Scope - What This Guide Covers
This guide addresses the operational and compliance challenges financial institutions face under Australia's Scams Prevention Framework, effective March 2027. It's for compliance managers, fraud risk officers, and GRC practitioners at banks and payment providers who could face penalties up to $52.7 million per contravention while operating in an ecosystem where critical scam vectors remain unregulated.
You'll find requirement breakdowns, strategies for managing liability in partial regulatory environments, and a framework for cross-organizational scam scenarios where your institution bears the risk but lacks control over the full transaction chain.
Key Concepts and Definitions
Regulated Entity: Banks and telecommunications providers fall under direct regulatory oversight with mandatory compliance obligations and reimbursement liability.
Excluded Platform: Dating apps, matchmaking services, crypto exchanges, crypto ATMs, certain digital wallets, and non-bank payment providers currently operate outside the framework's regulated digital platform category despite their documented role in scam lifecycles.
Cross-Platform Scam Lifecycle: The typical pattern where initial contact occurs on an unregulated platform (dating app), relationship development moves to encrypted messaging (WhatsApp, Telegram), and fund movement executes through a mix of regulated and unregulated channels.
Receiving Bank: The financial institution where scam proceeds ultimately land. Treasury confirmed verbally that receiving banks carry both compliance obligations and reimbursement liability, though this term doesn't appear in the banking sector code provisions.
Requirements Breakdown
Direct Compliance Obligations
Banks operating under the framework must:
- Implement detection systems capable of identifying scam patterns across transaction types.
- Maintain processes for victim reimbursement when scams involve your institution.
- Document compliance with framework provisions to avoid per-contravention penalties.
- Establish clear liability determination when scams cross organizational boundaries.
The Liability Gap Problem
A romance scam typically follows this pattern:
- Initial contact on a dating app (unregulated).
- Relationship building via encrypted messaging (unregulated).
- Payment request and fund movement (potentially through an unregulated non-bank provider).
- Receipt at your institution (regulated, liable).
You're responsible for reimbursement at step 4, but you had no visibility or control over steps 1-3. The framework provides no guidance on how liability and recovery work when a scam transits from unregulated to regulated entities.
The Data That Proves the Gap
The Australian Securities and Investments Commission reported 3,106 crypto investment scams removed in the past financial year, representing a 30% increase year-over-year. Crypto exchanges and crypto ATMs remain outside the framework despite documented evidence of their role in scam proceeds movement.
Implementation Guidance
Build Cross-Platform Visibility Where Regulation Won't
Since you can't rely on unregulated platforms to share scam intelligence, you need compensating controls:
Transaction Pattern Analysis: Develop behavioral models that flag characteristics common to cross-platform scams, even when you can't see the originating platform. Look for sudden relationship-driven payments, crypto exchange deposits following unusual communication patterns, or fund movements to known high-risk receiving jurisdictions.
Customer Communication Protocols: When your transaction monitoring flags potential romance or investment scam patterns, your intervention process becomes your primary defense. Document what you asked, when you asked it, and what the customer confirmed. This creates an audit trail showing you exercised reasonable care within your visibility constraints.
Inter-Bank Intelligence Sharing: Work with industry groups to share scam pattern data at the technical level. If receiving banks face liability but excluded platforms don't, your peer institutions are fighting the same battle.
Document the Regulatory Gap
Ken Palla, a fraud expert and retired director at MUFG Union Bank, requested that Treasury publish detailed guidance showing how liability and recovery work when scams cross from regulated to unregulated entities. That chart still doesn't exist. In the absence of official guidance:
- Maintain records of scenarios where scam proceeds entered your institution from excluded platforms.
- Document attempts to recover funds or obtain cooperation from unregulated entities.
- Track compliance costs attributable to liability for scams you couldn't prevent at origin.
- Build a case file showing the operational impact of regulatory exclusions.
This isn't just defensive documentation. It's evidence for future regulatory revision.
Prepare for Reimbursement Scenarios You Can't Control
You need internal decision frameworks for situations like:
- A customer loses funds to a crypto scam that moved through an excluded exchange. Do you reimburse? Under what criteria?
- Romance scam proceeds arrive at your institution from an overseas sender. You're the receiving bank. What's your liability exposure?
- A scam transits through three unregulated entities before reaching you. How do you demonstrate you met your obligations when you had no visibility into 75% of the chain?
These aren't theoretical. With March 2027 approaching, you need documented policies that address liability in partial-regulation scenarios.
Common Pitfalls
Assuming Verbal Guidance Equals Written Policy: Treasury confirmed verbally that receiving banks carry compliance and reimbursement obligations, but this hasn't been codified in the banking sector provisions. Don't build your compliance program on verbal confirmations from information sessions.
Waiting for Regulatory Clarification: Eight months after industry feedback highlighted the excluded platform problem, Treasury hasn't revised the framework. The March 2027 effective date isn't moving. Build your compliance program now based on what's published, not what should be published.
Treating This as a Fraud-Team Problem: This is a compliance, legal, and enterprise risk issue. Your fraud analysts can flag suspicious patterns, but they can't answer the liability questions or document the regulatory gap. This needs cross-functional ownership.
Ignoring the International Dimension: Scam proceeds frequently involve international receiving banks, many of which fall outside the framework. If you're processing cross-border payments, you need clarity on when you're acting as the liable receiving bank versus an intermediary.
Quick Reference Table
| Scam Scenario | Your Visibility | Your Liability | Regulatory Gap |
|---|---|---|---|
| Romance scam initiated on dating app | None until funds move | Full reimbursement if you're receiving bank | Dating apps excluded from framework |
| Crypto investment scam via excluded exchange | Transaction only | Unclear - no published guidance on recovery from excluded platforms | Crypto exchanges, crypto ATMs excluded |
| Cross-border scam with non-bank payment provider | Final receipt only | Receiving bank liability confirmed verbally, not in code | Non-bank providers excluded; international banks excluded |
| Scam transiting multiple excluded platforms | Final transaction | Full, despite zero control over origin | No published liability chart for multi-platform scenarios |
The framework takes effect in March 2027. You face penalties up to $52.7 million per contravention. Start building your compliance program around what you can control, document what you can't, and prepare for reimbursement scenarios the regulations haven't fully addressed.



