From HSBC to the Scams Prevention Framework: What Bank and Payment Compliance Teams Should Fix Now
- astridraetze7
- Jul 2
- 2 min read

Scam compliance has moved from a fraud operations issue to a legal, governance and customer-outcomes issue. For banks and payment providers, ASIC’s HSBC action and Treasury’s Scams Prevention Framework should be read together: one shows how existing obligations can already bite; the other shows where the regulatory perimeter is heading.
The practical message is clear. Firms should not wait for every new rule, code or liability pathway to be finalised before testing whether their scam controls, complaints handling, ePayments Code workflows and governance reporting are fit for purpose.
ASIC’s HSBC proceedings placed scam-response failures firmly in the enforcement frame. The case highlighted alleged weaknesses in systems, controls, response times, customer access, investigation processes and compliance with payment obligations. It also reinforced that regulators are unlikely to treat scam losses as solely a customer-behaviour problem where a firm’s own controls, escalation processes or remediation pathways are deficient.
At the same time, Treasury has progressed the Scams Prevention Framework. The framework is intended to impose sector-specific obligations on designated participants, including requirements to prevent, detect, report, disrupt and respond to scams. Banks and payment providers should expect closer scrutiny of how they identify scam risks, share intelligence, communicate with customers and resolve complaints.
Scam risk now cuts across multiple compliance areas: fraud monitoring, AFSL or credit governance obligations, internal dispute resolution, customer vulnerability, privacy, outsourcing, remediation and board reporting.
For ePayments Code subscribers, the issue is especially significant. The Code already sets expectations for electronic payment transactions and unauthorised transaction investigations. The Scams Prevention Framework is likely to add further structure around prevention, detection and response. Together, these developments increase the need for clear, consistent and well-documented scam workflows.
The immediate exposure sits with banks and payment providers. The broader risk extends to fintechs, digital wallet providers, stored-value providers, payment facilitators, remittance businesses, credit providers with payment functionality, and firms relying on outsourced fraud or customer-response functions.
Responsible managers, compliance teams and risk committees should also pay attention. Scam controls are now a governance issue, not merely an operational control.
The first risk is fragmented ownership. Scam incidents often involve fraud, legal, compliance, operations, technology, privacy and customer relations. If those teams apply different timeframes, definitions or decision criteria, the firm may struggle to show a coherent response.
The second risk is weak liability and remediation decision-making. Firms need clear criteria for unauthorised transactions, customer vulnerability, reimbursement, mule-account indicators, account restrictions and escalation to IDR.
The third risk is poor governance reporting. Boards and risk committees need more than aggregate loss figures. Reporting should show typologies, response times, complaint outcomes, remediation amounts, recurring control failures and overdue actions.
Compliance teams should test whether scam controls operate quickly, consistently and fairly. Key areas include real-time monitoring, payment holds, escalation thresholds, customer communications, ePayments Code workflows, IDR hand-offs, remediation records and board reporting.
The strategic question is no longer, “Do we have scam controls?” It is, “Can we prove those controls work when customers are exposed to real harm?”
HSBC shows that existing obligations already carry enforcement risk. The Scams Prevention Framework shows expectations will become more structured. Firms should review their scam-control environment before a regulator, AFCA complaint or serious incident does it for them.




Comments