Fraud stopped being a back-office problem for financial institutions some time ago, and the public data leaves little room to argue otherwise. In the FTC's 2025 figures, US consumers reported $15.9 billion in fraud losses, roughly 27 percent more than the year before, and the FBI's Internet Crime Complaint Center passed one million reports in a single year for the first time in its twenty-five years of collecting them.
Money also started moving faster than most control frameworks were designed for. Instant payment rails settle in seconds, scam-induced transfers look legitimate to systems built to catch stolen credentials, and rules in both the US and the UK now push a share of the loss onto the institutions carrying the payment. This guide to fraud detection and prevention for financial institutions covers what works, section by section, with deeper reading signposted throughout.
What Is Fraud Detection and Prevention?
Fraud detection is the process of identifying fraudulent activity in an institution's transactions, accounts, and logins, usually in real time and before funds settle. Fraud prevention is the set of controls that stop fraud from starting, such as identity verification, strong authentication, payee confirmation, and transaction limits. Together they form one program.
The split matters because the two halves are measured differently and are often owned by different teams. Prevention is judged on how much fraud never reaches the system and on how much legitimate business it turns away by accident. Detection is judged on what it catches afterwards, how quickly it catches it, and how many false alerts it produces along the way. An institution can be strong at one and weak at the other, and most are. The sections below take each layer in turn.
Detection vs Prevention: Two Halves of the Same Program
Prevention works on volume. Every control placed before a payment leaves reduces the number of events that detection has to judge later. That includes identity checks and document verification at onboarding, device binding and step-up authentication at login, confirmation of payee before a first transfer to a new beneficiary, velocity and value limits set by customer segment, and warnings shown at the moment a payment is initiated. None of these catch fraud. They make it more expensive to attempt. The full range of fraud prevention methods, and how to prevent fraud before it ever reaches detection, is worth taking separately, but the governing idea is simple. Applying friction early is less costly than conducting late investigations.
Detection takes what survives. It runs continuously across transactions, logins, device sessions, and profile changes, scores each event against what normal looks like for that customer, and decides in milliseconds whether to approve, hold, or block. What prevention cannot see, detection has to infer. An authorized push payment is the clearest case, because the customer really did approve it, the credentials really are theirs, and the only signal left is that the behavior does not fit. That is why neither half works alone. Prevention without detection misses anything that clears the front door, and detection without prevention drowns in volume it should never have received.
How Fraud Detection Works: Rules, Analytics, and AI
Modern detection is layered rather than single-engine. Three things run against the same event stream, and each catches what the others miss. Deterministic rules handle known patterns. Behavioral analytics handle deviation from an established baseline. Machine learning handles patterns nobody has written down yet. The output of all three feeds one risk score, and that score drives an approve, hold, or block decision, with anything ambiguous routed into a case queue for an analyst. Latency matters as much as accuracy here, since a decision that arrives after settlement is a loss report rather than a control. The complete guide to fraud monitoring provides a detailed overview of the entire pipeline.
The rules layer is the deterministic backbone. A rule states a condition and an action, such as holding a transfer when a login from an unrecognized device is followed within minutes by a high-value payment to a new beneficiary. Rules are fast, cheap to run, and fully explainable, which matters when a regulator asks why a particular payment was stopped. The weakness of rules is that they only catch patterns that someone has explicitly defined.
Behavioral analytics fills part of that gap. Instead of fixed thresholds, it builds a picture of how a specific customer normally behaves, when they log in, which devices they use, how they type and navigate, who they usually pay, and how much. Deviation from that baseline raises a score even when no rule fires. Peer group comparison adds a second reference point, since a transfer that is unremarkable for a corporate account can be wildly abnormal for a retail one. This layer is what catches the account takeover that arrives with the correct credentials.
Machine learning operates at a higher level, identifying combinations of weak signals that would go unnoticed by any analyst. It is also where the arms race is most visible, because attackers use the same tools. In its 2025 Internet Crime Report, the FBI tracked AI-enabled crime as its own category for the first time and recorded more than 22,000 complaints carrying $893 million in losses, driven largely by voice cloning, forged documents, and deepfake video used to defeat verification. AI in fraud detection is worth treating as its own subject, since the technology now sits on both sides of the problem.
Common Types of Fraud
Fraud typologies are worth learning as attack vectors rather than as control categories, because one customer can be hit by several in sequence, and a single control often covers more than one type. Scale gives some sense of where the pressure sits. Investment scams accounted for roughly half of the $15.9 billion US consumers reported losing in the FTC's 2025 data, while imposter scams generated the largest number of reports at over a million. A broader overview of the main types of fraud is available separately. The table below covers the ones that most often land on a financial institution's desk:
| Fraud type | How it works |
|---|---|
| Authorized push payment fraud | The customer is deceived into approving a real payment to an account the fraudster controls. |
| Account takeover fraud | Credentials are stolen or bypassed, and then the genuine account is drained from the inside. |
| Synthetic identity fraud | Real and invented details are combined to create a fictitious person, who is then granted credit. |
| Money mule activity | Accounts that are compromised or recruited receive and distribute stolen funds within hours. |
| Card-not-present fraud | The stolen card information is used online or over the phone where the actual card is never checked. |
| Chargeback fraud | A legitimate purchase is reversed through a dispute process that is supposed to protect cardholders. |
| First-party fraud | The real customer is the perpetrator, disputing or defaulting on something they genuinely did. |
| Pig butchering scams | A long grooming relationship ends in a fake investment platform and staged withdrawals. |
Two things connect most of these. The first is the mule layer. Almost every scam and every takeover needs somewhere for the money to land, which makes receiving-side detection as important as sending-side detection. In the UK it is also a shared liability rather than a courtesy, and a growing number of jurisdictions are heading the same way. The second is speed. Once funds arrive in a mule account, they are typically split, layered, and moved out within hours, often converted to crypto at the last hop, which means recovery windows are measured in minutes rather than days. An institution that only monitors outbound payments is watching half the problem.
Classification also drives control design, which is the practical reason to keep the typologies distinct. Takeover is defeated at authentication. Synthetic identity is defeated at onboarding because, after the account opens, the identity behaves like any other customer. Push payment scams can only be caught at the moment of initiation, since everything before that point looks legitimate. Fraud committed by genuine customers surfaces after the fact, through dispute patterns and account history. A program that treats fraud as one undifferentiated problem tends to over-invest in one of those stages and leave the rest thin.
Fraud Monitoring Rules and Scenarios
Detection logic is only as good as its configuration. In practice, fraud rules draw on four families of signals. Velocity covers how much, how often, and how fast, such as three transfers to the same new beneficiary inside an hour. Device and session signals cover fingerprint changes, emulators, remote access tools, and new hardware appearing shortly before a payment. Geolocation covers impossible travel and mismatches between IP address, billing address, and historical pattern. Beneficiary risk covers newly added payees, accounts with a short history, and counterparties already linked to reported fraud. The work of building fraud monitoring rules and scenarios is a discipline in itself.
Calibration is where most programs succeed or fail. A single global threshold fails in both directions at once, flooding analysts with alerts on corporate customers for whom the number is trivial while missing retail customers for whom the same amount is wildly out of character. Effective calibration segments the book first, then sets thresholds and time windows per segment, and documents the reasoning behind each one. The resulting matrix is also among the first artifacts an examiner asks to see, because it is the concrete form of a risk-based approach rather than a claim about one.
The false positive trade-off cannot be completely resolved. It can only be managed. Tighten a rule and you catch more genuine fraud while generating more noise, which costs analyst hours and customer patience. Loosen it, and the reverse happens. Most institutions do better starting with a small tiered library of high-confidence rules, running anything new in shadow mode before it is allowed to block, and retiring rules that have not produced a true positive in months. A rule nobody reviews is a liability rather than a control.
Building a Fraud Risk Management Framework
Controls without governance decay. The most widely used structure comes from COSO and the ACFE, whose Fraud Risk Management Guide organizes the work around five principles, namely governance, risk assessment, prevention and detection control activities, investigation and corrective action, and ongoing monitoring of the program itself. The point of the structure is not the document it produces. It is that someone owns fraud risk by name, that risks are assessed against the institution's actual products and channels rather than a generic list, and that the assessment is revisited when something material changes. A step-by-step guide on how to build a fraud risk management framework covers each principle in order.
Ownership usually follows the three lines of defense. The first line is the business, which runs the controls day to day and escalates what it sees. The second line is risk and compliance, which designs the controls, tunes them, and challenges the first line on the results. The third line is internal audit, which tests independently whether any of it works. The common failure is a second line that reports into the business it is meant to challenge, and that structural problem tends to surface only after a loss.
Measurement closes the loop, and detection speed is where the money sits. The ACFE's Report to the Nations, drawn from 2,402 investigated cases across 143 countries, puts the median occupational fraud loss at $104,000 and the typical time to detection at twelve months. Cases caught inside six months carry a median loss of around $40,000, while those running past five years pass $1.1 million. Tracking fraud KPIs and loss metrics is therefore not reporting overhead, because the interval between onset and detection is itself the single largest driver of what the fraud ends up costing.
Fraud and AML Convergence (FRAML)
Fraud and anti-money laundering teams have historically sat in different parts of the building, run different systems, and reported to different regulators. That separation is breaking down for a practical reason. They keep investigating the same accounts. A mule account is a fraud problem on the way in and a laundering problem on the way out that AML transaction monitoring is built to catch, and splitting it across two teams means each one sees half the picture. How fraud detection and AML transaction monitoring actually differ is worth reading before merging anything, because the two do answer genuinely different questions.
Convergence in practice usually starts with data rather than org charts. Shared entity resolution, so the same customer appearing in a fraud alert and an AML alert resolves to one profile. Shared case management, so an analyst sees both histories in one view instead of requesting the other team's file. Shared typology libraries, since mule networks, scam proceeds, and elder financial exploitation show up in both queues. Only after that does a combined team make much sense. What FRAML means for a compliance program, including where it pays off and where it creates new problems, is covered in detail separately.
Some things do not merge, and pretending otherwise causes trouble. Fraud decisions happen in milliseconds and end in a block, a hold, or a call to the customer. AML decisions happen over days and end in a filed report that the customer never learns about. Fraud answers to consumer protection rules such as Regulation E in the US and the UK reimbursement regime, while AML answers to the Bank Secrecy Act and the wider AML compliance program obligations derived from FATF standards. A converged program shares data, tooling, and staff but keeps two distinct decision paths and two distinct evidence trails.
Fraud by Sector
Banks carry a wider surface than most. They run several payment rails at once, which lets an attacker probe for the weakest and means monitoring has to work across rails rather than per product. They also carry the largest internal fraud exposure, since more staff hold direct access to customer accounts and payment initiation. Regulation has caught up with both. Nacha's fraud monitoring rules, phased in for the largest originators first and then for everyone else, require risk-based monitoring of ACH credit-push payments, including those the customer was deceived into authorizing. The particular risks and controls involved in fraud detection in banking are worth taking on their own.
Fintechs and neobanks face the same typologies at a different tempo. Onboarding that completes in under five minutes leaves very little history for a model to work with, digital-only verification is the only gate a synthetic identity has to pass, and instant cross-border payout compresses the recovery window to almost nothing. The design choices that make these products competitive are the same choices that widen the fraud surface, and regulators increasingly decline to treat an early-stage business model as a mitigating factor. Fintech and neobank fraud is a distinct problem set rather than a smaller version of the banking one.
Where to Start
Institutions that are developing or enhancing this capability typically benefit the most from a short sequence. Map where money can leave and how fast, since that defines the detection window you actually have. Segment the book before setting any threshold. Establish a small library of high-confidence rules and initially run all new rules in shadow mode. Then measure the interval between fraud onset and detection, and treat shortening it as the primary objective rather than a reporting line. Everything else, including the model layer, becomes easier once those four are in place.
Sources
- Federal Trade Commission, Consumer Sentinel Network data and 2025 fraud loss figures
- Federal Trade Commission, Testimony before the Joint Economic Committee on the rising scam economy (March 2026)
- Federal Bureau of Investigation, 2025 Internet Crime Report (IC3 Annual Report)
- Federal Bureau of Investigation, Cryptocurrency and AI scams bilk Americans of billions (press release on the 2025 IC3 report)
- Association of Certified Fraud Examiners, Occupational Fraud 2026: A Report to the Nations, key findings
- COSO and ACFE, Fraud Risk Management Guide, Second Edition, executive summary
- Nacha, Risk Management Topics: Fraud Monitoring Phase 1 (effective March 2026)
- Nacha, Risk Management Topics: Fraud Monitoring Phase 2 (effective June 2026)
- Payment Systems Regulator, Authorised push payment fraud reimbursement requirement
- Consumer Financial Protection Bureau, Regulation E, Electronic Fund Transfers (12 CFR Part 1005)