Field Notes · daily AI intelligence for Australian business
← Field Notes

AI Compliance & Regulation

Australia's Scam Law Now Covers Your Small Business

The Scams Prevention Framework switched on 1 September 2026 — $50m fines force banks, telcos and platforms to stop scams, and your small business is a protected consumer.

Australia's biggest scam law just switched on — and you're covered

From 1 September 2026, banks, telcos and digital platforms in Australia are required by law to stop scams — prevent, detect, disrupt, report and respond — or face civil penalties of up to $50 million per breach. The ACCC calls it a world-first, and it exists because scams cost Australians $2.18 billion in 2025. The part most owners have missed: your small business is a protected 'consumer' under it.

What the Scams Prevention Framework actually does

The Scams Prevention Framework (SPF) passed Parliament in February 2025. Its operating rules commenced on 1 September 2026, and the substantive sector codes phase in from 31 March 2027. It designates three sectors — banking, telecommunications and digital platform services — and puts five legal duties on the businesses in them: prevent, detect, disrupt, report and respond to scams. Three regulators share enforcement — the ACCC as general regulator, ASIC over banking, and ACMA over telcos.

The teeth are real. Non-compliance carries civil penalties of up to $50 million per contravention for the most serious breaches. And from 31 March 2027, a scam complaint a bank, telco or platform doesn't resolve internally can be escalated to the Australian Financial Complaints Authority (AFCA) — which every regulated entity must now belong to.

$50m

Maximum penalty per breach

Tier 1 contravention

3 regulators

Enforcing the framework

ACCC, ASIC, ACMA

<100 staff

Still a protected 'SPF consumer'

and under $10m turnover

Why your small business is a protected consumer

Here's the detail that turns this from someone else's compliance headache into your leverage. The framework defines an 'SPF consumer' as a natural person or a small business — one with fewer than 100 employees and under $10 million in turnover — provided one of these regulated services. That's most trades businesses and professional firms in the country. It means the protections, and the complaint rights, are yours.

More than that: consumers, small businesses included, can commence proceedings directly for damages when a regulated entity breaches its duties. So if your bank, telco or a digital platform fails to act on a scam it should have caught, you're no longer a bystander to a regulator's case — you have standing of your own. AI is why the law had to exist: the same tools that clone a voice or spin up a fake storefront industrialised scams to the point that voluntary codes couldn't hold the line.

If you're not sure which of your providers and platforms this now covers — or where a scam could still reach your accounts — a short call will map it.

Already using software that touches this? A 30-minute check maps which of these rules apply to your business.

Book the AI check

Where the framework stops — and your controls take over

Read the fine print before you relax. The SPF makes designated entities accountable for scams that run through their systems. It does not reimburse a business that was tricked into authorising a payment itself. That's precisely the fraud draining Australian firms right now: payment redirection, which cost businesses $166.8 million in 2025, where a fake-but-fluent invoice or a cloned voice convinces someone to send real money to a criminal's account. Because you approved the transfer, no bank breached a duty — so the framework's protections don't reach it.

This is a cost intelligence problem hiding as a compliance one. The law shifts genuine risk onto the big platforms, which is good news — but it draws a bright line around the fraud that still lands on you. The controls that catch that fraud cost nothing: never change a supplier's or an employee's bank details on an email or call alone, verify every change by ringing back on a number you already had, and require a second approver on any payment above a threshold you set.

What to do about it

Two moves. First, use the new leverage: if a scam reaches your business through a bank, telco or platform, you now have a documented complaint path to AFCA from March 2027 and, in a serious case, standing to seek damages — so keep records of every scam report you file and the provider's response. Second, close the gap the law leaves open. Write the callback-and-second-approver rule into your accounts process this week, because that's the fraud no regulator will refund. Knowing which risks are now someone else's, and which stay yours, is the whole game.

Key takeaways

01The Scams Prevention Framework's operating rules commenced 1 September 2026, requiring banks, telcos and digital platforms to prevent, detect, disrupt, report and respond to scams — with civil penalties up to $50 million per breach, enforced by the ACCC, ASIC and ACMA.
02Small businesses (under 100 employees and under $10 million turnover) are 'SPF consumers' — protected, able to escalate unresolved complaints to AFCA from 31 March 2027, and able to seek damages directly for a breach.
03The framework covers scams routed through designated entities; it does not reimburse a business that authorised a payment to a fraudster — the payment-redirection fraud that cost Australian businesses $166.8 million in 2025.
04Callback verification and a second approver on payments are still your defence for the fraud the law leaves with you.

Common questions

Does the Scams Prevention Framework protect my small business?

Yes. A business with fewer than 100 employees and under $10 million turnover is an 'SPF consumer', so the framework's protections and complaint rights apply to you when a regulated bank, telco or digital platform is involved.

What happens if a bank or platform breaches the framework?

From 31 March 2027 you can escalate an unresolved scam complaint to AFCA, and consumers — small businesses included — can commence proceedings directly for damages. The entity itself faces civil penalties of up to $50 million per contravention.

Does the framework cover invoice or payment redirection scams?

Not where you were tricked into authorising the payment yourself. The framework targets designated banks, telcos and platforms; an authorised business payment sits outside it, so callback verification and a second approver remain your defence.

Sources

Assumptions & methodology
  1. Last reviewed 26 September 2026. General information, not legal advice.
  2. The $50 million figure is the headline maximum for a Tier 1 (most serious) contravention. The Act expresses the cap as the greatest of a fixed penalty, a multiple of the benefit derived, or a proportion of the entity's adjusted turnover, so the effective maximum can be higher for a large corporation.
  3. The 'SPF consumer' definition — a natural person or a small business with fewer than 100 employees and under $10 million annual turnover — and the private right of action to seek damages are set out in the Scams Prevention Framework Bill 2024 and its Explanatory Memorandum, as summarised by Australian law firms (Gadens; Lexology).
  4. The $2.18 billion total and $166.8 million payment-redirection figures are National Anti-Scam Centre / ACCC Targeting Scams 2025 data, published 30 March 2026.
ShareLinkedInEmail

Field Notes are general commentary on AI trends for Australian businesses. They don’t constitute professional advice. Talk to your accountant, lawyer, or IT adviser before acting on anything specific to your situation.

If this applies to you

Not sure which scam risks are now covered — and which are still yours?

A short call maps where scams could reach your business, what the new framework now protects, and where a simple verification step belongs. Book a call to talk it through.

Don't miss the next one

Get each new Field Note in your inbox as it publishes — short, practical AI intelligence for business owners.