Veridict

Compliance · Singapore PDPC

NRIC Compliance Watch

Singapore's PDPC prohibits NRIC — full or partial — as an authentication factor from 31 December 2026, with enforcement from 1 January 2027.

Days to enforcement
154
Compliance deadline 31 Dec 2026 · enforcement 1 Jan 2027
Breaches found
25
NRIC used to authenticate
Breach rate
13.1%
of audited conversations
Agents involved
12
need retraining
Verified clear
0
coached and confirmed

Breach rate trend

Percentage of conversations per day where NRIC was used to verify identity.

05010007-0107-0607-1007-1407-1807-2207-2607-302026-07-01 — 100 (1 audits)2026-07-02 — 50 (4 audits)2026-07-03 — 0 (1 audits)2026-07-04 — 0 (3 audits)2026-07-06 — 0 (3 audits)2026-07-07 — 0 (1 audits)2026-07-08 — 14.3 (7 audits)2026-07-09 — 0 (2 audits)2026-07-10 — 25 (4 audits)2026-07-11 — 0 (4 audits)2026-07-12 — 25 (4 audits)2026-07-13 — 33.3 (3 audits)2026-07-14 — 0 (2 audits)2026-07-15 — 0 (2 audits)2026-07-16 — 0 (1 audits)2026-07-17 — 0 (2 audits)2026-07-18 — 0 (4 audits)2026-07-19 — 0 (2 audits)2026-07-20 — 0 (1 audits)2026-07-21 — 16.7 (6 audits)2026-07-22 — 42.9 (7 audits)2026-07-23 — 16.7 (6 audits)2026-07-24 — 12.5 (8 audits)2026-07-25 — 0 (2 audits)2026-07-26 — 0 (2 audits)2026-07-27 — 16.7 (6 audits)2026-07-28 — 0 (4 audits)2026-07-29 — 33.3 (3 audits)2026-07-30 — 20 (5 audits)2026-07-31 — 20 (5 audits)

By client

Where the exposure sits. Each client receives only their own findings.

Meridian Telecom15of 58
Lumina Retail5of 51
Straits Retail Bank3of 54
Anchor Insurance2of 28

Remediation tracker

AgentBreachesState
Priya Raman5coached
Priya Raman3flagged
Wei Ling Tan3flagged
Daniel Ong2flagged
Desmond Yeo2flagged
Nurul Aisyah2flagged
Jason Pereira2flagged
Bryan Ng2flagged

Offending conversations

ConversationAgentClient
conv-0179Farah IsmailStraits Retail BankEvidence →
call-001Priya RamanMeridian TelecomEvidence →
call-002Marcus LimStraits Retail BankEvidence →
conv-0078Daniel OngLumina RetailEvidence →
email-002Desmond YeoAnchor InsuranceEvidence →
chat-001Anitha SelvamLumina RetailEvidence →
call-006Nurul AisyahMeridian TelecomEvidence →
conv-0125Jason PereiraMeridian TelecomEvidence →
conv-0157Ravi KumarStraits Retail BankEvidence →
conv-0177Priya RamanMeridian TelecomEvidence →

How this is detected

The scorecard criterion nric_auth is an auto-fail rule evaluated on every conversation. It fires on the behaviour — an agent requesting or accepting NRIC digits to verify a caller — not on the value, which has already been redacted to [NRIC]before scoring. Partial forms (“last four”) are detected using the surrounding turns, because the request and the answer sit in different speakers' turns.