Singapore's New Scams Act Just Changed What "Service Provider" Means

Image

SG Parliament passed the Scams (Countermeasures) and Other Matters Bill on 9 September, and it does something most scam legislation doesn't: it stops treating financial institutions as the only party with obligations. 

The Act amends five separate statutes, the Protection from Scams Act, the Miscellaneous Offences Act, the Online Criminal Harms Act, the Police Force Act, and the Banking Act, and the common thread running through all five is a broader, more precisely defined category called a "scam-enabling service."

That category covers bank accounts, payment accounts, and digital payment token accounts, as expected. It also covers telephone lines, online accounts, credit facilities, web hosting, and domain registration. Telcos, online platforms, web hosts, and domain registrars are now deemed relevant service providers under the same framework banks have operated under since the Facility Restriction Framework launched in October 2025.

‍

Three New Orders, One Common Requirement: Speed

Prescribed officers, police, Commercial Affairs officers, and civilian specialists can now issue three types of orders. 

  1. Service Limitation Orders restrict a scam-enabling service to a named person for up to three years, on suspicion or reason to believe they'll use it to commit or facilitate a scam. 
  2. Account Disabling Orders go further, disabling an account outright for up to 30 days, extendable once, where an officer suspects the account has been or will be used in furtherance of a scam. 
  3. Disclosure Orders compel a service provider to hand over account or user information where disclosure is necessary to prevent a scam offence.

All three carry extra-territorial effects. A telco based outside Singapore, serving Singapore subscribers, is not insulated. Neither is a Singapore telco storing its data offshore.

The penalties attached to non-compliance are not symbolic. Failing to act on a Service Limitation or Account Disabling Order carries fines up to S$1 million for a company, plus a continuing fine of up to S$100,000 a day. 

 Under the enhanced OCHA provisions, platform penalties for code-of-practice breaches jump from S$1 million to S$10 million per instance, with a further S$300,000 a day for a continuing offence. The Act also permits OCHA directions, stop-communication and disabling directions, to be issued by a computer program assessing that a scam is underway, under a named responsible officer's authorisation.

‍

The Immunity Clause Is the Quiet Notice

Buried under the penalty schedule is a provision that matters more than it looks: a service provider that voluntarily discloses information in good faith, with reasonable care, is protected from liability under the Banking Act, the PDPA, contract, or professional conduct rules. 

A provider can also act to prevent use of an account for up to 30 days without waiting for an order, provided the suspicion traces back to information from an existing Account Disabling Order or Disclosure Order.

That's a legislative green light for exactly the kind of cross-institutional signal sharing that's been missing from most regional fraud responses until now. The Act doesn't just compel compliance after an order is issued. It removes the legal liability that's historically made institutions hesitant to share a suspicious signal before being formally required to.

‍

What Does This Mean for Your Organization?

Most institutions operating in Singapore now have a working answer for what happens once an order arrives. Fewer have the internal process to identify an affected account within the order's timeframe, apply only the restriction stated, and keep a complete audit trail, the responsible staff, the completion time, the expiry date, that would hold up if "reasonable excuse" for non-compliance is ever tested in court. 

Contact us here to talk through whether your current process would survive that test.

‍

Where Level Five Fits

This is precisely the area Level Five's work is built around. Three parts of the new regime map directly onto what our platform does for institutions across the region.

Identifying the right account, fast, inside a 30-day disabling window that only extends once, depends on the same device, identity, and behavioural intelligence that underpins fraud detection generally. An institution that can only investigate an Account Disabling Order manually, case by case, is working against a clock the Act doesn't extend for convenience.

The audit trail requirement, who acted, when, on what basis, is a documentation problem most fraud teams currently solve with spreadsheets and email threads. A connected intelligence platform that logs the signal, the decision, and the action in one place turns that audit trail from a scramble into a byproduct of normal operation.

And the immunity framework only works if institutions can actually act on cross-institutional signals once the legal barrier to sharing them is removed. That's the layer we've spent our work on: not replacing an institution's own fraud stack, but connecting what one institution sees to what its regulators, and increasingly its peers, now have a legal pathway to share. Singapore just built the legal infrastructure for faster, better-protected intelligence sharing. The institutions that benefit most will be the ones that already have the technical infrastructure to use it.

‍

Level Five's Perspective

For years, the real obstacle to cross-institutional fraud intelligence hasn't been technology. It's liability. 

A bank that spots a suspicious pattern touching another institution has had every legal incentive to stay quiet about it, exposing the institution to Banking Act and PDPA liability with no equivalent protection in return. 

Singapore's new immunity clause removes that calculation entirely. Disclosing in good faith, with reasonable care, and the legal exposure that used to make institutions hesitate simply isn't there anymore.

That's a bigger shift than any single order type in the Act. Service Limitation Orders and Account Disabling Orders compel action after a threshold is met. The immunity clause changes behaviour before any order is issued, it's what makes voluntary, proactive sharing a rational choice instead of a legal risk.

Singapore is first here, but it won't stay alone for long. Regional regulators watch each other's legislation closely, and a framework that demonstrably increases voluntary intelligence sharing without a corresponding spike in institutional liability is the kind of result that gets replicated. 

Malaysia, Thailand, and others are already moving on national anti-scam centres and shared reporting infrastructure. Legal cover for cross-institutional disclosure is the next logical piece, and institutions that build the technical capability to act on shared signals now will be ready when their own jurisdiction catches up.

That's where Level Five comes in. Removing the legal barrier to sharing a signal doesn't automatically mean an institution can use the signals it receives. That still depends on having device, identity, and behavioural intelligence connected well enough to recognise a pattern the moment it arrives from outside your own walls, not days later once someone manually cross-references it.

So the question worth asking is whether your institution actually knows what to do with the signal the moment it landed.

‍