Skip to main content

Clari5

From Compliance to Capability: The Fraud Leader’s Guide to Building Egypt’s Next Anti-Fraud Department

The Honest Conversation Your Board Has Not Had Yet

Here is something most compliance briefings will not tell you: The Central Bank of Egypt April 2026 circular mandating dedicated anti-fraud departments is not your biggest challenge. Your biggest challenge is the six to twelve months after you achieve structural compliance, when your board asks you a far harder question: “How well is it actually working?” Building a department on paper is straightforward. Building one that detects fraud before it lands, investigates efficiently, hands off cleanly to your AML unit, and still lets your digital banking channels run without friction. That is the real work. And it is this work that very few fraud leaders in the world get a playbook for. This is that playbook. Not a regulatory checklist. Not a vendor pitch. A genuine, practitioner-level guide to building something you will be proud of two years from now. It is structured around the questions that experienced fraud leaders know to ask before the org chart is drawn.

What You Will Learn

By the end of this guide, you will understand: 

✓ What the April 2026 CBE Circular requires 

✓ How to structure an anti-fraud department 

✓ The five architecture decisions every bank must make 

✓ How fraud and AML should work together 

✓ Common implementation mistakes 

✓ Practical deployment considerations 

✓ How Prepared Is Your Bank?

How Do Egyptian Banks Build a CBE-Compliant Fraud Department?

Most banks, under deadline pressure, start with structure: reporting lines, headcount, job titles. The CBE circular requires these things, and they matter. But the institutions that build truly effective anti-fraud capabilities start one step earlier. They begin with a clear answer to a more fundamental question.

Are you building a department that manages fraud, or one that prevents it?

These are not the same thing. A fraud management department responds. It investigates cases, prepares reports, maintains databases, and fulfils regulatory obligations. It is essential. A fraud prevention capability anticipates. It uses behavioural patterns to stop fraud before the customer is harmed, before the transaction is settled, before the loss is booked. 

Egypt’s digital financial landscape makes this distinction urgent. InstaPay now serves over 16 million users, processing nearly 1.1 billion transactions worth EGP 2.4 trillion. Meeza digital wallets have reached 55.5 million, executing 1.4 billion transactions worth more than EGP 1.8 trillion. These transactions happen around the clock. Seventy percent of InstaPay’s inaugural year transactions occurred outside regular banking hours. By the time an analyst reviews an end-of-day report, the fraud has already moved. 

The answer, for any serious fraud leader, is to build both: a department that fulfils its governance obligations and a detection capability that operates in real time. The CBE’s framework actually enables this. It mandates continuous monitoring mechanisms across all operations and products. The question is how you architect that monitoring, so it is genuinely intelligent, not merely active.

The Five Decisions That Determine Whether Your Department Thrives or Struggles

Once you have settled the strategic question, five practical decisions will define your department’s effectiveness. These are the decisions that experienced fraud leaders wish someone had walked them through before they started.

Decision One: Where Does Your Anti-Fraud Department Actually Sit in the Bank’s Intelligence Architecture?

The CBE requires your department to report to the Chief Risk Officer and present to the Board Risk Committee. That is the governance answer. This gives your department operational independence for investigations and reporting, not full independence from every other function in the bank. 

The operational answer is more complex: your anti-fraud function needs to receive data from, and influence decisions in, every channel: core banking, cards, online banking, mobile, InstaPay, POS, e-wallets, and merchant onboarding. The single most costly mistake banks make is building the department as a downstream consumer of other systems’ reports. That model creates lag. 

By the time fraud data reaches your analysts, the money has moved. The better model treats your anti-fraud capability as what it genuinely needs to be: a central nervous system that monitors every channel simultaneously, cross-pollinates intelligence in real time, and acts within the transaction window. When a card transaction fires in one location while the customer’s mobile banking session is active in another, that conflict should be detected and resolved in milliseconds, not the next morning. This is not aspirational. 

Banks across the MENA region and sub-Saharan Africa are operating at this standard today. The architecture exists, and it is implementable within Egypt’s banking infrastructure.

Decision Two: How Do You Handle Internal Fraud Without Destroying Your Culture?

The CBE circular is explicit: internal fraud investigation (involving employees) is a core responsibility of the anti-fraud department. This is the part of the mandate that creates the most discomfort in organisational conversations. 

The instinct in many banks is to treat internal fraud as a disciplinary and legal matter, handled quietly and case by case. The CBE is asking for something structurally different: a systematic, ongoing monitoring capability that identifies suspicious employee behaviour across access to critical customer information, transaction authorisations, and process controls, before a fraud crystallises. 

This protects the bank and, frankly, protects the employees too. Most internal frauds do not begin with premeditation. It begins with access, then opportunity, then rationalisation. A monitoring system that detects early warning patterns such as unusual access at unusual hours, transaction approvals outside an employee’s normal profile, and repeated overrides on the same account type. Such a system can interrupt that trajectory before it becomes a criminal matter. 

The cultural principle worth establishing from the start: surveillance of behaviour, not surveillance of people. Your system should monitor what happens, not build dossiers on individuals. This distinction matters enormously for staff trust and, increasingly, for the legal defensibility of your investigation outcomes. 

It also means building clear data retention and purpose-limitation rules into the monitoring system itself, in line with Egyptian labour law and data protection expectations, so employee behavioural data is used only for the fraud-prevention purpose it was collected for.

Decision Three: How Precisely Do You Manage the Fraud-AML Boundary?

The CBE’s June 2026 supplementary guidance devoted significant attention to this boundary, and for good reason. It is where the most coordination failures occur in practice. 

The guidance is clear: the anti-fraud department investigates the nature, method, and vulnerability dimension of fraud incidents. When those incidents involve suspected proceeds of crime, money laundering, or terrorist financing, the matter is referred to the AML/CFT unit, which remains the legally designated authority. 

In theory, clean. In practice, many fraud typologies sit directly at this intersection. Account takeover that feeds a mule network. First-party fraud on a loan product that gets layered through multiple accounts. Synthetic identity fraud used to open accounts for structuring. These are not fraud cases or AML cases in isolation. They are both, simultaneously. 

What makes this work operationally is a defined, practised, technology-supported handoff. Not an email chain. A case management system where the fraud investigation record transitions to the AML unit with full context intact: transaction data, behavioural analysis, entity links, investigation notes, and a preserved audit trail of timestamps and device metadata, so the transition holds up to regulatory scrutiny. The AML analyst does not start from zero. Egypt has been building its GoAML STR reporting infrastructure precisely to support this kind of structured intelligence sharing. Your internal case management should connect to that architecture cleanly. 

FATF recognised Egypt’s experience as an international best practice in advancing financial inclusion within AML/CFT frameworks in October 2025. This recognition reflects the strength of Egypt’s regulatory architecture. Your fraud department should be built to complement that architecture, not operate in parallel to it.

Decision Four: How Do You Monitor Digital Channels at Scale Without Drowning Your Analysts?

This is the question that keeps fraud leaders awake. According to Mordor Intelligence, Egypt’s mobile payments market is projected to reach USD 184.31 billion by 2030, growing at a projected 16.76% annually. Card POS terminals grew 49% in the most recent reporting period. Every one of those channels generates transaction data that your monitoring capability needs to assess. 

The traditional response is to add rules. More scenarios, more thresholds, more alerts. This produces alert fatigue. Analysts end up reviewing hundreds of low-confidence alerts daily and missing the high-confidence ones buried within them. It is genuinely one of the most debilitating problems in operational fraud management, and it is entirely preventable. 

The answer is not more rules; it is better decisioning. Consider the operational difference between legacy tracking and contextual intelligence: 

Detection Approach Operational Trigger Customer Impact & Analyst Burden
Legacy Threshold Rules Triggers an alert on any transfer of a certain size, or any transaction occurring at an unusual hour (e.g., 2 AM). High Noise: A customer who regularly sends large transfers to a family member in Alexandria on Sunday evenings continuously triggers false positives, drowning analysts in low-confidence alerts.
Contextual Intelligence Builds a dynamic, behavioural profile of each customer, merchant, and channel, alerting only when behaviour deviates meaningfully from that baseline. High Confidence: Recognises the normal Sunday transfer but immediately intercepts a first-time transfer of the same size sent to an unfamiliar account at 2 AM from a completely new device.

This distinction between contextual intelligence and threshold-based detection is what separates effective monitoring from noise. Leading banks that have deployed this approach report a unified view of risk across all channels, reduced fraud losses, real-time decisioning, and lower false-positive rates that have measurably improved customer experience.

Decision Five: How Do You Build the Watchlist and Database Infrastructure that the CBE Actually Requires?

The CBE requires banks to maintain internal watchlists covering customers, companies, suppliers, and employees involved in fraudulent activity, under a governance framework that ensures objectivity, proper vetting, and controlled use of data. It also requires a comprehensive database of fraud cases with corrective action plans. It requires immediate reporting of cases to the CBE’s Central Anti-Fraud and Financial Crimes Department. 

These are not data management tasks. They are, at their core, intelligence infrastructure tasks. The watchlist is only valuable if it is current, deduplicates correctly across entities, and is accessible to the right people at the right decision points. It should not be buried in a spreadsheet that gets updated monthly. The case database is only valuable if it discovers patterns across incidents that individual analysts cannot see. 

The infrastructure question worth asking early: does your case management system connect to your monitoring system, or are these two separate platforms with no shared intelligence? Banks that build these as a unified layer, where investigation findings feed back into detection models, where watchlist additions immediately affect transaction decisioning, build a compound capability that improves continuously. Banks that build them in silos improve slowly, and at significant operational cost.

If you have reached this point, you might reasonably ask whether every bank needs to build all of this from scratch.

There is a version of this journey that takes three years, significant internal resource, and multiple integration projects before you have something that functions at the standard Egypt’s evolving fraud environment requires. 

There is also a shorter path, and we will come back to it at the close of this guide. What the banks moving fastest have in common: they make the five decisions above before the org chart is finalised. They choose to build for prevention, not just management. They resolve the fraud-AML boundary in the system, not just in the policy document. And they build monitoring intelligence that their analysts can actually act on.

What Success Looks Like at Month Seven CBE examination visits will probe five things: governance independence, Board-approved strategy, live monitoring controls, functioning investigation infrastructure with fraud reporting connected to the CBE’s Central Anti-Fraud and Financial Crimes Department, and a demonstrated, documented relationship with the AML/CFT unit. 

But the measure of success that matters most to a fraud leader is simpler than any of that. It is the moment, sometime in your first operational quarter, when your system identifies a fraud pattern your analysts had not noticed: a new mule recruitment method using a previously unseen account opening sequence, or a merchant that had been quietly facilitating card-not-present fraud across a cluster of transactions too small to trigger manual review. That moment is when you know the department you built is real. That is what we want to help you build.

Frequently Asked Questions (FAQs)

Q1. What exactly does the CBE require Egyptian banks to do under the 2026 mandates?

Banks are legally expected to establish fully independent, dedicated anti-fraud capabilities. This must be supported by an explicit governance structure reporting to the Chief Risk Officer, real-time transaction monitoring controls across all products and operations, comprehensive case management databases with corrective action plans, and structured escalation processes for immediate reporting to the CBE’s Central Anti-Fraud and Financial Crimes Department.

Q2. What is the operational difference between fraud management and real-time fraud prevention?

Fraud management operates retrospectively. It investigates incidents after they occur, meaning losses have already been recorded and recovery becomes the primary goal. Real-time fraud prevention uses behavioural data to identify and disrupt suspicious transactions as they happen, intercepting the threat before the transaction settles and before the customer is harmed. The operational difference is significant: one recovers from fraud; the other prevents it.

Q3. How should anti-fraud and AML teams collaborate under the new CBE framework?

Collaboration must be built into the technology layer, not managed through email chains. When a fraud investigation uncovers suspected proceeds of crime, the case and its full context, including behavioural baselines, device profiles, entity links, and investigation notes, should transition through a shared workflow into the AML/CFT unit for GoAML STR reporting. The AML analyst should not need to start from zero. Structured escalation procedures, shared case management, and integrated intelligence sharing are the operational standard that the CBE’s framework now requires.

Q4. How can Egyptian banks reduce analyst alert fatigue as digital transaction volumes surge?

Banks must move away from static threshold rules that trigger alerts based purely on transaction size or time of day. By deploying contextual and behavioural intelligence, the monitoring system builds a dynamic profile of each customer, merchant, and channel, focusing analyst attention exclusively on deviations that are genuinely anomalous. This approach materially reduces false positives, improves detection confidence, and allows analysts to act on the alerts that actually matter.

Q5. What capabilities should anti-fraud leaders prioritise when building a new department?

The five capabilities that determine long-term effectiveness are: real-time cross-channel monitoring, internal fraud surveillance with clear behavioural baselines, a technology-supported fraud-AML handoff process, unified case management connected to the watchlist and detection infrastructure, and a Board-approved fraud strategy with documented governance independence. Institutions that resolve these five decisions before finalising their organisation chart build more resilient departments faster.

Q6. How long does it take to build an effective anti-fraud department from the ground up?

Building internal integrations, watchlists, and cross-channel monitoring tools independently can take twelve to eighteen months before the capability functions at the standard Egypt’s evolving fraud environment requires. Institutions leveraging proven enterprise fraud management platforms can accelerate deployment, meeting regulatory deadlines without operational downtime and without compromising on capability depth.

Final Thought

The greatest opportunity within the CBE mandate is not compliance. It is the capability building. The decisions made today will influence fraud resilience, customer trust, operational efficiency, and financial crime readiness for years to come. The institutions that embrace prevention, intelligence, and collaboration will be best positioned to thrive in Egypt’s rapidly evolving digital banking environment.

How Clari5 Helps Accelerate the Journey

Building a fully integrated anti-fraud capability internally can take years. Many institutions face resource constraints, integration complexity, and aggressive timelines.

Clari5 helps banks accelerate that journey through a unified enterprise fraud management platform supporting real-time fraud detection, cross-channel monitoring, watchlist management, centralized investigations, behavioral intelligence, and fraud-AML collaboration. Typical deployment for a standard-scope implementation runs four to six months, though timelines vary based on integration complexity and data readiness.

Rather than treating detection, investigations, and intelligence sharing as separate initiatives, Clari5 connects them into a single operating environment. The result is faster detection, better analyst productivity, stronger customer protection, and a more scalable fraud prevention capability.

How prepared is your bank? 

We have developed a practical readiness assessment based on the five architectural decisions in this guide. In a 20-minute working session, we will help you identify likely implementation gaps, discuss proven operating models, and benchmark your approach against regional practices. Whether you choose Clari5 or not, you will leave with a clearer roadmap for building a resilient anti-fraud capability.

Beyond Identity: Why the Next Objective in Digital Onboarding Is Trust

Identity is a fact. Trust is a prediction.

For years, digital onboarding has treated verifying identity as the whole task. Banks have invested heavily in eKYC, document verification, facial biometrics, liveness detection, OCR, and digital signatures, and these technologies have made customer onboarding faster, more secure, and far more convenient. They have also answered one specific question well: is this person who they claim to be.

That question remains necessary, but it is no longer sufficient.

Genuine Identities, Fraudulent Outcomes

Across banking, fintech, and financial crime prevention, a pattern keeps repeating. A customer with a completely genuine identity becomes a money mule. A customer who passes every onboarding check goes on to commit first-party fraud. A legitimate, fully verified account becomes the destination for scam proceeds or the starting point of a money laundering network.

In each case, identity was never the problem, trust was.

Some of the most sophisticated financial crimes active today do not rely on fake identities at all. It relies on genuine identities used for fraudulent purposes, which is precisely what identity verification cannot catch.

Trust Cannot Be Verified Like Identity

By design, identity is confirmed through a document, a biometric match, or a database lookup. Trust does not work that way. It emerges from the convergence of several signals, and no single one of these is decisive on its own:

  • Device intelligence
  • Behavioral patterns
  • Network relationships
  • Historical risk indicators
  • Digital footprint
  • Transaction intent
  • Consistency across the customer journey

Together, these signals help build confidence in a customer relationship. Identity remains the foundation of onboarding. But identity tells an institution who a customer is. Trust tells it how likely that customer is to misuse the financial system.

A Trust Score Is Still a One-Time Check

Many institutions that have made this shift have done something specific: they added trust signals to the onboarding gate. That is real progress. It is also, on its own, an incomplete version of the shift.

A trust assessment calculated once is still a single decision made at a single moment. It simply uses richer inputs than a document scan did. The gate became smarter but it remains just a gate.

That distinction matters because trust, unlike identity, does not hold still. A customer who looks low risk on day one can look markedly different on day ninety. A dormant account can activate to move money for a mule network. A verified small business can begin receiving transfers that have nothing to do with the business it was onboarded for. None of these customers would necessarily fail a trust assessment run today. They would only fail a later run, which is the assessment most onboarding programs stop performing once the file closes.

A Shift Already Underway, Just Not Yet in Banking

This argument is not unique to banking. Gartner has described a similar shift in security and risk management more broadly, under a framework it calls Continuous Adaptive Risk and Trust Assessment, or CARTA. Its core premise – move away from a single, static, yes-or-no decision at the gate, toward continuous, real-time assessment of risk and trust for as long as the relationship lasts.

Security teams in other industries have been operating this way for close to a decade. Banking has made some real progress on the trust half of this shift but not enough on the continuous half.

What the Next Generation of Onboarding Looks Like

The next generation of onboarding is likely to look less like a gate and more like a standing assessment, one that draws on identity, behavior, device and network signals, and a customer’s conduct across every channel they use to interact with the institution, including conversations conducted by voice, not only forms filled in on a screen.

Some institutions are already asking a further question: whether this kind of ongoing trust assessment should be rebuilt from scratch inside every institution, or whether it can be run as a continuously managed capability, purpose-built for this problem.

The Objective Onboarding Has Not Yet Adopted

Identity verification will remain the foundation of onboarding. But foundations are not objectives.

The objective is no longer only to verify who a customer is. It is to make a better, continuously updated decision about whether that customer can be trusted, for as long as the relationship lasts. Because the costliest fraud is rarely the transaction an institution manages to stop. It is the customer it should never have onboarded, and then never asked about again.

FATF 5th Round: Market Access Now Depends on Outcomes, Not Documents

Early evidence shows how high the bar is, and why fraud and AML teams must align now.

Greylisting. Remediation roadmaps. Correspondent banking restrictions. The Financial Action Task Force (FATF)’s 5th Round of Mutual Evaluations is not a compliance checkbox, it is a market access test.

And early results show that performance under the effectiveness standard is where jurisdictions are falling short, not on documentation.

The distinction matters more than ever.

What Changed in the 5th Round

The FATF revised its assessment methodology in 2022 to measure one thing: whether AML/CFT frameworks produce measurable outcomes. Not documentation or compliance checklists but real-world results: investigations opened, financial intelligence acted upon, proceeds confiscated.

The February 2026 FATF paper, Cyber-Enabled Fraud: Digitalisation and Money Laundering, Terrorist Financing and Proliferation Financing Risks, made the operational shift explicit: 156 jurisdictions, 90 percent of those assessed, now classify fraud as a major money laundering risk. That classification carries a supervisory expectation: fraud controls must feed directly into AML obligations, including suspicious transaction report (STR) production, investigations, and asset recovery.

Institutions still running fraud and AML as separate silos can create a material gap between their country’s fraud risk profile and their actual operational response. That is exactly the misalignment 5th Round assessors are focused on.

The Bar: Higher Than Expected

Early 5th Round assessments show just how demanding the effectiveness standard is:

  • Singapore was upgraded to regular follow-up, its best result under FATF monitoring, yet four of eleven Immediate Outcomes were still rated only moderately effective. Among them was IO7 on money laundering investigations and prosecutions, where FATF directed a shift toward more complex, high-value cases. If a leading financial center carries that gap at its strongest result, few institutions on the schedule should assume they do not.
  • Malaysia, one of the first countries assessed under the new round, was flagged for difficulty translating money laundering investigations into prosecutions. Like every jurisdiction assessed under the 5th Round, it received a time-bound roadmap of recommended actions with three years to demonstrate progress.

For compliance heads in the region, the message is clear: the gap between deployed controls and controls that produce outcomes is no longer theoretical. It is now reflected in real ratings and commercial consequences.

The regional reminder is recent. In February 2026, Kuwait was added to the FATF list of jurisdictions under increased monitoring, following the action plan from its 2024 MENAFATF mutual evaluation. The listing cited gaps in suspicious transaction report effectiveness, beneficial ownership accuracy, and the pace of investigations into cross-border currency movements. For banks in GCC markets, greylisting introduces correspondent banking surcharges, extended settlement times, and reputational friction with foreign investors.

For banks in GCC markets, greylisting introduces correspondent banking surcharges, extended settlement times, and reputational friction with foreign investors. The cost is not just a compliance fine; it is operational resilience and market confidence.

Where the Gap Is Most Visible

Three Immediate Outcomes are where assessors will find the sharpest distinction between institutions that have invested in compliance architecture and institutions whose architecture generates measurable results.

Immediate Outcome 6: Financial Intelligence Usability: The metric is not STR filing volume. It is narrative quality, timeliness, and whether an investigator can act on the report without requesting additional context. Institutions relying on manual STR drafting face an inherent consistency problem: output depends on individual analyst skill and available time. Automated, audit-ready STR narrative generation at scale, coupled with plain-language alert explainability, is the approach aligned with what assessors now evaluate.

Immediate Outcome 7: Investigation and Prosecution Effectiveness: Assessors examine case resolution rates, network analysis depth, and whether institutions can identify and surface complex mule account clusters and layering schemes. The FATF cyber paper describes mule networks as a defining feature of modern fraud infrastructure. Detection tooling that surfaces behavioral context, connected entities, and historical precedent, enabling investigators to move from alert to case resolution without sacrificing depth, is operationally essential.

Immediate Outcome 8: Asset Recovery: Revised FATF standards now emphasize rapid payment-suspension and freezing mechanisms to prevent proceeds from being transferred abroad, alongside non-conviction-based confiscation regimes. Detection without interception does not contribute to confiscation outcomes. Real-time monitoring that enables intervention at the transaction level before proceeds leave the jurisdiction is now the standard.

The direction of travel in the GCC is already visible. The UAE’s National AML/CFT/CPF Committee reported in June 2026 that money laundering cases handled by law enforcement rose nearly 46 percent year on year, frozen assets reached AED 150 million, and FIU information requests increased 20.7 percent. These are the outcome numbers a jurisdiction points to when demonstrating IO8 effectiveness to assessors.

What This Means for Your Institution

The 5th Round assessment cycle is approximately six years. Coupled with time-bound roadmaps for addressing deficiencies, this means jurisdictions and their banking sectors will be in near-continuous evaluation mode through the end of the decade.

Institutions that align fraud and AML capabilities now, rather than optimizing for detection volume and documentation depth, will not just perform better under assessment. They will define the effectiveness benchmark against which their peers are measured.

The compliance era rewarded documentation. The effectiveness era rewards working systems that produce auditable outcomes at scale.

Is Your Institution FATF 5th Round Ready?

The assessment window is open now. Benchmark your institution’s readiness against Immediate Outcomes 6, 7, and 8 while you still have time to close gaps. 

Clari5 is a FRAML platform serving 60+ financial institutions across 30 countries. Our GenAI capabilities, spanning automated SAR/STR narrative generation, alert explainability, investigator co-pilot, and false positive reduction, are built around the effectiveness outcomes assessed under FATF 5th Round Mutual Evaluation methodology.

BNM Card PDs: One Platform for Malaysian Banks, Not Three Procurements

BNM’s three card policy documents introduce obligations across three deadline waves. Most Malaysian banks are treating them as three separate procurement tracks. The architecture decision is singular, not sequential.

The architecture decision behind the deadlines

BNM’s card PDs do not create three technology decisions for Malaysian banks. They create one architecture decision.

Malaysian issuers that treat real-time fraud detection, dispute workflow, card-not-present (CNP) authentication, and customer alerts as separate procurement tracks may meet each deadline individually. They will not meet the operating-model test BNM’s supervisor applies across the issuer.

The deadlines look sequential. The decision is singular.

The three policy documents for Debit, Credit, and Charge cards, covering conventional and Islamic variants, were issued by BNM on 19 December 2025. Their obligations land in three waves.

The first wave is already in force. Real-time fraud detection, mandatory kill switch on debit, default CNP and overseas opt-in blocking, and the liability shift provisions all activated immediately. Credit Card PD §26.1(d) sets the new standard: detection must operate in real time. Where losses arise from weaknesses in the issuer’s systems, processes, or controls, cardholder liability may be limited. BNM’s footnote example is unambiguous. A series of transactions within a short time frame, inconsistent with the customer’s normal transaction behavior, left unblocked, becomes the issuer’s exposure.

The second wave landed on 1 April 2026. Issuers now have three working days to acknowledge a card dispute, must issue a written decision, and on debit disputes, must extend provisional credit if investigation runs past 14 working days (RM 5,000 cap), with full disbursement by 30 days.

The third wave arrives on 1 January 2027. Strong customer authentication on every CNP transaction with SMS OTP capped at RM 250, secure device binding by default, cooling-off on new enrollment and contact detail changes, idle CNP re-blocking after 12 months, and expanded customer alerts covering every CNP transaction, every rejected CNP attempt, and every toggle activation.

These three waves usually engage three different internal functions and trigger three separate vendor evaluations. At audit, BNM reads them as one supervisory view.

The procurement trap

What I see consistently across deployments in India, Indonesia, the Philippines, and now Malaysia is a sequential reading of the PDs. Wave one is operational. Wave two is dispute workflow. Wave three is authentication and device. Each wave maps to a different internal function. Each function takes its slice to its preferred vendor.

The result is three procurement tracks running in parallel: three vendor evaluations, three contracts, three integrations, three audit trails reconciling to one supervisory view.

The cost is operational. When fraud detection, dispute investigation, customer alerting, and device intelligence sit on different stacks with different data formats, the bank spends investigator time on data reconciliation, not fraud analysis. An investigator opening a card dispute case routinely pivots through four or five systems before reaching a decision. Under the 3-working-day BNM acknowledgement clock, that pivoting time is the binding constraint, not the investigator’s analytical capability.

The trap is that the procurement decision feels rational at each step. Fraud buys detection. Card buys customer alerting. Risk buys device intelligence. Dispute buys case management. Each function gets what it asked for. The bank gets an architecture that BNM, at audit time, reads as one liability surface with multiple internal seams.

The dual-stack reality in Malaysia

For Malaysian Tier 1s, the procurement trap compounds with the conventional and Islamic banking duality. Most run parallel cards businesses across a conventional book and an Islamic subsidiary, often on different cards processors, with different rule sets, different investigation workflows, and different reporting lines into BNMLINK. Shariah governance overlays add an approval cycle to every rule change on the Islamic side.

From a technology-purchase view, this looks like two separate engagements. The conventional bank evaluates one stack, the Islamic subsidiary another. Vendors quote separately, deploy separately, run separate roadmaps.

From BNM’s supervisory view, it is one issuer-wide exposure. The 3-working-day dispute acknowledgement clock runs on the slowest side. The behavioral baseline asked for in audit has to be assemblable across both books. The customer alert channel cannot fragment per book if the customer holds cards across both.

This is not a Shariah question but an architecture one. Islamic-side governance can be preserved with one platform and dual-rule-policy management. Banks that try to preserve it by buying two platforms end up paying twice for the same compliance capability and running twice the integration work.

What integrated looks like

The architecture that holds across all three BNM card PD waves runs four functional layers on one platform.

  1. The detection layer operates pre-authorization. Every card transaction is scored in real time against behavioral baselines built from device, location, network, and transaction signals. Rules catch known patterns. Machine learning surfaces anomalies and behavior drift. The detection layer addresses Wave 1 and produces the evidence trail the dispute desk later relies on.
  2. The decide-and-investigate layer is the case management workflow. It opens a case file with detection rationale, customer history, and device evidence pre-assembled. The 14 and 30 working-day debit provisional credit triggers operate automatically. Generative AI investigator support compresses case investigation time, which is where post-April 2026 dispute volume math becomes tractable. This layer addresses Wave 2.
  3. The inform-customer layer handles transaction alerts and customer notifications across SMS, in-app, and voice channels. BNM’s anti-phishing constraints (no hyperlinks, no callback numbers) are built into the alerting template. The layer scales to Wave 3’s expanded scope.
  4. The learn-and-adapt layer feeds detection rules with channel-level intelligence the other layers cannot see. Voice analytics on call-center intake surfaces social engineering coaching patterns and mule recruitment scripts before they appear in transaction data. These patterns become new detection rules in the detection layer, closing the loop. This is what continuous improvement looks like under the BNM standard, and it is what allows the detection layer to keep pace with fraud typology drift between PD reviews.

That is one audit trail end-to-end. The same architecture handles the conventional book and the Islamic book under one operational model, with Shariah governance preserved at the rule-policy level rather than at the platform level.

The three BNM card PD deadlines are sequential. The architecture decision that meets them is singular. Banks scoping it as one platform decision will be in compliance position when the third deadline lands. Banks buying in three pieces will spend the next twelve months reconciling vendors instead of investigating fraud.

The deadlines are the regulator’s design. The operating model that meets them is the bank’s responsibility. Integrated platform thinking is how that operating model gets built.

 

Approach BNM card PD compliance as one platform decision with Clari5

The architecture described in this article is one Clari5 has built, deployed, and refined across Indian, APAC, and MENA banks, including environments running parallel conventional and Islamic banking books on different cores. Request a conversation with our solution team →

Voice Analytics: The Behavioral Layer Financial Crime Detection Has Been Missing

Voice analytics is the behavioral detection layer most banks already hold the raw material for. It sits inside the bank’s own call archive, in the 95 percent of recordings that go unanalyzed. 

 

Bank fraud detection runs on two layers today. Transaction monitoring catches what moves through the payment system. Digital behavioral analytics catches how customers click, swipe, and type. There is a third behavioral signal most banks have not yet operationalized: what customers say and how they say it during analyst calls.

The threat data tells a consistent story. Pindrop’s 2025 Voice Intelligence and Security Report tracked a 149 percent year-on-year increase in synthetic voice attacks against banks and a 1,300 percent surge in deepfake fraud attempts. UK Finance reports that 17 percent of authorized push payment fraud cases in the first half of 2025 began through telecommunications.

The conversation is no longer a customer service channel. It is a fraud surface, an investigation source, and a compliance record, all at once. Every recording already sits inside the bank’s environment. Voice analytics is the layer that can turn it into intelligence.

The behavioral intelligence layer most banks already own

Banks record every analyst-customer call as standard practice. Most do not analyze them. The industry benchmark is well documented across multiple call quality studies: traditional manual quality assurance reviews 2 to 5 percent of calls, which means 95 to 98 percent of recorded conversations are never analyzed for fraud, compliance, or investigation value. That is the gap.

Inside that gap sits evidence fraud teams cannot find elsewhere. The contact center carries fraud risk on both sides of the call: Coached mule scripts that surface long before the money moves, agent collusion, coercive language toward distressed customers, and regulatory disclosure failures that sampling cannot catch. Voice carries intent, coercion, scripted behavior, and repeat-caller patterns. None of it reaches a fraud system if the recording is never opened.

Analyzing every call rather than a sample changes what fraud teams can find. Detection no longer depends on what the agent flagged in the moment or what made it into the post-call notes. The recording is the evidence. 

What changes when every call is analyzed

Transactional fraud detection asks what happened in the payment. Digital identity analytics asks how the customer accessed the bank across devices and sessions. Voice analytics asks how the customer sounded, what they said, and what they did not. The three layers are complementary, each carrying intelligence the others cannot generate alone.

Capabilities that open up once the voice layer is in place include:

  1. Earlier detection of social engineering through stress patterns, urgency cues, and coached language captured inside the call recording.
  2. Mule network identification across calls, where voice biometrics link first-time-seen accounts to repeat caller voices, adding evidence at the voice layer that transaction-pattern analysis cannot generate on its own.
  3. Genuine-victim versus coached-mule distinction within a single call, through pitch, rate, pauses, emotion, and cooperation patterns across the two speakers.
  4. Faster case action on high-risk calls, where findings route directly into the case management workflow rather than sitting in a separate quality assurance silo.

Call recordings thus stop being archive material and become operational evidence. Voice analytics enable banks to consistently extract intelligence that is scored objectively and pushed into the same workflows where fraud and compliance teams already act.

The Clari5 Maestro fit

Clari5 Maestro Voice Analytics is built for this layer. It is a post-call forensics and audit platform that runs every analyst-customer call recording through an advanced eight-stage analytical pipeline combining machine learning, voice biometrics, and generative-AI-accelerated language understanding. Sentiment, intent, fraud indicators, compliance adherence, and conversation quality are extracted from each call and surfaced inside the bank’s existing case management workflow. Each call receives a composite risk score across voice, emotion, behavior, and fraud patterns, classified Low to Critical. Coverage is 100 percent. Languages are configurable to local market needs. 

Voice analytics is the third layer, and the one most banks already hold the raw material for. The recordings exist. The processing capacity is available. What is left is the decision to treat the call archive as evidence rather than overhead.

See how Clari5 Maestro applies to fraud and compliance operations at your bank. clari5.com/maestro

Cross-Border Card Fraud: Why Your Authentication Stops Protecting at the Border

Blog - Cross-Border Card Fraud

A structural reality that card issuers across the GCC, South Asia, Southeast Asia, and Africa are now confronting in operational terms: cross-border payment fraud is increasingly industrialized, with attackers deliberately routing transactions through jurisdictions where authentication standards are weakest.

A recent coordinated fraud attack on an Indian bank revealed how cross-border authentication asymmetry creates exposure for every issuer with internationally enabled card products, from forex and prepaid cards to cross-border credit and debit. This piece breaks down the attack pattern, maps who carries the exposure, and outlines what practitioners should be reviewing now.

Authentication asymmetry is the gap that opens when a card transaction routes through a jurisdiction whose authentication standard is weaker than the issuer’s home market. It is the structural vulnerability behind almost every coordinated cross-border card fraud attack in the past two years.

How protected is a card portfolio when customers transact abroad?

Your customers’ fraud exposure on international transactions is not determined by how robust your domestic authentication framework controls are. It is determined by the weakest authentication standard on the transaction route. The moment a card is used with a merchant in a jurisdiction that does not enforce the same standard you do, your domestic safeguards stop protecting. Earlier this year, a coordinated fraud attack proved exactly how it works.

The incident: A coordinated card fraud attack hit a bank’s internationally enabled card portfolio. In a five-hour window, fraudsters drained USD 280,000 across 15 merchants operating in a jurisdiction that does not mandate two-factor authentication for e-commerce. Around 5,000 cardholders were impacted before the bank’s monitoring systems contained the breach.

The bank’s systems did work, partially. They intercepted nearly 700 additional unauthorized attempts and prevented an estimated USD 100,000 in further losses. The breach was detected, contained, and followed by coordinated chargeback action. But the damage was already done before detection.

What made this attack different

Every element of the attack pointed to deliberate planning:

  • The fraudsters targeted specific Bank Identification Numbers (BINs), suggesting prior intelligence about the card program’s infrastructure. This kind of BIN-targeted attack pattern is increasingly common in industrialized card-not-present fraud.
  • Activity was concentrated across 15 merchants in a single geography, pointing to coordinated merchant-side infrastructure rather than scattered opportunism
  • The attack was timed during early morning hours (3:30 AM to 8:30 AM local time) to maximize automated system dependency and minimize the window for human intervention
  • There are reported indications of CVV compromise, raising open questions about where in the supply chain card data was exposed

The jurisdiction choice, the BIN targeting, the timing, the merchant concentration all indicate an industrialized operation built around a regulatory gap.

Who carries this exposure

If you are thinking “this is a forex card problem” or “this is a country-specific issue,” I would push back.

This exposure applies to any card product with international transaction capability: debit cards enabled for cross-border use, credit cards in international e-commerce, multi-currency prepaid cards, co-branded and partnership products, and any card-not-present flow that spans multiple jurisdictions.

The attack happened to target one bank’s forex card portfolio. The vulnerability it exploited exists in every internationally enabled card program I have seen.

Direct, regulatory, and trust costs of a cross-border card fraud incident

The USD 280,000 in direct losses is not the only number that keeps a business head up at night. The real cost is threefold:

  • Direct financial impact. Fraud losses, chargeback processing costs, and the operational expense of investigating, containing, and remediating across thousands of affected accounts. For a larger portfolio or a longer detection window, multiply the numbers from this incident accordingly.
  • Regulatory exposure. In the mentioned case, the central bank summoned senior bank officials for a detailed briefing on root cause, timeline, and cybersecurity adequacy. Supervisory scrutiny does not end with a single meeting. It triggers audit cycles, remediation mandates, and in some jurisdictions, public disclosure requirements. If your regulator is already tightening expectations around card security, an incident like this accelerates that pressure significantly.
  • Customer trust erosion. Cardholders who discover unauthorized international transactions on their accounts do not parse the technical distinction between a domestic control failure and a cross-border authentication gap. They see a bank that failed to protect them. For card products where customer acquisition cost is high and switching cost is low, the downstream attrition impact can far exceed the fraud loss itself.

How this plays out differently across regions

The underlying vulnerability, cross-border authentication asymmetry, is universal. But the risk profile varies by market.

In Southeast Asia, cross-border e-commerce volumes are growing significantly faster than the fraud frameworks designed to monitor them. Banks scaling international card products into new corridors are inheriting authentication gaps they may not have stress-tested yet.

Across African markets, the rapid expansion of mobile money and prepaid card ecosystems is extending international reach into corridors where cross-border fraud controls are still maturing. The co-branded and partnership card models common in these markets add a layer of distributed accountability that this incident specifically exploited.

In the Middle East, regulatory modernization is moving quickly, but authentication standards still vary significantly across jurisdictions within the region. Banks operating across multiple MENA markets carry exposure not just to external geographies but to asymmetries within their own regional footprint.

None of these are hypothetical concerns. They are the operating reality for card issuers in these markets today.

Three questions your board will ask after an incident like this

If a similar attack hits your portfolio, your board or risk committee will want answers to three questions. It is worth having them ready now:

What is our actual exposure on internationally enabled card products? Not the number of cards issued, but a clear view of which products, which corridors, and which destination geographies carry the highest authentication risk.

Have we tested our cross-border fraud controls against this specific attack pattern? Coordinated multi-merchant, BIN-targeted, off-hours, routed through a jurisdiction with no two-factor mandate. If your last fraud control review did not simulate this scenario, it left a gap.

What is our detection and response time if this hits during off-hours? The five-hour window in this incident was not a coincidence. It was the attack design. If your escalation framework depends on human intervention during those hours, that is a timing vulnerability your board should know about.

What issuers should be reviewing

From a practitioner’s standpoint, four areas deserve priority attention:

  1. Cross-border fraud ruleset adequacy. Do your current detection rules account for coordinated multi-merchant attacks routed through jurisdictions with weaker authentication? Most legacy rulesets were not built for this pattern.
  2. Portfolio-level exposure mapping. Which card products in your book have international transaction capability, and which destination geographies carry the highest authentication risk? If you do not have a clear answer, that is the gap.
  3. Off-hours monitoring calibration. Fraudsters deliberately target windows of reduced human oversight. If your detection framework relies on manual escalation during these hours, you have a timing vulnerability worth closing.
  4. Card-not-present controls by jurisdiction. A flat set of rules applied uniformly across all geographies will not catch attacks designed to exploit jurisdiction-specific weaknesses. Detection logic needs to be sensitive to where the transaction is being processed, not just where the cardholder sits.

The structural trend behind cross-border card fraud

The incident is a case study in how cross-border payment fraud is evolving. Fraudsters are not just finding technical vulnerabilities. They are finding regulatory ones, jurisdictions where the rules give them room to operate, and building industrialized attack frameworks around those gaps.

The question for every issuer is not whether this can happen to you. It is whether your fraud detection framework is built for the world where it will happen.

If you would like to pressure-test your current cross-border fraud controls against this attack pattern, let’s connect.

Person Not Present: What AI Agents Mean for Your Fraud Detection Stack


Every fraud detection system in production today is built on one assumption: a human being initiates the transaction. That assumption no longer holds true with AI agents now able to initiate real payments for customers, at scale.

Mastercard launched Agent Pay in partnership with Microsoft, Stripe, and Google. Google’s Agent Payments Protocol has over 60 institutional backers, including American Express, PayPal, and Coinbase. India launched the world’s first national pilot integrating UPI directly into ChatGPT. Without a customer touching their screen, their AI agent can pay for groceries, book a flight, compare insurance premiums, and renew a policy.

This is payments infrastructure being laid across the world’s largest economies. And it changes the fraud equation in ways the industry has not fully absorbed.

 

From card-not-present to person-not-present

For two decades, card-not-present (CNP) defined the dominant fraud category. The physical card was absent, but a human was still on the other end, confirming intent, entering credentials, completing the action.

Javelin Strategy & Research describes what is now replacing it: person-not-present. The human is no longer at the point of transaction at all. The AI agent is the front-line actor. The authorization is indirect, and the initiating logic is not human-readable.

The distinction matters because CNP was an evolution within an existing trust model. Person-not-present breaks the trust model itself. Every verification method, every risk score, and every fraud rule in the stack was designed to answer one question: “Is this the right person?” When no person is present, that question has no answer.

And this is not a distant scenario. Datos Insights projects that 82 percent of midsize to large financial institutions will deploy GenAI into banking and payments workflows by the end of 2026. The infrastructure for AI-initiated transactions is scaling. The framework for monitoring them does not yet exist.

 

Why the current detection stack will not catch it

Rules-based systems evaluate transactions against static thresholds: Is this amount unusual? Is this merchant new? Is this device recognized? These questions assume a human made a decision to transact. When an AI agent initiates a purchase within its pre-set parameters, the transaction will look normal. It may pass velocity checks, come from a recognized device, and still be fraudulent.

Authentication will not catch it as there is no person present to authenticate. Bot detection will not catch it since the agent is legitimate and was invited in. The challenge is no longer separating bots from humans. It is separating legitimate agents from compromised ones that behave identically.

Consider what is no longer an edge case: a compromised agent redirected to transact with a fraudulent merchant. An agent exploited through prompt injection, executing transactions the customer never intended. An agent operating outside its authorized scope, where liability frameworks have not been written yet. Gartner projects that over 50 percent of successful attacks against AI agents will exploit access control issues using prompt injection through 2029.

 

The behavioral intelligence question

When the transaction initiator is not human, point-of-authentication controls lose their explanatory power. The question “Is this the right person?” becomes irrelevant. What replaces it is a different question entirely: “Does this action reflect the customer’s intent?”

That is a behavioral intelligence question. Answering it requires detection infrastructure built to evaluate patterns, sequences, and intent across the full session, not just the authentication moment.

This means analyzing how a session unfolds over time: Whether

  1. the sequence of events leading to a payment reflects genuine intent or manipulation
  2. an agent-initiated transaction aligns with the customer’s historical patterns of engagement
  3. the agent itself is operating within the boundaries the customer established.

Financial institutions that have invested in cross-channel behavioral monitoring are structurally better positioned for this shift than those relying on authentication-centric or rules-based models. The detection paradigm does not need to determine whether the actor is human or machine. It needs to determine whether the action is consistent with the customer’s intent. That distinction is what separates institutions that will detect agent-driven fraud from those that will discover it after settlement.

 

What this looks like in practice

Consider a retail banking customer who has used their account in a consistent pattern for three years: salary credits on the 28th, rent and utilities in the first week of the month, grocery purchases from two or three familiar merchants, and occasional travel bookings planned days in advance with browsing activity preceding the purchase.

The customer enables an AI shopping assistant. The agent is legitimate, authorized, and operating from a recognized device. Within its first week of activity, it initiates a high-value electronics purchase from a merchant the customer has never transacted with, in a product category with no historical precedent, and at a time that is inconsistent with the customer’s established transaction patterns.

A rules engine will see a valid payment within approved limits. Authentication is not triggered because the agent is operating under existing credentials. Bot detection is not triggered because the agent is not a bot. It is an authorized tool. But behavioral intelligence will see something different.

Behavioral intelligence will see a transaction that breaks the customer’s established pattern of engagement across multiple dimensions simultaneously: merchant category, transaction value, timing, and the absence of the browsing-then-purchasing sequence that has preceded every similar transaction in the customer’s history. That cluster of deviations, evaluated together and in real time, will generate the risk signal.

The agent may have been compromised through prompt injection. It may have been redirected to a fraudulent merchant optimized to look legitimate to automated tools. Or it may simply be the customer trying something new. Behavioral intelligence does not need to know the cause to flag the anomaly. It needs to surface the deviation from intent so the institution can act before settlement, not after.

 

The liability gap no one has closed

When a customer taps ‘Buy’, liability frameworks are well-established. This is not true when the customer’s AI agent does it.

OpenAI’s developer documentation places payment liability on merchants and their payment service providers. Google’s A2P Protocol introduces cryptographically signed mandates to create audit trails. Visa is tokenizing agent credentials with spending controls. Everyone is drawing lines, but no one knows where the boundaries will settle.

Javelin’s payments analysts put it plainly: the players involved are keenly aware of what is at stake, but the liability questions remain open. For financial institutions, that uncertainty is not a reason to wait. It is the reason to ensure that the detection infrastructure can distinguish between a legitimate agent acting on verified intent and an agent that has been manipulated, before the settlement window closes.

 

The question that matters now

When the AI layer your institution deployed to improve customer experience becomes the vector through which fraud enters your system, what in your current detection stack will catch it?

Gartner projects that 25 percent of enterprise breaches will trace to AI agent abuse by 2028. The institutions answering that question now will not be reacting to the next wave of agent-driven fraud; they will have already built for it.

Clari5 at Anti-Money Laundering Conference Dubai 2026

At AMLC 3.0, the 3rd Annual Anti-Money Laundering & Compliance Conference, Clari5 joins regulators, banks, fintechs, and policy makers from across the MENA region to explore how real-time intelligence is reshaping financial crime prevention and regulatory compliance.

Hosted at the DoubleTree by Hilton Dubai M Square Hotel & Residences, the conference convenes stakeholders from financial institutions, payment providers, DNFBPs, crypto firms, e-commerce players, and government agencies to address the growing impact of economically motivated crime.

Clari5 will engage with AML, compliance, and risk leaders on how enterprise-wide, real-time intelligence can help institutions:

  • Detect and prevent fraud and money laundering before financial or reputational impact
  • Strengthen AML operations with contextual, cross-channel monitoring and a unified view of customer risk
  • Achieve regulatory compliance through explainable, auditable decisioning aligned with evolving MENA and global standards
  • Enable better collaboration between policy, supervision, and technology teams through integrated analytics and case management

Meet the Clari5 team at AMLC 3.0 to explore how our real-time financial crime management platform can help your institution stay ahead of emerging threats while improving compliance efficiency.

Drop an email to connect@clari5.com

How UAE’s New AML Rules Change the Game for Financial Institutions

Entering 2026, the UAE’s financial sector is operating under a fundamentally different regulatory and market dynamic. The UAE’s exit from the FATF grey list, removal from the EU’s high-risk jurisdiction list, and AED 350 million in recent AML enforcement fines mark a decisive shift. The direction of travel is clear: enforcement is real, scrutiny is targeted, and differentiation has begun. Under Federal Decree-Law No. 10 of 2025, regulators are focused on demonstrable effectiveness rather than formal compliance. As FATF’s 2026 mutual evaluation approaches in June, institutions with mature AML capabilities, evidenced through effective transaction monitoring, timely escalation, and high-quality suspicious transaction reporting, will benefit from faster market access, improved cross border flows, stronger correspondent relationships and participation in regional and international growth opportunities. Those unable to evidence effectiveness face increased operational friction, regulatory attention, and strategic constraints. What the Fines Tell Us Recent enforcement action by the Central Bank in 2025 makes regulatory priorities unmistakable. It signals that regulators are focusing less on formal compliance frameworks and more on whether controls work in practice. Institutions with fragmented monitoring, weak escalation, or poor governance are under pressure. Those with demonstrably mature AML operations are increasingly differentiated by both regulators and counterparties. The New Rules: What Changed and Why It Matters Federal Decree-Law No. 10 of 2025, effective 14 October 2025, is not just another regulatory update. It is the enforcement mechanism behind the fines we have already seen and the framework that will determine which banks get access to the opportunities ahead. Lower Prosecution Threshold: The law no longer requires authorities to prove “actual knowledge” of criminal intent. Banks can now be held liable if they “should have known” based on circumstantial evidence. Extended Enforcement Powers: The Financial Intelligence Unit can now freeze funds for up to 30 days (up from 7) and suspend transactions for 10 working days without notice. For banks with weak screening systems or slow escalation processes, this means operational disruption. For those with automated controls and clear escalation protocols, it means being able to demonstrate rapid response capability. Personal Liability for Senior Management: Senior managers and directors can now face personal criminal liability, from fines to imprisonment, if violations occur due to breach of duty or known negligence. Corporate fines have doubled to a range of AED 5 million to AED 100 million. Expanded Scope: The law now criminalizes Proliferation Financing as a standalone offense, directly regulates Virtual Asset Service Providers (VASPs), and explicitly includes tax evasion as a predicate offense. Banks that have already integrated sanctions screening for proliferation risk and built VASP monitoring frameworks have a structural advantage. What This Means in Practice For Banks For banks, AML maturity is now directly linked to speed, access, and credibility. Banks with integrated monitoring systems, strong model governance, and clear escalation timelines will find cross-border transactions moving faster and relationships easier to maintain. Those that cannot evidence effectiveness may experience quiet friction — slower onboarding, enhanced reviews, and reduced appetite — even without formal regulatory action. In this environment, AML is no longer a defensive function. It is an enabler of market access. For Exchange Houses Exchange houses sit at the sharpest edge of enforcement risk. The scale and concentration of recent penalties indicate heightened regulatory sensitivity to cash-intensive activity, remittance corridors, and frontline control failures. For exchange houses, the issue is not just whether controls exist, but whether they scale with volume and velocity. For VASPs For VASPs, the regulatory transition is now explicit. They are expected to demonstrate the same seriousness of intent as traditional financial institutions — including transaction monitoring calibrated to blockchain risk typologies, sanctions screening, and meaningful STR engagement. FATF 2026: The Evidence Test All of this leads to a clear milestone. The FATF’s 5th Round Mutual Evaluation of the UAE is scheduled for June 2026. The methodology prioritizes effectiveness over form. Assessors will ask whether laws produce outcomes: investigations, convictions, asset recovery, and high-quality financial intelligence. Banks, exchange houses, and VASPs will collectively form the UAE’s evidence base. The Strategic Question For regulated institutions in the UAE, the strategic question has shifted. It is no longer whether an institution can pass an audit. It is whether its AML framework produces evidence that regulators can rely on and counterparties can trust. For leadership teams, now is an appropriate moment to step back and ask a simple question: If our AML framework were tested tomorrow, would it speak for itself? That reflection, more than any single regulatory deadline, is what will shape market access in the years ahead.

RBI Advisory on Real-Time NCRP API Integration: What Indian Banks Need to Know

The Regulatory Context
RBI’s latest advisory to all banks in India on integrating with the National Cyber Crime Reporting Portal (NCRP) for real-time complaint handling is unambiguous. Banks that have not completed onboarding must do so “without further delay” and treat this as “highest priority.”

The advisory also directs all banks, including those already on the portal, to complete API-based integration for real-time action on complaints. The integration must cover all systems and delivery channels. Performance must be reviewed periodically.

The message is clear; manual processing is no longer sufficient. Real-time response is now the expectation.

 

The Challenge
India’s instant payment infrastructure is a remarkable achievement. But speed cuts both ways. When fraud succeeds, funds can move through multiple banks, mule accounts, and exit channels within 30 minutes.

Still most banks process NCRP complaints through manual workflows. This made sense when volumes were lower. But as digital transactions scale and fraud patterns evolve, the gap between how fast money moves and how fast banks can respond is widening.

The goal now is to close that gap. When a complaint lands on NCRP, the response should be immediate: lien marked, freeze triggered, investigation initiated. This is the Golden Hour standard.

 

We Started This Journey Early
At Clari5, we recognised the importance of real-time NCRP integration before the regulatory push. In 2024, we partnered with Punjab National Bank to build India’s first national-scale implementation. Serving 180 million customers across 10,000 branches; PNB needed a system that could match the speed of the threat.

The Clari5 Cybercrime Complaints Processing Platform (CCCP) delivered:

  • Resolution time reduced from days to within the Golden Hour
  • Thousands of complaints processed daily without slowdowns
  • Full automation from 1930 Helpline intake to resolution
  • Complete alignment with RBI, DFS, and I4C requirements

We did not stop there. Since PNB, we have extended real-time NCRP API integration to more banks across India. Each implementation has sharpened our understanding of what works at scale.

 

Why Automation Matters
The benefits go beyond compliance.

Speed. When complaints resolve in the Golden Hour instead of days, funds have a better chance of recovery. Customers see the difference.

Focus. Automation handles the volume. Your investigators get to do real investigative work: pattern analysis, mule network mapping, regulatory coordination.

Confidence. When RBI reviews your fraud response capability, a working system speaks louder than a roadmap.

 

What This Means for Your Bank
Regardless of size, every bank faces the same question: can we respond in real time?

This does not require a multi-year transformation. We have helped banks go live under 30 days. The platform scales alike from regional players to institutions.

Nearly two decades of building fraud systems for Indian banks taught us one thing. The only defense that works is one that moves as fast as the attack. We have done this more than anyone else in this space, and we are ready to help you get there.

 

Looking Ahead
Regulatory expectations are only going to increase. Banks that move early will have time to refine their systems. Those that wait will find themselves under pressure.

Clari5 & PNB chose to be the Pioneers, we chose to lead. The playbook is proven. The technology is production-ready.

If you are evaluating your options, we would welcome the conversation. Schedule a demo.