The Conventional Wisdom
When scams occur, the prevailing thought is that banks should be responsible. This logic underpins many new scam prevention frameworks: banks handle the money, have advanced fraud detection systems, and should intercept fraudulent transactions. If they fail, they're liable. Australia's new Scams Prevention Framework even imposes penalties of up to $52.7 million per contravention on banks and telecoms when scams succeed.
This seems logical. Banks are regulated entities with established compliance programs, making them the obvious enforcement point. Apply enough financial pressure, and they'll enhance their controls.
Why This Approach Falls Short
This perspective misunderstands modern scams. It treats fraud as a single-platform issue when it's a cross-platform operation.
Consider the process: a scammer creates a fake persona on a dating app, builds trust over weeks, shifts the conversation to WhatsApp, then requests money through a crypto exchange or non-bank payment provider. By the time funds reach a regulated bank, the victim has been manipulated through several unregulated touchpoints. The bank sees a customer initiating what appears to be a legitimate transfer. The dating app where the scam began? Excluded from regulation. The crypto exchange where funds exit? Also excluded. The digital wallet that facilitated the transfer? Excluded.
You're expected to detect and prevent a scam whose manipulation phase occurred in systems you can't monitor, using platforms that owe the victim nothing under the law.
Fraud expert Ken Palla highlighted this issue with the Australian Treasury in January, seeking guidance on liability and reimbursement when scams cross from regulated to unregulated entities. Eight months later, that guidance is still absent. At Treasury's June information session, when Palla asked if receiving banks would be liable for compliance and reimbursement, Treasury verbally confirmed they would. Yet, "receiving bank" isn't mentioned in the banking sector's code provisions. You're held accountable under incomplete rules.
The Evidence
The Australian Securities and Investments Commission reported 3,106 crypto investment scams last financial year, a 30% increase. Crypto exchanges and crypto ATMs remain outside the Scams Prevention Framework. The industry flagged this exclusion as problematic before the framework was finalized. The numbers now validate their concerns.
This isn't a theoretical risk. When your SOC 2 Type II auditor asks how you're managing fraud detection controls, you can't point to a control monitoring activity on platforms you don't operate. When your ISO/IEC 27001 lead auditor reviews your risk treatment plan for financial fraud, you can't claim you've reduced likelihood when the attack vector is outside your control environment.
The framework creates a compliance paradox. You're expected to design preventive controls for threats that materialize in someone else's system. You're expected to maintain evidence of control effectiveness for scenarios where you have no visibility into the initial compromise. You're expected to demonstrate reasonable assurance when the regulatory structure itself excludes the platforms where scams begin.
What to Do Instead
First, document the gap in your risk register. Create a specific risk entry: "Liability for scams originating on unregulated platforms where the organization has no monitoring capability." Rate it as you would any risk where likelihood is outside your control but impact is severe. Your lead auditor will ask why you're accepting this risk rather than treating it. Your answer: the regulatory framework itself creates the gap, and you've escalated the issue to legal and executive leadership.
Second, build informal information-sharing arrangements with the platforms your customers use. You can't regulate a dating app, but you can ask if they'll share fraud indicators when they identify suspicious accounts. You can't force a crypto exchange to join your fraud detection program, but you can document that you requested cooperation. When the framework eventually expands (and it will, once enough banks are penalized for scams they couldn't see), you'll have evidence that you tried to close the gap before you were required to.
Third, adjust your customer communication controls. If you can't monitor where the scam starts, you can still warn customers before they complete the transfer. Implement transaction friction for high-risk payment patterns: first-time crypto transfers, payments to new international beneficiaries, unusual amounts to digital wallet providers. ISO/IEC 27001 Clause 7.4 (Communication) and SOC 2 CC2.3 (Communication with External Parties) both support this. You're not stopping the transaction, you're ensuring the customer has confirmed intent.
Fourth, lobby. If you're preparing for the March 2027 effective date and you're based in Australia, your compliance team should coordinate with your government affairs or legal team to submit feedback on the framework's exclusions. Palla's January submission asked Treasury for a chart showing how liability works across mixed scenarios. That chart still doesn't exist. Your auditor will want to see evidence that you've raised the issue with the regulator, not just accepted an impossible compliance position.
When the Conventional Wisdom Is Right
Banks should be liable when they miss red flags in their own systems. If your transaction monitoring rules are poorly tuned, if your customer due diligence is weak, if you're ignoring obvious fraud indicators because stopping the transaction would hurt your Net Promoter Score, you deserve the penalty.
The conventional wisdom is correct when the scam is detectable at the point where you have control. If a customer's account shows a sudden pattern of large transfers to known fraud destinations and your monitoring system flags it but your operations team overrides the alert without adequate justification, that's a control failure you own.
The framework is right to hold banks accountable for their own controls. It's wrong to hold them accountable for controls they can't implement because the regulatory scope deliberately excludes the platforms where the fraud begins.
Your job as a compliance manager isn't to argue that banks should never be liable. It's to document where your controls end and the regulatory gap begins. When your next audit asks how you're managing cross-platform fraud risk, the honest answer is: "We're not, because half the platforms in the scam chain aren't regulated yet."



