The scams prevention framework legislation was passed by Australian Parliament in February of last year. The enabling regulation has begun to work its way through the system. The basic structure is that each key industry sector—the digital platforms, the telecommunications sector and the banking sector—have a set of obligations under the headings of “detect”, “prevent” and “respond to” scams. There are a few others, such as governance, but these are the three most important ones.
They are responsible to their sector regulator. In the case of the banking sector, our normal regulator, the Australian Securities and Investments Commission, is the regulator for us for scams. It's similar for telcos and their regulator, and the platforms have actually had to find a new regulator because until now there wasn't one.
Each of those sectors has code obligations that are managed by sector regulators. Across that, there's a new super regulator, if you like, that sits horizontally for the issue of scams across all sectors. Its role is to make sure that the obligations are joined up and equivalent.
In my opening statement, I made the comment that keeping bad people out of your system in the first place is one way to help protect your citizens. For banks, we do that through KYC and through telcos. If someone really wants to send 10,000 SMSes in a minute—and there are legitimate use cases for that—find out who they are. Is that a genuine use case? Don't let just anybody use that product. Similarly for the platforms, if someone wants to advertise a financial product, check that they actually hold an Australian financial services licence, which is the licence that's required to offer investment products in Australia, before you allow them to advertise their product.
The obligations are different for each sector, but they have the same flavour because they have the same purpose—
