Fraud prevention has largely been treated as an institution-by-institution exercise. Banks built their own models, payment companies and vendors developed proprietary services and solutions.
The latest guidance from the Financial Crimes Enforcement Network (FinCEN) suggests there’s strength in numbers, so to speak, and collaboration among these stakeholders.
In updating its guidance on Section 314(b) of the USA PATRIOT Act, FinCEN wrote that it “strongly encourages financial institutions to participate in the program as information sharing between and among financial institutions can assist financial institutions in managing illicit financing risks and can ultimately provide the government with highly useful information to identify and prevent financial crime.”
The agency also said the program gives institutions “the flexibility and connectivity needed to counter these threats and prevent bad actors from exploiting gaps between institutions.”
The timing is likely fortuitous.
According to the PYMNTS Intelligence report, “State of Fraud and Financial Crime in the United States,” done in collaboration with Block, unauthorized-party fraud now accounts for 71% of fraud incidents and dollar losses, reversing last year’s pattern and illustrating how credential theft and account takeover have become the dominant challenge facing financial institutions. Fraudsters increasingly move across institutions rather than remaining confined to one, making isolated defenses less effective.
Banks are spending heavily to keep pace. The PYMNTS report found 68% of financial institutions increased fraud-detection spending over the past year, while 46% cited increasing fraud sophistication as one of their primary challenges. At the same time, 47% pointed to sanctions compliance pressures, 46% cited the increasing speed of payments and 41% highlighted the expansion of payment types and currencies as additional complications confronting fraud teams.
When Expertise Travels Further
The most important aspect of FinCEN’s guidance may lie with the breadth of information that regulators now explicitly recognize as appropriate for exchange.
The agency states that participating institutions may share transaction information, video surveillance, cyber-related data such as IP addresses and geolocations, device identification numbers, transaction monitoring alerts and indicators that activity may be suspicious, including newly added payees followed by large transfers or geographically distant login activity.
That list closely mirrors the kinds of signals developed by specialist fraud providers.
A company devoted to device intelligence sees relationships that transaction monitoring may miss. Behavioral analytics firms examine typing cadence, navigation patterns and session characteristics that distinguish legitimate customers from imposters. Network intelligence providers identify connections among accounts and entities that appear unrelated when viewed individually.
FinCEN is not endorsing any particular provider or technology. It is, however, recognizing that these different forms of intelligence can help identify money laundering and fraud when shared among participating institutions. And as a result, the value proposition of specialization is sharpened.
institutions can benefit from organizations that spend years refining expertise in a single area. Device specialists become more useful when their observations help multiple institutions identify compromised hardware. Behavioral specialists become more valuable when suspicious patterns observed at one institution can inform decisions elsewhere. Network analysts gain leverage when relationships uncovered in one investigation contribute to broader detection efforts.
The consortium approach thus receives a meaningful endorsement from Washington without requiring institutions to abandon their own controls.
The PYMNTS data underscores why collaboration may become increasingly attractive. Half of financial institutions reported that fraud has negatively affected customer loyalty, 48% said it has cost them new business opportunities and 44% cited damage to their brand and reputation. Fraud is no longer simply a loss item on a balance sheet. It has become a customer-retention problem.
Institutions also continue to face practical barriers to modernization, which gives the nod toward partnerships and specialization. Fifty-three percent identified higher data-management costs associated with new technology systems as an obstacle to innovation, 52% cited competing priorities and 47% reported difficulties integrating new solutions into existing infrastructure. Those challenges make it difficult for any organization to excel equally across every fraud discipline.
The response has been greater reliance on adaptive technology. According to the report, 95% of financial institutions now use behavioral analytics and 89% use machine learning, indicating that intelligent systems have largely moved from experimental projects into mainstream fraud operations. Yet even those tools benefit from broader visibility into attack patterns.
FinCEN’s guidance also extends beyond completed fraud. The agency says institutions may share information concerning attempted transactions and attempted schemes, including money mule activity, allowing participants to intervene before losses occur instead of documenting them afterward.
None of this diminishes the importance of internal controls, customer authentication or investigative teams. Institutions must still protect confidential information, maintain appropriate safeguards and comply with longstanding restrictions surrounding Suspicious Activity Reports.
What has changed is the recognition that no institution possesses a complete picture of today’s fraud landscape. Defenders should respond with greater coordination of their own. If that philosophy gains momentum, the biggest competitive advantage may belong to firms that know one fraud vector exceptionally well and can contribute that expertise to a much broader defensive, collaborative network.