Which version of the ABS Guidelines applies
An OSPAR audit tests a provider against the ABS Guidelines on Control Objectives and Procedures for Outsourced Service Providers, and the current text is Version 2.0, issued 25 March 2024. It replaces Version 1.1 of 1 June 2017, which in turn replaced the original of 25 July 2015. Version 2.0 exists to absorb six MAS releases that landed in between: Notice 655 on Cyber Hygiene, the Technology Risk Management Guidelines, the 2021 advisory on technology and cyber risk in public cloud adoption, the Guidelines on Business Continuity Management, Notices 658 and 1121 on management of outsourced relevant services, and the Guidelines on Outsourcing for banks. If a provider describes its OSPAR without reference to a version, it is worth asking which text the audit was performed against.
What the audit actually examines
The Guidelines are organised in three layers: entity level controls covering governance, risk assessment, information security policy, human resources and the handling of sub-contractors; general IT controls covering logical and physical security, change and incident management, backup and recovery, cryptography and data security; and service level controls covering how new clients and processes are set up, how transactions are authorised and processed, how records are maintained and how assets are safeguarded. ABS is explicit that these are the minimum, describing them as baseline controls, and says financial institutions with specific needs should continue to agree additional requirements bilaterally. An OSPAR is a floor a provider has been shown to meet, not a ceiling.
Who is qualified to perform an OSPAR audit
Not every audit firm can do this work, which is part of what the report is worth. The Guidelines require the provider to engage a qualified external auditor, and set a specific bar: the audit firm must have audited at least two commercial banks operating in Singapore in the last five years, and the engagement partner who signs the report must personally meet the same test. The audit should be performed once every 12 months. Where a provider changes auditor, the Guidelines require a proper handover between the outgoing and incoming firms so that the financial institutions relying on the report are not left with a gap.
ABS OSPAR audited vs. “OSPAR certified”
People often search for “OSPAR certified”, but OSPAR is an audit report, not a certification. ABS draws the distinction itself: certifications such as ISO 27001 sit under a different framework, and holding one does not remove the need for a separate OSPAR audit. There is no OSPAR certificate to frame on a wall. Instead an independent auditor issues a report on whether the provider's controls meet the ABS Guidelines, valid for twelve months from issuance or until the next report, and providers whose report is not renewed are removed from the register. So the accurate description is OSPAR audited, and the proof point is the register listing, which anyone can check.
How to verify an OSPAR-audited provider
Because OSPAR is an audit rather than a self-issued badge, you can confirm a provider's status independently. ABS publishes the register of OSPAR-audited outsourced service providers at abs.org.sg as a dated PDF, running to just over a hundred names, and it carries four things against each provider: the name, the nature of the services the audit covered, the audit period, and the date the OSPAR was issued. Read the scope column against the work you are actually placing, because two providers can both be OSPAR audited while only one has been audited for the service you are buying. Then read the two date columns, which tell you how current the report behind the listing is. The register is the check, and the scope wording is the part that answers your question.
Why choose an OSPAR-audited mailing house
For banks, insurers, healthcare providers and any organisation sending statements, policy documents or other regulated communications, the print-and-mail step is part of your data-protection perimeter. ABS puts the principle in one line in the Guidelines: the service can be outsourced, but the risk cannot. An OSPAR listing tells you a defined part of a provider's controls has been examined independently rather than self-declared, which is a useful input to your own due diligence. It does not replace it: ABS states plainly that undertaking an OSPAR does not diminish a bank's own obligations, and financial institutions and regulators may still audit a provider directly.
In-Touch's audited scope, stated precisely
In-Touch Singapore is listed on the ABS public register, and our audited scope is recorded there as mailroom, messaging and local courier services. That scope does not extend to printing or to lettershopping, and we would rather say so than let the listing imply otherwise. Several other providers on the same register do carry statement printing and enveloping in their audited scope; if that is specifically what you need evidenced, the register will tell you who holds it. Our print-side work is governed by the Personal Data Protection Act and by the terms of the engagement instead: encrypted transfer, restricted-access processing, purge after production, and recipient matching verified before sealing.