Scams Prevention Framework Codes and Rules
Market Insights
Treasury has commenced consultation on draft rules and sector codes to operationalise the Scans Prevention Framework (SPF), the foundation of the Government’s strategy to combat scams.
The consultation package introduces binding, prescriptive requirements governing how entities in regulated sectors must prevent, detect and respond to scam activity. It represents a shift towards a compliance-driven regulatory model.
The SPF adopts a whole-of-ecosystem approach, targeting sectors most frequently used by scammers and embedding shared responsibility across the scam lifecycle.
Draft rules and sector codes
| 1. Scam prevention and detection systems | Regulated entities are expected to adopt a proactive risk management response which will involve adopting robust systems and controls to:
|
| 2. Information sharing and coordination | As scams span across multiple sectors, it is expected that relevant data and intelligence will be shared across multiple regulated sectors to address the multi-channel nature of scams. |
| 3. Customer reporting and complaint handling | Regulated entities are anticipated to establish accessible and user-friendly scam reporting processes, timely investigation procedures and revised internal dispute resolution arrangements to address the SPF. |
| 4. Consumer redress and reimbursement | A material shift in financial exposure is proposed with streamlined consumer redress mechanisms, including:
|
| 5. Detailed rules framework | The rules are intended to ensure consistency across regulated entities with sufficient operational specificity to facilitate practical compliance with obligations and minimum technical requirements that support enforcement. |
Implications
The exposure draft rules and sector codes suggest significant uplift will be required in governance, systems and controls including investment in detection technologies. The real-time monitoring, intervention and cross-sector coordination required to comply with the exposure draft rules and sector codes will require substantial changes to existing business processes.
The position paper proposing the reimbursement model introduces potential direct financial liability on participants in regulated sectors for scam losses. It proposes that while Ministerial Guidance will make it clear that entities should reimburse consumers for scam losses under $3,000, entities will be liable for losses where they have breached their obligations under the SPF for all values of scam losses.
Where more than one regulated entity has breached its obligations under the SPF, it is proposed that liability should be shared equally between those breaching entities. While entities will be required to coordinate their response to the consumer, each entity will be responsible for directly reimbursing consumers for any losses the entity is liable for.
Key consultation issues
Treasury is seeking submissions on several critical aspects of its proposal including:
- Regulatory overlap: whether draft obligations conflict with existing frameworks;
- Implementation and transition: adequacy of proposed timeframes and staging;
- Privacy considerations: balancing information sharing with data protection; and
- Proportionality – whether obligations are appropriately calibrated to risk.
These issues will material to the final design of the rules and sector codes.
Industry stakeholders will be particularly concerned about:
- the lack of acknowledgement that scam victims are typically part of the cause of their own losses and need to be incentivised to exercise vigilance in order to avoid making Australia a potential honeypot jurisdiction for scammers undermining the objective of the SPF; and
- the extent to which the SPF loss allocation provisions gloss over the complexity of proportionate loss allocation particularly in circumstances where victims are unhelpful in identifying all entities involved. Victims are likely to just call on their bank to pay compensation without assisting the bank to identify the digital platform or telecommunications providers whose services may have facilitated the first leg of the scam activity.
Next steps
Banks, telecommunications providers and digital platforms should:
- review the exposure draft rules and codes,
- undertake a gap analysis of existing practices and what will be required under the SPF,
- assess financial exposure under the proposed reimbursement model,
- consider making as submission before 25 June 2026, and
- commence implementation planning, noting likely commencement in 2027.
This article was written by Andrew Galvin, Partner, Daniel Kiley, Partner, and Yvonne Nehme, Senior Associate.
Subscribe for publications + events
HWLE regularly publishes articles and newsletters to keep our clients up to date on the latest legal developments and what this means for your business. To receive these updates via email, please complete the subscription form and indicate which areas of law you would like to receive information on.
* indicates required fields

