Fraud prevention at a bank is not one program. It is a set of controls spread across deposit operations, lending, payments, information security, and human resources, and the losses concentrate wherever those functions hand off to each other without anyone owning the seam.
This guide maps the whole landscape — what the categories are, where money actually leaves, what controls work, and how to structure a response.
Fraud against banks divides into four groups that behave differently and require different controls.
Payment fraud — the fraudulent movement of money through checks, wires, ACH, or cards. Highest volume, and the category where the loss allocation rules matter most, because who absorbs a loss depends on the rail.
Account fraud — account takeover, new account fraud using stolen or fabricated identities, and money mule accounts opened to receive proceeds. This category has grown fastest, because credential compromise scaled and account opening moved online.
Lending fraud — falsified income or employment, straw borrowers, occupancy misrepresentation, collateral that does not exist or is pledged twice, and appraisal manipulation. Losses are large per event and surface late.
Internal fraud — employee theft, unauthorized transactions, false entries, and collusion with outsiders. Lowest frequency, highest per-event loss, and longest duration before discovery.
A useful way to hold these in mind: payment fraud is fast and bounded, account fraud is a volume problem, lending fraud is a credit problem wearing a fraud costume, and internal fraud is a control environment problem.
Three observations that shape where to spend.
The perimeter is not the branch. Most fraud now arrives through channels — online account opening, digital banking, call centers, and payment initiation — rather than across the counter. Institutions with strong branch procedures and weak call center authentication are defending a door nobody uses.
The customer is the attack surface. A large share of losses involve a customer who was deceived into acting: authorizing a payment, sharing a credential, or providing a one-time passcode. No amount of bank-side authentication stops a transaction the customer was persuaded to initiate, which is why customer education and out-of-band verification are controls rather than courtesies.
The seam between functions is where things fail. A wire released because operations assumed the relationship manager verified it. A new account opened because onboarding assumed screening would catch it. A loan funded because processing assumed underwriting reviewed the document. Fraud finds handoffs.
No single control stops fraud. The workable model is layers, each catching what the previous missed.
This is the single most important operational fact in fraud, and staff should know it cold.
Consumer electronic fund transfers fall under Regulation E, with consumer liability capped by tiered timeframes for unauthorized transfers — but a transfer the consumer was induced to make is generally authorized, and the protection does not apply.
Wires are governed by UCC Article 4A and are final on acceptance. If the payment order was authenticated under a commercially reasonable security procedure the customer agreed to, the loss generally stays with the customer. There is no chargeback.
Checks turn on UCC rules about ordinary care, alteration, forgery, and the customer's duty to examine statements and report promptly.
Business ACH debits carry a return window measured in banking days, not the sixty days consumers get.
Cards are governed by network rules layered on Reg E for consumer accounts, with chargeback rights that other rails lack.
The practical consequence: the same fraud on two different rails allocates the loss to two different parties. Explaining this to business customers before they experience it is what makes positive pay and callback verification sell.
Technology detects patterns. People detect wrongness. The institutions that catch fraud early are the ones where the teller who thinks a customer seems coached, or the analyst who notices a colleague's unusual activity, actually says something.
Four things determine whether that happens:
A frictionless referral path. If reporting a concern requires a form and a conversation with a supervisor, referrals approach zero.
No penalty for being wrong. Most referrals turn out to be nothing. If being wrong is embarrassing, staff stop referring, and the institution loses its best sensor.
Feedback. Staff who never learn what happened to their referral stop making them. A short note back — even "reviewed, no action" — sustains the channel.
Visible senior attention. Fraud losses discussed at management meetings, and control failures treated as organizational problems rather than individual ones.
An institution with a functioning fraud program can answer these questions with data:
Institutions that cannot answer these are managing fraud anecdotally, which usually means over-investing where the last loss occurred and under-investing everywhere else.
Structured coverage is available through our bank fraud prevention training, the Certificate in Fraud Prevention, Fraud Examination, and Financial Crimes Red Flags Training.
Fraud spending is chronically misallocated, because it is usually decided in the aftermath of a specific loss rather than against the distribution of expected losses. A structured approach answers three questions before anything is purchased.
What is the expected annual loss by category, and what is the tail? Payment fraud tends to be frequent and individually small — predictable enough to budget as a cost of doing business. Internal fraud and large-dollar wire fraud are infrequent and severe, which makes them a capital and reputational question rather than a run-rate one. Controls that reduce a predictable, bounded loss deserve a straightforward cost-benefit test. Controls that reduce a rare catastrophic loss deserve to be evaluated the way insurance is.
What does the control actually prevent, and what does it merely detect? Detection after settlement has real value — it stops the second event and supports recovery — but it does not prevent the first loss. Institutions frequently buy detection and describe it internally as prevention, then are surprised that losses did not fall.
What is the friction cost? Every control imposes cost on legitimate customers: declined transactions, additional verification steps, delayed payments, abandoned account openings. That cost is real and is rarely measured, which biases decisions toward adding controls indefinitely. A control that prevents $40,000 of annual loss while driving away more than that in customer relationships is a bad trade that no fraud report will show.
The output worth producing annually is a simple matrix: each significant control, what it prevents or detects, its cost, its friction, and the loss experience in the area it covers. Institutions that build it usually find two things — a control everyone assumes is working that has never actually stopped anything measurable, and an exposure with no meaningful control at all because no loss has yet occurred there.
That second finding is the important one. Fraud programs shaped entirely by past losses are, by construction, defending against last year's attack.
Institutions frequently combine these functions, particularly at community scale, and the combination works — provided the differences are understood.
Fraud management protects the institution and its customers from loss. Its measure of success is dollars not lost, and its orientation is prevention.
BSA/AML protects the financial system by generating reports investigators can use. Its measure of success is the quality and timeliness of filings, and its orientation is detection and reporting.
The overlap is genuine: fraud is a specified unlawful activity, so fraudulent activity frequently requires a SAR, and monitoring systems often serve both purposes. But the objectives diverge in specific situations that staff need to recognize. Exiting a customer relationship may be the right fraud decision and the wrong BSA decision, because law enforcement may prefer visibility maintained. Recovering funds quickly may conflict with preserving evidence. And a fraud investigation closed because the loss was recovered still requires a SAR assessment on its own standard.
The practical arrangement that works is shared detection with separate decisioning: one monitoring capability feeding two review processes, each applying its own standard, with a documented handoff. What does not work is treating a SAR filing as the conclusion of a fraud case, or treating loss recovery as satisfying the reporting obligation.
Payment fraud involving checks, wires, ACH, and cards; account fraud including takeover, new account fraud, and mule accounts; lending fraud such as falsified income, straw borrowers, and collateral misrepresentation; and internal fraud committed by employees. Each behaves differently — payment fraud is high volume and fast, internal fraud is low frequency with high per-event loss and long duration before discovery.
It depends on the payment rail. Consumer electronic transfers fall under Reg E with tiered liability caps for unauthorized transfers, though transfers the consumer was induced to make are generally treated as authorized. Wires are final under UCC Article 4A when properly authenticated. Checks turn on ordinary care and timely examination of statements. Business ACH debits have a return window of banking days rather than the sixty days consumers receive.
Out-of-band verification for any change to payment instructions — calling a known number on file rather than one supplied in the request. It addresses business email compromise, vendor impersonation, and most social engineering directed at payment initiation, which together account for a disproportionate share of large-dollar losses.
Through segregation of duties, dual control, mandatory absence or job rotation for sensitive positions, exception reporting reviewed independently, and monitored system access. Mandatory vacation is unusually effective because many long-running internal schemes require daily maintenance by the perpetrator to remain concealed.
No. Fraud management protects the institution and its customers from loss; BSA/AML generates reports useful to investigators. They overlap because fraud is a specified unlawful activity that frequently requires a SAR, and monitoring systems often serve both. But the objectives diverge — exiting a customer may be the right fraud decision and the wrong BSA one.
With a frictionless referral path, no penalty for referrals that turn out to be nothing, feedback on what happened, and visible senior attention to fraud losses. The front line remains the most productive detection channel in most institutions, and referral volume collapses when reporting is inconvenient or when being wrong is embarrassing.


