rulesmate.com.au — Compliance reference
https://rulesmate.com.au/insights/scams-prevention-framework-designated-sectors-duties
Printed 28 August 2026
Scams Prevention Framework: designated sectors and the six SPF principles
Which businesses the Scams Prevention Framework designates, the six SPF principles from govern to respond, the regulators, the key dates and the penalties.
Where the Scams Prevention Framework stands as at August 2026
The Scams Prevention Framework is law and the first sectors have been formally designated, but the substantive scam-handling duties do not commence until 31 March 2027.
Three things have already happened. First, the Scams Prevention Framework Act 2025 (No. 15, 2025) received assent on 20 February 2025 and the whole Act commenced on 21 February 2025. It does not stand alone: it inserts a new Part IVF into the Competition and Consumer Act 2010 (Cth). Second, the Competition and Consumer (Scams Prevention Framework—Regulated Sectors) Designation 2026 was made on 28 May 2026, designating the first regulated sectors and their sector regulators. Third, the ACCC has confirmed the operative dates: entities providing regulated services must be members of an authorised external dispute resolution scheme from 1 September 2026, and the framework obligations apply from 31 March 2027 (ACCC, checked August 2026).
What has not happened is equally important. The Act empowers the Minister to make sector-specific SPF codes, and those codes carry much of the operational detail — what counts as reasonable steps, what a report must contain, and what timeframes apply. Treasury has consulted on draft codes and rules. Before you build a control to a specific code requirement, confirm on the Federal Register of Legislation that the code for your sector has actually been registered. Do not treat an exposure draft as law.
Which businesses are designated
Three sectors are designated at the first stage: banking, telecommunications and digital platforms.
The Designation 2026 instrument sets out the designation for each sector separately, and defines the digital platform services caught — designated instant messaging services, internet search services and social media services. That scope is narrower than "any online business": a retailer running an e-commerce site is not a designated digital platform simply because it takes payments online.
| Sector | Broad scope of regulated services |
|---|---|
| Banking | Banking services supplied to consumers and small business |
| Telecommunications | Telecommunications services within the designated sector definition |
| Digital platforms | Designated instant messaging, internet search and social media services |
If your business sits outside these three sectors, the SPF principles do not apply to you at this stage. That is not a reason to ignore scams: telecommunications providers already carry separate obligations under the industry code on reducing scam calls and scam SMS, and every business remains exposed to payment-redirection fraud, invoice fraud and business email compromise regardless of designation.
Who regulates what
The ACCC is the SPF general regulator, and each sector has its own SPF sector regulator.
- ACCC — SPF general regulator for the overarching principles, and the sector regulator for digital platforms. See the ACCC profile.
- ASIC — SPF sector regulator for banking. See the ASIC profile.
- ACMA — SPF sector regulator for telecommunications. See the ACMA profile.
The split matters in practice. The general regulator enforces the SPF principles in Part IVF; the sector regulator enforces the SPF code for that sector. A single incident can therefore attract attention from two regulators applying two different instruments to the same facts.
The six SPF principles
Part IVF sets six overarching principles: govern, prevent, detect, report, disrupt and respond.
The simplified outline in section 58AB of the Act describes the principles as covering governance arrangements relating to scams, and preventing, detecting, reporting, disrupting and responding to scams. Each principle is built out in its own Subdivision of Division 2, and each contains one or more civil penalty provisions.
| Principle | What it requires, in substance |
|---|---|
| 1. Govern | Documented governance policies, procedures, metrics and targets for combatting scams, reviewed and certified by a senior officer at least annually, with records kept |
| 2. Prevent | Reasonable steps to prevent scams relating to, connected with or using your regulated services |
| 3. Detect | Reasonable steps to detect activities that are or may be scams |
| 4. Report | Reports of actionable scam intelligence to the SPF general regulator, plus scam reports on request from an SPF regulator |
| 5. Disrupt | Reasonable steps, within a reasonable time, to disrupt an activity and prevent loss or harm arising from it |
| 6. Respond | An accessible reporting mechanism for consumers, an accessible and transparent internal dispute resolution process, published information about both, and membership of an authorised external dispute resolution scheme |
Principle 1 is the one most often underestimated. It is not satisfied by a policy document alone: the Act contemplates documented policies, procedures, metrics and targets, senior-officer certification, record-keeping and compliance reporting.
Reporting, disrupting and responding in practice
The report, disrupt and respond principles are where most operational build work lands.
Reporting (Subdivision E, sections 58BQ to 58BV). A regulated entity must report actionable scam intelligence to the SPF general regulator within the period, and in the manner and form, prescribed by the SPF rules, containing the information those rules prescribe. Separately, an SPF regulator may issue a written request for a report about a specific scam, and failing to provide it within the period and in the form set out in the request is a civil penalty contravention. Section 58BU makes a duty of confidence owed under an agreement of no effect to the extent it is contrary to those reporting sections.
Disrupting (Subdivision F, sections 58BW to 58BZA). Where an entity has actionable scam intelligence, it must take reasonable steps within a reasonable time to disrupt the activity or prevent loss or harm arising from it. The steps taken should be proportionate to the intelligence held. The Act gives an example: a bank that has received a substantial number of similar reports of suspicious activity may find it appropriate to pause or delay authorised push payments while it investigates.
Responding (Subdivision G). The entity must have an accessible mechanism for consumers to report suspected scams, an accessible and transparent internal dispute resolution mechanism for complaints about scams or about the entity's own conduct, published information about both, and membership of an authorised external dispute resolution scheme. Firms already running an RG 271 complaints process under ASIC's internal dispute resolution standard should treat the SPF respond duty as an extension of that machinery, not a parallel system. Our explainer on AFCA complaints handling for financial firms covers how external dispute resolution fits together.
Penalties, safe harbour and private actions
Tier 1 contraventions carry a maximum penalty for a body corporate of the greater of 159,745 penalty units, three times the benefit obtained, or 30% of adjusted turnover during the breach turnover period.
Section 58FK sets that formulation for contraventions of civil penalty provisions of an SPF principle in Subdivisions C, D, F or G of Division 2. Penalty units are indexed: the ACCC records that the value of a penalty unit increased to $364 on 1 July 2026 (ACCC fines and penalties, checked August 2026), which puts 159,745 penalty units at roughly $58.1 million per contravention on current values. Because the unit value moves with indexation, model the exposure rather than quoting a fixed dollar figure — our penalty estimator does that arithmetic.
Three further features shape the risk profile:
- Safe harbour (section 58BZA). An entity is not liable in a civil action for taking action to disrupt an activity, provided the action is taken in good faith, in compliance with the SPF provisions, is reasonably proportionate, is taken during the window starting when the intelligence becomes actionable and ending when the entity reasonably believes the activity is or is not a scam or after 28 days, whichever is earlier, and is promptly reversed if the entity identifies the activity is not a scam and reversal is reasonably practicable.
- Private right of action (section 58FZC). A victim who suffers loss or damage from conduct contravening a civil penalty provision of an SPF principle or code may recover that loss from the contravening entity. An SPF regulator may bring the claim on the victim's behalf with written consent.
- Other enforcement tools. Infringement notices carry a 28-day compliance period (section 58FT). Enforceable undertakings (section 58FV) and injunctions (section 58FW) are also available.
What designated businesses should be doing now
With obligations commencing 31 March 2027 and external dispute resolution membership required from 1 September 2026, the sequencing is already tight.
- Confirm designation. Read the Designation 2026 instrument against your actual service lines rather than assuming your sector label answers the question.
- Secure external dispute resolution membership ahead of the 1 September 2026 date, and check whether your existing scheme membership covers scam complaints.
- Stand up the governance artefact. Documented policies and procedures, scam metrics and targets, an annual senior-officer certification, and a records regime that can evidence all of it.
- Define actionable scam intelligence internally and map where it currently sits — fraud systems, complaints, frontline reports, threat feeds.
- Build the reporting pipe to the SPF general regulator and rehearse the response to an ad hoc scam report request.
- Write the disruption playbook, including the proportionality test, the 28-day safe harbour window and the reversal trigger.
- Publish the consumer-facing reporting and complaints mechanisms, and train staff to recognise a scam complaint as a complaint.
- Track code registration for your sector and re-baseline your control set when the code is made.
What the framework does not do
The framework does not make a designated entity liable for every scam loss, and it does not replace existing consumer protection law.
Liability under Part IVF attaches to contravening the principles and codes, not to the fact that a customer was scammed. Equally, the framework sits on top of the Australian Consumer Law rather than displacing it — misleading conduct, unfair contract terms and consumer guarantees continue to apply in the ordinary way. See the Australian Consumer Law and consumer protection topic for that wider picture, and the Commonwealth's Scamwatch service for the consumer-facing reporting channel.
This article is a reference summary, not legal advice. Confirm the current status of the designation instrument and any sector code before relying on a specific obligation.
Frequently asked
Has the Scams Prevention Framework commenced?
The Scams Prevention Framework Act 2025 commenced on 21 February 2025 and inserted Part IVF into the Competition and Consumer Act 2010. The first sectors were designated by an instrument made on 28 May 2026. The ACCC states that external dispute resolution membership is required from 1 September 2026 and that the framework obligations apply from 31 March 2027.
Which businesses are designated under the SPF?
Banking, telecommunications and digital platforms. The digital platforms designation covers designated instant messaging services, internet search services and social media services — not every business with a website.
Who enforces the Scams Prevention Framework?
The ACCC is the SPF general regulator for the overarching principles and the sector regulator for digital platforms. ASIC is the sector regulator for banking and ACMA for telecommunications.
What are the six SPF principles?
Govern, prevent, detect, report, disrupt and respond. Each is built out in its own Subdivision of Division 2 of Part IVF and each contains civil penalty provisions.
What is the maximum penalty under the SPF?
For a tier 1 contravention by a body corporate, section 58FK sets the maximum as the greater of 159,745 penalty units, three times the benefit obtained, or 30% of adjusted turnover during the breach turnover period. The penalty unit value rose to $364 on 1 July 2026, so the unit-based limb is indexed rather than fixed.
Is there protection for a business that wrongly blocks a legitimate transaction?
Section 58BZA provides a safe harbour from civil liability where disruptive action is taken in good faith, in compliance with the SPF provisions, is reasonably proportionate, is taken within the window ending when the entity reasonably believes the activity is or is not a scam or after 28 days (whichever is earlier), and is promptly reversed if the activity turns out not to be a scam and reversal is reasonably practicable.
Related
Related reading
AFCA complaints handling for financial firms in 2026
AFCA complaints handling for financial firms in 2026: how the AFCA scheme works, RG 271 IDR timeframes, who must be a member, and how to avoid common compliance failures.
Telecommunications Consumer Protections Code C628 — 2025 update
How the ACMA-registered TCP Code (C628) sets the consumer protection obligations carriers and CSPs must meet, and what changed in the 2025 update.
ePayments Code 2022: ASIC's Updated Consumer Protections for Electronic Payments
ASIC published the updated ePayments Code on 2 June 2022 (mandatory from 2 June 2023), covering mistaken internet payments, unauthorised transactions, NPP payments and complaints handling.
Card surcharging for Australian merchants: what you can recover, and the 2026 reform
Card surcharging rules for Australian merchants as at August 2026: the excessive surcharge ban, what costs you may recover, and the removal of surcharging from 1 October 2026.
Obligations covered
Free tools
© Rules Mate · Source citations at the end · Information current as at 28 August 2026
Printed from https://rulesmate.com.au/insights/scams-prevention-framework-designated-sectors-duties