Mid-transaction fraud detection is the ability to evaluate a payment after it has been initiated but before it is released. It gives institutions a final opportunity to score risk, hold suspicious payments, step up authentication, or route the transaction for investigation before funds move.
This article is based on a Bottomline webinar featuring executives from Deloitte, Coop Pank AS, and Bottomline fraud and financial messaging specialists.
Faster payments, embedded finance, and AI-enabled fraud are turning payments security into a CFO-level control issue, where institutions need to detect risk before funds move.
There’s that word: “control.” With AI disrupting an already unruly business payments ecosystem, the need for platforms to be responsive and buttoned-up from the regulatory standpoint is driving decisions about where to invest in infrastructure and partners.
All are central themes of “Payments Connectivity & Compliance: Building Security Across the Payments Lifecycle,” a panel moderated by Bottomline’s Zhenya Winter. Panelists included Konrad Schwenke, Senior Manager, Deloitte Forensics, Financial Crime, Fraud & Data; Siiri Grabbi, Sanctions and CTF Officer at Coop Pank AS; along with Bottomline fraud expert, Eric Choltus, and financial messaging specialist, Natasha Lapierre.
Deloitte’s Schwenke described a shift in how organizations view payment security, from an operations concern to an “enterprise risk topic.” The consequences, he said, now include “customer harm, reputational damage for the organization, and regulatory scrutiny.” For payments, risk and fraud leaders, that’s the point. A failed control is no longer just a bad transaction. It can become a governance problem.
The board-level question, he added, is whether institutions can show they understand “prevention, detection, response” and can “learn from fraud across the full payment life cycle.” That is the governance model now forming around payments risk.
Mid-Transaction Fraud Detection Gets Attention
The most important risk change is happening the moment after a payment is initiated, but before it’s released. Many institutions are unprepared for changes at that juncture.
“I would say the exposure is growing fastest in the middle of the life cycle, where payments are moving too quickly for manual review,” said Bottomline’s Choltus. In older payment models, institutions often had time to review, recall, or recover funds. In faster and real-time payments, the money may be gone before the investigation has even caught up.
In an audience poll, roughly 44% of respondents identified mid-transaction fraud detection as their institution’s biggest payments security gap, ahead of pre-payment validation at about 28%, end-to-end visibility at 18.8%, and post-payment monitoring at just over 9%.

Pre-payment validation still matters. Post-payment monitoring still matters. But neither one is enough if the institution cannot assess risk while the payment is in flight.
A big reveal is that the payment may look clean…even when the transaction is fraudulent. In Authorized Push Payment (APP) fraud, for example, the real user may be logged in, authenticated, and approving the payment. The fraud is not always inside the payment message. It may be in the surrounding context.
“The risk is really not just the payment itself,” Choltus said, “but the connected signals around the user, the beneficiary, the device, and the session.” That’s a very different control model from simply asking whether a payment field looks wrong.
Schwenke made the distinction that matters most for control design. Many institutions are good at detecting compromised credentials, he said, but are “way less mature…when the customer is actually being manipulated into making the payment themselves.” If the real user is being coached into sending funds, authentication may only prove that the wrong action was performed by the right person.
Panelists agreed that fraud detection is on a behavioral journey. Device fingerprinting, geolocation, session activity, keystroke patterns, and mouse movement all help answer a sharper question than whether the user passed authentication. They help resolve whether the person in the session behaves like the real user, or not.
Also in that fraud mix is the fact that rail-specific controls can miss cross-rail fraud. Bottomline’s Lapierre noted that activity can look ordinary on SEPA and ordinary on Swift, but suspicious when viewed together. Her diagnosis? “The problem isn’t the real-time control, it’s not the data, it’s not the connectivity,” she said. “It’s about bridging them.”
That’s a weakness. Siloed controls can validate parts of the picture yet miss the big picture and broader patterns that fraudsters exploit.
Schwenke pointed to mule accounts as one example. “Mule accounts are a very critical part of the fraud chain.” Financial Institutions often focus on stopping customers from sending fraudulent payments while underestimating if their own accounts are receiving or moving fraudulent funds. That turns fraud from an outbound payment problem into an account integrity problem.
The challenge is that identifying those broader patterns depends on connecting data across rails, accounts, and systems.
On that score, ISO 20022 improves the data foundation, but doesn’t automatically deliver better controls. “ISO 20022 is necessary, but I’m going to say it’s not sufficient,” Lapierre said. Richer structured data helps only if institutions can use it across rails, systems, and decision workflows. Otherwise, you can end up with just a better-organized silo.
Fraudsters Have Options
Sizing up the active threats out there is an eye-opener. A major trend is “authorized fraud.” Fraudsters are increasingly manipulating legitimate users into sending payments themselves. That includes invoice redirection, business email compromise, supplier impersonation, and executive impersonation. Stronger login controls alone won’t solve it.
The correct countermeasure is risk-based decisioning that looks at the user, account, beneficiary, device, session, and payment together. A routine payment to a long-standing vendor and a payment to a changed supplier account after a last-minute instruction should not receive the same treatment.
Coop Pank’s Grabbi said Estonia has benefited from fast information exchange between banks when fraudulent funds move domestically. But the model weakens when payments cross borders. That’s the compliance paradox. Institutions need to share more risk intelligence, but legal and operational boundaries often slow the exchange.
The best posture is faster intelligence sharing, stronger consortium data, and the ability to implant that information directly into the payment decision. Choltus made the operational requirement unmistakable: “The key is to embed the intelligence, in real time, into the decisioning workflow, and not treat it as offline reporting.”
Low-value, high-volume fraud supported by automation and AI also needs to be addressed. Choltus painted a scenario that should get attention: “What if a fraudster does one million fraudulent transactions worth $1 each?” A single fraudulent transaction worth $1 million may be easy to flag because it breaks normal behavior. But one million tiny fraudulent payments might slip under threshold-based controls.
Real-time decisioning that can process large volumes of payment, account, and behavioral data in milliseconds is the way to beat these threats. Choltus described the goal as intervening only when risk is “meaningful and explainable,” and doing so “with precision.”
These trends expose the same underlying failures. Fraud, AML, sanctions, terrorist financing, operations, and technology still often sit in separate functions. Coop Pank’s Grabbi warned that teams may miss broader risk signals when sanctions, fraud and money-laundering alerts are treated as separate workflows and payment data remains fragmented across rails, making it harder to identify patterns that span channels. At the same time, regulations move more slowly than fraud typologies, while fraud models become less effective if they are only tuned at implementation and then allowed to drift without reviews or updates.
This is an operational trap. Faster connectivity without stronger control increases risk. More data without orchestration increases noise. APIs, ISO 20022, and AI are useful only when they support a coherent operating model.
The Mandate, In Brief
Panelists said payment security is increasingly treated as a broader risk and governance issue, as it affects customer trust, regulatory exposure, financial crime risk, and operational resilience. The right question is not whether the organization owns fraud tools, but whether it can detect risk earlier and make better payment decisions before funds leave.
Top takeaways:
- Build top and mid-transaction controls that can score, hold, or escalate suspicious payments before release.
- Move from payment-centric detection to account-centric and multi-rail visibility.
- Treat receiving accounts and mule behavior as core fraud risk indicators.
- Use ISO 20022 data, APIs, and consortium intelligence to improve decisions, not just to meet technical requirements.
- Keep tuning fraud models after launch so controls adapt as fraud patterns change.
A few plain-spoken definitions can help leadership teams align here. “Real-time decisioning” means evaluating a payment while it is still in motion. The system can release it, hold it, request more authentication, or send it for investigation before the money is gone.
“Behavioral biometrics” means looking at how a user behaves during a digital session. Typing rhythm, mouse movement, device, location, and navigation patterns can help identify whether the activity fits the real user.
A “unified data layer” means payment information from different systems and rails can be viewed together. Without it, an institution may see several normal-looking events while missing the suspicious pattern they create.
FAQs
ISO 20022 helps payment fraud detection by creating richer, more structured payment data. That data can improve sanctions screening, fraud monitoring, investigation and decisioning. But ISO 20022 only creates value if institutions can use the data across payment rails, systems, and workflows.
Mule accounts are a growing fraud risk because they help fraudsters receive, move, and disperse stolen funds quickly. Institutions that focus only on outgoing payment fraud may miss suspicious receiving-account behavior inside their own customer base.
Financial institutions can reduce payment fraud without adding unnecessary friction by using risk-based decisioning. Low-risk payments should move quickly, while higher-risk payments should trigger targeted intervention, such as a hold, investigation, or additional authentication.
Payment fraud prevention requires multi-rail visibility because suspicious behavior may not appear on a single payment rail. A payment pattern that looks normal in SEPA or Swift alone may look risky when viewed across rails, beneficiaries, and payment types.
The strongest message from the discussion is that payment security has to be designed across the lifecycle. Verification before payment, decisioning during payment, monitoring after payment and continuous learning all need to work together.
For payments, fraud, compliance and technology leaders, that means building payment operations that are fast enough for modern commerce, connected enough to see risk, and controlled enough to stop fraud before the money moves.
Share