Two of Australia’s key dispute resolution bodies have formalised how they will work together ahead of a scam complaints regime that will change how losses are attributed across sectors – including, eventually, insurance.
The Australian Financial Complaints Authority (AFCA) and the Telecommunications Industry Ombudsman (TIO) signed a Memorandum of Understanding (MoU) in September 2026, setting out information-sharing arrangements, referral processes, and regular communication protocols as the Scams Prevention Framework (SPF) moves toward full implementation.
For insurance professionals, the coordination agreement is worth watching – not for what it does administratively, but for what the broader framework signals about where liability for scam losses is heading.
Australians reported combined scam losses of $2.18 billion in 2025 – up 7.8% on the previous year – according to the Australian Competition and Consumer Commission’s (ACCC) Targeting Scams Report, released in March 2026.
Investment scams were the largest category at $837.7 million. Payment redirection scams accounted for $166.8 million – a figure directly relevant to the coverage questions brokers are now being asked to address.
The SPF, passed by Parliament in February 2025 as world-first scam prevention legislation, was built to distribute responsibility for those losses across the sectors through which scams operate. Under the framework, AFCA can consider the conduct of each business connected to a complaint and apportion compensation accordingly.
AFCA will begin accepting complaints under the framework from March 31, 2027. That date is a deadline, not a distant horizon.
Read next: Scam losses are up – but the real story is in the policy wording
The agreement prevents the same conduct from being examined by AFCA and the TIO simultaneously, routes complaints to the correct body, and establishes referral pathways where both organisations are involved.
AFCA CEO and chief ombudsman David Locke (pictured) said the arrangement is aimed at reducing friction for consumers and telcos. “Working closely with the TIO will help us make the complaints process as clear and straightforward as possible for consumers and telecommunications companies, particularly where a complaint involves both organisations,” Locke said.
AFCA chief scams officer Dave Lacey said the MoU also brings clarity for industry. “It will also give industry greater clarity and help avoid the same conduct being considered by both organisations,” Lacey said.
Telecommunications industry ombudsman Cynthia Gebert said closer coordination removes navigation burdens from consumers already dealing with scam fallout. “People shouldn’t have to navigate multiple pathways for help. Stronger collaboration between AFCA and TIO means consumers benefit from our combined expertise and can focus on resolving their concerns, knowing they’ve got the right support for their situation,” Gebert said.
AFCA has welcomed 118 new members under the SPF – 98 telcos and 16 digital platforms – including Apple, Google, Meta, Microsoft, TikTok, and X.
Entities required to hold AFCA membership under the framework faced a deadline of September 1, 2026. Those that missed it may face civil penalties.
The SPF currently covers banks, telecommunications providers, and digital platforms. Insurance is not yet a designated sector – but the government has put the superannuation, insurance, and cryptocurrency industries on notice as fast followers, under an expansion mechanism that gives the minister power to designate new sectors over time, according to law firm Johnson Winter Slattery.
The Insurance Council of Australia (ICA) engaged early. In a January 2025 submission to the Senate Economics Legislation Committee, the ICA recommended clarification on the legislation’s scope and called for a phased rollout if general insurance is designated. It also noted that scam types targeting insurers – phishing schemes, fraudulent insurance websites, and fake claim fee requests – differ from those targeting banks, and argued those differences warrant tailored obligations rather than direct equivalence.
The ICA has also been building infrastructure ahead of formal designation. In November 2025, it announced a national fraud detection and investigations platform being built with Shift Technology and EXL, through its counter-fraud division the Insurance Crime Intelligence Network of Australia (ICINA). Development was expected to begin in early 2026, with motor insurance as the first focus area.
Read next: The scam liability framework brokers cannot afford to ignore
The liability question the SPF creates – who pays when a scam loss crosses multiple sectors – has a direct read-across to policy wordings.
Coalition’s 2026 Cyber Claims Report, drawn from more than 100,000 policyholders globally, found that business email compromise (BEC) and funds transfer fraud (FTF) together accounted for 58% of all cyber insurance claims in 2025. Of those, 52% of funds transfer fraud claims originated as a business email compromise incident, carrying an average loss of AU$159,000.
Payment redirection scams sit squarely in this territory. Social engineering remains a common attack vector in Australia, with threat actors impersonating trusted parties to obtain access credentials, according to Gallagher’s September 2025 Cyber Insurance Market Update. When an employee is deceived into transferring funds rather than a system being technically compromised, some insurers classify the loss as a crime event rather than a cyber event – placing it outside the core cyber insuring agreement entirely.
Coalition Australia raised its standard cybercrime coverage for eligible occupations to AU$500,000 in June 2025, after claims data showed average funds transfer fraud losses had exceeded AU$250,000. The fact that the market moved on limits reflects how often existing sublimits were leaving clients exposed for the losses they were most likely to face.
The regulatory context adds further urgency. In May 2026, Australian Securities and Investments Commission (ASIC) Commissioner Simone Constant issued an open letter to all AFS licensees identifying cyber resilience as a core licensing obligation. ASIC has since commenced proceedings against Fortnum Private Wealth over alleged cybersecurity failures, following earlier action against RI Advice. For brokers placing cover for AFS licensees, the adequacy of cyber and professional indemnity programmes is a live question.
Checking whether a client’s policy covers social engineering and funds transfer fraud as standard – rather than as a sublimited extension – and whether those limits reflect current average loss figures, is a practical step brokers can take before the SPF’s complaint-handling framework becomes fully operational in March 2027.