Australia fintech platform regulation

Australia's Scams Prevention Framework Starts With a Complaints Body, and a Flat A$3,000 Refund Rule Deserves Scrutiny

AFCA membership became mandatory on 1 September 2026. The draft A$3,000 reimbursement default shows where the framework's design risks lie.

Australia's SPF draft rules at a glance People of Internet Research · Australia A$3,000 Auto-reimbursement threshold Draft default for verified scam lo… 200,000+ Platform user threshold Monthly active Australian users. A$1B+ Platform revenue threshold Global revenue test for platforms. £85,000 UK scheme ceiling UK APP fraud reimbursement limit. peopleofinternet.com
Australia's SPF draft rules at a glanc… People of Internet Research · Australia A$3,000 Auto-reimbursemen t threshold 200,000+ Platform user threshold A$1B+ Platform revenue threshold £85,000 UK scheme ceiling peopleofinternet.com

Key Takeaways

What changed on 1 September

On 1 September 2026, the first hard obligation of Australia's Scams Prevention Framework (SPF) took effect. Banks, telecommunications providers and digital platforms that provide a regulated service must be members of the Australian Financial Complaints Authority (AFCA). The ACCC says non-compliance may bring enforcement action, including civil penalties. The framework's substantive duties to prevent, detect, disrupt, report and respond to scams follow on 31 March 2027. Cyber Daily reports that AFCA will be the sole external dispute resolution scheme for scam-related complaints, and that it expects to start handling those complaints on 31 March 2027.

Three regulators will oversee the regime. The ACCC is the general regulator and the digital platforms regulator, ASIC covers banking and ACMA covers telecommunications. Treasury's consultation package, which opened on 27 May 2026, contains draft common codes, sector codes for banks, telcos and platforms, draft SPF rules and a position paper on internal dispute resolution. Submissions to that package closed on 25 June 2026, according to Treasury's consultation page. AFCA is separately consulting on the rules it will need to handle scam complaints. The hook for this piece puts the close of that consultation at 28 September 2026.

The strongest case for the framework

The case for this regime is real. Scam losses fall on people who are rarely at fault in any meaningful sense. Banks, telcos and large platforms are the only parties positioned to see a scam across its whole path: the advert or SMS, the account, the payment. Voluntary industry codes left that coordination problem unsolved. A single external dispute scheme with a clear duty on each sector gives victims a defined place to go and gives firms a reason to invest in prevention. That is a defensible design goal, and AFCA's existing standing in financial disputes makes it a credible forum.

Where proportionality gets tested

The draft rules reveal the harder questions. According to Ashurst's summary of the draft package, the proposal is automatic reimbursement of verified scam losses under A$3,000, with the cost split equally among entities found to have breached the framework. The position paper is quoted as saying that ministerial guidance will make clear that entities should reimburse consumers for losses under that figure.

A flat threshold has virtues: it is predictable, cheap to administer and spares small-loss victims a long investigation. But it has two design risks.

First, equal cost-splitting among breaching entities is blunt. A platform that missed one ad-review step and a bank that ignored clear fraud signals could pay the same share. Liability that does not track causation blunts the incentive to invest in the controls that actually stop scams. It also encourages disputes over who else "breached".

Second, a default refund rule can move behaviour on the consumer side. If small losses are refunded automatically, verification of the reimbursement claim becomes the entire control. Fraudsters and first-party abusers will test that boundary. Firms will respond by tightening account opening and payment friction for everyone, which costs legitimate users and new fintech entrants most.

The comparison with the UK is instructive. Ashurst notes the Australian threshold sits far below the ceiling of the UK's authorised push payment fraud scheme, which it puts at £85,000. A lower figure limits exposure and is arguably the more proportionate choice. But it also means larger losses go through AFCA determinations, so the quality of AFCA's benchmarks matters more than the headline threshold does. Ashurst says AFCA determinations will be guided by compliance with the SPF codes, and that the SPF will take priority over other frameworks, including the ePayments Code.

Scope: who is actually caught

The digital platform definition is deliberately narrow. Ashurst reports the draft applies to services meeting both an Active Australian User Test of 200,000 or more monthly users and a revenue test of A$1 billion or more in global revenue. That is a sensible guard against burdening start-ups, and it should be kept. Two questions remain. One is whether the thresholds will be reviewed as smaller platforms become scam vectors. The other is whether pushing scammers toward services just below the line produces displacement rather than protection. Regulators should measure that displacement, not assume it away.

What regulators should do before 31 March 2027

The hook reports penalties of up to A$50 million per contravention. Penalties at that scale, combined with the private right of action that law-firm commentary describes, make ambiguity expensive. That argues for specific things.

Bottom line

The 1 September step is administratively modest and sensible: build the complaints channel before the duties bite. The real policy will be set by the AFCA rules and the final reimbursement guidance. If those reward genuine prevention and keep costs proportionate, Australia can cut scam losses without pushing friction onto every legitimate payment. If they do not, the framework will tax honest users and small entrants for harms that large, well-resourced actors are better placed to stop.

Sources & Citations

  1. ACCC: Scams Prevention Framework
  2. Treasury: SPF codes and rules exposure draft
  3. Ashurst: SPF draft rules and codes released
  4. Cyber Daily: AFCA to become central scams complaints body