Skip to main content

Clari5

Nigeria’s Next Fraud Defence: Bringing Fraud, AML and AI Together to Protect Customers in Real Time

Nigeria’s digital payment fraud losses fell sharply in 2025. But the next fraud challenge will not be solved by more alerts, more rules or more disconnected systems.

 

According to NIBSS data presented at the 2026 Nigeria Electronic Fraud Forum, losses from electronic payment fraud fell by 51% in 2025 to ₦25.85 billion, down from ₦52.26 billion in 2024. That is welcome progress. Yet social engineering remained a major threat, while internet banking recorded ₦13.37 billion in losses from 4,507 cases.

The lesson is clear: Nigerian banks are improving their defences, but criminals are changing how they operate.

A fraudster may begin with social engineering, compromise a customer’s device, move money through several accounts and finally cash out through a digital wallet or agent network. Fraud teams may see the suspicious transaction. AML teams may see unusual movement of funds. Customer service may receive the complaint. Investigators may hold the history of a similar case.

But if these signals remain in siloes, the bank just sees disconnected parts of the whole picture.

The criminal sees the whole picture.

That is why the next phase of banking financial crime protection must bring real-time Fraud prevention, AML and AI together on one connected platform, with the ability to detect risk and act while the transaction is still in progress.

The risk is no longer sitting in one channel

Nigerian banks already operate important controls:

  • Know Your Customer and customer due diligence.
  • Sanctions screening.
  • Transaction monitoring.
  • Fraud detection.
  • Customer risk scoring.
  • Case management.
  • Regulatory reporting.

The challenge is not the absence of controls. It is the gap between them.

A customer may have a valid identity and a long banking history. The device may appear familiar. The transaction may not breach a single rule. Yet the customer may suddenly receive funds from unrelated accounts, add a new beneficiary and transfer money to an account already associated with suspicious activity.

Viewed separately, each event may appear manageable. Viewed together, it may indicate account takeover, social engineering, mule activity or an organised fraud network.

This is where Fraud and AML leaders need a shared risk picture.

Customer risk should influence transaction risk. Transaction behaviour should update customer risk. Real-time Fraud intelligence should support AML investigations. AML intelligence should help Fraud teams identify connected activity. Investigation outcomes should improve future detection and prevention.

The objective is simple: One customer. One risk picture. One continuous view of financial crime.

What AI should mean in practice

For banking leaders, AI should solve practical problems that affect customers, investigators and regulators. Used responsibly, it can help banks:

  • Connect customer, account, device, beneficiary and transaction information.
  • Identify unusual relationships across accounts and channels in real time.
  • Detect changes in behaviour before losses occur.
  • Prioritise the cases that deserve immediate attention.
  • Explain why a transaction or customer relationship appears risky.
  • Find links between current alerts and previous investigations.
  • Summarise complex cases for faster review.
  • Support consistent documentation and regulatory reporting.

Early evidence from Nigeria supports this direction. Academic studies on AI-driven real-time fraud detection in Nigerian banks report that machine-learning based systems can identify anomalous transactions faster and with greater accuracy than traditional rule-based approaches, especially when combined with human oversight. [Nigerian AI fraud study]

The purpose is not to remove the investigator from the process. It is to remove the unnecessary searching, duplication and manual work that prevent investigators from applying their judgement where it matters most.

 

Regulation is moving towards timely, connected controls

The regulatory direction in Nigeria is becoming clear. The CBN has continued to strengthen expectations around AML, sanctions compliance, payment security, agent banking, customer protection and electronic fraud response. Its reforms also highlight the importance of safer payment systems and stronger customer protection.

Recent CBN initiatives include enhanced sanctions-related obligations, tighter oversight of payment channels and measures designed to improve the traceability and resilience of digital transactions. The regulator has also emphasised faster fraud response, with a reported expectation that banks should reduce response times to less than 30 minutes.

Nigeria has also strengthened its broader financial-crime framework. In October 2025, the Financial Action Task Force (FATF) removed Nigeria from increased monitoring after the country completed its agreed action plan on AML and counter-terrorist financing. [FATF announcement].

At the same time, reporting obligations are becoming more active. In 2025, Nigerian banks and fintechs filed 42,082 suspicious transaction reports with the Nigerian Financial Intelligence Unit (NFIU), with banks accounting for about 92% of all filings. [NFIU 2025 data]

This matters because a suspicious transaction identified after completion is not the same as one identified during authentication or payment processing.

For a bank, timely detection can mean:

  • Stopping or slowing a suspicious payment.
  • Protecting a customer from a social-engineering scam.
  • Preventing funds from moving through connected mule accounts.
  • Preserving evidence for investigation.
  • Improving the quality and timeliness of regulatory reporting.

Compliance and customer protection should not be treated as competing priorities. In a well-designed operating model, they reinforce each other.

Five priorities for Nigerian banks

1. Map the complete customer journey

Review risk from onboarding through authentication, account activity, beneficiary management, payments, complaints and investigation.

Identify where data is lost between Fraud, AML, Operations, Customer Service and Technology.

2. Connect the signals that matter

Prioritise the data that changes a decision:

  • Identity and KYC information.
  • Device and session behaviour.
  • Transaction patterns.
  • Beneficiary relationships.
  • Account linkages.
  • Customer complaints.
  • Previous fraud and AML investigations.

The aim is not to collect everything. It is to connect the information that helps the bank act.

3. Move from detection to intervention

Real-time detection has limited value if the bank cannot respond in real time.

Define clear actions for different levels of risk, including step-up authentication, transaction holds, customer confirmation, account restrictions, investigation escalation and regulatory reporting.

4. Use AI where human judgement is strongest

Begin with areas where investigators lose the most time:

  • Alert prioritisation.
  • Case summarisation.
  • Relationship discovery.
  • Similar-case identification.
  • Evidence gathering.
  • Quality assurance.

Keep human oversight for important decisions, especially where customers may be inconvenienced or accounts may be restricted.

5. Measure outcomes, not activity

Alert volumes alone do not show whether a financial-crime programme is effective.

Senior leaders should track:

  • Time taken to detect and respond.
  • Confirmed fraud prevented.
  • Investigation turnaround time.
  • False-positive rates.
  • Customer impact.
  • Connected cases discovered.
  • Quality of suspicious-activity reporting.
  • Explainability of important decisions.

The strongest banks will not necessarily be those generating the most alerts. They will be those making the best decisions with the signals they already have.

The next three years: from separate systems to shared intelligence

The direction of travel is straightforward.

Today: Fraud and AML teams often investigate separate alerts.
Next: They share intelligence across customers, accounts, transactions and cases.
Then: The bank assesses identity, behaviour, device, transaction and network risk together.

The goal: Detect risk, decide quickly, act in real time and explain the decision clearly.

This is also where competitive advantage will emerge.

A bank with strong Fraud controls but limited AML context still has a blind spot. A bank with effective AML monitoring but weak real-time transaction intelligence has another. A bank with both capabilities but disconnected investigation workflows may still respond too slowly.

The banks that stand out will be those that make protection visible in the customer experience:

  • Fewer legitimate transactions interrupted.
  • Faster support when customers report fraud.
  • Quicker recovery and containment.
  • More consistent decisions across channels.
  • Greater confidence from regulators, boards and customers.

That is how financial-crime defence becomes more than a compliance function. It becomes part of the bank’s reputation.

The leadership question

The question to consider is:

“Can we bring real-time Fraud, AML and AI together to see the complete risk picture before the customer pays the price?”

Criminals are already connecting identities, accounts, devices, beneficiaries and people. Nigerian banks must now connect their own intelligence faster. The future belongs to the banking institutions that combine strong controls with good judgement, timely action and a clear understanding of the customer behind every transaction.

Better intelligence. Better decisions. Faster protection. That is the standard Nigerian banks should build towards.

Frequently Asked Questions

What is Fraud and AML integration in banking?

Fraud and AML integration connects real-time fraud detection, transaction monitoring, customer risk, sanctions screening and investigation intelligence. It helps teams identify related activity as one financial-crime event rather than as separate alerts.

How can AI help Nigerian banks prevent fraud?

AI can help identify unusual behaviour, connect accounts and transactions, prioritise alerts and provide investigators with relevant context. It should support established controls and human judgement, not replace them.

Why is real-time fraud detection important?

Digital payments can move money within seconds. Real-time detection allows a bank to assess risk and intervene while a transaction, login or beneficiary change is still taking place.

What should banks do about existing Fraud and AML systems?

Banks do not necessarily need to replace every existing system. They can begin by connecting critical data, intelligence and workflows, then modernise progressively according to risk, business priorities and regulatory expectations.

What should Fraud and AML leaders measure?

They should measure detection quality, response time, investigation time, false positives, customer impact, connected-case discovery and decision explainability, rather than alert volumes alone.

Mule Accounts in Indonesia: Why Banks Detect Them Too Late

The account passed KYC. Then it moved Rp2 billion in 47 minutes.

This is not a hypothetical scenario. It is what happened at a major Indonesian bank in early 2026. The customer had valid e-KYC. The account sat dormant for 98 days. Then, in less than an hour, funds arrived from three different sources and were dispersed through five channels: BI-FAST transfer, QRIS payment, e-wallet top-up, card transaction and cash withdrawal.

By the time the fraud team received an alert, the money was gone.

This is the dormancy-to-activation gap, and it is the single biggest blind spot in Indonesian banks’ fraud and AML controls today.

This brief is for: Chief Compliance Officers, Heads of Fraud Risk, AML leaders, Chief Risk Officers and Digital Banking executives at Indonesian banks who need to close the gap between onboarding controls and real-time fraud detection.

The numbers that should worry every bank CXO

Indonesia’s scam response system shows both the scale of the problem and why speed matters.

From 22 November 2024 to 28 December 2025, the Indonesia Anti-Scam Centre (IASC) received 411,055 reports involving reported losses of Rp9 trillion. Around Rp402.5 billion was blocked or saved. CNBC Indonesia

By January 2026, OJK reported 432,637 complaints, reported losses of Rp9.1 trillion and Rp436.88 billion blocked. OJK also confirmed that Rp161 billion had been returned to 1,070 victims through funds blocked across 14 banks. CNBC Indonesia – Fund Recovery

In June 2026, media reports cited IASC figures of 608,168 reported accounts and Rp674 billion frozen, with approximately Rp200 billion returned to victims. Jakartaglobe

These are not just consumer protection statistics. They show how quickly fraud proceeds move through Indonesian bank accounts, virtual accounts, e-wallets and payment channels.

The central question for bank leaders: Can your bank recognise a risky change in account behaviour before the money leaves?

Why mule accounts pass your onboarding checks

A compliance head at a top-10 Indonesian bank put it plainly at a recent industry roundtable:

“Onboarding checks verify who a customer is, but not what the account will ultimately be used for.” Regulation Asia

This is the core problem. Mule networks in Indonesia are not relying on forged identities or fake documents. They are exploiting the gap between:

  • Day 1 verification (KYC, CDD, initial risk rating)
  • Day 90+ behaviour (dormancy, activation, cross-channel movement)

A mule account can sit inside your system for 90 to 120 days with:

  • A validated identity
  • A clean compliance record
  • No transaction red flags (because there are no transactions)

Then, almost overnight, it becomes a conduit for layered fund movement and rapid outflows.

The four-stage mule lifecycle in Indonesia

Mule networks follow a predictable pattern. Understanding this pattern is the first step to detecting it earlier.

Stage 1: Recruitment (Weeks 1-2)

The account holder is recruited, often through social media, informal intermediaries or false employment opportunities. They open the account believing it serves a legitimate purpose such as side income or delivery work.

Stage 2: Dormancy (Months 1-4)

Nothing happens. No transactions. No alerts. Nothing for a monitoring system to catch, simply because there is nothing to catch yet.

This is where most banks’ controls fail. Dormancy is treated as low risk by default. But for mule networks, dormancy is a feature, not a bug.

Stage 3: Activation (Hours 0-48)

Funds arrive from a compromised business account or an investment scam victim. Within 24 to 48 hours, the mule moves money across channels:

  • Core banking to e-money wallet
  • Wallet to card
  • Card to wire transfer
  • Multiple BI-FAST transfers
  • QRIS payments

This fragmentation is deliberate. It is built to break the continuity of a monitoring trail that expects one channel at a time.

Stage 4: Exit (Hours 2-24)

Money leaves through remittance corridors, digital asset platforms, or trusted networks, often before any batch report or investigation has a chance to catch up.

Indonesia’s real-time payment rails make the exit phase especially fast. With BI-FAST (Bank Indonesia’s real-time interbank transfer system) and QRIS enabling instant, 24/7 transfers, the window between activation and exit has compressed from days to minutes. Bank Indonesia

Why your current monitoring misses this

Most Indonesian banks have strong transaction monitoring systems. But they have three structural gaps:

Gap 1: Channel isolation

E-money wallet movement and core banking movement get reported separately. A suspicious pattern only becomes visible when the events are connected.

Gap 2: Static risk profiles

A customer’s risk rating is set at onboarding and rarely updated based on behavioural changes. A low-risk customer can become high-risk within hours, but the system still treats them as low-risk.

Gap 3: Batch-based detection

Many banks still rely on end-of-day or end-of-week batch reports. A mule account that would previously have been caught in batch controls can now move funds across banks, e-money wallets and remittance channels before the batch ever fires.

What OJK and Bank Indonesia are watching

OJK and Bank Indonesia are not yet framing this specifically as a dormancy problem. But enforcement focus is shifting.

Based on current supervisory discussion and international pressure on Indonesia’s AML effectiveness, banks should prepare for:

  • Continuous risk assessment extending well past initial CDD, requiring banks to reassess account usage against declared purpose throughout the relationship
  • Dormancy-to-activation monitoring becoming an explicit supervisory expectation, flagging accounts that jump from dormant to high-activity after 60 or more days of inactivity
  • Cross-channel visibility rules requiring banks to see core banking, e-money and card activity simultaneously rather than reconciling it in batch
  • Predefined red flags for known mule typologies, such as dormancy followed by rapid outflow or simultaneous multi-channel movement

Banks that build these controls now, ahead of formal guidance, put themselves in a stronger position with regulators.

Five actions your fraud desk should take now

  1. Build dormancy profiles by customer segment

A student account sitting untouched for six months may be normal. A business account doing the same may not be. Calibrate dormancy thresholds by segment, product type and historical behaviour.

  1. Create an activation risk signal

When a dormant account suddenly activates, assess:

  • How long was the account inactive?
  • What triggered the first activity?
  • Who sent the money?
  • How quickly did the funds leave?
  • Were several channels involved?
  • Does the activity match the customer’s declared purpose?
  1. Connect channels in real time

Set up real-time correlation: when an account receives funds in core banking and shows outflow activity in a mobile wallet within two hours, treat that as one suspicious pattern, not two separate transactions.

  1. Validate incoming fund sources

Mule accounts often receive funds from recently compromised business accounts or known investment-scam recipients. Maintain a live list of flagged source accounts and review any dormant account that receives funds from them upon activation.

  1. Reconcile activity with purpose

Compare how an account is actually used against what the customer declared at onboarding. A customer who said they were opening an account for e-commerce purchases should not suddenly be receiving large transfers from multiple unrelated sources.

The business case for early action

Banks that move first on post-onboarding risk reassessment and cross-channel correlation stand to gain:

Regulatory credibility

When OJK eventually issues guidance on these controls, early movers will have months of operational data and maturity to show for it.

Reputation and trust

Banks that act early get to define their own reputation on this issue with customers and regulators alike.

Operational efficiency

A fraud desk that can identify mule accounts at activation, rather than weeks into the layering cycle, files more actionable Suspicious Transaction Reports (STRs) with Indonesia’s Financial Transaction Reports and Analysis Centre (PPATK).

How Clari5 approaches this problem

Clari5, a Perfios company, has been recognised across key industry benchmarks. In Chartis Research‘s Enterprise & Payment Fraud Solutions 2026 Quadrant Report, Clari5 was named a Category Leader across all three quadrants. In 2025, it was also named a Category Leader across four Chartis fraud quadrants, including Identity & Verification (ID&V). Most recently, Clari5 secured a Top 50 position in the Chartis Research FCC50 2026 rankings.

Our approach is built around Indonesia’s dormancy-and-activation reality:

  • Persistent customer risk profiles that update through every lifecycle stage, from onboarding through dormancy, activation and active use
  • Real-time cross-channel correlation across core banking, card and e-money channels
  • Behavioural machine learning trained on known mule-activation typologies
  • Post-activation risk reassessment that compares current usage against declared purpose
  • Explainable, auditable models so compliance and internal audit teams can trace why an account was re-rated as high risk

This is not about replacing your existing controls. It is about extending the same rigor you apply at onboarding further into the account lifecycle.

Key takeaway for bank leaders

Your onboarding controls have already done their job well. The next place to focus is the dormancy-to-activation transition, where purpose drift actually shows up.

A clean account can become a risky account.

The bank that detects that change early can protect the customer, preserve more funds and give investigators a better chance of disrupting the wider network.

That is the real purpose of lifecycle-based fraud and AML monitoring: not to distrust customers, but to protect legitimate financial activity when criminal behaviour enters the system.

Frequently asked questions

What is a mule account in Indonesia?

A mule account is a bank or payment account used to receive, hold or transfer funds obtained through fraud, scams or other financial crime. The account may belong to a recruited participant, a victim whose credentials were compromised or a person knowingly allowing others to use the account.

Why do mule accounts pass KYC checks?

KYC verifies identity and customer information at onboarding. It does not always reveal how an account will be used months later. Continuous monitoring is needed to identify changes in behaviour, purpose and transaction patterns.

What is dormancy-to-activation monitoring?

It is the monitoring of accounts that remain inactive for a defined period and then begin transacting suddenly or intensively. The risk assessment considers the dormancy period, first transaction, source of funds, velocity, beneficiaries and cross-channel activity.

How should Indonesian banks detect mule accounts?

Banks should combine customer lifecycle data, transaction monitoring, device and channel information, network relationships, external intelligence from IASC and investigator review. No single threshold is sufficient for every customer segment.

How does IASC support scam response in Indonesia?

IASC provides a coordinated channel for handling reports of financial scams and supporting the blocking and recovery of suspected funds. Customers should report scams through the official IASC website as soon as possible. CNBC Indonesia

Does stronger mule-account detection require blocking more customers?

Not necessarily. Risk-based controls can use step-up verification, temporary holds, customer confirmation and targeted investigation instead of automatically blocking every unusual transaction.

What will OJK expect from banks on mule accounts?

While OJK has not issued specific dormancy guidance, banks should prepare for closer supervisory attention to continuous customer risk assessment, behavioural monitoring and speed of response. Any future OJK or Bank Indonesia guidance should be treated as authoritative when issued.

How can banks measure success in mule-account detection?

Track time from activation to detection, time from detection to intervention, funds prevented from leaving, recovery rate, repeat use of linked accounts, number of related accounts identified, quality and timeliness of STR escalation, and customer impact and false-positive rates.

Kenya FATF Grey List Exit: Why Bank Fraud Desks Hold the Key

RBI’s New Fraud Liability Rules Aren’t About Fraud. They’re About Evidence.

When the Reserve Bank of India released the Third Amendment Directions on Responsible Business Conduct in June 2026, much of the discussion focused on one question: Who pays when a customer loses money through digital fraud?

It’s an understandable reaction. The new framework expands the definition of fraudulent electronic banking transactions, introduces clearer tests around customer and bank negligence, and standardises resolution timelines.

But that’s only the visible part of the change. The more significant shift is operational.

For the first time, every disputed digital transaction effectively becomes an evidentiary exercise. Banks won’t simply be expected to investigate fraud. They’ll be expected to demonstrate within defined regulatory timelines why a particular liability decision was reached and support that conclusion with an auditable chain of evidence.

That distinction may appear subtle. In practice, it changes almost everything.

A New Standard for Liability

The earlier framework largely revolved around unauthorised electronic banking transactions. The revised directions recognise that digital fraud has evolved.

Today’s losses often arise through social engineering, authorised push payment scams, coercion, compromised credentials, or failures involving third-party participants within the wider payments ecosystem.

The regulation acknowledges this reality by broadening the situations that fall within its scope. It also introduces greater clarity around liability.

Where the loss results from factors beyond the direct control of both the customer and the bank, customers who report the incident within five calendar days bear no liability.

Where customer negligence contributes to the fraud — for example, by sharing credentials or authentication details — the customer remains liable only until the incident is reported. Any subsequent loss shifts to the bank.

Domestic cases are expected to be resolved within 45 days, while cross-border transactions have a 60-day timeline. Viewed individually, none of these provisions appears revolutionary.

Taken together, however, they create a new operational expectation. Banks must now explain — not simply decide.

The Real Challenge Begins After the Fraud

Fraud detection has traditionally been measured by prevention:

  • Did the system identify suspicious activity?
  • Was the transaction blocked?
  • Was financial loss avoided?

Those questions remain important. They are no longer sufficient.

Every disputed transaction now requires a second capability that many organisations have never built with the same level of maturity:

  • Can the institution reconstruct exactly what happened?
  • Can investigators show which risk indicators were present?
  • Can they demonstrate which controls were triggered, what actions followed, and why the final liability determination was appropriate?
  • Can they produce that evidence quickly enough to satisfy regulators, auditors, ombudsmen and customers alike?

These questions shift fraud management beyond detection. It becomes a discipline centred equally on investigation, documentation and defensible decision-making.

Why Scale Changes Everything

This challenge cannot be viewed in isolation. India’s digital payments ecosystem operates at extraordinary scale.

UPI alone processed more than 228 billion transactions during the past year. Fraud remains only a tiny proportion of overall transaction volumes. Yet even a fraction of one percent translates into thousands of disputes that may require investigation, documentation and formal liability assessment. Every one of those investigations now runs against a regulatory clock.

Unlike transaction monitoring systems, regulatory timelines don’t scale automatically. If investigations depend on manual evidence gathering across disconnected systems, volume becomes the enemy.

Forty-five days disappears surprisingly quickly when investigators spend much of that time collecting information that already exists elsewhere.

The Hidden Risk Isn’t Fraud. It’s Fragmentation.

Many banks already operate sophisticated fraud detection platforms. Many also operate capable investigation teams.

The problem is that these capabilities often exist independently.

Transaction monitoring, fraud analytics, customer complaints, investigation workflows and case management frequently sit across different applications owned by different teams. That separation may have been manageable when disputes were relatively infrequent. It becomes a liability when every investigation requires a regulator-defensible explanation.

Investigators shouldn’t have to reconstruct history. Evidence should already exist. The strongest operating models won’t create documentation after a complaint arrives — they’ll generate it automatically as decisions are made.

The difference may appear procedural. In reality, it’s the difference between proving a conclusion and attempting to justify one.

This Is Now an Operational Capability

It is tempting to interpret these directions as another compliance exercise. That would be a mistake. Compliance teams don’t investigate fraud. Operations teams do. Fraud analysts do. Case managers do. Customer service teams do. Technology platforms support all of them.

Success therefore depends less on policy documents than on whether these functions operate as one connected system. Institutions preparing for January 2027 should be asking practical questions:

  • Can we explain why a transaction was or wasn’t flagged?
  • Can we demonstrate exactly when customer behaviour changed our liability position?
  • Can investigators access every relevant decision without searching multiple systems?
  • Can supervisors review an entire investigation from beginning to end without requesting additional evidence?

Most importantly: could we answer all of those questions tomorrow? Or would we begin assembling the evidence only after receiving the complaint?

The answer reveals far more about operational readiness than any policy manual.

Evidence Becomes the Competitive Advantage

Much has been written about artificial intelligence transforming fraud detection. Equally important is explainability.

An accurate decision that cannot be explained creates operational risk. A well-documented decision creates confidence. Customers trust outcomes they understand. Regulators trust institutions that can demonstrate consistency. Senior management gains better visibility into operational performance.

Evidence therefore becomes more than a compliance requirement. It becomes a trust asset.

Looking Ahead

The Third Amendment Directions do not require banks to eliminate every fraudulent transaction. No regulation can. What they require is something different.

Banks must consistently determine liability, complete investigations within prescribed timelines, and demonstrate — through evidence rather than opinion — how each conclusion was reached.

That represents a meaningful evolution in how digital fraud will be managed.

The institutions that begin strengthening those capabilities now will be better positioned not only for regulatory compliance but also for faster investigations, more consistent decisions and stronger customer confidence.

Ultimately, the most important question is no longer whether a fraud occurred. It is whether the bank can prove, clearly and consistently, how it reached its conclusion. That is the standard the new framework establishes. And that is where the industry’s attention should now be focused.

How Clari5 Helps Accelerate the Journey

Building a fully integrated anti-fraud capability internally can take years. Many institutions face resource constraints, integration complexity, and aggressive timelines.

Clari5 helps banks accelerate that journey through a unified enterprise fraud management platform supporting real-time fraud detection, cross-channel monitoring, watchlist management, centralized investigations, behavioral intelligence, and fraud-AML collaboration. Typical deployment for a standard-scope implementation runs four to six months, though timelines vary based on integration complexity and data readiness.

Rather than treating detection, investigations, and intelligence sharing as separate initiatives, Clari5 connects them into a single operating environment. The result is faster detection, better analyst productivity, stronger customer protection, and a more scalable fraud prevention capability.

How Prepared Is Your Bank?

We have developed a practical readiness assessment based on the five architectural decisions in this guide. In a 20-minute working session, we will help you identify likely implementation gaps, discuss proven operating models, and benchmark your approach against regional practices. Whether you choose Clari5 or not, you will leave with a clearer roadmap for building a resilient anti-fraud capability.

RBI’s New Fraud Liability Rules Aren’t About Fraud. They’re About Evidence

RBI’s New Fraud Liability Rules Aren’t About Fraud. They’re About Evidence.

When the Reserve Bank of India released the Third Amendment Directions on Responsible Business Conduct in June 2026, much of the discussion focused on one question: Who pays when a customer loses money through digital fraud?

It’s an understandable reaction. The new framework expands the definition of fraudulent electronic banking transactions, introduces clearer tests around customer and bank negligence, and standardises resolution timelines.

But that’s only the visible part of the change. The more significant shift is operational.

For the first time, every disputed digital transaction effectively becomes an evidentiary exercise. Banks won’t simply be expected to investigate fraud. They’ll be expected to demonstrate within defined regulatory timelines why a particular liability decision was reached and support that conclusion with an auditable chain of evidence.

That distinction may appear subtle. In practice, it changes almost everything.

A New Standard for Liability

The earlier framework largely revolved around unauthorised electronic banking transactions. The revised directions recognise that digital fraud has evolved.

Today’s losses often arise through social engineering, authorised push payment scams, coercion, compromised credentials, or failures involving third-party participants within the wider payments ecosystem.

The regulation acknowledges this reality by broadening the situations that fall within its scope. It also introduces greater clarity around liability.

Where the loss results from factors beyond the direct control of both the customer and the bank, customers who report the incident within five calendar days bear no liability.

Where customer negligence contributes to the fraud — for example, by sharing credentials or authentication details — the customer remains liable only until the incident is reported. Any subsequent loss shifts to the bank.

Domestic cases are expected to be resolved within 45 days, while cross-border transactions have a 60-day timeline. Viewed individually, none of these provisions appears revolutionary.

Taken together, however, they create a new operational expectation. Banks must now explain — not simply decide.

The Real Challenge Begins After the Fraud

Fraud detection has traditionally been measured by prevention:

  • Did the system identify suspicious activity?
  • Was the transaction blocked?
  • Was financial loss avoided?

Those questions remain important. They are no longer sufficient.

Every disputed transaction now requires a second capability that many organisations have never built with the same level of maturity:

  • Can the institution reconstruct exactly what happened?
  • Can investigators show which risk indicators were present?
  • Can they demonstrate which controls were triggered, what actions followed, and why the final liability determination was appropriate?
  • Can they produce that evidence quickly enough to satisfy regulators, auditors, ombudsmen and customers alike?

These questions shift fraud management beyond detection. It becomes a discipline centred equally on investigation, documentation and defensible decision-making.

Why Scale Changes Everything

This challenge cannot be viewed in isolation. India’s digital payments ecosystem operates at extraordinary scale.

UPI alone processed more than 228 billion transactions during the past year. Fraud remains only a tiny proportion of overall transaction volumes. Yet even a fraction of one percent translates into thousands of disputes that may require investigation, documentation and formal liability assessment. Every one of those investigations now runs against a regulatory clock.

Unlike transaction monitoring systems, regulatory timelines don’t scale automatically. If investigations depend on manual evidence gathering across disconnected systems, volume becomes the enemy.

Forty-five days disappears surprisingly quickly when investigators spend much of that time collecting information that already exists elsewhere.

The Hidden Risk Isn’t Fraud. It’s Fragmentation.

Many banks already operate sophisticated fraud detection platforms. Many also operate capable investigation teams.

The problem is that these capabilities often exist independently.

Transaction monitoring, fraud analytics, customer complaints, investigation workflows and case management frequently sit across different applications owned by different teams. That separation may have been manageable when disputes were relatively infrequent. It becomes a liability when every investigation requires a regulator-defensible explanation.

Investigators shouldn’t have to reconstruct history. Evidence should already exist. The strongest operating models won’t create documentation after a complaint arrives — they’ll generate it automatically as decisions are made.

The difference may appear procedural. In reality, it’s the difference between proving a conclusion and attempting to justify one.

This Is Now an Operational Capability

It is tempting to interpret these directions as another compliance exercise. That would be a mistake. Compliance teams don’t investigate fraud. Operations teams do. Fraud analysts do. Case managers do. Customer service teams do. Technology platforms support all of them.

Success therefore depends less on policy documents than on whether these functions operate as one connected system. Institutions preparing for January 2027 should be asking practical questions:

  • Can we explain why a transaction was or wasn’t flagged?
  • Can we demonstrate exactly when customer behaviour changed our liability position?
  • Can investigators access every relevant decision without searching multiple systems?
  • Can supervisors review an entire investigation from beginning to end without requesting additional evidence?

Most importantly: could we answer all of those questions tomorrow? Or would we begin assembling the evidence only after receiving the complaint?

The answer reveals far more about operational readiness than any policy manual.

Evidence Becomes the Competitive Advantage

Much has been written about artificial intelligence transforming fraud detection. Equally important is explainability.

An accurate decision that cannot be explained creates operational risk. A well-documented decision creates confidence. Customers trust outcomes they understand. Regulators trust institutions that can demonstrate consistency. Senior management gains better visibility into operational performance.

Evidence therefore becomes more than a compliance requirement. It becomes a trust asset.

Looking Ahead

The Third Amendment Directions do not require banks to eliminate every fraudulent transaction. No regulation can. What they require is something different.

Banks must consistently determine liability, complete investigations within prescribed timelines, and demonstrate — through evidence rather than opinion — how each conclusion was reached.

That represents a meaningful evolution in how digital fraud will be managed.

The institutions that begin strengthening those capabilities now will be better positioned not only for regulatory compliance but also for faster investigations, more consistent decisions and stronger customer confidence.

Ultimately, the most important question is no longer whether a fraud occurred. It is whether the bank can prove, clearly and consistently, how it reached its conclusion. That is the standard the new framework establishes. And that is where the industry’s attention should now be focused.

How Clari5 Helps Accelerate the Journey

Building a fully integrated anti-fraud capability internally can take years. Many institutions face resource constraints, integration complexity, and aggressive timelines.

Clari5 helps banks accelerate that journey through a unified enterprise fraud management platform supporting real-time fraud detection, cross-channel monitoring, watchlist management, centralized investigations, behavioral intelligence, and fraud-AML collaboration. Typical deployment for a standard-scope implementation runs four to six months, though timelines vary based on integration complexity and data readiness.

Rather than treating detection, investigations, and intelligence sharing as separate initiatives, Clari5 connects them into a single operating environment. The result is faster detection, better analyst productivity, stronger customer protection, and a more scalable fraud prevention capability.

How Prepared Is Your Bank?

We have developed a practical readiness assessment based on the five architectural decisions in this guide. In a 20-minute working session, we will help you identify likely implementation gaps, discuss proven operating models, and benchmark your approach against regional practices. Whether you choose Clari5 or not, you will leave with a clearer roadmap for building a resilient anti-fraud capability.

Anti-financial crime summit brings together Nigeria’s banking executives and regulators

Digital innovation expands the opportunity for financial inclusion while simultaneously increasing the chances for financial crime. There is a need for a fundamental shift in how Nigerian banks approach fraud, moving from reactive detection after the fact, to proactive, intelligence-led prevention at the point of risk. AI is no longer a future investment, and it is becoming a baseline requirement for effective fraud and AML management. The challenge for Nigerian institutions is not whether they have the right tools, but whether those tools are governed effectively, with board-level oversight and demonstrable evidence of operational effectiveness.

Read more

Nigeria’s booming digital payments are expanding the attack surface for AI-powered fraudsters, experts warn

As Nigeria’s digital payments industry continues its rapid growth, banks and regulators must rely on artificial intelligence (AI) to combat AI-enabled fraud, money laundering and financial crime. Banking is all about trust and institutions must optimise their systems to prevent attacks or at least protect the assets entrusted to them. Banks previously relied on reactive fraud management systems where different channels operated independently, making it easier for criminals to exploit gaps. Banks now need a unified fraud management platform and an AI-led financial crime management strategy if they want to stay ahead.

Read more

From Compliance to Capability: The Fraud Leader’s Guide to Building Egypt’s Next Anti-Fraud Department

The Honest Conversation Your Board Has Not Had Yet

Here is something most compliance briefings will not tell you: The Central Bank of Egypt April 2026 circular mandating dedicated anti-fraud departments is not your biggest challenge. Your biggest challenge is the six to twelve months after you achieve structural compliance, when your board asks you a far harder question: “How well is it actually working?” Building a department on paper is straightforward. Building one that detects fraud before it lands, investigates efficiently, hands off cleanly to your AML unit, and still lets your digital banking channels run without friction. That is the real work. And it is this work that very few fraud leaders in the world get a playbook for. This is that playbook. Not a regulatory checklist. Not a vendor pitch. A genuine, practitioner-level guide to building something you will be proud of two years from now. It is structured around the questions that experienced fraud leaders know to ask before the org chart is drawn.

What You Will Learn

By the end of this guide, you will understand: 

✓ What the April 2026 CBE Circular requires 

✓ How to structure an anti-fraud department 

✓ The five architecture decisions every bank must make 

✓ How fraud and AML should work together 

✓ Common implementation mistakes 

✓ Practical deployment considerations 

✓ How Prepared Is Your Bank?

How Do Egyptian Banks Build a CBE-Compliant Fraud Department?

Most banks, under deadline pressure, start with structure: reporting lines, headcount, job titles. The CBE circular requires these things, and they matter. But the institutions that build truly effective anti-fraud capabilities start one step earlier. They begin with a clear answer to a more fundamental question.

Are you building a department that manages fraud, or one that prevents it?

These are not the same thing. A fraud management department responds. It investigates cases, prepares reports, maintains databases, and fulfils regulatory obligations. It is essential. A fraud prevention capability anticipates. It uses behavioural patterns to stop fraud before the customer is harmed, before the transaction is settled, before the loss is booked. 

Egypt’s digital financial landscape makes this distinction urgent. InstaPay now serves over 16 million users, processing nearly 1.1 billion transactions worth EGP 2.4 trillion. Meeza digital wallets have reached 55.5 million, executing 1.4 billion transactions worth more than EGP 1.8 trillion. These transactions happen around the clock. Seventy percent of InstaPay’s inaugural year transactions occurred outside regular banking hours. By the time an analyst reviews an end-of-day report, the fraud has already moved. 

The answer, for any serious fraud leader, is to build both: a department that fulfils its governance obligations and a detection capability that operates in real time. The CBE’s framework actually enables this. It mandates continuous monitoring mechanisms across all operations and products. The question is how you architect that monitoring, so it is analytically advanced, not merely active.

The Five Decisions That Determine Whether Your Department Thrives or Struggles

Once you have settled the strategic question, five practical decisions will define your department’s effectiveness. These are the decisions that experienced fraud leaders wish someone had walked them through before they started.

Decision One: Where Does Your Anti-Fraud Department Actually Sit in the Bank’s Intelligence Architecture?

The CBE requires your department to report to the Chief Risk Officer and present to the Board Risk Committee. That is the governance answer. This gives your department operational independence for investigations and reporting, not full independence from every other function in the bank. 

The operational answer is more complex: your anti-fraud function needs to receive data from, and influence decisions in, every channel: core banking, cards, online banking, mobile, InstaPay, POS, e-wallets, and merchant onboarding. The single most costly mistake banks make is building the department as a downstream consumer of other systems’ reports. That model creates lag. 

By the time fraud data reaches your analysts, the money has moved. The better model treats your anti-fraud capability as what it actually needs to be: a central nervous system that monitors every channel simultaneously, cross-pollinates intelligence in real time, and acts within the transaction window. When a card transaction fires in one location while the customer’s mobile banking session is active in another, that conflict should be detected and resolved in milliseconds, not the next morning. This is not aspirational. 

Banks across the MENA region and sub-Saharan Africa are operating at this standard today. The architecture exists, and it is implementable within Egypt’s banking infrastructure.

Decision Two: How Do You Handle Internal Fraud Without Destroying Your Culture?

The CBE circular is explicit: internal fraud investigation (involving employees) is a core responsibility of the anti-fraud department. This is the part of the mandate that creates the most discomfort in organisational conversations. 

The instinct in many banks is to treat internal fraud as a disciplinary and legal matter, handled quietly and case by case. The CBE is asking for something structurally different: a systematic, ongoing monitoring capability that identifies suspicious employee behaviour across access to critical customer information, transaction authorisations, and process controls, before a fraud crystallises. 

This protects the bank and, frankly, protects the employees too. Most internal frauds do not begin with premeditation. It begins with access, then opportunity, then rationalisation. A monitoring system that detects early warning patterns such as unusual access at unusual hours, transaction approvals outside an employee’s normal profile, and repeated overrides on the same account type. Such a system can interrupt that trajectory before it becomes a criminal matter. 

The cultural principle worth establishing from the start: surveillance of behaviour, not surveillance of people. Your system should monitor what happens, not build dossiers on individuals. This distinction matters enormously for staff trust and, increasingly, for the legal defensibility of your investigation outcomes. 

It also means building clear data retention and purpose-limitation rules into the monitoring system itself, in line with Egyptian labour law and data protection expectations, so employee behavioural data is used only for the fraud-prevention purpose it was collected for.

Decision Three: How Precisely Do You Manage the Fraud-AML Boundary?

The CBE’s June 2026 supplementary guidance devoted significant attention to this boundary, and for good reason. It is where the most coordination failures occur in practice. 

The guidance is clear: the anti-fraud department investigates the nature, method, and vulnerability dimension of fraud incidents. When those incidents involve suspected proceeds of crime, money laundering, or terrorist financing, the matter is referred to the AML/CFT unit, which remains the legally designated authority. 

In theory, clean. In practice, many fraud typologies sit directly at this intersection. Account takeover that feeds a mule network. First-party fraud on a loan product that gets layered through multiple accounts. Synthetic identity fraud used to open accounts for structuring. These are not fraud cases or AML cases in isolation. They are both, simultaneously. 

What makes this work operationally is a defined, practised, technology-supported handoff. Not an email chain. A case management system where the fraud investigation record transitions to the AML unit with full context intact: transaction data, behavioural analysis, entity links, investigation notes, and a preserved audit trail of timestamps and device metadata, so the transition holds up to regulatory scrutiny. The AML analyst does not start from zero. Egypt has been building its GoAML STR reporting infrastructure precisely to support this kind of structured intelligence sharing. Your internal case management should connect to that architecture cleanly. 

FATF recognised Egypt’s experience as an international best practice in advancing financial inclusion within AML/CFT frameworks in October 2025. This recognition reflects the strength of Egypt’s regulatory architecture. Your fraud department should be built to complement that architecture, not operate in parallel to it.

Decision Four: How Do You Monitor Digital Channels at Scale Without Drowning Your Analysts?

This is the question that keeps fraud leaders awake. According to Mordor Intelligence, Egypt’s mobile payments market is projected to reach USD 211.79 billion by 2031, growing at a projected 16.45% CAGR. Card POS terminals grew 49% in the most recent reporting period. Every one of those channels generates transaction data that your monitoring capability needs to assess. 

The traditional response is to add rules. More scenarios, more thresholds, more alerts. This produces alert fatigue. Analysts end up reviewing hundreds of low-confidence alerts daily and missing the high-confidence ones buried within them. It is genuinely one of the most debilitating problems in operational fraud management, and it is entirely preventable. 

The answer is not more rules; it is better decisioning. Consider the operational difference between legacy tracking and contextual intelligence: 

Detection ApproachOperational TriggerCustomer Impact & Analyst Burden
Legacy Threshold RulesTriggers an alert on any transfer of a certain size, or any transaction occurring at an unusual hour (e.g., 2 AM).High Noise: A customer who regularly sends large transfers to a family member in Alexandria on Sunday evenings continuously triggers false positives, drowning analysts in low-confidence alerts.
Contextual IntelligenceBuilds a dynamic, behavioural profile of each customer, merchant, and channel, alerting only when behaviour deviates meaningfully from that baseline.High Confidence: Recognises the normal Sunday transfer but immediately intercepts a first-time transfer of the same size sent to an unfamiliar account at 2 AM from a completely new device.

This distinction between contextual intelligence and threshold-based detection is what separates effective monitoring from noise. Leading banks that have deployed this approach report a unified view of risk across all channels, reduced fraud losses, real-time decisioning, and lower false-positive rates that have measurably improved customer experience.

Decision Five: How Do You Build the Watchlist and Database Infrastructure that the CBE Actually Requires?

The CBE requires banks to maintain internal watchlists covering customers, companies, suppliers, and employees involved in fraudulent activity, under a governance framework that ensures objectivity, proper vetting, and controlled use of data. It also requires a comprehensive database of fraud cases with corrective action plans. It requires immediate reporting of cases to the CBE’s Central Anti-Fraud and Financial Crimes Department. 

These are not data management tasks. They are, at their core, intelligence infrastructure tasks. The watchlist is only valuable if it is current, deduplicates correctly across entities, and is accessible to the right people at the right decision points. It should not be buried in a spreadsheet that gets updated monthly. The case database is only valuable if it discovers patterns across incidents that individual analysts cannot see. 

The infrastructure question worth asking early: does your case management system connect to your monitoring system, or are these two separate platforms with no shared intelligence? Banks that build these as a unified layer, where investigation findings feed back into detection models, where watchlist additions immediately affect transaction decisioning, build a compound capability that improves continuously. Banks that build them in silos improve slowly, and at significant operational cost.

If you have reached this point, you might reasonably ask whether every bank needs to build all of this from scratch.

There is a version of this journey that takes three years, significant internal resource, and multiple integration projects before you have something that functions at the standard Egypt’s evolving fraud environment requires. 

There is also a shorter path, and we will come back to it at the close of this guide. What the banks moving fastest have in common: they make the five decisions above before the org chart is finalised. They choose to build for prevention, not just management. They resolve the fraud-AML boundary in the system, not just in the policy document. And they build monitoring intelligence that their analysts can actually act on.

What Success Looks Like at Month Seven CBE examination visits will probe five things: governance independence, Board-approved strategy, live monitoring controls, functioning investigation infrastructure with fraud reporting connected to the CBE’s Central Anti-Fraud and Financial Crimes Department, and a demonstrated, documented relationship with the AML/CFT unit. 

But the measure of success that matters most to a fraud leader is simpler than any of that. It is the moment, sometime in your first operational quarter, when your system identifies a fraud pattern your analysts had not noticed: a new mule recruitment method using a previously unseen account opening sequence, or a merchant that had been quietly facilitating card-not-present fraud across a cluster of transactions too small to trigger manual review. That moment is when you know the department you built is real. That is what we want to help you build.

Frequently Asked Questions (FAQs)

Q1. What exactly does the CBE require Egyptian banks to do under the 2026 mandates?

Banks are legally expected to establish fully independent, dedicated anti-fraud capabilities. This must be supported by an explicit governance structure reporting to the Chief Risk Officer, real-time transaction monitoring controls across all products and operations, comprehensive case management databases with corrective action plans, and structured escalation processes for immediate reporting to the CBE’s Central Anti-Fraud and Financial Crimes Department.

Q2. What is the operational difference between fraud management and real-time fraud prevention?

Fraud management operates retrospectively. It investigates incidents after they occur, meaning losses have already been recorded and recovery becomes the primary goal. Real-time fraud prevention uses behavioural data to identify and disrupt suspicious transactions as they happen, intercepting the threat before the transaction settles and before the customer is harmed. The operational difference is significant: one recovers from fraud; the other prevents it.

Q3. How should anti-fraud and AML teams collaborate under the new CBE framework?

Collaboration must be built into the technology layer, not managed through email chains. When a fraud investigation uncovers suspected proceeds of crime, the case and its full context, including behavioural baselines, device profiles, entity links, and investigation notes, should transition through a shared workflow into the AML/CFT unit for GoAML STR reporting. The AML analyst should not need to start from zero. Structured escalation procedures, shared case management, and integrated intelligence sharing are the operational standard that the CBE’s framework now requires.

Q4. How can Egyptian banks reduce analyst alert fatigue as digital transaction volumes surge?

Banks must move away from static threshold rules that trigger alerts based purely on transaction size or time of day. By deploying contextual and behavioural intelligence, the monitoring system builds a dynamic profile of each customer, merchant, and channel, focusing analyst attention exclusively on deviations that are truly anomalous. This approach materially reduces false positives, improves detection confidence, and allows analysts to act on the alerts that actually matter.

Q5. What capabilities should anti-fraud leaders prioritise when building a new department?

The five capabilities that determine long-term effectiveness are: real-time cross-channel monitoring, internal fraud surveillance with clear behavioural baselines, a technology-supported fraud-AML handoff process, unified case management connected to the watchlist and detection infrastructure, and a Board-approved fraud strategy with documented governance independence. Institutions that resolve these five decisions before finalising their organisation chart build more resilient departments faster.

Q6. How long does it take to build an effective anti-fraud department from the ground up?

Building internal integrations, watchlists, and cross-channel monitoring tools independently can take twelve to eighteen months before the capability functions at the standard Egypt’s evolving fraud environment requires. Institutions leveraging proven enterprise fraud management platforms can accelerate deployment, meeting regulatory deadlines without operational downtime and without compromising on capability depth.

Final Thought

The greatest opportunity within the CBE mandate is not compliance. It is the capability building. The decisions made today will influence fraud resilience, customer trust, operational efficiency, and financial crime readiness for years to come. The institutions that embrace prevention, intelligence, and collaboration will be best positioned to thrive in Egypt’s rapidly evolving digital banking environment.

How Clari5 Helps Accelerate the Journey

Building a fully integrated anti-fraud capability internally can take years. Many institutions face resource constraints, integration complexity, and aggressive timelines.

Clari5 helps banks accelerate that journey through a unified enterprise fraud management platform supporting real-time fraud detection, cross-channel monitoring, watchlist management, centralized investigations, behavioral intelligence, and fraud-AML collaboration. Typical deployment for a standard-scope implementation runs four to six months, though timelines vary based on integration complexity and data readiness.

Rather than treating detection, investigations, and intelligence sharing as separate initiatives, Clari5 connects them into a single operating environment. The result is faster detection, better analyst productivity, stronger customer protection, and a more scalable fraud prevention capability.

How prepared is your bank? 

We have developed a practical readiness assessment based on the five architectural decisions in this guide. In a 20-minute working session, we will help you identify likely implementation gaps, discuss proven operating models, and benchmark your approach against regional practices. Whether you choose Clari5 or not, you will leave with a clearer roadmap for building a resilient anti-fraud capability.

Beyond Identity: Why the Next Objective in Digital Onboarding Is Trust

Identity is a fact. Trust is a prediction.

For years, digital onboarding has treated verifying identity as the whole task. Banks have invested heavily in eKYC, document verification, facial biometrics, liveness detection, OCR, and digital signatures, and these technologies have made customer onboarding faster, more secure, and far more convenient. They have also answered one specific question well: is this person who they claim to be.

That question remains necessary, but it is no longer sufficient.

Genuine Identities, Fraudulent Outcomes

Across banking, fintech, and financial crime prevention, a pattern keeps repeating. A customer with a completely genuine identity becomes a money mule. A customer who passes every onboarding check goes on to commit first-party fraud. A legitimate, fully verified account becomes the destination for scam proceeds or the starting point of a money laundering network.

In each case, identity was never the problem, trust was.

Some of the most sophisticated financial crimes active today do not rely on fake identities at all. It relies on genuine identities used for fraudulent purposes, which is precisely what identity verification cannot catch.

Trust Cannot Be Verified Like Identity

By design, identity is confirmed through a document, a biometric match, or a database lookup. Trust does not work that way. It emerges from the convergence of several signals, and no single one of these is decisive on its own:

  • Device intelligence
  • Behavioral patterns
  • Network relationships
  • Historical risk indicators
  • Digital footprint
  • Transaction intent
  • Consistency across the customer journey

Together, these signals help build confidence in a customer relationship. Identity remains the foundation of onboarding. But identity tells an institution who a customer is. Trust tells it how likely that customer is to misuse the financial system.

A Trust Score Is Still a One-Time Check

Many institutions that have made this shift have done something specific: they added trust signals to the onboarding gate. That is real progress. It is also, on its own, an incomplete version of the shift.

A trust assessment calculated once is still a single decision made at a single moment. It simply uses richer inputs than a document scan did. The gate became smarter but it remains just a gate.

That distinction matters because trust, unlike identity, does not hold still. A customer who looks low risk on day one can look markedly different on day ninety. A dormant account can activate to move money for a mule network. A verified small business can begin receiving transfers that have nothing to do with the business it was onboarded for. None of these customers would necessarily fail a trust assessment run today. They would only fail a later run, which is the assessment most onboarding programs stop performing once the file closes.

A Shift Already Underway, Just Not Yet in Banking

This argument is not unique to banking. Gartner has described a similar shift in security and risk management more broadly, under a framework it calls Continuous Adaptive Risk and Trust Assessment, or CARTA. Its core premise – move away from a single, static, yes-or-no decision at the gate, toward continuous, real-time assessment of risk and trust for as long as the relationship lasts.

Security teams in other industries have been operating this way for close to a decade. Banking has made some real progress on the trust half of this shift but not enough on the continuous half.

What the Next Generation of Onboarding Looks Like

The next generation of onboarding is likely to look less like a gate and more like a standing assessment, one that draws on identity, behavior, device and network signals, and a customer’s conduct across every channel they use to interact with the institution, including conversations conducted by voice, not only forms filled in on a screen.

Some institutions are already asking a further question: whether this kind of ongoing trust assessment should be rebuilt from scratch inside every institution, or whether it can be run as a continuously managed capability, purpose-built for this problem.

The Objective Onboarding Has Not Yet Adopted

Identity verification will remain the foundation of onboarding. But foundations are not objectives.

The objective is no longer only to verify who a customer is. It is to make a better, continuously updated decision about whether that customer can be trusted, for as long as the relationship lasts. Because the costliest fraud is rarely the transaction an institution manages to stop. It is the customer it should never have onboarded, and then never asked about again.

FATF 5th Round: Market Access Now Depends on Outcomes, Not Documents

Early evidence shows how high the bar is, and why fraud and AML teams must align now.

Greylisting. Remediation roadmaps. Correspondent banking restrictions. The Financial Action Task Force (FATF)’s 5th Round of Mutual Evaluations is not a compliance checkbox, it is a market access test.

And early results show that performance under the effectiveness standard is where jurisdictions are falling short, not on documentation.

The distinction matters more than ever.

What Changed in the 5th Round

The FATF revised its assessment methodology in 2022 to measure one thing: whether AML/CFT frameworks produce measurable outcomes. Not documentation or compliance checklists but real-world results: investigations opened, financial intelligence acted upon, proceeds confiscated.

The February 2026 FATF paper, Cyber-Enabled Fraud: Digitalisation and Money Laundering, Terrorist Financing and Proliferation Financing Risks, made the operational shift explicit: 156 jurisdictions, 90 percent of those assessed, now classify fraud as a major money laundering risk. That classification carries a supervisory expectation: fraud controls must feed directly into AML obligations, including suspicious transaction report (STR) production, investigations, and asset recovery.

Institutions still running fraud and AML as separate silos can create a material gap between their country’s fraud risk profile and their actual operational response. That is exactly the misalignment 5th Round assessors are focused on.

The Bar: Higher Than Expected

Early 5th Round assessments show just how demanding the effectiveness standard is:

  • Singapore was upgraded to regular follow-up, its best result under FATF monitoring, yet four of eleven Immediate Outcomes were still rated only moderately effective. Among them was IO7 on money laundering investigations and prosecutions, where FATF directed a shift toward more complex, high-value cases. If a leading financial center carries that gap at its strongest result, few institutions on the schedule should assume they do not.
  • Malaysia, one of the first countries assessed under the new round, was flagged for difficulty translating money laundering investigations into prosecutions. Like every jurisdiction assessed under the 5th Round, it received a time-bound roadmap of recommended actions with three years to demonstrate progress.

For compliance heads in the region, the message is clear: the gap between deployed controls and controls that produce outcomes is no longer theoretical. It is now reflected in real ratings and commercial consequences.

The regional reminder is recent. In February 2026, Kuwait was added to the FATF list of jurisdictions under increased monitoring, following the action plan from its 2024 MENAFATF mutual evaluation. The listing cited gaps in suspicious transaction report effectiveness, beneficial ownership accuracy, and the pace of investigations into cross-border currency movements. For banks in GCC markets, greylisting introduces correspondent banking surcharges, extended settlement times, and reputational friction with foreign investors.

For banks in GCC markets, greylisting introduces correspondent banking surcharges, extended settlement times, and reputational friction with foreign investors. The cost is not just a compliance fine; it is operational resilience and market confidence.

Where the Gap Is Most Visible

Three Immediate Outcomes are where assessors will find the sharpest distinction between institutions that have invested in compliance architecture and institutions whose architecture generates measurable results.

Immediate Outcome 6: Financial Intelligence Usability: The metric is not STR filing volume. It is narrative quality, timeliness, and whether an investigator can act on the report without requesting additional context. Institutions relying on manual STR drafting face an inherent consistency problem: output depends on individual analyst skill and available time. Automated, audit-ready STR narrative generation at scale, coupled with plain-language alert explainability, is the approach aligned with what assessors now evaluate.

Immediate Outcome 7: Investigation and Prosecution Effectiveness: Assessors examine case resolution rates, network analysis depth, and whether institutions can identify and surface complex mule account clusters and layering schemes. The FATF cyber paper describes mule networks as a defining feature of modern fraud infrastructure. Detection tooling that surfaces behavioral context, connected entities, and historical precedent, enabling investigators to move from alert to case resolution without sacrificing depth, is operationally essential.

Immediate Outcome 8: Asset Recovery: Revised FATF standards now emphasize rapid payment-suspension and freezing mechanisms to prevent proceeds from being transferred abroad, alongside non-conviction-based confiscation regimes. Detection without interception does not contribute to confiscation outcomes. Real-time monitoring that enables intervention at the transaction level before proceeds leave the jurisdiction is now the standard.

The direction of travel in the GCC is already visible. The UAE’s National AML/CFT/CPF Committee reported in June 2026 that money laundering cases handled by law enforcement rose nearly 46 percent year on year, frozen assets reached AED 150 million, and FIU information requests increased 20.7 percent. These are the outcome numbers a jurisdiction points to when demonstrating IO8 effectiveness to assessors.

What This Means for Your Institution

The 5th Round assessment cycle is approximately six years. Coupled with time-bound roadmaps for addressing deficiencies, this means jurisdictions and their banking sectors will be in near-continuous evaluation mode through the end of the decade.

Institutions that align fraud and AML capabilities now, rather than optimizing for detection volume and documentation depth, will not just perform better under assessment. They will define the effectiveness benchmark against which their peers are measured.

The compliance era rewarded documentation. The effectiveness era rewards working systems that produce auditable outcomes at scale.

Is Your Institution FATF 5th Round Ready?

The assessment window is open now. Benchmark your institution’s readiness against Immediate Outcomes 6, 7, and 8 while you still have time to close gaps. 

Clari5 is a FRAML platform serving 60+ financial institutions across 30 countries. Our GenAI capabilities, spanning automated SAR/STR narrative generation, alert explainability, investigator co-pilot, and false positive reduction, are built around the effectiveness outcomes assessed under FATF 5th Round Mutual Evaluation methodology.

BNM Card PDs: One Platform for Malaysian Banks, Not Three Procurements

BNM’s three card policy documents introduce obligations across three deadline waves. Most Malaysian banks are treating them as three separate procurement tracks. The architecture decision is singular, not sequential.

The architecture decision behind the deadlines

BNM’s card PDs do not create three technology decisions for Malaysian banks. They create one architecture decision.

Malaysian issuers that treat real-time fraud detection, dispute workflow, card-not-present (CNP) authentication, and customer alerts as separate procurement tracks may meet each deadline individually. They will not meet the operating-model test BNM’s supervisor applies across the issuer.

The deadlines look sequential. The decision is singular.

The three policy documents for Debit, Credit, and Charge cards, covering conventional and Islamic variants, were issued by BNM on 19 December 2025. Their obligations land in three waves.

The first wave is already in force. Real-time fraud detection, mandatory kill switch on debit, default CNP and overseas opt-in blocking, and the liability shift provisions all activated immediately. Credit Card PD §26.1(d) sets the new standard: detection must operate in real time. Where losses arise from weaknesses in the issuer’s systems, processes, or controls, cardholder liability may be limited. BNM’s footnote example is unambiguous. A series of transactions within a short time frame, inconsistent with the customer’s normal transaction behavior, left unblocked, becomes the issuer’s exposure.

The second wave landed on 1 April 2026. Issuers now have three working days to acknowledge a card dispute, must issue a written decision, and on debit disputes, must extend provisional credit if investigation runs past 14 working days (RM 5,000 cap), with full disbursement by 30 days.

The third wave arrives on 1 January 2027. Strong customer authentication on every CNP transaction with SMS OTP capped at RM 250, secure device binding by default, cooling-off on new enrollment and contact detail changes, idle CNP re-blocking after 12 months, and expanded customer alerts covering every CNP transaction, every rejected CNP attempt, and every toggle activation.

These three waves usually engage three different internal functions and trigger three separate vendor evaluations. At audit, BNM reads them as one supervisory view.

The procurement trap

What I see consistently across deployments in India, Indonesia, the Philippines, and now Malaysia is a sequential reading of the PDs. Wave one is operational. Wave two is dispute workflow. Wave three is authentication and device. Each wave maps to a different internal function. Each function takes its slice to its preferred vendor.

The result is three procurement tracks running in parallel: three vendor evaluations, three contracts, three integrations, three audit trails reconciling to one supervisory view.

The cost is operational. When fraud detection, dispute investigation, customer alerting, and device intelligence sit on different stacks with different data formats, the bank spends investigator time on data reconciliation, not fraud analysis. An investigator opening a card dispute case routinely pivots through four or five systems before reaching a decision. Under the 3-working-day BNM acknowledgement clock, that pivoting time is the binding constraint, not the investigator’s analytical capability.

The trap is that the procurement decision feels rational at each step. Fraud buys detection. Card buys customer alerting. Risk buys device intelligence. Dispute buys case management. Each function gets what it asked for. The bank gets an architecture that BNM, at audit time, reads as one liability surface with multiple internal seams.

The dual-stack reality in Malaysia

For Malaysian Tier 1s, the procurement trap compounds with the conventional and Islamic banking duality. Most run parallel cards businesses across a conventional book and an Islamic subsidiary, often on different cards processors, with different rule sets, different investigation workflows, and different reporting lines into BNMLINK. Shariah governance overlays add an approval cycle to every rule change on the Islamic side.

From a technology-purchase view, this looks like two separate engagements. The conventional bank evaluates one stack, the Islamic subsidiary another. Vendors quote separately, deploy separately, run separate roadmaps.

From BNM’s supervisory view, it is one issuer-wide exposure. The 3-working-day dispute acknowledgement clock runs on the slowest side. The behavioral baseline asked for in audit has to be assemblable across both books. The customer alert channel cannot fragment per book if the customer holds cards across both.

This is not a Shariah question but an architecture one. Islamic-side governance can be preserved with one platform and dual-rule-policy management. Banks that try to preserve it by buying two platforms end up paying twice for the same compliance capability and running twice the integration work.

What integrated looks like

The architecture that holds across all three BNM card PD waves runs four functional layers on one platform.

  1. The detection layer operates pre-authorization. Every card transaction is scored in real time against behavioral baselines built from device, location, network, and transaction signals. Rules catch known patterns. Machine learning surfaces anomalies and behavior drift. The detection layer addresses Wave 1 and produces the evidence trail the dispute desk later relies on.
  2. The decide-and-investigate layer is the case management workflow. It opens a case file with detection rationale, customer history, and device evidence pre-assembled. The 14 and 30 working-day debit provisional credit triggers operate automatically. Generative AI investigator support compresses case investigation time, which is where post-April 2026 dispute volume math becomes tractable. This layer addresses Wave 2.
  3. The inform-customer layer handles transaction alerts and customer notifications across SMS, in-app, and voice channels. BNM’s anti-phishing constraints (no hyperlinks, no callback numbers) are built into the alerting template. The layer scales to Wave 3’s expanded scope.
  4. The learn-and-adapt layer feeds detection rules with channel-level intelligence the other layers cannot see. Voice analytics on call-center intake surfaces social engineering coaching patterns and mule recruitment scripts before they appear in transaction data. These patterns become new detection rules in the detection layer, closing the loop. This is what continuous improvement looks like under the BNM standard, and it is what allows the detection layer to keep pace with fraud typology drift between PD reviews.

That is one audit trail end-to-end. The same architecture handles the conventional book and the Islamic book under one operational model, with Shariah governance preserved at the rule-policy level rather than at the platform level.

The three BNM card PD deadlines are sequential. The architecture decision that meets them is singular. Banks scoping it as one platform decision will be in compliance position when the third deadline lands. Banks buying in three pieces will spend the next twelve months reconciling vendors instead of investigating fraud.

The deadlines are the regulator’s design. The operating model that meets them is the bank’s responsibility. Integrated platform thinking is how that operating model gets built.

 

Approach BNM card PD compliance as one platform decision with Clari5

The architecture described in this article is one Clari5 has built, deployed, and refined across Indian, APAC, and MENA banks, including environments running parallel conventional and Islamic banking books on different cores. Request a conversation with our solution team →