September 20, 2024

Search
Close this search box.

We are creating some awesome events for you. Kindly bear with us.

Singapore: Shared Responsibility Framework to Combat Phishing Scams

Getting your Trinity Audio player ready...

The Monetary Authority of Singapore (MAS) and Infocomm Media Development Authority (IMDA) have jointly released a consultation paper outlining a groundbreaking Shared Responsibility Framework (SRF) aimed at tackling phishing scams.

This innovative framework assigns specific responsibilities to financial institutions (FIs) and telecommunications companies (Telcos) to prevent phishing scams and introduces payouts to victims when these duties are breached.

Adapted from MAS Infographic on Proposed Shared Responsibility Framework

Building on previous efforts, this comprehensive SRF encompasses both FIs and Telcos, recognising their pivotal roles in safeguarding financial transactions against the rising threat of digitally enabled scams. These scams, characterised by unauthorised transactions initiated without the victim’s consent or knowledge, pose a significant risk to digital banking and payment systems.

The SRF focuses on a specific category of phishing scams where individuals unknowingly reveal their account credentials to scammers posing as legitimate entities, resulting in unauthorised transactions. It aims to bolster the direct accountability of FIs and Telcos to consumers by defining clear duties for each party, such as FIs ensuring the transmission of transaction notifications and Telcos implementing scam filters. Breaches of these duties will determine responsibility for losses under the framework, encouraging strict adherence to anti-scam controls.

Responsibility for losses follows a “waterfall approach” with FIs bearing the primary responsibility, given their role as custodians of consumers’ funds. Telcos assume secondary responsibility due to their involvement in facilitating SMS delivery. However, if both parties fulfil their duties, no payouts to consumers will be required, emphasising the importance of consumer vigilance.

The SRF does not cover malware-enabled scams at this stage, considering the evolving nature of these threats. The government remains committed to combating malware scams through industry collaboration, safeguard measures, and public education.

The joint consultation paper seeks feedback on various aspects of the SRF, including its scope, duties, and payout approach. MAS and IMDA will consider these comments when finalising the framework. Ms Ho Hern Shin, Deputy Managing Director (Financial Supervision) at MAS, highlighted that the SRF encourages vigilance among all stakeholders in the payment ecosystem and complements proposed amendments to the E-payments User Protection Guidelines (EUPG).

Aileen Chia, Deputy Chief Executive (Connectivity, Development & Regulation) at IMDA, emphasised the success of measures like the mandatory SMS Sender ID Registry in reducing scam SMS cases and underscored the Telcos’ role in strengthening the ecosystem against scams.

Interested parties are invited to submit their comments on the proposed framework by 20 December 2023. For detailed information, please refer to the consultation paper [link]. The Singapore government continues its commitment to combat phishing scams and safeguard the integrity of digital financial transactions.

Summary of multi-layered approach to address scam calls and scam SMS

Image adapted from Consultation Paper on Proposed Shared Responsibility Framework

OpenGov Asia reported that the National University of Singapore (NUS) and the Cyber Security Agency of Singapore (CSA) had joined forces to create the NUS-CSA CyberSG Talent, Innovation and Growth (TIG) Collaboration Centre that aims to position Singapore as a leading global hub for cybersecurity innovation to uplift the nation’s cybersecurity sector.

In 2018, the Monetary Authority of Singapore (MAS) introduced the E-payments User Protection Guidelines, a pivotal step in bolstering trust in electronic payments. These guidelines outlined the responsibilities and liabilities of financial institutions and consumers in the face of unauthorised or erroneous payment transactions, instilling confidence in electronic payment methods.

Fast forward to February 2022, MAS revealed its ongoing commitment to enhancing payment security through a review of the Shared Responsibility Framework (SRF) Guidelines. The Payments Council, led by MD MAS, initiated this review in July 2021, as part of a broader effort to reinforce safety measures in digital banking.

The SRF Guidelines are poised to address the responsibilities of financial institutions, including banks, credit card issuers, and major payment service providers offering account issuance services, as well as those of consumers when faced with unauthorised or incorrect payment transactions. This comprehensive review signifies Singapore’s dedication to maintaining and improving the security of digital payment systems.

Additional Documents

Draft Guidelines on Shared Responsibility Framework

Infographic on Proposed Shared Responsibility Framework

PARTNER

Qlik’s vision is a data-literate world, where everyone can use data and analytics to improve decision-making and solve their most challenging problems. A private company, Qlik offers real-time data integration and analytics solutions, powered by Qlik Cloud, to close the gaps between data, insights and action. By transforming data into Active Intelligence, businesses can drive better decisions, improve revenue and profitability, and optimize customer relationships. Qlik serves more than 38,000 active customers in over 100 countries.

PARTNER

As a Titanium Black Partner of Dell Technologies, CTC Global Singapore boasts unparalleled access to resources.

Established in 1972, we bring 52 years of experience to the table, solidifying our position as a leading IT solutions provider in Singapore. With over 300 qualified IT professionals, we are dedicated to delivering integrated solutions that empower your organization in key areas such as Automation & AI, Cyber Security, App Modernization & Data Analytics, Enterprise Cloud Infrastructure, Workplace Modernization and Professional Services.

Renowned for our consulting expertise and delivering expert IT solutions, CTC Global Singapore has become the preferred IT outsourcing partner for businesses across Singapore.

PARTNER

Planview has one mission: to build the future of connected work. Our solutions enable organizations to connect the business from ideas to impact, empowering companies to accelerate the achievement of what matters most. Planview’s full spectrum of Portfolio Management and Work Management solutions creates an organizational focus on the strategic outcomes that matter and empowers teams to deliver their best work, no matter how they work. The comprehensive Planview platform and enterprise success model enables customers to deliver innovative, competitive products, services, and customer experiences. Headquartered in Austin, Texas, with locations around the world, Planview has more than 1,300 employees supporting 4,500 customers and 2.6 million users worldwide. For more information, visit www.planview.com.

SUPPORTING ORGANISATION

SIRIM is a premier industrial research and technology organisation in Malaysia, wholly-owned by the Minister​ of Finance Incorporated. With over forty years of experience and expertise, SIRIM is mandated as the machinery for research and technology development, and the national champion of quality. SIRIM has always played a major role in the development of the country’s private sector. By tapping into our expertise and knowledge base, we focus on developing new technologies and improvements in the manufacturing, technology and services sectors. We nurture Small Medium Enterprises (SME) growth with solutions for technology penetration and upgrading, making it an ideal technology partner for SMEs.

PARTNER

HashiCorp provides infrastructure automation software for multi-cloud environments, enabling enterprises to unlock a common cloud operating model to provision, secure, connect, and run any application on any infrastructure. HashiCorp tools allow organizations to deliver applications faster by helping enterprises transition from manual processes and ITIL practices to self-service automation and DevOps practices. 

PARTNER

IBM is a leading global hybrid cloud and AI, and consulting services provider, helping clients in more than 175 countries capitalize on insights from their data, streamline business processes, reduce costs and gain the competitive edge in their industries. Nearly 3,800 government and corporate entities in critical infrastructure areas such as financial services, telecommunications and healthcare rely on IBM’s hybrid cloud platform and Red Hat OpenShift to affect their digital transformations quickly, efficiently, and securely. IBM’s breakthrough innovations in AI, quantum computing, industry-specific cloud solutions and business services deliver open and flexible options to our clients. All of this is backed by IBM’s legendary commitment to trust, transparency, responsibility, inclusivity, and service. For more information, visit www.ibm.com