Skip to main content
Scams Prevention Penalties: Who Pays When Regulation Stops Halfway?general
5 min readFor Compliance Managers

Scams Prevention Penalties: Who Pays When Regulation Stops Halfway?

What Changed

Australia's Scams Prevention Framework, effective March 2027, imposes penalties up to $52.7 million per contravention on banks and telecoms while excluding digital platforms where many scams originate. Dating apps, crypto exchanges, digital wallets, and non-bank payment providers remain unregulated. This creates a liability structure where regulated entities bear full enforcement risk for fraud chains they don't control.

The framework marks a shift in government approach to scam liability, but its exclusion list undermines its purpose. For compliance teams at regulated institutions, this means preparing for enforcement against your organization while coordinating with entities that face no equivalent obligation.

Key Findings

Finding 1: The scam chain crosses regulatory boundaries by design

Romance scams illustrate the problem. A scammer builds trust on an excluded dating platform, moves the conversation to WhatsApp or Telegram, then requests money through an excluded payment provider or crypto exchange. The regulated bank that processes the transaction sees only the final step. Under the framework, that bank faces the $52.7 million penalty exposure while the platforms that enabled relationship-building and fund movement carry no compliance burden.

Ken Palla, a fraud expert and retired director at MUFG Union Bank, submitted detailed questions to Australian Treasury about this scenario: how does reimbursement work when a scam crosses from regulated to unregulated entities? Treasury confirmed verbally at a June information session that receiving banks would be liable, but the banking sector's own code provisions don't define "receiving bank." The liability chart Palla requested in January still doesn't exist eight months later.

Finding 2: Crypto scams are accelerating outside the framework's scope

The Australian Securities and Investments Commission reported 3,106 crypto investment scams over the past financial year, a 30% increase year-over-year. Crypto exchanges and crypto ATMs remain excluded from the Scams Prevention Framework. Industry submissions flagged this gap during consultation. The data now validates those warnings, but the exclusion list hasn't changed.

For your compliance program, this creates a documentation problem. You're expected to demonstrate effective scam prevention controls, but the fraud vectors generating the highest growth sit outside your regulatory perimeter. Your risk assessment must account for threats you can't directly control.

Finding 3: Treasury hasn't clarified cross-boundary reimbursement mechanics

When a scam starts with an email, moves through an excluded non-bank payment provider, and lands at an excluded international receiving bank, who reimburses the victim? The framework doesn't specify. Treasury's verbal confirmation that receiving banks bear liability doesn't match the written code provisions banks are actually held to. This ambiguity matters because your organization's financial exposure depends on interpreting obligations that regulators haven't fully articulated in enforceable text.

Finding 4: Regulated entities face asymmetric information requirements

You're required to implement detection and prevention controls for fraud chains where you see only the final transaction. The dating app knows the relationship context. The messaging platform has the conversation history. The payment provider has the routing details. You have a wire instruction and limited time to evaluate it. The framework penalizes you for missing the scam but doesn't require the entities with upstream visibility to share intelligence or implement comparable controls.

What This Means for Your Team

You're building a compliance program for a regulation that assumes coordination the law doesn't mandate. Your risk treatment plan must address threats that originate outside your control perimeter, move through unregulated channels, and arrive at your institution with enforcement liability fully attached.

This isn't a theoretical gap. If you're a bank compliance lead, your March 2027 readiness depends on establishing relationships with entities that face no regulatory incentive to participate. You need fraud intelligence sharing, but the framework doesn't create data-sharing obligations for excluded platforms. You need clear reimbursement procedures, but Treasury hasn't published the liability mechanics for cross-boundary scenarios.

Your audit evidence will need to demonstrate that your controls are effective despite these constraints. That means documenting not just your internal detection capabilities, but also your attempts to coordinate with unregulated entities, your escalation procedures when scams cross regulatory boundaries, and your methodology for assessing fraud risk in transactions that appear clean at your visibility point.

Action Items by Priority

Priority 1: Map your fraud chain visibility gaps

Document where scams enter your transaction flow and which upstream entities have context you don't. For each common scam type (romance, investment, impersonation), identify which platforms are excluded from the framework. This becomes your risk register for regulatory exposure you can't directly mitigate. Update this quarterly as ASIC publishes new scam statistics.

Priority 2: Establish intelligence-sharing channels before March 2027

Reach out to the dating apps, crypto exchanges, and payment providers your customers use. Propose information-sharing arrangements even though the framework doesn't require them to participate. Document these attempts. If entities decline to coordinate, that documentation demonstrates you made reasonable efforts to close visibility gaps. If they agree, you've built a fraud prevention capability that exceeds the baseline regulatory requirement.

Priority 3: Clarify internal reimbursement decision authority

Treasury hasn't published the cross-boundary liability chart, so you need to define your own decision framework. Who in your organization determines whether your institution is the "receiving bank" in a multi-party scam? What evidence threshold do you require before processing a victim reimbursement? What's your escalation path when liability is ambiguous? Codify this now, before the first enforcement action forces you to reverse-engineer your reasoning.

Priority 4: Build scenario-based testing for excluded platforms

Your control testing should include representative scenarios where scams originate on dating apps, move through messaging platforms, and request funds via crypto exchanges. Test whether your transaction monitoring flags these patterns when you can't see the relationship-building phase. If your controls fail these tests, document the visibility constraints and escalate the gap as a residual risk your current tooling can't address.

Priority 5: Track Treasury guidance and code updates

The framework's ambiguities might get resolved between now and March 2027, or they might not. Assign someone to monitor Australian Treasury announcements, banking code revisions, and ASIC enforcement actions. If Treasury publishes the liability chart Palla requested, that document becomes your compliance reference. If they don't, that absence becomes evidence that regulators left critical questions unanswered.

Topics:general

You Might Also Like