Turn Australia's Scams Prevention Framework’s obligations into a step-by-step checklist you can use to assess your current controls, record the evidence behind them, score your readiness, and identify the work that needs attention first.
What you'll find inside
Download the checklist to:
Assess your readiness against all six Scams Prevention Framework principles: Govern, Prevent, Detect, Disrupt, Respond, and Report.
Identify gaps across governance, fraud controls, dispute resolution, reporting, and actionable scam intelligence.
Understand how the draft sector-specific codes differ for banks, telecommunications providers, and digital platform services.
Prioritize remediation activities before the March 31, 2027 commencement date using a practical implementation roadmap.
Build a defensible record of the reasonable steps your organization has taken using evidence-based assessment criteria.
Benchmark your current capabilities and focus resources where regulatory and operational risk is greatest.
Prepare for the SPF with confidence
FAQs about Scam Prevention Framework Readiness
What is Australia's Scams Prevention Framework?
The Scams Prevention Framework (SPF) is Australian legislation, introduced through the Scams Prevention Framework Act and built into the Competition and Consumer Act 2010, that requires designated sectors to take reasonable steps to protect customers from scams such as investment scams and romance scams. It sets six binding principles and gives regulators the power to impose civil penalties for non-compliance. The National Anti-Scam Centre (NASC) and Scamwatch support the framework by collecting scam reports and coordinating the national response to financial crime.
Who does the SPF apply to?
The SPF applies to three designated sectors, each overseen by its own enforcement regulator: banks, regulated by the Australian Securities and Investments Commission (ASIC); telecommunications providers, regulated by the Australian Communications and Media Authority (ACMA); and digital platforms, regulated by the Australian Competition and Consumer Commission (ACCC). Its reach extends to organizations based outside Australia where they serve Australian-resident customers. Superannuation, insurance, online marketplaces, and cryptocurrency services have been identified as candidates for future designation.
What are the six SPF principles?
The framework is built on six principles: Govern, Prevent, Detect, Disrupt, Respond, and Report. Together, they set the standard for how regulated entities manage scam risk, apply measures such as targeted warnings to reduce customer exposure, remove scam infrastructure, handle disputes, and share actionable scam intelligence with regulators. The sector-specific codes add more detailed obligations for each designated sector.
How do customers raise scam complaints under the SPF?
The framework sets out a dispute-resolution pathway with two stages. Internal dispute resolution (IDR) is handled by the regulated entity itself. Where a complaint isn't resolved, external dispute resolution (EDR) is handled by an independent body: the Australian Financial Complaints Authority (AFCA) for banks, and the Telecommunications Industry Ombudsman (TIO) for telecommunications providers. The framework also provides for multi-party complaints where a scam spans more than one sector, and consumer advocates such as the Consumer Action Law Centre have pressed for accessible routes including a small claims process.
The sector codes aren't finalized yet. Do we need to act now?
Yes. The six principles are already law, and several deadlines fall before the March 2027 commencement, including AFCA membership from September 2026. The exposure drafts are the clearest available indication of what regulators will expect, so they provide a workable basis for assessing controls and closing gaps now.



