By Joshua Clouston, Head of Product, ezyshield
Australia's Scams Prevention Framework: What Payee Verification Means for Your Business
Australia's SPF consultation closes 25 June. Banks must verify payees before payments. Here's what changes - and what it means for your business.
Last year, Australians lost $166.8 million to payment redirection fraud - not through hacking, not through data breaches, but because someone paid the wrong bank account. The invoice looked right. The email looked right. The only thing missing was a check on whether the account actually belonged to who it claimed to.
In 13 days, the consultation window on Australia’s Scams Prevention Framework closes. When it does, the era of “we paid who we were told to pay” as a complete defence ends.
Why $166.8 Million Walked Out the Door Last Year
Payment redirection fraud - also called business email compromise or invoice fraud - is the second-biggest scam category in Australia by dollar value. The ACCC’s 2025 Targeting Scams report puts total scam losses at $2.18 billion, with payment redirection accounting for $166.8 million of that across 481,523 total scam reports.
The mechanics are straightforward. A criminal intercepts legitimate email correspondence - between a business and its supplier, or a firm and its client - and substitutes new bank account details into an invoice or payment request. The victim pays. The money lands with the criminal. The real supplier never sees it.
The AFP flagged a 66 per cent increase in BEC losses in 2024, with the construction sector hit hardest. Total BEC losses that year reached $152.6 million, up from $91.6 million in 2023. AFP Assistant Commissioner Richard Chin put it plainly: “The construction sector, with its high-value transactions and complex subcontracting chains, has become an attractive target for organised cybercrime groups operating both domestically and offshore.”
A Tasmanian homeowner had $120,000 taken after scammers intercepted her email correspondence with a construction company. In a South Australian case, a conveyancing firm’s email was compromised and a client was sent a fraudulent invoice for $338,000. The AFP’s Operation Dolos recovered the full amount in the SA case - but recovery at that scale is the exception, not the rule.
The common thread: nobody verified the bank account before the payment left.
What the Scams Prevention Framework Actually Requires
The Scams Prevention Framework (SPF) passed Parliament earlier this year. It designates banks, telecommunications providers, and digital platforms as entities with mandatory obligations. Treasury is consulting on the draft rules and codes - submissions close 25 June 2026.
The bank-sector obligations that matter most for payment fraud:
- Payee name verification - before transfers are processed, banks must check that the account name matches what is held on file. If the invoice says “Jones Building Pty Ltd” but the account belongs to someone else, that mismatch must surface before the payment completes.
- Transaction monitoring - banks must identify high-risk scam activity and notify affected customers in real time.
- Reversal and blocking - where scam activity is confirmed, banks must act to reverse transactions and block associated accounts.
- Identity verification - customer and payee identity must be verified before services are provided.
Payee name verification is the lever that changes the payment redirection equation. The UK’s Confirmation of Payee scheme - a direct equivalent - reduced misdirected payments by 35 per cent in the first year after mandatory rollout to the six largest banks. Australia has observed that result closely.
The $50 Million Penalty and the Liability Shift
The penalty structure is where the SPF gets its force. Breaching entities face civil penalties of up to $50 million per contravention. Multi-entity breaches - where a scam crosses a bank, a telco, and a digital platform - share liability equally by default.
The core test for liability is whether an entity took “reasonable steps” to prevent the scam. That test applies to the entity’s conduct, not the victim’s experience. A bank that processes a high-value payment without checking whether the payee account name matches the invoice will struggle to argue it met the standard.
On 28 May, Assistant Treasurer Daniel Mulino announced the $3,000 automatic reimbursement threshold as part of the SPF rules. Verified scam losses under $3,000 are reimbursed automatically - no investigation required. Losses above that threshold go through AFCA’s dispute resolution process.
Meta, for its part, argued the reimbursement scheme could reduce consumer vigilance and “embolden criminal scam syndicates.” The Government proceeded regardless.
AFCA and the New Disputes Landscape
The Australian Financial Complaints Authority becomes the single external dispute resolution body for scam complaints under the SPF. Membership for newly designated entities opens 1 July 2026 - three weeks from now. Full SPF-aligned complaint handling begins 31 March 2027.
AFCA’s jurisdiction already expanded in March 2026 to cover receiving banks. This is a structural shift: if a scammer opens a mule account at Bank B, and a victim banked at Bank A sends money to that account, Bank B can now be named in a complaint - even though the victim was never Bank B’s customer.
For businesses, the practical implication is this: when a payment redirection fraud ends up in a dispute, AFCA will trace accountability across the whole payment chain. The bank that verified, monitored, and maintained clean account records will have a defensible position. The bank that did none of those things will not.
The Consultation Closes in 13 Days - What Happens Next
Key dates after 25 June:
- 1 July 2026 - AFCA membership opens for newly designated SPF entities
- 1 September 2026 - SPF Rules commence; designated entities must be AFCA members
- 31 March 2027 - Sector codes commence; AFCA begins handling SPF-aligned complaints
Entities must also provide signed statements of compliance within 21 calendar days of receiving a scam complaint. This puts named senior officers on the hook for their firm’s conduct - it is not a delegatable administrative task.
For businesses outside the designated sectors - construction firms, professional services, logistics, property - the SPF does not impose direct obligations. But it changes the environment. Banks under compliance pressure will increasingly embed verification into the payment flow itself, and businesses that build their own verification layer above that will be better placed when disputes arise.
Verify Before You Pay: Where the Gap Still Lives
The SPF’s payee verification requirement operates at the bank layer. But the fraud pattern in construction, conveyancing, and professional services typically involves a compromised or spoofed email chain that sits above the bank’s visibility entirely.
A contractor emails a payment instruction. The email looks authentic. The BSB and account number look plausible. Nothing in the bank’s system flags it - because the bank has no way of knowing the email was intercepted upstream.
Verification that closes this gap needs to happen before the payment reaches the bank. Checking that the account belongs to the entity named on the invoice - against ABN records, business registration, and account-holder data - at the point of invoice approval rather than at the payment gateway is what changes the outcome.
By the time money arrives at the bank’s payment system, the victim has already been socially engineered. The fraud has already succeeded in all but the funds transfer. Building the verification step into accounts payable - before the payment instruction is approved - is what breaks the attack at its weakest point.
The AFP’s Operation Dolos has recovered funds in some cases by acting within hours of payment. But the window is narrow. Once funds move internationally, recovery rates fall sharply. The only reliable intervention is before the payment leaves.
The Numbers Behind the Urgency
One in seven Australians experienced personal fraud in 2024-25, according to ABS data released in March 2026. That is 3.2 million people. Card fraud alone hit 2.3 million Australians - double the figure from a decade ago - with $2.2 billion in losses.
Authorised push payment fraud, the category that includes payment redirection, is projected to reach $1.76 billion annually by 2028 if current trends hold. The SPF is the government’s structural response: mandatory obligations, civil penalties, and an independent dispute body to adjudicate when things go wrong.
The UK ran this experiment first. APP fraud reimbursement combined with Confirmation of Payee bent the curve within twelve months. Australia is building toward the same model. The consultation closes in 13 days.
ezyshield is on a mission to eliminate payment fraud in Australia. We verify the person, the business, and the bank account before money moves - so payments only ever land with who they’re meant to. Learn more
Keep reading
Australia's Scams Prevention Framework Is Now Law - and the September Clock Is Ticking
Australia's Scams Prevention Framework is now law. Banks, telcos and platforms face $50M fines per breach. Here's what changed on 1 July 2026 and what's coming 1 September.
newsAustralia's Scams Prevention Framework Is Live - and Confirmation of Payee Is Now the Law
Australia's SPF Stage 1 went live 1 July 2026. Banks must now verify payees before money moves or face $50M fines. Here's what changed - and what still hasn't.
newsConfirmation of Payee Is Live: What It Covers, What It Misses
Australia's banks reached industry-wide Confirmation of Payee coverage in 2026. What it covers, what it misses, and what B2B businesses need to do next.
Stop payment fraud before money moves
Verify the person, business, and bank account before any payment leaves your account.