Skip to main content
Banks Pay the Fine, Platforms Walk FreeFraud Typologies
4 min readFor Bank Information Security Officers

Banks Pay the Fine, Platforms Walk Free

Australian bank fraud teams, compliance officers, and payment security leads have spent the last eight months grappling with the Scams Prevention Framework, set to take effect in March 2027. They're the ones facing penalties of up to $52.7 million per violation, while scams originate on platforms that owe victims nothing under the same law. These aren't theoretical concerns; they're real issues raised in incident reviews, executive briefings, and cross-functional meetings as you try to build controls around a regulatory gap you can't close.

Q1: Are dating apps really excluded from this framework?

Yes. Dating and matchmaking platforms are currently outside the regulated digital-platform category under the Scams Prevention Framework. This exclusion is significant because romance scams often move beyond their starting point. A scammer builds trust inside the app, then shifts the conversation to WhatsApp or Telegram. By the time money changes hands, the platform where the manipulation began has no visibility into what happens next and, under this framework, no legal obligation to prevent it or reimburse the victim.

Your bank, however, does have that obligation. You're regulated. The app isn't.

Q2: What about crypto exchanges? They're where a lot of scam funds end up.

Crypto exchanges and crypto ATMs are also excluded. The Australian Securities and Investments Commission reported 3,106 crypto investment scams over the past financial year, a 30% increase. This happened while the exclusion list remained unchanged, even after industry feedback highlighted crypto platforms as a gap.

If a victim sends funds to a crypto exchange based on a scam involving your institution, you're potentially liable for reimbursement. The exchange that received the money isn't.

Q3: How does liability work when a scam crosses from a regulated entity to an unregulated one?

No one knows for sure, and that's the problem. Ken Palla, a fraud expert and former director at MUFG Union Bank, submitted detailed feedback to Treasury in January asking for guidance on liability and recovery when a scam moves through multiple entities, some regulated and some not. Consider a scam that starts with a phishing email, routes through an excluded non-bank payment provider, and lands at an excluded international receiving bank. Who reimburses the victim? Who's responsible for detection at each stage?

At Treasury's June information session, officials stated that receiving banks would be responsible for compliance and reimbursement. However, the term "receiving bank" doesn't appear in the banking sector's code provisions. The chart Palla requested still doesn't exist. You're expected to comply with a framework that hasn't defined how cross-entity liability resolves.

Q4: What's our legal exposure if we can't stop a scam that started elsewhere?

Up to $52.7 million per contravention. That's the statutory maximum penalty under the framework. Your compliance obligation doesn't decrease because the scam originated on an unregulated platform. You don't get partial credit because the victim was manipulated elsewhere before the transaction hit your systems.

You're responsible for transaction monitoring, filing Suspicious Activity Reports (SARs), and making customer reimbursement decisions under your internal policies and the framework's requirements. The platform where the scam began? It has no such burden.

Q5: Can we get better intelligence sharing from the platforms where scams originate?

Not under this framework. There's no requirement for unregulated platforms to share scam intelligence with banks, and no standardized mechanism for them to do so even if they wanted to. Your fraud detection models are trying to catch manipulation that happened days or weeks earlier on a platform you can't access, using behavioral signals you don't have.

Some platforms do share threat intelligence voluntarily, but it's inconsistent and often comes too late to prevent the transaction. You're building transaction-monitoring rules around patterns that may have already shifted by the time you see them in your data.

Q6: What can we do to reduce our exposure while these gaps exist?

Start with what you can control. Enhance your customer education programs around common scam types: romance scams, crypto investment fraud, business email compromise. Ensure your transaction-monitoring rules flag rapid changes in customer behavior, like new payees, sudden international transfers, and first-time crypto purchases above a threshold.

Document every scam case in detail to show you followed your procedures. If you're facing a potential penalty review, your defense will rest on whether you had reasonable controls in place and applied them consistently, not whether you stopped every scam that touched an unregulated platform before reaching you.

Push for industry coordination. If your peer banks are seeing the same patterns from the same excluded platforms, that's evidence worth aggregating and submitting to Treasury. The 30% increase in crypto scams that ASIC reported didn't come from nowhere; it came from a regulatory gap that multiple parties flagged and that remains unaddressed.

And if you're building a business case for additional fraud-prevention investment, frame it around the penalty exposure you're carrying that other parts of the scam chain aren't. Your executive team needs to understand that you're absorbing liability for a problem you can only partially control.

Where to go for more

Treasury's Scams Prevention Framework documentation is your starting point, but it won't answer the cross-entity liability questions that matter most. Track ASIC's quarterly scam reports for trend data on the excluded platforms. If you're part of an industry working group, use it. The regulatory ambiguity around receiving-bank liability and cross-border recovery won't get resolved without sustained, coordinated industry pressure.

And if you're preparing for March 2027, assume you're operating under the framework as it exists now, not as you hope it might change. Build your controls, document your decisions, and be ready to explain why you did what you did with the visibility you had.

You Might Also Like