Singapore Payments Code Bans Drip Pricing, Forces FX Markup Disclosure Before Transfer
Resumo
Singapore Payments Industry Code of Conduct entra em vigor proibindo 'drip pricing' e exigindo divulgação de markups de câmbio antes da confirmação de transação, estabelecendo padrão de transparência para provedores de pagamento signatários.

Singapore's payments industry has imposed a new transparency standard on itself: payment service providers that want to claim they meet the sector's best-practice norms must now show customers the full, true cost of a transaction — including any exchange rate markup — before that transaction is confirmed. "Zero-fee" advertising is banned when hidden exchange rate spreads make up the real cost of a transfer. The Singapore FinTech Association (SFA) published the voluntary Payments Industry Code of Conduct on August 3, 2026, with a broad group of payment service providers as partners.
Drip Pricing Is Now Explicitly Banned for Code Adherents
The code defines "drip pricing" — a practice the Singapore Ministry of Trade and Industry identified as a documented problem in both online and physical retail as far back as 2022 — as advertising a lower price than the actual final cost by adding mandatory fees only during the transaction process. Under the code, a payment service provider (PSP) that has publicly declared itself a "Code Adherent" must include all mandatory charges in the amount shown to a customer before the customer confirms a payment.
The exchange rate markup transparency requirement is the code's most operationally demanding provision for many providers. Where a currency conversion service is offered, Code Adherents must clearly disclose the exchange rate applied — and, critically, must not advertise a service as "free" or "zero fee" when exchange rate markups constitute a real cost to the customer. The code defines "Exchange Rate Mark-up" specifically: the difference between what the provider charges and the true mid-market rate — the midpoint between buy and sell prices in global currency markets, sourced from a neutral benchmark administrator with no more than a 10-minute data delay.
The gap between benchmark and retail rates in Singapore's payments market is material. Data from Singapore-based providers indicates traditional banks typically charge 1.5% to 2.5% above the interbank rate on international transfers, while digital payment providers often advertise 0.3% to 0.6% above interbank — and some advertise "no fee" while embedding a spread in the exchange rate entirely. On a transfer of S$10,000 (approximately $7,800), a 2% spread represents S$200 (approximately $156) that was never disclosed as a fee.
The final transaction summary presented to a customer before execution must now show these charges separately: the principal amount, the transaction fees, the applicable exchange rate and whether any markup exists, and the final amount to be transferred.
What 'Code Adherent' Status Actually Means for Consumers
The code is entirely voluntary. Adherence rests on a PSP's own self-assessment — an internal review of its policies, processes, and systems against the code's standards. A firm that determines it meets those standards may publicly declare itself a "Code Adherent." That declaration does not constitute independent verification or regulatory approval by the SFA.
The annual renewal requirement creates some accountability structure. Code Adherent status expires after 12 months unless a fresh self-assessment is completed. A provider that fails to renew must cease any public-facing claim of adherence. The SFA does not conduct supervisory audits or enforcement reviews of declared adherents.
This structure is consistent with how industry self-regulation works in practice: it creates reputational pressure without legal consequence for non-compliance. Whether that pressure is sufficient to drive consistent adherence depends on whether consumers distinguish between Code Adherent and non-adherent providers when choosing a payment service — and on whether competitors use the standard as a competitive differentiator in marketing. The more visible the "Code Adherent" designation becomes, the more costly non-adherence becomes reputationally.
Where the SFA code's provisions conflict with MAS requirements under the Payment Services Act 2019, the PS Act takes precedence. The PS Act already requires fee disclosures from all licensed PSPs; the code operationalizes those obligations with specific, standardized procedures and extends expectations into areas the Act does not prescribe with this level of detail.
Fraud Prevention Requirements: Risk Frameworks and Real-Time Monitoring
On fraud prevention, the code requires Code Adherents to establish and maintain a documented fraud prevention framework covering regular fraud risk assessments, real-time transaction monitoring, incident response and escalation procedures, and ongoing customer education about prevalent scam typologies.
This requirement arrives alongside sustained pressure on Singapore's payments infrastructure from scam activity. The Singapore Police Force's Annual Scam and Cybercrime Brief 2025, released in February 2026, recorded S$913.1 million (approximately $712 million) in total scam losses for 2025 — a 17.9% decline from S$1.1 billion reported in 2024, but with a rising median loss per case: S$1,644 (approximately $1,282), up from S$1,389 in 2024.
A persistent structural challenge complicates the picture. As of 2025, 81.8% of reported scam cases in Singapore involved victims who transferred funds voluntarily after being manipulated through social engineering — not unauthorized technical account access. This category, called "self-effected transfers," lies outside the scope of the Shared Responsibility Framework (SRF) that MAS and the Infocomm Media Development Authority (IMDA) implemented in December 2024, which assigns liability to financial institutions and telecommunications operators for phishing scam losses. The SFA code's fraud prevention requirements, while voluntary, extend an obligation into this gap by requiring PSPs to build and operate active customer education programs.
Card Dispute Liability: A S$100 Cap for Qualifying Unauthorized Transactions
For PSPs offering card-based payment services, the code establishes liability standards aligned with those applicable to banks under the Association of Banks in Singapore (ABS) Code of Practice for Banks — Credit Cards.
The standard includes a cap on customer liability for unauthorized card transactions: for qualifying unauthorized transactions reported before a fraud is discovered, customer liability is capped at S$100 (approximately $78), provided the customer did not act fraudulently or with gross negligence and notified the card issuer as soon as reasonably practicable after becoming aware the card was lost or stolen. The issuer retains discretion to waive even this limited liability on a case-by-case basis.
The code specifies conditions of full non-liability — including where a card was not stolen but card details were used for unauthorized online or phone transactions, and where unauthorized PIN-activated transactions occurred. Issuers must provide a dedicated hotline for reporting card loss, and are required to waive or refund interest and fees accrued during fraud investigations.
Operational Resilience and Data Obligations
Beyond pricing and fraud, Code Adherents commit to identifying and stress-testing four categories of critical systems: ledger and wallet infrastructure, payment gateway and switch systems, customer-facing APIs and mobile back-end services, and authentication systems including one-time password (OTP) delivery.
This builds on existing MAS technology risk management obligations. The code also requires adoption of the MAS API Framework for open banking to a degree proportionate to each provider's scale, and recommends security certifications including ISO/IEC 27001, SOC 2 Type II, and the Singapore-specific Multi-Tier Cloud Security (MTCS) SS 584 standard.
On data, Code Adherents must collect only information reasonably necessary for their services — a data minimization principle — and must comply with breach notification requirements under Singapore's Personal Data Protection Act 2012, specifically notifying affected users and regulators within three calendar days of determining a breach is notifiable.
Singapore's Growing Digital Payments Market
The SFA published the code against the backdrop of a rapidly expanding payments market. A joint report from PwC Singapore and the SFA — the "Payments' State of Play 2026" — found that digital payments in Singapore reached a transaction value of $39.37 billion in 2023, with projections pointing to $113.65 billion by 2030. Payments accounted for 44% of Singapore's total fintech funding in the period covered by the report. As of 2026, an estimated 98% of Singaporean adults hold bank accounts.
SFA President Holly Fang, commenting on the code at launch, described it as establishing a common set of standards covering pricing transparency, fair advertising, fraud protection, and data stewardship that gives consumers clearer recourse when something goes wrong and raises the baseline of trust for the industry.
The code explicitly positions itself as a complement to, not a replacement for, the statutory framework. Where MAS requirements are prescriptive, PSPs must comply with those requirements regardless of whether they have declared Code Adherent status. The voluntary code's value lies in what it requires beyond current statutory minimums — specifically, the granular upfront disclosure of FX markups, the prohibition on "zero-fee" marketing when spreads constitute a real cost, and the explicit card liability framework for non-bank PSPs.
Frequently Asked Questions
Does the SFA Payments Industry Code of Conduct have any enforcement mechanism if a provider violates it?
No. Adherence is entirely voluntary and based on each payment service provider's own self-assessment. The SFA does not conduct audits, supervise adherents, or impose penalties for non-compliance. A provider that publicly declares "Code Adherent" status takes on a reputational commitment — and must remove that claim if it fails to renew its annual self-assessment — but no regulatory sanction flows from the SFA itself. Violations of the underlying MAS requirements under the Payment Services Act remain enforceable by MAS independently.
What is an FX markup, and why does it matter if a payment is advertised as 'zero fee'?
A foreign exchange (FX) markup is the difference between the true mid-market exchange rate — the midpoint between buy and sell prices for a currency pair — and the rate a payment provider actually applies to a customer's transfer. When a provider offers a "zero fee" or "no fee" international transfer, it often recovers its revenue through a wider exchange rate spread instead of a visible transaction charge. On a transfer of S$10,000 (approximately $7,800), a 2% markup costs approximately S$200 (approximately $156) that a consumer never sees itemized on screen. Under the new code, Code Adherents must disclose the markup explicitly and cannot market a service as "free" when a markup exists.
Which types of payment providers does the code apply to, and does it cover cryptocurrency services?
The code applies to holders of a major payment institution license, standard payment institution license, money-changing license, or exempt payment service providers under Singapore's Payment Services Act 2019 — specifically for their non-cryptocurrency payment services. Digital payment token and crypto-related services are explicitly excluded from the code's scope. A hybrid provider that offers both conventional payments and crypto services is covered by the code only for its conventional payments business.
How does the code's card liability cap differ from protections consumers already have at banks?
The S$100 (approximately $78) liability cap for qualifying unauthorized card transactions mirrors the standard long established for bank-issued credit and debit cards under the Association of Banks in Singapore's Code of Practice for Banks. The SFA code extends an equivalent standard to non-bank PSPs offering card payment services — digital wallets and fintech-issued cards — that previously may not have had explicit contractual liability limits aligned with this level of consumer protection.
ⓒ 2026 TECHTIMES.com All rights reserved. Do not reproduce without permission.