How to Build a Mature Anti-Fraud Function

Fraudsters rarely attack a company’s defences directly. They usually look for something the business already regards as normal: rapid onboarding, a convenient payment journey, trust in the customer or an approval process designed to remove friction.

In other words, a vulnerability can resemble an efficient business process.

This is why an anti-fraud function cannot be limited to investigating incidents after money has been lost. It should help the business identify how legitimate products, processes and customer journeys could be misused.

Giana Quandt-Martiena, Compliance Manager at KBC Bank NV in the Netherlands, approaches fraud prevention in these terms. Her experience shows that effective fraud risk management depends on more than controls. Product design, organisational culture, business engagement, reliable metrics and analytical detection all play a part. Above all taking care of the most valuable but vulnerable asset, the coworker or team member. 

Fraud develops where the business leaves room for it

Fraud generally depends on a combination of motivation, opportunity, rationalisation and the ability to conceal what has happened.

A company cannot control every person’s motives. It can, however, make fraud more difficult to commit and harder to hide. Segregation of duties, targeted monitoring, well-designed controls and thorough investigations all reduce the room available for abuse.

The problem is not always an obvious absence of control. Sometimes the business unintentionally creates the opportunity itself.

A complicated process may make unusual activity difficult to identify. Superficial onboarding may allow questionable customers or counterparties into the system. A control programme may no longer reflect the way the product operates. Commercial and risk teams may each hold part of the relevant information without bringing it together.

Companies should therefore ask where their current operating model could be exploited. That assessment needs to be repeated as products, customer behaviour and fraud techniques change.

What distinguishes a mature anti-fraud function

Anti-fraud capabilities tend to develop gradually.

At an early stage, teams rely heavily on manual reviews. Cases may be triggered by customer complaints, whistleblowing reports or information from another institution. Data exchange between compliance, operations, security and the business is often limited.

More developed functions introduce automated detection rules, standard investigation procedures and clearer escalation routes. They may also use network analytics to identify relationships between accounts and respond closer to real time.

At a strategic level, fraud risk becomes part of product design, enterprise risk assessment and management decision-making. The anti-fraud team is no longer involved only when an incident occurs. It helps the business decide which risks to accept, which controls to strengthen and where additional friction is justified.

This development is not a one-off programme. Detection rules need to be refined, closed cases reviewed and emerging patterns shared with product and business owners. Fraud techniques change quickly, so controls based on old cases lose relevance unless the organisation continues to learn.

A fraud risk culture depends on whether people speak up

A policy of zero tolerance means little if employees are reluctant to report what they see.

Before raising a concern, an employee may consider the personal consequences. Will it damage a working relationship? Will a manager view it as an unnecessary obstacle? Could it delay an important transaction or product launch? Will I be judged? The customer has a long-standing relationship with us. I do not want to ruin it. 

A credible fraud risk culture gives employees a clear reporting route and confidence that concerns will be assessed fairly. Whistleblower protection, practical training for the first line and well-defined escalation procedures are all important.

Management behaviour matters just as much. Employees quickly notice whether leaders welcome difficult information or prefer not to hear it.

Fraud prevention should also be part of product development. New features, payment journeys and onboarding processes should be tested for potential misuse before launch. Otherwise, the organisation begins designing controls only after fraudsters have demonstrated where the product is vulnerable.

A red flag rarely tells the whole story

An individual transaction may look reasonable when viewed in isolation. Concern usually develops when it is compared with the customer’s profile, the stated purpose of the account and the behaviour of connected parties.

Possible red flags include:

  • A recently incorporated company with little verifiable digital presence
  • Payment activity that does not match the stated business model
  • Limited online or telephone contact information
  • Borrowing that appears inconsistent with the company’s operations
  • Funds that leave the account shortly after arriving
  • Repeated use of the same intermediaries or beneficiaries

Consider an IT business receiving a high volume of unexplained consumer payments. The activity is not necessarily fraudulent, but the mismatch deserves closer examination.

The speed of fund movement can be particularly revealing. In certain money-laundering patterns, between 70 and 90 per cent of incoming funds may leave an account within 24 to 72 hours. Rapid pass-through activity becomes more significant when combined with newly opened accounts, unusual counterparties or links to higher-risk withdrawal channels.

Employee behaviour may also provide useful context. An unexplained change in lifestyle, repeated reluctance to take leave or unusual secrecy around routine responsibilities may warrant attention. None of these is evidence of fraud on its own. Their value lies in the wider pattern.

Cross-border fraud cannot be understood one transaction at a time

One banking case illustrates how quickly a fraud scheme can extend across jurisdictions.

Victims were persuaded to move money into supposedly safe accounts. The funds passed through accounts held by sole traders in the Netherlands before being transferred onwards, including through SEPA payments between the Netherlands, Romania, Bulgaria and Belgium. At the final stage, the money could be converted into cryptoassets or withdrawn in cash.

Looking at each payment separately revealed only fragments of the scheme.

Investigators needed to establish whether the same telephone numbers, email addresses, IP addresses or beneficial owners appeared elsewhere. They also needed to understand how quickly the funds moved and where the trail became harder to follow. Cross border cooperation is essential.

Traditional transaction monitoring remains useful, but it may not reveal these connections. Complex cross-border fraud calls for network analysis capable of linking participants, accounts, devices and transactions.

The relevant risk may sit in the relationship between events rather than in any single payment.

Anti-fraud KPIs should measure outcomes

The number of fraud cases detected is easy to report. It is much harder to interpret.

An increase may show that detection has improved. It could also mean that attacks are becoming more frequent, controls are producing excessive alerts or a known vulnerability remains unresolved.

A stronger set of anti-fraud KPIs may include:

  • Fraud losses prevented or reduced
  • False-positive rates
  • Time to detect suspicious behaviour
  • Case resolution time
  • Recovery rates
  • Investigation cost per case
  • Customer friction caused by controls
  • Recurrence of previously identified schemes

There is no universal set of metrics. The right measures depend on the product, customer profile, transaction model and risk exposure.

They should, however, be understandable outside the anti-fraud team. Business owners need to see how fraud controls affect losses, processing times, customer experience and operating costs. That creates a more useful discussion about which controls are proportionate and where they need to change.

Limited resources make a risk-based approach essential

Experienced fraud professionals are difficult to recruit, and simply adding more investigators is rarely a sustainable response.

Organisations also need to develop fraud awareness in the first line, share specialist knowledge across teams and use external expertise selectively. Most importantly, they must decide which risks deserve the greatest attention.

Automation can reduce manual work, but only after the underlying problem is understood. A sensible sequence is to identify the most material schemes, find repeatable patterns, test detection rules and examine the quality of the resulting alerts. Analytics can then be scaled where they demonstrate value.

Trying to examine every customer and transaction with the same intensity usually spreads resources too thinly. A risk-based model concentrates attention on scenarios with the strongest warning signs or the greatest potential loss.

AI can strengthen detection, but it also needs oversight

AI can identify patterns that are difficult to capture through fixed rules. It may reveal anomalies in IP activity, device metadata, account relationships or transaction behaviour.

Its output still needs context.

A model-generated alert should be checked against other sources and, where the consequences are significant, reviewed by an experienced investigator. Training data must also be examined carefully. A model that learns from incomplete or distorted historical decisions may repeat those weaknesses at scale.

AI governance is therefore part of fraud risk management. The company should define what the model is intended to detect, who reviews its output, how performance is monitored and what happens when the model behaves unexpectedly.

AI will not compensate for unclear responsibilities or unreliable data. It becomes useful when those foundations are already in place.

Five questions for management

Companies reviewing their anti-fraud function should begin with five questions.

Do we understand our current vulnerabilities?

If controls are strengthened only after an incident, the organisation remains reactive.

Is fraud risk considered before a product is launched?

New channels and customer journeys should be assessed for possible misuse while the design can still be changed.

Do our KPIs support business decisions?

Metrics should explain the effect on losses, customers and operating performance, not merely describe the anti-fraud team’s workload.

Can we see the network around a suspicious transaction?

Complex schemes often become visible through shared devices, repeated intermediaries, connected beneficiaries and the speed of fund movement.

Can employees raise concerns without creating a personal risk for themselves?

Rules and analytics will never capture everything. Employees must be able to report what the systems miss.

The most useful test is not how many fraud cases the company can investigate. It is how often the organisation identifies and closes a vulnerability before that vulnerability produces another case.

How attackers enter corporate networks through employee accounts
How attackers enter corporate networks through employee accounts
#Anti-Fraud, #Cybersecurity, #Data Protection, #Hybrid Work, #Risk Management

Why the most dangerous threat to businesses is no longer external hacking, but access gained through legitimate employee accounts. How security logic is evolving in hybrid environments, how attackers penetrate internal systems, and which signals can reveal an attack before it results in data leakage or infrastructure takeover.

Similar articles

How attackers enter corporate networks through employee accounts
#Anti-Fraud #Cybersecurity #Data Protection #Hybrid Work #Risk Management
How attackers enter corporate networks through employee accounts

Why the most dangerous threat to businesses is no longer external hacking, but access gained through legitimate employee accounts. How security logic is evolving in hybrid environments, how attackers penetrate internal systems, and which signals can reveal an attack before it results in data leakage or infrastructure takeover.

How Corporate Governance Failures Create the Conditions for Fraud
#Compliance #Corporate Governance #Fraud #GRC #Internal Control #KPIs #Operational Efficiency #Risk
How Corporate Governance Failures Create the Conditions for Fraud

Corporate fraud is usually blamed on the individuals involved. But there is another question worth asking: which management decisions allowed the misconduct to begin, spread and remain undetected? Drawing on two anonymised cases, Elina Moshkovich shows how conflicts of interest, poorly designed KPIs and weak control functions can turn isolated abuse into a systemic business risk.

Anti-fraud under resource constraints: how to identify risk convergence points
#Anti-Fraud #Risk Management
Anti-fraud under resource constraints: how to identify risk convergence points

How banks can build effective anti-fraud systems when resources are insufficient for total control. Why, in such conditions, the number of checks matters less than precise prioritization, the ability to separate noise from real risk, and the discipline to identify where fraudulent activity converges. What measures strengthen protection without heavy infrastructure: monitoring dormant accounts, limiting remote onboarding, analyzing links between transactions, and involving employees beyond the anti-fraud function.

External Attack, Internal Gaps: Rethinking Anti-Fraud for a New Fraud Ecosystem
#Anti-Fraud #Cybersecurity #Financial Fraud #Risk Management #Social Engineering
External Attack, Internal Gaps: Rethinking Anti-Fraud for a New Fraud Ecosystem

Modern fraud rarely looks like a conventional cyberattack. It is often disguised as routine customer activity and moves through marketplaces, messaging apps, remote identity checks and gaps in a company’s own processes. What does this mean for anti-fraud, the allocation of responsibility and the way businesses manage risk?