What happened

Australia's Scams Prevention Framework, which takes effect in March 2027, puts banks and telecoms on the hook for penalties of up to $52.7 million per contravention. But the regulated list has deliberate exclusions: dating and matchmaking apps sit outside the regulated digital-platform category, as do digital wallets, crypto exchanges, crypto ATMs and non-bank payment providers.

The gaps matter because scams do not stay inside one channel. A romance scam builds trust inside a dating app, then moves the victim to WhatsApp or Telegram, and the money can exit through an excluded exchange or land at an excluded international receiving bank. The platform where the manipulation began has no visibility into what happens next and, under the framework, no obligation to have any.

Fraud expert Ken Palla, a retired MUFG Union Bank director, has raised exactly this problem with the Treasury: the framework has no clear picture of how a victim gets reimbursed once a scam crosses from a regulated organization into an unregulated one. He asked Treasury to publish a chart showing how liability and recovery work across those scenarios. Months later, and after multiple follow-ups, the chart still does not exist. Treasury confirmed verbally in June that receiving banks would be on the hook for both compliance and reimbursement, yet the term receiving bank appears nowhere in the banking sector's own code provisions. Meanwhile ASIC took down 3,106 crypto investment scams over the past financial year, up 30% year on year, and crypto remains outside the framework.

Why this is a GRC story

This is the compliance trap of liability without visibility. The entities carrying the penalty bear obligations for a chain they do not control, while the links where the manipulation actually happens owe the victim nothing. For compliance teams, the lesson is to map the full fraud chain before accepting obligations, and to get the regulator's answer in writing, not as a verbal confirmation at an information session.

The other lesson is that exclusions can quietly persist. Eight months after industry objections, Treasury has shown no sign of revisiting the list, and the enforcement numbers keep proving the objectors right. If you are preparing for the framework as a bank or telecom compliance lead, your plan needs to account for the unregulated middle of the chain, because that is where the recovery questions will land.

What to watch

Watch whether Treasury revisits the exclusions before March 2027 and whether the reimbursement chart Palla requested finally appears. Watch how banks operationalize the receiving-bank obligations they were verbally told they hold, since the code provisions do not yet define the term.

The ASIC takedown numbers are the pattern to track: if crypto scam takedowns keep climbing while crypto stays outside the framework, the pressure to close the gap will only grow, and compliance teams should expect the rules to move.

Attribution: Analysis based on DataBreachToday's reporting and related public reporting. This article is original commentary, not a repost of the source material.

More daily case studies
← Back to GRC News