Singapore FinTech Association Launches Voluntary Payments Code of Conduct
According to the Singapore FinTech Association (SFA), payment service providers in Singapore now have a voluntary code of conduct covering pricing transparency, fraud prevention, data protection and operational resilience.
Spencer Merrick·updated August 06, 2026

The framework applies to licensed payment institutions, money-changing licensees and exempt providers offering regulated fiat-currency payment services under the Payment Services Act. For users of digital wallets, payment apps and cross-border services, the practical change is limited but material: participating firms are expected to disclose the real cost of a transaction before it is authorised.
Voluntary compliance is not regulatory approval
The Payments Industry Code of Conduct is based on self-assessment. Providers that decide they meet its standards can publicly describe themselves as “Code Adherent” for one year, after which the declaration must be renewed through another self-assessment.
That distinction matters. The code does not replace the requirements of Singapore’s Payment Services Act or the rules of the Monetary Authority of Singapore (MAS). Existing regulatory obligations take precedence where there is a conflict. Nor does a code declaration amount to independent verification or formal regulatory approval.
The scope is also narrower than the broader fintech market. Digital payment token and crypto-related services are excluded. The framework is aimed at regulated fiat payment activity, including services delivered by major and standard payment institutions, money-changing licensees and exempt payment service providers.
This creates a familiar compliance structure: a mandatory regulatory floor, with an industry-defined layer above it. The value of the second layer will depend on how consistently firms apply it and how much information customers can actually verify.
The controls target hidden pricing and fraud
Code Adherents are expected to show customers the full cost of a transaction before they proceed. That includes fees, exchange-rate mark-ups and other pricing components. The code discourages drip pricing and restricts “free” or “zero-fee” claims where a currency mark-up forms part of the cost, unless that cost is clearly disclosed.
Providers must also make key information on fees, pricing and liability readily accessible, using plain-language summaries of relevant terms. For customers comparing neobanks or payment apps, this is more useful than a headline fee schedule that omits the exchange-rate spread or presents the final cost only at the last stage of checkout.
Fraud controls are addressed at the infrastructure level. The framework calls for risk assessments, real-time monitoring, incident-response procedures and customer education on scams. It also covers authentication services, payment gateways, customer-facing APIs, ledger and wallet systems. Those are not cosmetic components: failures in any of them can affect transaction integrity, access to funds and the accuracy of account records.
For card payments, the code introduces liability standards broadly aligned with those applied to banks. One example in the framework involves a S$100 cap on customer liability for certain unauthorised transactions, subject to conditions. That is not a universal guarantee. Customers will still need to examine the provider’s stated liability rules and the conditions attached to them.
The data provisions require firms to limit collection to information that is reasonably necessary and to follow applicable breach-notification requirements. Operational resilience requirements focus on identifying and stress-testing critical systems, a process already required under existing regulation for some payment providers.
What users should verify before relying on the label
The code gives customers a reasonable set of questions, but not a complete risk assessment.
First, check whether the provider is actually participating and whether its “Code Adherent” declaration is current. A one-year self-assessment is a signal of stated alignment, not proof that controls have been independently tested.
Second, compare the total transaction cost rather than the advertised fee. This is particularly relevant to cross-border payments, where exchange-rate mark-ups can be embedded in an apparently free service. The relevant figure is the amount received or charged after all disclosed pricing components are applied.
Third, review fraud and dispute procedures before an incident occurs. The important details are reporting deadlines, authentication requirements, the allocation of liability and the provider’s process for investigating unauthorised transactions. The code may establish a baseline, but the practical recourse remains dependent on the provider’s implementation and the transaction’s circumstances.
The SFA said the code will be reviewed as the payments sector develops. That leaves its main weakness unchanged: adherence is voluntary and self-declared. The framework may reduce opaque pricing and clarify expected safeguards, but it does not remove counterparty risk, system dependency or the need to reconcile what a provider promises with what its API, ledger and support process actually deliver.
As digital services expand into adjacent subscription and consumer markets, including the growth of digital fitness and activewear, the same issue will persist: a visible compliance label is useful only when the underlying transaction architecture can withstand scrutiny.