Manage due diligence, screening, statutory records and review deadlines from one system. Episcript builds custom corporate compliance software for organisations that manage obligations across many entities and cannot rely on spreadsheets to prove what was done.
KYC and AML checks, identity verification, statutory records, audit trails, XBRL filings and recurring reviews sit on the same record. The system follows the controls and approval steps your organisation already applies. AI features can be added later to read documents, flag gaps and rank what needs attention this week.
Built in Singapore, for Singapore regulatory obligations.
Compliance work becomes difficult when due diligence, screening, review dates and supporting evidence sit in separate places. A corporate compliance system brings those checks together and keeps the audit trail against the same entity or person.
We map the controls your organisation already applies and build the workflows, fields and modules around them. KYC, risk ratings, screening, identity checks, review dates and supporting evidence can all sit within the same compliance record.
If your main requirement is company administration, ACRA filings, statutory registers and corporate documents, our corporate secretarial software covers that area. This system focuses on the wider compliance programme, including due diligence, identity verification, screening, monitoring and audit evidence.
What changes when the system is in place
Each client, entity and officer travels the same route. The system records where each one has reached, what evidence supports it and who holds the next task.
Open the record, collect the documents your policy demands and log who supplied each one.
Confirm identity through an approved Singpass route, passport matching or live facial capture.
Run AML and sanctions screening through your provider, then file the result against the subject.
Record the risk rating, the reviewer and the reasoning. Escalations follow your own approval chain.
Watch expiry dates, periodic reviews and statutory deadlines, with reminders sent well ahead.
Prepare the compliance report, the audit trail and the annual filing information from the same data set.
The system holds the whole due diligence file against the person or entity it concerns. Identification documents, proof of address, source of funds declarations, screening results and the risk rating all attach to one subject. Open the record and the current position reads at a glance, including what expires next.
Screening runs through the provider your organisation already subscribes to, where that provider publishes an API. Results return to the record rather than to somebody's inbox. A match escalates to the reviewer your policy names, who clears it or refers it upward, and the decision stays on file with the reasoning attached.
Two routes to the same outcome. Use the national service where it suits the client, and your own capture where it does not.
Where the use case is eligible and approved, clients verify themselves through Singpass rather than sending documents by email. The check returns a pass or a fail to the subject record, with the timestamp attached. We confirm the route available to your organisation during scoping.
Our own capture covers foreign directors, shareholders and anyone outside Singpass. The subject takes a live photograph, the system matches it against the passport or identity document supplied, and both images file against the record.
A staff member reviews each result and approves or rejects it. Every attempt writes to the verification log with the user, the method and the outcome, which answers the question an auditor asks first.
Compliance checks need a subject. Four modules hold who the entity is, who runs it and who owns it, which is what your screening and your registers draw on.
Every entity keeps one record: incorporation particulars, UEN, SSIC codes, financial year end, registered and correspondence addresses, service tags and key dates. Search and filter across the whole portfolio, whether you hold thirty entities or three thousand. Change a detail once and every register, document and report drawn from it picks up the new value.
Directors, company secretaries and other officers sit against the entity with their appointment and cessation dates, identity documents and supporting files. Each officer is also a due diligence subject, which means their verification status and screening result read from the same screen. Registers and forms populate from what is already stored.
Individual and corporate shareholders share one module, with share records, certificates and allotment history behind each holder. Ownership passing up through a corporate shareholder stays traceable, which matters when you have to identify the controller sitting at the top. The record supports the register of members and your beneficial ownership work.
Track issued and paid-up capital by share class and currency. Record an allotment, amend a class, and the capital position updates across the register of members and the certificates issued from it. Earlier positions remain readable, so a reviewer can see the structure as it stood on any past date without rebuilding it from board papers.
Registers generate from the entity record and update in real time. Nobody maintains a parallel spreadsheet, and nobody discovers at year end that the two versions disagree.
Corporate changes carry their own history. Share transfers, allotments, address changes and financial year updates each open as an action, run through to completion and stay readable afterwards. Export any register when a regulator, an auditor or a bank asks for it.
Four modules watch the calendar and the log, which between them answer what is due, what is late and what changed.
The reminder engine tracks AGM, annual return, ECI and GST dates alongside your own internal review cycles. Reminders leave by email, WhatsApp or SMS on the lead time you set, and the wording is yours. A live dashboard separates what falls due this month from what has already slipped, and delivery is tracked, so a client cannot claim the notice never arrived.
Reports cover tax progress, AGM status, KYC completeness, entities without an assigned reviewer and anything else you filter on. Run them when a partner asks, or schedule them for the monthly compliance meeting. The numbers come from the live record, which removes the round of email chasing that usually precedes the meeting.
Every edit, approval, deletion and record view writes to the log with the user and the timestamp. The trail runs in the background, so nobody has to remember to record anything. When an auditor asks who amended a controller entry in March, the answer takes a search rather than an investigation, and the export goes straight into the audit file.
Start a share transfer, an address change or a financial year update as an action and follow it through. Each change shows its current stage, the person holding it and the documents collected so far. Completed changes drop into the entity history, where they stay readable years later without anyone opening a folder of scanned paper.
The system prepares the annual report and generates the XBRL file itself, ready for submission through BizFile.
Trial balances, disclosures, notes and statements draw on the same figures. Nobody reformats a spreadsheet, and nobody checks the same number in three documents. Version control keeps each draft, and the audit trail records who changed what between them. Preparation that used to mean manual formatting runs as a guided workflow, with review points built into it.
From trial balance to submission
Documents draft themselves from data already held, travel out for signature, and file back where the evidence belongs.
Resolutions, declarations, forms, agreements and certificates draft from the entity record using your own branded templates and merge fields. Your team reviews the draft and releases it. Nobody opens last year's file and edits the names, which is where the wrong company name usually creeps in.
Send a document for signature and track it to completion. Signing uses a one-time password, works on a phone, and handles bulk dispatch when the same declaration goes to forty directors. Each signature carries its own record: who signed, when, and from which verified identity.
System-generated and uploaded files sit in structured folders against the entity, with tags, version control and access granted by role. A junior reaches the files they work on. Sensitive matters stay closed. Finding a document takes a search rather than a message to whoever filed it.
Compliance work stalls when it waits on a client. The portal turns that wait into something you can see and chase.
Clients sign in and serve themselves. They download documents, read invoices, answer a request for information, upload the identity documents your due diligence needs and complete any form you have published. Access reaches their own records only. Every action writes to the log against that client, which settles the question of who supplied what and when. The chase for a missing document turns into a status column rather than a fortnight of email.
The modules above carry the compliance work. Behind them sits the wider library. We switch on what you need, quote the rest as later phases, and build anything you run that is not listed here.
Fees raised, chased and reconciled against the client record.
Raise invoices for retainers, compliance reviews or one-off work directly from the client file. Track payments, issue reminders and draw reports by client or by service. Organisations billing well beyond compliance work can widen this into our invoicing and payment management system.
Service agreements held with their fees, durations, renewal dates and termination terms. Active, terminated and reinstated agreements each carry their own status, and the system validates the dates rather than trusting a typed entry.
Who is doing what, and where anything is filed.
Log a conversation, assign a task, set the deadline and attach the discussion to the client or the record it concerns. A reviewer picking up a file reads the context rather than asking the colleague who handled it last.
Search across people, entities, roles, KYC status, billing and compliance history from one interface. Filter on any condition you set: entities overdue for review, controllers with an expired identity document, clients screened before a given date.
Reaching clients on the channel they actually read.
Send personalised reminders, document requests and status updates through WhatsApp Business or SMS. Delivery is tracked and every message logs against the client, which matters when a deadline passes and the file has to show what was sent.
Run campaigns to your client list using branded templates and filters. Announce a regulatory change, circulate a newsletter or warn a segment about an approaching deadline, then read the engagement figures afterwards.
Enquiry forms on your website and social channels drop straight into the system. Each enquiry lands with a follow-up owner and a status, and the conversion picture builds from real records rather than a spreadsheet somebody updates on Fridays.
The physical side of the work, recorded like everything else.
Log incoming mail against the entity, notify the client, forward it and record the outcome. Collections require identity verification before anything leaves the office, and the activity report shows every item handled over any period you choose.
AI features for corporate compliance software are scoped with you and built in their own phase. Each one works with information already held in your system, and you watch it run before it goes live.
AI reads an incoming identity document, certificate or letter and lifts the names, dates, addresses and figures from it. Your staff confirm the values before anything updates a record.
AI sorts screening hits by how closely they match the subject you hold, and drafts a short note on each one. A reviewer still decides, and the decision files with the reasoning.
AI scans entity records for what is missing or inconsistent: a controller without particulars, an expired identity document, an officer with no verification result. Each finding lands as a task.
AI ranks the entities needing attention this week, weighing risk rating, review dates, filing status and how long a request has waited on a client response.
AI summarises a compliance file before a periodic review: the current officers, the ownership chain, recent changes, screening history and anything outstanding, drawn from your own records.
AI answers client questions inside the portal using information from their own file. Anything it cannot answer routes to the staff member handling that client.
We scope each connection against the platforms your organisation already uses. Where a screening provider, accounting package or signing service publishes a suitable API, we can quote that integration as part of the build.
How a custom corporate compliance system compares with an off-the-shelf compliance platform.
| Point of comparison | EpiscriptCustom build | Typical productOff-the-shelf platform |
|---|---|---|
| Fit to your compliance controls | Built around your policy, risk bands, approvals and review cycles | Configured within the workflows, rules and options the platform supports |
| Due diligence and screening | Connects to the screening provider you choose, where a suitable API is available | Provider choice and pricing depend on the platform's supported integrations or bundled services |
| Identity verification | Supports approved Singpass routes, live capture and document matching | Identity verification depends on the platform and its supported Singapore integrations |
| Singapore registers and filings | Modules built around Singapore records such as the RORC and nominee registers | Coverage varies according to the markets and jurisdictions the product supports |
| XBRL and annual reporting | Generates XBRL output from the same controlled data set where included in scope | May be built in, integrated, or handled through a separate preparation tool |
| Evidence and audit trail | Audit evidence follows your own record structure, permissions and reporting needs | Audit trails generally follow the structure and export formats the product supports |
| Adding a module later | Additional modules designed and quoted as later phases | Additional functionality depends on available modules, APIs and the vendor roadmap |
| AI features | Scoped around your own data, controls and human review process | AI capabilities depend on what the platform provides and how much configuration it allows |
| Commercial model | Usually project-based, with hosting, support and licensing defined in the agreement | Usually subscription-based, often by user, entity, module or usage |
Swipe to see the full table
A focused first phase can often be delivered within weeks, depending on scope and integrations. Policy mapping and template work take the opening stretch, then migration, testing and training follow. The number of modules and the depth of customisation set the pace, and builds with a portal, verification and provider integrations run longer.
Most teams do not need to move everything at once. They usually start with entity records, due diligence and reminders, then add verification, registers, XBRL, the portal and AI features as later phases. Each phase carries its own quote and its own release, which spreads the cost across the financial year and keeps the first release small enough to test properly.
Where compliance reviews and internal deadlines feed a wider view of your team's workload, they can also flow into our project management system.
We walk through your compliance policy, risk bands, approval steps and document wording, then agree what the first phase covers.
You review working screens as they arrive rather than a written specification. Changes cost least at this point.
We map your spreadsheets or your current system, run a test import for you to check, then load the live data.
Your staff train on their own records. Support continues after handover, by phone, email or video call.
Corporate secretarial software runs company administration: incorporation, ACRA filings, statutory registers, AGMs and corporate documents. Corporate compliance software covers the wider obligation: due diligence, identity verification, AML screening, risk ratings, monitoring, evidence and regulatory reporting. Many organisations run both, on one platform, with the entity record shared between them.
Yes. We build the due diligence workflow around the policy your organisation already applies: the documents you collect, the checks you carry out, the risk rating you assign, the reviewer who approves it and the review dates that follow. Screening results, expiry dates and KYC status file against each individual and entity. The obligation stays with your organisation, and the system keeps the record.
The system connects to the screening provider your organisation already subscribes to, where that provider publishes a suitable API. We scope the connection during the build and quote it as part of the project. Episcript does not resell a screening service, so you keep your existing contract, your existing data sources and your existing per-check pricing.
Identity verification runs two ways. Singpass-enabled verification can be integrated where the use case is eligible and approved, since the higher-assurance Singpass routes are restricted and subject to approval. Everyone else, including foreign directors and shareholders, uses our own live facial capture with passport or identity document matching. A staff member approves or rejects each result, and every attempt writes to the verification log.
Yes. The system generates the XBRL file itself, ready for submission through BizFile. You import the trial balance, map the accounts once, complete the guided disclosures, and the annual report and the XBRL file both build from that single data set. Version control keeps each draft, and the audit trail records who changed what along the way.
Statutory dates are tracked per entity, covering AGM, annual return, ECI and GST, alongside your own review cycles and document expiry dates. Reminders leave by email, WhatsApp or SMS on the lead time you set, with delivery tracked. A dashboard separates what falls due from what has already slipped, and alerts fire when something passes without action.
Every edit, approval, deletion and record access writes to the log with the user and the timestamp. The trail runs in the background rather than depending on staff to record anything. You can filter it by entity, by user or by date range, then export the result for an audit file, an internal review or a regulator's request.
Yes. The client portal handles document downloads, invoices, reminders, form submissions and uploads. Clients supply the identity documents your due diligence needs without sending them by email. Access reaches their own records only, and every portal action writes to the log against that client, which shows who supplied what and when.
Yes. We map your spreadsheets or your current database to the new structure, clean the data with you, then load entity records, officers, shareholdings, due diligence files and document history. You check a test import before the live run. Nothing is dropped without your sign-off, and the old system stays available until you are satisfied.
Yes. Most teams begin with entity records, due diligence and reminders. Identity verification, registers, XBRL preparation, the client portal, reporting and AI features follow in later phases. Each phase is quoted and released on its own, which spreads the cost across your financial year and keeps the first release small enough to test properly.
The system prepares the records, annual report information and XBRL file the filing workflow needs. Submission itself still takes place through ACRA BizFile, and the generated file is prepared for that process. Where a direct integration is available for a particular transaction, we assess it as part of the project scope.
Hosting is scoped around your organisation’s security, deployment and data residency requirements. Where Singapore hosting is required, the system can be deployed on suitable Singapore-based infrastructure. Role-based access, document permissions, logging and other controls are configured to support your PDPA and internal security requirements.
Compliance work holds a great deal of personal data. Access is granted by role and by client, documents carry their own permissions, and activity logs record who viewed or changed a record. Those controls support your obligations under the PDPA, alongside your own policies and staff training. Responsibility for meeting those obligations stays with your organisation.
Government support may be available for qualifying projects, subject to the prevailing eligibility criteria and approval requirements. Software costs form part of some transformation grants. Approval is never guaranteed, and the position changes from time to time, so confirm your eligibility with the relevant agency before committing to the project.
Finance, operations and reporting on one platform, where compliance is one function among several.
Read more Human resource managementStaff records, work passes, leave and payroll, with their own set of statutory dates to watch.
Read more Custom CRM softwareA fuller pipeline for firms chasing corporate work, with scoring, routing and campaign tracking.
Read moreWhether you manage a small portfolio or several hundred entities, Episcript builds a corporate compliance system matched to your workflows, your controls and your regulatory obligations. Book a demo and we will walk through it with a real file.