7 Temasek Boulevard, #12-07 Suntec Tower One, Singapore 038987martin@prosecsingapore.com·+65 8898 4830
Banking

CorpPass for Singapore Company Compliance: Access, Roles and Filing Control

Corppass Setup for Singapore Company Compliance: A Practical Founder Checklist. This guide explains corppass setup for Singapore company directors and...

Quick answer

CorpPass is the authorisation system used by entities to manage access to government digital services. For a Singapore company, CorpPass is part of compliance control because the people with access can file tax returns, assign e-services, authorise third parties, deal with CPF or transact with other agencies. Directors should treat CorpPass access like a corporate control, not a casual login.

  • Identify the CorpPass Admin and confirm the company still has active control of the account.
  • Assign e-services based on role rather than giving broad access to everyone.
  • Review third-party authorisations for tax agents, payroll providers and corporate service providers.
  • Remove or revise access when staff, directors or service providers change.
Updated: 2026-06-25Reviewed by a Chartered Accountant of SingaporeSingapore regulatory focusCorpPass access control

Why CorpPass matters for compliance

Many compliance failures are not caused by the law being unclear. They happen because the wrong person has access, the right person has no access, or an old provider remains authorised after transfer. CorpPass can affect Bizfile access, IRAS corporate tax filing, GST, CPF, Customs and other government e-services. If the company loses control of CorpPass, it may struggle to file, check reminders or authorise a new provider.

For foreign-owned companies, CorpPass planning should happen early. The overseas owner may not personally be able to manage every Singapore government e-service without local access arrangements. The company should know who is the Admin, who approves filings, who can authorise third parties and how access will be changed if the service provider changes.

Access areaControl point
CorpPass AdminWho can create users and manage access.
IRAS e-servicesWho can prepare or approve tax and GST submissions.
Bizfile accessWho can handle ACRA transactions through authorised roles.
Third-party authorisationWhich provider has access and for what scope.

Director control versus operational convenience

It is convenient to give a bookkeeper, secretary or employee broad access, but convenience should not override control. A small company should decide which person can prepare filings, which person can approve them, and whether a third-party provider should be authorised directly rather than using a founder’s personal credentials. Access should follow the work actually being performed.

Directors should also keep a simple access register: who has CorpPass roles, what e-services are assigned, when the access was granted, and when it should be reviewed. This is especially useful when a staff member leaves or a company changes secretary, accountant or tax agent.

Third-party authorisation

Where a tax agent or service provider helps with filings, third-party authorisation may be more controlled than sharing login details. The company can authorise selected services and roles. For IRAS corporate tax e-services, role settings such as preparer and approver can matter because they affect who can lodge or approve the final submission.

The company should not authorise a provider indefinitely without review. After a transfer, remove the old provider’s access and confirm the new provider has only the services required. A clean CorpPass transfer reduces the risk of missed tax filing, duplicate submissions or inaccessible government notices.

Common setup problems

Common issues include no active Admin, an Admin who has left the company, access being held by an old corporate secretary, employees with unnecessary e-services, tax agents unable to see the correct year of assessment, or directors not knowing whether filings have been submitted. These are practical control gaps rather than purely technical problems.

Another common problem is treating CorpPass as something to set up only when filing is due. That creates pressure when an IRAS or ACRA deadline is approaching. It is better to set up and test access when the company is incorporated or when a new provider is appointed.

Suggested review checklist

Review CorpPass access whenever there is a change of director, finance staff, bookkeeper, company secretary, tax agent or payroll provider. Also review it before Annual Return filing, corporate tax filing season, GST registration, GST filing or CPF onboarding. The company should be able to answer who has access, why they have access and whether that access is still needed.

For companies using outsourced providers, keep a short note in the compliance file showing which providers are authorised for ACRA, IRAS, CPF or other e-services. This note helps the next transfer and prevents access decisions from being trapped in one person’s memory.

The review should confirm who has Admin rights, which users can access IRAS, CPF, Bizfile or other e-services, which third-party entities are authorised, and whether the access matches the current service scope. Keep a screenshot or exported list in the compliance file after every major transfer. This small step makes future reviews much easier.

CorpPass should be reviewed whenever a company changes secretary, accountant, tax agent or payroll provider. Old users or third-party authorisations may remain active long after the engagement ends. That creates unnecessary exposure and can confuse responsibility if a filing is missed or submitted incorrectly.

Access review after provider changes

This check is valuable even for dormant companies. A dormant company may still need to authorise a tax agent, file or review waiver status, respond to an IRAS notice or keep access ready for future reactivation. CorpPass should therefore be part of the compliance calendar, alongside Annual Return, ECI, corporate tax, GST and CPF deadlines.

Before tax season, the founder should test access rather than assume it works. Confirm that the company can log in through the correct route, that IRAS corporate tax services are assigned, that the tax agent or preparer has the intended role, and that the person expected to approve the filing can actually approve it. Do the same for GST if the company is GST-registered and CPF if the company has employees.

Founder checklist before tax season

Frequently asked questions

What is CorpPass used for?

CorpPass is used by entities to manage digital service access for employees or authorised users who perform corporate transactions with government agencies.

Should I share my CorpPass login with a provider?

No. A safer approach is to use proper user access or third-party authorisation where available, so the scope and role can be controlled.

Who should be the CorpPass Admin?

The Admin should be a trusted person who can manage users and e-services responsibly. The company should ensure the Admin remains active and reachable.

When should access be removed?

Remove or revise access when staff leave, directors change, service providers are replaced or the provider no longer needs a particular e-service.

What should I send ProSec for a CorpPass compliance review?

Send the list of current Admins, users, assigned e-services, third-party authorisations and the filings or services you expect ProSec to support.

Official sources

Continue with related guidance

Written and reviewed by Martin, CA Singapore

Martin is the founder of ProSec Pte. Ltd. and a Chartered Accountant of Singapore. He reviews ProSec guides for practical consistency with Singapore company, accounting and tax requirements.

Need help coordinating CorpPass, tax and ACRA access?

ProSec can help identify the access needed for company secretary, accounting, tax, GST and payroll workflows without relying on informal login sharing.

View compliance supportWhatsApp ProSec
WhatsApp ProSec