Cyberoo logo
Home
|
About
|
Products
|
Solutions
|
Insights
|
Contact
Cyberoo logo
Leading the fight against scammers, supporting organisations globally in detecting and disrupting scams, including those preparing for regulatory frameworks such as Australia's Scams Prevention Framework
Prescient Security ISO/IEC 27001:2022 certification mark
ISO/IEC 27001:2022

Cyberoo Pty Ltd.'s Information Security Management System is certified by Prescient Security.

Certification scope & details
Menu
HomeAboutInsightsContact
Products
NothingPhishyScams.ReportMuleHunt
Solutions
SPF Compliance for Scam PreventionScam Detection & Threat IntelligenceDigital Risk & Infrastructure DisruptionWebsite Takedown & Digital Risk ProtectionPayment Scam & Mule Account IntelligenceScam Awareness & Behavioural Defence
Contact
Level 1/63 Ann Street,
Surry Hills
NSW 2010
info@cyberoo.ai
© All rights reserved | Cyberoo Pty LtdPrivacy PolicyTerms of Use
Back to Insights

From Bank Complaint to Scam Chain: What the Proposed AFCA Scam Rules Change

The proposed SPF dispute model treats scams as multi-party events across banks, digital platforms and telecommunications providers rather than isolated complaints against one organisation.

September 4, 2026 | Written by Cyberoo Research & Analysis Team

Consultation status: This article considers the AFCA Scam Rules proposed for consultation in August 2026. The proposals remain subject to consultation, AFCA Board approval and ASIC approval. The new SPF external dispute resolution jurisdiction is planned to commence on 31 March 2027, with Operational Guidelines expected to be developed in early 2027.

Diagram showing a consumer scam journey across a digital platform, telecommunications provider, sending bank, receiving bank and AFCA, connected by a shared evidence trail.
Click to view full size

A scam rarely belongs to one organisation.

A victim may first encounter an advertisement on a digital platform, receive a message or call through a telecommunications service, make a payment through one bank, and send funds to an account held by another bank. The proposed AFCA Scam Rules are being designed around that reality.

For regulated entities, this changes the practical meaning of scam complaint readiness. The question may no longer be limited to whether one organisation handled one customer interaction correctly. AFCA may need to reconstruct the wider scam journey, identify the regulated entities connected to it, and assess the role each played.

That makes cross-sector evidence, timelines and scam intelligence increasingly important.

Multi-party complaints move from exception to operating model

Multi-party dispute resolution is not new to AFCA. What is new is the scale at which AFCA expects it to occur under the SPF. During its consultation webinar, AFCA explained that modern scams commonly involve multiple organisations, channels and sectors, and that its new jurisdiction is being built to handle complaints crossing those boundaries.

The proposed Scam Rules reflect that expectation. Rule 1.6 introduces a dedicated framework for SPF complaints involving multiple regulated entities. AFCA may add or remove regulated entities during the complaint process as the facts become clearer. The comparative rules document describes this as a significant change from AFCA's existing approach.

This matters because the organisation named in the original complaint may not be the only organisation ultimately examined.

The consumer does not need to map the scam chain first

Scam victims frequently see only fragments of what happened. They may know which account they paid from, but not which institution received the funds. They may remember an investment advertisement without knowing the entity responsible for the relevant platform service. They may have received calls, SMS messages and instant messages without understanding which providers formed part of the scam journey.

The proposed framework recognises that information imbalance. AFCA proposes to assist consumers in identifying issues and potentially relevant regulated entities when a complaint is lodged. This makes the original complaint the beginning of the investigation rather than necessarily the final boundary of it. AFCA can then gather additional information and decide whether other regulated entities have a sufficient connection to the activity to become part of the complaint.

Automatic refer-back is also changing

Under AFCA's existing Financial Firm Rules, complaints are generally referred back to the relevant financial firm before AFCA proceeds further. The proposed SPF model is different.

The comparative rules document expressly states that there will be no automatic refer-back process for SPF complaints. AFCA may commence consideration as soon as possible unless it considers it appropriate to provide one or more regulated entities additional time to resolve the matter. AFCA explained during the consultation webinar that this reflects the likelihood that a scam complaint may already have gone through a coordinated or partially coordinated IDR process involving multiple entities. Automatically repeating that process could create unnecessary delay and duplication.

The practical implication is significant. The quality of the original IDR investigation, evidence and explanation matters more if organisations cannot assume they will always receive another opportunity to reconstruct the case after it reaches AFCA.

The scam journey becomes the more useful unit of analysis

Traditional dispute files often begin when the customer complains. A scam investigation should begin earlier. It may need to establish:

  • how the victim was approached;
  • which scam infrastructure was involved;
  • what accounts, numbers, advertisements or identities were used;
  • when relevant information became available;
  • what each organisation knew at that point;
  • what investigation occurred;
  • what preventive or disruptive action was available;
  • what action was actually taken; and
  • what happened afterwards.

This is closer to reconstructing a scam chain than reviewing a single transaction. AFCA's proposed Rule 1.9 reinforces this direction by expressly confirming its inquisitorial approach. AFCA may determine what information is relevant, obtain documents, make inquiries and, where appropriate, obtain information from third parties including regulators. A transaction record alone may therefore tell only part of the story.

Cross-sector evidence needs to survive organisational boundaries

Each organisation may see a different part of the scam. A digital platform may know when an advertisement was created, reported or removed. A telecommunications provider may hold information about calls, messages, numbers or sender identities. A sending bank may hold payment information, warnings and customer interactions. A receiving bank may see the destination account, incoming transfers and subsequent fund movement.

The operational challenge is not simply collecting more data. It is preserving enough context so that information created inside one organisation remains meaningful when reviewed by somebody outside it. A useful scam evidence record should connect the signal, the assessment, the affected service, the action and the outcome.

Cyberoo perspective

The proposed AFCA framework reinforces an operational principle that already applies to effective scam prevention:

The scam should be analysed as a connected journey, not as a collection of isolated incidents.

That model is valuable before a complaint occurs. Connecting the lure, digital infrastructure, scam narrative, payment destination and supporting evidence can help organisations identify intervention opportunities earlier. Under SPF, the same connected intelligence may also become important after the event when an organisation needs to explain its place in the scam chain.

A complaint file tells you what was reported. A scam evidence chain helps explain what actually happened.

Frequently Asked Questions

Does every SPF scam complaint need to involve multiple regulated entities?

No. Some complaints may concern only one regulated entity. The proposed framework nevertheless assumes that multi-party complaints will be common because scams frequently cross banking, telecommunications and digital platform services.

Can AFCA add an organisation that the consumer did not originally complain about?

Under the proposed Scam Rules, AFCA may add another regulated entity where the available information establishes a sufficient connection to the complaint, subject to the relevant procedural requirements.

Will every SPF complaint automatically be sent back to the regulated entity before AFCA investigates?

No. AFCA proposes not to use automatic refer-back for SPF complaints. It may allow additional time for IDR where appropriate.

What should organisations prepare now?

In addition to updating complaint procedures, organisations should test whether they can reconstruct a scam chronology and retrieve the evidence supporting their investigation, communications, decisions and actions.

Cyberoo perspective on readiness

Cyberoo helps organisations connect scam verification, external scam infrastructure, payment-destination intelligence and disruption evidence into a more complete view of a scam event.

For organisations reviewing SPF readiness, the ability to reconstruct that event may become increasingly important both for intervention before loss and explanation afterwards.

References

  • Australian Financial Complaints Authority, Consultation on AFCA's Proposed Rule Changes for the Scams Prevention Framework, August 2026
  • Australian Financial Complaints Authority, Proposed AFCA Scam Rules, August 2026
  • Australian Financial Complaints Authority, List of Proposed Changes to the AFCA Rules, August 2026
  • Australian Financial Complaints Authority, Scam Rules Consultation Webinar, September 2026

Related Articles

  • What Is Australia's Scams Prevention Framework (SPF)
  • The Operational Challenges of Implementing the Scams Prevention Framework
  • From Scam Signal to Reasonable-Steps Evidence: Building an SPF Evidence Spine

A complaint file tells you what was reported. A scam evidence chain helps explain what actually happened.