The Scam Liability Shift: How APAC Banks Must Rebuild Payments Defense Under Mandatory Reimbursement
Executive Summary
For a decade, scam losses in Asia-Pacific were treated as a customer problem. That premise has collapsed. Singapore's Shared Responsibility Framework (SRF) went live in December 2024, apportioning losses between banks, telcos and consumers. Australia's Scams Prevention Framework became law in February 2025, imposing enforceable obligations on banks, telcos and digital platforms with penalties of up to AUD 50 million per breach. Hong Kong's Anti-Scam Consumer Protection Charter 2.0 has drawn 200-plus institutions into a coordinated response, and the United Kingdom's mandatory reimbursement regime for authorized push payment (APP) fraud - effective October 2024 - has become the international reference model.

For APAC banks the strategic implication is precise: scam losses are now a P&L item, not a customer service item. Banks that cannot detect a socially-engineered payment in flight, coordinate with telcos and platforms within seconds, and evidence a defensible decision at claim time will face rising reimbursement costs, regulatory action and reputational damage. Global authorized-push-payment (APP) scam losses are projected to reach USD 6.8 billion by 2027, up from USD 5.3 billion in 2023, according to ACI Worldwide and GlobalData research (ACI Worldwide, 2024).
This article sets out (i) why the liability shift is structural, not cyclical; (ii) the four engineering capabilities APAC banks now need - behavioral signals, real-time orchestration, shared-signal exchange and evidentiary automation; and (iii) a 12-month build sequence for CIOs and Chief Risk Officers. The banks that treat this as an operating-model reset - not a fraud policy tweak - will convert a regulatory headwind into a durable trust advantage.
Introduction
The last two years have inverted the economics of consumer scams in the region. Instead of banks absorbing fraud losses only when their controls fail (unauthorized transactions), regulators are now assigning liability for losses on payments the customer themselves authorized under deception. Singapore's Monetary Authority, its Infocomm Media Development Authority, the Australian Government, the UK's Payment Systems Regulator and the Hong Kong Monetary Authority are moving in the same direction, with variations of scope but a common principle: financial institutions carry a share of the loss when they miss red flags.
That principle is easy to state and expensive to operationalise. The typical scam payment moves through instant rails such as FAST, PayNow, NPP or Faster Payments, is initiated by a genuine customer under emotional or social pressure, and clears in seconds. Legacy fraud stacks - built around card-not-present anomalies, batch scoring and rules trees - were not designed to intervene in these flows. Building the new capability is a cross-functional programme spanning payments engineering, data platforms, contact-center orchestration, telco and platform partnerships, and dispute operations.
Industry Context: A Regulatory Cascade
The regulatory cascade is now unambiguous.

Singapore. The SRF, effective 16 December 2024, applies to phishing scams involving digitally enabled payments from Singapore-based accounts and imposes a waterfall: if a bank fails a duty (real-time transaction alerts, 24/7 self-service kill switch, cooling-off period for token activation, outgoing transaction alerts), it pays first; if a telco fails duties on SMS sender-ID verification, it pays next; the customer bears residual loss (Monetary Authority of Singapore and IMDA, 2024). The framework is deliberately narrow but sets the anchor for future expansion.
Australia. The Scams Prevention Framework Act 2025 designates banks, telcos and digital platforms as "regulated entities" under a principles-based code with mandatory information sharing, victim-reporting channels and an external dispute resolution pathway. Penalties reach AUD 50 million or 30% of adjusted turnover per contravention (Australian Government, 2025). Voluntary industry action has already moved the numbers - Australian Financial Crimes Exchange members reported a 26% year-on-year fall in scam losses to AUD 2.03 billion in 2024, the first sustained decline since 2019 (National Anti-Scam Center, ACCC, 2025).
Hong Kong. The HKMA-coordinated Anti-Scam Consumer Protection Charter 2.0, extended in 2024-2025, brings retail banks, licensed money lenders, credit card issuers, insurers and stored-value operators under a common protective standard. The Hong Kong Police's Anti-Deception Coordination Center (ADCC) recorded 44,480 deception cases in 2024 with reported losses of HKD 9.1 billion - a 12% year-on-year rise - underscoring why the Charter is being tightened (Hong Kong Police Force, 2025).
United Kingdom (reference model). The PSR's mandatory reimbursement regime, live from 7 October 2024, splits APP scam losses 50/50 between the sending and receiving payment service providers, with a per-claim cap of GBP 85,000, a GBP 100 excess and a five-business-day decision window (Payment Systems Regulator, 2024). Early data from UK Finance shows a 20% drop in APP losses in the first half of 2024 versus the prior year, to GBP 213.7 million (UK Finance, 2024) - a proof point that liability alignment moves the needle.
European Union. The Instant Payments Regulation, applicable from October 2025 for outgoing payments in euro, mandates confirmation-of-payee (verification-of-payee) checks and 24/7 SEPA Instant availability, and the pending PSD3/PSR package extends liability where banks fail those verifications (European Parliament and Council, 2024).
The pattern is consistent: real-time rails plus consumer scam vectors have forced regulators to internalize the externality by giving banks a direct financial incentive to intervene.
Current Challenges: Why Legacy Fraud Stacks Fail Here
Five structural gaps recur across APAC bank estates.
1. Signal poverty inside the bank. Most transaction fraud models were tuned on unauthorized events - card testing, account takeover, identity theft. Scam payments look like legitimate customer behavior because they are legitimate customer behavior, under duress. The predictive signals live outside the transaction record: session telemetry (unusual dwell times, copy-paste of account numbers, remote-access tools), device changes, new payee patterns and behavioral biometrics.
2. Latency mismatch. Instant payment rails settle in 5-15 seconds. Batch-scored fraud queues, manual review desks and outbound "verification calls" cannot intervene in that window. Every additional second of decisioning latency shrinks the population of stoppable payments.
3. Cross-institution blindness. The receiving account - the "mule" - almost always sits at a different bank. Without a shared inference layer, the sending bank sees only its own payer; the receiving bank sees only inbound credits. Singapore's SGFinDex-style consent rails, Australia's AFCX and Hong Kong's Financial Intelligence Evaluation Sharing Tool (FINEST) point the direction, but adoption inside the fraud stack is uneven.
4. Weak orchestration at the moment of truth. When a payment is flagged, the bank must trigger the right intervention in real time: step-up authentication, an in-app scam warning tailored to the vector (romance, investment, impersonation), a call from a scam-response agent, or a hold with a cooling-off period. Most digital channels do not expose the hooks required, and contact centers do not have the payment-context screens to convert a warning into a save.
5. Evidentiary debt. Under reimbursement regimes, banks must justify why they did or did not reimburse within tight deadlines (five business days in the UK; equivalent in Singapore under the SRF's timelines). Case data typically sits across the core, digital channel logs, contact-center transcripts and third-party enrichment tools, with no consolidated case record. Manual assembly is unsustainable at claim volumes projected to rise 3-5x under the new regimes.
Key Trends Reshaping Payments Defense
Trend 1: From fraud rules to behavioral inference. Leading APAC banks are moving to graph-based and sequence-model architectures that score the whole session, not just the payment. UOB, DBS, CBA and Westpac have all publicly described investments in behavioral-biometric and session-level scoring in the past 18 months. Studies of behavioral biometric deployments show a 25-40% uplift in detection of social-engineering-driven payments compared with rules-only stacks (BioCatch, 2024).
Trend 2: Confirmation-of-Payee becomes table stakes. The UK's Confirmation of Payee (CoP) service reduced APP misdirection losses meaningfully after full rollout in 2020; the EU has now mandated an equivalent under IPR. In APAC, PayNow's proxy-name matching in Singapore and NPP's PayID lookup in Australia are already in-market; the frontier is extending these checks to cross-border and non-proxy flows.
Trend 3: Consortium data and public-private exchange. Real-time mule-account intelligence - shared across banks and, increasingly, telcos and digital platforms - is the highest-leverage lever. Australia's AFCX Scam Intelligence Loop, Singapore's ScamShield and the UK's Faster Payments' "Enhanced Fraud Data" corridor all evidence single-digit-second sharing of enriched risk signals. Banks without a real-time inbound-hit interface will pay disproportionately under reimbursement regimes.
Trend 4: In-flow customer friction, engineered as UX. The regulatory duty is not to block all suspicious payments; it is to intervene proportionately. Best-in-class implementations use dynamic warnings tied to the scam typology, biometric re-confirmation, and human-in-the-loop calls for high-risk vectors. Poorly designed friction produces false-positive rage and channel abandonment. This is a product design problem as much as a risk problem.
Trend 5: Generative AI cuts both ways. GenAI has industrialized social engineering - voice clones, localized phishing, deepfake video calls - and simultaneously enabled better defensive capabilities: LLM-based classifiers for scam narratives in chat logs, synthetic-victim testing of controls, and real-time explainers for customer-facing warnings. The Association of Certified Fraud Examiners' 2024 report identifies AI-enabled fraud as the fastest-growing typology globally (ACFE, 2024).
Strategic Analysis: Four Capabilities That Now Compound
Framing the response as "buy a better fraud engine" understates the problem. Four capabilities compound and must be built together.

Capability 1 - Unified behavioral signal fabric. A single low-latency store of session, device, biometric, payee-history and payment-context features, accessible by both real-time decisioning and offline model training. This is a data-engineering problem: streaming ingestion, feature store, entity resolution across channels, sub-100ms lookups. Cloud-native feature platforms (Feast, Tecton, Databricks Feature Store, or bank-built equivalents) have matured to the point where this is no longer bespoke work.
Capability 2 - Real-time orchestration layer. A decisioning service that, on every payment initiation, retrieves signals, invokes scoring, selects an intervention from a policy catalogue and drives the response in-channel within one to two seconds. This is where most APAC banks have architectural debt: fraud logic is bolted into channel apps or the core, not exposed as a domain service. The pattern that works is a decisioning service on the event backbone (Kafka, Solace or equivalent), calling out to specialist scoring, and returning a structured decision object that channels, IVR, contact-center desktop and dispute case tools all consume.
Capability 3 - Shared-signal exchange. APIs and consent mechanisms to send and receive risk signals at payment-event granularity with other banks, telcos, digital platforms and law-enforcement clearing houses. The design questions are governance, liability of the signal producer, and privacy engineering (differential privacy, hashing, private set intersection). Confidential-computing enclaves are becoming the preferred substrate for high-sensitivity exchanges.
Capability 4 - Evidentiary automation. A case-record service that assembles, per payment, the full evidentiary trail - signals evaluated, model scores, interventions triggered, customer responses, contact-center transcripts, outbound alerts, telco and receiving-bank exchanges - into a defensible pack within minutes of a claim. Under SRF and Australian SPF timelines this stops being an operations question and becomes an engineering deliverable.
Banks that build one without the others will over-invest and under-detect. Signal fabric without orchestration produces good dashboards and slow decisions. Orchestration without shared signals catches only what your own channels see. Evidentiary automation without a signal fabric produces empty case files.
Real-World Reference Points
UK Finance H1 2024: APP scam losses fell 20% year-on-year to GBP 213.7 million; total unauthorized and authorized fraud losses fell 16% - the largest half-yearly decline on record, coinciding with pre-reimbursement industry investment (UK Finance, 2024).
Australia National Anti-Scam Center: Reported scam losses fell from AUD 2.74 billion in 2023 to AUD 2.03 billion in 2024, a 26% drop, following the launch of the National Anti-Scam Center and industry investment in intelligence sharing - but investment scam losses still dominated at AUD 945 million (National Anti-Scam Center, ACCC, 2025).
Singapore Police Force: Scam and cybercrime cases hit 55,810 in 2024 with reported losses of SGD 1.1 billion - a record - with government-official-impersonation and investment scams the dominant vectors, motivating the SRF's narrow phishing scope as a first step (Singapore Police Force, 2025).
Hong Kong: ADCC recorded 44,480 deception cases in 2024, losses of HKD 9.1 billion, a 12% year-on-year rise; the Anti-Scam Consumer Protection Charter 2.0 now covers over 200 institutions across banks, insurers and stored-value operators (Hong Kong Police Force, 2025).
The pattern is clear: liability alignment and shared intelligence infrastructure move the loss curve; jurisdictions that rely on customer education alone do not see the same result.
Actionable Recommendations: A 12-Month Sequence
For CIOs and CROs entering FY26 planning, a defensible sequence is:

Months 0-3 - Establish the operating baseline. Instrument every payment initiation channel with session and device telemetry. Publish a single fraud-loss and reimbursement metric to the executive committee, decomposed by vector, channel and receiving institution. Establish a joint sponsor across risk, product and technology; fraud can no longer sit inside one function.
Months 3-6 - Build the decisioning spine. Stand up the real-time decisioning service on the event backbone. Migrate high-risk vectors (first-payee, high-value, new-device, cross-border) to the new service first, keeping legacy rules parallel. Instrument policy-catalogue interventions (dynamic warnings, step-up, cooling-off, agent transfer). Target under two seconds end-to-end decision time on 99th percentile.
Months 6-9 - Integrate the ecosystem. Onboard to the national scam-signal exchange (AFCX in Australia, ScamShield-linked feeds in Singapore, HKMA-coordinated intelligence in Hong Kong). Extend Confirmation-of-Payee coverage. Formalize 24/7 SLAs with priority telcos and platforms on takedown and impersonation flags. Deploy behavioral biometrics on retail digital channels.
Months 9-12 - Automate the evidentiary chain. Build the case-record service; regression-test five- and 10-business-day decision windows on live claim populations. Deploy generative-AI-assisted claim narrative generation with human-in-the-loop review. Publish an internal reimbursement rate benchmark and quarterly deep-dive on adverse outcomes.
Two governance decisions determine whether this programme succeeds or stalls: (i) a single accountable executive owning end-to-end scam loss, not split between fraud, cyber and product; and (ii) fraud-and-scam engineering treated as a first-class product domain with its own roadmap, capacity and platform investment, not as a rules-tuning function inside operations.
sourceCode Perspective
sourceCode works with APAC banks and insurers on the engineering underneath these programmes: streaming event platforms, real-time feature stores, decisioning services, channel orchestration and evidentiary case tooling. The pattern we consistently see is that the payments Defense programme fails or succeeds on architecture choices made in the first quarter - whether decisioning is a domain service or a bolt-on, whether signals are federated or siloed, whether the case record is a first-class data product or a stitched report.
Our teams help clients design and build the decisioning spine on cloud-native event backbones, integrate behavioral signals and third-party intelligence feeds without leaking PII, and build the operational tooling that dispute and financial-crime teams need to work at reimbursement-era volumes. We also embed model-risk and responsible-AI controls into the fraud analytics pipeline, so that decisions are explainable and auditable under regulatory review. This work sits at the intersection of engineering excellence, data platform design and regulated-industry delivery - the areas we have built the firm around.
Conclusion
The scam-liability shift is a structural rewrite of who pays when a customer is deceived on an instant payment. Singapore, Australia and Hong Kong have moved decisively; the UK's early evidence shows the intervention works. The technology response is not a fraud-rules upgrade - it is a real-time decisioning platform, wired to shared intelligence and defensible evidence. Banks that build this well will spend less on reimbursement, cut customer harm and earn the trust dividend that follows. Banks that treat it as compliance overhead will pay twice - once in losses, once in reputation.
Looking to design the decisioning, orchestration and evidentiary layers that will carry your bank through the reimbursement era? Talk with sourceCode about building payments Defense platforms that are fast enough for instant rails and defensible enough for the regulator.
FAQ
Q: What is the Shared Responsibility Framework (SRF) in Singapore? A: Effective 16 December 2024, the SRF allocates losses from digitally enabled phishing scams involving Singapore-based accounts across financial institutions, telcos and consumers, based on a duty-based waterfall published jointly by MAS and IMDA.
Q: When did Australia's Scams Prevention Framework take effect? A: The Scams Prevention Framework Act 2025 was passed in February 2025, establishing enforceable obligations on regulated entities (banks, telcos, digital platforms) with penalties up to AUD 50 million per contravention.
Q: How does the UK's mandatory reimbursement regime split liability? A: Under the PSR's regime live from 7 October 2024, APP fraud losses are split 50/50 between sending and receiving payment service providers, with a GBP 85,000 per-claim cap, a GBP 100 excess, and a five-business-day decision window.
Q: What is the biggest engineering challenge for banks under these regimes? A: Real-time decisioning latency. Instant payment rails settle in seconds; legacy fraud queues cannot intervene in that window. Banks need a sub-two-second decisioning service that unifies session, device, behavioral and payment signals.
Q: How much can shared intelligence reduce scam losses? A: UK Finance data shows a 20% year-on-year fall in APP losses in H1 2024, and Australia recorded a 26% decline in reported losses in 2024, both correlated with shared-intelligence investment and liability alignment.
References
ACFE (2024). Occupational Fraud 2024: A Report to the Nations. Association of Certified Fraud Examiners. Austin, TX.
ACI Worldwide and GlobalData (2024). Scamscope 2024: Global Real-Time Payments and Fraud Trends. ACI Worldwide.
Australian Government (2025). Scams Prevention Framework Act 2025. Federal Register of Legislation, Canberra.
BioCatch (2024). 2024 Digital Banking Fraud Trends in APAC. BioCatch Research Report.
European Parliament and Council (2024). Regulation (EU) 2024/886 on Instant Credit Transfers in Euro (Instant Payments Regulation). Official Journal of the European Union.
Hong Kong Police Force (2025). Anti-Deception Coordination Center - 2024 Annual Statistics. HKPF, Hong Kong SAR.
Monetary Authority of Singapore and IMDA (2024). Shared Responsibility Framework for Phishing Scams: Response to Consultation. MAS and IMDA, Singapore.
National Anti-Scam Center, ACCC (2025). Targeting Scams: Report of the ACCC on Scams Activity 2024. Australian Competition and Consumer Commission, Canberra.
Payment Systems Regulator (2024). Faster Payments APP Scams: Policy Statement PS24/3 - Mandatory Reimbursement Requirements. PSR, London.
Singapore Police Force (2025). Annual Scams and Cybercrime Brief 2024. SPF, Singapore.
UK Finance (2024). Half Year Fraud Report 2024. UK Finance, London.