Corporate Compliance Software for Singapore Companies

Manage due diligence, screening, statutory records and review deadlines from one system. Episcript builds custom corporate compliance software for organisations that manage obligations across many entities and cannot rely on spreadsheets to prove what was done.

KYC and AML checks, identity verification, statutory records, audit trails, XBRL filings and recurring reviews sit on the same record. The system follows the controls and approval steps your organisation already applies. AI features can be added later to read documents, flag gaps and rank what needs attention this week.

Built in Singapore, for Singapore regulatory obligations.

Corporate compliance software from Episcript, showing due diligence records, screening status and review deadlines for one entity
  • Screening, verification and review dates tracked per entity
  • Built to order, around your own compliance controls
  • Singpass-enabled identity verification
  • Connects to WhatsApp Business, SMS, digital signing and more
  • Eligible for Government grants
Built around your controls

Corporate compliance management in one connected system

Compliance work becomes difficult when due diligence, screening, review dates and supporting evidence sit in separate places. A corporate compliance system brings those checks together and keeps the audit trail against the same entity or person.

We map the controls your organisation already applies and build the workflows, fields and modules around them. KYC, risk ratings, screening, identity checks, review dates and supporting evidence can all sit within the same compliance record.

If your main requirement is company administration, ACRA filings, statutory registers and corporate documents, our corporate secretarial software covers that area. This system focuses on the wider compliance programme, including due diligence, identity verification, screening, monitoring and audit evidence.

Connected compliance records

What changes when the system is in place

  • Each entity carries its KYC status, risk rating and next review date
  • Screening results are recorded against the relevant person or company
  • Identity checks can run through Singpass or an approved verification process
  • Compliance deadlines can trigger reminders before they fall due
  • The audit trail records changes, checks and reviewer activity automatically
  • AI features can work with your compliance data and be added when required
The compliance lifecycle

How a compliance obligation moves through the system

Each client, entity and officer travels the same route. The system records where each one has reached, what evidence supports it and who holds the next task.

  1. 01

    Onboard

    Open the record, collect the documents your policy demands and log who supplied each one.

  2. 02

    Verify

    Confirm identity through an approved Singpass route, passport matching or live facial capture.

  3. 03

    Screen

    Run AML and sanctions screening through your provider, then file the result against the subject.

  4. 04

    Assess

    Record the risk rating, the reviewer and the reasoning. Escalations follow your own approval chain.

  5. 05

    Monitor

    Watch expiry dates, periodic reviews and statutory deadlines, with reminders sent well ahead.

  6. 06

    Report

    Prepare the compliance report, the audit trail and the annual filing information from the same data set.

Due diligence

KYC, CDD and AML compliance software

The system holds the whole due diligence file against the person or entity it concerns. Identification documents, proof of address, source of funds declarations, screening results and the risk rating all attach to one subject. Open the record and the current position reads at a glance, including what expires next.

Screening runs through the provider your organisation already subscribes to, where that provider publishes an API. Results return to the record rather than to somebody's inbox. A match escalates to the reviewer your policy names, who clears it or refers it upward, and the decision stays on file with the reasoning attached.

  • Customer and entity due diligence files, structured to your own policy
  • AML and sanctions screening through your chosen provider
  • Risk ratings, escalation routes and named reviewers
  • Document expiry dates that raise an alert before they pass
  • Periodic review cycles set by risk band
  • KYC status visible across every individual and entity you hold
Due diligence record in the Episcript compliance system, showing KYC status, screening results and the next review date
Identity checks

Identity verification and face scan

Two routes to the same outcome. Use the national service where it suits the client, and your own capture where it does not.

Singpass-enabled verification

Where the use case is eligible and approved, clients verify themselves through Singpass rather than sending documents by email. The check returns a pass or a fail to the subject record, with the timestamp attached. We confirm the route available to your organisation during scoping.

Live facial capture and passport matching

Our own capture covers foreign directors, shareholders and anyone outside Singpass. The subject takes a live photograph, the system matches it against the passport or identity document supplied, and both images file against the record.

Admin approval and verification log

A staff member reviews each result and approves or rejects it. Every attempt writes to the verification log with the user, the method and the outcome, which answers the question an auditor asks first.

The data underneath

Entity, officer and ownership records

Compliance checks need a subject. Four modules hold who the entity is, who runs it and who owns it, which is what your screening and your registers draw on.

Company profile module holding incorporation particulars, SSIC codes, addresses and key dates

Company profile management

Every entity keeps one record: incorporation particulars, UEN, SSIC codes, financial year end, registered and correspondence addresses, service tags and key dates. Search and filter across the whole portfolio, whether you hold thirty entities or three thousand. Change a detail once and every register, document and report drawn from it picks up the new value.

Officers module tracking director and secretary appointments, cessations and identity documents

Officers and appointments

Directors, company secretaries and other officers sit against the entity with their appointment and cessation dates, identity documents and supporting files. Each officer is also a due diligence subject, which means their verification status and screening result read from the same screen. Registers and forms populate from what is already stored.

Shareholder module showing individual and corporate holders, certificates and allotment history

Shareholders and ownership

Individual and corporate shareholders share one module, with share records, certificates and allotment history behind each holder. Ownership passing up through a corporate shareholder stays traceable, which matters when you have to identify the controller sitting at the top. The record supports the register of members and your beneficial ownership work.

Share capital module covering share classes, issued and paid-up amounts and historical changes

Share capital

Track issued and paid-up capital by share class and currency. Record an allotment, amend a class, and the capital position updates across the register of members and the certificates issued from it. Earlier positions remain readable, so a reviewer can see the structure as it stood on any past date without rebuilding it from board papers.

Regulatory records

Statutory registers and corporate changes

Registers generate from the entity record and update in real time. Nobody maintains a parallel spreadsheet, and nobody discovers at year end that the two versions disagree.

Corporate changes carry their own history. Share transfers, allotments, address changes and financial year updates each open as an action, run through to completion and stay readable afterwards. Export any register when a regulator, an auditor or a bank asks for it.

Register of registrable controllers
RORC entries with beneficial ownership particulars, cessation dates and the change history behind each one.
Registers of members and officers
Shareholdings, transfers and appointments, drawn from the entity record rather than typed a second time.
Register of charges
Charges recorded against the entity with their particulars, dates and supporting documents.
Nominee director and shareholder registers
ROND and RONS records held alongside the RORC where your organisation maintains them.
Corporate change history
Every transfer, allotment, name change and particulars update, with changes in progress visible separately.
Compliance evidence
The documents, approvals and screening results supporting each entry, attached where a reviewer expects to find them.
Staying ahead of the date

Compliance monitoring, reminders and audit trails

Four modules watch the calendar and the log, which between them answer what is due, what is late and what changed.

Deadline reminder engine tracking AGM, annual return, ECI and GST dates

Compliance and deadline reminders

The reminder engine tracks AGM, annual return, ECI and GST dates alongside your own internal review cycles. Reminders leave by email, WhatsApp or SMS on the lead time you set, and the wording is yours. A live dashboard separates what falls due this month from what has already slipped, and delivery is tracked, so a client cannot claim the notice never arrived.

Compliance reporting screen covering tax progress, AGM tracking and outstanding client follow-ups

Compliance reports and dashboards

Reports cover tax progress, AGM status, KYC completeness, entities without an assigned reviewer and anything else you filter on. Run them when a partner asks, or schedule them for the monthly compliance meeting. The numbers come from the live record, which removes the round of email chasing that usually precedes the meeting.

Audit trail log recording edits, approvals and record access with user and timestamp

Audit trails and access logs

Every edit, approval, deletion and record view writes to the log with the user and the timestamp. The trail runs in the background, so nobody has to remember to record anything. When an auditor asks who amended a controller entry in March, the answer takes a search rather than an investigation, and the export goes straight into the audit file.

Corporate changes module tracking share transfers, address changes and financial year updates

Corporate changes in progress

Start a share transfer, an address change or a financial year update as an action and follow it through. Each change shows its current stage, the person holding it and the documents collected so far. Completed changes drop into the entity history, where they stay readable years later without anyone opening a folder of scanned paper.

Regulatory filings

Annual report and XBRL preparation software

The system prepares the annual report and generates the XBRL file itself, ready for submission through BizFile.

Annual report and XBRL preparation module showing a guided workflow with disclosures and version history

One data set, one filing

Trial balances, disclosures, notes and statements draw on the same figures. Nobody reformats a spreadsheet, and nobody checks the same number in three documents. Version control keeps each draft, and the audit trail records who changed what between them. Preparation that used to mean manual formatting runs as a guided workflow, with review points built into it.

The workflow

From trial balance to submission

  1. 1Import the trial balance. Load the figures for the entity and map the accounts once. The mapping holds for next year.
  2. 2Complete the disclosures. Work through the guided set, with last year's answers carried forward for editing.
  3. 3Generate the statements. The system builds the financial statements and the notes from the mapped data.
  4. 4Review and version. Circulate the draft, record the comments and keep each version with its author.
  5. 5Generate the XBRL file. The system produces the XBRL file, ready for submission through BizFile.
Paperwork and proof

Document generation, digital signing and the compliance repository

Documents draft themselves from data already held, travel out for signature, and file back where the evidence belongs.

Document generation module drafting resolutions, forms and certificates from live entity data

Document generation

Resolutions, declarations, forms, agreements and certificates draft from the entity record using your own branded templates and merge fields. Your team reviews the draft and releases it. Nobody opens last year's file and edits the names, which is where the wrong company name usually creeps in.

Digital signing screen showing OTP verification, bulk dispatch and signature status per recipient

Digital signing and form distribution

Send a document for signature and track it to completion. Signing uses a one-time password, works on a phone, and handles bulk dispatch when the same declaration goes to forty directors. Each signature carries its own record: who signed, when, and from which verified identity.

Document repository with structured folders, tagging, version control and role-based access

Document repository and folders

System-generated and uploaded files sit in structured folders against the entity, with tags, version control and access granted by role. A junior reaches the files they work on. Sensitive matters stay closed. Finding a document takes a search rather than a message to whoever filed it.

Client access

Client portal for documents and submissions

Compliance work stalls when it waits on a client. The portal turns that wait into something you can see and chase.

Client portal showing documents, invoices, reminders and outstanding form submissions for one client

Self-service for the documents you keep chasing

Clients sign in and serve themselves. They download documents, read invoices, answer a request for information, upload the identity documents your due diligence needs and complete any form you have published. Access reaches their own records only. Every action writes to the log against that client, which settles the question of who supplied what and when. The chase for a missing document turns into a status column rather than a fortnight of email.

Module library

More modules in the compliance library

The modules above carry the compliance work. Behind them sits the wider library. We switch on what you need, quote the rest as later phases, and build anything you run that is not listed here.

Billing and agreements

Fees raised, chased and reconciled against the client record.

  • Invoicing and billing

    Raise invoices for retainers, compliance reviews or one-off work directly from the client file. Track payments, issue reminders and draw reports by client or by service. Organisations billing well beyond compliance work can widen this into our invoicing and payment management system.

  • Agreement management

    Service agreements held with their fees, durations, renewal dates and termination terms. Active, terminated and reinstated agreements each carry their own status, and the system validates the dates rather than trusting a typed entry.

Team workload and search

Who is doing what, and where anything is filed.

  • Internal notes, tasks and memos

    Log a conversation, assign a task, set the deadline and attach the discussion to the client or the record it concerns. A reviewer picking up a file reads the context rather than asking the colleague who handled it last.

  • Advanced search and reporting

    Search across people, entities, roles, KYC status, billing and compliance history from one interface. Filter on any condition you set: entities overdue for review, controllers with an expired identity document, clients screened before a given date.

Client messaging

Reaching clients on the channel they actually read.

  • WhatsApp Business and SMS

    Send personalised reminders, document requests and status updates through WhatsApp Business or SMS. Delivery is tracked and every message logs against the client, which matters when a deadline passes and the file has to show what was sent.

  • Mass email and broadcasting

    Run campaigns to your client list using branded templates and filters. Announce a regulatory change, circulate a newsletter or warn a segment about an approaching deadline, then read the engagement figures afterwards.

  • Online enquiries

    Enquiry forms on your website and social channels drop straight into the system. Each enquiry lands with a follow-up owner and a status, and the conversion picture builds from real records rather than a spreadsheet somebody updates on Fridays.

Operational support

The physical side of the work, recorded like everything else.

  • Mail management

    Log incoming mail against the entity, notify the client, forward it and record the outcome. Collections require identity verification before anything leaves the office, and the activity report shows every item handled over any period you choose.

Capability

AI features for corporate compliance software in Singapore

AI features for corporate compliance software are scoped with you and built in their own phase. Each one works with information already held in your system, and you watch it run before it goes live.

AI reading an incoming identity document and lifting names, dates and addresses from it

Document reading

AI reads an incoming identity document, certificate or letter and lifts the names, dates, addresses and figures from it. Your staff confirm the values before anything updates a record.

AI sorting screening hits by how closely each one matches the subject on file

Screening match triage

AI sorts screening hits by how closely they match the subject you hold, and drafts a short note on each one. A reviewer still decides, and the decision files with the reasoning.

AI checking an entity record for missing particulars and expired documents

Gap detection in records

AI scans entity records for what is missing or inconsistent: a controller without particulars, an expired identity document, an officer with no verification result. Each finding lands as a task.

AI ranking entities by risk rating and outstanding review dates

Suggested review priorities

AI ranks the entities needing attention this week, weighing risk rating, review dates, filing status and how long a request has waited on a client response.

AI summarising a compliance file ahead of a periodic review

File summaries for review

AI summarises a compliance file before a periodic review: the current officers, the ownership chain, recent changes, screening history and anything outstanding, drawn from your own records.

AI answering a client question inside the compliance portal

Portal assistant

AI answers client questions inside the portal using information from their own file. Anything it cannot answer routes to the staff member handling that client.

Connections

Integration with the systems you already run

We scope each connection against the platforms your organisation already uses. Where a screening provider, accounting package or signing service publishes a suitable API, we can quote that integration as part of the build.

  • Singpass
  • WhatsApp Business
  • SMS gateways
  • Digital signing
  • KYC and screening providers
  • Email campaigns
Weighing it up

Custom compliance software or a packaged platform

How a custom corporate compliance system compares with an off-the-shelf compliance platform.

Comparison of a custom corporate compliance system and a packaged compliance platform across process fit, due diligence, identity verification, registers, XBRL, evidence, extensibility, AI and commercial model.
Point of comparison EpiscriptCustom build Typical productOff-the-shelf platform
Fit to your compliance controls Built around your policy, risk bands, approvals and review cycles Configured within the workflows, rules and options the platform supports
Due diligence and screening Connects to the screening provider you choose, where a suitable API is available Provider choice and pricing depend on the platform's supported integrations or bundled services
Identity verification Supports approved Singpass routes, live capture and document matching Identity verification depends on the platform and its supported Singapore integrations
Singapore registers and filings Modules built around Singapore records such as the RORC and nominee registers Coverage varies according to the markets and jurisdictions the product supports
XBRL and annual reporting Generates XBRL output from the same controlled data set where included in scope May be built in, integrated, or handled through a separate preparation tool
Evidence and audit trail Audit evidence follows your own record structure, permissions and reporting needs Audit trails generally follow the structure and export formats the product supports
Adding a module later Additional modules designed and quoted as later phases Additional functionality depends on available modules, APIs and the vendor roadmap
AI features Scoped around your own data, controls and human review process AI capabilities depend on what the platform provides and how much configuration it allows
Commercial model Usually project-based, with hosting, support and licensing defined in the agreement Usually subscription-based, often by user, entity, module or usage

Swipe to see the full table

Implementation

What the first few weeks look like

A focused first phase can often be delivered within weeks, depending on scope and integrations. Policy mapping and template work take the opening stretch, then migration, testing and training follow. The number of modules and the depth of customisation set the pace, and builds with a portal, verification and provider integrations run longer.

Most teams do not need to move everything at once. They usually start with entity records, due diligence and reminders, then add verification, registers, XBRL, the portal and AI features as later phases. Each phase carries its own quote and its own release, which spreads the cost across the financial year and keeps the first release small enough to test properly.

Where compliance reviews and internal deadlines feed a wider view of your team's workload, they can also flow into our project management system.

  1. Scope your controls

    We walk through your compliance policy, risk bands, approval steps and document wording, then agree what the first phase covers.

  2. Build the first phase

    You review working screens as they arrive rather than a written specification. Changes cost least at this point.

  3. Migrate your records

    We map your spreadsheets or your current system, run a test import for you to check, then load the live data.

  4. Train the team and go live

    Your staff train on their own records. Support continues after handover, by phone, email or video call.

Questions

Corporate compliance software questions we are asked

Corporate secretarial software runs company administration: incorporation, ACRA filings, statutory registers, AGMs and corporate documents. Corporate compliance software covers the wider obligation: due diligence, identity verification, AML screening, risk ratings, monitoring, evidence and regulatory reporting. Many organisations run both, on one platform, with the entity record shared between them.

Yes. We build the due diligence workflow around the policy your organisation already applies: the documents you collect, the checks you carry out, the risk rating you assign, the reviewer who approves it and the review dates that follow. Screening results, expiry dates and KYC status file against each individual and entity. The obligation stays with your organisation, and the system keeps the record.

The system connects to the screening provider your organisation already subscribes to, where that provider publishes a suitable API. We scope the connection during the build and quote it as part of the project. Episcript does not resell a screening service, so you keep your existing contract, your existing data sources and your existing per-check pricing.

Identity verification runs two ways. Singpass-enabled verification can be integrated where the use case is eligible and approved, since the higher-assurance Singpass routes are restricted and subject to approval. Everyone else, including foreign directors and shareholders, uses our own live facial capture with passport or identity document matching. A staff member approves or rejects each result, and every attempt writes to the verification log.

Yes. The system generates the XBRL file itself, ready for submission through BizFile. You import the trial balance, map the accounts once, complete the guided disclosures, and the annual report and the XBRL file both build from that single data set. Version control keeps each draft, and the audit trail records who changed what along the way.

Statutory dates are tracked per entity, covering AGM, annual return, ECI and GST, alongside your own review cycles and document expiry dates. Reminders leave by email, WhatsApp or SMS on the lead time you set, with delivery tracked. A dashboard separates what falls due from what has already slipped, and alerts fire when something passes without action.

Every edit, approval, deletion and record access writes to the log with the user and the timestamp. The trail runs in the background rather than depending on staff to record anything. You can filter it by entity, by user or by date range, then export the result for an audit file, an internal review or a regulator's request.

Yes. The client portal handles document downloads, invoices, reminders, form submissions and uploads. Clients supply the identity documents your due diligence needs without sending them by email. Access reaches their own records only, and every portal action writes to the log against that client, which shows who supplied what and when.

Yes. We map your spreadsheets or your current database to the new structure, clean the data with you, then load entity records, officers, shareholdings, due diligence files and document history. You check a test import before the live run. Nothing is dropped without your sign-off, and the old system stays available until you are satisfied.

Yes. Most teams begin with entity records, due diligence and reminders. Identity verification, registers, XBRL preparation, the client portal, reporting and AI features follow in later phases. Each phase is quoted and released on its own, which spreads the cost across your financial year and keeps the first release small enough to test properly.

The system prepares the records, annual report information and XBRL file the filing workflow needs. Submission itself still takes place through ACRA BizFile, and the generated file is prepared for that process. Where a direct integration is available for a particular transaction, we assess it as part of the project scope.

Hosting is scoped around your organisation’s security, deployment and data residency requirements. Where Singapore hosting is required, the system can be deployed on suitable Singapore-based infrastructure. Role-based access, document permissions, logging and other controls are configured to support your PDPA and internal security requirements.

Compliance work holds a great deal of personal data. Access is granted by role and by client, documents carry their own permissions, and activity logs record who viewed or changed a record. Those controls support your obligations under the PDPA, alongside your own policies and staff training. Responsibility for meeting those obligations stays with your organisation.

Government support may be available for qualifying projects, subject to the prevailing eligibility criteria and approval requirements. Software costs form part of some transformation grants. Approval is never guaranteed, and the position changes from time to time, so confirm your eligibility with the relevant agency before committing to the project.

Next step

See the compliance system on your own records

Whether you manage a small portfolio or several hundred entities, Episcript builds a corporate compliance system matched to your workflows, your controls and your regulatory obligations. Book a demo and we will walk through it with a real file.