Scam Complaints Will Test Your Evidence Trail Before March 2027

Regulatory Strategy  ·  October 2026  ·  Australia

AFCA will hear Scams Prevention Framework complaints from March 2027. What banks, telcos and digital platforms should be able to show across fraud and identity controls.

Scams Prevention Framework evidence will be tested from March 2027. Australia’s Scams Prevention Framework (SPF) puts banks, telecommunications providers and digital platforms inside one complaints system for the first time. Regulated entities in those sectors had to be members of the Australian Financial Complaints Authority (AFCA) from 1 September 2026, and AFCA has consulted on the rules it proposes to use for SPF scam complaints from 31 March 2027, the date most framework obligations also begin.

Much of the commentary has focused on compensation limits. For fraud and risk leaders, the more immediate issue is evidential. An SPF scam complaint is likely to involve several organisations, and each will need to show what its own controls did at each point in the scam. If that evidence is spread across fraud, identity, payments and complaints systems that were never designed to be read together, it will be slow to assemble and easy to contest.

This article separates what is settled from what is still proposed, then maps the records your controls should already be leaving behind. It is general information, not legal advice.

Scams Prevention Framework evidence visual showing a scam event across platform, telecommunications and banking controls, and the evidence each control should record

A scam event can cross a digital platform, a telecommunications provider and one or more banks. Each control along the way should leave a record that can be linked to the same event.

1

Lure or contact

A platform or telco carries the advertisement, call or message.

2

Account and session

Identity, due diligence and fraud signals are generated before payment.

3

Payment and warning

Authentication outcomes, warnings and customer acknowledgements are recorded.

4

Intervention and complaint

Holds, calls, recovery attempts and dispute steps follow.

Quick answer

AFCA has consulted on rules to hear Scams Prevention Framework complaints from 31 March 2027, and a single complaint may involve a platform, a telecommunications provider and one or more banks. Each entity will need to show what its own controls did, and when. Linking fraud, identity, payments and complaints records to one scam event makes that evidence faster to assemble and harder to contest.

What is settled and what is still proposed

Some parts of the framework are in place, while others are still being consulted on or developed. ASIC’s Scams Prevention Framework overview summarises the commencement dates.

Element Position Status
AFCA membership Entities in banking, telecommunications and digital platforms that provide a regulated service had to be AFCA members from 1 September 2026. Most SPF obligations start on 31 March 2027. Settled
External dispute resolution AFCA has been the authorised external dispute resolution (EDR) scheme for SPF complaints since 1 July 2026. Settled
AFCA scam rules AFCA’s consultation on its proposed scam rules ran from 31 August to 28 September 2026. AFCA expects to publish final rules in early 2027, subject to ASIC approval. Proposed
Compensation limit The proposed limit for direct financial loss is $1,263,000 per scam complaint. It would apply once per scam regardless of how many regulated entities are involved, and AFCA could apportion an award between them. Proposed
Sector codes and SPF rules Still being developed by government. Treasury’s earlier exposure draft rules included internal dispute resolution and record-keeping requirements, and a government position paper proposed automatic reimbursement of verified losses below $3,000 and equal sharing of liability between entities found to have breached their obligations. In development

Any of the proposed elements may change. The evidence question does not depend on the final numbers, which is why it is worth working on now.

Why multi-party complaints change the evidence problem

AFCA’s consultation anticipates complaints in which a platform carried the advertisement, a telecommunications provider carried the call or message, and one or more banks moved the money. That is a different shape from most complaints AFCA handles today, and it changes three things.

Each entity answers for its own conduct

Evidence that another party missed a warning sign does not substitute for evidence of what your controls did. If liability is apportioned, the share an entity carries will depend on what it can show about its own actions.

Sequence and timing matter

Showing that a warning was displayed, a payment was paused or an account was flagged is only useful if the record shows when, relative to the customer’s actions and to information received from other parties.

The scam event is the unit of analysis

Most fraud, payments and complaints systems are organised around accounts, transactions, cases or tickets. A multi-party complaint asks what happened across the whole scam. Few organisations can answer that from one place.

What a multi-party complaint could involve

Consider the shape AFCA’s consultation anticipates: a scam advertisement on a platform, a call or message carried by a telecommunications provider, and payments moved by one or more banks.

Each entity would need to produce its own part of the record:

  • The platform: reports received, detection and takedown actions, and timestamps.
  • The telecommunications provider: scam filtering actions and timestamps for the call or message.
  • The sending bank: session signals, the risk score and logic version, the authentication outcome, warnings shown and any intervention.
  • The receiving bank: onboarding and monitoring evidence for an account suspected of mule activity.

Mapping Scams Prevention Framework evidence across controls

The table maps the stages of a typical scam to the control domain involved, the record an organisation should be able to produce, and the gap that most often makes it hard to produce.

Scam stage Control domain Record to be able to produce Common gap
Lure or first contact Platform trust and safety; telecommunications scam filtering (for those sectors) Reports received, detection and takedown actions, timestamps Held by a separate team and not linked to later complaints
Account opening or access Identity verification; customer due diligence Verification method and result at onboarding; due diligence on receiving accounts suspected of mule activity Receiving-account evidence sits in AML systems, not in the scam case
Session before payment Fraud detection Device, location and behavioural signals, the risk score and the rule or model version that produced it Scores retained, but not the version of the logic in force at the time
Payment instruction Payments and authentication Authentication outcome (for card payments, the 3D Secure result), warnings or confirmations shown, customer acknowledgements No record of which version of a warning the customer actually saw
Intervention Scam interdiction Holds, outbound calls, outcomes and staff notes Call records and notes stored outside the case system
After the event Reporting, recovery and complaints Information shared with other entities, recovery attempts, internal dispute resolution steps and dates Complaint handling tracked in a separate system with no link to control evidence

Two items that are easy to overlook

Most of the table is familiar. These two items are where evidence packs most often fall short.

Version control Fraud rules, models and customer warnings change frequently. An organisation that cannot show which version applied on the day will struggle to show its controls were reasonable at that time.
The receiving side When a bank’s account is used to receive scam proceeds, its onboarding and monitoring evidence may matter as much as the sending bank’s.

Building one event view without rebuilding your stack

None of this requires a single new platform. It requires agreement on how evidence is linked and kept.

01

Define a scam event identifier

Attach it to records in fraud, payments, identity, AML and complaints systems, so evidence can be gathered by event rather than by account.

02

Keep the versions of rules, models and warnings

Retain the versions in force at each point in time, with change dates.

03

Set retention with legal advice

Final SPF record-keeping requirements are not yet settled, so use the draft rules as a baseline and revisit them when the codes and rules are made.

04

Run a dry run

Take three recent scam cases, assemble the evidence pack each would need for a multi-party complaint, and time how long it takes and which teams were involved.

05

Name an internal coordinator

Appoint one coordinator for multi-party complaints, so that responses to AFCA reflect one organisational view rather than several team views.

06

Set a review trigger

Review when AFCA’s final rules and the SPF codes are published, expected in early 2027.

Where this sits in enterprise fraud strategy

The SPF will make visible something many organisations already know: fraud, identity, payments and complaints controls generate evidence independently, and nobody owns the joined-up record. Treating scam evidence as an enterprise asset, rather than a by-product of each control, is likely to pay off before the first complaint arrives, because the same linked view also improves detection and investigation.

Proposed figures may change

The $1,263,000 compensation limit, the $3,000 automatic reimbursement proposal and equal sharing of liability are proposals, not settled rules. Re-check them when AFCA publishes its final rules and government makes the SPF codes and rules.

How Nexiant supports Scams Prevention Framework evidence

Nexiant brings together specialist capabilities across identity verification, AML screening, transaction monitoring and payment authentication. Risk leaders can use the evidence map above to test where scam-relevant records are produced across those controls, and where the links between them are missing.

Questions to ask before March 2027

The evidence map translates into a short set of questions for fraud, payments and complaints leaders:

  • Can you gather every record for one scam event, rather than one account or one case?
  • Can you show which version of a fraud rule, model or customer warning applied on the day?
  • Can you produce onboarding and monitoring evidence for accounts that received scam proceeds?
  • Are intervention call records and staff notes linked to the case system?
  • Is complaint handling linked to the control evidence behind it?
  • Who coordinates your response when a complaint involves other regulated entities?

A dry run on a few recent cases is the quickest way to find out.


Frequently Asked Questions

AFCA has consulted on rules that would let it consider SPF scam complaints from 31 March 2027, the date most framework obligations begin. Final rules are expected in early 2027, subject to ASIC approval.
The first designated sectors are banking, telecommunications and digital platforms. Entities in those sectors that provide a regulated service had to be AFCA members from 1 September 2026.
AFCA has proposed a limit of $1,263,000 per scam complaint for direct financial loss, applying once per scam however many regulated entities are involved. This is a proposal and may change.
No. The sector codes and further SPF rules are still being developed by government, so organisations should use the draft rules as a baseline and review their retention settings when the final instruments are made.
For each stage of a scam, an organisation should be able to show what its own controls did and when. That includes detection and takedown actions, identity verification results, fraud signals with the version of the rule or model in force, authentication outcomes and warnings shown, interventions, and internal dispute resolution steps.

Connect your scam control evidence

Speak with a Nexiant expert about connecting fraud, identity and financial crime evidence across your scam controls.

Speak to our fraud prevention team

This article was accurate at the time of publication in October 2026 and is intended for general informational purposes only. It does not constitute legal, regulatory or compliance advice. Organisations should seek qualified professional guidance in relation to their specific obligations.