Singapore has no direct equivalent of the United Kingdom’s public interest disclosure regime or the United States’ Sarbanes Oxley and Dodd Frank whistleblower provisions. There is no single statute that gives a Singapore employee immunity from retaliation simply because they reported wrongdoing at work.
That gap surprises many directors, especially after the Corporate and Accounting Laws (Amendment) Act 2025 (CALA 2025) sharply raised penalties for director misconduct, and the Corporate Service Providers Act 2024 (CSP Act) put new obligations on the company secretaries who serve private companies. Fraud is usually uncovered because someone inside the company spoke up, so the absence of a legal mandate does not mean a whistleblowing policy is optional in practice.
This article sets out what Singapore law does and does not require on whistleblowing, where the real protections sit, and how a private company should design a policy that is compliant with the Personal Data Protection Act 2012 (PDPA) when handling a whistleblower’s personal data.
Does Singapore Have a Whistleblower Protection Law for Private Companies?
The honest answer is no, not in the form most business owners expect. Singapore has no general whistleblower protection statute giving every employee a standalone legal right to report wrongdoing free from retaliation. What exists instead is a patchwork: a governance recommendation for listed companies, a regulatory requirement for a defined set of financial institutions, a narrow protection for corruption informants, and an indirect route through wrongful dismissal law that only helps after the fact.
For a private limited company that is not listed on the Singapore Exchange and not regulated by the Monetary Authority of Singapore (MAS), there is no law that compels the board to adopt a whistleblowing policy. That is the premise worth correcting first: a whistleblowing policy is best practice, but it is not yet a statutory duty for every Singapore Pte Ltd.
Where Whistleblowing Rules Do Apply Under Singapore Law
Several pockets of Singapore law do impose whistleblowing related obligations, but each one is narrower than most owners assume.
Listed Companies: The Code of Corporate Governance 2018
Provision 10.1 of the Code of Corporate Governance 2018 recommends that the Audit Committee of a listed company put in place a whistleblowing policy, that the policy and its channels be communicated to staff, and that whistleblowers be offered confidentiality and protection from reprisal. The Code operates on a “comply or explain” basis through the Singapore Exchange listing rules, so it is a governance recommendation rather than hard law, and it only binds companies listed on SGX. A private company that has never listed shares sits outside its scope.
MAS Regulated Financial Institutions
The picture changes for a defined group of financial institutions. Under the MAS Guidelines on Corporate Governance, banks, financial holding companies, direct insurers, reinsurers and captive insurers incorporated in Singapore are expected to have a formal whistleblowing policy with clear reporting channels, a defined investigation process, and protection from reprisal for staff who raise concerns in good faith. This is close to a mandate, but only for that narrow class of regulated entities. A typical trading, consulting or manufacturing SME sits outside it entirely, even if it is otherwise a well run private company.
The Prevention of Corruption Act 1960
Where a report concerns a suspected corruption offence, the Prevention of Corruption Act 1960 gives a genuine, long standing legal protection: the identity of an informer is shielded, complaints are generally not admissible in a way that reveals the informer, and no witness can be compelled to disclose an informer’s name or address. This protection is administered through the Corrupt Practices Investigation Bureau (CPIB) and is specific to corruption reporting. It safeguards anonymity in corruption cases, not employment security across every type of whistleblowing complaint.
Indirect Protection for Employees Who Speak Up
Outside these three areas, an employee dismissed after making a complaint has to rely on general employment law, and the protection is indirect.
The Employment Act 1968 and Wrongful Dismissal
The Employment Act 1968 has no clause that specifically protects whistleblowers. An affected employee can bring a wrongful dismissal claim through the Tripartite Alliance for Dispute Management and, if unresolved, the Employment Claims Tribunals. Under the Ministry of Manpower’s guidance on wrongful dismissal, a dismissal carried out to punish an employee for exercising an employment right can be found wrongful. A retaliatory sacking after a genuine internal report may well fall into that category, but it is decided case by case on the facts, addressing the dismissal after it has happened rather than preventing retaliation in the first place.
The Workplace Fairness Act: A Narrow Protection From Late 2027
The Workplace Fairness legislation, passed in two Bills through 2025, comes closest to an explicit anti-retaliation clause. It requires employers to put grievance handling processes in place and bars retaliation against employees who report workplace discrimination or harassment on protected grounds such as age, nationality, sex, race, religion or disability. According to the Ministry of Manpower, the substantive provisions take effect at the end of 2027, and even then the anti-retaliation protection is scoped to fair employment complaints. It will not cover an employee who reports financial fraud or a breach of company policy unrelated to discrimination or harassment.
Where Whistleblowing Obligations Currently Sit
| Legal instrument | Who it applies to | What it actually requires |
|---|---|---|
| Code of Corporate Governance 2018, Provision 10.1 | SGX listed companies | Recommends a whistleblowing policy on a comply or explain basis |
| MAS Guidelines on Corporate Governance | Banks, financial holding companies, insurers and reinsurers incorporated in Singapore | Expects a formal whistleblowing policy, channels and protection from reprisal |
| Prevention of Corruption Act 1960 | Anyone reporting a suspected corruption offence | Protects the informer’s identity in relation to that report |
| Employment Act 1968 and wrongful dismissal law | All employees | Indirect protection, assessed after dismissal on the specific facts |
| Workplace Fairness Act (from end 2027) | All employers | Bans retaliation, but only for discrimination and harassment complaints |
| Ordinary Singapore private companies generally | No general mandate | A whistleblowing policy is best practice, not a statutory requirement |
Why Private Companies Should Adopt a Whistleblowing Policy Anyway
Two developments make a whistleblowing policy a sensible investment, even without a legal mandate. CALA 2025 has raised the cost of director inattention, increasing the maximum penalties for breaching the core director duties in section 157 of the Companies Act 1967, the duty to act honestly and use reasonable diligence. Our guide to CALA 2025 and our guide to director duties and personal liability explain the mechanics. A functioning reporting channel is a practical way for a board to show it exercised reasonable diligence, since problems surface internally rather than being discovered years later by a liquidator or IRAS.
The CSP Act 2024 has also changed the obligations of the corporate service providers who support private companies. Registered providers now carry due diligence and reporting duties under the framework administered by ACRA, set out on the ACRA CSP Act page and our own explainer on the CSP Act 2024. A company secretary who spots red flags such as suspicious related party payments has obligations of their own, so it helps if the underlying company already has a channel for raising concerns before they escalate.
Fraud is expensive, and whistleblowing is consistently one of the most effective ways it gets caught. For an SME, protecting the company’s cash flow is part of sound financial management for the business and, indirectly, for the owners who depend on it. Investors, banks and grant administrators increasingly expect basic governance discipline before they commit funds; our note on the governance and secretarial steps an SME must get right before signing covers similar due diligence terrain. A written whistleblowing policy is a small, low cost signal of that discipline.
What a Good Whistleblowing Policy Should Contain
A workable policy for a Singapore SME does not need to be long. It should set out:
- What can be reported: fraud, corruption, breaches of law, accounting irregularities, safety issues and serious misconduct, stated broadly enough to cover the things that actually matter
- How to report it: at least one channel that does not run through the complainant’s direct manager, such as a dedicated email address, an independent director, or an external hotline
- A commitment to confidentiality: naming who will know the complainant’s identity and when it might have to be disclosed, for example to CPIB in a corruption case
- A no retaliation commitment: a clear statement that no employee will be disadvantaged for a report made in good faith, even if the concern turns out to be unfounded
- An investigation process: who investigates, the expected timeframe, and how the outcome is communicated back to the reporter
- Record keeping: how reports and investigation outcomes are documented, consistent with the company’s PDPA obligations
Whistleblowing Reports and the PDPA: Handling Personal Data Responsibly
A whistleblowing report almost always involves personal data, both the complainant’s identity and details about the person being reported. That brings the PDPA into play. Consent from the person under investigation is obviously impractical, but the PDPA’s exceptions for collection, use and disclosure without consent, including where this is necessary for an investigation or related proceedings, generally cover a genuine internal whistleblowing case. That is a general framework point rather than an automatic pass, so companies should still apply the PDPA’s core obligations of purpose limitation, reasonable security and data minimisation to whatever a whistleblowing file contains. Our guide to the eleven PDPA obligations every director must know sets out the underlying framework and is worth reading alongside any whistleblowing policy before it is rolled out.
In practice this means restricting access to a report to the people who genuinely need it, keeping the file separate from general HR records where possible, retaining it only as long as necessary, and being upfront in the policy about who may see a complainant’s identity in the course of an investigation.
Practical Steps for SMEs Putting a Policy in Place
Keep implementation simple: draft a short policy using the elements above, get board approval, communicate it to staff in plain language, nominate a specific channel to receive reports, and review it annually. Where a report touches on suspected corruption, it should also go to CPIB, and where it involves a potential breach of tax or company law, the company’s auditors or company secretary should be looped in early. Because this area of law is fragmented and fact dependent, a company facing a live complaint that could lead to dismissal or a regulatory report should treat it as needing proper advice rather than a template exercise; if you need legal advice on this, get it before, not after, a decision is made.
Conclusion
Singapore does not force every private company to have a whistleblowing policy, and any article claiming otherwise overstates the law. What the law does do is single out listed companies and MAS regulated financial institutions for something close to a mandate, protect the identity of corruption informants specifically, and leave everyone else to rely on general, after the fact employment remedies until the Workplace Fairness Act’s narrower protections take effect at the end of 2027. Against that backdrop, with CALA 2025 raising the personal stakes for directors and the CSP Act 2024 raising the bar for the professionals around them, a private company that puts a simple, well documented whistleblowing policy in place is not complying with a rule that does not exist. It is closing a gap the law has left open, and protecting itself in the process. For wider context on how Singapore’s governance and compliance landscape is shifting, see recent Singapore business news coverage of governance and enforcement trends.
To speak with the team at Raffles Corporate Services, you can email [email protected] or call, SMS, or WhatsApp +65 8501 7133. We are happy to assist with any queries.
The Editorial Team, Raffles Corporate Services
Leave A Comment