Banks are investing more because fraud risk is now tied to regulatory accountability, reimbursement obligations, customer protection expectations, and reputational risk — not just rising fraud volumes.
After two weeks of meetings with Tier 1 banks, private banks, and payment partners across the UK and Switzerland, I came away convinced that fraud prevention has reached an inflection point.
What struck me most was that banks are not investing in fraud prevention simply because fraud is increasing. Fraud has been rising for years.
What has changed is the environment around it.
Across markets, regulators are increasing accountability for fraud outcomes. Reimbursement obligations are expanding. Customer protection expectations are rising. Reputational consequences are becoming more severe. Together, these forces are changing banks' thinking about fraud risk and where they invest. Banks are increasingly being held accountable not only for the controls they deploy, but for the outcomes those controls produce.
As a result, institutions are moving beyond the traditional question of whether a payment looks suspicious. Instead, they are asking what happened before the payment, what else is occurring across the customer journey, and how to manage fraud risk across the entire lifecycle.
It was obvious in many discussions that the institutions making the greatest progress are no longer focused solely on transaction monitoring. They focus on enterprise fraud management.
Today’s fraud rarely begins with the transaction itself. It begins with manipulation, compromised access, abnormal behavior, altered payment instructions, or activity that looks harmless in isolation. By the time a payment reaches a traditional control point, the fraud may already be well underway.
Simply put, the industry needs to move from transaction-centric detection toward enterprise fraud intelligence. That means connecting payments with login activity, session behavior, non-monetary events, network signals, and investigative context. It also means recognizing that no institution can see the full pattern alone.
Fraud Ownership Is Moving Up the Organization
Another consistent theme was organizational change.
Fraud management is no longer viewed solely as an operational responsibility. Increasingly, discussions involve payments leaders, risk leaders, COOs, fraud executives, and senior business stakeholders. During the roadshow, many of our conversations included exactly these audiences.
That shift reflects growing regulatory expectations. In markets such as the UK, EU, and Switzerland, regulatory developments including PSR, PSD3, FINMA guidance, and evolving EBA expectations are raising the bar for how institutions identify, manage, and monitor fraud risk. Reimbursement obligations and customer protection requirements are creating additional pressure for banks to prove effective outcomes.
As fraud becomes a customer protection and reputation issue, ownership naturally moves higher within the organization. The question is no longer simply how to detect suspicious activity. The question is how to manage fraud risk across the entire customer journey while maintaining trust, protecting customers and growing the business.
Fraud and Scams Are Converging in Practice
Banks continue to draw legal and operational distinctions between unauthorized fraud and customer-authorized scams. Those distinctions may remain important for reimbursement and liability, but they are becoming less useful from a prevention perspective.
A romance scam, investment fraud, or impersonation attack may involve a genuine customer, valid login, successful authentication, and an approved payment. A transaction-only system may conclude that nothing is wrong. The broader behavioral pattern may tell a different story.
This is why fraud prevention must examine intent, context, and deviation from normal behavior. The question is not only whether the customer authorized the payment. It is whether the activity is consistent with the customer’s normal behavior and whether surrounding signals indicate manipulation.
Several institutions I met with framed the issue the same way: less focus on categorizing events as fraud versus scam, and more focus on protecting customers from financial harm regardless of the mechanism involved.
For institutions serving high-net-worth clients, the stakes are especially high. Fraud protection is inseparable from trust. The most effective strategies will combine detection accuracy with customer context rather than treating fraud prevention and customer experience as opposing goals.
The Fraud Decision Starts Earlier
Many fraud programs still concentrate their strongest controls at the point of payment execution. That is still necessary, but it is no longer sufficient.
During the roadshow, banks repeatedly emphasized the importance of upstream signals. They wanted earlier visibility into risk. They wanted to monitor activity at login and throughout the customer session, before suspicious payment instructions reach final execution. They were also interested in how non-monetary actions, such as changes to beneficiaries or account settings, could influence a risk decision.
This reflects a more mature understanding of fraud. A payment should not be judged as a single event. It should be evaluated as part of a sequence.
A valid login does not prove that the customer is acting freely. A successfully authenticated payment does not prove that the customer has not been manipulated. Context changes the meaning of the transaction.
This is where a platform approach such as Bottomline's Payment Fraud Defense (PFD) becomes strategically important. The value is not simply in screening more payments. It is in creating a broader decision layer that can combine monetary and non-monetary signals, support earlier intervention, and improve consistency across channels.
Detection Effectiveness and Operational Efficiency
One of the strongest messages throughout my meetings was that banks are tired of equating lower alert volumes with better outcomes.
Many institutions operate several fraud, sanctions, and screening tools introduced at different times for different purposes. The result can be overlapping alerts, duplicated investigations, fragmented data, and significant tuning work.
Machine learning can improve this picture, but only if institutions measure the right things.
Some Banks reported that moving from rules-based controls to machine learning reduced false positives and improved operational efficiency but did not materially improve fraud detection. That's a critical distinction. While efficiency is delivers meaningful value, effectiveness remains the ultimate measure of success.
The real test is whether a solution identifies genuine risk, identifies it earlier, reduces unnecessary friction, and gives investigators better evidence for action.
No Bank Can See the Whole Attack
A significant structural weakness discussed during the roadshow was the lack of cross-bank visibility.
Coordinated fraud often moves through multiple institutions, mule accounts, low-value transactions, and different jurisdictions. Each bank sees only a fragment of the activity. Viewed locally, the behavior may not appear significant. Viewed across the network, it may be obvious.
That is the strategic case for fraud intelligence sharing.
Bottomline's Fraud Intelligence Exchange solution is built for this reality. Institutions need a way to identify suspicious beneficiaries, counterparties, payment corridors, and coordinated activity that no single bank can detect independently.
Banks were receptive to this idea because they increasingly recognize that fraudsters collaborate far more effectively than financial institutions do, but they also want information sharing to happen responsibly, with strong privacy protections, security safeguards, and clear governance.
The industry has to think differently here. Fraud intelligence sharing should not stop at the institution's boundary. Fraudsters do not organize themselves according to bank architecture, product silos, or national operating models. Effective defenses cannot remain trapped inside them either.
Fraud Intelligence Is Becoming a Strategic Capability
The most important lesson from the roadshow is that fraud prevention is no longer being driven solely by fraud volumes.
The market is being reshaped by a convergence of fraud risk, regulatory accountability, reimbursement obligations, customer protection requirements, and reputational concerns. Together, these forces are changing how banks evaluate fraud investments and what they expect from their technology partners.
The target state is broader, earlier, more connected, and more accountable.
Banks need to detect risk before the payment, not only during it. They need to manage fraud and scams through a common customer-protection lens.
They need to balance strong fraud detection with operational efficiency
And they need network intelligence that shows how fraud moves.
Fraud prevention has traditionally been treated as a cost center. Increasingly, however, banks are viewing fraud intelligence as a strategic capability that helps protect customers, strengthen trust, support growth, and meet rising regulatory expectations.
The institutions that lead this transition will stop treating fraud as a sequence of isolated alerts. They will treat it as an enterprise pattern spanning customers, systems, channels, and networks.
By the time the payment instruction arrives, the most important evidence may already exist. The advantage will belong to the institutions that can connect it.
FAQs
Enterprise fraud management connects payment activity with login behavior, session data, non-monetary events, network signals, and investigative context to detect fraud earlier and more accurately.
Transaction monitoring often sees fraud too late and misses critical indicators of suspicious activities. Many scams begin before the payment through manipulation, compromised access, beneficiary changes, or abnormal customer behavior.
Banks can improve detection by sharing fraud intelligence across institutions and monitoring risk upstream at the enterprise level, helping identify suspicious beneficiaries, counterparties, payment corridors, and coordinated activity that no single bank can see alone.
Share