Back to Blog
Launch Strategy7 min readSeptember 13, 2026

Australia's New Scam Law Puts Your App in Scope From This Month

Australia's Scams Prevention Framework brought mandatory AFCA membership for digital platforms on 1 September 2026, with penalties up to AUD $50 million per contravention.

Alex Rivera

Alex Rivera

Growth at NeedBase

Australia's Scams Prevention Framework (SPF) Rules commenced on 1 September 2026. From that date, membership of the Australian Financial Complaints Authority's (AFCA) dispute-resolution scheme became mandatory for banks, telcos, and digital platforms โ€” and the framework names social media, messaging, and search services specifically. If your SaaS product lets Australian users message one another, browse a marketplace, or search for content within the app, this law is now written with you in mind.

A lighter "reasonable steps" obligation had already applied since 1 July 2026. The full framework โ€” covering prevent, detect, disrupt, report, and respond duties โ€” takes effect from 31 March 2027. That is the date that matters most for planning, because building the processes the framework requires takes months, not weeks.

Why "digital platform" now includes you

Previous Australian scam rules focused on banks and telecommunications carriers. The SPF widens the regulated perimeter to any digital platform with social media, messaging, or search functionality, regardless of size. There is no small-business carve-out described in the published rules. A SaaS product with in-app messaging between users, a marketplace or listings feature, or a search function that surfaces user-generated content should treat itself as potentially in scope and check the detail of the rules rather than assume the law is aimed only at the largest platforms.

According to the Australian Competition and Consumer Commission (ACCC), which administers the framework, the regulated sectors are defined broadly enough to capture platforms that facilitate contact between an Australian consumer and a scammer โ€” whether that contact happens over a chat feature, a listings page, or a search result.

What AUD $50 million per contravention means for a small company

The framework carries civil penalties of up to AUD $50 million per contravention, and it creates a private right of action letting affected consumers sue for damages directly. For a large bank, a single penalty is a cost of doing business. For a small SaaS company, a single enforcement action tied to one scam incident could be existential, and the private right of action means the exposure isn't limited to regulator attention โ€” an individual user can bring a claim.

That asymmetry is the reason to treat this as a now problem rather than a 2027 problem. A large platform can absorb the cost of hiring a compliance team in the first quarter of 2027. A ten-person SaaS company cannot build a dispute-resolution process, a scam-detection workflow, and AFCA membership in the weeks before a deadline without cutting corners somewhere.

What to check now

Start with three questions. First, does your product have any feature that lets an Australian consumer be contacted by, or send money or information to, another party through your platform โ€” messaging, a marketplace, forums, or search results that surface third-party listings? Second, do you have any dispute-resolution process today for a user who claims they were scammed through your product, and does it meet a standard a regulator would recognise? Third, have you reviewed whether the "reasonable steps" obligation that started 1 July 2026 already applies to you, since that threshold is lower than the full framework's.

The Treasury's published draft rules and codes, and law firm Ashurst's summary of them, both set out the specific obligations tier by tier. Read the actual rule text rather than relying only on secondary commentary, because the exact scope language determines whether your feature set puts you in or out.

What to start building before 31 March 2027

Three things take real time to stand up, so start now rather than in early 2027. Membership of AFCA's dispute-resolution scheme is mandatory from 1 September 2026 for the sectors it covers โ€” if you're in scope, get that membership process started rather than waiting to see if enforcement arrives. A written, workable process for what happens when a user reports a scam โ€” who reviews it, what evidence gets collected, how a decision gets communicated, and how it's logged โ€” needs testing before it's needed for real. And the "prevent, detect, disrupt, report, respond" duties in the full framework are five separate operational capabilities, not one policy document; each one needs an owner and a process, and detection and disruption in particular usually require product changes, not just paperwork.

If you serve Australian users and any part of your product involves user-to-user contact, put an SPF scope assessment on your roadmap this quarter, not next year. A short piece of legal advice now, confirming whether you're in scope and what tier applies, is far cheaper than discovering the answer during an AFCA complaint.

The bottom line

The Scams Prevention Framework's mandatory AFCA membership and reasonable-steps obligations are already in force, and the full prevent-detect-disrupt-report-respond regime lands on 31 March 2027 with penalties of up to AUD $50 million per contravention and a private right of action for consumers. If your product has messaging, marketplace, or search features touching Australian users, check your scope now and start building the dispute-resolution and detection processes this year, not in the first quarter of 2027.

This is general information, not legal advice. Rules and figures can change; verify current details with a qualified professional in your jurisdiction.

Found this useful?

Share it with a founder who needs it.

Ready to launch your product?

Join thousands of makers who launched on NeedBase.

Submit Your Product โ†’