On 3 August 2026, the Singapore FinTech Association (SFA) published a Payments Industry Code of Conduct. Holly Fang, President of the Association, in explaining the purpose of the Code, said people deserve to know exactly what they are paying and what protection they have. Jeremy Tan, CEO of Liquid Group and co-chair of SFA’s Payments Subcommittee, said the Code should reinforce Singapore’s position as a “trusted global payments and fintech hub” as those payments become more digital, instant and cross-border.
Licensed payment firms already sit under the Payment Services Act 2019 and Monetary Authority of Singapore (MAS) rules. That is how MAS governs a firm. The Code is layered on top of those obligations. It guides a participating provider on how to communicate when a customer disputes a payment: a charge they do not recognise, a card already reported lost, or a transfer that did not arrive as expected.
What happened
The Code applies to holders of a major payment institution licence, a standard payment institution licence or a money-changing licence, and to exempt payment service providers, for ordinary currency services under the Act. Digital payment token services sit outside it. A firm can voluntarily become a Code Adherent by checking its own policies, processes and systems against the Code and publishing a dated declaration that lasts one year. The Association leaves that assessment with the firm. Where the Code and MAS rules overlap, the MAS rules remain the governing standard.
Here are some of the duties a Code Adherent takes on:
Fair dealing (clause 3.1). The firm agrees to be guided by MAS’s Guidelines on Fair Dealing, last revised 30 May 2024: clear information, and complaints handled independently, effectively and promptly. That is the general path for a disputed payment.
Operational resilience and APIs (clauses 4–5). Applicable regulations already require payment firms to identify critical systems and stress-test them. Code Adherents are to specifically identify and test the systems that would stop payments if they failed, including ledgers and wallets, payment gateways and switches, customer-facing application programming interfaces (APIs) and mobile back-ends, and authentication such as one-time passwords. They also adopt the MAS API framework for open banking to the extent that fits the business, and obtain recognised cybersecurity certifications from vendors where that is relevant.
Pricing (clause 6). A customer must be able to view the full cost before committing. The final summary on screen, before execution, should show:
1. The principal amount to be transferred
2. The transaction fees, as a monetary amount
3. The applicable exchange rate, and any exchange-rate mark-up or range of mark-ups (the difference between the rate offered to the customer and the benchmark rate the firm itself obtained)
4. The final amount to be transacted.
Code Adherent firms must not engage in drip pricing: advertising a price lower than the final price by adding mandatory charges during the transaction that were not disclosed up front. Where an exchange-rate mark-up is in the total, the firm must not represent the service as “free” or “zero fee” unless that cost is disclosed. SK Saraogi, CEO of Wise Asia Pacific, who co-chaired the Payments Subcommittee while the Code was prepared, said a mark-up hidden in the exchange rate is still a cost to the customer, and that seeing the total is “good for business.”
Marketing and terms (clauses 7–8). Advertisements must follow the Consumer Protection (Fair Trading) Act and the Singapore Code of Advertising Practice. The Code treats an exchange-rate mark-up as material information that must be disclosed under the Fair Trading Act. Comparisons with competitors must be fair, accurate and capable of being substantiated. Free trials should come with notice before they end, and a clear cancellation path.
Fraud prevention (clause 9). The firm keeps a documented framework that, at minimum, includes regular fraud risk assessments, real-time transaction monitoring, clear incident-response and escalation procedures, and ongoing user education on common scams.
Card-dispute liability (clause 10). Firms that issue cards write into the customer contract how liability works for fraudulent, lost or stolen card transactions, and adopt standards commensurate with the Association of Banks in Singapore (ABS) Code of Practice for Banks – Credit Cards. Those standards include:
1. A liability cap for unauthorised charges before the loss is reported, with SGD 100 given as the example, and discretion for the issuer to waive the rest
2. Cases in which the customer owes nothing if they were not fraudulent or grossly negligent, including telephone or internet use of the card details and unauthorised PIN transactions
3. A pause on interest and late fees while an investigation runs
4. The issuer’s right to terminate the card and recover amounts if the customer is found grossly negligent and refuses to settle
5. The customer’s duty to provide information for the investigation
6. Clear procedures to stop the card and report loss or theft
7. A dedicated hotline to report a lost card
8. Dispute-resolution protocols aligned with Fair Dealing.
Data (clauses 11–13). Internal controls should include role-based access, segregation of duties, a documented compliance policy, audit trails, and regular vulnerability assessments. The firm follows the Personal Data Protection Act, collects only what it needs, and, after assessing a notifiable breach, tells affected users and the Personal Data Protection Commission as soon as practicable and within three calendar days.
What it means
Let’s say a customer gets home, finds a credit card missing, and later sees charges they did not make. A Code Adherent that issued the card is asked to have already written the eight terms above into the customer contract. That includes a cap on how much the customer can still be asked to pay for unauthorised charges that went through before they reported the card missing. The Code’s example is SGD 100. The issuer may waive even that remainder.
On 7 January 2025, MAS restated that bank-card practice. Some online checkouts ask the cardholder to approve the payment with an extra password or an app prompt, known as 3-D Secure (3DS). If the customer authenticates that step and the charge later proves fraudulent, MAS treats the approval as negligence. The SGD 100 limit on the customer’s liability would not apply, and the customer could be asked to bear more of the loss.
If the disputed payment was a PayNow transfer, a wallet top-up or money sent overseas, clause 3.1 is the route: complaints handled independently, effectively and promptly. The SGD 100 figure sits in the card chapter of the Code.
The significance of the Code is that the industry wrote the standard itself. Holly Fang said it “raises the baseline of trust that good businesses are built on,” and that it is built to grow with the sector as more providers adopt it. Jeremy Tan said a common standard, with room to innovate, should give customers greater confidence and reinforce Singapore’s position as a “trusted global payments and fintech hub.” Other APAC markets can study that industry-driven approach, and adapt it to their own payment rails.
What to watch
• Public declarations. Whether payment firms publish a dated Code Adherent statement this year, and whether those statements are renewed or taken down when the year ends, so the label still matches a live self-assessment.
• Upfront pricing. Whether the four-line cost summary appears before confirm, including exchange-rate mark-ups, and whether “free” or “zero fee” claims recede where a spread remains.
• Card contracts. Whether fintech card agreements carry the SGD 100 example cap, the telephone, internet and PIN exceptions, a dedicated loss hotline, and dispute protocols aligned with Fair Dealing.
• Incidents. How firms handle a scam, a leak or an outage: whether the fraud plan, the three-day breach clock, and the tests on ledgers, gateways and login systems are visible when a real event arrives.



