Core Development
MAS clarified two related but distinct scam-control regimes on 10 September 2026. Customers disputing unauthorised banking transactions are entitled to prompt investigation and fair handling, while authorised-transfer scams require preventive controls across platforms, banks and individuals rather than automatic application of the same liability framework.
Institutional Context
The first parliamentary reply addressed unauthorised transactions, including customer reporting, investigation, payment suspension for disputed amounts and liability assessment. The second addressed self-effected transfers and explained why the Shared Responsibility Framework, designed around phishing and unauthorised transactions, is not directly suitable when a victim personally authorises a transfer.
Material Issue
The distinction determines what evidence is needed to allocate responsibility. Authentication alone does not resolve every dispute, but a customer-authorised instruction also cannot be assessed as if no consent occurred. Effective governance therefore depends on a controlled record of transaction authentication, warnings, cooling periods, account changes, merchant safeguards and the customer's decision path.
Evidence & Implementation
Banks should preserve the full dispute and prevention record, explain liability conclusions and keep disputed amounts outside normal collection while investigations are pending. For higher-risk authorised transfers, controls should include cooling periods for new payees, limit increases and large account-draining payments. Messaging platforms must reduce unsolicited contact and present effective warnings.
Key Claims & Figures
MAS stated that prompt disputes involving merchants without 3-D Secure generally do not leave customers liable because merchant liability applies. It also noted that banks may consider vulnerability and financial circumstances in goodwill decisions, and that FIDReC provides independent dispute resolution. For authorised scams, MAS reported that cooling-period controls were being progressively implemented by major retail banks.
Market Implications
For Singapore, the replies define an operational boundary for banks, platforms, merchants and consumers as scam patterns evolve. The ASEAN relevance lies in cross-border payment corridors and platform-enabled fraud, where inconsistent authentication, warnings and redress can shift risk across jurisdictions and undermine confidence in digital finance.
Singapore & ASEAN Market Perspective
From an SNN.SG Pre-Disclosure Evidence Infrastructure perspective, liability should follow reconstructable event evidence rather than a single label such as authorised or unauthorised. A defensible record links device and identity signals, 3-D Secure status, payee creation, limit changes, warnings displayed, cooling periods, transaction execution, customer reporting and investigation findings.
What to Watch
Watch for quantitative outcomes from cooling periods, changes to bank and platform controls, FIDReC dispute patterns and any future refinement of the Shared Responsibility Framework. The policy question is whether evidence-based prevention and redress can adapt without weakening clear responsibility boundaries.

