Skip to content
Coverage

Card and bank billing

Singapore — MAS E-Payments User Protection Guidelines and the Shared Responsibility Framework

NationalSGDerived or secondary source

Singapore

Rule id
billing.sg-epayments
Version
1.0.0
In force from
June 30, 2019
Last read against its sources
August 5, 2026
Countries bound
Singapore

In plain language

What this regime says.

Singapore allocates the loss on unauthorised e-payments by duties, not by fault. If your bank failed one of its duties — most commonly, sending you a transaction notification — it bears the whole loss. If you complied with yours, your liability is capped at SGD 100. FIDReC resolves the dispute free of charge and its adjudications bind the bank.

Who is covered

Consumers and sole proprietors with protected accounts at Singapore financial institutions: bank accounts, credit and charge cards, and e-wallets.

What you get

Reversal of the unauthorised amount, with liability capped at SGD 100 where you met your duties and nil where the institution failed one of its own; plus the Shared Responsibility Framework waterfall for phishing scams.

Where claims go wrong

  • Not asking for the transaction notification logs. A missing or late notification is the institution's duty failure and shifts the whole loss.
  • Accepting "you gave away your OTP" as the end of the analysis. The test looks at both sides.
  • Not going to FIDReC. Mediation is free and adjudication binds the institution.
The official claim route

Authority

Every citation,
with its pinpoint.

A claim that cites “EU law” gets filed. A claim that cites Article 7(1)(c) gets answered. These are the exact coordinates this entry rests on.
  1. MAS E-Payments User Protection Guidelines (PSN07)Monetary Authority of Singapore, E-Payments User Protection GuidelinesDuties of the account holder and the financial institution; liability allocation for unauthorised transactions; investigation timeframes of 21 business days for straightforward cases and 45 business days for complex or cross-border cases
  2. Shared Responsibility Framework for phishing scamsMAS and IMDA Shared Responsibility FrameworkWaterfall of responsibility: financial institutions first, then telecommunication operators, where prescribed anti-scam duties were breached
  3. FIDReC — Financial Industry Disputes Resolution CentreFIDReC Terms of Reference

Sources

Where a figure is indexed, converted or published by a regulator rather than fixed in the instrument, the provenance is recorded separately. Anything marked as a modelled estimate is exactly that — a model, not a statutory number.

What it imposes

Clocks, defences and the ladder.

A rule module builds these while it evaluates, because a limitation period depends on which forum is open to you. What follows is the structure this regime produces — deliberately with no dates and no figures, because those belong to your facts rather than to the law.

The clocks it starts

  • Institution must complete its investigation (21 business days)The Guidelines expect a straightforward case to be completed within 21 business days, and a complex or cross-border case within 45 business days, with written reasons and the option of an independent review. Hold them to the timetable and ask for it in writing. (Period: 21 business days. We need the start date to work out your exact deadline.)MAS E-Payments User Protection Guidelines (PSN07) — Duties of the account holder and the financial institution; liability allocation for unauthorised transactions; investigation timeframes of 21 business days for straightforward cases and 45 business days for complex or cross-border casesResponse due
  • Complex or cross-border investigation (45 business days)Where the institution says the case is complex, ask it to say so in writing and to explain why. The longer period is not available by default. (Period: 45 business days. We need the start date to work out your exact deadline.)MAS E-Payments User Protection Guidelines (PSN07) — Duties of the account holder and the financial institution; liability allocation for unauthorised transactions; investigation timeframes of 21 business days for straightforward cases and 45 business days for complex or cross-border casesResponse due
  • Limitation period (6 years)Fatal if missedSection 6 of the Limitation Act 1959 gives six years for an action founded on contract or tort. FIDReC has its own, much shorter, practical expectation: complain to the institution first and refer to FIDReC promptly after its final reply.Limitation period

What it entitles you to, beyond money

  • Check whether the bank actually notified youThe Guidelines require the institution to provide transaction notifications for every outgoing transaction on a protected account, in a form you have chosen and can reasonably be expected to receive. A missing, delayed or suppressed notification is a duty failure that puts the whole loss on the institution. Ask for the notification logs.Duties of the account holder and the financial institution; liability allocation for unauthorised transactions; investigation timeframes of 21 business days for straightforward cases and 45 business days for complex or cross-border cases
  • The Shared Responsibility Framework for phishingFor phishing scams involving a spoofed digital message, the Framework imposes a waterfall: the financial institution bears the loss where it breached its prescribed duties, then the telecommunication operator where it breached its own. It is separate from, and additional to, the Guidelines.Waterfall of responsibility: financial institutions first, then telecommunication operators, where prescribed anti-scam duties were breached

What the other side will say

Each of these is a refusal this regime lets a counterparty attempt, paired with the answer to it. Reading them before you write is worth more than any amount of polish on the letter itself.

"You disclosed your one-time password"

high likelihood

The bank says you failed the credential-protection duty and so bear the whole loss.

What answers it

The framework is a two-sided test. Even where the account holder failed a duty, the institution bears the loss if it also failed one of its own — and the notification duty is the one most often missed. Ask for the notification logs, the timestamps, and the institution's written analysis of both sides of the test rather than just yours.

MAS E-Payments User Protection Guidelines (PSN07) — Duties of the account holder and the financial institution; liability allocation for unauthorised transactions; investigation timeframes of 21 business days for straightforward cases and 45 business days for complex or cross-border cases

"This is a complex case, so we need 45 business days"

medium likelihood

The institution invokes the longer investigation period without explanation.

What answers it

The longer period is for complex or cross-border cases. Ask the institution to state in writing why this one is complex, and to confirm the date by which it will conclude. An unexplained extension is a good opening line at FIDReC.

MAS E-Payments User Protection Guidelines (PSN07) — Duties of the account holder and the financial institution; liability allocation for unauthorised transactions; investigation timeframes of 21 business days for straightforward cases and 45 business days for complex or cross-border cases

Where to take it next

  1. Report to the financial institution and confirm in writingUse the reporting channel the institution is required to provide, obtain the reference, then confirm in writing. Ask expressly for the transaction notification logs and for the institution's assessment of which duty, if any, it says you failed.Claim directtypically 21 days
  2. Request an independent reviewThe Guidelines contemplate the account holder being able to seek a review of the institution's determination. Ask for it and for the reasons in writing before going further.Internal appealtypically 21 days
  3. FIDReCBinding on themThe Financial Industry Disputes Resolution Centre handles disputes with Singapore financial institutions. Mediation is free to consumers and adjudication carries a nominal fee; an adjudicator's award binds the institution if you accept it. FIDReC's claim limit was raised in recent years — check the current figure on its website.Alternative dispute resolutiontypically 90 daysofficial page
  4. Monetary Authority of SingaporeMAS does not resolve individual disputes but does supervise compliance with the Guidelines and the Shared Responsibility Framework. A report costs nothing and matters when the failure is systemic.Regulatortypically 90 daysofficial page
  5. Small Claims TribunalsFor claims against a merchant the Small Claims Tribunals are fast and cheap, with a limit of SGD 20,000 (raised to SGD 30,000 where both parties consent). Lawyers are not permitted, which keeps costs down.Small claimstypically 60 daysofficial page

Documents

What this regime can produce.

Every one of these is a document you send yourself, in your own name. Duesday never writes to anybody on your behalf and is never anyone’s agent.

The same claim type elsewhere

Card scheme chargeback rules (Visa, Mastercard, American Express, Discover)SCHEMESupranationalparty states varyVisa Core Rules and Visa Product and Service RulesConfidence: mediumPSD2 — unauthorised transactions and direct-debit refunds (Directive (EU) 2015/2366)EUSupranational30 countriesDirective (EU) 2015/2366 (PSD2)Confidence: highNorway — Financial Contracts Act 2020 and FinansklagenemndaNONationalNorwayLov om finansavtaler (finansavtaleloven), LOV-2020-12-18-146Confidence: mediumRussia — Federal Law 161-FZ on the National Payment System and the financial ombudsmanRUNationalRussiaФедеральный закон от 27.06.2011 № 161-ФЗ «О национальной платежной системе», ст. 9Confidence: mediumSwitzerland — Financial Services Act ombudsman affiliation and the Swiss Banking OmbudsmanCHNationalSwitzerlandFinancial Services Act (FinSA / FIDLEG), SR 950.1Confidence: mediumTürkiye — Bank Cards and Credit Cards Law No. 5464 and the Consumer Arbitration CommitteesTRNationalTürkiyeBanka Kartları ve Kredi Kartları Kanunu No. 5464Confidence: mediumConsumer Credit Act 1974 s.75 (and s.75A) — creditor joint and several liabilityGBNationalUnited KingdomConsumer Credit Act 1974, s.75Confidence: highCanada — payment card codes of conduct, provincial consumer protection and OBSICANationalCanadaCode of Conduct for the Payment Card Industry in CanadaConfidence: medium

Other rights in the same countries

Does this one reach your facts?

The engine runs every regime that could apply at once and reconciles them, rather than making you guess which page to read.

Not a law firm. Not legal advice. You send it yourself. This page describes a law; it is not advice about your situation and no outcome is promised.