You open your banking app and see a payment you do not recognise. The immediate question is not technical — it is who wears the loss while the transaction is investigated, and who wears it if the money cannot be recovered.
In Australia, the starting point for that question is the ePayments Code. This guide explains what the Code does, how it allocates responsibility for unauthorised transactions, how the Australian Securities and Investments Commission (ASIC) administers it, and where to find the version that currently applies.
What the ePayments Code is
The ePayments Code is an industry code covering electronic payment facilities in Australia. ASIC describes it as playing an important role in the regulation of those facilities. It is not a piece of legislation in itself, but a set of obligations that financial institutions take on, and that ASIC oversees.
ASIC's own page on the Code sets out three things in particular: the protections available under the Code, which financial institutions must comply with it, and how ASIC administers it. Among those protections, ASIC states that the Code "sets out the rules for determining who pays for unauthorised transactions" — which is precisely the part that matters when a disputed charge lands on your account.
That single function is worth understanding properly. The Code does not simply say "the bank pays" or "the customer pays." It provides a framework for working out responsibility, based on the circumstances of the transaction. The outcome in any individual case depends on facts: how the payment was initiated, whether it was genuinely unauthorised, and what happened after it was discovered.
Why allocation of responsibility matters more than a promise of a refund
If you search for the ePayments Code in Australia, you will find plenty of confident summaries promising that you will always be reimbursed. Treat those with caution.
The practical value of the Code is procedural. It gives you a framework to point to when you report a transaction, and it gives your financial institution obligations to follow once you have reported it. What it does not do is guarantee a particular outcome regardless of the facts.
So the useful question to ask your provider is not "am I protected?" but "which part of the Code applies to this specific transaction, and what does it require of each of us?"
Who must comply with the Code
Not every payment product or provider is covered in the same way. ASIC's page explains which financial institutions must comply with the Code, and that is the authoritative list — not a blog post, a comparison site or a forum thread.
Two practical implications follow:
- Check subscriber status directly. Ask your provider whether it is bound by the ePayments Code for the specific account or facility in question. A large institution may be a subscriber while a particular product sits outside the Code's scope.
- Check the product, not just the brand. The Code applies to electronic payment facilities. Your transaction's route — card, direct debit, BPAY-style transfer, wallet or something else — affects which rules are relevant.
If your provider is not bound by the Code, your rights still come from somewhere: your account terms, the contract governing the facility, and Australian consumer and financial services law. The Code is an important layer, not the only one.
Exemptions and declarations
The Code is not applied uniformly without exception. ASIC's page includes a section on exemptions and declarations under the ePayments Code, and records individual instruments. One example listed is an instrument relating to Australia and New Zealand Banking Group, identified as Instrument 14-0398.
This matters for a practical reason: if your institution has been granted an exemption or has a declaration in place, the obligations that apply to your transaction may differ from the general position. That is not something you can assume either way. Where a dispute turns on a specific Code obligation, it is legitimate to ask your provider whether any exemption or declaration affects how the Code applies to your account.
Do not attempt to interpret an instrument number on your own. Exemption instruments are technical documents, and their effect depends on their terms. Ask the institution to explain, in plain English, what it says it is relying on.
How ASIC administers the Code
ASIC's role is not simply publishing a document. According to ASIC, it administers the ePayments Code, including monitoring compliance and conducting regular reviews.
Two consequences follow for readers:
- Compliance is supervised. If you believe a provider has not met its obligations, that is a matter that can be raised with the institution and, if unresolved, escalated.
- The Code changes. Because ASIC conducts regular reviews, the version you read today may not be the version that applied when your transaction occurred, or the version that will apply next year. Always read the current version on ASIC's site and check its commencement or version details.
This is the reason to go to the source rather than relying on secondary summaries. ASIC's page is the place to confirm the Code's text, the protections it describes, which institutions are covered, and the exemptions and declarations on record.
What to do when you spot a transaction you did not authorise
The Code allocates responsibility, but you still have to trigger the process. The following steps are practical rather than legal, and each depends on your provider's own procedures:
| Step | Why it matters |
|---|---|
| Contact your provider immediately using its official disputed-transaction or fraud channel | Starts the process and limits further exposure |
| Note the date, time, and who you spoke to | Creates a record if the matter is escalated later |
| Ask which Code obligations apply to this transaction | Turns a vague complaint into a specific question |
| Secure the account — card freeze, password reset, device check | Prevents repeat transactions while the matter is open |
| Request the outcome and the reasoning in writing | Makes review and escalation possible |
| If unresolved, use the provider's internal dispute process, then its external scheme | Most institutions belong to an external dispute resolution body — confirm which one applies to yours |
Where a transaction is disputed, keep your own file: screenshots, reference numbers, correspondence and dates. Disputes are rarely won on recollection.
Questions worth asking your provider
Rather than arguing about whether you are "covered", ask questions that force a specific answer:
- Is this account or facility covered by the ePayments Code?
- Is your institution a subscriber, and is any exemption or declaration relevant to my account?
- Which provisions of the Code apply to the transaction I have reported?
- What is the process from here, and how will I be told the outcome?
- If the outcome is not what I expect, what is the next step in your dispute process?
Asking for the reasoning, not just the result, is usually the fastest way to find out whether a complaint has been handled correctly.
Limits of what the Code does
It is worth being clear about the boundaries. The Code covers electronic payment facilities; it is not a general consumer guarantee scheme, and it is not a substitute for your account terms. It does not mean every unauthorised transaction ends in a refund, and it does not remove your own obligations around keeping credentials and devices secure.
It also does not make any institution a guarantor of your account against every loss. The Code's contribution is that it sets out rules for determining who pays — a structured answer in place of an ad hoc one.
Next steps
- Read ASIC's ePayments Code page and open the current version of the Code itself: https://www.asic.gov.au/regulatory-resources/financial-services/epayments-code
- Confirm whether your provider and your specific account are covered.
- If you have a live dispute, put the questions above to your provider in writing and keep the responses.
- If the matter is not resolved internally, ask your provider to identify its external dispute resolution scheme and how to access it.
- Re-check ASIC's page periodically, since ASIC reviews the Code regularly and the current version may change.
General information only
This article is general information about how the ePayments Code works in Australia. It is not legal, financial or credit advice, and it is not a determination of who is liable for any particular transaction. The Code is administered and reviewed by ASIC, and its contents change over time — always read the current version published by ASIC. Australian Cash is an independent information publisher; it is not a lender, a broker, a government body, a regulator or a comparison service, and it does not assess claims or decide disputes. If you need advice about your specific circumstances, speak to your financial institution or a qualified professional.