Singapore’s payments industry has introduced a voluntary code covering pricing, fraud protection and consumer safeguards.
The Payments Industry Code of Conduct was launched by the Singapore Fintech Association (SFA) with industry participants.
It sets common standards that payment service providers can choose to adopt.
The framework covers major payment institutions, standard payment institutions, money-changing licensees and exempt payment service providers for regulated payment services under the Payment Services Act 2019.
Digital payment token and crypto-related services are excluded.
Adherence is based on self-assessment. Providers that determine they meet the standards can publicly declare themselves a “Code Adherent”, although this does not amount to independent verification or regulatory approval.
Declarations are valid for one year and must be renewed through another self-assessment.
The code complements existing MAS requirements, which take precedence if there is a conflict.
Clearer Pricing, Fewer Hidden Costs
Code Adherents must show customers the full cost of a transaction before they proceed, including fees and exchange rate mark-ups.
Exchange rates must also be disclosed where practicable.
They must avoid drip pricing and cannot market services as “free” or “zero fee” when exchange rate mark-ups form part of the cost unless this is clearly disclosed.
Competitor comparisons must also be fair and accurate.
Providers must give customers plain-language summaries of terms and make key information on pricing, fees and liability readily accessible.
Stronger Fraud and Card Safeguards
Code Adherents must maintain fraud prevention frameworks covering risk assessments, real-time monitoring, incident response and customer education on scams.
For card payments, they must adopt liability standards broadly aligned with those applying to banks.
The code gives an example of capping customer liability for certain unauthorised transactions at S$100, subject to conditions.
Data and Operational Resilience
The code also covers data protection and operational resilience.
Providers must limit the collection of customer data to what is reasonably necessary and follow applicable breach notification requirements.
PSPs are already required under existing regulations to identify and stress-test critical systems.
The code highlights areas such as ledger and wallet systems, payment gateways, customer-facing APIs and authentication services.
It also calls for fair treatment across customer groups, proportionate controls and anti-money laundering and counter-terrorism financing frameworks aligned with MAS notices.

SFA President Holly Fang said,
“This code gives providers a common set of standards to work towards, covering pricing transparency, fair advertising, fraud protection and how customer data is handled.
For consumers, that means fewer surprises and clearer recourse when something goes wrong. For the industry, it raises the baseline of trust that good businesses are built on.”
The SFA and industry participants plan to review and update the code as Singapore’s payments sector develops.
Featured image: Edited by Fintech News Singapore, based on image by DC Studio via Magnific


