evidence are not obtained within that later deadline. Reapply enhanced review annually to undocumented accounts where relevant, and periodically verify undocumented, dormant and excluded classifications.
Closure outcomes 18–20 — all five checks
Use an account-closure definition consistent with Singapore applicable law and OECD commentary; where local law does not address closure, apply the institution’s normal procedures consistently to all accounts. Identify closed accounts for the reporting year. Before holder-initiated closure of a dormant account, conduct the required review and obtain CRS documents arising from it. Record closures accurately and promptly for reporting. Closure is therefore an event to capture, not an automatic reason to remove an account from the year’s reporting.
Reporting outcomes 21–23 — all ten checks
Extract complete/accurate database information using an appropriate cut-off; reconcile reports to source data and perform analytical/exception reviews. Use the latest CRS XML Schema or fillable PDF and IRAS XML User Guide. Track the statutory deadline, obtain internal approvals before submission and file Nil Returns when no reportable account exists for the relevant year. Monitor and correct errors promptly, investigate their root causes to prevent recurrence, and resubmit corrected returns in time. Data extraction, approval and correction controls all form part of the reporting evidence.
Risk factors and how IRAS conducts a review
Risk factors include industry/sector, business type and complexity, size, client profile, geographic presence, domestic/multinational group membership and CRS resources; FATCA/CRS timeliness, quality and completeness; AML/KYC and tax compliance; and partner feedback on data and correction speed. IRAS may examine trends such as major changes in reported record counts. It contacts the designated Point of Contact and may use desk questionnaires/clarifications or on-site interviews and document/process reviews. On-site preparations use a reasonable mutually agreed timeline. The intensity depends on risks identified through the review, and the listed factors are not exhaustive.
Remediation, independent assurance and 2025 changes
IRAS may set recommendations and a specific remediation timetable, follow up with explanations/documents, and request independent ad-hoc attestations if dissatisfied with corrective action. Later reviews may be ad hoc, annual or less frequent depending on risk. IRAS may rely on internal/external review results case by case, considering reviewer independence, audit competence and technical CRS knowledge. Institutions should disclose issues early and work with IRAS; no mandatory universal annual external audit or automatic safe harbour is created here. Enquiries use the IRAS international-tax contact page. The October 2025 revision added the website compliance-information pointer, expressly included IT changes in entity checklist 13, and made editorial amendments; the first edition was July 2019.
Official source
This article independently explains the substantive contents of the official PDF, including the relevant conditions, procedures and annexes. The linked document remains the authoritative source for its original wording, and later changes should be checked separately.
Read the official PDF ↗
