Investigating loyalty abuse fairly: Preserve transaction records, ledger entries, and programme terms at time of event; Hold rewards only if there's credible risk of loss, with documented authorisation; Explain decisions clearly and offer a reconsideration route under Australian privacy law
Image: Loyalty Marketing Guide

Loyalty Fraud

Part of Loyalty fraud and abuse

Investigating suspected abuse without wrongly penalising a member

Preserve evidence, check ordinary explanations, limit temporary holds and give members a clear review path when loyalty abuse is suspected.

Investigate suspected loyalty abuse by preserving the record, checking ordinary explanations and giving the member a fair chance to clarify. Restrict an account or reward temporarily only when a specific current risk warrants it. An alert is a signal to assess, not proof that points should be taken away.

Establish what happened

Open a case with the transaction and rule that raised concern. Preserve the programme terms in force at the time, ledger entries, linked orders, reward status, account changes and alert details. Note relevant time zones and distinguish a reward claimed from one used. Leave the original ledger intact so later corrections remain traceable.

Check delayed posting, duplicate events, refunds, shared contact details, staff corrections and promotions before deciding there was abuse. For a lasting or high-impact decision, have a second reviewer examine the evidence. Record what supports the concern and what remains uncertain.

Contain a specific risk

If fulfilment is imminent and there is credible risk of loss, consider a short, documented hold on the affected reward. Keep unrelated access available where practical. Record who authorised the hold, its scope, review time and member contact route. A score or shared device alone should not trigger account closure.

If account takeover is possible, treat the member as a possible victim. Use the established identity-check route before changing contact details or restoring access. Avoid sending sensitive case information to an address or number that may have just been changed.

Ask, decide and explain

Tell the member which transaction or benefit is affected, what temporary limit applies and how they can respond. Ask only for information needed to decide the case; organisations covered by Australian privacy law must keep personal-information collection reasonably necessary and proportionate. Rights to access or correct personal information may also apply, subject to their legal limits.

Set an internal review deadline and update the member if it slips. Record the outcome as a confirmed rule breach, account compromise, system or staff error, legitimate activity, or insufficient evidence.

Check the terms that governed the event. Give a concise reason for an adverse decision and a route for reconsideration. If the programme made a mistake, correct the balance, lift the restriction and explain the correction.

The ACCC recommends ways businesses can improve their customer loyalty schemes and accepts reports about conduct people consider improper, but it does not investigate individual complaints.

Assess any suspected unauthorised access to personal information through the separate privacy-incident process; the Notifiable Data Breaches scheme sets out when a data breach must be notified.

Check whether the alert helped and whether the response caused avoidable harm. Track overturned decisions and time under a hold as well as confirmed losses.

Privacy and Compliance Considerations

APPIs apply to all personal information collected
Under Australian Privacy Principles (APPs)
Data breaches must be notified if serious
Under Notifiable Data Breaches (NDB) scheme
ACCC does not investigate individual complaints
But accepts reports on questionable loyalty scheme conduct

More from Loyalty Fraud

Loyalty Fraud

Loyalty fraud and abuse

Map loyalty abuse risks across signup, earning, redemption and staff access, then investigate unusual activity without treating alerts as proof.