Australia
Bank Liability for Identity Theft in Australia: The ePayments Code Explained

Under the ePayments Code, your bank generally cannot make you pay for a transaction you did not authorise unless it proves you contributed to the loss, and even then your liability is usually capped at $150.
If identity theft is what caused the unauthorised transaction in the first place, see Identity Theft Laws in Australia for the underlying offences, and Identity Theft Victims' Certificate Australia for the document that can help you dispute fraudulent records with an organisation.
The ePayments Code Is Voluntary, Not a Statute
The ePayments Code, administered by ASIC, is not legislation. ASIC's own description is direct: "The ePayments Code is presently a voluntary code of practice." Banks, credit unions, building societies and other electronic-payment providers choose to subscribe, and a subscriber must warrant compliance with the Code in its own terms and conditions. That is what makes the Code enforceable for a subscriber's customers: as a term of their account contract, not as free-standing law. If your provider has not subscribed, the Code's protections do not automatically apply, so it is worth checking your provider's own terms or ASIC's published subscriber list.
The current version has been in effect since 2 June 2022, following ASIC's most recent review of the Code. Despite claims that circulate about a substantial 2025 revision, ASIC's live overview page still identifies 2 June 2022 as the current version, with no later update listed, and the Code's own administration clause requires only that a review begin within five years of the last one, pointing to the next review being due around 2027. Do not rely on a "revised 2025" claim about the ePayments Code itself.
When You Are Not Liable
Chapter C of the Code deals with liability for "unauthorised transactions", meaning any transaction not authorised by you and not done with your knowledge and consent. Clause 10 sets out when you are not liable at all. You are not liable for loss from an unauthorised transaction where the cause is any of the following: fraud or negligence by a subscriber's own employee or agent, a networking third party, or a merchant or its staff; a device, identifier or passcode that is forged, faulty, expired or cancelled; a transaction that required a device or passcode you had not yet received, including a reissued one; a transaction that was incorrectly debited more than once; or an unauthorised transaction that happened after you told the subscriber the device was lost, stolen or misused, or that a passcode had been compromised. You are also not liable for a transaction that could be carried out using an identifier alone, without a passcode.

Clause 10.3 adds a general backstop: you are not liable for loss from an unauthorised transaction wherever it is clear that you did not contribute to the loss. And if there is a dispute over whether you ever actually received a device or passcode, clause 10.4 presumes you did not receive it unless the subscriber proves otherwise. Proof that something was mailed to your correct address is not, by itself, enough to prove you received it.
When You Are Liable, and the $150 Cap
Clause 11 only applies where clause 10 does not. Under clause 11.2, if your bank proves, on the balance of probability, that you contributed to the loss through fraud or a breach of the Code's passcode security requirements (clause 12), you can be held liable for losses that occurred before you reported the loss, theft or misuse, subject to any daily or periodic transaction limits and your facility's balance. Clause 11.8 is an important limit on that proof: the mere fact that a transaction was carried out using the correct device or passcode is significant, but on its own it is not enough to prove you contributed to the loss.
For most everyday disputes, the number that matters most is clause 11.7's default cap: where a passcode was required and the more specific liability tests in clauses 11.2 to 11.6 do not apply, your liability is capped at the least of $150 (or a lower figure your subscriber sets), your facility's accessible balance or credit limit, or the actual loss at the time you reported it. Clause 11.4 makes you liable for losses from leaving a card in an ATM, if the ATM met reasonable safety standards. Clause 11.5 covers unreasonable delay in reporting a lost, stolen or misused device or a compromised passcode: if the subscriber proves you unreasonably delayed, you are liable only for losses between when you became, or should have become, aware and when you actually reported it. Clause 11.6 requires any fee your subscriber charges for reporting or replacing a device to be weighed when deciding whether a delay counts as unreasonable, so a subscriber cannot charge a steep replacement fee and then blame you for a resulting delay.
Clause 12 defines what counts as a breach of passcode security for clause 11.2 purposes, including voluntarily disclosing a passcode to anyone, including family, or keeping an unprotected written record of it with the device. The Code separately describes "extreme carelessness" as carelessness that greatly exceeds ordinary carelessness, but the operative test for liability remains clause 11.2's balance-of-probability contribution standard, not a stand-alone extreme-carelessness rule.
How to Complain: Your Bank, Then AFCA
Report an unauthorised transaction to your bank first, through its free reporting channel; the Code gives you up to six years from when you became, or should have become, aware of the problem to report it. Your bank must acknowledge the report and complete its investigation, telling you the outcome, the reasons and the relevant clauses, generally within 21 days, or tell you it needs more time, with 45 days as the outer limit absent exceptional circumstances.

If you are not satisfied with your bank's response, the next step is the Australian Financial Complaints Authority. AFCA describes itself as "a free, fair and independent dispute resolution scheme", and its role is to help consumers and small businesses reach agreements with financial firms about how to resolve their complaints. It is not a government department or a regulator; it is a not-for-profit dispute resolution body that can make decisions binding on the financial firm and can award compensation for losses caused by a firm's error or inappropriate conduct. AFCA's own banking page confirms it considers complaints about internet and telephone banking, ATM transactions and unauthorised transactions specifically, among other issues. The online complaint form generally takes 30 to 50 minutes, can be saved and resumed, and AFCA offers an interpreter service, the National Relay Service and translated materials for people who need them.
AFCA does have monetary jurisdiction limits and compensation caps, and those figures are periodically adjusted for indexation. This page does not state a specific dollar figure because none could be confirmed from a current AFCA source at the time of writing; ask AFCA directly, or check its current rules, for the limits that apply to your complaint.
AFCA's Expanded Jurisdiction Over Mule Accounts
A gap used to exist for one specific identity-theft scenario: if a fraudster opened a bank account in your name at an institution where you were not otherwise a customer, that "mule account" fell outside AFCA's jurisdiction over your dispute, because you were not the receiving bank's customer. Following a change to AFCA's Authorisation Conditions by the federal government, AFCA's rules were amended to close that gap. Effective 12 March 2026, AFCA's jurisdiction was expanded to include complaints involving receiving banks and unauthorised accounts opened by scammers or identity thieves in a complainant's name. In practice, this means a victim whose stolen identity was used to open a fraudulent account can now bring a complaint against the bank that opened that account, not only against their own bank.
A Different, Not-Yet-Live Mechanism: The Scams Prevention Framework
Do not confuse the ePayments Code liability rules above with the Scams Prevention Framework Act, a separate piece of 2025 federal legislation that places obligations on banks, telecommunications providers and digital platforms to help protect consumers from scams. The two mechanisms cover different fact patterns. The ePayments Code and the AFCA process above apply where someone else used your identity or account without your knowledge or authorisation. The Scams Prevention Framework is aimed at scams, where a criminal deceives you into authorising a payment yourself.

The framework is also not yet a live complaints channel. AFCA becomes the authorised external dispute resolution scheme for scam complaints under the framework from 1 July 2026, but consumers and small businesses will only be able to bring a scam complaint to AFCA under the framework from 31 March 2027, and only for conduct occurring on or after that date. If your situation is identity theft rather than a scam you were personally deceived into authorising, the ePayments Code and AFCA process described above, not the Scams Prevention Framework, is the relevant mechanism today.
If the identity theft also involved a serious invasion of your privacy, the statutory tort for serious invasions of privacy is a separate civil route. For the free first steps after a data breach or suspected identity theft, see What to Do If Your Information Is Affected by a Data Breach. For the full picture of Australian privacy law, start at the Australia Data Privacy Laws hub.
Frequently Asked Questions
Is the ePayments Code a law?
No. It is a voluntary code of practice administered by ASIC. It only binds a bank, credit union or building society if that provider has subscribed to it and written compliance into its own terms and conditions, which is how it becomes enforceable for that provider's customers.
Was the ePayments Code updated in 2025?
No. The current version took effect on 2 June 2022 and remains the current version. ASIC's own page and the Code's built-in five-year review cycle do not show a 2025 or 2026 revision.
What is the most I can be liable for if I did not contribute to an unauthorised transaction?
Nothing, if it is clear you did not contribute to the loss. Where your bank does prove you contributed, the general cap under clause 11.7 of the ePayments Code is the lesser of $150, your account balance or limit, or the actual loss at the time you reported it.
Does it cost anything to complain to AFCA?
No. AFCA describes itself as a free, fair and independent dispute resolution service, and it does not charge consumers to lodge or pursue a complaint.
Someone opened a bank account in my name that I never had. Can I do anything about it?
Since 12 March 2026, AFCA's jurisdiction has expanded to cover complaints against the receiving bank, the one that opened the account, over unauthorised accounts opened by scammers or identity thieves in a victim's name.
Can I use the Scams Prevention Framework for identity theft?
Not yet, and it is a different mechanism. The Scams Prevention Framework Act targets scams, where you are deceived into authorising a payment yourself, not identity theft, where someone else uses your identity without your knowledge or consent. AFCA is not yet accepting complaints under it: the earliest is 31 March 2027, and only for conduct occurring on or after that date.
Updates
Independently fact-checked against the cited primary sources
Sources and References
- ASIC, ePayments Code overview, voluntary status and current 2 June 2022 version(asic.gov.au).gov
- ePayments Code, effective from 2 June 2022 (ASIC), Chapter C liability clauses 9-19 and Chapter F complaints clauses 38-40(asic.gov.au).gov
- AFCA, About AFCA (free, fair and independent dispute resolution; not a government agency or regulator)(afca.org.au)
- AFCA, Make a complaint about banking (jurisdiction over unauthorised transactions, ATM and internet banking complaints)(afca.org.au)
- AFCA, Rules consultation 2025, expanded jurisdiction over receiving banks and mule accounts effective 12 March 2026(afca.org.au)
- AFCA, Scams Prevention Framework (obligations from 2025, AFCA as authorised EDR scheme from 1 July 2026, complaints acceptable from 31 March 2027)(afca.org.au)