News Flash: The Government Cant Protect You From Being Scammed.
Australia has a $2 billion scam problem and a framework designed to fix it — but the auditors just found a critical flaw in how it's being built.
Australians lost at least $2.03 billion to scams in 2024. Nearly half a million scam reports were lodged. The government's response was to build a legislative framework, the Scams Prevention Framework, designed to force banks, telcos, and digital platforms to take scams seriously or face penalties. It was a sensible idea. According to the national audit office, Treasury is not ready to deliver it.
The Australian National Audit Office report, published in late June 2026, is careful in its language, as audit offices tend to be. Treasury's implementation plan is described as "largely appropriate." But peel back the qualifications and the picture is less reassuring. As of March 2026, Treasury had completed 60 of 163 implementation activities. It had also identified 15 major delays and 16 minor delays. The framework is supposed to be operational by the end of 2027. That is not a lot of runway.
The delays are one problem. The deeper problem is what Treasury has not planned for at all.
Treasury has built a framework it cannot measure
The ANAO found that Treasury's implementation planning essentially stops at the point where the framework goes live. There are no arrangements for monitoring whether the framework is actually working once it is operational. There is no benchmark data being collected that would allow anyone to measure outcomes against a baseline. There is no evaluation plan. There is no performance reporting design that would let Treasury tell the government, or the Parliament, or the public, whether this $1 billion industry cost imposition is doing what it is supposed to do.
This is a specific kind of bureaucratic failure, and it matters more than it sounds. A framework with no evaluation mechanism is a framework that can never be found to have failed. It can also never be found to have succeeded. It simply exists, generating compliance costs, regulators, and reports, while the question of whether Australian consumers are being scammed less remains permanently unanswerable. The framework is meant to coordinate the work of four separate regulators: the ACCC, ASIC, ACMA, and the Australian Financial Complaints Authority. Treasury is supposed to advise government on their collective performance. It has not yet established the arrangements to do that.
A framework with no evaluation mechanism is a framework that can never be found to have failed.
Treasury agreed to all four of the ANAO's recommendations, which is standard practice and, by itself, means nothing. Agencies agree to audit recommendations as a matter of course. The question is whether the recommendations get implemented, whether they get implemented well, and whether the underlying institutional incentives that produced the gap in the first place have changed. The audit cannot answer any of those questions. That is the work of the next audit.
The policy logic is sound — the implementation risk is not
There is a genuine policy logic to the Scams Prevention Framework. The previous approach, which amounted to consumer education and voluntary industry codes, was not working. Banks and telcos had little reason to invest heavily in scam prevention when the cost of a scam fell primarily on the customer. Shifting liability changes that calculus. If a bank can be held responsible for failing to detect a scam, it has a direct financial incentive to detect scams. That is a coherent mechanism. It is how similar frameworks have operated in the United Kingdom, and there is reasonable evidence the UK's mandatory reimbursement regime reduced certain categories of fraud.
The problem is not the design of the policy. The problem is that a policy is only as good as its implementation, and implementation requires someone to be clearly responsible for outcomes, to have the tools to measure those outcomes, and to be accountable when the outcomes do not arrive. Right now, Treasury is building the plane while running down the runway, has not decided what altitude counts as flying, and has no instruments to check.
The scams won't wait for Treasury to catch up
Scams are not a static threat. The people running them are adaptive, technically sophisticated, and increasingly using artificial intelligence to make fraudulent communications indistinguishable from legitimate ones. A regulatory framework that takes years to become operational, and then lacks the monitoring architecture to detect whether it is working, is not well matched to that threat. By the time Treasury has the evaluation arrangements in place to determine whether the framework succeeded, the scams it was designed to stop may have evolved into something the framework was never designed to address.
Australians are being told there is a framework coming that will make them safer. That may be true. But right now, the scaffolding is incomplete, the instruments are missing, and the people building it do not yet have a plan for how they will know if it works.
Sources
Frequently Asked Questions
What is Australia's Scams Prevention Framework and when does it start?
The Scams Prevention Framework is a legislative regime that compels banks, telcos, and digital platforms to take active steps to prevent scams or face financial penalties. It is designed to be operational by the end of 2027, though as of March 2026 Treasury had completed fewer than half of its 163 implementation activities.
Why can't Treasury just measure whether the framework is working once it launches?
Because measuring outcomes requires baseline data collected before the framework goes live — without it, there is nothing to compare results against. Treasury has not yet established the benchmarks, evaluation plans, or performance reporting arrangements needed to assess whether scam losses actually fall once the framework is operational.
What happens if one of the four regulators overseeing scams fails to do its job?
Right now, nobody has a clear answer. The framework relies on the ACCC, ASIC, ACMA, and the Australian Financial Complaints Authority working in coordination, with Treasury advising government on their collective performance. Treasury has not yet established the arrangements to do that coordinating work.
Did the UK's approach to scam prevention actually work?
The UK introduced mandatory bank reimbursement for certain fraud categories, and there is evidence it reduced losses in those specific categories. Australia's framework draws on that model, but the UK experience also showed that scammers adapt quickly to new regulatory environments — which is part of why monitoring and evaluation architecture matters so much.
Does Treasury agreeing to the ANAO's recommendations mean the problems will be fixed?
Not necessarily. Agencies routinely agree to audit recommendations as a matter of procedure. Whether the recommendations are implemented well, and whether the institutional incentives that created the gaps have actually changed, are questions only a future audit can answer.