Thank you, Mr. Chair.
Good evening, and good morning from Australia.
My name is Nicholas Giurietto, and I head financial crime policy at the Australian Banking Association. That's the main industry representative body for the banking sector in Australia. My area of responsibility includes AML-CTF, cybersecurity and scams, and I've been heavily involved in the development and now implementation of the Australian government's scam prevention framework. This has involved collaboration with government policy bodies, various regulators and colleagues from other industry sectors.
The unifying purpose of all of these stakeholders is a shared desire to keep Australians as safe as possible from the scourge of scams conducted by global organized crime gangs. Our approach is to work together to stop scams before they happen, not simply requiring one part of the scam chain to take responsibility for protecting or refunding customers. It's about acknowledging the complexity of our digital world by working together to stop scams at the source. The Australia scam prevention framework has attracted a lot of attention around the world as the first example of an anti-scams regulatory regime based on the principle that all industry sectors must do their share to tackle scams.
Going first is hard. There are many details to be worked through in translating an important simple policy proposition into real world implementation. That can be difficult in practice. Some of the challenges still remain to be resolved in Australia. Nevertheless, the early signs are positive, and we remain more convinced than ever that the only way to minimize the devastating harm that scams cause to everyday Australians is a coordinated cross-sectoral ecosystem approach with each industry sector doing their bit.
The scam prevention framework has two basic principles. The first is recognizing that sophisticated methods of a scam attack occur across industry sectors and indeed often deliberately exploit the gaps between them. The scam prevention framework requires all sectors in the scam chain to take appropriate action to prevent, detect and respond to scam attacks.
Each sector has a responsibility to harden their business processes against scammers with analogous but industry-specific obligations. For example, the requirement on banks to apply rigorous know-your-customer checks when opening an account is matched with an analogous obligation on telcos to check the legitimate business need for a SIM box capable of sending tens of thousands of SMS messages in an hour, or an obligation on digital platforms to confirm the bona fides of an advertiser of an investment product. The exact obligations are different, but the purpose for each sector is the same: trying to keep bad actors out of the system from the start.
In Australia, we have commenced the SPF rollout with the three core sectors: banks, telcos and digital platforms. This acknowledges the practical fact that you have to start somewhere. However, it's acknowledged that our national suit of armour against scams will not be complete until all other sectors that can be involved in a scam chain are also part of the coordinated response. These include crypto exchanges, non-bank money remitters, remote access software providers, online marketplaces, gift card providers and many more. Unfortunately, the ingenuity of scammers knows few limits, and it is of little comfort to a scam victim to know that the front door to their life savings has been kept secure when thieves have been able to climb in the window.
The second key principle of the SPF is cross-industry data sharing: facilitating the secure and privacy-compliant exchange of data that indicates a scam risk. Actionable scams intelligence, as it is described in the SPF legislation, is an essential tool in the anti-scam response.
Despite the best efforts of all participants, it is not always possible to protect the first victim from the scam, but the rapid exchange of actionable scam intelligence, followed by prompt action—for example, taking down a scam website or blocking a compromised telephone or bank account—can quickly close that vulnerability and protect the hundreds or even thousands of potentially subsequent victims. Scammers can continue to probe the defences, but by reducing their success rate and increasing the cost of their business model, we make Australia a less attractive target.
The most effective approach to deliver cross-industry data sharing is through private-to-private collaboration—for example, through the Australian Financial Crimes Exchange, which I understand will be providing testimony today—with appropriate linkages to law enforcement. The key role of government is to provide the policy framework that enables secure and privacy-compliant data exchange with appropriate safe harbour protections.
I will conclude my initial comments at this point and would be delighted to offer any further insights from our experience in Australia that the committee may wish to request.