Clari5

Voice Analytics: The Behavioral Layer Financial Crime Detection Has Been Missing

Voice analytics is the behavioral detection layer most banks already hold the raw material for. It sits inside the bank’s own call archive, in the 95 percent of recordings that go unanalyzed. 

 

Bank fraud detection runs on two layers today. Transaction monitoring catches what moves through the payment system. Digital behavioral analytics catches how customers click, swipe, and type. There is a third behavioral signal most banks have not yet operationalized: what customers say and how they say it during analyst calls.

The threat data tells a consistent story. Pindrop’s 2025 Voice Intelligence and Security Report tracked a 149 percent year-on-year increase in synthetic voice attacks against banks and a 1,300 percent surge in deepfake fraud attempts. UK Finance reports that 17 percent of authorized push payment fraud cases in the first half of 2025 began through telecommunications.

The conversation is no longer a customer service channel. It is a fraud surface, an investigation source, and a compliance record, all at once. Every recording already sits inside the bank’s environment. Voice analytics is the layer that can turn it into intelligence.

The behavioral intelligence layer most banks already own

Banks record every analyst-customer call as standard practice. Most do not analyze them. The industry benchmark is well documented across multiple call quality studies: traditional manual quality assurance reviews 2 to 5 percent of calls, which means 95 to 98 percent of recorded conversations are never analyzed for fraud, compliance, or investigation value. That is the gap.

Inside that gap sits evidence fraud teams cannot find elsewhere. The contact center carries fraud risk on both sides of the call: Coached mule scripts that surface long before the money moves, agent collusion, coercive language toward distressed customers, and regulatory disclosure failures that sampling cannot catch. Voice carries intent, coercion, scripted behavior, and repeat-caller patterns. None of it reaches a fraud system if the recording is never opened.

Analyzing every call rather than a sample changes what fraud teams can find. Detection no longer depends on what the agent flagged in the moment or what made it into the post-call notes. The recording is the evidence. 

What changes when every call is analyzed

Transactional fraud detection asks what happened in the payment. Digital identity analytics asks how the customer accessed the bank across devices and sessions. Voice analytics asks how the customer sounded, what they said, and what they did not. The three layers are complementary, each carrying intelligence the others cannot generate alone.

Capabilities that open up once the voice layer is in place include:

  1. Earlier detection of social engineering through stress patterns, urgency cues, and coached language captured inside the call recording.
  2. Mule network identification across calls, where voice biometrics link first-time-seen accounts to repeat caller voices, adding evidence at the voice layer that transaction-pattern analysis cannot generate on its own.
  3. Genuine-victim versus coached-mule distinction within a single call, through pitch, rate, pauses, emotion, and cooperation patterns across the two speakers.
  4. Faster case action on high-risk calls, where findings route directly into the case management workflow rather than sitting in a separate quality assurance silo.

Call recordings thus stop being archive material and become operational evidence. Voice analytics enable banks to consistently extract intelligence that is scored objectively and pushed into the same workflows where fraud and compliance teams already act.

The Clari5 Maestro fit

Clari5 Maestro Voice Analytics is built for this layer. It is a post-call forensics and audit platform that runs every analyst-customer call recording through an advanced eight-stage analytical pipeline combining machine learning, voice biometrics, and generative-AI-accelerated language understanding. Sentiment, intent, fraud indicators, compliance adherence, and conversation quality are extracted from each call and surfaced inside the bank’s existing case management workflow. Each call receives a composite risk score across voice, emotion, behavior, and fraud patterns, classified Low to Critical. Coverage is 100 percent. Languages are configurable to local market needs. 

Voice analytics is the third layer, and the one most banks already hold the raw material for. The recordings exist. The processing capacity is available. What is left is the decision to treat the call archive as evidence rather than overhead.

See how Clari5 Maestro applies to fraud and compliance operations at your bank. clari5.com/maestro

Cross-Border Card Fraud: Why Your Authentication Stops Protecting at the Border

Blog - Cross-Border Card Fraud

A structural reality that card issuers across the GCC, South Asia, Southeast Asia, and Africa are now confronting in operational terms: cross-border payment fraud is increasingly industrialized, with attackers deliberately routing transactions through jurisdictions where authentication standards are weakest.

A recent coordinated fraud attack on an Indian bank revealed how cross-border authentication asymmetry creates exposure for every issuer with internationally enabled card products, from forex and prepaid cards to cross-border credit and debit. This piece breaks down the attack pattern, maps who carries the exposure, and outlines what practitioners should be reviewing now.

Authentication asymmetry is the gap that opens when a card transaction routes through a jurisdiction whose authentication standard is weaker than the issuer’s home market. It is the structural vulnerability behind almost every coordinated cross-border card fraud attack in the past two years.

How protected is a card portfolio when customers transact abroad?

Your customers’ fraud exposure on international transactions is not determined by how robust your domestic authentication framework controls are. It is determined by the weakest authentication standard on the transaction route. The moment a card is used with a merchant in a jurisdiction that does not enforce the same standard you do, your domestic safeguards stop protecting. Earlier this year, a coordinated fraud attack proved exactly how it works.

The incident: A coordinated card fraud attack hit a bank’s internationally enabled card portfolio. In a five-hour window, fraudsters drained USD 280,000 across 15 merchants operating in a jurisdiction that does not mandate two-factor authentication for e-commerce. Around 5,000 cardholders were impacted before the bank’s monitoring systems contained the breach.

The bank’s systems did work, partially. They intercepted nearly 700 additional unauthorized attempts and prevented an estimated USD 100,000 in further losses. The breach was detected, contained, and followed by coordinated chargeback action. But the damage was already done before detection.

What made this attack different

Every element of the attack pointed to deliberate planning:

  • The fraudsters targeted specific Bank Identification Numbers (BINs), suggesting prior intelligence about the card program’s infrastructure. This kind of BIN-targeted attack pattern is increasingly common in industrialized card-not-present fraud.
  • Activity was concentrated across 15 merchants in a single geography, pointing to coordinated merchant-side infrastructure rather than scattered opportunism
  • The attack was timed during early morning hours (3:30 AM to 8:30 AM local time) to maximize automated system dependency and minimize the window for human intervention
  • There are reported indications of CVV compromise, raising open questions about where in the supply chain card data was exposed

The jurisdiction choice, the BIN targeting, the timing, the merchant concentration all indicate an industrialized operation built around a regulatory gap.

Who carries this exposure

If you are thinking “this is a forex card problem” or “this is a country-specific issue,” I would push back.

This exposure applies to any card product with international transaction capability: debit cards enabled for cross-border use, credit cards in international e-commerce, multi-currency prepaid cards, co-branded and partnership products, and any card-not-present flow that spans multiple jurisdictions.

The attack happened to target one bank’s forex card portfolio. The vulnerability it exploited exists in every internationally enabled card program I have seen.

Direct, regulatory, and trust costs of a cross-border card fraud incident

The USD 280,000 in direct losses is not the only number that keeps a business head up at night. The real cost is threefold:

  • Direct financial impact. Fraud losses, chargeback processing costs, and the operational expense of investigating, containing, and remediating across thousands of affected accounts. For a larger portfolio or a longer detection window, multiply the numbers from this incident accordingly.
  • Regulatory exposure. In the mentioned case, the central bank summoned senior bank officials for a detailed briefing on root cause, timeline, and cybersecurity adequacy. Supervisory scrutiny does not end with a single meeting. It triggers audit cycles, remediation mandates, and in some jurisdictions, public disclosure requirements. If your regulator is already tightening expectations around card security, an incident like this accelerates that pressure significantly.
  • Customer trust erosion. Cardholders who discover unauthorized international transactions on their accounts do not parse the technical distinction between a domestic control failure and a cross-border authentication gap. They see a bank that failed to protect them. For card products where customer acquisition cost is high and switching cost is low, the downstream attrition impact can far exceed the fraud loss itself.

How this plays out differently across regions

The underlying vulnerability, cross-border authentication asymmetry, is universal. But the risk profile varies by market.

In Southeast Asia, cross-border e-commerce volumes are growing significantly faster than the fraud frameworks designed to monitor them. Banks scaling international card products into new corridors are inheriting authentication gaps they may not have stress-tested yet.

Across African markets, the rapid expansion of mobile money and prepaid card ecosystems is extending international reach into corridors where cross-border fraud controls are still maturing. The co-branded and partnership card models common in these markets add a layer of distributed accountability that this incident specifically exploited.

In the Middle East, regulatory modernization is moving quickly, but authentication standards still vary significantly across jurisdictions within the region. Banks operating across multiple MENA markets carry exposure not just to external geographies but to asymmetries within their own regional footprint.

None of these are hypothetical concerns. They are the operating reality for card issuers in these markets today.

Three questions your board will ask after an incident like this

If a similar attack hits your portfolio, your board or risk committee will want answers to three questions. It is worth having them ready now:

What is our actual exposure on internationally enabled card products? Not the number of cards issued, but a clear view of which products, which corridors, and which destination geographies carry the highest authentication risk.

Have we tested our cross-border fraud controls against this specific attack pattern? Coordinated multi-merchant, BIN-targeted, off-hours, routed through a jurisdiction with no two-factor mandate. If your last fraud control review did not simulate this scenario, it left a gap.

What is our detection and response time if this hits during off-hours? The five-hour window in this incident was not a coincidence. It was the attack design. If your escalation framework depends on human intervention during those hours, that is a timing vulnerability your board should know about.

What issuers should be reviewing

From a practitioner’s standpoint, four areas deserve priority attention:

  1. Cross-border fraud ruleset adequacy. Do your current detection rules account for coordinated multi-merchant attacks routed through jurisdictions with weaker authentication? Most legacy rulesets were not built for this pattern.
  2. Portfolio-level exposure mapping. Which card products in your book have international transaction capability, and which destination geographies carry the highest authentication risk? If you do not have a clear answer, that is the gap.
  3. Off-hours monitoring calibration. Fraudsters deliberately target windows of reduced human oversight. If your detection framework relies on manual escalation during these hours, you have a timing vulnerability worth closing.
  4. Card-not-present controls by jurisdiction. A flat set of rules applied uniformly across all geographies will not catch attacks designed to exploit jurisdiction-specific weaknesses. Detection logic needs to be sensitive to where the transaction is being processed, not just where the cardholder sits.

The structural trend behind cross-border card fraud

The incident is a case study in how cross-border payment fraud is evolving. Fraudsters are not just finding technical vulnerabilities. They are finding regulatory ones, jurisdictions where the rules give them room to operate, and building industrialized attack frameworks around those gaps.

The question for every issuer is not whether this can happen to you. It is whether your fraud detection framework is built for the world where it will happen.

If you would like to pressure-test your current cross-border fraud controls against this attack pattern, let’s connect.

Person Not Present: What AI Agents Mean for Your Fraud Detection Stack


Every fraud detection system in production today is built on one assumption: a human being initiates the transaction. That assumption no longer holds true with AI agents now able to initiate real payments for customers, at scale.

Mastercard launched Agent Pay in partnership with Microsoft, Stripe, and Google. Google’s Agent Payments Protocol has over 60 institutional backers, including American Express, PayPal, and Coinbase. India launched the world’s first national pilot integrating UPI directly into ChatGPT. Without a customer touching their screen, their AI agent can pay for groceries, book a flight, compare insurance premiums, and renew a policy.

This is payments infrastructure being laid across the world’s largest economies. And it changes the fraud equation in ways the industry has not fully absorbed.

 

From card-not-present to person-not-present

For two decades, card-not-present (CNP) defined the dominant fraud category. The physical card was absent, but a human was still on the other end, confirming intent, entering credentials, completing the action.

Javelin Strategy & Research describes what is now replacing it: person-not-present. The human is no longer at the point of transaction at all. The AI agent is the front-line actor. The authorization is indirect, and the initiating logic is not human-readable.

The distinction matters because CNP was an evolution within an existing trust model. Person-not-present breaks the trust model itself. Every verification method, every risk score, and every fraud rule in the stack was designed to answer one question: “Is this the right person?” When no person is present, that question has no answer.

And this is not a distant scenario. Datos Insights projects that 82 percent of midsize to large financial institutions will deploy GenAI into banking and payments workflows by the end of 2026. The infrastructure for AI-initiated transactions is scaling. The framework for monitoring them does not yet exist.

 

Why the current detection stack will not catch it

Rules-based systems evaluate transactions against static thresholds: Is this amount unusual? Is this merchant new? Is this device recognized? These questions assume a human made a decision to transact. When an AI agent initiates a purchase within its pre-set parameters, the transaction will look normal. It may pass velocity checks, come from a recognized device, and still be fraudulent.

Authentication will not catch it as there is no person present to authenticate. Bot detection will not catch it since the agent is legitimate and was invited in. The challenge is no longer separating bots from humans. It is separating legitimate agents from compromised ones that behave identically.

Consider what is no longer an edge case: a compromised agent redirected to transact with a fraudulent merchant. An agent exploited through prompt injection, executing transactions the customer never intended. An agent operating outside its authorized scope, where liability frameworks have not been written yet. Gartner projects that over 50 percent of successful attacks against AI agents will exploit access control issues using prompt injection through 2029.

 

The behavioral intelligence question

When the transaction initiator is not human, point-of-authentication controls lose their explanatory power. The question “Is this the right person?” becomes irrelevant. What replaces it is a different question entirely: “Does this action reflect the customer’s intent?”

That is a behavioral intelligence question. Answering it requires detection infrastructure built to evaluate patterns, sequences, and intent across the full session, not just the authentication moment.

This means analyzing how a session unfolds over time: Whether

  1. the sequence of events leading to a payment reflects genuine intent or manipulation
  2. an agent-initiated transaction aligns with the customer’s historical patterns of engagement
  3. the agent itself is operating within the boundaries the customer established.

Financial institutions that have invested in cross-channel behavioral monitoring are structurally better positioned for this shift than those relying on authentication-centric or rules-based models. The detection paradigm does not need to determine whether the actor is human or machine. It needs to determine whether the action is consistent with the customer’s intent. That distinction is what separates institutions that will detect agent-driven fraud from those that will discover it after settlement.

 

What this looks like in practice

Consider a retail banking customer who has used their account in a consistent pattern for three years: salary credits on the 28th, rent and utilities in the first week of the month, grocery purchases from two or three familiar merchants, and occasional travel bookings planned days in advance with browsing activity preceding the purchase.

The customer enables an AI shopping assistant. The agent is legitimate, authorized, and operating from a recognized device. Within its first week of activity, it initiates a high-value electronics purchase from a merchant the customer has never transacted with, in a product category with no historical precedent, and at a time that is inconsistent with the customer’s established transaction patterns.

A rules engine will see a valid payment within approved limits. Authentication is not triggered because the agent is operating under existing credentials. Bot detection is not triggered because the agent is not a bot. It is an authorized tool. But behavioral intelligence will see something different.

Behavioral intelligence will see a transaction that breaks the customer’s established pattern of engagement across multiple dimensions simultaneously: merchant category, transaction value, timing, and the absence of the browsing-then-purchasing sequence that has preceded every similar transaction in the customer’s history. That cluster of deviations, evaluated together and in real time, will generate the risk signal.

The agent may have been compromised through prompt injection. It may have been redirected to a fraudulent merchant optimized to look legitimate to automated tools. Or it may simply be the customer trying something new. Behavioral intelligence does not need to know the cause to flag the anomaly. It needs to surface the deviation from intent so the institution can act before settlement, not after.

 

The liability gap no one has closed

When a customer taps ‘Buy’, liability frameworks are well-established. This is not true when the customer’s AI agent does it.

OpenAI’s developer documentation places payment liability on merchants and their payment service providers. Google’s A2P Protocol introduces cryptographically signed mandates to create audit trails. Visa is tokenizing agent credentials with spending controls. Everyone is drawing lines, but no one knows where the boundaries will settle.

Javelin’s payments analysts put it plainly: the players involved are keenly aware of what is at stake, but the liability questions remain open. For financial institutions, that uncertainty is not a reason to wait. It is the reason to ensure that the detection infrastructure can distinguish between a legitimate agent acting on verified intent and an agent that has been manipulated, before the settlement window closes.

 

The question that matters now

When the AI layer your institution deployed to improve customer experience becomes the vector through which fraud enters your system, what in your current detection stack will catch it?

Gartner projects that 25 percent of enterprise breaches will trace to AI agent abuse by 2028. The institutions answering that question now will not be reacting to the next wave of agent-driven fraud; they will have already built for it.

Clari5 at Anti-Money Laundering Conference Dubai 2026

At AMLC 3.0, the 3rd Annual Anti-Money Laundering & Compliance Conference, Clari5 joins regulators, banks, fintechs, and policy makers from across the MENA region to explore how real-time intelligence is reshaping financial crime prevention and regulatory compliance.

Hosted at the DoubleTree by Hilton Dubai M Square Hotel & Residences, the conference convenes stakeholders from financial institutions, payment providers, DNFBPs, crypto firms, e-commerce players, and government agencies to address the growing impact of economically motivated crime.

Clari5 will engage with AML, compliance, and risk leaders on how enterprise-wide, real-time intelligence can help institutions:

  • Detect and prevent fraud and money laundering before financial or reputational impact
  • Strengthen AML operations with contextual, cross-channel monitoring and a unified view of customer risk
  • Achieve regulatory compliance through explainable, auditable decisioning aligned with evolving MENA and global standards
  • Enable better collaboration between policy, supervision, and technology teams through integrated analytics and case management

Meet the Clari5 team at AMLC 3.0 to explore how our real-time financial crime management platform can help your institution stay ahead of emerging threats while improving compliance efficiency.

Drop an email to connect@clari5.com

How UAE’s New AML Rules Change the Game for Financial Institutions

Entering 2026, the UAE’s financial sector is operating under a fundamentally different regulatory and market dynamic. The UAE’s exit from the FATF grey list, removal from the EU’s high-risk jurisdiction list, and AED 350 million in recent AML enforcement fines mark a decisive shift. The direction of travel is clear: enforcement is real, scrutiny is targeted, and differentiation has begun. Under Federal Decree-Law No. 10 of 2025, regulators are focused on demonstrable effectiveness rather than formal compliance. As FATF’s 2026 mutual evaluation approaches in June, institutions with mature AML capabilities, evidenced through effective transaction monitoring, timely escalation, and high-quality suspicious transaction reporting, will benefit from faster market access, improved cross border flows, stronger correspondent relationships and participation in regional and international growth opportunities. Those unable to evidence effectiveness face increased operational friction, regulatory attention, and strategic constraints. What the Fines Tell Us Recent enforcement action by the Central Bank in 2025 makes regulatory priorities unmistakable. It signals that regulators are focusing less on formal compliance frameworks and more on whether controls work in practice. Institutions with fragmented monitoring, weak escalation, or poor governance are under pressure. Those with demonstrably mature AML operations are increasingly differentiated by both regulators and counterparties. The New Rules: What Changed and Why It Matters Federal Decree-Law No. 10 of 2025, effective 14 October 2025, is not just another regulatory update. It is the enforcement mechanism behind the fines we have already seen and the framework that will determine which banks get access to the opportunities ahead. Lower Prosecution Threshold: The law no longer requires authorities to prove “actual knowledge” of criminal intent. Banks can now be held liable if they “should have known” based on circumstantial evidence. Extended Enforcement Powers: The Financial Intelligence Unit can now freeze funds for up to 30 days (up from 7) and suspend transactions for 10 working days without notice. For banks with weak screening systems or slow escalation processes, this means operational disruption. For those with automated controls and clear escalation protocols, it means being able to demonstrate rapid response capability. Personal Liability for Senior Management: Senior managers and directors can now face personal criminal liability, from fines to imprisonment, if violations occur due to breach of duty or known negligence. Corporate fines have doubled to a range of AED 5 million to AED 100 million. Expanded Scope: The law now criminalizes Proliferation Financing as a standalone offense, directly regulates Virtual Asset Service Providers (VASPs), and explicitly includes tax evasion as a predicate offense. Banks that have already integrated sanctions screening for proliferation risk and built VASP monitoring frameworks have a structural advantage. What This Means in Practice For Banks For banks, AML maturity is now directly linked to speed, access, and credibility. Banks with integrated monitoring systems, strong model governance, and clear escalation timelines will find cross-border transactions moving faster and relationships easier to maintain. Those that cannot evidence effectiveness may experience quiet friction — slower onboarding, enhanced reviews, and reduced appetite — even without formal regulatory action. In this environment, AML is no longer a defensive function. It is an enabler of market access. For Exchange Houses Exchange houses sit at the sharpest edge of enforcement risk. The scale and concentration of recent penalties indicate heightened regulatory sensitivity to cash-intensive activity, remittance corridors, and frontline control failures. For exchange houses, the issue is not just whether controls exist, but whether they scale with volume and velocity. For VASPs For VASPs, the regulatory transition is now explicit. They are expected to demonstrate the same seriousness of intent as traditional financial institutions — including transaction monitoring calibrated to blockchain risk typologies, sanctions screening, and meaningful STR engagement. FATF 2026: The Evidence Test All of this leads to a clear milestone. The FATF’s 5th Round Mutual Evaluation of the UAE is scheduled for June 2026. The methodology prioritizes effectiveness over form. Assessors will ask whether laws produce outcomes: investigations, convictions, asset recovery, and high-quality financial intelligence. Banks, exchange houses, and VASPs will collectively form the UAE’s evidence base. The Strategic Question For regulated institutions in the UAE, the strategic question has shifted. It is no longer whether an institution can pass an audit. It is whether its AML framework produces evidence that regulators can rely on and counterparties can trust. For leadership teams, now is an appropriate moment to step back and ask a simple question: If our AML framework were tested tomorrow, would it speak for itself? That reflection, more than any single regulatory deadline, is what will shape market access in the years ahead.

RBI Advisory on Real-Time NCRP API Integration: What Indian Banks Need to Know

The Regulatory Context
RBI’s latest advisory to all banks in India on integrating with the National Cyber Crime Reporting Portal (NCRP) for real-time complaint handling is unambiguous. Banks that have not completed onboarding must do so “without further delay” and treat this as “highest priority.”

The advisory also directs all banks, including those already on the portal, to complete API-based integration for real-time action on complaints. The integration must cover all systems and delivery channels. Performance must be reviewed periodically.

The message is clear; manual processing is no longer sufficient. Real-time response is now the expectation.

 

The Challenge
India’s instant payment infrastructure is a remarkable achievement. But speed cuts both ways. When fraud succeeds, funds can move through multiple banks, mule accounts, and exit channels within 30 minutes.

Still most banks process NCRP complaints through manual workflows. This made sense when volumes were lower. But as digital transactions scale and fraud patterns evolve, the gap between how fast money moves and how fast banks can respond is widening.

The goal now is to close that gap. When a complaint lands on NCRP, the response should be immediate: lien marked, freeze triggered, investigation initiated. This is the Golden Hour standard.

 

We Started This Journey Early
At Clari5, we recognised the importance of real-time NCRP integration before the regulatory push. In 2024, we partnered with Punjab National Bank to build India’s first national-scale implementation. Serving 180 million customers across 10,000 branches; PNB needed a system that could match the speed of the threat.

The Clari5 Cybercrime Complaints Processing Platform (CCCP) delivered:

  • Resolution time reduced from days to within the Golden Hour
  • Thousands of complaints processed daily without slowdowns
  • Full automation from 1930 Helpline intake to resolution
  • Complete alignment with RBI, DFS, and I4C requirements

We did not stop there. Since PNB, we have extended real-time NCRP API integration to more banks across India. Each implementation has sharpened our understanding of what works at scale.

 

Why Automation Matters
The benefits go beyond compliance.

Speed. When complaints resolve in the Golden Hour instead of days, funds have a better chance of recovery. Customers see the difference.

Focus. Automation handles the volume. Your investigators get to do real investigative work: pattern analysis, mule network mapping, regulatory coordination.

Confidence. When RBI reviews your fraud response capability, a working system speaks louder than a roadmap.

 

What This Means for Your Bank
Regardless of size, every bank faces the same question: can we respond in real time?

This does not require a multi-year transformation. We have helped banks go live under 30 days. The platform scales alike from regional players to institutions.

Nearly two decades of building fraud systems for Indian banks taught us one thing. The only defense that works is one that moves as fast as the attack. We have done this more than anyone else in this space, and we are ready to help you get there.

 

Looking Ahead
Regulatory expectations are only going to increase. Banks that move early will have time to refine their systems. Those that wait will find themselves under pressure.

Clari5 & PNB chose to be the Pioneers, we chose to lead. The playbook is proven. The technology is production-ready.

If you are evaluating your options, we would welcome the conversation. Schedule a demo.

Clari5 Powers Real-Time AML & Fraud Controls for Indonesia’s OJK Regulation No. 12/2024: A New Era of Accountability

Indonesia’s Financial Services Authority (OJK) is bringing in a new era of anti-fraud governance with Regulation No. 12/2024. It mandates that all Financial Services Institutions (LJKs), including banks, insurers, and fintechs, implement a comprehensive, four-pillar anti-fraud strategy. This regulation supersedes earlier fragmented rules, holds  boards and commissioners directly accountable, and expands requirements across the broader financial landscape.​

The four foundational pillars that OJK sets out are prevention; detection; investigation, reporting, and sanctions; and monitoring, evaluation, and follow-up. These anti-fraud pillars demand holistic integration across all channels and product lines. Banks must unify monitoring systems, deploy forward-looking behavioral analytics, conduct scenario-based simulations for emerging threats such as fraud rings, and provide audit-ready documentation at all times. Institutions relying on legacy rule-based systems, disconnected fraud tools, or manual reporting workflows face a critical choice: modernize rapidly or risk operational disruption, regulatory penalties, and erosion of customer trust.

Timeline: POJK 12/2024 was issued on July 31, 2024, and took effect on October 31, 2024. Banks must now have anti-fraud strategies fully operational, with the next semi-annual reporting deadline of January 31, 2026, rapidly approaching.

 

The Impact for Indonesian Banks
Clari5 has been transforming fraud prevention over the last two decades, iterating continuously to address challenges typically faced by large FIs and to provide an enterprise-wide solution equipped for the new-age fraud landscape. Just as the brain processes threats instantly, Clari5 can help process fraud intelligence across channels in milliseconds.

Holistic integration
Institutions must unify real-time monitoring, AI-driven analytics, and scenario management across all channels. No more silos.

Board-driven compliance
Boards are explicitly accountable for embedding anti-fraud strategies, with sharp personal penalties for lapses.

Stricter controls
From enhanced identity verification and fraud scenario simulations to real-time behavioral monitoring and fraud ring detection, compliance is both proactive and preventive.

Ecosystem-wide effect
The rules extend beyond banks, affecting conglomerate subsidiaries and non-regulated entities under their control.​

 

Meeting OJK 12/2024’s Mandates: The Clari5 (Perfios) Approach
OJK 12/2024 requires a unified, intelligence-led fraud strategy. Clari5, a Perfios company, delivers this through

  • Holistic Integration (Article 7): Unified real-time monitoring across accounts, cards, payments, and wallets, eliminating the data silos that plague legacy systems
  • Board Accountability (Article 5): Automated dashboards with incident tracking, ensuring boards have real-time visibility into fraud KPIs
  • Rapid Reporting (Article 12): was Significant fraud incidents must be reported to OJK within 3 business days of discovery—a deadline impossible to meet with manual processes. Clari5’s pre-configured report templates and automated data aggregation enable 1-click submission, ensuring timely compliance and protecting board members from personal liability.
  • Advanced Detection (Article 8): Graph-based analytics for fraud ring/mule detection, going beyond transaction rules to behavioral patterns

 

Unlike generic fraud alerts that frustrate customers by halting legitimate transactions, Clari5’s AI learns each customer’s transaction behavior. This reduces false positives and enables smooth, secure transactions. A win-win for the bank and its customers!

 

Why Clari5 Stands Out

Enterprise Fraud Management vs Traditional Systems

Component Clari5 Capability
Unified, Real-Time Protection Clari5 eliminates data silos by monitoring accounts, cards, payments, digital wallets, and lending from a single platform. This holistic approach directly addresses OJK’s cross-channel oversight requirements and delivers operational efficiency that fragmented point solutions cannot match.
AI-Driven Intelligence Advanced behavioral analytics and AI/ML models detect fraud patterns invisible to rule-based systems. This helps identify fraud rings, mule networks, and insider collusion by analyzing relationships across the entire customer ecosystem. Such intelligence-led approaches fulfill OJK’s mandate for forward-looking, scenario-based detection.
Compliance Automation Pre-configured OJK reporting templates and incident workflows ensure 3-day notification compliance. Automated data aggregation, case documentation, and alert escalation eliminate manual bottlenecks while providing boards with real-time dashboards to demonstrate governance oversight.
Adaptive Threat Response New fraud scenarios can be deployed in minutes as threats evolve, from AI-generated deepfakes and social engineering to instant payment exploitation. This agility supports OJK’s requirements for proactive, preventive controls without extensive system reconfiguration.
Ecosystem Integration For banking groups, Clari5 extends detection across subsidiaries and fintech partners, meeting OJK’s mandate for comprehensive entity coverage. Seamless integration with core banking systems and payment gateways ensures full protection without disrupting existing technology investments.

Why Clari5 Stands Out

  • For a large Global Retail Bank with 150M customers, Clari5 prevented $600M fraud losses over 5 years demonstrating 90%+ fraud detection rates in real time.
  • Clari5 is recognized by Chartis Research as a Global Category Leader in the RiskTech Quadrant for EFM and AML for the past 5 years.

Why Does This Change the Game?

  • OJK 12/2024 accelerates Indonesia from a reactive, incident-driven model to a unified, real-time and intelligence-led approach. It will help the country outpace many regional peers while reflecting the urgency due to runaway fraud losses compared to neighboring markets:
  • A recent report from Indonesia’s Financial Services Authority (OJK) found that between November of 2024 and February of 2025, the Indonesian economy lost about IDR 700 billion (USD 45 million) to scams.
  • Losses accelerating faster than regional peers in the ASEAN region.
  • Online Scams Drain $474 Million from Indonesians in a Year.
  • The OJK established the Indonesian Anti-Scam Center (IASC) in November 2024 to identify the scale of the problem and work on collaborative solutions.
  • The IASC deals with 18 types of fraud, including illegal investments, online shopping scams, unlicensed lending and social media fraud.

The Risk of Non-Compliance: Financial, Operational & Reputational

  • OJK 12/2024’s penalties are designed to compel immediate action.
  • Non-compliant institutions face escalating administrative sanctions including financial penalties, license suspensions.
  • The market impact is equally damaging. Indonesian consumers increasingly evaluate banks on security and digital experience.
  • Institutions suffering publicized fraud incidents risk deposit flight and market share loss to competitors demonstrating superior protection.
  • In a digitally-driven market where switching costs are low, security perception directly impacts customer acquisition, retention, and brand value.

OJK 12/2024 marks a shift from fragmented controls to an integrated, intelligence-driven fraud framework. Indonesia’s comprehensive framework positions its financial institutions to leapfrog regional peers if they act decisively.

The path forward requires unified platforms, AI-driven detection, and automated compliance workflows. With the right technology foundation, Indonesian banks can transform OJK 12/2024’s requirements into competitive advantages: faster fraud interdiction, operational efficiency, and customer trust.

Clari5 delivers this through real-time behavioral analytics, automated reporting, and proven fraud prevention capabilities. The institutions that move quickly will define Indonesia’s financial services landscape for the decade ahead.

XacBank Fortifies AML Defense with Clari5

As Mongolia’s regulatory landscape evolved to meet FATF standards, XacBank faced a critical inflection point: modernize its financial crime compliance infrastructure or risk falling behind. The bank needed an integrated platform capable of addressing the full anti-money laundering (AML) lifecycle, from watchlist screening through investigation and regulatory reporting.

With Clari5’s AI-powered AML platform, XacBank now operates a unified compliance ecosystem spanning six core functional areas and 15 sophisticated monitoring scenarios. The on-premise deployment ensures complete data sovereignty while delivering enterprise-grade detection capabilities.

Discover how XacBank is setting a new standard for AML compliance in Mongolia’s banking sector.

Philippine Veterans Bank Sets New Benchmark with Clari5

Philippine Veterans Bank has partnered with Clari5 to deploy its AI-powered Enterprise Fraud and Risk Management platform in just 45 days, achieving one of the fastest enterprise-scale fraud prevention rollouts in the industry. The record implementation strengthens real-time fraud detection across digital channels and regulatory compliance, positioning PVB as a leader in next-generation banking security.
Read more on Yahoo FinanceThe Asian BankerStraits TimesFinTech Finance NewsFinTech News SingaporeFinTech News PhilippinesMoney CompassThe Manila TimesCyberSec Asia and Business News This Week.

Financial Trojan Horses: The Growing Impact of Money Mule Fraud in the Middle East

Across the Middle East, money mule fraud is escalating, driven by fake job scams, social engineering, and high-volume remittance flows. With criminal rings operating across borders, regulators such as CBUAE, SAMA, and QCB are redefining fraud prevention for the digital era. This paper unpacks the region’s fast-changing risk dynamics and the immediate priorities for bank leaders to stay ahead.

Download Case Study

Download Whitepaper