Callstrike
Compliance

Voice phishing simulations in Singapore

Phone numbers in SingaporeProvisioned by Callstrike after approval

Singapore is the only country in this portal where social engineering testing is named in an Act of Parliament, and it is named in a licensing provision that binds whoever sells the service rather than the company buying it. A voice phishing simulation against your own staff needs no licence, no union sign-off and no agreement from the people called. What it needs is a standing notice and a deliberate choice of which statutory basis you are relying on.

Phone numbers

Supplied by Callstrike

Local numbers in Singapore, after a one-time approval.

Running a simulation

Permitted, and licensable to sell

Run in-house it needs no licence. Sold into Singapore as a service, it does.

Consent

Dispensed with, and notice survives

One general notice covers it, and the regulator expects none before each test.

Getting a phone number in Singapore

One approval per country, completed in the console.

Provisioned by Callstrike after approval

Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

Singapore is one of three countries in this portal where the carrier publishes a requirements table for a number type it sells here but not for the one we supply, so this page has no list to reproduce and the clearance form in the console is the authority on what it will ask you for. The panel below says the same thing in the carrier's own terms. Plan for the ordinary business-identity and local-address checks and take the form as the answer.

The fact that actually decides a Singapore campaign is not in any statute and cannot be cured by documentation. The communications regulator has carriers block international incoming calls whose caller identity is falsified with a Singapore prefix to resemble a local call, and tag every remaining international call with a plus prefix to remind the public to be vigilant. So an overseas-originated call spoofing a Singapore number does not arrive at all and the test fails silently rather than illegally, while a legitimate overseas call arrives visibly labelled as foreign, which defeats any pretext that the caller is the local help desk. A realistic Singapore simulation has to originate on a Singapore number you actually hold, and that is the reason to start the approval early.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in Singapore is assigned to youCallstrike
  4. 04Build and launch the campaignYour team

The carrier does not publish a requirements table for the number type we supply here, so what you will be asked for is whatever the clearance form in the console requests at the time. Treat that form as authoritative.

Is it lawful to run a simulation in Singapore?

The position in short, before your counsel reads the detail below.

Yes, and the first decision is which statutory basis you write down. Singapore's structure is agreement-first with statutory exceptions, and the exception you pick changes what you owe afterwards. The right one for a security test is the employment relationship limb, which permits collection where it is reasonable for the purpose of or in relation to entering into, managing or terminating an employment relationship, and the regulator's own list of purposes inside that limb expressly includes monitoring how an employee uses company network resources and conducting checks on conduct or discipline.

A third limb looks attractive and is a trap worth naming. Collection is also permitted where necessary for evaluative purposes, and that limb carries no notification duty where the employment one does. But evaluative purpose is statutorily defined as determining suitability, eligibility or qualifications for employment, for promotion or continuance in employment, or for removal from it. An awareness test is not ordinarily run to decide who keeps their job, and stretching the definition to avoid a notice recharacterises the whole programme as an employment-decision exercise, which is wrong on the facts and considerably worse for you. The remaining limb, legitimate interests, is available but brings its own pre-processing assessment with a fixed minimum content.

Then the mechanic that catches people. Dispensing with agreement looks as though it dispenses with notification, and one subsection says exactly that, but the next opens with the words despite that subsection and reinstates the duty for the employment-relationship purposes. The regulator reconciles it with an unannounced test in a single sentence that a Singapore programme is built on: where an organisation has sufficiently provided a general notification of the purposes for which employees' personal data may be collected, the Commission does not expect it to notify employees of the same purpose prior to each time it engages in such activities. General notice once, through the contract, handbook or intranet. Individual tests unannounced.

Two boundaries are real and both are documentary. The first is the licensing provision: penetration testing service is a licensable cybersecurity service and its statutory definition expressly includes utilising social engineering to assess the level of vulnerability of an organisation, with the offence attaching to providing it to other persons. Running the exercise in-house against your own staff, or for a related company, is outside those words; buying it in means checking your supplier holds the licence. The second is the Penal Code's cheating provision, whose second limb needs no fraud and no dishonesty: only intentional inducement to do something the person would not otherwise have done, where that act or omission is likely to cause damage or harm in body, mind, reputation or property. Written employer authorisation is what keeps an authorised test on the right side of it, and recording is otherwise easy here, because no Singapore statute binds a private party against recording their own call.

What your company needs to do

8 items, in the order you will need them.

  • Write down which First Schedule basis you are relying onSingapore-specificPick the employment-relationship limb deliberately and record that you did. It is the one the regulator's own examples describe, and the choice changes what you owe: the evaluative limb recharacterises the programme, and the legitimate interests limb brings an assessment the other two do not.
  • If you use the legitimate interests limb, do the assessment firstSingapore-specificIt has a fixed minimum content and it has to be done before collecting: identify any adverse effect the proposed collection is likely to have, and identify and implement reasonable measures to eliminate it, reduce the likelihood of it occurring, or mitigate it. You also have to give people reasonable access to information about the collection. It is the closest thing Singapore has to an impact assessment and it arises only on this limb.
  • Issue the standing general notice once, and keep the dateThrough the employment contract, the employee handbook or a notice on the intranet. That single notice is what satisfies the duty that survives the exception, and the regulator expressly does not expect one before each individual test.
  • Get written employer authorisation for the exerciseSingapore-specificThe cheating provision's second limb needs neither fraud nor dishonesty, and harm to mind and reputation are inside it by name. An authorised, employer-sanctioned test that extracts no property and is designed to cause no harm is outside it; a test run without proper authorisation, or one designed to humiliate, is what it reaches. This is a documentation point rather than a formality.
  • Originate on a Singapore number you holdSingapore-specificAn overseas-originated call presenting a falsified Singapore identity is identified and blocked at the network, and remaining international calls arrive tagged with a plus prefix. Neither outcome is a legal problem and neither can be fixed with paperwork, which is exactly why it belongs on a planning list rather than a legal one.
  • Do not go looking for a consultation stepThere is none that a simulation engages, and that is a finding rather than a gap. The employment statute contains no works council provision at all, and its only two consultation duties concern the scheduling of annual leave and a transfer of business. No consultation, no notice period, no union sign-off.
  • If you buy the exercise in, check the licenceSingapore-specificProviding a licensable cybersecurity service to other persons without a licence carries a fine of up to fifty thousand dollars or two years or both, and a separate provision denies an unlicensed provider any court proceeding to recover its fees. That is a question about your supplier rather than about you, and it is a short one to ask.
  • Cite the right financial-sector instrumentThe technology risk guidelines describe scenario-based cyber exercises that could include social engineering, and ask for objectives, scope and rules of engagement fixed before an adversarial simulation begins. The binding cyber hygiene notice says nothing about phishing, social engineering, training or awareness at all. The regulatory weight and the subject-matter coverage run in opposite directions here.

The controls that do the work

How Callstrike is configured, and which provision in Singapore each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

Be clear about what this does and does not reach in Singapore, because the honest answer is narrower here than in Japan or Korea. There is no Singapore offence about acquiring data by deception for it to dispose of. What it answers is the standard that runs through the whole statute, which is that an organisation may collect only for purposes a reasonable person would consider appropriate in the circumstances, and the cheating provision's harm limb, which asks whether the inducement was likely to cause damage or harm. A call that ends before a credential is spoken collects the least the purpose can be served by and puts nothing at risk that a harm argument could attach to.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

The Penal Code limb that matters here reaches harm to mind and to reputation and requires no dishonesty, so how the exercise ends is a legal question in Singapore rather than a courtesy. A second voice that breaks character the moment the call ends, with vishing training in writing the same day, is the hardest possible fact pattern for an argument that the inducement was likely to cause harm, because the person learns what happened before they have had time to carry it anywhere.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

Agreement is dispensed with here and notification is not, so the deliverable is unusually precise: evidence of when the standing general notice was given and to whom, rather than anything gathered around individual calls. That is the shape the regulator's own reconciliation asks for, since it accepts a general notification and expressly does not expect one before each instance. Uploading the contract clause, handbook page or intranet notice with a signed and timestamped attestation of the scope it covers is what makes the general notice provable a year later.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

Singapore's obstacle is the network rather than the law, and this is the delivery that has no inbound leg to be blocked and no plus prefix to give it away. Callstrike's vishing simulator carries the same deepfake voice into a web call the learner opens themselves after working through the module, so the do-not-call regime and the calling line identification rule, both of which are scoped to commercial specified messages anyway, have nothing to reach. The licensing provision is about who provides the service rather than how it is delivered, so it is unaffected either way, and the same First Schedule basis and standing notice carry whatever the module collects.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

Consent is not needed and notification survives anyway

Singapore's structure is consent-first with statutory exceptions, and the exception you pick changes what you owe afterwards.

An organisation must not collect, use or disclose personal data unless the individual gives or is deemed to give consent, or the collection is required or authorised under the Act or any other written law. The Act then permits collection without consent in the circumstances listed in the First Schedule, and two of those circumstances are candidates here.

The first is legitimate interests, and it is not the bare balancing test the same phrase denotes in Europe. It applies where the collection is in the legitimate interests of the organisation or another person and those interests outweigh any adverse effect on the individual, and it then imposes a procedure: the organisation must conduct an assessment before collecting to determine whether that is satisfied, must provide the individual with reasonable access to information about the collection, and in that assessment must identify any adverse effect the proposed collection is likely to have, and identify and implement reasonable measures to eliminate it, to reduce the likelihood of its occurring, or to mitigate it. A documented pre-processing assessment with a fixed minimum content. It is the closest thing Singapore has to an impact assessment, and it arises only if you rely on this limb.

The second is the employment relationship: collection is permitted where it is reasonable for the purpose of or in relation to entering into, managing or terminating an employment relationship. That is the correct basis for a security test, and choosing it deliberately matters.

It matters because a third limb looks attractive and is a trap. Collection is also permitted where necessary for evaluative purposes, and the regulator confirms that this limb carries no notification duty where the employment limb does. But evaluative purpose is statutorily defined as determining the suitability, eligibility or qualifications of an individual for employment, for promotion or continuance in employment, or for removal from it. An awareness test is not ordinarily run to decide who keeps their job, and stretching the definition to avoid a notice would recharacterise the whole programme as an employment-decision exercise. That is wrong on the facts and considerably worse for the employer.

Now the mechanic that catches people. Dispensing with consent under the First Schedule looks as though it dispenses with notification, and one subsection says exactly that. The next subsection opens with the words despite that subsection and reinstates the duty for the employment-relationship purposes: the organisation must still inform the individual of the purpose, and on request of the business contact information of someone who can answer questions about it.

The regulator then reconciles that with an unannounced test, and this is the sentence a Singapore programme is built on. The Act does not prescribe the manner of notification, and organisations may inform employees of these purposes through employment contracts, employee handbooks or notices on the company intranet. And where an organisation has sufficiently provided a general notification of the purposes for which employees' personal data may be collected, the Commission does not expect it to notify employees of the same purpose prior to each time it engages in such activities.

General notice, once. Individual tests unannounced. Both halves are required, and citing either one alone produces the wrong answer. The regulator's own list of purposes falling within managing the employment relationship expressly includes monitoring how an employee uses company computer network resources and conducting checks on conduct or discipline, so the activity is squarely inside the limb it names.

One standard runs through all of it: in meeting its responsibilities an organisation must consider what a reasonable person would consider appropriate in the circumstances, and may collect only for purposes that a reasonable person would consider appropriate and of which the individual has been informed.

No statute stops a participant recording, and none is hiding

Singapore has no wiretapping statute binding private parties, and we established that by reading the candidates rather than by not finding one.

The telecommunications statute contains two occurrences of the word intercept and neither reaches a caller. The first is an offence committed by a person who, intending to prevent or obstruct transmission, to intercept or acquaint themselves with the contents of a message, or to commit mischief, damages, removes, tampers with or touches any installation or plant used for telecommunications belonging to a public licensee. Recording your own call touches no plant. The second binds officers, employees and agents of a public telecommunication licensee who, except under a ministerial order or a court's direction, wilfully intercept or acquaint themselves with a message. That is a rule for telco insiders.

The Penal Code contains no occurrence of the word intercept at all, and there is no recording offence in it.

So the criminal exposure for a participant recording its own call in Singapore is, so far as we could establish, none. What remains is entirely a data protection question, and it is not a small one: the voice recording is personal data, so the same First Schedule basis and the same notification duty carry it, the protection obligation governs how it is secured, and the retention obligation governs how long it is kept. Breach is a civil and regulatory matter enforced by the Commission through directions and financial penalties, not a crime.

The practical consequence is that Singapore is one of the easier jurisdictions in this portal in which to record, and the discipline it requires is documentary rather than architectural: the recording must fall within a stated basis, be covered by the standing notice, be secured, and not outlive its purpose.

Nine purposes, all commercial, and two belts on the braces

The do-not-call regime does not reach an internal security test, and the reason is definitional rather than argumentative.

The regime bites only on a specified message, which is a message where it would be concluded that a purpose is an applicable purpose, and applicable purpose means a purpose specified in the Tenth Schedule. That schedule lists nine, and every one is commercial: offering to supply goods or services; advertising or promoting goods or services; advertising or promoting a supplier of them; the same three again for land or an interest in land; and the same three for a business or investment opportunity.

A simulated security test offers nothing and promotes nothing, so it is not a specified message, and the whole of that Part falls away with it: the duty to check the register, the contact-information rule and the calling line identification rule all attach only to specified messages.

Two further exclusions would carry it even if the characterisation were wrong. A message sent while the sender is in an ongoing relationship with the recipient, whose sole purpose relates to the subject matter of that relationship, is excluded, and the Act defines an ongoing relationship as one arising from the carrying on of a business or an activity, commercial or otherwise, by the sender. An employer calling its own staff is inside that. And a message sent to an organisation rather than to an individual acting in a personal or domestic capacity is separately excluded.

One newer statute is worth ruling out explicitly because its name invites the question. The online criminal harms legislation does not apply, for two reasons. Its operative unit is online activity, defined as activity conducted by means of the internet, and an ordinary telephone call is not that. And structurally it is a directions and takedown regime: it empowers an officer to direct persons and service providers, and criminalises non-compliance with those directions. It creates no impersonation offence and no conduct rule addressed to a caller, and the word impersonation does not appear in it at all.

The real criminal boundary is in the Penal Code and it is worth reading carefully because one limb is broader than people assume. Cheating by personation is committed by a person who cheats by pretending to be some other person. Cheating itself has two limbs: the first requires fraudulent or dishonest inducement to deliver property, and the second requires only that the deceiver intentionally induces the person deceived to do or omit something they would not otherwise have done, where that act or omission causes or is likely to cause damage or harm to any person in body, mind, reputation or property.

No fraud and no dishonesty is needed for that second limb, and harm to mind and reputation are expressly within it. An authorised, employer-sanctioned test that extracts no property and is designed to cause no harm sits outside it. A test run without proper authorisation, or one designed to humiliate, is exactly what it would reach. Written employer authorisation is what keeps the conduct on the right side, and that is a documentation point rather than a formality.

On synthetic voice, Singapore has no binding disclosure duty. Its AI instruments say so in their own words: the transparency guidelines for generative chatbots are described by the regulator as new voluntary guidelines, and the model governance framework provides guidance and recommends measures. Neither has a statutory footing, a penalty, or a regulator empowered to enforce it.

The law bans concealing, and the network blocks falsifying

Singapore's statutory caller identity rule is narrower than people expect, and its operational reality is stricter. Both facts matter and they point in opposite directions.

The statutory rule prohibits a person who makes a voice call containing a specified message to a Singapore telephone number from concealing or withholding the calling line identity of the sender, or from performing any operation that has that effect. Read it precisely: it prohibits concealing, not falsifying, and only for a specified message, which as the previous section explains an internal test is not. Singapore has no general statutory prohibition on a caller presenting a number it does not hold.

The operational position is the opposite way round, and it is decisive. The regulator describes a set of network measures including upfront blocking of international calls exhibiting unusually high frequency, and states that all international incoming calls where the caller identity is falsified with a plus six five prefix to resemble a call made from Singapore were also identified and blocked. It adds that all remaining calls from international numbers are tagged with a plus prefix to remind the public to be vigilant.

Two consequences follow for anyone designing a test against Singapore staff, and neither is a legal one. An overseas-originated call spoofing a Singapore number will not arrive: the test fails silently rather than illegally. And a legitimate overseas call does arrive, but pre-labelled with a plus prefix, which visually defeats any pretext that the caller is the local helpdesk.

That is an engineering constraint enforced by the carriers rather than a prohibition on the caller, and the distinction matters because it cannot be cured by consent, by authorisation or by documentation. A realistic Singapore simulation has to originate on a Singapore number the tester actually holds.

What the country matrix holds for Singapore

Number types:
Local
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

No consultation duty exists, and that is a finding

Singapore has no statutory works council, no employee consultation requirement and no union sign-off engageable by a security test, and that clean negative is worth establishing on the face of the statute rather than by silence.

We counted the employment statute through. The phrase works council returns nothing. Collective agreement returns eleven and trade union twenty-nine, all in the machinery of industrial relations rather than in any duty to consult about workplace practices. The word consult returns twice, and we read both. One concerns the times at which annual leave is granted, determined by the employer after consultation with the employee or their representatives. The other concerns a transfer of business, requiring the transferor to notify affected employees and any union to enable consultations before the transfer takes place.

So the only statutory consultation duties in Singapore employment law attach to leave scheduling and to a transfer of undertaking. Neither is engaged by a simulation. There is no consultation, no notice period and no union sign-off.

The tripartite guidelines that Singapore issues in some employment areas are not legislation, and we did not locate one addressing employee monitoring or security testing. Nothing is asserted about one here.

What Singapore does require is documentary, and it comes from the sections above rather than from a consultation regime. A standing general notice of the purposes for which employee personal data may be collected, delivered through the contract, the handbook or the intranet, which is what satisfies the notification duty that survives the consent exception. A record of which First Schedule basis is being relied on, because picking the employment limb rather than the evaluative one is a deliberate choice with different consequences. The pre-processing assessment with its prescribed content, if and only if the legitimate interests limb is used. Written employer authorisation for the exercise, which is what keeps the pretext outside the cheating provisions. And, if the programme is bought in rather than run in-house, the supplier's cybersecurity service provider licence, for the reason set out in the next section.

A licensable service, and a binding notice that says nothing

Singapore names this activity in an Act of Parliament, and it names it in a licensing provision. That is the most consequential fact on this page for anyone selling the service.

The cybersecurity statute lists two licensable cybersecurity services: managed security operations centre monitoring, and penetration testing service. It then defines penetration testing service as a service for assessing, testing or evaluating the level of cybersecurity of a computer or computer system by searching for vulnerabilities in, and compromising, its cybersecurity defences, and provides that it includes determining or testing the organisation's ability to identify and respond to cybersecurity incidents through simulation of attempts to penetrate those defences, and utilising social engineering to assess the level of vulnerability of an organisation to cybersecurity threats.

Utilising social engineering to assess the level of vulnerability of an organisation. That is this product, written into a schedule to a statute.

The consequence is a licence. Except in accordance with a cybersecurity service provider's licence, no person may engage in the business of providing any licensable cybersecurity service to other persons, or advertise or hold out that they provide it. Contravention carries a fine not exceeding fifty thousand dollars or imprisonment not exceeding two years or both. And a separate provision denies an unlicensed provider any proceeding in court to recover commission, fees or reward for the service provided.

Read the words to other persons, because they are where the line falls. An employer running the exercise in-house against its own staff is not providing a service to other persons and needs no licence, and the Act separately exempts the provision of a cybersecurity service by a company to its related company. A vendor selling vishing simulation into Singapore does need one, and cannot even sue for its fees without it.

The financial-sector position then inverts the usual expectation about regulatory weight. The technology risk management guidelines say that a financial institution should carry out regular scenario-based cyber exercises to validate its response, recovery and communication plans, and that these exercises could include social engineering, table-top or cyber range exercises, with a footnote defining social engineering as a process in which criminals manipulate an unsuspecting person into divulging sensitive details such as passwords through techniques including phishing. They add that for an adversarial attack simulation exercise the objectives, scope and rules of engagement should be defined before the commencement of the exercise, which should be conducted in a controlled manner under close supervision, and a footnote describes such an exercise as targeting the people, processes and technology underpinning critical functions.

Rules of engagement fixed in advance, in the regulator's own words, and an express blessing for testing people rather than only systems. But those guidelines are not binding in the way the notice on cyber hygiene is. That notice is issued under the banking statute and applies to all banks in Singapore, and we counted its five pages through: phishing, voice phishing, social engineering, simulation, penetration test, training and awareness each return zero. It is purely technical, covering administrative accounts, patching, security standards, network perimeter defence, malware protection and multi-factor authentication.

So an institution citing the regulator for a phishing simulation requirement is citing the guidelines, not the notice. The regulatory weight and the subject-matter coverage run in opposite directions, and conflating the two instruments is the commonest error in this area.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in SINGAPORE. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. A general notice of employment-related collection purposes sits in the handbook.

Verify or correct each proposition below against primary Singapore sources, and tell me which basis to record:

1. ⚠⚠ Cybersecurity Act 2018 Second Schedule para 2(d) defines «penetration testing service» to include «utilising social engineering to assess the level of vulnerability of an organisation», and s 24 bites on providing a licensable service «to other persons» (with s 24(3) exempting a related company). Confirm an in-house programme needs no licence and that a VENDOR selling into Singapore does.
2. ⚠ PDPA s 20(3) removes notification when a First Schedule exception is relied on, but s 20(4) opens «Despite subsection (3)» and REINSTATES it for employment-relationship purposes. Both halves are needed.
3. PDPC Selected Topics 6.20: a GENERAL notification suffices and «the Commission does not expect organisations to notify employees of the same purpose prior to each time». Confirm this is current.
4. ⚠ First Schedule Part 2 para 10 (employment relationship) is the right basis, NOT para 2 (evaluative purposes), because «evaluative purpose» is statutorily about suitability or CONTINUANCE IN EMPLOYMENT. Advise on the risk of stretching para 2 to avoid the notice.
5. If we rely on legitimate interests instead, what exactly must the pre-collection assessment contain, and must it be disclosed?
6. ⚠ Penal Code s 415's SECOND limb requires no fraud or dishonesty: only intentional inducement plus an act or omission likely to cause damage or harm to body, MIND, reputation or property. Confirm that written employer authorisation is what keeps an authorised test outside ss 415 and 416.
7. Employment Act 1968 contains no works council provision, and its only consultation duties are ss 18A(5) (annual leave) and 41AB(3) (transfer of business). Confirm no consultation duty is engaged.
8. MAS Notice 655 is binding under Banking Act s 55(1) and says nothing about phishing, social engineering, training or awareness; the TRM Guidelines are not binding in the same sense and do name social engineering. Confirm both.

Flag anything that has changed since September 2026, and tell me whether any Tripartite guideline now addresses employee monitoring: we located none.

Common questions

Do we need a licence to run vishing simulations in Singapore?
If you sell the service to another organisation, yes. Penetration testing service is a licensable cybersecurity service and its statutory definition expressly includes utilising social engineering. Running it in-house against your own staff, or for a related company, needs no licence.
Must we tell employees before each test?
No, but you must have told them once. Dispensing with consent does not dispense with notification for employment purposes, and the regulator accepts a general notice through the contract, handbook or intranet, expressly not expecting notice before each individual instance.
Is there a consultation duty in Singapore?
None that a security test engages, and that is a finding rather than a gap. The employment statute contains no works council provision at all, and its only two consultation duties concern the scheduling of annual leave and a transfer of business. No consultation, no notice period and no union sign-off.
Why do our overseas-originated calls fail to arrive?
Because international incoming calls with a falsified Singapore caller identity are identified and blocked at the network, and remaining international calls are tagged with a plus prefix. The test fails silently rather than illegally, and no amount of documentation cures it. Originate locally.

Elsewhere in Asia Pacific

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.