Singapore's OCHA Office issued three anti-scam codes of practice on 18 August 2026: one for seven messaging services (WhatsApp, Telegram, WeChat, iMessage, FaceTime, Google Messages, Google Meet), one for Facebook, Instagram and TikTok, and an enhanced one for Carousell, Facebook Marketplace and Facebook Business Pages. All must comply by 31 January 2027.
The headline changes: unknown senders get warning labels and consent gates on messaging apps, and advertisers must pass identity checks against government records before their ads can target Singapore users. Proposed penalties reach S$10 million per breach.
None of this restricts a business that already operates verifiably: official WhatsApp Business Platform line, verified Meta Business portfolio, opted-in lists, conversations the customer starts. This post covers the codes and the practices we run so client channels stay on the right side of them.
Scam victims in Singapore have one thing in common with legitimate businesses: both rely on the same platforms. The Singapore Police Force's answer, announced on Tuesday, is to make those platforms police their own doors.
We build WhatsApp automation and run Meta ad campaigns for clients every day, so these codes land squarely on the channels we operate. Here is what was announced, what it means in practice, and the operating standards we already hold client accounts to, written so you can apply them yourself.
What SPF announced on 18 August
The codes come from the OCHA Office, the unit that administers the Online Criminal Harms Act, and they apply to "designated online services" assessed to carry the highest scam risk for people in Singapore. Three codes were announced: a new one for messaging services, a new one for social media platforms, and an enhanced one for e-commerce services.
The two new codes absorb the relevant parts of the existing Online Communication Services Code, which will be rescinded once they take effect. Every named service has the same deadline to implement its measures: 31 January 2027.
| Code | Who it covers | Headline requirements | Deadline |
|---|---|---|---|
| Messaging | WhatsApp, Telegram, WeChat, Apple iMessage, Apple FaceTime, Google Messages, Google Meet | Consent before group adds by unknown contacts; warning labels on unknown senders; silence and block controls | 31 Jan 2027 |
| Social media | Facebook, Instagram, TikTok | Advertiser identity checks against government records; scam-ad screening and removal; licensing checks on financial ads | 31 Jan 2027 |
| E-commerce (enhanced) | Carousell, Facebook Marketplace, Facebook Business Pages | Stronger consent on logins from new devices; adopts the social media code's ad safeguards | 31 Jan 2027 |
Behind the codes sits a sharper enforcement stick. The Ministry of Home Affairs has tabled amendments that would raise the ceiling from S$1 million to S$10 million per breach, covered below.
The messaging code: seven apps, three new safeguards
SPF's numbers explain the priority: in 2025, WhatsApp and Telegram alone featured in about 23 per cent of all scam cases, and about 18 per cent of government-official impersonation cases happened on WhatsApp. Investment scams are the standing concern, with strangers approaching victims from previously unknown accounts.
The code names seven messaging and conferencing services: WhatsApp, Telegram, WeChat, Apple iMessage, Apple FaceTime, Google Messages and Google Meet. Three requirements stand out:
- Consent before group adds. An unknown contact can no longer drop you into a chat group or channel without your agreement. The classic investment-scam opener, waking up inside a "trading signals" group, stops working.
- Warning labels on unknown senders. Messages and calls from unknown or suspicious accounts will carry contextual risk indicators, which could include the account's creation date and country of origin.
- Silence, filter, block. Users get controls to mute or block messages and calls from any number not in their contact list.
Here is roughly what that first contact from a stranger could look like once the safeguards are live:
Illustrative mock-up of the contextual warnings the code calls for. Actual labels will vary by platform.
Read those three safeguards again from a business owner's seat. Every one of them keys off a single question: does the recipient already know this sender? That question is about to decide how your messages are dressed when they arrive.
The social media code: advertisers get identity checks
Facebook, Instagram and TikTok are assessed as the highest-risk social platforms: about 30 per cent of 2025's scam cases involved them, with Facebook alone at about 18 per cent. SPF's stated concern is advertising, and its position is blunt: platforms profit from ads, so they must ensure ads are not furthering a crime.
Under the code, the three platforms must screen ads before publication and block ones they have reason to suspect, including checking for tricks like URL cloaking that hide an ad's real destination. They must also promptly remove suspected scam ads that slip through, including those reported by users.
The deeper change is at the account level. Platforms must verify advertiser identities against government-issued records before allowing them to publish ads targeting Singapore users. And ads offering financial services or products are blocked unless the advertiser is licensed by the Monetary Authority of Singapore or another applicable authority.
The e-commerce code: logins and listings tighten
The enhanced e-commerce code covers Carousell, Facebook Marketplace and Facebook Business Pages, building on the seller-verification and payment-protection requirements introduced in June 2024. The new addition: stronger consent measures before a login from a new or unrecognised device is allowed, which targets account takeovers.
The code also adopts the social media code's advertising safeguards, so marketplace ads face the same screening and identity checks. If your business sells through Facebook Business Pages, both codes now apply to how you appear.
The penalties behind the codes
A code without teeth is a suggestion, so the enforcement framework is being upgraded in parallel. Today, the OCHA Office can issue a rectification notice, and ignoring one carries a fine of up to S$1 million plus S$100,000 for each day the breach continues after conviction.
The proposed framework in the Scams (Countermeasures) and Other Matters Bill, due for its second reading in Parliament in September, goes much further:
| Situation | Current framework | Proposed framework |
|---|---|---|
| Breaching a code or implementation directive | Rectification notice issued first | Financial penalty of up to S$10 million per instance, or a rectification notice or compliance order |
| Ignoring a rectification notice or compliance order | Fine of up to S$1 million | Fine of up to S$10 million |
| Continuing non-compliance | Up to S$100,000 per day after conviction | Up to S$300,000 per day after conviction |
The practical read: platforms will not treat these codes as optional, and they will not build the safeguards narrowly. When a platform faces S$10 million per lapse, it errs on the side of flagging more, not less. That is exactly why legitimate businesses should care.
Why this is good news for legitimate businesses
The codes bind platforms, not businesses. But every safeguard sorts senders and advertisers into two piles: known and verifiable, or unknown and suspicious. Which pile you land in is determined by how you already operate.
Consider what the messaging safeguards do to common grey habits. Cold outreach from a staff member's personal number now arrives wrapped in warning labels. Broadcasts to a bought list hit contacts who never saved you, exactly the people whose silence filters will eat the message. Adding leads to a WhatsApp group without asking now requires their consent first.
Now consider the businesses on the other side. A verified business account the customer has already messaged carries none of those flags. A click-to-WhatsApp ad has the customer start the conversation, so there is no unknown sender at all. An opted-in broadcast list is, by definition, made of people who asked to hear from you.
The scam filters are a moat for whoever operates verifiably. Every shady competitor and every scammer imitating your industry gets noisier warnings around them, while your messages arrive clean. The rest of this post is the operating standard that puts you on that side.
How we keep client WhatsApp channels on the right side
These are house rules we apply to every client line, and they are all things any business can copy. None of them require an agency; they require deciding to be verifiable.
- Official WhatsApp Business Platform only. Client lines run on the official API through an authorised provider, never grey gateways or a personal number with a business sticker on it. Official rails are what the platforms can vouch for.
- Verified business identity. Meta business verification done properly under the client's registered entity, with an approved display name that matches the brand customers know. That is what separates a verified business from an anonymous number.
- Every template through Meta review. Anything sent outside the 24-hour service window is a Meta-approved template, so the platform has seen and categorised every message format before it ever goes out. Our follow-ups guide covers the mechanics.
- Opt-in first, exit always. Broadcasts go only to contacts with a recorded opt-in, and every marketing send carries a visible way out. The full reasoning lives in our line-quality playbook.
- One official number, published. Each brand messages from one consistent line, listed on its own website, so customers can check who is really writing to them and staff never improvise from personal phones.
Here is why the difference will be visible in the inbox. Compare the unknown-sender mock-up above with the same inbox receiving a verified business the customer already knows:
Illustrative template with a fictional business, sent from a verified account the customer has already messaged.
How we run ad accounts that pass identity checks
Advertiser verification against government records is the social media code's sharpest edge, and it is the one businesses feel first because it decides whether your ads serve at all. Our standards for client ad accounts map directly onto it:
- The client's own verified Business portfolio. Campaigns run from a Meta Business portfolio verified under the client's real legal entity, with the client holding ownership. Never a rented account, never an agency-owned account the client cannot see into.
- Verified domains, honest destinations. The landing page sits on a domain the business owns and has verified, and the page delivers what the ad promises. No cloaked links, no redirect chains, no link shorteners in ad URLs.
- Claims the business can honour. Ad creative states offers the business actually fulfils, with no fake scarcity and no borrowing of other brands' names or likenesses. Scam-ad classifiers are trained on exactly those patterns.
- Licence checks before financial claims. Anything resembling a financial product or investment offer needs the advertiser to hold the relevant licence before the campaign is even drafted. Under the new code the platforms will check; we check first.
If your advertising currently runs from a personal ad account or an account under someone else's name, the deadline to fix that is effectively 31 January 2027. Verification queues get long when everyone applies at once; start early.
What we do inside the team
Scam defence is also an internal discipline, because an agency holds the keys to many businesses' channels at once. These are standing practices inside Zelix, shared here because any team that touches customer messaging can adopt them.
- Two-factor sign-in on every internal surface. Our client portal and team tools require a second factor beyond the password. A password alone opens nothing that touches client data.
- We never ask for OTPs or passwords. Clients hear this at onboarding and it never changes: no one from our team will ever ask for a verification code, a password, or a payment outside agreed channels. Any such request is an impersonation attempt and should be reported to us immediately.
- A reviewed template registry with kill switches. Every WhatsApp template we operate lives in a central registry, categorised and Meta-approved, and every automated send sits behind a switch we can flip off in seconds if anything misbehaves.
- Certification before client lines. Team members pass internal certification, which includes Meta policy and scam-awareness training, before they touch a client workspace. Access is role-based and removed when no longer needed.
- Authenticated email domains. Our transactional email is sent only from domains we own with sender authentication in place, so a spoofed message pretending to be us fails the checks receiving inboxes run.
None of this is exotic. It is the same principle the codes impose on platforms, applied one level down: make impersonating us, or acting in our name, verifiably hard.
Get ready before the deadlines
The platforms have until 31 January 2027 to implement the safeguards, but they will phase them in earlier, and verification queues grow near deadlines. Here is the sorting the new filters will effectively perform, so you can put your business in the left column now.
Reads as legitimate
- Official WhatsApp Business Platform line, verified business behind it
- Approved display name matching the brand customers know
- Broadcasts only to recorded opt-ins, exit on every send
- Conversations the customer starts (ads, website, QR codes)
- Ad account verified under your own legal entity
- Landing pages on your own verified domain
- Team briefed: we never ask customers for codes or passwords
Reads as suspicious
- Messaging new customers from staff personal numbers
- Broadcasts to bought or scraped lists
- Adding leads to groups or channels uninvited
- Ads from rented or borrowed ad accounts
- Cloaked links, redirect chains, shorteners in ad URLs
- Financial-sounding promises without a licence
- Asking customers for OTPs or account details in chat
If most of your operation sits in the left column already, the codes cost you nothing and quietly remove competitors who cut corners. If several right-column habits look familiar, you have runway until January 2027, and the fixes above are all achievable within weeks.
Questions we hear a lot
Do the codes apply to my business, or only to the platforms?
The codes bind the designated platforms. But their safeguards sort every sender and advertiser by verifiability, so how you operate decides how your messages and ads are received. You are not regulated; you are being classified.
Will my WhatsApp broadcasts be flagged?
Broadcasts to opted-in customers from a verified business line they have already messaged are not what the code targets. Unknown accounts approaching strangers cold are. Keep the list clean and the account official, and the filters work in your favour.
Does business verification stop the warning labels?
No platform has published its exact rules yet, so nobody can promise that. But the signals named so far, contact-list status, account age, registration country, all favour an established verified account whose conversations customers start. Verification is the cheapest insurance available.
My ads run from a personal account. Will they stop delivering?
The code requires identity verification against government records before ads can target Singapore users. An account that cannot pass that check is precisely what platforms must stop serving. Move campaigns into a Business portfolio verified under your legal entity well before the deadline.
When does all this take effect?
The codes were announced on 18 August 2026, and every named service must implement its measures by 31 January 2027. The strengthened penalty framework is in a Bill due for its second reading in September.
We are not in Singapore. Does this matter to us?
Not directly, but platforms tend to build safeguards once and reuse them across markets, and regulators elsewhere are moving in the same direction. The practices that pass these codes protect your deliverability everywhere.
Final words
Every code in this announcement asks the platforms one question about each sender and advertiser: can anyone vouch for who this is? Scammers cannot survive that question. A legitimate business can answer it once, through verification, official channels and recorded consent, and then benefit from every filter that question powers.
We hold client channels to that standard because it protects reach as well as reputation: the same habits that satisfy regulators are the ones that keep a WhatsApp number healthy. Get verifiable before January 2027, and the new rules become a moat around your channels.