Singapore payments code targets hidden fees, fraud and data protection
Singapore’s voluntary payments code sets standards for transparent fees, advertising, fraud controls, data protection and system resilience.
A new self-regulatory framework established by the Singapore FinTech Association aims to bring consistency to non-crypto payment services by enforcing clear pricing, robust scam defences, and stricter operational safeguards across the industry.
Table Of Content
The Singapore FinTech Association has launched a voluntary code of conduct that establishes uniform operational standards across the local payments landscape. Designed to govern how institutions handle pricing, advertising, fraud mitigation, customer disputes, personal data, and critical payment infrastructure, the Payments Industry Code of Conduct was developed alongside industry participants to foster greater consistency and trust. The framework encompasses major and standard payment institutions, money changers, and exempt payment service providers, strictly regulating services involving fiat currencies while excluding digital payment token services.
Participation in the framework remains entirely discretionary, leaving individual providers to decide whether to adopt the standards. Entities choosing to align with the code must conduct an internal assessment of their policies, processes, and technical systems before publicly declaring themselves a Code Adherent. These public declarations must explicitly state the year in which the self-assessment was conducted, remaining valid for one year before requiring a fresh evaluation to maintain adherent status. Because adherence relies on internal reviews rather than independent verification or regulatory approval, the code functions as a supporting mechanism alongside existing obligations under the Payment Services Act and Monetary Authority of Singapore regulations, which take precedence at all times.
Transaction costs must be shown upfront
Institutions adopting the code commit to displaying the complete cost of a transaction to customers prior to final confirmation. This breakdown includes the principal amount, transaction fees, the applicable exchange rate, any exchange-rate mark-up, and the final transacted total. To ensure pricing clarity, the framework prohibits drip pricing, preventing providers from introducing compulsory charges partway through the payment journey. Furthermore, institutions cannot describe a service as free or zero fee when the total cost incorporates an exchange-rate mark-up, unless that specific fee is explicitly disclosed.
Advertising practices must also maintain strict accuracy to ensure consumers are never given a false or misleading impression regarding the true cost of a service. Any comparative claims made against competitors must be accurate, supported by solid evidence, and calculated using equivalent costs. To avoid creating a false impression of savings, providers must not exclude their own charges while selectively highlighting competitor fees.
SK Saraogi, chief executive officer of Wise Asia Pacific and outgoing co-chair of the SFA Payments Subcommittee, emphasised that the code serves to make payment costs easier to understand.
“One of the clearest messages from this Code is that customers deserve greater transparency and confidence when they make a payment. That starts with understanding the total cost of a payment before they make it. A mark-up hidden in the exchange rate is still a cost to the customer and should be displayed transparently. When pricing is presented clearly and consistently across payment providers, consumers can make informed choices and competition is driven by real value. The broad industry support from our subcommittee shows that the industry recognises transparency and strong consumer protection isn’t just good for consumers, it’s good for business. I hope more payment service providers will self-assess against the Code and publicly declare their adherence. This is how we’ll build trust and raise the bar together as an industry.”
Fraud prevention and card disputes
To combat financial crime, Code Adherents must establish and maintain a documented fraud prevention framework incorporating regular risk assessments, continuous transaction monitoring, clear escalation procedures, and customer education on widespread scams. Institutions are expected to participate in relevant fraud and risk initiatives led by the Singapore FinTech Association, the Monetary Authority of Singapore, or other industry bodies, with the level of involvement tailored to each provider’s business model, size, and risk profile. Additionally, providers offering card-based payment services must adopt liability standards aligned with those applying to banks under the Association of Banks in Singapore Code of Practice, which includes setting clear limits on customer liability for unauthorised transactions and outlining precise procedures for reporting lost or stolen cards.
Data protection and system resilience
Participating providers must maintain robust controls to protect customer and transaction data, limit the collection of unnecessary personal information, and comply fully with Singapore’s Personal Data Protection Act. Should a data breach be assessed as notifiable, institutions are required to inform both affected users and the Personal Data Protection Commission as soon as practicable, and no later than three calendar days after completing that assessment.
The code further obliges providers to identify and stress-test critical operational systems, including ledger and wallet systems, payment gateways, customer-facing application programming interfaces, and authentication services. Beyond technical safeguards, the broader principles of the framework mandate fair treatment across all customer groups, security measures proportionate to each provider’s size and risk profile, active industry cooperation, and robust anti-money laundering and counter-terrorism financing measures that align with Monetary Authority of Singapore requirements.
Moving forward, the Singapore FinTech Association plans to review and update the code as the payments industry evolves, allowing more entities to join over time while keeping adoption voluntary and ensuring that each participating provider remains responsible for the accuracy of its public declaration.





