Cyberoo logo
Home
|
About
|
Products
|
Solutions
|
Insights
|
Contact
Cyberoo logo
Leading the fight against scammers, supporting organisations globally in detecting and disrupting scams, including those preparing for regulatory frameworks such as Australia's Scams Prevention Framework
Prescient Security ISO/IEC 27001:2022 certification mark
ISO/IEC 27001:2022

Cyberoo Pty Ltd.'s Information Security Management System is certified by Prescient Security.

Certification scope & details
Menu
HomeAboutInsightsContact
Products
NothingPhishyScams.ReportMuleHunt
Solutions
SPF Compliance for Scam PreventionScam Detection & Threat IntelligenceDigital Risk & Infrastructure DisruptionWebsite Takedown & Digital Risk ProtectionPayment Scam & Mule Account IntelligenceScam Awareness & Behavioural Defence
Contact
Level 1/63 Ann Street,
Surry Hills
NSW 2010
info@cyberoo.ai
© All rights reserved | Cyberoo Pty LtdPrivacy PolicyTerms of Use
Back to Insights

Under SPF, Having Controls Is Not Enough. You Need the Evidence.

The proposed SPF complaint framework places growing weight on investigation records, decision traceability and the evidence showing what an organisation knew, decided and did.

September 7, 2026 | Written by Cyberoo Research & Analysis Team

Consultation status: This article considers current SPF exposure drafts and AFCA proposals as at September 2026. Final SPF Codes, Rules, AFCA Scam Rules and Operational Guidelines may change before commencement.

Evidence chain diagram showing a scam signal progressing through evidence, assessment, decision, action and outcome with an audit trail running beneath every stage.
Click to view full size

A policy can show that a control was designed. It cannot necessarily show what happened when a real scam reached that control. The proposed SPF dispute framework makes that distinction increasingly important.

Treasury's proposed Rules require regulated entities to provide detailed Statements of Compliance during internal dispute resolution. The proposed AFCA Scam Rules then allow AFCA to look beyond that statement, request supporting information and investigate the underlying events.

For regulated entities, SPF readiness is therefore becoming an evidence problem as much as a control-design problem.

A Statement of Compliance is more than an outcome letter

The draft SPF Rules prescribe substantial information for a Statement of Compliance. It may need to describe the matters raised in the complaint, material findings of fact, information relied upon, the process followed, the outcome, action or compensation provided and, where relevant, information about the conduct of another entity that affected the outcome.

The Statement must also explain whether, based on the information reasonably available at the time, the regulated entity considers that it complied with the SPF obligations relevant to the complaint. In most cases, the draft Rules require the Statement within 21 calendar days.

This is not simply a writing exercise. The organisation first needs to possess the evidence required to support what it writes.

The consumer-facing statement is not the full evidence record

The draft Rules appropriately restrict certain information from appearing directly in the Statement of Compliance, including commercially sensitive and personal information. That protection should not be confused with an absence of underlying evidence requirements.

AFCA's proposed Rule 1.9 reaffirms its inquisitorial approach and gives AFCA discretion to obtain relevant information and documents. The proposal also narrows the ability to rely on confidentiality alone as a reason for withholding information, with parties expected to consider alternative ways of providing relevant material. AFCA may also obtain information from third parties, including regulators, where appropriate.

During its consultation webinar, AFCA made clear that the Statement of Compliance will not necessarily be the end of the evidentiary inquiry.

The practical model therefore has two layers: the explanation provided to the consumer and the evidence capable of supporting that explanation if challenged.

Investigation records are already being built into the SPF

The broader SPF Codes move in the same direction. The proposed common Code provisions require regulated entities to have systems and processes for detecting scams, investigating actionable scam intelligence and recording relevant information about investigations.

The explanatory material makes clear that actionable scam intelligence arises where there are reasonable grounds to suspect that a communication, transaction or other activity connected with a regulated service is a scam.

Operationally, that creates an evidence chain:

Signal → Investigation → Assessment → Decision → Action → Outcome

The stronger that chain is, the easier it becomes to understand later why a particular decision was made.

Traditional fraud records may preserve only part of the story

Many fraud systems were built to record transactions. They may preserve a risk score, alert, payment decision or analyst disposition. That is useful, but authorised scam payments often involve evidence outside the transaction itself.

Relevant evidence may include:

  • an investment website;
  • an impersonation profile;
  • a social media advertisement;
  • a phone number or sender identity;
  • scam correspondence;
  • a beneficiary account;
  • external scam intelligence;
  • previous reports involving related infrastructure;
  • warnings provided to the customer; and
  • information received from another organisation.

If those records remain disconnected, the organisation may have performed substantial operational work but still struggle to recreate the reasoning months later.

“We showed a warning” may not answer the real question

Consider a simple example.

A bank may be able to establish that a warning appeared before a payment. That proves that a warning existed. It does not necessarily explain:

  • why the warning was triggered;
  • whether it was generic or targeted;
  • which scam indicators were known;
  • whether the beneficiary had known risk indicators;
  • whether related scam intelligence already existed;
  • whether the customer response created further warning signs;
  • whether escalation occurred; or
  • whether subsequent intelligence should have changed the original assessment.

The more useful question is not merely: Did the control run?

It is: What did the control know, what decision did it support, and what happened next?

SPF readiness is becoming an observability problem

In technology, observability describes the ability to understand what happened inside a system from the information it produces. The same idea applies to scam operations.

  • Can an organisation explain what it knew at a particular time?
  • Can it identify the evidence that was available?
  • Can it show what investigation occurred?
  • Can it explain why a particular disruptive or preventive action was taken or not taken?
  • Can another investigator reproduce that reasoning without relying on the memory of the original analyst?

A policy is evidence that a control was designed. It is not evidence that the control worked effectively in a particular scam.

Cyberoo perspective

Cyberoo treats evidence and explainability as part of scam intelligence rather than an administrative step after a decision.

A useful scam assessment should preserve why an activity was considered malicious. A useful takedown record should preserve the evidence supporting intervention. Useful payment-destination intelligence should retain the scam context that makes the destination relevant.

Under SPF, those practices increasingly support two objectives at the same time: better operational action today and better explanation tomorrow.

Frequently Asked Questions

Is a Statement of Compliance enough by itself?

Not necessarily. The proposed AFCA Rules allow AFCA to request information beyond the Statement where further material is required to resolve the complaint.

Does AFCA operate like a court applying formal rules of evidence?

No. AFCA continues to use an inquisitorial and relatively informal dispute resolution model, while maintaining procedural fairness.

Can AFCA obtain technical expert advice?

Yes. The proposed Rules continue AFCA's ability to obtain expert advice and propose increasing the expert-cost contribution cap from $5,000 to $10,000 for SPF matters.

What should a useful scam evidence record contain?

At minimum, it should preserve the signal, supporting evidence, assessment, decision rationale, relevant actions, timestamps and outcome in a traceable form.

Cyberoo perspective on readiness

For SPF readiness, the organisations in the strongest position may not simply be those with the greatest number of controls.

They may be those that can demonstrate, quickly and consistently, what they knew, what they decided, what they did and why.

References

  • Australian Treasury, Competition and Consumer (Scams Prevention Framework) Rules 2026 – Exposure Draft
  • Australian Treasury, Explanatory Statement: Competition and Consumer (Scams Prevention Framework) Rules 2026
  • Australian Treasury, Competition and Consumer (Scams Prevention Framework—SPF Codes) Instrument 2026 – Exposure Draft
  • Australian Financial Complaints Authority, Consultation on AFCA's Proposed Rule Changes for the Scams Prevention Framework, August 2026
  • Australian Financial Complaints Authority, Proposed AFCA Scam Rules, August 2026

Related Articles

  • Why Explainable Scam Verification Matters
  • How Regulators May Enforce the Scams Prevention Framework
  • From Scam Signal to Reasonable-Steps Evidence: Building an SPF Evidence Spine

A policy is evidence that a control was designed. It is not evidence that the control worked effectively in a particular scam.