<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=3887732&amp;fmt=gif">
Start Integrating

Transak Blog

What Is the Scams Prevention Framework in Australia?

Sep 20, 2026, 12:30:00 AM / by Sankrit K.

[[key]]

  • Australia's Scams Prevention Framework creates enforceable responsibilities for covered banks, telecommunications providers and digital platforms to tackle scams.
  • AFCA membership became mandatory for covered businesses on 1 September 2026. Most obligations apply from 31 March 2027.
  • Wallets and crypto platforms need to assess their specific services. AUSTRAC registration and Scams Prevention Framework coverage are separate questions.

[[/key]]

A scam can begin with an online advertisement, continue through a message and end with a payment. Each business involved may see a different part of what happened.

Australia's Scams Prevention Framework connects those responsibilities. It gives covered businesses duties to prevent and respond to scams, supported by enforcement and a shared complaints pathway.

For teams building wallets and financial applications, the immediate questions are which services fall within scope, when the requirements apply and how payment partners fit into the response.

This article reflects the rules and official guidance available on 21 September 2026.

What is Australia's Scams Prevention Framework?

The Scams Prevention Framework, or SPF, is Australia's legal framework for reducing scams through obligations on businesses in designated sectors.

The Scams Prevention Framework Act 2025 introduced it into Part IVF of the Competition and Consumer Act 2010.

It combines broad duties, sector-specific codes, information sharing and routes for consumers to seek redress. Its central expectation is that covered businesses take reasonable steps to address scams involving their services.

Consider a fake investment advertisement that leads someone to transfer money. The framework allows responsibilities to be examined across the services involved, including the platform carrying the advertisement and the bank processing the payment. Treasury's framework guide explains this shared approach.

When does the Scams Prevention Framework start?

The framework is being introduced in stages. Passing the Act, designating sectors and activating particular obligations happen at different points.

DateWhat changes
February 2025The Scams Prevention Framework Act becomes law.
May 2026Banking, telecommunications and specified digital-platform services are designated.
1 September 2026Covered businesses must hold AFCA membership. Rules defining certain scope exceptions also take effect.
31 March 2027Most obligations apply, and AFCA begins handling eligible SPF complaints about matters occurring from this date.

The ACCC's implementation guidance confirms the membership and March 2027 dates. As of this article's update, the sector codes and further rules remain under development.

Mandatory reporting of actionable scam intelligence has a separate implementation path. Treasury's May 2026 consultation guide says that duty depends on further rules, with implementation intended by the end of 2027. Treat that as a policy timetable pending those rules.

Which businesses does the SPF cover?

Coverage depends on the service provided and any applicable exceptions. The designation instrument identifies three initial sectors.

Banking services

The designation covers banking services provided by authorised deposit-taking institutions, or ADIs, in Australia. The rules contain exceptions, including for foreign ADIs, certain purchased-payment-facility providers and specified services without a relevant consumer connection.

Telecommunications services

Covered services include specified voice calls and messages delivered through telecommunications networks. The rules exclude certain private-line services.

Digital platforms

This category covers defined social-media, instant-messaging and internet-search advertising services. An application does not fall within scope simply because it operates online.

The rules effective from 1 September 2026 generally require both:

  • At least 200,000 average monthly active Australian users for the relevant service.
  • At least A$1 billion in gross revenue under the rules' entity and corporate-group calculation.

The tests use specified reporting periods. The exceptions also depend on providing information requested by the ACCC to assess eligibility.

For a fintech, this makes service classification the starting point. A banking licence, a messaging product and a standalone crypto wallet can produce different scope assessments.

What are the six SPF principles?

The framework sets out six principles. Sector codes supply more detail about how covered businesses should meet them.

PrincipleWhat it addresses
GovernancePolicies, senior accountability and records showing how scam risks are managed.
PreventReasonable steps to reduce the risk of scams involving the service.
DetectIdentifying scams and investigating actionable scam intelligence.
ReportGiving regulators the required scam information.
DisruptTaking reasonable steps to interrupt suspected scam activity.
RespondAccessible scam reporting, complaints handling and dispute resolution.

Under Part IVF of the Act, reasonable steps depend on factors such as the business's size, services, customers and scam risks. Compliance with relevant code obligations is the primary consideration where applicable.

For product teams, these principles suggest a useful design question: when a warning appears, can the right person or system act on it?

An alert needs an owner, a decision process and a record of the outcome. Building that connection helps teams turn detection into action.

Who regulates the Scams Prevention Framework?

Responsibilities are divided between three regulators:

  • ACCC: General regulator for the framework and sector regulator for digital platforms.
  • ASIC: Sector regulator for banking.
  • ACMA: Sector regulator for telecommunications.

AFCA, the Australian Financial Complaints Authority, provides external dispute resolution. Its role is to handle eligible unresolved complaints; regulatory enforcement sits with the relevant regulators.

What are the SPF penalties and compensation rules?

Civil penalties

The Act uses two penalty tiers. For a corporate tier-one contravention, the maximum is the greatest of:

  • 159,745 penalty units.
  • Three times the attributable benefit, where it can be determined.
  • 30% of adjusted turnover during the breach turnover period, where that benefit cannot be determined.

At the A$364 penalty-unit value applying from 1 July 2026, the first amount equals approximately A$58.15 million. The benefit or turnover calculation can produce a higher maximum. Tier-two breaches have a lower penalty formula.

These are maximum civil penalties for contraventions, rather than an automatic charge whenever a customer is scammed. The formulas appear in sections 58FK and 58FL of the Act.

Consumer compensation

The framework creates routes to seek compensation where a business's failure to meet its obligations causes loss. It does not promise reimbursement for every scam.

Consumers generally raise the complaint with the business first. Eligible unresolved matters can then go to AFCA, which will be able to consider complaints involving multiple organisations under the SPF.

AFCA's guidance states that its new SPF jurisdiction covers matters occurring on or after 31 March 2027. Existing complaint arrangements continue before then.

Does the SPF apply to crypto wallets and exchanges?

A business is not automatically covered because it offers crypto services. The initial designations concern particular banking, telecommunications and digital-platform services.

A wallet or exchange should assess whether any of its activities meet those definitions. The outcome can depend on the legal entity, service design and applicable exceptions.

SPF and AUSTRAC address different obligations

AUSTRAC supervises Australia's anti-money laundering and counter-terrorism financing regime. Its guidance for virtual asset service providers addresses obligations such as customer due diligence, reporting and AML/CTF programs.

SPF coverage requires a separate assessment. AUSTRAC registration does not establish that a business is covered by the SPF or that it meets SPF requirements.

Also Read: Why AUSTRAC Compliance Matters for Platforms Expanding to Australia

Payment partners still matter to wallet teams

Even where a wallet is outside the initial designations, its users may fund purchases through a covered bank. Our practical recommendation is to agree how the wallet and its payment providers will handle suspected scams.

For example, a customer may pass identity checks while being deceived into sending funds. The product team needs to understand where a warning can appear, who can review a payment and how support teams exchange the relevant information lawfully.

How should fintechs prepare for the SPF?

The following steps are product-planning recommendations. Apply them alongside a legal assessment of your services and the final rules relevant to your business.

Confirm which services are covered

  • Map your services against the designations and exceptions.
  • Record which legal entity provides each service.
  • Confirm AFCA membership where required.

Assign ownership of scam reports

  • Give customers a clear way to report a suspected scam.
  • Identify who can review an alert and escalate it to a payment partner.
  • Agree how customers will receive updates while the report is investigated.

Test the payment journey

  • Walk through a suspected scam from the first warning to the support response.
  • Check which actions remain possible before payment or crypto delivery completes.
  • Show accurate order states so users understand whether a payment is pending, failed or completed.

Keep evidence of the response

  • Link the complaint to the relevant order and support records.
  • Record the warning, decision and action taken.
  • Set access and retention rules that account for applicable legal requirements.

A practical test is to give support and engineering the same example incident. Check whether both teams can identify the order, the responsible provider and the next available action.

How Transak supports Australian payment integrations

At Transak, we provide fiat-to-crypto payment infrastructure for wallets and financial applications. Our Australian entity is registered with AUSTRAC.

Our payment infrastructure brings together capabilities relevant to the funding journey:

  • Identity and risk checks: Our KYC processes include identity verification, sanctions screening, wallet screening and velocity checks, as applicable.
  • Transaction monitoring: Our AML program uses a risk-based approach to assessing transactional activity and behaviour.
  • Order visibility: Our webhooks provide status updates that partners can connect to their product and support workflows.

These capabilities support the payment portion of a platform's controls. Each business still needs to assess its own obligations and agree the responsibilities it shares with providers.

If you are building an Australian wallet or fintech payment flow, talk to our team about the integration and how its controls fit your user journey.

Conclusion

Australia's Scams Prevention Framework makes scam prevention a defined responsibility for covered businesses. For wallet and fintech teams, preparation starts with understanding scope and connecting the product, payments and support response.

Take one suspected-scam scenario through your current flow. Can your team identify who acts, what information they need and how the customer gets help? Use any gaps to set the next integration priorities.

Frequently asked questions

What is the Scams Prevention Framework Act 2025?

It is the Australian law that introduced the SPF into the Competition and Consumer Act 2010. It establishes overarching scam-prevention duties and powers to designate sectors, make sector codes and provide enforcement and dispute-resolution mechanisms. The requirements apply through a staged implementation process.

Is the Scams Prevention Framework already in force?

The legislation and initial sector designations are in place. Covered businesses have been required to hold AFCA membership since 1 September 2026. Most operational obligations apply from 31 March 2027. Particular requirements, including mandatory intelligence sharing, depend on the relevant rules and their commencement arrangements.

Does every online business count as a digital platform?

No. The designation defines particular social-media, instant-messaging and internet-search advertising services. The September 2026 rules also provide user and revenue thresholds and other conditions. A business should assess the services it actually provides rather than rely on the general description of itself as a platform.

Does AUSTRAC registration satisfy the SPF?

No. AUSTRAC registration relates to the AML/CTF regime. SPF duties arise under separate legislation and depend on the designated services a business provides. A platform may need to address more than one regulatory regime, with responsibilities determined by its activities and operating model.

Will scam victims automatically receive a refund?

The SPF does not establish a universal refund guarantee. It provides avenues for redress when a covered business fails to meet its obligations and that failure causes loss. The circumstances, responsibilities of the businesses involved and applicable dispute-resolution rules affect the outcome.

Can consumers complain to AFCA before March 2027?

Existing AFCA arrangements remain available for eligible complaints about member financial firms. The new SPF jurisdiction begins on 31 March 2027 and applies to relevant matters occurring from that date. Consumers should first raise the issue with the business through its internal complaints process.

Does a successful KYC check mean a payment is scam-free?

No. Identity verification establishes information about the customer. A real, verified customer can still be manipulated by a scammer. Payment-risk controls, appropriate warnings, transaction monitoring and a responsive support process address different parts of that problem.

Can a payment provider handle all SPF responsibilities?

A provider can supply agreed payment and risk-management capabilities. A platform must still understand its own legal position and the controls it operates. Document who handles alerts, customer contact, escalation and records so an incident has a clear response across the integration.

Tags: Learn

Sankrit K.

Written by Sankrit K.

Content writer at Transak