Overview
One of the most significant operational requirements within Australia’s Scams Prevention Framework (SPF) is the obligation to investigate scam activity once an organisation receives actionable scam intelligence.
Under the SPF, regulated entities cannot simply identify potential scam activity and move on. Once actionable scam intelligence exists, organisations are required to investigate whether the activity is a scam and take reasonable steps to do so within a defined timeframe.
This requirement is often referred to as the SPF’s “28-day investigation clock”.
For many organisations, this represents a significant shift. Detection remains important, but detection alone is not enough. Organisations must also be able to investigate suspicious activity, record their findings, maintain evidence and demonstrate how decisions were made throughout the process.
Understanding when the clock starts, what information must be recorded and how investigations should be managed will be critical for organisations preparing for SPF compliance.
What Starts the 28-Day Clock?
The SPF’s investigation requirement does not apply to every alert, report or suspicious activity that an organisation receives.
Instead, the obligation is triggered when an organisation receives what the draft SPF Codes refer to as actionable scam intelligence.
Once intelligence becomes actionable scam intelligence, organisations are required to investigate whether the activity is a scam and take reasonable steps to do so within 28 days.
Importantly, the 28-day investigation period begins when intelligence becomes actionable scam intelligence for an organisation, not after an activity has already been formally identified as a scam. The purpose of the investigation is to determine whether the activity is a scam and gather information to support that assessment.
This distinction is significant. Organisations may receive large volumes of alerts, reports and threat intelligence every day. The challenge is not simply detecting potential scam activity, but having processes in place to assess incoming information, determine when it becomes actionable and ensure investigations are commenced and tracked accordingly.
Understanding what constitutes actionable scam intelligence is therefore critical for organisations preparing to comply with the SPF.
What Is Actionable Scam Intelligence?
The SPF’s 28-day investigation requirement is triggered by what Treasury refers to as actionable scam intelligence.
According to Treasury, actionable scam intelligence is information held by a regulated entity that provides reasonable grounds to suspect that a communication, transaction or activity is a scam. This information may come from a scam report, information shared by regulators or an organisation’s own investigation activities.
Actionable scam intelligence can take many forms, including suspicious URLs, email addresses, phone numbers or information relating to a suspected scammer.
Importantly, not every alert or report will automatically become actionable scam intelligence. Organisations need processes in place to assess incoming information and determine when it warrants further investigation.
This is where the SPF’s investigation requirements become important. Once intelligence becomes actionable, organisations are expected to investigate whether the activity is a scam and take reasonable steps to do so within the required timeframe.
For many organisations, the challenge is not simply receiving intelligence. It is ensuring that intelligence is reviewed, assessed and progressed through a structured investigation process that can be tracked, documented and evidenced if required.
Why Detection Alone Isn't Enough
Detection is an important part of the SPF, but detection alone does not satisfy an organisation’s obligations.
Identifying a suspicious website, email address, social media account or phone number is only the beginning of the process. Once intelligence becomes actionable, organisations need a structured way to assess the activity, gather supporting information and determine whether it constitutes a scam.
This distinction is important because many organisations already receive large volumes of alerts from internal teams, customers, threat intelligence providers and monitoring tools. However, receiving an alert is not the same as conducting an investigation.
As scam activity continues to increase in volume and complexity, organisations need processes that allow them to move efficiently from detection to investigation. This includes triaging intelligence, assessing potential threats and ensuring investigations are commenced within the required timeframe.
The Importance of Audit Trails
The SPF’s investigation requirements are closely linked to record-keeping obligations.
Under the draft SPF Codes, organisations must record information relevant to their investigations, including whether an activity was identified as a scam, information supporting their assessment, the methods used to contact affected consumers and details about the scam itself, including relevant identifiers such as URLs, email addresses, phone numbers and social media profiles.
In practice, this means organisations need a reliable way to document what happened throughout the investigation lifecycle.
Organisations should be able to demonstrate when intelligence became actionable, what information was reviewed, what evidence was gathered, what conclusions were reached and what actions were taken.
Maintaining clear records not only helps support compliance with the SPF, but also enables organisations to review investigations, identify trends and demonstrate consistency in their approach to scam prevention and disruption.
Preparing for the SPF
While the SPF’s obligations do not commence until 31 March 2027, organisations should not underestimate the work required to prepare.
The 28-day investigation requirement is not simply about identifying scams. It requires organisations to have processes for assessing intelligence, managing investigations, gathering evidence, maintaining records and demonstrating how decisions were made.
(Within the unphish platform, every investigation action is recorded in a centralised activity log, supporting transparency, accountability and regulatory reporting requirements.)
For many organisations, this will require a shift from reactive scam handling towards more structured investigation and scam disruption workflows.
This is where technology can play an important role. Platforms such as unphish help organisations centralise threat intelligence, manage investigations, collect evidence, maintain audit trails and coordinate enforcement actions through a single workflow.
(Each case within the unphish platform is enriched with evidence, screenshots, metadata and analyst notes, providing investigators with the context needed to validate threats and coordinate enforcement actions.)
As the SPF moves closer to commencement, organisations should be assessing whether their current processes are capable of supporting the investigation, record-keeping and disruption requirements outlined in the framework.
Assess Your SPF Readiness with us
Complete the form below and one of our specialists will be in touch.