unphish
unphish unphish

Australia’s Scams Prevention Framework: What Every Business Needs to Know

Australia's Scams Prevention Framework
When unphish was awarded a grant by the Australian Government, it was clear that addressing the growing number of online scams targeting Australians was high on the agenda. We were an unusual applicant, most of the other recipients were tackling manufacturing and industrial challenges. But our AI-first approach to brand protection and scam detection was highly appealing to the grant committee, and so we started the journey to build what we now describe as an SPF-ready platform.
 
That was before the Scams Prevention Framework existed in its current form. Looking back, the timing could not have been better.
 
For years, scam prevention in Australia operated on an implicit understanding: organisations should try to help, but ultimately scams were something that happened to consumers. The burden fell on individuals to spot a fake website, question a suspicious email, or second-guess a payment request.
 
That understanding is now law, and it runs in the opposite direction.
 
Australia’s Scams Prevention Framework (SPF), enacted under the Competition and Consumer Act 2010 and commencing 31 March 2027, places a mandatory legal obligation on regulated organisations to proactively prevent, detect, disrupt and respond to scam activity. Non-compliance is not a risk to be managed. It is a civil penalty.
 
Here is what businesses need to understand.

Who Is Directly Regulated

The SPF’s initial scope covers three designated sectors: banks, telecommunications providers and digital platforms. Banks face the heaviest obligations, including payee confirmation, transaction monitoring, account monitoring and payment recall processes. Digital platforms must verify users and advertisers, monitor content and remove scam activity. Telco-specific code provisions are forthcoming.
 
But the practical reach extends further. The framework is explicitly designed to expand, and insurance, superannuation and e-commerce are the most likely near-term additions.

The Brand Impersonation Obligation

This is the provision most businesses outside the directly regulated sectors need to understand. Section 2-7 of the SPF Codes Instrument requires regulated entities to monitor the internet for brand impersonation and promptly send takedown requests for impersonation websites. It also requires them to protect their official communication channels and inform customers how to identify them.
 
This is the first time Australian legislation has effectively moved brand impersonation monitoring from a best practice into a legal obligation. For banks, insurers, airlines, utilities and government agencies, this is no longer optional.

The Detect Obligation and the 28-Day Clock

Once an organisation has what the SPF calls actionable scam intelligence, a compliance clock starts. The entity has 28 days to investigate whether the activity is a scam and must record its findings, including the determination made, the evidence considered, the identifiers involved, and the actions taken. This is a forensic audit trail requirement, not light-touch record keeping.

Why Non-Regulated Businesses Should Still Pay Attention

Even if your organisation is not directly regulated today, four pressures will close that gap.
The regulatory perimeter will expand. The SPF is structured to designate additional sectors over time.
 
Board and insurer pressure will arrive before legislation does. Directors who are aware of the SPF and choose not to implement equivalent controls will face difficult questions if an impersonation incident causes consumer harm.
 
Third-party accountability flows down the chain. Regulated entities must supervise their vendors and third-party providers against SPF obligations. If you supply services to a regulated bank, telco or platform, expect to be assessed.
 
The SPF establishes the standard of care. Any organisation that suffers a brand impersonation incident and cannot demonstrate active monitoring and takedown processes will face reputational and legal exposure regardless of whether it is formally regulated.

What a Compliant Programme Looks Like

Organisations need documented governance policies covering scam risk assessment and staff training. They need continuous monitoring across domains, social media, advertising networks and Certificate Transparency logs. They need defined takedown workflows with SLAs, not ad hoc responses. They need case management that generates the evidence regulators will ask for. And they need to have assessed their third-party providers against the same standards.
 
The commencement date is 31 March 2027. That sounds distant. It is not.

Read the Full Guide

We have produced a detailed guide to the SPF for boards and executive leadership teams, covering what the framework requires, which sectors are most exposed, what a compliant programme looks like, and the questions regulators are likely to ask.
 

Assess Your SPF Readiness

The SPF introduces new obligations around scam prevention, detection, investigation, and response. Understanding where your organisation stands today is the first step toward compliance.

Speak with our team about:

Complete the form below and one of our specialists will be in touch.

    About unphish

    Protect Your Brand with unphish

    unphish is a threat detection and disruption platform built to identify and take down phishingscams, and digital impersonation at scale. We combine intelligence-led detection with automated enforcement to help organisations protect their brand, customers, and digital ecosystem.

    See unphish in Action

    Detect, Validate, and Take Down Threats Automatically

    unphish combines intelligence-led detection with automated enforcement so you can protect your brand, customers, and digital ecosystem without the manual effort.

    Create your account