AFCA’s expanded scams jurisdiction and how it assesses liability

AFCA scams

On 15 March 2026, a receiving bank accepts a transfer into what appears to be an ordinary retail account. The funds have come from a customer of another bank who believes they are paying for a legitimate investment. By the next morning, the money has largely disappeared through a series of onward transfers. Days later comes a surprise. The receiving bank is contacted not by its own customer, but by the person who lost the money. They want answers: why was the account opened, were there warning signs, and could the bank have intervened? Until recently, the institution could have argued that these were someone else's questions to answer. But the Australian Financial Complaints Authority (AFCA) can now look beyond the sending bank and examine the conduct of receiving banks as well. The result is a wider complaints net, and a major shift in where scam-related liability risks may emerge.

Key takeaways

  • Since 12 March 2026, AFCA has been able to consider scam complaints against receiving banks, not only the victim’s own bank.

  • AFCA can also consider complaints about unauthorised account opening, including where the complainant is not the bank’s customer.

  • The change creates no new statutory duty of care, but receiving banks may still face liability through AFCA’s fairness jurisdiction.

  • For sending banks, liability continues to turn largely on whether the transaction was authorised or unauthorised.

  • Authorised scam payments are assessed through the “duty to inquire”; unauthorised transactions are generally assessed under the ePayments Code.

  • AFCA cannot yet review the adequacy of a bank’s scam-detection systems or require particular controls. The Scams Prevention Framework (SPF) is expected to address that gap.

  • Banks should update internal dispute resolution (IDR), evidence retention and fraud-response processes now, not wait for the SPF.

This change is not waiting for the SPF

Major changes to the scams regulatory environment will be coming into force in March 2027 with the SPF (see our recent article), but banks do not need to wait until then to face a wider scam-related complaints risk.

The changes made on 12 March 2026 mean that AFCA can now investigate scam-related complaints involving:

  • receiving banks — the institution that received funds transferred as part of a scam, where those funds often flow into “mule” accounts; and

  • unauthorised account opening — where an account or credit facility is opened in a consumer’s name without their consent or authority.

AFCA can consider these complaints even where the complainant is not a customer of the bank in question. Every local bank in the chain of scam funds can be brought before AFCA.

The change flows from the Government’s March 2025 decision to amend the conditions of AFCA’s authorisation to allow it to consider the actions of a receiving bank.

A few procedural points to note:

  • A consumer who wants both the sending and receiving bank investigated must lodge against each bank separately. They are treated as separate complaints.

  • Historic events are in scope, within standard time limits. Consumers can complain about receiving bank and unauthorised-account events that occurred before 12 March 2026, provided the complaint is lodged within the earlier of six years of becoming aware of the loss and two years of an IDR response.

  • Jurisdiction is fixed at the date of lodgement. A complaint that was outside AFCA’s jurisdiction when first lodged stays outside, even if re-lodged after 12 March 2026.

  • AFCA expects both receiving and sending banks to complete IDR before it will investigate — including where the complainant is not the receiving bank’s customer. Complaints that have not been through IDR will be referred back.

New AFCA guidance

AFCA has also updated its published guidance on how it investigates scam complaints and assigns liability. The new guidance includes factsheets on:

Receiving banks - expanded jurisdiction, unchanged duties

The expanded AFCA jurisdiction does not create new legal obligations or duties of care owed by banks to consumers who are not their customers. AFCA makes clear in its guidance that the legal obligations banks owe to non-customers remain limited, and that further consumer protections are expected to come with the SPF.

So how can a receiving bank be found liable to someone who is not its customer? Through AFCA’s fairness jurisdiction. AFCA decides complaints on what is fair in all the circumstances, having regard to legal principles, applicable industry codes, good industry practice, and its previous decisions. That standard allows AFCA to hold a receiving bank to account where it has fallen short of good industry practice, even in the absence of a strict legal duty.

AFCA’s guidance on receiving banks includes hypothetical examples.

  • In one example, a receiving bank that ignored multiple confirmed fraud reports received through the Fraud Reporting Exchange (FRX), and failed to restrict the mule account as its own fraud policy required, would be exposed to compensating the victim’s financial loss.

  • A receiving bank that froze funds but then lifted the restriction through human error before completing its investigation was similarly exposed.

  • A bank that opened an account on stolen identity documents without checking the Document Verification Service (DVS) — described by AFCA as standard industry practice — faced orders to close the account and compensate for non-financial loss.

Receiving banks now carry meaningful exposure, and the AFCA measure is good industry practice. This includes freezing accounts on notice of confirmed fraud, acting on FRX and regulator warnings, and verifying identity properly at account opening.

The position is different for sending banks. For them, AFCA’s analysis continues to begin with the character of the transaction: was it authorised or unauthorised?

Sending banks - how AFCA assesses liability

For the sending bank, AFCA’s approach continues to turn mainly on the question whether the disputed transaction was authorised or unauthorised.

AFCA says that a transaction is authorised if the customer made it, or authorised a third party to make it — even where the customer was tricked into doing so. It is unauthorised if a third party made it without the customer’s knowledge or consent. The two categories are assessed very differently.

Authorised scam payments - the duty to inquire

Where a customer authorised the payment, the bank’s primary duty is to act on the customer’s instructions. But that duty is not absolute. AFCA applies a “duty to inquire”: where an honest and reasonable banker, with knowledge of the relevant facts, would consider there was a serious possibility the customer is being scammed, the bank should make further inquiries before processing the payment.

Whether that duty arises depends on the circumstances. In-branch and telephone instructions give staff more opportunity to detect confusion or third-party influence. Online payments offer less opportunity, but the duty can still arise where the bank has special knowledge about the transaction or the recipient account.

AFCA’s examples of special knowledge include regulator or Scamwatch warnings that the recipient account may be connected with scams, or a fraud-detection alert triggered by the bank’s own systems. In practical terms, the question is whether the bank knew something material about the payment risk that the customer did not know, and whether appropriate inquiries were made before the payment was processed.

If the bank did make inquiries, AFCA asks whether they were meaningful and relevant and not merely scripted. Where the inquiries were meaningful and the bank was reasonably satisfied by the customer’s answers, AFCA is unlikely to find it liable.

There is a limit on how far this goes. In the absence of any legislative framework for scam detection, AFCA cannot review the adequacy of a bank’s scam-detection systems. The SPF may fill that gap.

Unauthorised scam transactions - the ePayments Code

AFCA’s factsheet gives examples of common unauthorised transaction scams. They include impersonation scams, phishing scams, remote-access scams and digital-wallet scams. These typically involve the scammer manipulating the customer into disclosing personal information, passwords or one-time passcodes, or giving the scammer remote access to a phone or computer. AFCA also makes clear that a transaction is not unauthorised merely because the customer intended to pay someone else, if the customer carried out the payment themselves or authorised another person to do so.

Where a customer disputes a transaction as unauthorised, AFCA’s first step is to decide whether the most likely explanation is that the transaction was authorised or unauthorised. It does this on the balance of probabilities, after considering the information provided by both parties. AFCA says it will give greater weight to documents created at the time of the disputed transactions. If the evidence is evenly balanced, so that it is equally likely the transaction was authorised or unauthorised, the customer’s claim that the transaction was unauthorised is not established. In that case, AFCA assesses the matter under its authorised transactions approach.

If AFCA finds the transaction is more likely unauthorised, liability will usually be determined under the ePayments Code. The Code is voluntary but binding on subscribing firms. It applies to electronic transactions, such as internet banking, mobile banking and card transactions, but only where the facility was not established primarily for business purposes.

Under the ePayments Code, the question is whether the customer contributed to the loss by breaching the passcode-security requirements; for example, by voluntarily disclosing a passcode, recording it without disguising it, acting with extreme carelessness, or delaying reporting. Two features favour the consumer: the onus is on the bank to prove contribution on the balance of probabilities (and, where multiple passcodes were required, that the breach was more than 50% responsible), and disclosure only counts where it was genuinely “voluntary”. AFCA recognises that in some cases it is not.

AFCA also retains a discretion to reduce a customer’s liability, for example where no reasonable daily transaction limit applied. For business facilities, including business accounts that are not subject to the ePayments Code, AFCA will not apply the Code liability rules unless the account terms adopt them. Instead, liability turns on the account terms and conditions, the general law and good industry practice. AFCA says it will publish further guidance on how it will assess liability in those matters.

Evidence AFCA is likely to request

For both authorised and unauthorised transaction complaints, AFCA’s factsheets also give a high-level indication of the information it is likely to request. In broad terms, AFCA will usually seek the customer’s account of what happened and the bank’s transaction records, communications, investigation notes, applicable terms and conditions, and any relevant fraud or recovery material. These are a useful guide as to the information that a bank can be expected to be asked to provide as part of the complaint resolution process.

Non-financial loss compensation

The AFCA factsheets also explain that AFCA may award non-financial loss compensation where the bank’s response to a scam complaint was inappropriate, for example because it delayed raising a recall request, delayed notifying the customer of the outcome, failed to meet applicable ePayments Code investigation timeframes, or failed to give reasons. The factsheets give examples of actual AFCA cases, but those examples are illustrative rather than binding rules.

The bridge to the SPF

While AFCA has expanded jurisdiction across the whole payment chain and has refreshed its guidance, the standards it applies currently remain the pre-SPF standards — the duty to inquire, the ePayments Code, and good industry practice.

The SPF will lift those standards into mandatory, enforceable code obligations, close the systems-adequacy gap AFCA has flagged, and formalise receiving bank disruption duties (such as payment recall and account blocking) that AFCA currently reaches only through its fairness jurisdiction.

In practice, the good-industry-practice benchmarks emerging from AFCA’s decisions are a preview of the SPF code obligations banks will need to meet in any event.

What should banks do now?

  • Receiving banks

    • Uplift mule-account detection and response. Ensure confirmed fraud reports, FRX notices and regulator warnings are triaged and actioned promptly.

    • Restrict accounts when required. Check that staff understand when to freeze or restrict accounts and that restrictions are not lifted before investigations are complete.

    • Review account-opening controls. Confirm that DVS checks are completed, evidenced and escalated where stolen-document indicators arise.

  • Sending banks

    • Strengthen duty-to-inquire processes. Review how higher-risk payments are identified and how customer inquiries are conducted.

    • Avoid scripted questioning. Ensure frontline staff ask questions that are meaningful and responsive to the specific scam risk.

    • Improve unauthorised-transaction assessments. Make sure ePayments Code decisions are supported by evidence about passcode disclosure, voluntariness, reporting delays and transaction limits.

  • All banks

    • Prepare IDR for the wider jurisdiction. Confirm the process can handle receiving bank complaints, non-customer complaints, unauthorised account-opening complaints and historic matters.

    • Improve evidence capture. Retain fraud notes, contact records, call recordings, warning records, identity-verification records and payment-recall timelines.

    • Use AFCA readiness as SPF preparation. Map AFCA’s good-industry-practice benchmarks against SPF gap assessments.

Conclusion

AFCA’s expanded jurisdiction does not create a new statutory scam duty, but it does change the practical risk landscape. Receiving banks, sending banks and account-opening processes can now be examined through a broader complaints lens, with AFCA applying existing legal obligations, industry codes and good-industry-practice standards.

Banks should not wait for the SPF codes to commence. The SPF will raise and formalise the standard, but AFCA’s expanded jurisdiction is already here. IDR, fraud response, account restrictions, customer inquiries and evidence retention should be reviewed now.

Get in touch if you’d like to discuss how AFCA’s expanded scams jurisdiction affects your business, or how to align your fraud controls with the incoming Scams Prevention Framework.

‍ ‍

Next
Next

Financial Services and Credit Monthly Update June 2026