
For years, the burden of proving a scam wasn't your fault sat almost entirely with the victim. That has now changed in Australia. As of 1 September 2026, entities designated under the Scams Prevention Framework (SPF) were required to become members of the Australian Financial Complaints Authority's dispute resolution scheme, and the framework's substantive rules commenced the same day. The question banks now have to answer isn't just “did a customer get scammed?” it's “can we prove we took reasonable steps to stop it?”
This article explains what the Scams Prevention Framework actually requires, what the latest figures show about why regulators moved so decisively, the operational and liability impact for banks caught short, and how continuous behavioural fraud detection helps build the kind of defensible, evidenced position the framework now demands.
The SPF is, in the ACCC's own description, world-first legislation that sets consistent, enforceable obligations on businesses in sectors where scammers most commonly operate, starting with banks, telecommunications providers, and digital platforms. Regulated entities must comply with overarching principles covering governance, and the prevention, detection, disruption, reporting, and response to scams, enforced by a multi-regulator model: ASIC for banks, ACMA for telcos, and the ACCC as general regulator.
The stakes are substantial. As the ACCC stated when the legislation passed, “businesses that do not meet their obligations under the Framework can face fines up to $50 million”, alongside a private right of action that lets consumers seek direct redress where a regulated entity failed to meet its obligations.
Three developments through 2026 mark the shift from legislative promise to live obligation:
Read together: the money lost is significant and hasn't meaningfully fallen, the dispute-resolution infrastructure is now live, and the compliance deadline banks have been preparing for is no longer a future date on a roadmap.
The SPF doesn't require banks to guarantee zero scams, that isn't achievable, and the framework doesn't pretend otherwise. What it requires is evidence. Liability and any obligation to reimburse a customer turn on whether the regulated entity took reasonable steps to prevent, detect, disrupt, report, and respond to the scam in question, not simply on the fact that a customer was deceived and lost money.
That reframes the compliance question banks need to be able to answer. It isn't only “did we stop this scam?” It's “can we show, with evidence, what our systems detected, when, and what action followed?” A fraud detection capability that can't produce that audit trail leaves an institution exposed under the framework even where its underlying controls were reasonably strong.
Meeting the SPF's principles in practice points toward specific technical capability, not just policy documentation:
Australia's shift toward institutional liability for scams mirrors action already underway elsewhere in Vericent's markets. In the UAE, Article 149 of the Central Bank's Fraud Prevention law, effective since September 2025, similarly requires licensed financial institutions to implement fraud prevention and detection mechanisms and empowers the Central Bank to set minimum standards, including transaction monitoring. The specific mechanisms differ, but the direction is the same: regulators in both regions are moving fraud and scam prevention from a best-practice recommendation to a binding, evidenced obligation.
For banks and other regulated entities, the SPF changes the calculus around fraud investment in concrete ways:
The SPF's reasonable-steps test rewards exactly the capability behavioural detection is built to provide: continuous evaluation of transaction and account behaviour, in real time, with a clear record of what was flagged and what happened next. A static rule engine that only reviews transactions after the fact struggles to demonstrate the kind of proactive disruption the framework expects.
FraudCentral's multi-LLM AI engine evaluates transaction and behavioural signals continuously, its unified investigation dashboard gives compliance and fraud teams a single, auditable view of what was detected and actioned, and its automated remediation can intervene on a suspicious transaction in real time rather than only flagging it for later review. Verified platform outcomes 75% faster investigations and 100% audit compliance speak directly to the evidentiary standard the SPF's reasonable-steps test now demands, and its support for 50+ enterprise systems keeps that capability connected across the core banking and payments platforms scam disruption actually depends on.
The Scams Prevention Framework has moved from legislative milestone to live, enforceable obligation. AFCA membership and the SPF Rules are already in force, the penalty exposure is real, and the framework's reasonable-steps test means proof of proactive detection now matters as much as the detection itself. Banks that can demonstrate continuous, evidenced, real-time fraud disruption will be the ones meeting the standard the framework ses not the ones hoping their existing controls are enough.