Australia’s scam laws are coming. Is your company ready?

Australia’s Scams Prevention Framework is moving from principle to practice. Draft rules commence 1 September 2026, with broader sector-code obligations for banks, telecommunications providers and digital platforms from 31 March 2027. Non-compliance carries civil penalties of up to $50 million per contravention. (Gilbert + Tobin)

The sharpest obligation for banks, telcos and platforms is cross-sector cooperation. The principle underpinning these obligations is crucial: risk is expected to be visible as it moves between parties, not reconstructed after the loss.

When a customer is scammed, the clock starts. Complaints will span banks, telcos and platforms, and each party will be expected to show what it saw, what it did and why. Controls built for periodic review cannot answer that. Compliance now depends on continuous visibility over every transaction, and on evidence that exists before anyone asks for it.

RedOwl gives regulated entities that continuous view. RedOwl analyses every transaction in real time for anomalies, control gaps and fraud indicators, validating payments before they are released and escalating what needs human judgement. Compliance and finance teams see risk as it moves, not after it settles.

Critically, that oversight produces its own evidence: every check, decision and approval, by person or AI agent, is logged, timestamped, attributed and exportable, creating an audit-ready record of every transaction. When the regulator asks how a payment was verified, the answer is produced on demand, not reconstructed.

The consultation window has closed and regulated entities have notice of what the SPF codes require; uplift is expected to start now. The direction is clear: reactive review is giving way to continuous, evidence-based oversight.

Think you are a great fit for RedOwl but don't see the rights role for you?

Click here to let us know you are interested in joining the RedOwl team.

Apply Now ->