Fraud Monitoring: A Complete Guide for Financial Institutions

Fraud monitoring is the continuous, real-time review of transactions, devices and behavioral signals to identify activity that may indicate theft, scams, account compromise or other unauthorized financial activity, and leads to taking action before the money leaves. It combines rule logic, behavioral analytics and risk scoring into a single decision layer that approves, holds or blocks events in milliseconds, routing anything that needs investigating into a case management workflow.

It is not the same thing as fraud prevention or fraud detection, the three are often used interchangeably. Fraud prevention is the discipline of the controls (strong authentication, payee verification, transaction limits, customer education) that prevent fraud from happening in the first place. Fraud detection is the point of recognition. It is realizing that a particular event is or may be fraudulent. Fraud monitoring is the continuous process of detection. The live fraud monitoring pipeline observes every transaction, every login, every device, every change in behavior all the time, and produces the alerts that detection acts on. Prevention makes the rules of the road; monitoring is the patrol that runs constantly as traffic moves.

In this guide, we’ll cover what fraud monitoring is, how it works, what it needs to capture, the data that defines its scale and the U.S. regulatory framework it now operates inside.

  • Fraud Monitoring vs AML Transaction Monitoring
  • How Does Fraud Monitoring Work?
  • Fraud Types It Must Catch
  • Fraud Monitoring Statistics
  • Real-Time Fraud Monitoring & Modern Payment Rails
  • Internal Fraud vs External Fraud
  • The Role of AI in Fraud Monitoring
  • US Fraud Monitoring Regulation: BSA, SARs, and the Nacha 2026 Rule
  • How Sanction Scanner Helps in Fraud Monitoring

Support 20260720160445 3868

Fraud Monitoring vs AML Transaction Monitoring

Both fraud monitoring and AML transaction monitoring are data and tooling driven, but they answer different questions. Fraud monitoring prevents direct theft and scam losses to customers and to the institution. It helps with the institution’s measure of success: Loss avoided and recovery speed. AML transaction monitoring is used to detect the movement of illicit proceeds through the financial system for regulatory reporting purposes, and the success metric is the quality of investigation and timeliness of SAR filings. Both processes work with the same data, and often with the same customer, but produce different red flags, different timelines, and different downstream outcomes.

How Does Fraud Monitoring Work?

The pipeline that creates a fraud decision runs in a defined sequence. Understanding the sequence is the basis of everything that follows.

Inputs of data. The system ingests all the signals that the institution can feed it: The transaction itself (amount, channel, beneficiary, geography, time), device intelligence (fingerprint, browser, OS, jailbreak status), behavioral signals (session navigation, cadence of typing, swipe patterns) and the customer profile (KYC data, historical baseline, risk score, account age, product mix). The range of inputs sets the ceiling to detection, which is made up of a monitoring system that can only see transaction fields. It can't catch fraud that only manifests in device or behavioral anomalies.

Behavioral analytics and rules. Detection layer uses two complementary logic types. Rules capture known patterns (velocity breaches, geo mismatches, strange beneficiary, round number anomalies) in deterministic “if-then” form. Behavioral analytics learns what the customer’s baseline looks like and flags deviations from it, catching the things rules can’t articulate ahead of time. Rules offer explainability, and behavioral models offer flexibility. A mature monitoring system uses both.

Real time risk scores. The detection logic and inputs are combined into a single risk score for the event in question, generated in milliseconds. The score considers the static customer risk rating, the dynamic event signals and any cross stream context (open AML alerts, recent fraud history, network ties to other suspicious accounts). The decision is dictated by the score, not by any one rule.

Generation of alerts. If the score and rule outputs exceed defined thresholds, the system will either act directly, such as blocking the transaction, stepping up authentication, or holding the wire, or generate an alert into the case management queue. Auto decisioning handles the unambiguous cases at machine speed; the ambiguous cases are sent to analysts with the full event context attached.

Case management and disposition. Each alert has a case with a disposition path: Confirm fraud, release as false positive, escalate, refer to law enforcement, file a SAR where the activity is also AML reportable. Disposition closes the loop. Confirmed cases feedback into model training, rule calibration, and the customer’s risk profile, so the next decision is better than the last.

Support 20260720160000 8064

Types of Fraud It Must Catch

Fraud monitoring is not a single typology issue. It’s a portfolio of different frauds, each with its own signals, its own playbook. The big ones are:

Check fraud. For all the chatter about checks being dead, check fraud remains one of the most reported types of fraud in the United States, and FinCEN advisories continue to sound alarms about growing volumes in mail theft driven check fraud schemes. Odd endorsements, washed checks, rapid deposits and withdrawals and mismatches of beneficiaries are monitored.

Wire fraud. Wire and ACH transactions are high on the list of reported fraud losses in the FBI’s 2024 IC3 data, driven primarily by business email compromise (BEC) and social engineering scams. Wires are high value and fast and have traditionally been difficult to reverse. Real time monitoring at the time of authorization is the only meaningful defense.

ACH fraud. Automated Clearing House abuse includes unauthorized debits and the credit push frauds that have become the focus of regulator attention. The Nacha 2026 fraud monitoring rule, discussed in detail below, has raised the compliance baseline for every party in the ACH chain.

Business Email Compromise (BEC). The IC3 report showed BEC losses totaled $2.77 billion across 21,442 reported incidents in 2024, the second highest dollar category. The attack is low tech and high yield: Fake or hijacked email accounts redirect real payments to the attacker’s locations. It catches it in monitoring through payee change anomalies, urgency markers and out of pattern wire instructions.

Account takeover fraud. Attackers can hijack accounts as the legitimate customer through compromised credentials, session hijacking, and SIM swap attacks. Monitoring is based on device intelligence, behavioral biometrics and session anomalies, because the credentials check out and the transaction profile is the only remaining tell tale.

Synthetic identity fraud, which the Federal Reserve has reported as the fastest-growing financial crime in the US, uses real Social Security numbers combined with fabricated names and details to create identities that pass onboarding and build credit before busting out. It was the fastest-growing digital fraud type by volume from the second half of 2023 to the first half of 2024, up 153% according to TransUnion, and US lender exposure to synthetic identities reached a record $3.3 billion at the end of 2024.

Credit card fraud. Card not present fraud, BIN attacks and card data abuse remain a multi billion dollar global loss category, with instant payment rails compressing the window for detection and reversal. It monitors issuer side authorization speed runs against velocity, merchant category and device signals.

Money mule activity. Every successful fraud scheme needs an exit account. That account is owned by a money mule. Mule detection is on the fraud AML seam: The receiving institution sees what looks like a normal customer getting paid and it's only the network and behavioral analysis that uncovers the cluster.

Authorized push payments fraud. APP fraud, where a customer is duped into authorising a payment, has become the most prevalent scam typology across a number of markets. The costliest APP variant in the US is investment fraud which was the most expensive type of IC3 in 2024, costing $6.57 billion, with cryptocurrency investment fraud (“pig butchering”) alone making up $5.8 billion. The pattern is social engineering, often takes weeks, and ends in a payment the customer themselves have approved.

AI and deepfake scams. Voice-cloned execs authorizing wires, deepfake liveness defeat at onboarding, AI generated synthetic media at scale, the attacker toolkit has materially changed since 2023. Monitoring must evolve with it.

Fraud Monitoring Statistics

The scale of the problem that fraud monitoring seeks to address is now measured in tens of billions of dollars per year, and the latest authoritative U.S. data set leaves no doubt as to where this is headed.

In 2024, the FBI’s Internet Crime Complaint Center (IC3) said there was a new high for reported losses. It received 859,532 complaints with $16.6 billion in losses, a 33% increase from 2023. Cyber enabled fraud accounted for nearly 83 percent of all losses reported to IC3 in 2024, with $13.7 billion in losses and 333,981 complaints. All scam types combined, elder fraud losses reported in 2024 totaled $4.9 billion, a 43% increase over 2023. The 60 plus demographic represented the most complaints, with 147,127 reports, and the highest losses of any demographic. Cryptocurrency related losses totaled $9.3 billion across 149,686 complaints, a 66% increase year over year.

The industry trajectory response is equally clear, beside the IC3 picture. According to independent industry research, 93% of U.S. mid-market banks are pursuing or plan to pursue convergence of their AML and fraud programs due to potential for significant cost savings, increased accuracy of detection and stronger regulatory alignment. The convergence trend matters because it is the manifestation in the operating model of what the data is telling us: Fraud and money laundering are increasingly the same operation seen from two sides and the institutions fighting them are aligning their detection accordingly.

Real-Time Fraud Monitoring & Modern Payment Rails

The transition to instant payment rails has shifted what “real time” means in fraud monitoring. On FedNow and the RTP network in the U.S., on SEPA Instant in the EU, on UPI in India, on FAST in Singapore, once the payment is settled, it’s final. There is no overnight clearing window where a confirmed fraud transfer can be reversed. ACH and wire rails still have their recovery options, but that is gone.

This shrinks the detection window from hours down to milliseconds and completely alters the architecture. Pre-settlement risk scoring, in line behavioral analytics and auto decisioning have moved from being advanced features to table stakes. If a monitoring system detects a fraudulent instant payment two seconds after settlement, it is not preventing a loss, it is describing a loss.

The direct regulatory expression of this same shift is the Nacha 2026 fraud monitoring rule, discussed in detail below: Every party in the ACH chain, such as sending banks, receiving banks, originators, third party senders, third party service providers, is now expected to monitor in real or near real time, because the rails themselves no longer leave a comfortable downstream recovery window.

Support 20260720160012 8710

Internal Fraud vs External Fraud

Most fraud coverage is geared towards external attackers, criminals outside the institution targeting the institution and its customers. The other half of the problem, often under covered, is internal: Fraud perpetrated by employees, contractors or partners with privileged access to systems and data.

Internal fraud comes in a number of recurring forms. Employee fraud includes unauthorized access to customer accounts, tampering with records, theft of funds or data, and the misuse of system overrides. Embezzlement is the theft of the institution or customer funds by somebody in a position of trust . This is usually done over long periods of time, in small repeated transactions designed to be below the review thresholds . Collusion involves both internal and external actors. The employee provides the access or override, the external party provides the laundering channel.

The monitoring patterns tuned to detect internal fraud are different than those tuned for external attackers. Out of hours system access for privileged users. Manual overrides are clustered around some employees or customers. Approvals not routed consistent with institution’s authority matrix. Customer account changes initiated from the internal terminal with no associated service request. Unusual activity concentrations on dormant accounts. You don’t just see these signals in transaction streams, you see them in the intersection of transaction data, access logs, and approval workflows. This is why mature programs feed all three into the same monitoring layer.

Governance separation is also most important in internal fraud. The structural problem of a monitoring system which is maintained and tuned by the very people whose activity it is supposed to monitor. The standard control is independent oversight of the rules and thresholds for internal fraud and examiners are becoming more explicit about expecting it.

The Role of Artificial Intelligence in Fraud Monitoring

Artificial intelligence has leveled the playing field on both sides of fraud detection, and the game is more an arms race than a silver bullet on either side.

On the defense side, AI is now the operational base of any monitoring system handling meaningful volume. Behavioral analytics and anomaly detection, the disciplines that learn each customer’s individual baseline and flag deviations from it, are entirely reliant on machine learning. That’s the basis of graph and network analysis, exposing mule clusters and synthetic identity rings that per account screening can’t see. This is critical for detecting adverse media and adverse events across a variety of languages. Today’s AML and fraud platform operators have shifted from rule only architectures to hybrid ones that blend rules for explainability with ML models for adaptability.

On the offense side, AI has industrialized the attacker's tool kit. Generative models can produce convincing phishing emails in any language, without the grammatical tells that once gave away fraud attempts. Voice cloning tools recreate executives from seconds of publicly available audio, fueling “deepfake CEO” wire fraud calls. AI generated synthetic identities with fabricated faces, addresses and credit histories sail through onboarding at industrial scale, driving the synthetic identity fraud growth captured in the numbers above. Deepfake document fraud creates realistic pay stubs, statements and invoices with realistic formatting and signatures designed to defeat document checks. Every defensive improvement gets an offensive counter, often in months.

The framing is important: AI is not a switch to turn on the defensive side and be done. It is a continuous capability that needs to be governed, model risk managed, retrained, and adversarially tested, because the attackers using it on the other side are doing the same.

Support 20260720160514 3012

US Fraud Monitoring Regulation: BSA, SARs, and the Nacha 2026 Rule

Fraud monitoring in the United States is conducted within a defined regulatory framework, and in 2026 that framework has just changed in the most consequential way in a decade.

BSA/AML & Fraud SARs. The Bank Secrecy Act mandates institutions to file suspicious activity reports for a wide array of fraud adjacent activity, and the categories of fraud that trigger SAR filing have been steadily expanding over the past decade. Therefore, fraud monitoring is not just a customer protection and loss management function, it is also a feeder to the institution’s BSA reporting obligations, the formal point at which fraud and AML converge in compliance documentation.

The Nacha 2026 fraud monitoring rule. The biggest thing in 2026 for U.S. fraud monitoring is Nacha’s risk management rule package, which changes fraud monitoring requirements across the ACH network.

Phase 1 was effective March 20, 2026. This applies to all Originating Depository Financial Institution (ODFIs) and to those non-consumer Originators, Third Party Senders and Third Party Service Providers that have an origination or transmission volume exceeding 6 million entries in 2023. And it requires Receiving Depository Financial Institution (RDFIs) with 2023 ACH receipt volume of 10 million or more to develop risk based processes to identify credit entries initiated as a result of fraud. Phase 2 will be effective June 19, 2026, removing the volume threshold so all non consumer Originators, Third Party Service Providers, Third Party Senders and all RDFIs are included regardless of volume. Because June 19 is a federal holiday, the effective compliance date is the next business day.

Two design features of the rule deserve immediate attention. First, Nacha replaced the older “commercially reasonable” language with “risk based” processes and procedures a material change in standard that requires documented, reviewable risk assessments rather than informal industry norm. Second, the rule establishes a new “False Pretenses” standard, defined as the inducement of a payment by a person misrepresenting that person’s identity, association with or authority to act on behalf of another person, or ownership of the account to be credited. The False Pretenses standard more explicitly encompasses the credit push scams that had fallen between the cracks: BEC, payroll diversion, vendor payment diversion, and romance and investment scams.

Nacha has emphasized that for the first time, RDFIs, have a formal role in fraud monitoring because of the way credit push frauds work, with financial institutions on both sides of a payment having to be part of the monitoring solution. That unique perspective of the receiving institution, seeing incoming payments against the profile and historical activity of the receiver’s account, is exactly the angle from which credit push fraud can be caught in time to recover funds.

The Nacha rule does not apply directly to institutions outside the U.S., but the conceptual shifts are likely to be referenced in supervisory expectations globally over the next two to three years, from “commercially reasonable” to documented risk based, from sender only to dual sided monitoring, from generic suspicion to a defined false pretenses standard.

How Sanction Scanner Helps in Fraud Monitoring

Sanction Scanner's unified Fusion platform which includes Fraud Detection is built for the operational reality described in this article. Real-time fraud monitoring across modern payment rails, with a convergence layer that ties fraud directly to AML transaction monitoring instead of running it as a separate stack.

The platform provides real-time transaction monitoring and risk scoring, a flexible rules engine that supports the rule archetypes outlined above, behavioral analytics, name screening across sanctions, PEP, and adverse media, and unified case management for fraud and AML. Cross-module signal sharing means the queues talk to each other. A fraud alert raises the AML risk score, and an AML pattern tightens fraud thresholds, so the institution works from one risk surface rather than two disconnected queues. Built around real-time scoring and a shared data layer, the platform is designed for the latency demands of FedNow and RTP, the Nacha 2026 requirements environment, and the post-2024 IC3 typology mix.

Support 20260720160047 6288

Sources:

[1] Federal Bureau of Investigation, Internet Crime Complaint Center. 2024 Internet Crime Report. 2025.

[2] Federal Reserve, FedPayments Improvement. Synthetic Identity Fraud. 2024.

[3] TransUnion. TransUnion Analysis Finds Fraud Costing Businesses Equivalent of Nearly 7% of Revenues and TransUnion Research Highlights Power of Public Data in Uncovering $3.3B Synthetic Identity Threat. 2024 and 2025.

[4] Nacha. Risk Management Topics – Fraud Monitoring Phase 1 and Risk Management Topics – Fraud Monitoring Phase 2. 2026.

[5] Financial Crimes Enforcement Network. FinCEN Alert on Nationwide Surge in Mail Theft-Related Check Fraud Schemes Targeting the U.S. Mail. 2023.

[6] Financial Crimes Enforcement Network. Frequently Asked Questions Regarding the FinCEN Suspicious Activity Report. 2025.

FAQ's Blog Post

Fraud monitoring feeds SAR filing directly. The Bank Secrecy Act requires institutions to report a wide range of fraud-adjacent activity, so monitoring is not only loss management, it is a feeder to the institution's reporting obligations. That is the formal point where fraud and AML converge in compliance documentation.

AI runs the core of modern fraud monitoring: Behavioral analytics that learn each customer's baseline, and graph analysis that exposes mule clusters and synthetic identity rings. But it cuts both ways. Attackers use the same tools for deepfake wire fraud and synthetic identities, so AI needs governance and continuous retraining, not a one-time switch.

External fraud comes from criminals outside the institution targeting it and its customers. Internal fraud comes from employees, contractors, or partners with privileged access. They need different monitoring: Internal fraud shows up in the intersection of transaction data, access logs, and approval workflows, not in transaction streams alone.

Any institution on the US ACH network is inside the Nacha 2026 fraud monitoring rule. It requires risk-based monitoring across the whole chain, introduced a False Pretenses standard covering credit push scams, and gave receiving institutions a formal role. Phase 1 took effect 20 March 2026, Phase 2 on 22 June.

Real-time fraud monitoring scores and decides on a payment before it settles, rather than reviewing it afterward. Instant rails like FedNow and RTP settle in seconds and are irrevocable, so a system that flags a fraudulent payment two seconds after settlement is describing a loss, not preventing one.

Fraud monitoring covers a portfolio, not one typology: Check fraud, wire fraud, ACH fraud, business email compromise, account takeover, synthetic identity fraud, credit card fraud, money mule activity, authorized push payment scams, and AI or deepfake-driven fraud. Each has its own signals, so the monitoring layer needs several detection methods working together.

Fraud monitoring runs a pipeline: It ingests transaction, device, behavioral, and customer-profile data, applies rules and behavioral analytics, and combines them into a real-time risk score in milliseconds. The score decides whether to approve, step up authentication, block, or route the event into a case management queue for an analyst.

Fraud monitoring prevents direct theft and scam losses, measured by loss avoided and recovery speed. AML transaction monitoring tracks illicit proceeds through the system for regulatory reporting, measured by investigation quality and SAR timeliness. Same data, often the same customer, but different red flags, timelines, and outcomes.

The three describe different stages. Fraud prevention builds the controls that stop fraud happening, like authentication and payee verification. Fraud detection is the moment of recognizing an event as fraudulent. Fraud monitoring is the continuous process that runs detection, watching every transaction and login all the time and producing the alerts detection acts on.

Fraud monitoring is the continuous, real-time review of transactions, devices, and behavioral signals to catch theft, scams, or account compromise before money leaves the account. It combines rules, behavioral analytics, and risk scoring into one decision layer that approves, holds, or blocks each event in milliseconds.