FAQ

What are scam prevention obligations for financial advisers in Australia?

SIC expects AFS licensees and advisers to take reasonable steps to prevent, detect, and respond to scams as part of their obligations to act efficiently, honestly, and fairly and to maintain adequate risk management systems. This includes protecting clients, monitoring transactions, and responding appropriately to suspected scam activity.

Expanded Answer
AFS licensees are responsible for implementing systems and controls to manage risks to clients, including scams and financial fraud. ASIC has made clear that scam prevention forms part of broader obligations around client protection, supervision, and operational risk management. Advisers are expected to remain alert to red flags and act in the client’s best interests where scam risks are identified.

In practice, scam prevention involves identifying unusual client instructions, changes in behaviour, or transaction patterns that may indicate fraud. Advisers should verify instructions, particularly for withdrawals or changes to payment details, and escalate concerns in line with licensee procedures. Licensees are expected to support this with training, monitoring systems, and clear escalation pathways.

Regulatory scrutiny increases where scams result in client loss, and there is evidence that warning signs were missed or controls were inadequate. ASIC expects licensees to demonstrate that they have taken reasonable steps to prevent harm, including responding quickly to suspected scams and improving controls where weaknesses are identified. For further context, see cybersecurity compliance: protecting client data and a comprehensive guide to data governance in Australian financial services.

Why it matters
Failure to identify or respond to scams can result in significant client losses, complaints, and regulatory action. ASIC increasingly treats scam prevention as a core part of licensee obligations and client protection.

Unsure how this applies to you?
Get a clear answer in a 15-minute call with a compliance specialist. Book your call.

Practical guidance

  • Verify client instructions independently, especially for withdrawals or changes to payment details.
  • Identify and escalate red flags such as urgency, secrecy, or unusual transaction patterns.
  • Implement and follow incident response processes to act quickly where scams are suspected.

Further reading
Cybersecurity compliance: protecting client data
The role of data in improving compliance and business performance in 2025

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?