Insights

Questions to ask before you sign

Most employers evaluating an HR provider compare price and scope, then move on. The questions that actually predict whether the relationship survives its first hard moment sit somewhere else: where your data lives, who answers when your usual contact is away, and what happens the day you decide to leave. Ask these before you sign, not after something goes wrong.

By Skillsforce · People-operations teamLast updated 30 August 20266 min read
In brief

What should you ask an HR provider before signing an agreement?

Ask where your employee data sits and who is accountable for it under the PDPA; who your named contact is and what happens when they are away; the escalation path if a filing is late; whether they hold or just use your Corppass; what notice ends the contract; and what you get back on exit, and in what format.

Direct line+65 6291 5200Monday to Friday
8:30AM to 5:30PM

Most sales conversations with an HR provider cover the same ground: what is included, what it costs, how fast they can start. Those are fair questions, but they are not the ones that tell you what happens when something goes wrong, because nothing has gone wrong yet. The questions below are the ones worth asking before you sign, precisely because they are awkward to ask afterward.

Where does our employee data actually sit, and who answers to the PDPC if something goes wrong?

This is the question most SMEs skip entirely, and it is the one with the clearest regulatory answer. Under the Personal Data Protection Act, an organisation that engages another party to process personal data on its behalf is typically engaging what the PDPA calls a data intermediary. The important part is what does not change: you, the employer, remain responsible for that personal data, including for notifying affected individuals or the Personal Data Protection Commission if there is a breach. Handing the work to a provider does not hand over the accountability.

That said, the provider is not off the hook either, provided the arrangement is set up properly. Where a data intermediary processes personal data under a written contract strictly on your behalf, it has to meet the Protection Obligation, reasonable security arrangements to prevent unauthorised access, use or disclosure, and the Retention Limitation Obligation, not keeping data once the purpose it was collected for is no longer being served. Ask the provider to point to where these obligations are written into your contract, not described in a sales deck. The PDPC publishes a guide with sample data protection clauses for exactly this kind of agreement, and a provider that has never seen it is worth a second look.

If any part of your data is processed or stored outside Singapore, one more question follows: does that transfer meet a standard of protection comparable to the PDPA. This is worth confirming in writing rather than assuming, particularly if the provider uses an offshore team or a cloud platform hosted overseas.

Who is our named contact, and what happens when they are away?

A provider will usually introduce you to one relationship manager or account lead during the pitch. That person is the face of the service, and also, if nothing else is in place, its single point of failure. Ask directly: if this person is on leave, out sick, or leaves the company, who picks up our account, and do they already know it or are they opening our file for the first time.

This is a different question from what backup HR means for your own internal team, which is worth understanding on its own terms. Here the question is about the provider’s bench, not yours: does more than one person at the firm actually know your account, your KETS templates, your leave policy quirks, the history of anything unresolved. A provider with a genuine second person costs you nothing extra to ask about, and their answer, confident and specific versus vague and reassuring, tells you a good deal about how the account is actually staffed.

What is the escalation path if something is filed late?

Ask this one plainly: if a CPF contribution or an Auto-Inclusion Scheme submission is filed late because of an error on your provider’s side, what happens next, and who do you call. The honest answer starts with a fact worth being clear-eyed about: the regulator does not deal with the provider. MOM, CPF Board and IRAS hold the employer accountable for statutory filings regardless of who prepared them, which means the interest, the fine, or the personal exposure a director might face lands on you first, not on the vendor that made the mistake.

What a contract can do is allocate that cost afterward: an indemnity clause, a service credit, a commitment to cover a penalty caused by the provider’s own error. A provider that has already thought through this, and can describe their escalation process without reaching for a lawyer, is a provider that has been through it before. One that has never considered the question has not been tested yet, which is not the same as being reliable.

Do you hold our Corppass access, or do we grant it to you?

Corppass is the practical mechanism behind almost every filing a provider does on your behalf, and it is built for exactly this kind of arrangement: your own Corppass administrator authorises a provider with time-bound, role-based access scoped to specific digital services, without ever handing over the underlying account. You can review that access and revoke it at any time.

The question worth asking a prospective provider is not whether they have access, but precisely what they can see and do with it, how it was granted, and how quickly you could take it back if the relationship ended tomorrow. A provider who answers with specifics, which e-services, what role, reviewed how often, is describing a properly scoped arrangement. A provider who says something closer to “we manage that for you” without detail is asking you to trust rather than verify, and this is one place where verifying costs you nothing.

What notice ends this agreement, and what does it cost to leave?

This is a commercial contract term, not a statutory one, so there is no fixed answer, only the one you negotiate. Read the termination clause before you sign, not after you need it: how much notice either party must give, whether early termination carries a fee, and whether the notice window is actually long enough to hand records and access to a new provider without a gap in filings or coverage.

A short notice period sounds convenient when you are the one signing up. It is considerably less convenient when you are the one trying to leave and the provider is entitled to walk away from your account with two weeks’ notice while a CPF deadline sits three days out. Ask what the notice period looks like from both directions, not just the one that got you excited to sign.

What do we get back if we switch providers, and in what format?

The last question is the one that determines whether an exit is a transition or a fire drill: on the way out, do you get your employment records, KETS and contract documents, leave and payroll history, and any policy documents the provider maintained, and do you get them in a format a new provider or an in-house system can actually use, rather than a static PDF export you have to retype.

This sits close to, but is distinct from, what HR outsourcing actually covers while the relationship is active. That question is about scope during the engagement. This one is about what survives the engagement ending. A provider who can answer both without hesitation, in writing, in the contract, is behaving like a firm that expects to earn your business every renewal rather than lock you in by making an exit expensive.

A short list to bring to the sales conversation

Six questions, in the order they matter most:

  • Where is our employee data stored, and what does the contract say about your Protection and Retention obligations under the PDPA?
  • If any data leaves Singapore, does the transfer meet a comparable standard of protection?
  • Who is our named contact, and who covers for them, by name, not by title?
  • What is the escalation process if a filing is late or wrong, and who bears the cost?
  • What Corppass access are we granting, for which services specifically, and how do we revoke it?
  • What is the notice period to end this agreement, and what do we get back, in what format, if we do?

None of these questions are hostile. A provider worth signing with should welcome all six, because they are the same questions a careful operator would ask of themselves. The ones worth being cautious about are the providers who treat the list as an inconvenience rather than as due diligence any serious vendor relationship deserves.

If you are working through a shortlist and want a second set of eyes on what a provider’s answers actually mean, our HR team is happy to talk through what belongs in the contract before you sign, not after.

Common questions

What questions should I ask an HR provider before signing a contract?

Ask five things beyond scope and price: where our employee data is stored and who is accountable for it under the PDPA, who our named contact is and what happens when they are away, what the escalation path looks like if something is filed late, whether you hold or merely use our Corppass access, and what notice ends this agreement and what we get back if we leave. A provider who answers these clearly and in writing is behaving like a long-term partner. One who waves them off is telling you something too.

Is my HR provider responsible for my employees' personal data under the PDPA?

No, not in the way that matters. Under the PDPA, a provider processing personal data on your behalf is typically a data intermediary, but the organisation that engaged them, you, remains responsible for that data, including for notifying affected individuals or the PDPC if there is a breach. The provider does carry the Protection Obligation and Retention Limitation Obligation while processing under a written contract on your behalf, but the accountability for your employees' data stays with you.

Should an HR provider hold our Corppass login, or just have access?

Neither, strictly speaking. Corppass is designed so the employer's own administrator grants a provider time-bound, role-based access to specific digital services, without ever handing over the account itself. A provider asking to be given the login directly, rather than authorised access you control and can revoke, is asking for more than it needs.

What happens if our HR provider files something late?

The regulator holds you, not the provider. MOM, CPF Board and IRAS deal with the employer of record, regardless of who prepared or submitted the filing on your behalf. A good service agreement sets out what the provider owes you if its error causes a penalty, an indemnity, a service credit, a defined escalation path, but that contract term allocates cost between you and the vendor. It does not change who the regulator comes to first.

How much notice should we require before ending an HR provider agreement?

There is no single statutory answer, since this is a commercial contract term, not an employment one, so it is set by what you negotiate. What matters is reading the clause before you sign: how much notice either side must give, whether there are early-termination fees, and whether the notice period gives you enough runway to transition records, Corppass access and any open filings to a new arrangement without a gap.

What should we get back if we switch HR providers?

At minimum: employment records for current and departed staff, KETS and contract documents, leave and payroll history, and any policies or handbooks the provider maintained on your behalf, in a format you can actually load into a new system rather than a locked export. Ask for this in writing before you sign, because a provider's willingness to commit to it upfront is a reasonable proxy for how easy the eventual handover will be.

Do we still need to check an HR provider's EA licence?

Only if the provider also places or supplies workers, which is a recruitment agency function requiring a licence from MOM, not a general HR administration one. If your provider does both, verify the licence separately in MOM's public EA Directory; general HR outsourcing and payroll administration do not require an EA licence in the first place.

Sources & references

Figures are drawn from primary government and vendor sources. Always confirm against the live source before acting. Rules change.

Disclaimer

This page summarises official guidance as at the date shown above. Rules and figures change, so verify against the primary source before acting. It is not professional advice: for guidance on your specific situation, talk to Skillsforce.

Talk to Skillsforce

Tell us where you can't
afford a gap.

Hiring, HR, payroll, manpower outsourcing, or setting up in Singapore: tell us what needs covering and we will come back within one to three working days with a practical next step.

One to three working days.

Prefer to talk first?

Call or email the office directly, whichever is easier.

Direct line+65 6291 5200
Office hoursMonday to Friday, 8:30AM to 5:30PM

Fields marked * are required.

We use these details only to answer your enquiry and to reply by email or phone. We will not add you to a marketing list. To ask what we hold about you, or to have it removed, email info@skillsforce.com.sg, attention Data Protection Officer. Our privacy notice sets out how we handle personal data in full.

Employment Agency Licence 99C3289UEN 199900539E