Australia’s Scams Prevention Framework entered its second transitional phase on September 1, 2026, adding an external dispute resolution membership duty for banks, telecommunications carriers and large digital platforms ahead of full Part IVF obligations on March 31, 2027 — but the banking perimeter is drawn by prudential charter rather than by scam exposure, and the rules registered on August 31, 2026 narrow it further.
The Competition and Consumer (Scams Prevention Framework) Rules 2026 (F2026L01140) were made on August 31, 2026 and commence on the later of registration and September 1, 2026. They sit under the Competition and Consumer (Scams Prevention Framework—Regulated Sectors) Designation 2026 (F2026L00627), registered May 28, 2026, which designates covered banking services as a regulated sector under subsection 58AC(1) of the Competition and Consumer Act 2010. Together they draw a liability boundary that captures authorised deposit-taking institutions (ADIs) and releases two classes of payment provider ASIC had already reviewed for anti-scam practice.
Key facts
- Second transitional phase commenced September 1, 2026 and runs until before March 31, 2027, adding section 58BZG (SPF external dispute resolution scheme membership) to the obligations in force (Designation ss.101(3)–(4), 102(3)–(4), 103(3)–(4)).
- Banking perimeter is charter-based: a covered banking service is one provided by an ADI in the course of carrying on its banking business in Australia, or an ADI’s provision of a purchased payment facility (Designation s.11(2)).
- Two classes are subtracted outright: purchased payment facility providers and foreign ADIs are not regulated entities for covered banking services (Rules s.3-1(1)).
- ASIC is the banking sector regulator under subsection 58ED(1) (Designation s.12); ACMA regulates telecommunications (s.14).
- Digital platform gate: A$1 billion or more in aggregated gross revenue plus 200,000 or more average monthly active Australian users, both struck on 1 January (Rules ss.1-5, 1-6, 3-10).
- Australians reported $2.18 billion in scam losses in 2025, up 7.8% across 481,523 reports, investment scams the largest category at $837.7 million (National Anti-Scam Centre, March 30, 2026).
- AFCA was authorised on June 9, 2026 to handle SPF external disputes across all three sectors (Treasury).
Methodology and sources
This analysis rests on the authorised versions of two instruments downloaded from the Federal Register of Legislation and read in full: F2026L01140 (Rules, registered August 31, 2026) and F2026L00627 (Designation, registered May 28, 2026). Register metadata for both, and for the Scams Prevention Framework Act 2025 (No. 15 of 2025), confirms each is in force as a principal instrument with no commenced unincorporated amendments — so the as-made text is the operative text as at September 1, 2026. Supervisory and statistical material comes from ASIC, APRA, the National Anti-Scam Centre and Treasury, each linked inline.
Two limits should be stated plainly. This article does not quantify Part IVF’s civil penalties: the penalty-unit counts and the current value of a penalty unit were not verified against primary sources, so penalties are described qualitatively. And the comparison below covers Australia, the United Kingdom and the European Union; Singapore’s Shared Responsibility Framework is omitted because MAS pages were unreachable at the time of writing and no figure was taken on trust.
What the rules actually say
The Designation enables and the Rules narrow. Section 11(2) defines a covered banking service by who provides it — an ADI within the meaning of the Banking Act 1959 — not by what the service does or how much scam loss flows through it. Section 12 designates ASIC as the SPF sector regulator under subsection 58ED(1).
Section 3-1(1) then removes two classes from the regulated-entity population under paragraph 58AD(4)(a). The first is a “provider of purchased payment facilities”, defined in s.1-4 as an ADI providing at least one purchased payment facility determined by APRA as mentioned in section 6 of the Banking Regulation 2016, and which does not otherwise carry on banking business within section 5 of the Banking Act 1959. The second is any foreign ADI.
Section 3-1(2) narrows further under paragraph 58AD(4)(b), and its structure matters. A service escapes the regulated-service definition only if it satisfies three cumulative limbs joined by “and”: it is not provided directly to a natural person or small business operator under a contract, arrangement or understanding; it involves no indirect outbound transfer from such a person’s account; and no indirect inbound receipt into one. Because the limbs are conjunctive, a service touching any retail payment leg stays inside. The drafting is tight where it applies — the looseness is in who reaches it at all.
The digital platforms gate is a two-key test. Section 3-10(1) exempts an entity failing the revenue test; s.3-10(2) exempts a service failing the active Australian user test. Section 1-6(2) sets the revenue threshold at A$1 billion or more, summed across four limbs — the entity, its controlled entities, its controlling entities, and those controllers’ other controlled entities — with s.1-6(3) preventing double counting. Section 1-6(1)(b) adds an alternative: the threshold is met if it was met in two of the last three reporting periods. Section 1-5(1) sets the user threshold at 200,000 average monthly active Australian users.
The exemption revokes itself. Section 3-10(3) is the provision compliance teams should read twice. The exceptions in subsections (1) and (2) do not apply where the provider fails to give the ACCC, on written notice and within a reasonable time specified in that notice, information or copies of documents that would reasonably assist the ACCC to determine whether the entity meets the revenue test or the service meets the active user test. There is no determination to make, no instrument to register and no review step: a platform that ignores an ACCC notice becomes a regulated entity by operation of the Rules themselves, as the explanatory note confirms. The cost of non-response is not a penalty — it is the loss of the exemption that kept it outside Part IVF.
How three jurisdictions draw the perimeter
| Jurisdiction / instrument | Key dates | Who is inside | Test that draws the line | Redress / sanction |
|---|---|---|---|---|
| Australia — Scams Prevention Framework (CCA Part IVF; F2026L00627; F2026L01140) | Rules commence September 1, 2026; full Part IVF March 31, 2027 | ADIs (s.11(2)); telecoms carriers (s.13); instant messaging, search, social media (s.15) | Prudential charter, less foreign ADIs and purchased payment facility providers (Rules s.3-1(1)); platforms gated at A$1bn and 200,000 users | AFCA authorised June 9, 2026; s.58BZG duty from September 1, 2026; tiered Part IVF civil penalties |
| Australia — ePayments Code (voluntary, ASIC-administered) | Governed the conduct in ASIC’s HSBC proceedings, commenced December 13, 2024 | Subscribing account issuers only | Voluntary subscription, limited to “unauthorised transactions” | $35m penalty plus adverse publicity orders against HSBC Bank Australia Limited (ASIC 26-127MR) |
| United Kingdom — PSR APP scam reimbursement requirement | Final policy statement December 2023; enabling legislation June 2023 | Sending and receiving firms | Payment rail: Faster Payments and CHAPS between UK accounts | Cost split 50:50; most victims reimbursed within five business days; £459.7m APP losses in 2023 (PSR) |
| European Union — PSD2 and the PSD2 review | Strong customer authentication September 13, 2019; political agreement November 27, 2025 | All categories of payment service provider | Entity function: PSD1 “introduced a new category of payment service providers other than banks” (European Commission) | Obligations attach to the payment function, not to a deposit-taking licence |
Sources: Federal Register of Legislation, ASIC, the Payment Systems Regulator and the European Commission, linked above. Last updated: September 1, 2026.
The comparison exposes the design choice. The European Union regulates the payment function: the Commission’s own account is that the first Payment Services Directive “introduced a new category of payment service providers other than banks”, so obligations follow the activity into payment and electronic money institutions. The United Kingdom regulates the rail: the reimbursement requirement attaches to Faster Payments and CHAPS and splits the cost 50:50, pulling the receiving institution into the liability chain regardless of charter. Australia has done neither. It regulated the licence.
Australia’s own prudential register makes the consequence visible. APRA’s register of authorised deposit-taking institutions separates locally incorporated banks from branches of foreign banks, and lists purchased payment facility providers separately. HSBC Bank Australia Limited appears among the foreign subsidiary banks — locally incorporated, inside the SPF perimeter. The Hongkong and Shanghai Banking Corporation Limited appears among the branches of foreign banks — a foreign ADI, excluded outright by Rules s.3-1(1)(b). One group, one brand, two sides of the line. The register lists more than 50 foreign bank branches in that excluded category, placing a substantial share of cross-border flow beyond Part IVF while a domestic ADI of identical size carries the full duty.
The purchased payment facility carve-out is the sharpest illustration. APRA’s register names exactly two such providers: PayPal Australia Pty Limited and Wise Australia Pty Ltd. Both are subtracted from the SPF banking sector by Rules s.3-1(1)(a). Both were also among the 15 institutions ASIC examined in Report 790, its 2024 review of anti-scam practices at banks outside the four majors — which found customers bore 96% of total scam losses across 2022–23 and that the institutions detected and stopped only 19% of scam transactions by value. ASIC studied these two for their scam handling in 2024; the rules registered on August 31, 2026 place them outside the framework that would have made that handling enforceable. Nothing about their exposure changed. Their charter did.
“Today’s outcome is one of the first of its kind globally and the $35 million penalty ordered against HSBC is the strongest scam wake-up call yet to the banking industry. Banks have been well on notice about the risks of scams for some time. They have now been given a clear message to have adequate controls and ensure their interactions with scam victims help – not hinder.”
— Sarah Court, Chair, Australian Securities and Investments Commission (ASIC 26-127MR)
Enforcement context: the $35 million that came from a voluntary code
ASIC commenced civil penalty proceedings against HSBC Bank Australia Limited on December 13, 2024. The Federal Court, per Justice Bennett in Melbourne, ordered a $35 million penalty and adverse publicity orders on the bank’s website, app and in letters to affected customers. HSBC admitted failures under the ePayments Code: it took 144 days on average to investigate scam reports, and did not apply the Code’s rules for determining whether customer or bank should bear a loss. It also admitted lacking adequate systems to help customers regain banking access after being scammed. Her Honour held the failures were widespread and systemic.
The operational finding matters most. The Court found HSBC had implemented scam controls on some payment systems but not the key controls on the internal (IAT) rail — where the majority of customer losses occurred. Controls existed; they were absent from the path the money took. HSBC has since paid around $21.5 million in compensation and recovered and returned a further $6.5 million.
The instructive point is what the case was brought under. The ePayments Code is voluntary and reaches only “unauthorised transactions” — a category that by definition excludes the authorised push payment, where the victim is deceived into instructing the transfer. Australia’s largest scam-protection penalty to date was therefore extracted from a subscribing ADI under a non-binding code addressing the narrower half of the problem. Part IVF replaces that improvisation with a statutory duty — but only for entities the Designation and Rules actually reach.
What this means for brokers, exchanges, platforms and compliance teams
For AFSL-holding FX and contract-for-difference brokers, no SPF obligation attaches; a broker that is not an ADI sits in none of the three designated sectors. This is a reminder that registered is not the same as regulated, and that what an Australian financial services licence actually buys is a conduct regime, not an anti-scam liability regime. Brokers should still expect pressure down the chain: designated banks facing Part IVF duties from March 31, 2027 will tighten onboarding, payment screening and counterparty diligence on accounts receiving scam-derived funds, and much of that flow terminates at trading and remittance venues. Firms holding offshore FX licensing should expect the sharpest tightening.
For digital currency exchanges and remitters, the same absence and the same second-order exposure apply. Investment scams accounted for $837.7 million of Australia’s $2.18 billion in reported 2025 losses — the largest single category — and those funds characteristically leave the banking system for venues carrying no SPF duty at all. The perimeter stops at the first hop.
For large digital platforms, the two-key test demands a standing calendar. Both tests are struck on 1 January and hold for that whole year, so status is fixed annually — but the aggregation in s.1-6(2) reaches controlling entities and their other controlled entities, meaning a modest Australian service inside a large international group can be captured by group revenue it does not earn. Legal teams should map the four aggregation limbs against the group structure before the next 1 January test time, and treat any ACCC information notice as an exemption-critical deadline under s.3-10(3), not routine correspondence.
For designated banks the near-term deliverable is narrow but dated: SPF external dispute resolution membership under s.58BZG, live since September 1, 2026, with AFCA as the scheme. The substantive prevent-detect-disrupt-respond-report duties land on March 31, 2027, and the HSBC findings supply the template for how they will be tested — control coverage assessed rail by rail, not programme by programme. Firms already mapping where a regulatory perimeter actually bites will recognise the pattern.
“Scams are costing Australians billions, and the human impact is even greater. That’s why we’re moving beyond voluntary action to a stronger, coordinated approach across the economy. By working with industry, we’re stopping scams earlier and protecting Australians’ hard-earned money.”
— Daniel Mulino, Assistant Treasurer and Minister for Financial Services (Treasury, May 28, 2026)
What’s next — and a drafting error still on the register
The government has reserved the power to widen the perimeter and said so explicitly. The same May 28, 2026 release states it “will continue to closely monitor scam activity and will not hesitate to bring additional sectors into scope where needed” — an acknowledgement that three sectors are a starting position, not a complete map. A consultation on consumer redress, proposing that victims with verified losses below $3,000 be automatically reimbursed, closed on June 25, 2026. Sector-specific codes under Division 3 remain the mechanism giving the substantive obligations detail before March 31, 2027.
One drafting defect deserves correction first. In the authorised, in-force text of the Designation, the transitional provision that took effect on September 1, 2026 lists its carve-outs as “(a) section 58BZG (about membership of an SPF EDR scheme); and (a) Division 3; and (b) section 58DB” — two paragraphs labelled (a). The error appears identically in all three transitional provisions: s.101(3) for banking, s.102(3) for telecommunications and s.103(3) for digital platforms. Register metadata confirms the Designation is a principal instrument with no commenced unincorporated amendments, so the as-made text is operative and the duplication stood uncorrected as at September 1, 2026. The meaning is recoverable — all three plainly preserve section 58BZG, Division 3 and section 58DB — but a mislabelled paragraph in a provision determining which statutory duties bind an entire sector invites argument at the margin, and is trivially fixable by minor amendment before March 2027.
TL;DR
Australia’s Scams Prevention Framework entered its second transitional phase on September 1, 2026, adding a section 58BZG external dispute resolution membership duty ahead of full Part IVF obligations on March 31, 2027, with AFCA authorised as the scheme. The banking perimeter is defined by prudential charter (Designation s.11(2)) and then narrowed by Rules s.3-1(1), which excludes foreign ADIs and purchased payment facility providers — the latter being PayPal Australia and Wise Australia, two of the 15 institutions ASIC reviewed in Report 790, which found customers bore 96% of scam losses in 2022–23. AFSL brokers, remitters and digital currency exchanges carry no SPF duty, even though investment scams accounted for $837.7 million of $2.18 billion in 2025 losses.
FAQ
Which entities are actually inside the banking perimeter?
Only ADIs. Designation s.11(2) defines a covered banking service as one provided by an ADI carrying on its banking business in Australia, or an ADI’s provision of a purchased payment facility. Rules s.3-1(1) then removes purchased payment facility providers and foreign ADIs. A locally incorporated ADI is captured; a branch of a foreign bank on APRA’s register is not.
Do FX and CFD brokers have SPF obligations?
No. The only designated sectors are covered banking, telecommunications and digital platform services. An Australian financial services licensee that is not an ADI falls into none of them and carries no Part IVF duty. Brokers should still expect indirect effects, as designated banks preparing for March 31, 2027 tighten payment screening and counterparty diligence on accounts receiving scam-derived funds.
How do the digital platform thresholds work?
Both must be satisfied. Rules s.1-6(2) sets a revenue threshold of A$1 billion or more, aggregated across the entity, its controlled entities, its controlling entities and those controllers’ other controlled entities, with double counting excluded by s.1-6(3). Section 1-5(1) sets an active-user threshold of 200,000 average monthly active Australian users. Both are struck on 1 January and hold all year. Section 1-6(1)(b) allows the revenue threshold to be met in two of the last three periods.
Can a platform lose its exemption without any regulator decision?
Yes. Rules s.3-10(3) provides that the exceptions in subsections (1) and (2) do not apply where the provider fails to give the ACCC, on written notice and within a reasonable time specified in it, information or documents reasonably assisting the ACCC to determine whether the thresholds are met. No determination, instrument or review step is required: non-response converts the entity into a regulated entity by operation of the Rules.
What penalties does the framework carry?
Part IVF carries tiered civil penalties, with the highest tier reserved for the most serious contraventions. This article does not quantify them: the penalty-unit counts and the current dollar value of a penalty unit were not verified against primary sources for this piece. Firms should take those figures from the Scams Prevention Framework Act 2025 and section 4AA of the Crimes Act 1914 as currently in force, rather than from secondary summaries.
Who resolves disputes under the framework?
The Australian Financial Complaints Authority. Treasury announced on June 9, 2026 that AFCA had been formally authorised to handle SPF external disputes across banking, telecommunications and digital platforms. Its decision-making will be guided by an assessment of SPF Code obligations and will consider whether entities had regard to the internal dispute guidelines in the SPF rules, with the SPF taking priority over other applicable frameworks.
See also our analysis of ASIC’s cash-settled swap disclosure thresholds and our coverage of APP fraud liability in the UK and EU.
This article is informational analysis only and does not constitute legal, regulatory, tax, or investment advice. Regulatory frameworks change frequently and interpretation depends on facts and circumstances; primary documents and official regulator guidance always supersede summaries. Firms should consult qualified legal counsel and their relevant supervisory authority before taking any action based on the analysis above.