Treasury's draft codes and rules put more meat on the bones of the Scams Prevention Framework. The development the payments industry should be watching, though, is not in the headline obligations. Previously ‘goods & services” disputes were clearly marked as out-of-scope, the current expectations lean on legitimacy testing.
In late May 2026, Treasury released its draft codes and rules for the Scams Prevention Framework (SPF) for consultation, alongside the designation of banking, digital platforms and telecommunications as the first regulated sectors. The consultation is open until 25 June 2026, and the framework comes into full effect on 31 March 2027.
There is, finally, more meat on the bones. The draft code sets out the first concrete examples of what designated entities will be expected to do across the six SPF principles, and the draft rules and IDR position paper begin to describe how complaints, reimbursement and liability apportionment will work in practice. That is real progress, and it is welcome.
But anyone reading the consultation questions alongside the Q&A sections of the joint Treasury and ACMA walkthrough will come away with at least as many questions as answers.
Most issuers have treated the SPF as an authorised-scam problem: payments a customer is deceived into making, which the bank is expected to help prevent, detect and disrupt. Chargebacks have sat in a separate world, governed by scheme rules and Australian Consumer Law, run as a commercial dispute process. The draft suggests those two worlds now overlap. Goods-and-services disputes — "not received", "not as described" — appear to fall within scope where the merchant was not a legitimate business. That is new, and it changes what issuers are obliged to do with a category of dispute they currently process as routine.
What the scam data shows: lower value, higher volume
The shape of the problem the SPF is responding to is changing in a way that makes this overlap matter more, not less.
The National Anti-Scam Centre's Targeting Scams report for 2025 records total reported losses of $2.18 billion, up 7.8% on 2024, against a report volume that held relatively steady (481,523 reports, compared with 494,732 the year before). Inside those aggregates, the more telling figure is the median loss, which fell from $500 in 2024 to $400 in 2025. Meaning, there is a pattern towards lower-value/higher-volume attacks.
The new bit: goods-and-services disputes appear to be in scope
Earlier framing of the SPF's scope appeared to keep card chargebacks for "goods or services not received" or "not as described" outside the scam perimeter — treating them as commercial disputes, resolvable through scheme chargeback rules and the Australian Consumer Law, rather than as scams attracting SPF obligations and reimbursement.
The current position reads differently. As we understand the consultation materials, there is no blanket exemption for these dispute categories. Instead, the line between a stock standard chargeback and a scam appears to turn on the legitimacy of the business on the other side of the transaction. A legitimate merchant that simply failed to deliver, or delivered something defective falls under the chargeback process. A "merchant" that never existed as a real business — set up to take a payment and disappear — is a scam, with everything that follows from that classification.
That is a defensible place to draw the line. It is also a line that has to be drawn by someone, on a transaction-by-transaction basis, and the draft does not yet make clear who, when, or on what evidence. For issuers, the practical effect is an additional step layered on top of an already cumbersome chargeback process. Treasury is expected to provide additional rules as the definition of a scam is still under development.
The issuer's problem: judging legitimacy from a payment message
Once chargebacks are accepted as in scope, the operational question is unavoidable, and it is hard precisely because of how little the issuer has to work with.
At the point a dispute is raised, the issuer is judging legitimacy from the payment message: a merchant descriptor, an amount, a date, a semi-useful category code. It is unknown from looking at a transaction, how the consumer engaged with that merchant - if that was through a digital provider, link-to-pay presented by a telco, straight through the website, etc. To form any view on legitimacy, the issuer would have to go and find them:
- Resolve the descriptor to a website. Descriptors are poor identifiers, and a convincing storefront is the cheapest part of a fraudulent operation to build. The existence of a live site proves very little. Most Australian Issuers implemented the “Look Who’s Charging/Experian” solution which is a good place to start filtering.
- Check website signals. Age of the domain, the presence and quality of an SSL certificate, registration details — weak signals individually. A domain registered last week is not necessarily fraudulent, and an SSL certificate is now table stakes for any site, legitimate or not.
- Check licensing. Where an industry requires an Australian licence to operate, verifying the merchant holds one is tractable. For the many industries that are not licensed at all, it is meaningless.
- Check business registers. ASIC and the ABR are the obvious starting points, but cross-border commerce means the relevant register may be in another jurisdiction. Is the issuer expected to check global registers, and against what standard of coverage?
- Check consumer reports. Trustpilot, ProductReview and similar sources carry real signal, but they are gameable, inconsistently populated, and not designed to support a defensible compliance determination. None of this is in the payment message, and none of it produces a clean binary from evidence that only ever supports a probability. And a consumer proclaiming “This merchant is such a scam” is not a reliable signal. There is also no platform to lean on by default. A digital platform may not have been involved in the purchase at all — and if one was, the issuer may have no way of knowing it from the transaction and correlation of data will be another interesting challenge. At most, an issuer might reach out to a platform when in doubt. But the draft offers no guidance on how communication between banks, telcos and digital platforms is meant to work in practice: the framework contemplates multi-party cooperation and information sharing, without yet describing the mechanism, the timing, or who carries the cost. The "when in doubt, ask the platform" fallback has no plumbing behind it.
What counts as a "legitimate" business?
The harder problem sits upstream of the operational one: the framework needs a clearer definition of what "legitimate" means before any entity can be expected to test for it.
The edge cases are not exotic. A business selling counterfeit goods is trading legally but infringing intellectual property — does that render the merchant illegitimate, and the transaction therefore a scam, generating actionable scam intelligence? What about a business that is trading legally, has records with ABR but has excessive amounts of “not as described” claims and significant negative commentary on product review sites? Or a business that never delivered? A drop-shipment business that does not provide domestic stock as promised?
If "legitimate" is left undefined, the distinction between a scam and a sharp-but-lawful business model collapses into the judgement nightmare of whichever operator happens to be working the queue.
This is not a reason to abandon the approach. It is a reason to define it. A legitimacy test that cannot tell a fraudulent storefront apart from a lawful discount retailer will either over-capture — sweeping legitimate merchants into scam intelligence on thin signals — or under-capture, and miss the operations it was built to catch.
The overlooked victim: the low-value scam and the case for card replacement
There is a consumer-protection consequence here that the low dollar values tend to obscure.
When a consumer is deceived by a fraudulent online store, the harm is not measured only by the amount debited. To complete the purchase, the consumer handed the bad actor not just their payment credentials but their name, delivery address, email and phone number. That is a data set, freely given, to an operator whose business is exploiting it. The consumer is now exposed to follow-on financial crime — card-not-present reuse, identity-linked phishing, repeat targeting — regardless of whether the purchase was just $20.
In current practice, a dispute of this kind would rarely trigger a card replacement. Standard operating procedures treat a small-value goods-and-services dispute as a straight-through- process refund question, not a security event, and reissuing a card for every such case would be operationally costly.
The change in scope reframes that calculation. If the transaction is recognised as a scam rather than a commercial dispute, then the consumer is a scam victim whose credentials are in the hands of a criminal — and the proportionate response is no longer simply a refund. It is a card replacement and clear information about the risks that follow a scam event. This is not a stretch beyond the framework's own logic: the draft code already obliges banks to identify and notify customers affected by scams. Acting on that identification — by treating compromised credentials as compromised — is the natural next step.
A $20 loss can still be the front door to a much larger one. The framework's value here is that it forces issuers to consider that door!
The questions worth pressing during consultation
Pulling fraudulent-merchant transactions into scope is the right direction. It closes a gap that left deceived consumers vulnerable to follow-on financial crime. But the draft leaves the operational core of that expansion undefined — and leaves it sitting with industry to resolve. Yet a consumer with bank A should not be more or less protected than a consumer with bank B. Competitive tension is welcome for interest rates, card offers etc but not in defining how to protect a consumer. With consultation open until 25 June 2026, these are the questions that need answers:
- How is an issuer expected to assess merchant legitimacy from a payment message alone, and to what standard of evidence, before classifying a transaction as a scam?
- How will communication between banks, telcos and digital platforms work in practice — particularly where it is unknown whether a platform was even part of the purchase?
- What is the definition of a "legitimate" business and how can we hit the middle ground between under- and over-reporting?
Sources: Treasury, Scams Prevention Framework — consultation on draft codes and rules (open to 25 June 2026); Scams Prevention Framework designation instrument; National Anti-Scam Centre, Targeting Scams: Report of the National Anti-Scam Centre 2025 (median loss $500 in 2024 to $400 in 2025; total reported losses $2.18 billion).