Mail Fulfillment Services Singapore

    What It Means to Be OSPAR Audited in Singapore

    In-Touch is an ABS OSPAR-audited outsourced service provider, listed on the Association of Banks in Singapore public register, with our audited scope recorded there as mailroom, messaging and local courier services.

    Get a quote

    Tell us about your mailing

    Volume, format and the date it needs to land. We come back with an all-in cost within a few business hours.

    By submitting this form you consent to In-Touch Singapore Pte Ltd collecting and using your personal data for the purpose of responding to your enquiry, in accordance with Singapore's Personal Data Protection Act (PDPA).

    What does “OSPAR audited” mean?

    OSPAR audited means an independent auditor has examined a defined scope of a service provider's controls against the Association of Banks in Singapore (ABS) Guidelines, and recorded the results in an Outsourced Service Provider's Audit Report. It is an assurance report, not a certification, and audited providers are listed on the ABS public register.

    OSPAR stands for the Outsourced Service Provider's Audit Report, an independent audit defined by the Association of Banks in Singapore. The criteria are the ABS Guidelines on Control Objectives and Procedures for Outsourced Service Providers, and the resulting report is one the provider's financial-institution clients can review.

    ABS describes the reporting framework as an assurance engagement under ISAE 3000 or SSAE 3000, giving an opinion and reasonable assurance against those criteria. The point of it is that the controls have been tested by an independent party rather than self-declared.

    Reading the register as a procurement document is a separate skill from knowing what the audit is: what the OSPAR register actually tells a bank about its mail vendor goes through the scope column entry by entry, and what a listing does not settle.

    Which version of the ABS Guidelines applies

    An OSPAR audit tests a provider against the ABS Guidelines on Control Objectives and Procedures for Outsourced Service Providers, and the current text is Version 2.0, issued 25 March 2024. It replaces Version 1.1 of 1 June 2017, which in turn replaced the original of 25 July 2015. Version 2.0 exists to absorb six MAS releases that landed in between: Notice 655 on Cyber Hygiene, the Technology Risk Management Guidelines, the 2021 advisory on technology and cyber risk in public cloud adoption, the Guidelines on Business Continuity Management, Notices 658 and 1121 on management of outsourced relevant services, and the Guidelines on Outsourcing for banks. If a provider describes its OSPAR without reference to a version, it is worth asking which text the audit was performed against.

    What the audit actually examines

    The Guidelines are organised in three layers: entity level controls covering governance, risk assessment, information security policy, human resources and the handling of sub-contractors; general IT controls covering logical and physical security, change and incident management, backup and recovery, cryptography and data security; and service level controls covering how new clients and processes are set up, how transactions are authorised and processed, how records are maintained and how assets are safeguarded. ABS is explicit that these are the minimum, describing them as baseline controls, and says financial institutions with specific needs should continue to agree additional requirements bilaterally. An OSPAR is a floor a provider has been shown to meet, not a ceiling.

    Who is qualified to perform an OSPAR audit

    Not every audit firm can do this work, which is part of what the report is worth. The Guidelines require the provider to engage a qualified external auditor, and set a specific bar: the audit firm must have audited at least two commercial banks operating in Singapore in the last five years, and the engagement partner who signs the report must personally meet the same test. The audit should be performed once every 12 months. Where a provider changes auditor, the Guidelines require a proper handover between the outgoing and incoming firms so that the financial institutions relying on the report are not left with a gap.

    ABS OSPAR audited vs. “OSPAR certified”

    People often search for “OSPAR certified”, but OSPAR is an audit report, not a certification. ABS draws the distinction itself: certifications such as ISO 27001 sit under a different framework, and holding one does not remove the need for a separate OSPAR audit. There is no OSPAR certificate to frame on a wall. Instead an independent auditor issues a report on whether the provider's controls meet the ABS Guidelines, valid for twelve months from issuance or until the next report, and providers whose report is not renewed are removed from the register. So the accurate description is OSPAR audited, and the proof point is the register listing, which anyone can check.

    How to verify an OSPAR-audited provider

    Because OSPAR is an audit rather than a self-issued badge, you can confirm a provider's status independently. ABS publishes the register of OSPAR-audited outsourced service providers at abs.org.sg as a dated PDF, running to just over a hundred names, and it carries four things against each provider: the name, the nature of the services the audit covered, the audit period, and the date the OSPAR was issued. Read the scope column against the work you are actually placing, because two providers can both be OSPAR audited while only one has been audited for the service you are buying. Then read the two date columns, which tell you how current the report behind the listing is. The register is the check, and the scope wording is the part that answers your question.

    Why choose an OSPAR-audited mailing house

    For banks, insurers, healthcare providers and any organisation sending statements, policy documents or other regulated communications, the print-and-mail step is part of your data-protection perimeter. ABS puts the principle in one line in the Guidelines: the service can be outsourced, but the risk cannot. An OSPAR listing tells you a defined part of a provider's controls has been examined independently rather than self-declared, which is a useful input to your own due diligence. It does not replace it: ABS states plainly that undertaking an OSPAR does not diminish a bank's own obligations, and financial institutions and regulators may still audit a provider directly.

    In-Touch's audited scope, stated precisely

    In-Touch Singapore is listed on the ABS public register, and our audited scope is recorded there as mailroom, messaging and local courier services. That scope does not extend to printing or to lettershopping, and we would rather say so than let the listing imply otherwise. Several other providers on the same register do carry statement printing and enveloping in their audited scope; if that is specifically what you need evidenced, the register will tell you who holds it. Our print-side work is governed by the Personal Data Protection Act and by the terms of the engagement instead: encrypted transfer, restricted-access processing, purge after production, and recipient matching verified before sealing.

    Common questions

    ABS OSPAR-Audited Mail Handling — frequently asked

    OSPAR audited means an independent auditor has examined a defined scope of a service provider's controls against the Association of Banks in Singapore (ABS) Guidelines and recorded the results in an Outsourced Service Provider's Audit Report. Audited providers are listed on the ABS public register, which records the nature of the services each audit covered.

    Version 2.0, issued 25 March 2024. It replaced Version 1.1 of 1 June 2017, which replaced the original issued 25 July 2015. Version 2.0 was written to bring the Guidelines in line with six MAS releases, among them Notice 655 on Cyber Hygiene, the Technology Risk Management Guidelines, the 2021 public cloud advisory, the Business Continuity Management Guidelines, and Notices 658 and 1121 on outsourced relevant services. Ask a provider which version its audit was performed against.

    No, because there is no such thing. OSPAR is an independent audit report, not a certification, and there is no OSPAR certificate. In-Touch is ABS OSPAR-audited, and the listing is verifiable on the Association of Banks in Singapore's public register rather than resting on a self-issued badge.

    Mailroom, messaging and local courier services, as recorded against our name on the ABS public register. That scope does not extend to printing or to lettershopping. Our print-side handling of customer data is governed by the Personal Data Protection Act and by the engagement terms instead, and should be evidenced on those terms rather than folded into an audit that did not cover it.

    Check the Association of Banks in Singapore's public register at abs.org.sg. Read the nature-of-services column, not just the presence of the name: the register records what each audit actually covered, so you can confirm whether it covers the work you are placing.

    Once every 12 months, under the ABS Guidelines, and the report is valid for 12 months from the date it is issued or until the next one is issued, whichever is earlier. One detail worth knowing when you assess a new listing: ABS asks for at least six months of steady-state operation of the controls for a first-year OSPAR, and twelve months in subsequent years. So a provider in its first year has been audited over a shorter run of operation than one that has been listed for several. Providers whose OSPAR is not renewed on time are removed from the list.

    A qualified external auditor meeting a specific bar set in the Guidelines: the audit firm must have audited at least two commercial banks operating in Singapore in the last five years, and the engagement partner who signs the report must personally meet the same test. Where a provider changes auditor, the Guidelines require a proper handover between the outgoing and incoming firms.

    Not on its own. ABS states that undertaking an OSPAR does not diminish a financial institution's obligations to comply with Singapore law and regulation, and that institutions and regulators may still audit a provider directly or request further information where they judge a report insufficient. Treat the listing as an input to your due diligence rather than a replacement for it.