Australia's Scams Prevention Framework: What 'Reasonable Steps' Now Means for Banks

Australia's Scams Prevention Framework: What 'Reasonable Steps' Now Means for Banks

For years, the burden of proving a scam wasn't your fault sat almost entirely with the victim. That has now changed in Australia. As of 1 September 2026, entities designated under the Scams Prevention Framework (SPF) were required to become members of the Australian Financial Complaints Authority's dispute resolution scheme, and the framework's substantive rules commenced the same day. The question banks now have to answer isn't just “did a customer get scammed?” it's “can we prove we took reasonable steps to stop it?”

This article explains what the Scams Prevention Framework actually requires, what the latest figures show about why regulators moved so decisively, the operational and liability impact for banks caught short, and how continuous behavioural fraud detection helps build the kind of defensible, evidenced position the framework now demands.


What Is the Scams Prevention Framework?

The SPF is, in the ACCC's own description, world-first legislation that sets consistent, enforceable obligations on businesses in sectors where scammers most commonly operate, starting with banks, telecommunications providers, and digital platforms. Regulated entities must comply with overarching principles covering governance, and the prevention, detection, disruption, reporting, and response to scams, enforced by a multi-regulator model: ASIC for banks, ACMA for telcos, and the ACCC as general regulator.

The stakes are substantial. As the ACCC stated when the legislation passed, “businesses that do not meet their obligations under the Framework can face fines up to $50 million”, alongside a private right of action that lets consumers seek direct redress where a regulated entity failed to meet its obligations.


Why September 2026 Is a Turning Point

Three developments through 2026 mark the shift from legislative promise to live obligation:

  • Entities designated under the SPF were required to join AFCA's dispute resolution scheme from 1 September 2026, with the ACCC confirming that entities failing to meet this obligation may face enforcement action, including civil penalties.
  • According to the ACCC's March 2026 update citing the National Anti-Scam Centre's Targeting Scams report, Australians lost more than AU$2 billion to scams again in 2025, underscoring why regulators moved from voluntary industry initiatives to a binding regime.
  • Under the framework's authorising legislation, described in Treasury's own policy paper, banks, certain digital platforms, and telcos are the first sectors required to comply, specifically because Treasury identified them as where the greatest harm to consumers is currently occurring.
  • The Australian Financial Complaints Authority now the authorised external dispute resolution body for scam complaints under the SPF notes that in 2023 alone, Australians lost over $2.74 billion to scams, with 65% of victims receiving no refund or remedy at all. That gap is precisely what the SPF's reimbursement and dispute-resolution pathway is designed to close.

Read together: the money lost is significant and hasn't meaningfully fallen, the dispute-resolution infrastructure is now live, and the compliance deadline banks have been preparing for is no longer a future date on a roadmap.


The “Reasonable Steps” Test: Why Proof Matters as Much as Prevention

The SPF doesn't require banks to guarantee zero scams, that isn't achievable, and the framework doesn't pretend otherwise. What it requires is evidence. Liability and any obligation to reimburse a customer turn on whether the regulated entity took reasonable steps to prevent, detect, disrupt, report, and respond to the scam in question, not simply on the fact that a customer was deceived and lost money.

That reframes the compliance question banks need to be able to answer. It isn't only “did we stop this scam?” It's “can we show, with evidence, what our systems detected, when, and what action followed?” A fraud detection capability that can't produce that audit trail leaves an institution exposed under the framework even where its underlying controls were reasonably strong.


What This Means for Fraud Detection and Monitoring Systems

Meeting the SPF's principles in practice points toward specific technical capability, not just policy documentation:

  • Prevention and detection: continuous, behavioural monitoring of transactions and account activity, rather than static rules alone, to catch the patterns that indicate a scam in progress, including payment redirection and social-engineering-driven transfers.
  • Disruption: the ability to intervene in real time, holding or flagging a transaction rather than only recording it for later review, since disruption before funds leave the institution is far more valuable than detection after.
  • Reporting and evidencing: a clear, auditable record of what was detected, when, and what action was taken, to support both regulatory reporting obligations and any dispute referred to AFCA.
  • Cross-sector and cross-account correlation: since scams frequently involve payment redirection to mule-style receiving accounts, detection capability that spans accounts and channels closes gaps that single-transaction review leaves open.

A Global Pattern: Australia Isn't Acting Alone

Australia's shift toward institutional liability for scams mirrors action already underway elsewhere in Vericent's markets. In the UAE, Article 149 of the Central Bank's Fraud Prevention law, effective since September 2025, similarly requires licensed financial institutions to implement fraud prevention and detection mechanisms and empowers the Central Bank to set minimum standards, including transaction monitoring. The specific mechanisms differ, but the direction is the same: regulators in both regions are moving fraud and scam prevention from a best-practice recommendation to a binding, evidenced obligation.


Business and Operational Impact

For banks and other regulated entities, the SPF changes the calculus around fraud investment in concrete ways:

  • Direct financial exposure: civil penalties of up to $50 million per contravention, alongside a private right of action for damages.
  • Reimbursement obligations: where an entity hasn't met its obligations, it may be required to compensate affected customers, shifting cost from the victim to the institution.
  • Dispute-resolution exposure: with AFCA now the authorised EDR body, unresolved scam complaints have a clear, formal escalation path that didn't previously carry the same weight across all designated sectors.
  • Reputational and competitive impact: institutions seen to be lagging on scam prevention face customer and market scrutiny in a market where the framework itself has made this a public compliance benchmark.

Practical Recommendations for Fraud, Risk, Compliance, and Finance Leaders

For Compliance and Legal Teams
  • Map current fraud controls directly against the SPF's five principles prevent, detect, disrupt, report, respond and document gaps in evidentiary capability, not just control existence.
  • Build the audit trail now: ensure detection and response actions are logged in a form that can support both regulatory reporting and an AFCA dispute.

For Fraud and Risk Teams
  • Prioritise real-time disruption capability over after-the-fact detection the value of catching a scam before funds leave the institution is materially higher under a reasonable-steps standard.
  • Extend monitoring to the patterns most associated with scams specifically payment redirection, urgency-driven transfers, and new-payee anomalies not only classic account-takeover or mule-account indicators.

For Finance and Executive Leadership
  • Treat SPF compliance investment as core risk infrastructure spend, not a discretionary uplift the penalty and reimbursement exposure make the cost of inaction directly quantifiable.
  • Track the UAE's parallel liability-shift trajectory if your institution operates across both markets, since compliance architecture built for one increasingly transfers to the other.

How Behavioural Anomaly Detection and FraudCentral Can Help

The SPF's reasonable-steps test rewards exactly the capability behavioural detection is built to provide: continuous evaluation of transaction and account behaviour, in real time, with a clear record of what was flagged and what happened next. A static rule engine that only reviews transactions after the fact struggles to demonstrate the kind of proactive disruption the framework expects.

FraudCentral's multi-LLM AI engine evaluates transaction and behavioural signals continuously, its unified investigation dashboard gives compliance and fraud teams a single, auditable view of what was detected and actioned, and its automated remediation can intervene on a suspicious transaction in real time rather than only flagging it for later review. Verified platform outcomes 75% faster investigations and 100% audit compliance speak directly to the evidentiary standard the SPF's reasonable-steps test now demands, and its support for 50+ enterprise systems keeps that capability connected across the core banking and payments platforms scam disruption actually depends on.


Conclusion

The Scams Prevention Framework has moved from legislative milestone to live, enforceable obligation. AFCA membership and the SPF Rules are already in force, the penalty exposure is real, and the framework's reasonable-steps test means proof of proactive detection now matters as much as the detection itself. Banks that can demonstrate continuous, evidenced, real-time fraud disruption will be the ones meeting the standard the framework ses not the ones hoping their existing controls are enough.