Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Dark navy graphic reading Scams Prevention Framework: The 1 September Deadline, with a shield deflecting an incoming payment line

Author: Dan Briggs  |  Published: 17 August 2026  |  Reading time: 17 minutes

Executive summary

On 1 September 2026, the first hard deadline in Australia’s Scams Prevention Framework takes effect. Every bank, telecommunications provider and digital platform that offers a regulated service must be a member of the Australian Financial Complaints Authority (AFCA) from that date, or face enforcement action including civil penalties.

That deadline does not apply to your business. The consequences of it absolutely do.

The Scams Prevention Framework Act 2025 received Royal Assent on 20 February 2025 and imposes six statutory obligations — govern, prevent, detect, disrupt, respond and report — on banks, telcos and digital platforms, with maximum penalties for a body corporate set at the greater of 159,745 penalty units (just over $50 million), three times the benefit obtained, or 30 per cent of adjusted turnover during the breach period. Most of those obligations start on 31 March 2027.

The part that matters to an Australian business owner is what happens after that date. From 31 March 2027, AFCA becomes the external dispute resolution body for scam complaints across all three sectors, and eligible small businesses — not just consumers — can escalate an unresolved scam complaint to AFCA and have it decide whether the bank, telco or platform failed to meet its obligations. AFCA has confirmed it can only consider complaints where the relevant matter occurs on or after 31 March 2027.

Australians reported $2.18 billion in scam losses in 2025 across 481,523 reports, according to the National Anti-Scam Centre’s Targeting Scams reporting — an increase of 7.8 per cent on 2024. The Australian Signals Directorate’s Annual Cyber Threat Report 2024–25 put the average self-reported cost of cybercrime for a small business at approximately $56,600 per report, and $97,200 for a medium business. Business email compromise resulting in financial loss accounted for 15 per cent of the top cybercrimes reported by businesses.

Between now and March 2027 there is a window. What you do in it determines whether a future scam loss is a write-off or a claim. This paper sets out what changes, who it covers, and the specific records and controls we recommend Australian businesses put in place now.

What actually changes on 1 September 2026

The 1 September obligation is narrow and administrative, which is why most business coverage has skipped it. Entities in the banking, telecommunications and digital platform sectors that provide a regulated service must be AFCA members from that date. The ACCC has said plainly that an entity which does not meet the AFCA membership obligation from 1 September may face enforcement action, including civil penalties. AFCA opened membership applications for the framework on 1 July 2026.

Administrative, but not trivial. Membership is the plumbing that makes everything else work. Without a compulsory dispute resolution scheme sitting behind the framework, the statutory obligations that begin on 31 March 2027 would be enforceable only by regulators, and regulators do not recover individual losses. The AFCA membership requirement is what converts the framework from a compliance exercise for large institutions into a mechanism an individual business can actually use.

The regulators and who watches whom

Three regulators share the work, and knowing which one covers which sector saves time later:

  • The ACCC is the general regulator for the framework, and the sector regulator for digital platforms.
  • The Australian Securities and Investments Commission is the sector regulator for banks.
  • The Australian Communications and Media Authority is the sector regulator for telecommunications providers.
  • AFCA is the external dispute resolution service, handling eligible scam complaints that are not resolved through a business’s internal dispute resolution process from 31 March 2027.

One practical consequence of the split: a typical invoice-redirection scam touches at least two regulated sectors. The email arrives through a platform, the phone call that confirms the fake bank details comes through a telco, and the money moves through a bank. If you end up in dispute, you may have grounds against more than one entity, and AFCA is the single door for all three.

What is still being written

As at the ACCC’s page update of 11 August 2026, the sector codes and the rules underpinning the framework were still being developed by government, following a Treasury consultation on draft codes and the first set of rules. That matters for how you plan. The direction of travel is fixed by legislation, but the operational detail — how quickly a bank must act on a scam report, what a telco must do about number spoofing, what a platform must do about a fraudulent advertisement — is being settled now. Anyone telling you exactly what your bank will be required to do for you in April 2027 is guessing at the specifics.

Who the framework regulates, and whether that includes you

The framework applies to entities providing regulated services in three designated sectors: banking, telecommunications and digital platforms. For the overwhelming majority of Australian SMBs and mid-market organisations, the answer is straightforward: you are not a regulated entity, you are a beneficiary.

Three exceptions are worth checking properly rather than assuming.

You resell telecommunications services. Managed service providers, IT firms and phone-system resellers that supply carriage services under their own brand should confirm their position. If you resell SIP trunks, mobile plans or a hosted PBX to end customers, work out whether you are supplying a regulated service in your own right or acting as an agent for a carrier.

You operate something that looks like a digital platform. Marketplaces, booking platforms, classifieds, and services that carry third-party paid advertising can fall closer to the digital platform definition than the operators expect. If your business runs a site where third parties list, advertise or transact with each other, get the definition checked rather than presumed.

You are a supplier to a regulated entity. This is the one we are already seeing bite. Where a client of ours provides services into a bank or a telco, scam-control questions have started appearing in supplier onboarding and annual assurance questionnaires. Nobody is required to make you answer them, but a regulated entity carrying $50 million penalty exposure will push obligations down its supply chain, and the questionnaires arrive well before the deadlines do. If you sell into the banking, telco or platform sectors, expect this in your next renewal cycle.

What it means when your business gets scammed

Here is the situation as it stands today, and it is worth being blunt about it because a lot of business owners believe otherwise.

If your bookkeeper pays $84,000 to bank details supplied in a spoofed supplier email, and the funds are gone by the time anyone notices, your practical options are limited. You report to your bank and hope a recall works. You report to Scamwatch and ReportCyber. You claim on cyber insurance if you hold a policy with social engineering cover, and many SMB policies either exclude it or sub-limit it heavily. Then you write it off.

The ePayments Code, which many owners have half-heard of, governs unauthorised electronic transactions for consumers. A payment your own staff member authorised, from a business account, is not an unauthorised transaction and is not covered. That is the single most common misunderstanding we encounter after a loss: the business assumes there is a code somewhere that makes the bank wear it, and there is not.

From 31 March 2027, the question changes. It stops being can we get the money back and becomes did the bank, the telco or the platform meet its statutory obligations to prevent, detect, disrupt and respond. If the answer is no, AFCA can consider the complaint and the framework contemplates compensation where obligations were breached.

Why that is a bigger shift than it sounds

Under the current arrangement, the burden sits entirely on the victim. You lost the money, you authorised the payment, the bank’s position is that it processed a valid instruction, and there is no forum with jurisdiction to test whether the bank’s scam detection should have flagged a first-time payment of $84,000 to a newly created account. From April 2027 there is such a forum.

The catch is evidentiary, and it is the reason this paper exists. AFCA will be assessing whether a regulated entity met its obligations in relation to a specific scam. That assessment depends on a factual record: what warnings appeared on screen, what the bank’s staff said on the phone, when you reported it, what the telco did about the spoofed number, how quickly the platform removed the fraudulent listing. Almost none of that is captured by default. Businesses that lose money to scams are, understandably, dealing with the loss rather than documenting it, and by the time anyone thinks about a complaint the screenshots are gone and nobody wrote down the time of the call.

In the incidents we work through with Australian clients, the pattern is consistent. The loss is discovered somewhere between five and thirty days after it happened, usually at bank reconciliation or when the genuine supplier chases an overdue invoice. By then the funds have been layered through mule accounts and recall is theoretical. What survives is whatever the business happened to keep. That is a fixable problem, and fixing it costs nothing.

The gap between now and 31 March 2027

There are roughly seven months between the AFCA membership deadline and the day the substantive obligations commence, and a further gap before the first determinations start to give the framework real shape. Three things are worth understanding about that period.

Nothing in the framework helps you retrospectively. AFCA has confirmed it will not have jurisdiction over complaints where the relevant matters occur before 31 March 2027. A scam that hits your business in November 2026 sits under the old rules permanently. If you are currently in dispute with a bank over a scam loss, the framework will not rescue that dispute.

The sector codes will define what good looks like. Once codes are registered, they establish the concrete expectations against which a regulated entity is measured. That is the document to read when it lands, because it tells you what you are entitled to expect from your own bank and telco and, by extension, what an AFCA complaint would need to demonstrate.

Your own controls are the only thing under your direct control. A framework that lets you recover a portion of a loss after a two-year dispute is a poor substitute for not losing the money. The businesses that come through this well will be the ones that treat the framework as a backstop rather than a plan.

The scam evidence pack: what to capture in the first 48 hours

This is the practical recommendation we are giving clients now, and it is the part of this paper we would keep if we could keep only one section.

Write a one-page procedure, put it where your finance staff can find it, and make it the first thing anyone does when a payment turns out to be fraudulent. It should sit alongside your incident response process, not inside it, because the person discovering the loss is usually a bookkeeper rather than an IT contact.

Capture immediately

  • The original email or message in full, with headers. Not a forward and not a screenshot of the body. Export the message with internet headers intact, because the headers are what demonstrate spoofing or account compromise. In Outlook this is File, then Save As, then choosing the .msg format.
  • Every screen the person saw during the payment. Including the confirmation screen and any warning the bank displayed or failed to display. Whether a bank presented a payee-verification warning, and what it said, will be squarely relevant to whether it met its detect and disrupt obligations.
  • Payee details exactly as entered, including the account name typed, the name the bank returned if confirmation-of-payee was in play, the BSB, the account number and the reference.
  • Call records. Time, date, number dialled or received, the name the caller gave, what they asked for, and what the business did. If your phone system records calls, mark that recording for retention immediately so it is not overwritten by a retention policy.
  • Timestamps for everything. When the payment was made, when the loss was discovered, when the bank was called, who you spoke to, what reference number they gave, and what they said they would do.

Report within 48 hours

  • Your bank’s fraud line, and get a reference number in writing by email as well as verbally.
  • Scamwatch, which feeds the National Anti-Scam Centre.
  • ReportCyber through cyber.gov.au, which generates a police report reference your insurer will want.
  • Your telco, if a spoofed number or a mobile port was involved.
  • The platform, if a fraudulent listing, advertisement or profile was part of the chain.
  • Your cyber insurer, within whatever notification period your policy specifies. Late notification voids more claims than any other single factor.

Preserve for at least seven years

Store the pack somewhere that is not the mailbox that was compromised. We recommend a dated folder in your document management system with restricted access, because mailbox retention policies and staff departures destroy this material with remarkable efficiency.

The reason for the seven-year horizon is simple. A scam occurring in April 2027 may become an AFCA complaint in 2028 and a determination in 2029. Nobody will remember what the screen said. The evidence pack is the difference between a complaint AFCA can assess and a complaint that reduces to your word against your bank’s system logs.

What this looks like in Central West NSW and on the Northern Beaches

The framework is national, but the exposure is not evenly distributed, and the difference shows up clearly across the markets we work in.

In Orange, Bathurst and Dubbo, the practical reality of the past several years has been branch consolidation. Business banking that used to involve walking a payment change into a branch and having it questioned by someone who knew the business now happens by app and by phone. That removes a control nobody ever wrote down: a teller who recognised a business owner and thought a $60,000 transfer to a new payee was odd. The telco leg of the scam chain is correspondingly more important for regional operators, because the phone is doing more of the work. Number spoofing, mobile porting and SIM swap all sit inside the telecommunications sector’s obligations from March 2027, and they are exactly the attacks that undermine a business relying on SMS codes.

There is a second regional pattern worth naming. A single mobile number frequently serves as the business’s public contact number — on the ute, on the website, in the Google listing — and as the second factor for banking and Microsoft 365. That combination is a targeting map. An attacker who wants to compromise the account already knows which number to port. Splitting those two functions is a half-hour job and one of the highest-value changes a small regional business can make. Our explainer on how vishing calls walk past MFA covers the mechanics.

Across Sydney, the exposure profile is different. Brookvale and the wider Northern Beaches skew towards trades, construction, hospitality and professional services, and the dominant loss pattern is invoice redirection at volume. A building company paying forty subcontractors a month has forty opportunities for a changed BSB to slip through, and the amounts are large enough to hurt and routine enough not to attract a second look. Hospitality operators face the platform leg more than the bank leg, with fraudulent booking confirmations and supplier impersonation around deliveries.

For Brisbane and Melbourne clients in professional services, the pressure point is trust and settlement money. A conveyancer, accountant or advice firm moving client funds carries an exposure that is not just financial: it is regulatory and reputational at the same time. We wrote about the Queensland council that lost $1.9 million to an AI-assisted payment scam, and the mechanism there is available to anyone targeting a firm that moves money on behalf of clients.

Your action checklist and timeline

The table below is the version to hand to whoever owns finance and whoever owns IT. Dates are drawn from the ACCC and AFCA published positions as at August 2026.

When What happens What your business should do
Now — September 2026 Regulated banks, telcos and platforms complete AFCA membership Write the one-page scam evidence procedure. Store it outside email. Brief finance staff.
1 September 2026 AFCA membership obligation takes effect for regulated entities Confirm your business bank and your telco are AFCA members. Ask in writing and keep the answer.
September — December 2026 Sector codes and rules finalised by government Read the code covering your bank and telco when registered. Note what you can expect from them.
Q4 2026 Move payment approvals to dual authorisation. Enable phishing-resistant MFA. Separate your public number from your authentication number.
Q1 2027 Regulated entities finalise scam controls Run a payment-fraud tabletop with finance staff. Confirm cyber insurance covers social engineering and check the sub-limit.
31 March 2027 Substantive SPF obligations commence. AFCA scam jurisdiction opens. From this date, activate the evidence pack for every scam attempt, successful or not.
After 31 March 2027 Eligible small businesses can escalate unresolved scam complaints to AFCA Exhaust the entity’s internal dispute resolution first, in writing, then escalate.

The seven questions to answer this month

  1. Who in this business can move money, and how many people have to agree before it leaves the account?
  2. What is our documented process when a supplier emails to change their bank details, and does it require an outbound call to a number from our own records rather than the email?
  3. Is our cyber insurance policy’s social engineering cover a real limit or a token sub-limit, and what is the notification window?
  4. If a fraudulent payment went out this afternoon, who would notice, and when?
  5. Are we still using SMS codes for banking or Microsoft 365 sign-in, and what would a mobile port do to us?
  6. Where would the evidence pack be stored, and does it survive the compromise of a single mailbox?
  7. Do we know, in writing, that our bank and our telco are AFCA members?

The controls that stop the loss happening at all

The framework is a backstop. These are the controls that mean you never need it, ordered by the ratio of protection to effort as we see it across Australian client environments.

Dual authorisation on payments above a threshold

Set the threshold at a number that hurts — for most SMBs somewhere between $5,000 and $20,000 — and require a second person to release the payment. The second approver must have independent visibility of the payee, not just a click-to-approve prompt on a phone. This single control defeats most invoice redirection, because it requires the attacker to compromise two people rather than one.

Callback verification on any change to payment details

Any request to change a supplier’s bank details triggers a phone call to a number held in your own supplier master file, never a number from the email requesting the change. Document the call. This is the control most frequently written down and least frequently followed, and the failure mode is always the same: it is Friday afternoon, the supplier is chasing, and someone skips it. Making the callback a field in the payment approval workflow rather than a policy in a manual is what makes it stick.

Phishing-resistant multi-factor authentication

SMS and voice codes are the weakest common factor and are being retired across major platforms. Move business-critical sign-in to passkeys or an authenticator app with number matching. Our breakdown of how modern phishing kits steal Microsoft 365 logins and walk past MFA explains why the type of second factor matters more than having one at all.

Mailbox rule monitoring

Almost every business email compromise involves an inbox rule that hides the attacker’s tracks by moving supplier replies to a rarely checked folder. Alerting on new forwarding and move rules in Microsoft 365 is inexpensive and catches compromise during the reconnaissance phase, before any money moves. Our guide to business email compromise in Australia covers the detection settings in detail.

Supplier master file discipline

Restrict who can change bank details in your accounting system, turn on change logging, and review the change log monthly. In most SMB accounting setups every user with access can silently edit a supplier’s account number, and nobody looks at who changed what.

Domain protections

Publish SPF, DKIM and DMARC records with an enforcing DMARC policy so criminals cannot send email that appears to come from your domain. This protects your customers and suppliers from being scammed in your name, which is both an ethical obligation and a reputational one. Register lookalike domains where the cost is justified.

Telco account hardening

Put a port-out lock and an account PIN on every mobile number used for authentication or business banking. Ask your telco what verification it requires before a port, and keep the answer. From March 2027, the telco’s handling of a fraudulent port becomes directly relevant to a complaint, and the ACMA SMS Sender ID Register has already changed how business texts are treated in Australia.

Frequently asked questions

Does the Scams Prevention Framework apply to my business?

Almost certainly not as a regulated entity. The framework applies to entities providing regulated services in the banking, telecommunications and digital platform sectors. If you resell carriage services, operate a marketplace or advertising platform, or supply into a regulated entity, check your position properly rather than assuming, because supplier assurance questionnaires from regulated entities are already circulating.

What actually happens on 1 September 2026?

Entities in the banking, telecommunications and digital platform sectors that provide a regulated service must be members of the AFCA dispute resolution scheme from that date. The ACCC has stated that entities failing to meet the membership obligation may face enforcement action including civil penalties. The substantive obligations to prevent, detect, disrupt, respond, report and govern begin on 31 March 2027.

If we lose money to an invoice scam today, can we complain to AFCA?

Not under the Scams Prevention Framework. AFCA can only consider complaints under the framework where the relevant matters occur on or after 31 March 2027. A loss occurring before that date falls under the arrangements that exist today, which for an authorised business payment offer very limited recourse.

Will the bank have to refund us if we authorised the payment ourselves?

Not automatically. The framework does not create a guaranteed reimbursement right. What it creates is a statutory standard the bank must meet and a forum that can decide whether it met that standard in your case. If AFCA finds the bank breached its obligations, compensation is contemplated. If the bank did everything required and your staff member still approved the payment, that finding is unlikely to go your way. The ePayments Code, which some owners assume protects them, covers unauthorised consumer transactions and does not apply to a payment your own staff authorised from a business account.

What should we do first if money has already gone out the door?

Call your bank’s fraud line immediately and ask for a recall, then get the reference number confirmed in writing. Preserve the original email with its full internet headers, screenshots of every payment screen, and a written timeline with timestamps. Report to Scamwatch and to ReportCyber at cyber.gov.au, notify your cyber insurer within the policy’s notification window, and change the credentials on any mailbox that may have been accessed. Do not delete the fraudulent email.

Where to go from here

The Scams Prevention Framework is a genuine improvement, and it will take years to show what it is worth. In the meantime the arithmetic has not changed: the cheapest scam is the one that fails at the callback, and the most expensive is the one nobody documented.

If you want a second set of eyes on your payment controls, your Microsoft 365 configuration or your evidence-capture procedure before March 2027, we work with businesses across Sydney, Brisbane, Melbourne and Central West NSW on exactly this. Call All IT Services on 1300 425 548 or get in touch through our contact page. A payment-fraud review takes about an hour and generally pays for itself the first time someone picks up the phone instead of paying the invoice.

Sources