Whether your organisation is liable turns on what you did to prevent, detect and disrupt — not on whether a customer was deceived. That makes it an evidentiary problem. This page sets out which limb is hardest to evidence, why, and exactly what artefacts this service produces against it.
Australians reported $2.18 billion in scam losses in 2025 — a 7.8% increase on 2024, reversing two years of decline. Investment scams accounted for $837.7 million and payment-redirection scams for $166.8 million. Source: the National Anti-Scam Centre's Targeting Scams report, March 2026.
Prevention and disruption leave records inside your organisation: the warning you displayed, the payment you held, the account you froze. Every one of those is a row in a system you already own.
Detection is different. A scam that never became a transaction leaves nothing behind at all. The member who received a payment-redirection email, hesitated, checked it, and did not send the money is — in your data — indistinguishable from a member who was never targeted. That near-miss is simultaneously the best outcome the framework is trying to produce and the one event your systems cannot see.
This service sits at the point where that event happens: the member's own phone, before the transaction. When a member forwards a suspicious message and receives a verdict, that exchange becomes a dated record of a scam campaign reaching your covered population — evidence of detection that exists precisely because the loss did not.
A monthly campaign evidence record: every scam campaign that reached your own covered households, with a stable campaign reference, the UTC time the campaign was first seen anywhere in the network, how many of your households it reached, the domains involved, and a redacted sample template.
Artefact: campaign evidence record (HTML or CSV), any month, on demand
Wave events delivered to your fraud systems as campaigns are detected, signed with a per-tenancy secret, plus a reporting API your own tooling can poll. Both carry campaign references, first-seen times, household counts and domains — the raw material for your own blocking, alerting and customer-warning decisions.
Artefact: signed webhook feed and keyed reporting API
Every evidence document ends with a SHA-256 integrity digest computed over its own content. For a closed month, that digest is written once to an append-only ledger and never updated, and the weekly operations record notes the ledger's size. Reissuing the same closed month reproduces the same digest — so a document you produced in April can later be shown to have existed in April, rather than assembled afterwards.
Artefact: content-addressed integrity digest, recorded at first generation
A member who says the scam already worked receives recovery steps by return message, in damage-limiting order — who to contact first, what to say. The exchange is recorded as a check like any other, so the fact and timing of the response are part of the same record.
Artefact: dated check records covering post-incident guidance
Enrolment is opt-in, per member, and every consent event is written to an append-only ledger with its timestamp and channel. A consent attestation can be produced for any covered member. Members can withdraw at any time by replying STOP, which is recorded the same way.
Artefact: append-only consent ledger with per-member attestation
This matters as much as what it does contain, and it is a hard architectural rule rather than a policy setting. Partner-facing surfaces — evidence records, the reporting API, the webhook feed — carry counts, categories, campaign references and timestamps. They never carry member names, phone numbers, email addresses or message content.
Sensitive categories are stricter still. Romance and extortion scams are excluded from every partner-facing surface entirely, including from counts and category totals. With a pilot-sized covered population, a category count of one is not an aggregate: it identifies a person, and what it identifies about them is the most shame-loaded fact the system holds. Those verdicts stay between the service and the person who asked.
Campaign references are derived per tenancy, so the same campaign carries a different reference in your record than in another organisation's. Two partners comparing documents cannot determine that they saw the same campaign.
AFCA membership required for designated sectors under the Scams Prevention Framework.
AFCA begins accepting scam complaints, for matters occurring on or after that date. A complaint about a matter in April 2027 will be assessed on what you did — and on what you can show.
Evidence is only useful if it predates the complaint. A record of detection generated in response to a determination is worth considerably less than one that was already on file.
Confirm the detail yourself. Designation, obligations and dates under the framework depend on your sector and on instruments that continue to be made. Nothing here is legal advice, and we would rather you verified every date on this page with your own advisers than took ours.
This service does not make an organisation compliant. Compliance is an assessment of your whole conduct across every limb, and no supplier can deliver it. What this produces is dated, tenancy-specific evidence relevant to the limb that is hardest to evidence.
It does not see everything. Members forward what they find suspicious. A scam nobody forwards is a scam we never saw, and no document will suggest otherwise. Absence of a campaign from a record is not evidence the campaign did not reach your members.
It does not stop transactions. There is no integration with your payment rails, and detection happens at the member's phone, not in your systems. What a member does after receiving a verdict remains their decision.
It is not an ombudsman defence in itself. The evidence record is a document you can put in a compliance file or attach to a response. Its weight in any particular matter is for the decision-maker, not for us.
The fastest way to test all of this is a small, specific pilot: one branch of your member base, one intake period, one quarter. At the end of the first full month, we generate your own campaign evidence record — real data, your households, integrity digest included — and you hand it to whoever will actually have to rely on it.
That review, by your compliance officer rather than your fraud analyst, is the honest test of everything on this page. If the document does not do what a compliance file needs, better to find that out in a pilot than in a determination.
The useful conversation isn't a demo — it's your risk or compliance lead asking what exactly a document would contain, what it would not, and whether that is worth anything in a determination. We would rather answer that early and honestly than sell past it.
Ask for the partner pack. It includes the sections most suppliers leave out: what we hold, where it goes, what we have not built, and what we would have to fix before a large organisation could reasonably sign.
hello@getforwardit.com