[[key]]
[[/key]]
A scam can begin with an online advertisement, continue through a message and end with a payment. Each business involved may see a different part of what happened.
Australia's Scams Prevention Framework connects those responsibilities. It gives covered businesses duties to prevent and respond to scams, supported by enforcement and a shared complaints pathway.
For teams building wallets and financial applications, the immediate questions are which services fall within scope, when the requirements apply and how payment partners fit into the response.
This article reflects the rules and official guidance available on 21 September 2026.
The Scams Prevention Framework, or SPF, is Australia's legal framework for reducing scams through obligations on businesses in designated sectors.
The Scams Prevention Framework Act 2025 introduced it into Part IVF of the Competition and Consumer Act 2010.
It combines broad duties, sector-specific codes, information sharing and routes for consumers to seek redress. Its central expectation is that covered businesses take reasonable steps to address scams involving their services.
Consider a fake investment advertisement that leads someone to transfer money. The framework allows responsibilities to be examined across the services involved, including the platform carrying the advertisement and the bank processing the payment. Treasury's framework guide explains this shared approach.
The framework is being introduced in stages. Passing the Act, designating sectors and activating particular obligations happen at different points.
| Date | What changes |
|---|---|
| February 2025 | The Scams Prevention Framework Act becomes law. |
| May 2026 | Banking, telecommunications and specified digital-platform services are designated. |
| 1 September 2026 | Covered businesses must hold AFCA membership. Rules defining certain scope exceptions also take effect. |
| 31 March 2027 | Most obligations apply, and AFCA begins handling eligible SPF complaints about matters occurring from this date. |
The ACCC's implementation guidance confirms the membership and March 2027 dates. As of this article's update, the sector codes and further rules remain under development.
Mandatory reporting of actionable scam intelligence has a separate implementation path. Treasury's May 2026 consultation guide says that duty depends on further rules, with implementation intended by the end of 2027. Treat that as a policy timetable pending those rules.
Coverage depends on the service provided and any applicable exceptions. The designation instrument identifies three initial sectors.
The designation covers banking services provided by authorised deposit-taking institutions, or ADIs, in Australia. The rules contain exceptions, including for foreign ADIs, certain purchased-payment-facility providers and specified services without a relevant consumer connection.
Covered services include specified voice calls and messages delivered through telecommunications networks. The rules exclude certain private-line services.
This category covers defined social-media, instant-messaging and internet-search advertising services. An application does not fall within scope simply because it operates online.
The rules effective from 1 September 2026 generally require both:
The tests use specified reporting periods. The exceptions also depend on providing information requested by the ACCC to assess eligibility.
For a fintech, this makes service classification the starting point. A banking licence, a messaging product and a standalone crypto wallet can produce different scope assessments.
The framework sets out six principles. Sector codes supply more detail about how covered businesses should meet them.
| Principle | What it addresses |
|---|---|
| Governance | Policies, senior accountability and records showing how scam risks are managed. |
| Prevent | Reasonable steps to reduce the risk of scams involving the service. |
| Detect | Identifying scams and investigating actionable scam intelligence. |
| Report | Giving regulators the required scam information. |
| Disrupt | Taking reasonable steps to interrupt suspected scam activity. |
| Respond | Accessible scam reporting, complaints handling and dispute resolution. |
Under Part IVF of the Act, reasonable steps depend on factors such as the business's size, services, customers and scam risks. Compliance with relevant code obligations is the primary consideration where applicable.
For product teams, these principles suggest a useful design question: when a warning appears, can the right person or system act on it?
An alert needs an owner, a decision process and a record of the outcome. Building that connection helps teams turn detection into action.
Responsibilities are divided between three regulators:
AFCA, the Australian Financial Complaints Authority, provides external dispute resolution. Its role is to handle eligible unresolved complaints; regulatory enforcement sits with the relevant regulators.
The Act uses two penalty tiers. For a corporate tier-one contravention, the maximum is the greatest of:
At the A$364 penalty-unit value applying from 1 July 2026, the first amount equals approximately A$58.15 million. The benefit or turnover calculation can produce a higher maximum. Tier-two breaches have a lower penalty formula.
These are maximum civil penalties for contraventions, rather than an automatic charge whenever a customer is scammed. The formulas appear in sections 58FK and 58FL of the Act.
The framework creates routes to seek compensation where a business's failure to meet its obligations causes loss. It does not promise reimbursement for every scam.
Consumers generally raise the complaint with the business first. Eligible unresolved matters can then go to AFCA, which will be able to consider complaints involving multiple organisations under the SPF.
AFCA's guidance states that its new SPF jurisdiction covers matters occurring on or after 31 March 2027. Existing complaint arrangements continue before then.
A business is not automatically covered because it offers crypto services. The initial designations concern particular banking, telecommunications and digital-platform services.
A wallet or exchange should assess whether any of its activities meet those definitions. The outcome can depend on the legal entity, service design and applicable exceptions.
AUSTRAC supervises Australia's anti-money laundering and counter-terrorism financing regime. Its guidance for virtual asset service providers addresses obligations such as customer due diligence, reporting and AML/CTF programs.
SPF coverage requires a separate assessment. AUSTRAC registration does not establish that a business is covered by the SPF or that it meets SPF requirements.
Also Read: Why AUSTRAC Compliance Matters for Platforms Expanding to Australia
Even where a wallet is outside the initial designations, its users may fund purchases through a covered bank. Our practical recommendation is to agree how the wallet and its payment providers will handle suspected scams.
For example, a customer may pass identity checks while being deceived into sending funds. The product team needs to understand where a warning can appear, who can review a payment and how support teams exchange the relevant information lawfully.
The following steps are product-planning recommendations. Apply them alongside a legal assessment of your services and the final rules relevant to your business.
A practical test is to give support and engineering the same example incident. Check whether both teams can identify the order, the responsible provider and the next available action.
At Transak, we provide fiat-to-crypto payment infrastructure for wallets and financial applications. Our Australian entity is registered with AUSTRAC.
Our payment infrastructure brings together capabilities relevant to the funding journey:
These capabilities support the payment portion of a platform's controls. Each business still needs to assess its own obligations and agree the responsibilities it shares with providers.
If you are building an Australian wallet or fintech payment flow, talk to our team about the integration and how its controls fit your user journey.
Australia's Scams Prevention Framework makes scam prevention a defined responsibility for covered businesses. For wallet and fintech teams, preparation starts with understanding scope and connecting the product, payments and support response.
Take one suspected-scam scenario through your current flow. Can your team identify who acts, what information they need and how the customer gets help? Use any gaps to set the next integration priorities.
It is the Australian law that introduced the SPF into the Competition and Consumer Act 2010. It establishes overarching scam-prevention duties and powers to designate sectors, make sector codes and provide enforcement and dispute-resolution mechanisms. The requirements apply through a staged implementation process.
The legislation and initial sector designations are in place. Covered businesses have been required to hold AFCA membership since 1 September 2026. Most operational obligations apply from 31 March 2027. Particular requirements, including mandatory intelligence sharing, depend on the relevant rules and their commencement arrangements.
No. The designation defines particular social-media, instant-messaging and internet-search advertising services. The September 2026 rules also provide user and revenue thresholds and other conditions. A business should assess the services it actually provides rather than rely on the general description of itself as a platform.
No. AUSTRAC registration relates to the AML/CTF regime. SPF duties arise under separate legislation and depend on the designated services a business provides. A platform may need to address more than one regulatory regime, with responsibilities determined by its activities and operating model.
The SPF does not establish a universal refund guarantee. It provides avenues for redress when a covered business fails to meet its obligations and that failure causes loss. The circumstances, responsibilities of the businesses involved and applicable dispute-resolution rules affect the outcome.
Existing AFCA arrangements remain available for eligible complaints about member financial firms. The new SPF jurisdiction begins on 31 March 2027 and applies to relevant matters occurring from that date. Consumers should first raise the issue with the business through its internal complaints process.
No. Identity verification establishes information about the customer. A real, verified customer can still be manipulated by a scammer. Payment-risk controls, appropriate warnings, transaction monitoring and a responsive support process address different parts of that problem.
A provider can supply agreed payment and risk-management capabilities. A platform must still understand its own legal position and the controls it operates. Document who handles alerts, customer contact, escalation and records so an incident has a clear response across the integration.