Back to blog

    Compliance & Security

    What the OSPAR Register Actually Tells a Bank About Its Mail Vendor

    ·By In-Touch Singapore
    A register of provider rows where each scope entry is a different width, one marked in red

    The Association of Banks in Singapore publishes a list of OSPAR-audited outsourced service providers, and most vendors treat an entry on it as a badge. The register is more specific than that. Against every name sits the nature of the services the audit actually covered, and those descriptions differ sharply from one provider to the next. If you are about to hand a print or mail vendor a file of customer records, that column is the part of the document that answers your question.

    The register lists scope, not status

    Every entry on the ABS list of OSPAR audited outsourced service providers carries four fields: the provider's name, the nature of the services audited, the audit period, and the date the OSPAR was issued. The scope wording is written per provider and it is not boilerplate.

    Among the providers whose scope touches mail, the register records entries as specific as "Bank Statements, Mailers & Advices - Printing & Enveloping", "Cheque Books, Promotion Cheques and Account Statements Printing Services", and "Printing, Enveloping and Two-factor Authentication Token Storage and Fulfilment Services". Others read simply "Mailroom Services". Card personalisation, records storage and secure destruction each appear as their own scope against different names again.

    Two providers can therefore both be described as OSPAR-audited while only one of them has been audited for the work you are buying. The ABS guidelines make this explicit: an OSPAR covers the services the provider actually delivers, and where a control is not applicable to the nature of that service, it can be scoped out with a rationale agreed with the auditor. Scope is the whole content of the listing.

    It is an audit report, not a certificate

    ABS states the distinction itself, and in unusually direct terms. In its frequently asked questions on the guidelines, ABS contrasts OSPAR with the certifications it is often confused with: ISO 27000 and ISO 31000 "are certifications whereas the OSPAR reporting framework is based on the International Standards on Assurance Engagement (ISAE) 3000 for Assurance Engagements or Singapore Standards on Assurance Engagements (SSAE) 3000 for Assurance Engagements which is used to provide an 'opinion' and 'reasonable assurance' that the service organisation meets the criteria set out in the ABS guidelines."

    The practical consequences follow from that. An auditor cannot perform an OSPAR under the ISO 27000 framework. Holding ISO 27001, or an existing ISAE3402 or SSAE18 report, does not exempt a provider from a separate audit against the ABS guidelines. And because it is an assurance engagement rather than a certification, what it produces is an opinion on a defined scope over a defined period, which is why the register records both.

    This is also why the phrasing matters when a vendor describes itself. A provider that says it is OSPAR-certified is describing something that does not exist. So is one that claims to be MAS-approved: MAS regulates the bank, not the bank's print vendor.

    A listing is current, or it is not there

    An OSPAR is valid for twelve months from the date the report is issued, or until the next one is issued, whichever comes first. ABS states that providers whose OSPAR is not renewed on time are removed from both the public list and the members-only registry.

    That makes presence on the register a currency signal in itself, which is the opposite of how a static logo on a vendor's website behaves. The review is annual. A provider newly engaged by a bank is expected to have at least six months of steady-state control operation before the first audit, and twelve months in subsequent years.

    Our own observation from being audited under this framework is about what that steady-state requirement does to a provider. An assurance engagement of this kind does not test what you are capable of on the day the auditor visits; it samples evidence that the control operated across the whole period. A process that exists as a written procedure but is applied inconsistently produces no usable evidence trail, and so cannot pass. The requirement is less about buying new equipment than about being able to show a year of the same behaviour.

    What a bank may rely on, and what it still owes

    A bank may rely on an independent third-party audit, but that reliance has limits the register itself spells out.

    Quoting the MAS Guidelines on Outsourcing (Banks), ABS notes that audits or expert assessments performed as part of a certification process, "but not self-attestations", may be relied on to meet audit expectations where performed by independent and competent auditors, and that banks may also rely on pooled audits or third-party certification of their service providers performed by independent parties. ABS adds that MAS accepts pooled audits to fulfil the requirement for an independent audit. The carve-out is the important half: a supplier's own declaration about its controls carries no weight here.

    What reliance does not do is transfer the obligation. The register carries its own caveat on this point: "Undertaking an Outsourced Service Providers Audit Report (OSPAR), does not diminish the obligations of a bank/institution to comply with relevant laws and regulations in Singapore." Banks may still audit a provider directly, may request site visits and additional service control audits where they judge an OSPAR insufficient, and regulators may do the same. Where a provider declines the OSPAR route altogether, ABS is blunt about the alternative: it will be audited directly by its bank clients instead.

    The public list is also only a summary. The fuller ABS OSP Registry, which includes providers currently undergoing audit, is available to ABS members, so a bank can see more than a vendor's website shows.

    Where our own scope stops

    We are on that register, and our entry reads "Mailroom, Messaging & Local Courier Services". That is the scope of our ABS OSPAR audit, and it does not extend to printing or to lettershopping. Several other providers on the same list do carry printing and enveloping in their audited scope. If your requirement is specifically for OSPAR-audited statement printing, the register will tell you who holds it, and the honest answer is that we do not.

    What governs our print-side work instead is the Personal Data Protection Act and the terms of the engagement: encrypted transfer, restricted-access processing, purge after production, and recipient matching verified piece by piece before sealing. That is a different assurance route from OSPAR, and should be evidenced on its own terms rather than folded into an audit that never covered it. We set out those controls under secure data printing, and the wider framework in the 2026 guide to secure document fulfillment.

    Before you sign the outsourcing paperwork

    Read the nature-of-services wording against your own scope of work, not against the vendor's marketing. If the audit covered mailroom services and you are outsourcing statement production, the listing is real but it is not evidence about the thing you are buying.

    Then ask any vendor for two things in writing: the scope wording exactly as it appears on the register, and, for whatever falls outside it, the controls that do apply and how each is evidenced. A vendor that draws that line clearly is easier to place in your outsourcing register than one that lets the badge cover everything.

    Tags

    BankingABS OSPARComplianceOutsourcingVendor Management

    Ready to personalize your next campaign? Let's build a tailored solution today.