Business Insight

AFCA Scam Rules: 10 key takeaways to prepare for the new complaint regime 

Close-up of a modern glass skyscraper facade with teal reflective panels and golden structural elements in urban light

    What you need to know

    • On 31 August 2026, AFCA released its consultation on the proposed 'Scam Rules', being the framework governing the rules and processes that apply to AFCA complaints under the Scams Prevention Framework (SPF) for the regulated banking, digital platform and telecommunications sectors from 31 March 2027.
    • Key changes from AFCA's current Complaint Resolution Scheme Rules – which for now only apply to registered financial institutions – include changes to the direct financial loss compensation cap with a new limit of $1,263,000 per scam, a new multi-party complaint framework, and the removal of the automatic referral back to the regulated entity to consider whether a resolution can be achieved prior to AFCA determination.
    • AFCA’s jurisdiction now also extends to suspected scam activity. There is also a prohibition on non-disclosure clauses in binding release agreements, which means all determinations will now be publicly available.
    • With the majority of the SPF obligations commencing 31 March 2027, the draft Scam Rules foreshadow AFCA's proposed framework for resolving financial liability and apportionment as the single external dispute resolution body for the SPF. The Scam Rules will operate alongside the yet-to-be released liability apportionment guidelines that Treasury has foreshadowed will be contained in the Competition and Consumer (Scams Prevention Framework) Rules 2026 (SPF Rules).

    What you need to do

    • Assess your exposure: The changes in compensation limits will have a material impact on which customers can access compensation and the financial impact to the regulated entity. Regulated entities should model and assess the financial impact and make sure that these financial provisions are accounted for.
    • Evidence base: The SPF obligations will require regulated entities to map and evidence their compliance with SPF obligations. The Scam Rules are yet another reminder of the operational complexities that need to be addressed before the majority of SPF obligations go live on 31 March 2027. In particular scam processes must be documented, auditable and ready for multi-party complaints.
    • Consultation: Regulated entities are able to make submissions on the Scam Rules given the operational and financial consequences of the ultimate EDR framework. Those submissions close 28 September 2026, and details can be found here. AFCA conducted a webinar on 3 September 2026 for stakeholders, which can be watched here.
    • Stay up to date: Monitor the release of the final parts of the SPF Rules (including the liability framework and Statement of Compliance obligations) which are yet to be registered, as well as AFCA's Operational Guidelines in early 2027. We will keep you updated as those events unfold.

    The consultation package

    Regulated entities were required to join AFCA by 1 September 2026 – an obligation that carries civil penalties for non-compliance. But AFCA membership is only part of the process, and the proposed Scam Rules released on 31 August 2026 as part of a consultation package now reveal what that membership will mean in practice. For example, the proposed Scam Rules detail how complaints will be handled, how liability will be apportioned (alongside the yet-to-be released liability apportionment provisions in the SPF Rules), and what financial exposure regulated entities may face.

    The consultation package includes the proposed AFCA Scam Rules, proposed amendments to AFCA's existing Compensation Resolution Scheme Rules (now relabelled as the 'Financial Firm Rules'), a comparative list of all changes and an explanation of corresponding Financial Firm Rule amendments. Operational Guidelines will be developed and released for consultation feedback in early 2027.

    With the majority of SPF obligations going live from 31 March 2027, the proposed Scam Rules represent a further development in the SPF’s shift from policy to practice. We set out below our top 10 takeaways for regulated entities.

    1. Compensation limits have changed

    Under the existing Compensation Scheme Rules, most claims for direct financial loss are capped at $631,500, though certain categories (for example, superannuation complaints and certain guarantor claims) are uncapped or have higher limits.

    The proposed Scam Rules take a uniform approach, with the direct financial loss compensation limit capped at $1,263,000 per scam, regardless of complainant or complaint type, aligning compensation with AFCA’s monetary jurisdiction limit. The table below sets out the proposed limits.

    Type of claimCompensation limitJurisdiction limit
    Direct financial loss
    $1,263,000 per scamMust not exceed $1,263,000
    Indirect financial loss$6,300 per regulated entityN/A
    Non-financial loss$12,600 per regulated entityN/A
    Legal / professional / travel costs$5,000 per regulated entityN/A

    2. Scam Rules are designed for multi-party complaints

    AFCA expects most scam complaints will involve more than one regulated entity. The Scam Rules give AFCA the power to add, remove and coordinate complaints between multiple regulated entities in respect of a single complainant, and to apportion liability between two or more entities having regard to the SPF Rules. The worked examples in the Consultation Paper are illustrative of how these powers would operate in practice.

    Regulated entities can expect to be drawn into complaints initiated against other SPF regulated entities. The apportionment power means that liability can be split across the scam ecosystem – bank, telco and digital platform – within a single process. However, the liability apportionment guidelines to be prescribed in the SPF Rules have not yet been released, leaving a significant gap for entities assessing their multi-party exposure. Internal complaint processes must be coordinated, well-documented and capable of withstanding external scrutiny.

    3. SPF complaints are not limited to actual scams

    The Scam Rules do not require a confirmed scam to have occurred for AFCA to consider liability. Scam Rule 1.4.3 mirrors the SPF legislation and allows AFCA to consider complaints about a regulated entity's conduct in responding to suspected scam activity – including suspected scams, attempted scams, and situations initially believed to be scams but later determined not to be. This means a customer who suffers loss from an account freeze or transaction hold based on suspected (but unconfirmed) scam activity may bring a complaint to AFCA regardless of whether a scam actually occurred. Complainants may also be able to lodge complaints with AFCA sooner as they will not be required to wait for definitive evidence that a scam has occurred before seeking compensation.

    This will create tension in practice as regulated entities are required by the SPF to disrupt suspected scam activity, but may face complaints if premature blocking or holding of payments cause loss or harm to customers where the activity turns out not to be a scam. Processes for responding to suspected scams – including account freezes, transaction holds and customer communications – need to be carefully calibrated to minimise complaint risk, even where the entity is acting in good faith.

    4. AFCA can request "reasonable assistance" from any AFCA member regulated entity

    Under the proposed Scam Rules, AFCA can request reasonable assistance from any member entity, even if that entity is not a party to the complaint – for example, a digital platform that has separately settled a complaint may still be required to provide information relevant to a customer's complaint against their bank and/or telco. This is a significant departure from the current regime, and member entities should establish systems for their compliance and legal teams to be able to deal with the likely uptick in information requests that will flow once the SPF EDR obligations commence.

    5. AFCA has discretion to deal with a SPF complaint immediately (removal of automatic refer-back)

    Unlike the Financial Firm Rules, the Scam Rules give AFCA discretion to commence dealing with a complaint immediately where the regulated entity has already had the opportunity to consider and respond through IDR. Where IDR has not yet occurred, AFCA will generally allow up to 30 days for the entity to respond (noting this timeframe may be subject to change once the SPF Codes and Rules are finalised). The automatic refer-back process has been removed for SPF complaints.

    This is one of the more consequential operational changes in the Scam Rules. Since AFCA will not automatically refer escalated complaints back to the regulated entity for reconsideration, IDR processes must be robust, well-resourced and capable of producing a comprehensive response that adheres to SPF obligations on first instance.

    6. AFCA must report systemic issues to both the ACCC and the sector-specific regulator

    Under the current framework, AFCA may report any identified systemic issues to ASIC. The Scam Rules expand this obligation to include both the SPF General Regulator (the ACCC) and any applicable SPF Sector Regulator. This dual reporting obligation means that patterns in complaint outcomes such as repeat failures in scam detection or response are more likely to attract regulatory attention from multiple directions, placing a premium on proactive compliance monitoring and remediation.

    7. Complainant eligibility is assessed at the time of the scam conduct, not the time of complaint

    The Scam Rules assess a complainant's eligibility based on their circumstances at the time of the scam conduct, not when the complaint is lodged. The definitions of "SPF Consumer" and "Small Business Operator" reflect the legislative definitions in the Competition and Consumer Act (where the SPF legislation is contained in Part IVF).

    For example, a small business with fewer than 100 employees and annual turnover under $10 million at the time the business is impacted by the scam would be eligible to bring a complaint, even if its revenue subsequently increased above the threshold by the time the complaint is made. Regulated entities cannot rely on a complainant's current financial position to challenge eligibility.

    This ensures access to EDR is not affected by subsequent changes in circumstances and provides a wider window for complaints. Entities should factor this into their assessment of potential claim exposure, particularly for complaints that may be lodged well after the relevant conduct.

    8. AFCA must exclude complaints about conduct before 31 March 2027

    The Scam Rules apply only to conduct that occurs on or after 31 March 2027 and AFCA must exclude complaints about conduct that pre-dates commencement. For example, a complaint lodged in July 2027 about an investment scam where the relevant digital platform ad appeared in January 2027, the scammer called in February 2027, and funds were transferred in April 2027 would only proceed against the bank as the digital platform and telco conduct occurred before 31 March 2027. Of course, complaints related to banks prior to 31 March 2027 can be considered under the Financial Firm Rules.

    9. Decision-making guided by the Competition and Consumer Act, SPF Codes and SPF Rules

    AFCA decision-makers will be guided by a broader set of reference points under the Scam Rules, including the SPF part of the Competition and Consumer Act, the SPF Codes and the SPF Rules. AFCA can apportion liability between regulated entities having regard to the liability guidelines in the SPF Rules (yet to be released), and AFCA determinations will be published identifying regulated entities - noting, non-disclosure clauses cannot be included in binding release agreements.

    Over time, published determinations will build a body of public guidance, with adverse outcomes visible to the market, competitors and regulators. This transparency shift should be factored into settlement and litigation strategy as complainants will be able to draw on the publicly available determinations to strengthen their potential complaints.

    10. Scam Rules retain similar discretionary exclusions, with new SPF-specific additions

    The Scam Rules retain the existing discretionary exclusions for frivolous or vexatious complaints, complaints better suited to another forum, and matters already dealt with. However, the Scam Rules also introduce new SPF-related exclusions, including complaints:

    • about a regulated entity's practice or policy where there is no allegation of error or failure to meet SPF obligations. The purpose is to distinguish between complaints about compliance with SPF obligations (which AFCA can consider) and complaints that seek review of commercial decisions in their own right (which AFCA cannot consider); and
    • submitted by suspected scammers, being a secondary scam and fraud protection mechanism that is a welcome safeguard for regulated entities.

    A forward-looking addition is Scam Rule 1.12, which gives AFCA discretion to control the format, length and presentation of submissions. The consultation paper indicates that this is responding in part to the increasing use of GenAI tools that can generate voluminous or repetitive material.

    Where to from here

    The Scam Rules are a material development that inform the way regulated entities should operationalise their IDR and EDR systems and processes. Critically, the SPF Rules detailing the liability apportionment guidelines are yet-to-be released, and the AFCA Operational Guidelines should be released in early 2027. We are also waiting on the final SPF Codes to be registered to understand what changes Treasury has made since they were released in draft for consultation in May 2026.

    Consultation on the Scam Rules closes on 28 September 2026, with SPF Code and Scam Rules obligations commencing on 31 March 2027. Some actions regulated entities should be taking right now include:

    • Review the consultation package in detail and consider making a submission by 28 September 2026. We are available to assist.
    • Assess IDR capacity as automatic refer-back has been removed for SPF complaints. AFCA has discretion to commence EDR immediately where IDR has already occurred, or to progress complaints sooner where fairness or efficiency warrant it.
    • Prepare for multi-party complaints by ensuring that you have systems and processes that are able to effectively document your entity's compliance with its SPF obligations. Evidence of compliance will be critical if AFCA is trying to resolve and/or apportion liability between multiple parties.
    • Model the financial impact of the revised compensation limits, particularly for entities with material scam complaint volumes. Entities should consider the extent to which their standard operating procedures and complaint resolution processes require amendment to take into account the prohibition against non-disclosure clauses.
    • Monitor Treasury's release of the updated SPF Rules and registration of final SPF Codes. The SPF Rules should include the liability apportionment guidelines, and the final SPF Codes will set out the precise obligations following Treasury’s consultation earlier this year.

    Want to know more?

    Authors: Felicity Healy, Partner; Jonathan Perkinson, Partner, Risk Advisory; Josh Krechman, Senior Associate and Lucy Lennon, Lawyer. 

    This publication is a joint publication from Ashurst Perkins Coie Australia and Ashurst Perkins Coie Risk Advisory Pty Ltd, which are part of the Ashurst Perkins Coie Group.

    Ashurst Perkins Coie Australia (ABN 75 304 286 095) is a general partnership constituted under the laws of the Australian Capital Territory.

    Ashurst Perkins Coie Risk Advisory Pty Ltd is a proprietary company registered in Australia and trading under ABN 74 996 309 133.

    The Ashurst Perkins Coie Group comprises Ashurst Perkins Coie UK LLP, Ashurst Perkins Coie US LLP, Ashurst Perkins Coie Australia and their respective affiliates (including independent local partnerships, companies or other entities) which are authorised to use the name "Ashurst Perkins Coie" or describe themselves as being affiliated with Ashurst Perkins Coie. Some members of the Ashurst Perkins Coie Group are limited liability entities. Some members of the Ashurst Perkins Coie Group provide legal services and some provide non-legal services. Different legal entities in the group may operate in the same jurisdictions. Information about which Ashurst Perkins Coie Group entity operates in any country can be found on our website at www.ashurstperkinscoie.com.

    The services provided by Ashurst Perkins Coie Risk Advisory Pty Ltd do not constitute legal services or legal advice, and are not provided by qualified legal practitioners acting in that capacity. The laws and regulations which govern the provision of legal services in the relevant jurisdiction do not apply to the provision of non-legal services.

    This material is current as at 25 September 2026 but does not take into account any developments after that date. It is not intended to be a comprehensive review of all developments in the law or in practice, or to cover all aspects of those referred to, and does not constitute professional advice. The information provided is general in nature, and does not take into account and is not intended to apply to any specific issues or circumstances. Readers should take independent advice. No part of this publication may be reproduced by any process without prior written permission from Ashurst Perkins Coie. We accept no liability for use of these materials and reliance upon it by any person.