Record-Keeping Requirements¶
Back to Governance & Accountability
Overview¶
Financial institutions (FIs) in Singapore are subject to extensive record-keeping obligations under the Securities and Futures Act (SFA), Financial Advisers Act (FAA), and various MAS notices and guidelines. These requirements ensure that FIs maintain adequate records of their business activities, client interactions, and representative conduct for regulatory oversight, dispute resolution, and audit purposes. Failure to maintain proper records can result in regulatory action, including fines, reprimands, and restrictions on business activities.
Statutory Retention Periods¶
Primary Legislation¶
Record retention requirements are established through multiple regulatory instruments:
- Securities and Futures Act (SFA): Section 104 requires capital markets services licence holders to maintain records for at least 5 years
- Financial Advisers Regulations (FAR): Regulation 27 requires financial advisers to maintain records for at least 5 years from the date of the transaction (note: FAA s27 is the suitability obligation, not the record-keeping provision — record-keeping is in FAR Reg 27)
- Securities and Futures (Licensing and Conduct of Business) Regulations: Detailed record-keeping requirements for CMS licence holders
- Financial Advisers Regulations: Specific record-keeping requirements for financial advisers
Retention Period Summary¶
| Record Type | Minimum Retention Period | Regulatory Basis |
|---|---|---|
| Client account records | 5 years from last transaction | SFA s.104 (CMS holders) / FAR Reg 27 (FA firms) |
| Transaction records | 5 years from transaction date | SFA s.104 (CMS holders) / FAR Reg 27 (FA firms) |
| Client communication records | 5 years from date of communication | SFA Regulations |
| Financial needs analysis (FNA) | 5 years from date of advice | FAA-N16 |
| Product recommendation records | 5 years from date of recommendation | FAA-N16 |
| Representative appointment records | 5 years from cessation of appointment | FAA Regulations |
| Training and CPD records | 5 years from date of training | MAS Guidelines |
| Compliance monitoring records | 5 years from date of review | MAS Guidelines |
| Complaint records | 5 years from resolution (minimum 7 years recommended) | MAS Guidelines |
| AML/CFT records | 5 years from end of business relationship or transaction | MAS Notice SFA 04-N02 (CMS) / FAA-N06 (FA) — note: FAA-N01 was cancelled 1 July 2025; FAA-N06 is the current AML/CFT Notice for financial advisers |
| Audit trail records | 7 years (best practice) | Internal governance |
| Board and committee minutes | Permanent or 7+ years | Company law / best practice |
Extended Retention¶
Certain circumstances require records to be retained beyond the statutory minimum:
- Ongoing disputes or litigation: Records must be retained for the duration of any legal proceedings
- Regulatory investigations: Records must not be destroyed while subject to regulatory investigation
- Tax requirements: Tax-related records may need to be retained for longer under IRAS requirements
- Contractual obligations: Client agreements may specify longer retention periods
Types of Records¶
Client Records¶
FIs must maintain comprehensive client records:
Know Your Client (KYC) records: - Client identification and verification documents (NRIC, passport, proof of address) - Risk profiling questionnaires and results - Client investment objectives, financial situation, and experience assessment - Source of funds and wealth documentation - Ongoing due diligence records and periodic review notes
Account records: - Account opening forms and agreements - Powers of attorney and authorised signatory records - Account statements and portfolio valuations - Client correspondence and instructions - Account closure records and reasons
Financial needs analysis: - Completed financial needs analysis forms - Basis of recommendation documents - Product comparison analyses - Client acknowledgement of advice received - Any amendments or updates to the needs analysis
Transaction Records¶
All transactions executed by or through representatives must be recorded:
- Order records: Date, time, product, quantity, price, client instructions, representative identity
- Execution records: Execution venue, actual price, settlement details, any deviations from client instructions
- Confirmation records: Client confirmations sent and received
- Cancellation records: Cooling-off period exercises, cancellation requests, refund calculations
- Switch and replacement records: Documentation supporting product switches or policy replacements, including comparison of old and new products
Communication Records¶
Records of communications between representatives and clients:
Verbal communications: - Call recordings (where required by regulation or internal policy) - Meeting notes and summaries - Records of verbal instructions from clients
Written communications: - Emails between representatives and clients - Letters, including advice letters and product illustrations - Text messages and instant messaging (where used for business purposes) - Social media interactions (where used for business purposes)
Disclosure records: - Product disclosure documents provided to clients - Fee and commission disclosures - Risk warnings and disclaimers - Client acknowledgements of disclosures received
Training Records¶
Records of representative training and professional development:
- Pre-appointment training: CMFAS examination results, module completion certificates
- Ongoing training: CPD hours completed, training programmes attended, assessment results
- Product training: Records of product-specific training and competency assessments
- Compliance training: AML/CFT training, fair dealing training, regulatory update briefings
- Remedial training: Training required as a result of compliance findings or performance issues
Representative Management Records¶
Records related to the lifecycle management of representatives:
- Appointment records: Form 3A/3B/3C submissions, MAS approval correspondence, fit and proper assessments
- Supervision records: Supervisory review notes, call monitoring results, file check findings
- Performance records: Balanced scorecard assessments, performance reviews, development plans
- Disciplinary records: Warnings, suspensions, investigations, and outcomes
- Cessation records: Form cessation submissions, exit interviews, handover documentation, reasons for cessation
Electronic Records¶
MAS Requirements for Electronic Records¶
MAS recognises electronic records as valid provided they meet certain conditions:
- Integrity: Electronic records must maintain data integrity throughout the retention period
- Accessibility: Records must be readily accessible and retrievable within reasonable timeframes
- Readability: Records must be readable and reproducible in a comprehensible format
- Authentication: Electronic records must be capable of being authenticated as to their origin and completeness
- Non-repudiation: Systems should prevent unauthorised alteration of records after creation
Electronic Record-Keeping Standards¶
FIs should implement the following standards for electronic records:
Storage and backup: - Records stored on secure, access-controlled systems - Regular backup schedules with offsite or cloud-based redundancy - Disaster recovery plans that include record recovery procedures - Storage media and formats that remain accessible throughout the retention period
Format and migration: - Records should be stored in formats that can be read without proprietary software, or with the necessary software retained - Migration plans should ensure records remain accessible when systems are upgraded or replaced - Metadata (creation date, author, modification history) should be preserved during migration
Access controls: - Role-based access controls limiting record access to authorised personnel - Audit trails recording who accessed, modified, or deleted records and when - Segregation of duties between record creation, modification, and deletion - Regular review of access permissions
Email and messaging: - Business emails and messages should be archived in a searchable, tamper-evident system - Personal devices used for business communications must be covered by the record-keeping framework - Automated archiving is preferred over reliance on individual representatives to preserve records
MAS Inspection Access¶
Regulatory Powers¶
MAS has broad powers to access records held by financial institutions:
- Section 150 SFA / Section 45 FAA: MAS may require the production of books, accounts, and documents
- Section 152 SFA: MAS may conduct inspections of regulated persons
- MAS inspection guidelines: MAS may request records in advance of or during on-site inspections
Access Requirements¶
FIs must ensure that:
- Records can be produced to MAS within the timeframes specified in inspection notices (typically 3-14 days for standard requests)
- Records are produced in the format requested by MAS (electronic, hardcopy, or both)
- Authorised MAS officers are provided with reasonable access to systems containing records
- Translations are provided where records are not in English
- Explanations of record-keeping systems and data structures are available for MAS inspectors
Preparation for Inspections¶
FIs should maintain readiness for MAS inspections:
- Designated contact persons for regulatory inspections
- Pre-established processes for collecting and producing records in response to inspection notices
- Regular testing of record retrieval capabilities
- Training for staff on their obligations during regulatory inspections
- Legal counsel arrangements for managing complex or sensitive document requests
Destruction Policies¶
Principles¶
Record destruction must be managed systematically to ensure that:
- Records are not destroyed before the expiry of the statutory retention period
- Records subject to legal holds, investigations, or litigation are preserved regardless of retention schedules
- Destruction is conducted securely to protect confidential information
- Destruction is documented and auditable
Destruction Process¶
- Identification: Records reaching the end of their retention period are identified
- Legal hold check: Records are checked against any active legal holds or regulatory investigations
- Approval: Destruction is approved by the records management function and, where required, the compliance function
- Secure destruction: Records are destroyed using appropriate methods:
- Paper records: Cross-cut shredding or incineration
- Electronic records: Secure deletion or media destruction using certified methods
- Backup media: Inclusion in backup rotation and eventual secure destruction
- Documentation: A destruction certificate or log entry is created recording what was destroyed, when, and by whom
- Verification: Spot checks to verify that destroyed records are no longer accessible
Legal Holds¶
When a legal hold is in place:
- All records potentially relevant to the matter must be preserved, regardless of retention schedules
- Automated destruction processes must be suspended for affected records
- All personnel who may hold relevant records must be notified of the hold
- The hold remains in effect until formally released by legal counsel
- Destruction of records subject to a legal hold may constitute obstruction of justice or contempt of court
Destruction Schedule¶
FIs should maintain a documented destruction schedule that:
- Lists all record categories with their retention periods
- Identifies the regulatory or legal basis for each retention period
- Specifies the destruction method appropriate for each record category
- Assigns responsibility for destruction decisions and execution
- Is reviewed and updated at least annually
Practical Implementation¶
Records Management Framework¶
FIs should establish a comprehensive records management framework:
- Records management policy: Board-approved policy covering creation, classification, retention, access, and destruction of records
- Records classification scheme: Taxonomy for categorising records by type, business function, and regulatory relevance
- Retention schedule: Comprehensive schedule mapping record categories to retention periods
- Roles and responsibilities: Clear assignment of records management responsibilities across the organisation
- Training: Regular training for all staff on records management obligations
Technology Considerations¶
Modern record-keeping requires appropriate technology infrastructure:
- Document management systems: Centralised repositories for storing and managing records with version control, metadata, and search capabilities
- Email archiving: Automated email archiving systems that capture all business communications
- Surveillance systems: Call recording and monitoring systems for verbal communications
- Compliance platforms: Systems that integrate record-keeping with compliance monitoring and regulatory reporting
- Cloud storage: Consideration of data residency requirements when using cloud-based record storage (MAS Technology Risk Management Guidelines)
Common Deficiencies¶
MAS inspections frequently identify the following record-keeping deficiencies:
- Incomplete or missing financial needs analysis documentation
- Failure to record verbal communications and client instructions
- Inadequate supervision records for representative oversight
- Missing or incomplete training and CPD records
- Inconsistent application of retention schedules across business units
- Reliance on individual representatives to maintain records rather than centralised systems
- Failure to preserve electronic communications (particularly from personal devices and messaging platforms)
FIs should proactively address these common deficiencies through regular self-assessments and compliance monitoring.