The Singapore FinTech Association (SFA) together with industry players has on Monday launched its Payments Industry Code of Conduct.

The code sets out consistent general standards of professional conduct and transparency that payment service providers (PSPs) in Singapore may adopt in their dealings with customers and other members of the industry, the association said in a statement.

The SFA and industry players will review and update the code regularly as Singapore’s payments industry evolves, working with other stakeholders, and will welcome new market participants and providers over time.

The code applies to holders of a major payment institution license, standard payment institution license, or money-changing license, as well as exempt payment service providers, in relation to their regulated fiat currency related payment services under the Payment Services Act 2019. It does not extend to any digital payment token services which may be conducted by the PSP.

Adherence to the code is voluntary and based on self-assessment. A PSP may become a “Code Adherent” by assessing its own policies, processes and systems against the standards in the Code, and may then declare publicly that it adheres to the Code.

The code is intended to complement, not replace, existing obligations under the Payment Services Act and MAS regulations.

Code adherents are responsible for ensuring their ongoing compliance to maintain the validity of their public declaration and to avoid making any false or misleading claims to customers and the public.

Public declarations of adherence must state the year the self-assessment was conducted and are valid for one year, after which a renewed self-assessment is required to maintain Code Adherent status. To avoid doubt, the Code does not automatically apply to all PSPs and PSPs may choose to adhere to the Code or not adhere to the Code.

The code crystallizes best practices across several areas, including pricing and transparency; prohibition of drip pricing or hidden mark-ups; fair marketing and advertising; fraud prevention and consumer protection; card dispute liability; data privacy and security; operational resilience and critical systems.

Firstly, code adherents commit to showing customers the full cost of a transaction before they commit to it, including the principal amount, transaction fees, the applicable exchange rate and any mark-up, and the final amount to be transacted.

Secondly, code adherents will not add mandatory charges halfway through a transaction, and will not describe a service as “free” or “zero fee” where the total cost includes a mark-up or spread on the exchange rate, unless that cost is clearly disclosed.

Thirdly, advertisements must not give a false or misleading impression regarding the cost of service. Comparisons with competitors must be fair, accurate and capable of substantiation. Code adherents must not selectively exclude their own costs while highlighting competitors’ fees, to create a false impression of cost-savings in choosing one PSP over another.

Fourthly, code adherents will maintain a documented fraud prevention framework, including regular risk assessments, transaction monitoring, clear escalation procedures and ongoing user education on common scams. They must also participate in, support, or contribute to SFA-led, Monetary Authority of Singapore (MAS)-led, or other structured industry-wide collaboration initiatives, where relevant and proportionate to their business model, size, and risk profile, including any Fraud and Risk Committee or equivalent forum established by SFA, MAS, or the industry.

Fifthly, for card-based payment services, code adherents will adopt liability standards in line with those applying to banks under the Association of Banks in Singapore Code of Practice, including caps on customer liability for unauthorized transactions and clear procedures for reporting lost or stolen cards.

Sixthly, code adherents commit to internal controls, data minimization and compliance with the Personal Data Protection Act. In the event of a notifiable data breach, they will notify affected users and the Personal Data Protection Commission as soon as practicable, and within three calendar days of assessing the breach.

Seventhly, code adherents will identify and stress-test critical systems such as ledger and wallet systems, payment gateways, customer-facing APIs and authentication services.

Underpinning the code are core principles of fair treatment across all customer segments, proportionality to a provider’s size and risk profile, industry collaboration on systemic challenges, and robust anti-money laundering and countering the financing of terrorism (AML/CFT) frameworks aligned with the relevant MAS Notices, said the statement.

“Payments touch almost every part of daily life in Singapore, and people deserve to know exactly what they are paying and what protection they have,

“This code gives providers a common set of standards to work towards, covering pricing transparency, fair advertising, fraud protection and how customer data is handled,” said Holly Fang, President of the SFA.

“For consumers, that means fewer surprises and clearer recourse when something goes wrong. For the industry, it raises the baseline of trust that good businesses are built on,

“The code is built to grow with the sector, and we welcome more providers to adopt it as the payments landscape develops,” she added.

Singapore’s payments sector funding reaches $319M in first nine months of 2025