Review of Payments System Regulation Summary of Submissions to the Review of Payments System Regulation Issues Paper
5. Cryptography and Fraud Prevention
5.1 Cryptography in the payments system
Many stakeholders considered that strengthening cryptographic protections should be a priority for the payments industry. However, fewer submissions supported the introduction of regulatory mandates for encryption by the RBA.
Stakeholders that supported the RBA prioritising this issue outlined the following challenges with progressing cryptographic uplift:
- While industry has been undertaking work to strengthen cryptographic security, further uplift in efforts and scope may be required. Stakeholders acknowledged initiatives, such as the industry-led Advanced Encryption Standard (AES) Migration Program; and participant-level investments into stronger encryption and authentication, tokenisation, hardware-backed security, dynamic cryptograms, short-lived keys and cryptographic agility. Some stakeholders also stated that cryptographic protections should extend beyond payment credentials to user authorisations, permissions for recurring payments, card-on-file payments, beneficiary and evidence records, particularly as payments become more automated and delegated.
- The scale and interdependence of the payments system may make cryptographic uplift difficult to achieve. Stakeholders noted that migration must be coordinated across financial institutions, schemes, processors, merchants, technology providers, gateways, wallets, terminals and ATMs. Several submissions cited estimates that around 970,000 payment terminals and 25,000 ATMs may require replacement or upgrade as part of AES migration. Some stakeholders noted that a weakness or delay in one part of the transaction chain could undermine the effectiveness of uplift elsewhere.
- Numerous barriers could slow or fragment implementation. Commonly cited barriers included legacy systems and devices with lengthy hardware replacement cycles, limited key-translation capability, lack of vendor readiness and dependence exacerbated by skills shortages, competing cyber and resilience priorities, implementation costs, compliance fatigue and uncertainty about the timing of quantum threats. Smaller institutions and merchants were considered likely to face disproportionately greater financial and technical constraints.
- Different standards, risk assessments and implementation timelines could create coordination and interoperability problems. Stakeholders noted possible divergence between international card and security standards, domestic national security guidance and organisation-specific risk assessments. In particular, some identified a risk of conflict or misalignment between the Australian Signals Directorates (ASD) objectives and the PCI Security Standards Councils (PCI) global security standards. Cross-border harmonisation of post-quantum approaches was also described as incomplete, with new algorithms potentially imposing greater processing, bandwidth and data-size requirements on terminals and chip cards.
A small number of stakeholders called for a regulatory mandate from the RBA on cryptographic practices. One industry group proposed a standard set and enforced by the RBA for all critical payment systems. This mandate would set a regulatory floor to meet 2030 readiness and cover symmetric and asymmetric cryptography, payments in transit and data at rest, quantum-resistant protection (where relevant) and full lifecycle key management.
However, most stakeholders did not support the RBA setting mandatory technical standards. These stakeholders stated that:
- Premature mandates could create stranded costs or lock participants into immature solutions; a better alternative is a gradual transition supported by ongoing testing and evaluation. Stakeholders noted that participants are already building cryptographic inventories, assessing supplier readiness, monitoring evolving standards and preparing migration plans. Some characterised quantum readiness as a long-term transition comparable to planning for the Year 2000 problem, while others supported evaluating post-quantum algorithms as they advance, before committing to any specific solutions. Premature regulatory intervention could incur costs that could not be recovered due to unanticipated changes in the environment, or lock participants into immature solutions. Some stakeholders considered that moving too early on industry mandates could require replacement of systems or algorithms before standards mature, while algorithm-specific mandates could inhibit crypto-agility. A gradual industry-led transition involving parallel testing and evaluation was therefore preferred by some stakeholders.
- Several stakeholders considered that established industry programs and international standards already provide an appropriate basis for uplift. These stakeholders generally supported completing the AES Migration Program and continuing alignment with PCI requirements, ASD guidance and standards developed through the National Institute of Standards Technology (NIST), International Standards Organization (ISO), EMVCo and other specialist bodies. Some also noted that duplicative or divergent domestic requirements could increase cost, disruption and interoperability risk. A separate Australian approach through RBA technical mandates could fragment implementation and create difficulties for globally connected schemes and service providers.
- The majority of stakeholders supporting RBA involvement identified a coordination and facilitation role as being more appropriate for shepherding a coherent system-wide transition. Suggested roles included convening participants, monitoring readiness and interdependencies, aligning expectations across domestic agencies and international bodies, setting high-level outcomes or reference timelines, collecting evidence, promoting crypto-agility and supporting pilots or proofs of concept. Some stakeholders considered that visible RBA support could increase awareness, provide investment certainty and encourage participants to prioritise quantum-safe payments.
5.2 Card payments fraud overseas
While submissions regarded fraud as a significant issue for industry and the government, few submissions explicitly supported the RBA prioritising this issue. The small number of stakeholders that supported prioritisation stated:
- Overseas card-not-present (CNP) fraud is a material consumer protection and efficiency issue, given the overrepresentation of overseas transactions in CNP fraud. Several industry groups, issuers, PSPs and merchants cited figures from 2024 AusPayNet data such as the estimated $454 million value of gross overseas fraud on Australian cards; and overseas transactions comprising approximately half of the fraud on these cards despite only forming 3 per cent of the total value of transactions. Fraud-related costs could be borne within Australia even where the relevant merchant or acquirer is overseas.
- Australias existing CNP framework only applies to domestic participants, resulting in an overseas gap. The CNP Fraud Mitigation Framework is enforced via AusPayNets IAC Code Set. As such, stakeholders flagged how it cannot compel overseas participants to implement an equivalent level of fraud prevention controls. This can leave Australian parties exposed to fraud generated elsewhere in the payment chain.
While there was limited support for regulatory intervention, a few stakeholders addressed potential regulatory initiatives including a Strong Customer Authentication (SCA) mandate for high-risk transactions or the standardisation of issuer-level fraud controls for overseas transactions. Some stakeholders provided views about the scope of entities to be captured: some proposed regulatory action on a domestic issuer-level, others emphasised card networks and overseas merchants; one issuer supported an ecosystem-wide, end-to-end SCA approach, combined with scheme fraud-performance frameworks and proportionate consequences for excessive fraud.
Many submissions did not support prioritising the issue. These stakeholders stated:
- Although overseas CNP fraud was recognised as a valid concern, it is a relatively low priority for the Review. Stakeholders stated that there was limited evidence to suggest that the status quo warrants formal RBA intervention.
- Industry measures are already underway, and future initiatives are being developed. A global participant reported that both cross-border CNP fraud rates and overall card fraud rates for Australian cards have declined. Additionally, an industry group noted that it is currently developing a program of work that would help coordinate industrys response to overseas CNP fraud.
- Various options outside of formal regulatory intervention were supported by stakeholders as
means of furthering progress on the issue of overseas CNP fraud.
- International coordination is crucial, given the issues inherently cross-border nature. Many stakeholders stated that domestic action would have a limited impact because overseas merchants and acquirers are the underlying driver behind overseas CNP fraud. As such, stakeholders suggested that the RBA play a supporting role and work with card networks, industry bodies, overseas regulators, and international standard-setting processes to encourage the uplift of global CNP standards.
- Better data collection and sharing by payments participants was proposed as a way to advance current efforts, with several stakeholders commenting on how effective fraud prevention and management ultimately relied on participants continued investment into data, technology, and analytics, and collaborating with others across industry. Some stakeholders suggested that the RBA could support the facilitation of such industry collaborations.
- For some stakeholders, effectively addressing overseas CNP fraud means looking towards the wider policy landscape. Stakeholder suggestions included updating other mechanisms like the ePayments Code or the Scams Prevention Framework. One stakeholder stated that, as telecommunications fraud is becoming increasingly intertwined with CNP fraud, policy responses should also consider the role of telecommunications operators and mobile-device manufacturers.