Voice phishing simulations in Singapore
Singapore is the only country in this portal where social engineering testing is named in an Act of Parliament, and it is named in a licensing provision that binds whoever sells the service rather than the company buying it. A voice phishing simulation against your own staff needs no licence, no union sign-off and no agreement from the people called. What it needs is a standing notice and a deliberate choice of which statutory basis you are relying on.
Phone numbers
Supplied by Callstrike
Local numbers in Singapore, after a one-time approval.
Running a simulation
Permitted, and licensable to sell
Run in-house it needs no licence. Sold into Singapore as a service, it does.
Consent
Dispensed with, and notice survives
One general notice covers it, and the regulator expects none before each test.
Getting a phone number in Singapore
One approval per country, completed in the console.
Provisioned by Callstrike after approval
Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.
Singapore is one of three countries in this portal where the carrier publishes a requirements table for a number type it sells here but not for the one we supply, so this page has no list to reproduce and the clearance form in the console is the authority on what it will ask you for. The panel below says the same thing in the carrier's own terms. Plan for the ordinary business-identity and local-address checks and take the form as the answer.
The fact that actually decides a Singapore campaign is not in any statute and cannot be cured by documentation. The communications regulator has carriers block international incoming calls whose caller identity is falsified with a Singapore prefix to resemble a local call, and tag every remaining international call with a plus prefix to remind the public to be vigilant. So an overseas-originated call spoofing a Singapore number does not arrive at all and the test fails silently rather than illegally, while a legitimate overseas call arrives visibly labelled as foreign, which defeats any pretext that the caller is the local help desk. A realistic Singapore simulation has to originate on a Singapore number you actually hold, and that is the reason to start the approval early.
- 01Complete the regulatory clearance formYour administrator, in the Callstrike console.
- 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
- 03A dedicated number in Singapore is assigned to youCallstrike
- 04Build and launch the campaignYour team
The carrier does not publish a requirements table for the number type we supply here, so what you will be asked for is whatever the clearance form in the console requests at the time. Treat that form as authoritative.
Is it lawful to run a simulation in Singapore?
The position in short, before your counsel reads the detail below.
Yes, and the first decision is which statutory basis you write down. Singapore's structure is agreement-first with statutory exceptions, and the exception you pick changes what you owe afterwards. The right one for a security test is the employment relationship limb, which permits collection where it is reasonable for the purpose of or in relation to entering into, managing or terminating an employment relationship, and the regulator's own list of purposes inside that limb expressly includes monitoring how an employee uses company network resources and conducting checks on conduct or discipline.
A third limb looks attractive and is a trap worth naming. Collection is also permitted where necessary for evaluative purposes, and that limb carries no notification duty where the employment one does. But evaluative purpose is statutorily defined as determining suitability, eligibility or qualifications for employment, for promotion or continuance in employment, or for removal from it. An awareness test is not ordinarily run to decide who keeps their job, and stretching the definition to avoid a notice recharacterises the whole programme as an employment-decision exercise, which is wrong on the facts and considerably worse for you. The remaining limb, legitimate interests, is available but brings its own pre-processing assessment with a fixed minimum content.
Then the mechanic that catches people. Dispensing with agreement looks as though it dispenses with notification, and one subsection says exactly that, but the next opens with the words despite that subsection and reinstates the duty for the employment-relationship purposes. The regulator reconciles it with an unannounced test in a single sentence that a Singapore programme is built on: where an organisation has sufficiently provided a general notification of the purposes for which employees' personal data may be collected, the Commission does not expect it to notify employees of the same purpose prior to each time it engages in such activities. General notice once, through the contract, handbook or intranet. Individual tests unannounced.
Two boundaries are real and both are documentary. The first is the licensing provision: penetration testing service is a licensable cybersecurity service and its statutory definition expressly includes utilising social engineering to assess the level of vulnerability of an organisation, with the offence attaching to providing it to other persons. Running the exercise in-house against your own staff, or for a related company, is outside those words; buying it in means checking your supplier holds the licence. The second is the Penal Code's cheating provision, whose second limb needs no fraud and no dishonesty: only intentional inducement to do something the person would not otherwise have done, where that act or omission is likely to cause damage or harm in body, mind, reputation or property. Written employer authorisation is what keeps an authorised test on the right side of it, and recording is otherwise easy here, because no Singapore statute binds a private party against recording their own call.
What your company needs to do
8 items, in the order you will need them.
- Write down which First Schedule basis you are relying onSingapore-specificPick the employment-relationship limb deliberately and record that you did. It is the one the regulator's own examples describe, and the choice changes what you owe: the evaluative limb recharacterises the programme, and the legitimate interests limb brings an assessment the other two do not.
- If you use the legitimate interests limb, do the assessment firstSingapore-specificIt has a fixed minimum content and it has to be done before collecting: identify any adverse effect the proposed collection is likely to have, and identify and implement reasonable measures to eliminate it, reduce the likelihood of it occurring, or mitigate it. You also have to give people reasonable access to information about the collection. It is the closest thing Singapore has to an impact assessment and it arises only on this limb.
- Issue the standing general notice once, and keep the dateThrough the employment contract, the employee handbook or a notice on the intranet. That single notice is what satisfies the duty that survives the exception, and the regulator expressly does not expect one before each individual test.
- Get written employer authorisation for the exerciseSingapore-specificThe cheating provision's second limb needs neither fraud nor dishonesty, and harm to mind and reputation are inside it by name. An authorised, employer-sanctioned test that extracts no property and is designed to cause no harm is outside it; a test run without proper authorisation, or one designed to humiliate, is what it reaches. This is a documentation point rather than a formality.
- Originate on a Singapore number you holdSingapore-specificAn overseas-originated call presenting a falsified Singapore identity is identified and blocked at the network, and remaining international calls arrive tagged with a plus prefix. Neither outcome is a legal problem and neither can be fixed with paperwork, which is exactly why it belongs on a planning list rather than a legal one.
- Do not go looking for a consultation stepThere is none that a simulation engages, and that is a finding rather than a gap. The employment statute contains no works council provision at all, and its only two consultation duties concern the scheduling of annual leave and a transfer of business. No consultation, no notice period, no union sign-off.
- If you buy the exercise in, check the licenceSingapore-specificProviding a licensable cybersecurity service to other persons without a licence carries a fine of up to fifty thousand dollars or two years or both, and a separate provision denies an unlicensed provider any court proceeding to recover its fees. That is a question about your supplier rather than about you, and it is a short one to ask.
- Cite the right financial-sector instrumentThe technology risk guidelines describe scenario-based cyber exercises that could include social engineering, and ask for objectives, scope and rules of engagement fixed before an adversarial simulation begins. The binding cyber hygiene notice says nothing about phishing, social engineering, training or awareness at all. The regulatory weight and the subject-matter coverage run in opposite directions here.
The controls that do the work
How Callstrike is configured, and which provision in Singapore each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
Be clear about what this does and does not reach in Singapore, because the honest answer is narrower here than in Japan or Korea. There is no Singapore offence about acquiring data by deception for it to dispose of. What it answers is the standard that runs through the whole statute, which is that an organisation may collect only for purposes a reasonable person would consider appropriate in the circumstances, and the cheating provision's harm limb, which asks whether the inducement was likely to cause damage or harm. A call that ends before a credential is spoken collects the least the purpose can be served by and puts nothing at risk that a harm argument could attach to.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
The Penal Code limb that matters here reaches harm to mind and to reputation and requires no dishonesty, so how the exercise ends is a legal question in Singapore rather than a courtesy. A second voice that breaks character the moment the call ends, with vishing training in writing the same day, is the hardest possible fact pattern for an argument that the inducement was likely to cause harm, because the person learns what happened before they have had time to carry it anywhere.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
Agreement is dispensed with here and notification is not, so the deliverable is unusually precise: evidence of when the standing general notice was given and to whom, rather than anything gathered around individual calls. That is the shape the regulator's own reconciliation asks for, since it accepts a general notification and expressly does not expect one before each instance. Uploading the contract clause, handbook page or intranet notice with a signed and timestamped attestation of the scope it covers is what makes the general notice provable a year later.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
Singapore's obstacle is the network rather than the law, and this is the delivery that has no inbound leg to be blocked and no plus prefix to give it away. Callstrike's vishing simulator carries the same deepfake voice into a web call the learner opens themselves after working through the module, so the do-not-call regime and the calling line identification rule, both of which are scoped to commercial specified messages anyway, have nothing to reach. The licensing provision is about who provides the service rather than how it is delivered, so it is unaffected either way, and the same First Schedule basis and standing notice carry whatever the module collects.
Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.