By Joshua Clouston, Head of Product, ezyshield
Australia's Scams Prevention Framework Is Live - and Confirmation of Payee Is Now the Law
Australia's SPF Stage 1 went live 1 July 2026. Banks must now verify payees before money moves or face $50M fines. Here's what changed - and what still hasn't.
Today, 1 July 2026, Australian banks woke up with legal obligations they have never had before.
For the first time in this country’s history, it is not enough for a bank to process a payment. Under Stage 1 of the Scams Prevention Framework (SPF), banks must now actively prevent, detect, and disrupt scams - or face fines of up to $50 million per contravention. That is not a guideline. That is the law, enforced by ASIC, the ACCC, and ACMA, with AFCA opening as the formal dispute authority for consumer scam complaints from 1 January 2027.
This is the most significant structural shift in Australian payment fraud regulation since the New Payments Platform launched in 2018. And at the centre of it sits one control that matters more than most: Confirmation of Payee.
What the SPF Actually Requires Banks to Do
The SPF is built around six obligations that apply to every designated entity - banks first, telcos and digital platforms close behind. They are: govern, prevent, detect, disrupt, respond, and report.
Govern means having a named senior accountable person responsible for scam prevention - someone who can be called before a Senate estimates committee and asked why the bank’s fraud rate went up. Accountability is the intent. The days of fraud losses landing in a shared “operational risk” bucket without a face attached are over.
Prevent is where payee verification lives. Banks must implement systems that confirm the destination account name matches what the payer entered before funds transfer. This is Confirmation of Payee - the same control the UK mandated in 2020 after its own APP fraud epidemic reached £456 million in a single year. In Australia, it arrives codified in law for the first time today.
Detect requires real-time scam-pattern detection on outbound payments. Behaviourally unusual payments - new payee, atypical amount, device signals that don’t match the account’s history - must trigger friction: warnings, cooling-off periods, or human review based on a risk score. The framework is explicit that banks must not let unusual-pattern payments pass silently.
Disrupt extends the obligation beyond the payer side. Banks must implement mule detection on inbound payments, coordinating anti-money laundering transaction monitoring with scam-detection systems. Intercepting the money-laundering phase - where scam proceeds hit a mule account and get moved - is as much a bank obligation as stopping the outbound transfer.
Respond and Report set standards for handling scam complaints and keeping regulators informed. Banks that drag their feet on compensation do not just face fines - they face adverse-publicity orders. The reputational lever is deliberate: slow-moving banks become named examples.
Non-compliance is not a back-office risk. Three enforcement bodies, $50 million per contravention, and a consumer compensation pathway opening in early 2027. The incentive structure has changed.
Confirmation of Payee: The Control That Should Have Been Here a Decade Ago
The UK introduced Confirmation of Payee in 2020. The research since then is consistent: CoP materially reduces misdirected payments and creates real friction for fraudsters who rely on last-minute account substitution - the moment a payment instruction is about to be sent and the destination account number has been swapped for one the fraudster controls.
Australia watched that experiment for five years before embedding the same requirement in law. As of today, when an Australian bank customer initiates a payment, their bank must check whether the account name they entered matches the name on the destination account. If it does not, the customer must be warned. Banks must handle full matches, partial matches, and mismatches with distinct UX treatments specific enough to survive litigation - because the first bank to present a partial-match warning that a court finds inadequate will be the test case that sets the standard for everyone else.
The logic is sound and the mechanism is necessary. But the bank rail is not where payment fraud starts.
Why CoP Does Not Close the Full Gap
APP fraud losses in Australia hit AUD $1.24 billion in 2023 and are projected to reach $1.76 billion by 2028 without systemic intervention, according to ACI Worldwide’s Scamscope report. Business Email Compromise - the specific fraud type that uses fake or intercepted invoices to redirect business payments to mule accounts - cost Australian businesses $166.8 million in 2025 alone, up 9.3 per cent on the previous year.
Here is how BEC typically unfolds. A fraudster compromises a supplier’s email account, or creates a convincing lookalike domain. They monitor the email thread until an invoice cycle is due, then send the victim business a payment notification with updated bank details. The victim’s accounts payable team updates their system. When the payment hits the bank rail, the account name on the fraudulent account either closely mirrors the supplier’s name or has been set up as a partial match. The CoP system flags a partial match. The accounts payable team, confident they received a legitimate supplier update and seeing an “almost” match, confirms the payment anyway.
The account substitution happened upstream of the bank. By the time CoP runs its check, the fraud is already baked into the payment instruction. The bank did everything the SPF requires - it ran the check and presented the warning. The money still went to a mule account.
CoP closes one specific gap: the spontaneous last-minute account swap on the bank rail. It cannot reach the gap that costs Australian businesses $167 million a year - the injection of fraudulent account details into accounts payable systems before the payment instruction is ever created.
The Numbers Are Not Slowing Down
Scam losses to Australians exceeded $2 billion in the most recent reporting year, according to the National Anti-Scam Centre. APP fraud - where the victim is deceived into authorising a payment themselves - is the fastest-growing category.
The CBA $1 billion AI-powered loan fraud, currently under joint investigation by ASIC, AUSTRAC, and the NSW Police Financial Crimes Squad, illustrates how sophisticated the fraud supply chain has become. In that case, AI-generated fake income statements and tax returns were convincing enough to pass through CBA’s referral network - accountants, lawyers, and real estate agents paid commissions to bring in customers. Twenty-seven people have been charged under Strike Force Myddleton. AUSTRAC has issued a sector-wide warning to major banks about referral program monitoring. ASIC is reviewing loan introduction processes across the industry.
The common thread in BEC, APP fraud, and AI-assisted loan fraud is the same: a trusted identity was impersonated or a relationship was exploited. In every case, the intervention that would have changed the outcome is verification - of the person, the business, and the bank account - before money changed hands.
What Businesses Should Do Before Their Bank’s Next Statement Cycle
The SPF changes what banks are legally required to do. It does not, by itself, protect the businesses sitting upstream of the bank rail from having their payment details changed by a fraudster before a payment is even initiated.
There are practical steps every business can take now.
Treat any change to supplier bank details as a red-flag event. A supplier updating their BSB and account number is the most common BEC trigger. Verify the change out of band - a call to a known contact number from your existing records, not a number provided in the email requesting the change.
Do not rely on partial-match warnings alone. When your bank presents a CoP partial-match warning on a high-value payment, stop and verify the full account details directly with the payee. The warning creates friction; it does not confirm fraud. That decision requires a human with context.
Verify before you add. The moment new payment details enter your accounts payable system is the highest-risk point in the payment cycle. Running a verification check at that point - confirming the BSB and account number belong to the legal entity you think you are paying - closes the gap before any bank-side control even sees the transaction.
Check the ABN, not just the name. Fraudsters set up mule accounts in names that partially match legitimate suppliers. An ABN check against the business register, combined with an account name verification, confirms the entity behind the account number is who you expect. A name-only check is not enough.
The SPF will raise the floor for bank-side controls across Australia. Businesses that want genuine payment protection need to apply the same logic upstream - before the payment instruction is built and before the bank ever sees it.
A Landmark Day, with Work Still to Do
Today marks the start of a new era for payment fraud accountability in Australia. The SPF’s six obligations, the $50 million penalty regime, and the mandatory Confirmation of Payee requirement represent the most significant regulatory uplift this country’s payment system has seen. The framework that took years to design, consult on, and legislate is now operational.
But regulation at the bank level is a floor, not a ceiling. The fraud patterns that cost Australian businesses $167 million in BEC losses last year do not all originate on the bank rail. They originate in email inboxes, accounts payable systems, and supplier onboarding processes that have no verification step at all.
The legal obligation is now on banks to verify at the point of transfer. The commercial imperative is on businesses to verify before the instruction is ever sent.
ezyshield is on a mission to eliminate payment fraud in Australia. We verify the person, the business, and the bank account before money moves - so payments only ever land with who they’re meant to. Learn more
Keep reading
Australia's Scams Prevention Framework Is Now Law - and the September Clock Is Ticking
Australia's Scams Prevention Framework is now law. Banks, telcos and platforms face $50M fines per breach. Here's what changed on 1 July 2026 and what's coming 1 September.
newsConfirmation of Payee Is Live: What It Covers, What It Misses
Australia's banks reached industry-wide Confirmation of Payee coverage in 2026. What it covers, what it misses, and what B2B businesses need to do next.
newsAustralia's Scams Prevention Framework: What Payee Verification Means for Your Business
Australia's SPF consultation closes 25 June. Banks must verify payees before payments. Here's what changes - and what it means for your business.
Stop payment fraud before money moves
Verify the person, business, and bank account before any payment leaves your account.