Australia's Scams Prevention Framework takes effect in March 2027, imposing penalties of up to $52.7 million per violation for banks. However, the framework excludes the platforms where most scams originate and the channels through which they complete. If you're building compliance for this framework, you're preparing for a law that holds you liable for transactions you didn't initiate and can't see until the money is already gone.
Why These Mistakes Keep Happening
Regulatory exclusions are deliberate choices influenced by political compromise, lobbying, and an incomplete understanding of fraud across organizational boundaries. The Australian Treasury received detailed industry feedback identifying these gaps months before finalization. This feedback included scenarios showing how scams move from unregulated platforms into regulated ones, leaving banks to absorb both the liability and the reimbursement cost. Treasury acknowledged the problem verbally but never published the cross-sector liability chart the industry requested. The exclusions remain.
This pattern repeats because regulators often regulate entities, not fraud typologies. They write rules for banks because banks have compliance teams and balance sheets. They skip dating apps and crypto exchanges because those sectors lack unified regulatory frameworks or are considered too difficult to bring into scope quickly. The result is a law that assigns blame based on who can be regulated, not who enabled the harm.
Mistake 1: Treating Platform Exclusions as Someone Else's Problem
Why it happens: Your compliance team sees "dating apps excluded" and moves on because your organization isn't a dating app. The exclusion feels irrelevant to your control environment.
Real consequence: Romance scams don't stay on dating platforms. A scammer builds trust inside the app, moves the conversation to WhatsApp or Telegram, then requests a bank transfer or crypto payment. By the time your fraud monitoring flags the transaction, the relationship has been manipulated for weeks on a platform that has no obligation to detect or report the scam. You're liable for reimbursement. The platform that facilitated the initial contact isn't.
The fix: Map the full scam lifecycle for the top three fraud types hitting your institution right now. Identify every platform, app, and intermediary involved before the transaction reaches you. For each unregulated entity in that chain, document what visibility you don't have and what control gap it creates. Use this map in your March 2027 readiness brief to executive leadership. They need to understand that compliance with this framework doesn't mean you can prevent the scams it's designed to address.
Mistake 2: Assuming "Receiving Bank" Liability Is Clearly Defined
Why it happens: Treasury confirmed verbally in June that receiving banks would be liable for both compliance and reimbursement. Your legal team assumes that means the framework's banking code provisions spell out what a receiving bank must do.
Real consequence: The term "receiving bank" doesn't appear in the banking sector's code provisions. There's no published guidance on how liability works when a scam crosses from a regulated organization into an unregulated one, then back into a regulated one. If a victim sends money through an excluded non-bank payment provider to an excluded international receiving bank, who reimburses? The framework doesn't say. Fraud expert Ken Palla asked Treasury for a chart showing exactly this in January. It still doesn't exist.
The fix: Don't wait for regulatory clarity that may never arrive. Draft your own internal liability matrix covering every scenario where funds exit your institution, pass through an excluded entity, and reach a destination you can't control. For each scenario, assign a provisional liability assumption (you reimburse, you don't, you split cost with another regulated entity). Share this matrix with your legal and finance teams now. When the first dispute arrives in April 2027, you'll have a decision framework instead of scrambling to interpret a silent regulation.
Mistake 3: Ignoring the Crypto Gap While Scam Volumes Climb
Why it happens: Crypto exchanges and crypto ATMs are outside the framework. Your fraud monitoring flags crypto transactions as high-risk, but you assume that's enough because the exchange itself will eventually get regulated.
Real consequence: The Australian Securities and Investments Commission reported pulling down 3,106 crypto investment scams over the past financial year, up 30% from the prior year. The industry objected to the crypto exclusion eight months ago. The numbers keep climbing. Meanwhile, you're on the hook if your customer sends money to one of these scams, but the exchange that accepted the fraudulent deposit has no obligation to reimburse, monitor, or even respond to your investigation request.
The fix: Implement a two-tier control for crypto transactions. First tier: real-time friction. Any transaction to a crypto exchange or ATM triggers a mandatory customer callback with scripted questions about the recipient's identity and the purpose of the payment. Don't rely on automated warnings the customer will click through. Second tier: post-transaction monitoring. Flag all crypto transactions for manual review within 24 hours. If the customer reports a scam within 72 hours, you have evidence you applied enhanced due diligence even though the framework didn't require the exchange to do the same.
Mistake 4: Accepting Verbal Assurances Without Written Guidance
Why it happens: Treasury provides verbal confirmation during an online information session. Your compliance lead takes notes and reports back that the question was answered. The team moves forward as if the answer is now policy.
Real consequence: Verbal assurances aren't enforceable. They don't appear in examination manuals, dispute resolution procedures, or court filings. When you're facing a $52.7 million penalty, "Treasury said so in June" won't hold up if the written regulation is silent or contradictory. Palla followed up multiple times after his January submission asking for written guidance on cross-sector liability. He still hasn't received it.
The fix: Every time you receive verbal regulatory guidance, send a written follow-up within 48 hours summarizing what you understood and asking for written confirmation. If you don't get it, document that you asked and didn't receive a response. This creates a record showing you acted in good faith based on the information available. More importantly, it forces the regulator to either commit in writing or reveal that the policy isn't actually settled.
Mistake 5: Building Compliance Without Building Advocacy
Why it happens: Your job is to comply with the framework as written, not to lobby for changes. You focus on controls, monitoring, and documentation because that's what you can control.
Real consequence: If every regulated bank complies silently with a framework that doesn't work, the framework never improves. The exclusions remain. The liability imbalance persists. Your fraud losses climb while unregulated platforms face no consequences. Treasury has shown it won't revisit exclusions without sustained pressure, even when the data proves the exclusions are failing.
The fix: Compliance and advocacy aren't separate functions under a flawed framework. Join or form an industry working group focused specifically on the platform exclusions. Collect data on every scam your institution processes where an excluded entity was involved. Quarterly, submit that data to Treasury with specific requests: add dating apps to the digital platform category, define receiving bank liability in writing, bring crypto exchanges into scope. Make your compliance lead responsible not just for meeting the framework's requirements but for documenting why those requirements aren't sufficient.
Prevention Checklist
- Map the full scam lifecycle for your top three fraud types, identifying every unregulated entity involved before transactions reach you
- Draft an internal liability matrix covering scenarios where funds pass through excluded entities
- Implement mandatory customer callbacks for all crypto transactions, not just automated warnings
- Send written follow-ups within 48 hours of any verbal regulatory guidance, asking for written confirmation
- Document every scam involving an excluded entity and submit quarterly summaries to Treasury with specific regulatory requests
- Assign one senior compliance or fraud lead to track platform exclusion advocacy, not just internal controls
- Prepare an executive brief for March 2027 explaining what compliance with this framework does not prevent
- Review your fraud monitoring rules to ensure they flag transactions to excluded entities for enhanced manual review
- Establish a response protocol for scams that cross regulated and unregulated boundaries, including evidence collection and dispute escalation procedures
The framework you're preparing for in March assigns you the liability without giving you the visibility. That's not a compliance problem you can solve with better controls. It's a structural problem that requires both operational adaptation and sustained regulatory pressure. Build for both.



