Govern
Document and implement scam-governance policies, procedures, metrics and targets; review them and obtain senior-officer certification on the statutory cycle.
Banks, telecommunications services and specified digital platforms sit at the centre of Australia's framework. Professional firms are not regulated entities merely because they advise or transact with a client—but they still operate inside the same scam event.
The Scams Prevention Framework Act 2025 creates a structure under which the Minister designates regulated sectors and identifies the services and entities within them. Banking, telecommunications and digital-platform services covering social media, paid search advertising and direct messaging are the intended initial sectors. The designation instruments, rules and sector codes determine the operative detail.
A conveyancer receiving settlement instructions, an accountant handling a refund or an adviser processing a withdrawal is not directly regulated under the SPF simply because a bank, telco or platform is also involved. Professional firms must follow their existing legal, professional, contractual and regulatory duties. The SPF adds direct obligations only where the firm itself falls within a designated sector and meets the regulated-entity test.
The overarching principles are civil-penalty provisions for regulated entities. Sector codes can make them specific to the service and entity. This is an operating system for scam controls, not a promise that every scam will be stopped or every victim reimbursed.
Document and implement scam-governance policies, procedures, metrics and targets; review them and obtain senior-officer certification on the statutory cycle.
Take reasonable steps to prevent scams connected with or using the regulated service, informed by the entity, service, consumers, risks and applicable SPF code.
Investigate actionable scam intelligence and identify affected or potentially affected consumers within the reasonable-steps framework.
Create and share required scam reports and intelligence through the channels and timeframes set by the Act, rules and sector code.
Act on actionable scam intelligence and take reasonable steps to prevent losses from the identified activity.
Provide accessible reporting paths, investigate reports and complaints, communicate outcomes and operate the redress processes that apply to the regulated service.
For a regulated entity, reasonable steps are assessed in context. The Act points to the entity's size, the kind of regulated service, its consumer base, the scam risks those services face and—primarily where applicable—compliance with relevant SPF code obligations. The answer therefore comes from evidence about an operating control, not from a slogan or a single universal checklist.
The framework combines regulator enforcement, external dispute resolution and court remedies. It allows compensation and damages mechanisms where their legal tests are met, but it does not create automatic reimbursement for every scam loss. Outcomes turn on the parties, applicable provisions, causation and the available evidence.
That architecture changes the conversation after an incident. A bank can be asked what its systems detected and how it responded; a platform what it did with actionable intelligence; and a telco how the relevant service was protected. A professional firm remains outside those direct SPF questions unless it is regulated, but may still need to explain the instruction, authority and verification steps on its side of the event.
These are pathways of scrutiny, not new statutory SPF duties for a professional firm. Each forum applies its own rules and must assess the evidence and law relevant to the particular dispute.
The Act permits an existing scheme such as AFCA to be authorised as an SPF external dispute-resolution scheme. In a complaint involving a bank or financial service, the regulated entity's response, intelligence and evidence may be tested. That does not make an adviser, lawyer or accountant an SPF-regulated entity, but a professional firm's instruction and verification records may become relevant facts in the wider transaction history.
SPF does not rewrite a professional firm's policy or decide insurance cover. After a scam loss, however, insurers and claims handlers may examine whether the firm followed its documented procedure, separated duties, verified a changed instruction and retained evidence. The framework's emphasis on operational controls and records can influence the questions stakeholders consider reasonable, without creating a direct SPF duty for the firm.
The Act creates remedies against regulated entities for relevant contraventions and recognises that more than one wrongdoer can be involved. Separate claims against a professional firm still depend on the applicable contract, duty, causation and evidence. A court may examine the full sequence—who received the warning, who controlled the payment, what each party checked and whether a documented stop signal was ignored.
A professional firm should design controls for its own duties and risks, not claim SPF compliance it does not owe. The same disciplined evidence can still help explain the firm's conduct when a scam crosses several organisations.
Show why the interaction entered the high-risk path: new payment details, a changed contact point, unusual urgency, an unexpected representative or a mismatch with the known relationship.
Record where the trusted phone number came from and that it predated the suspicious request. Do not authenticate an instruction using the number supplied by that instruction.
Capture the requester, masked target, method, timestamp, outcome and any failed or abandoned attempt. A failure is evidence to stop and escalate, not a reason to bypass the procedure.
Keep the original instruction, read-back or comparison, approvals, escalation, warnings and final action together so a reviewer can reconstruct what happened before the loss or payment.
Vericode uses possession-based verification. A code goes to the verified phone number held for the real person, not to the contact details supplied in the suspicious request. Australian SMS providers MobileMessage or ClickSend using the ACMA-registered sender ID VERICODE.
Each authorised-contact check creates a timestamped, hash-chained record: who requested it, the masked target, method and outcome. Compliance-authorised users can export the record as PDF or CSV. This supports evidence of a defined check; it does not prove every surrounding instruction was safe or satisfy SPF duties by itself.
Verification evidence, not client files. Customer and verification data — recipient details, messages and verification records — is hosted in Australia. Staff sign-in is handled by our identity provider, WorkOS, in the United States; see the subprocessor information.
Public legislation and commentary are cited for context only. No government, AFCA or Bird & Bird endorsement of Vericode is implied.
Use qualified advice to set the firm's obligations and procedure. Then preserve a consistent authorised-contact check when a live instruction reaches the high-risk path.