Sardine named a Leader in The Forrester Wave™: Financial Crime Management Solutions, Q3 2026

Learn More
FRAUDFORWARD
#119

Cómo crear un programa antifraude: el fraude desde los cimientos

59 min

¿Qué tal, luchadores contra el fraude? ¡Bienvenidos de nuevo a Fraud Forward!

Hoy me siento en la silla de invitado.

Si escuchaste el episodio de The Saturday Fraud Strategist que se publicó junto con este, ya sabes que Chen Zamir y yo decidimos intercambiar los papeles. Él vino a Fraud Forward para entrevistarme y yo fui a su programa para entrevistarlo. Vamos juntos a Money 20/20 en Las Vegas y pensamos que esta sería una forma divertida de empezar.

Paso mucho tiempo haciendo preguntas. Estar al otro lado del micrófono es una experiencia diferente, y Chen no hace preguntas fáciles. Esta conversación tomó rumbos que no esperaba del todo. Terminamos hablando de cómo crear un programa de prevención del fraude que funcione y, lo que es más importante, de los obstáculos que lo impiden.

Si alguna vez has llegado a una organización que llevaba un año luchando contra el fraude, había invertido dinero en proveedores y personal y, aun así, seguía en el mismo punto de partida, este episodio es para ti. La solución va mucho más allá de añadir otra herramienta.

Lo que escucharás en este episodio:

  • Cómo elaborar una evaluación del programa de prevención del fraude al incorporarse a una organización que lleva tiempo atravesando dificultades sin que nadie sepa explicar por qué
  • Por qué la gestión del fraude y los riesgos comienza por las personas, los procesos, la tecnología y los datos, en ese orden, y por qué la mayoría de las organizaciones empieza por la tecnología y acaba generando más problemas
  • El modelo de planificación de la capacidad para la gestión del fraude que desarrollé como profesional para demostrar a los directivos las necesidades de personal, incluido el cálculo de tres minutos por alerta y cómo crear un modelo de semana laboral de 40 horas que tenga en cuenta todo lo que realmente hace tu equipo
  • Por qué la estructura del equipo de fraude es importante antes de poder optimizar cualquier aspecto, y cómo resolver la cuestión de si debe ser centralizada o descentralizada antes de empezar a contratar personal o adquirir soluciones
  • El marco de evaluación del riesgo de fraude que considero la herramienta más importante en el programa de un responsable de prevención del fraude, incluida la diferencia entre el riesgo de fraude inherente y el riesgo residual, y por qué la ausencia de pérdidas no implica la ausencia de riesgo
  • Por qué una implementación por capas mal planteada de tecnologías antifraude se asemeja a combinar medicamentos que interactúan negativamente entre sí, y cómo es realmente un análisis de carencias tecnológicas en materia de fraude antes de una demostración de un proveedor
  • Cómo el fraude mediante pagos push autorizados pone en jaque la arquitectura antifraude, diseñada en torno a una única pregunta —«¿es realmente nuestro cliente?»—, y por qué las señales de comportamiento para detectar estafas requieren un enfoque completamente distinto
  • El marco bancario de intervención contra estafas que utilicé como profesional, incluidas las medidas de fricción selectiva, los períodos de espera y la frase que considero mi momento culminante
  • Cómo abordo la comunicación con la alta dirección sobre el fraude y la defensa de los programas antifraude cuando los directivos ven las pérdidas en un panel de control, pero pasan por alto los quince millones que el equipo evitó perder
  • El modelo de informes del panel de fraude que me gustaría ver: intentos de fraude, fraudes evitados y pérdidas reales, normalizados en función del volumen de transacciones o los depósitos, y no solo las pérdidas brutas por fraude
  • Por qué la IA antifraude con intervención humana no es escalable y qué implica la supervisión humana para el desarrollo de las competencias de los equipos antifraude en la actualidad
  • Cuál es realmente el nivel de madurez de los programas antifraude según el análisis comparativo que he estado realizando, y por qué los equipos antifraude lo están haciendo mejor de lo que creemos

Deberías escuchar este episodio si:

  • Estás creando o reconstruyendo un programa de prevención del fraude y quieres saber cómo lo abordo realmente desde cero, no con un marco teórico sacado de un libro de texto, sino con el proceso real que utilicé como profesional
  • Alguna vez han tenido que justificar la plantilla, la tecnología o el presupuesto ante un equipo directivo que no comprende del todo lo que realmente implica la prevención del fraude y quieren un modelo que respalde la propuesta con datos
  • Trabajan en un banco o una cooperativa de crédito, sienten la presión del cambio del fraude no autorizado al fraude mediante pagos push autorizados y las estafas, y no saben con certeza cómo adaptar su infraestructura de prevención del fraude
  • Quieres el modelo de planificación de capacidad para la gestión del fraude que elaboré manualmente como profesional, el cálculo de tres minutos por alerta y el desglose de la semana laboral de 40 horas que finalmente logró que la dirección prestara atención
  • Están intentando determinar cómo integrar la IA en su programa de prevención del fraude sin perder a los investigadores que han tardado años en formar
  • Lideran un equipo de prevención del fraude y quieren saber cuál es realmente el nivel de madurez de su programa antifraude, según el análisis comparativo que he estado realizando en distintas instituciones financieras
  • Alguna vez has entrado en una sala y te has encontrado con miradas inexpresivas al preguntar a tu equipo qué está provocando realmente las pérdidas por fraude, y has necesitado un mejor punto de partida para esa conversación
Notas del episodio

Una evaluación del programa de fraude cuando el equipo no sabe qué está fallando

Formule preguntas que ayuden a comprender la composición del fraude, no solo las pérdidas por fraude. ¿Cambió la composición del fraude? ¿Las pérdidas pasaron del fraude con tarjetas a las estafas? ¿Se lanzó un nuevo producto digital sin informar al equipo de prevención del fraude? ¿Aumentó el volumen de transacciones? ¿El volumen de alertas creció más rápido que el fraude real? ¿Algún control simplemente desplazó el fraude a otro canal?

La mayoría de las veces, los equipos que atraviesan dificultades no pueden responder a esas preguntas. Y, si pudieran, no se encontrarían en la situación en la que están. No es una crítica, sino un diagnóstico. Antes de recomendar nada, lo que busco determinar es si la estrategia contra el fraude refleja realmente el fraude al que se enfrenta la institución hoy en día, y no los patrones de fraude de hace tres, cuatro o cinco años, cuando se redactaron originalmente las reglas.

El modelo práctico de planificación de la capacidad para la gestión del fraude

Este es uno de los marcos de trabajo de los que más me enorgullezco, y lo desarrollé manualmente antes de que la IA pudiera hacerlo por mí. El modelo parte de una pregunta sencilla: ¿cuánto tiempo dedica su equipo a cada alerta? No una estimación, sino una medición real.

Mi equipo estableció tres minutos como punto intermedio entre las alertas sencillas, que se resolvían en menos de un minuto, y las alertas complejas, que requerían cinco minutos de investigación. A partir de ahí, hice un seguimiento de cuántas alertas se gestionaban, cuántas daban lugar a un caso, cuánto tiempo se dedicaba a investigar cada caso, cuántas llamadas telefónicas atendía el equipo, cuánto tiempo se dedicaba a mensajes privados y comunicaciones internas, cuánto tiempo se pasaba con las víctimas de estafas y cuánto tiempo se invertía en desarrollar procesos y procedimientos.

Al calcular todo eso sobre la base de una semana laboral de 40 horas y multiplicarlo por el número de personas del equipo, las carencias se hacen evidentes de inmediato. También incluí los requisitos anuales de formación profesional, los créditos de educación profesional continua (CPE) y otras obligaciones que la mayoría de los modelos de capacidad pasan por alto. El resultado es un documento que demuestra a los directivos no solo que el equipo necesita más recursos, sino también el motivo exacto, desglosado hasta la última hora. La defensa de las necesidades del equipo de fraude por parte de sus responsables debe basarse en datos. No basta con decir que estamos desbordados. Hay que demostrarlo con cifras.

El marco de evaluación del riesgo de fraude

Mi postura es que una evaluación del riesgo de fraude es la herramienta más importante que necesita un programa antifraude para justificar los recursos que requiere. Y la mayoría de las evaluaciones del riesgo de fraude se realizan de forma incorrecta.

El objetivo no es confirmar que el fraude en transferencias bancarias supone un riesgo elevado. Cualquiera que trabaje en el sector ya lo sabe. El objetivo es responder a cuatro preguntas concretas: ¿Dónde estamos expuestos? ¿Qué gravedad podría alcanzar esa exposición? ¿Qué controles tenemos y qué tan eficaces son? ¿Y qué vamos a hacer con respecto al riesgo residual?

Esa última pregunta es donde la mayoría de las evaluaciones fracasan. Si se completa la evaluación, se le asignan calificaciones en rojo, amarillo y verde, se presenta ante un comité una vez al año y no cambia nada a nivel operativo, el ejercicio no habrá servido de nada.

El riesgo inherente es el riesgo existente antes de considerar cualquier control. El riesgo residual es el que permanece después de aplicar los controles. El error que cometen la mayoría de los equipos es evaluar el riesgo inherente basándose en las pérdidas históricas. La ausencia de pérdidas no significa que no haya riesgo. Puede significar que los controles están funcionando. También puede significar que los defraudadores aún no han descubierto esa vulnerabilidad. Mi ejemplo del fraude con cheques lo ilustra claramente. Si todos los cheques que su institución ha aceptado fueran fraudulentos y no contara con ningún control, ¿a qué nivel de exposición se enfrentaría por cada cheque? Ese es su riesgo inherente, no su historial de pérdidas.

El fraude de pagos push autorizados rompe todos los fundamentos de la infraestructura antifraude

Durante años, mi infraestructura antifraude se diseñó en torno a una pregunta: ¿se trata realmente de nuestro cliente? El dispositivo, la contraseña, la autenticación multifactor, la biometría y la autenticación mediante la dirección IP responden a esa pregunta. Las estafas plantean una segunda pregunta que la autenticación no puede responder: ¿entiende nuestro cliente lo que está haciendo? Puedo demostrar con casi total certeza que el cliente inició la transacción. Pero eso no demuestra en absoluto si lo hizo porque alguien le convenció de que su dinero estaba en peligro.

Las señales de comportamiento para detectar estafas funcionan de otra manera. ¿Es este un comportamiento habitual en este cliente? ¿El destinatario es nuevo? ¿Ha cambiado recientemente sus datos de contacto? ¿Ha aumentado los límites de transferencia? ¿Ha añadido un dispositivo nuevo? ¿Ha movido dinero entre cuentas justo antes de la transacción? ¿Está vaciando una cuenta que ha tardado veinte años en acumular? Puede que cada señal por separado no signifique gran cosa. Juntas cuentan una historia. Y esa historia requiere un enfoque completamente distinto del que desarrollé en torno a la autenticación.

La comunicación con los directivos sobre el fraude y cómo la IA puede transformar su lucha

Si el consejo de administración solo ve las pérdidas por fraude, únicamente está viendo los fallos. Necesita ver qué está evitando el programa. El modelo de panel de control de fraude que propongo incluye los intentos de fraude, los fraudes evitados y las pérdidas reales, todo ello normalizado en función de un parámetro relevante, como el volumen de transacciones, el crecimiento de la clientela o los depósitos. Una pérdida de dos millones de dólares tiene un significado muy distinto en una cooperativa de crédito con quinientos millones de dólares en activos que en un banco con cincuenta mil millones. Las pérdidas son fáciles de medir. La prevención es difícil de cuantificar. El panel debe mostrar ambas cosas; de lo contrario, la dirección solo verá la mitad de la realidad.

Voy a ser completamente transparente. No tengo una respuesta definitiva sobre cómo cambiará la IA el papel del investigador de fraude. Lo que sí tengo es una dirección clara. El modelo de «humano en el circuito», en el que los investigadores revisan y validan cada decisión de la IA, no es escalable. El futuro del puesto está en el modelo de «humano sobre el circuito», en el que mi equipo establece las políticas y supervisa los sistemas de IA, en lugar de revisar resultados individuales. Mi consejo para los equipos de fraude es que empiecen a formarse desde ahora. Identifiquen qué tecnología probablemente necesitará su programa dentro de dos años y comiencen a desarrollar las habilidades que harán que los investigadores sean valiosos en ese entorno. No podemos adoptar un enfoque preventivo y proactivo contra el fraude basándonos únicamente en el trabajo humano. Tenemos que empezar a invertir desde ahora en nuestros equipos para que estén preparados cuando llegue ese momento.

Conclusiones clave
  • Para crear un programa de prevención del fraude, primero hay que entender por qué se están produciendo las pérdidas, antes de asumir que la solución pasa por incorporar más tecnología o más personal. Es necesario comprender los distintos tipos de fraude, el volumen de alertas y la ubicación de los controles antes de proponer cualquier solución.
  • Mi modelo de planificación de capacidad para la gestión del fraude parte de tres minutos por alerta y desarrolla una visión completa de una semana laboral de 40 horas que permite demostrar a los directivos, con datos y no desde la frustración, las carencias de recursos.
  • La diferencia entre el riesgo inherente y el riesgo residual de fraude es el aspecto que más suele malinterpretarse en una evaluación del riesgo de fraude. La ausencia de pérdidas históricas no implica que no exista riesgo inherente. Puede significar que los controles están funcionando o que los defraudadores aún no han detectado la vulnerabilidad.
  • La integración por capas de tecnologías antifraude implica comprender qué función cumple cada componente y cómo se integra con los demás, no añadir otra herramienta cada vez que algo no funciona. El análisis de carencias tecnológicas en materia de fraude que se realiza antes de una demostración de un proveedor es lo que distingue una integración eficaz por capas de una combinación de medicamentos con interacciones adversas.
  • El fraude de pagos push autorizados exige plantearse una cuestión completamente distinta a la del fraude no autorizado. La autenticación demuestra la identidad, pero no la intención. Las señales de comportamiento para detectar estafas son las que permiten cerrar esa brecha.
  • Mi marco de comunicación sobre fraude para la alta dirección presenta el fraude evitado junto con las pérdidas reales, normalizados en función de una métrica significativa, como el volumen de transacciones. La dirección necesita ver ambas cifras para comprender lo que realmente está logrando el programa.
  • La supervisión humana de los sistemas es hacia donde debe orientarse ahora mismo el desarrollo de competencias de los equipos antifraude. Gobernar los sistemas de IA a nivel de políticas requiere habilidades distintas de las necesarias para revisar alertas individuales, y este es el momento de desarrollar esa capacidad.
Conclusión final

Chen me hizo preguntas difíciles en esta ocasión, y me alegro de que lo hiciera. La conversación que terminamos teniendo es la que me gustaría que más responsables de la lucha contra el fraude mantuvieran ahora mismo dentro de sus organizaciones. Crear un programa de prevención del fraude no es algo que se haga una sola vez. Es un proceso continuo que consiste en evaluar en qué punto se encuentra la organización, comprender qué factores impulsan los resultados y asegurarse de que la estrategia refleje realmente el fraude que se observa hoy, y no el que se observaba hace cinco años. Si esta conversación les ha dado una idea que compartir con su equipo esta semana, espero que sea el permiso para detenerse a reflexionar antes de comprar la próxima herramienta y preguntarse si realmente saben qué problema intentan resolver.

Si quieres escuchar cómo le doy la vuelta a la situación con Chen, visita The Saturday Fraud Strategist para oír la otra mitad de esta conversación.

Hasta la próxima. Manténganse alerta, manténganse informados y sigan impulsando la lucha contra el fraude.

Recursos y enlaces del episodio:

Conecta con Chen Zamir | LinkedIn
Presentador de The Saturday Fraud Strategist
Ayuda a las fintech a desarrollar defensas más inteligentes contra el fraude
Coautor de «The Fraud Fighter’s AI Playbook»

Conecta con Hailey Windham, CFCS | LinkedIn
Presentadora del pódcast Fraud Forward
Responsable de la comunidad bancaria en Sardine
Especialista certificada en delitos financieros (CFCS)
Credit Union Rockstar 2023, CU Magazine
Premio a la Mejora Continua, SAFE Federal Credit Union, 2023
Una de las 20 mejores profesionales menores de 40 años, The Sumter Item, 2022

Episode transcript
Chen Zamir
Chen Zamir
00:05
What's up, fraud fighters? I'm Hailey. No, you know what? I'm tired of this charade. Uh, the tokens cost me too much. Uh, being like a fake uh fake blonde with a fake southern accent. I cannot afford it any longer. And I want to admit it's been me all this time. Uh, Chen Zamir. No. Uh, just kidding. Hailey, it's so great to be uh on your show as a guest interviewer. How are you?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
00:34
I am doing so well and I'm I'm so glad that the the truth has finally come out and I mean come on.
Chen Zamir
Chen Zamir
00:40
Yes.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
00:41
It's really been you this entire time.
Chen Zamir
Chen Zamir
00:44
Yes. You know, well, uh I thought uh tokens would be cheaper than uh wigs, but apparently that's not the case. So, I'm done with that.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
00:53
I'm just so glad you agreed to to come in on my podcast as well. We just uh recorded the reverse interview on yours and now we're kind of uh flipping the script again and letting you take the lead on the podcast on on Fraud Forward.
Chen Zamir
Chen Zamir
01:09
Yes, absolutely. And if you didn't catch uh the episode of the Saturday Fraud Strategist, uh Hailey and I spoke about why we're doing all of that. And that is because I'm actually not exactly sure when this episode is going to drop, but probably a couple of weeks after you're listening to this, we are heading to Vegas uh to participate in Money20/20. Hailey, do you want to uh uh give the juice about it?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
01:34
Yeah, I am so stoked. Um last year I went to Money20/20 and um I got lost everywhere I went in the Venetian. Um so I'm really excited to do that again. Uh but this year I will have a partner in crime. Chen Zamir and I will be at uh the Sardine booth. We will be recording podcasts throughout uh the the days um of Money 20/20. And we'll also just kind of be floating around having great conversations with people, hosting a happy hour or two. And I'm just I'm really excited and looking forward to to that time where we can meet in person um and then people can experience the magic of us uh live in in Vegas.
Chen Zamir
Chen Zamir
02:12
It's just me. We just said it. It's just me. There's no Yeah. Yeah. There's no Hailey.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
02:17
There is no Hailey.
Chen Zamir
Chen Zamir
02:23
Yeah. You know, it's a funny thing because I I was just trying to think. I was in in Money 20/20 Vegas once and in my mind it was always like around 2018 2019 and I couldn't quite recall. But one thing that I like that really stuck to my memory is that I remember staying uh back then uh at the Trump Tower and I remember that being like just before the elections and I said well that doesn't make sense because in 2018 2019 Trump was already president and I was like going through my through my uh phone pictures uh like the other day and I realized that actually I've been there in 2016. It was two months before the elections. Yeah. And actually that would mean that I'm now returning to Money 20/20 Vegas after a full decade. So that's a bit of a mindblower.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
03:16
Yeah.
Chen Zamir
Chen Zamir
03:17
Yeah.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
03:17
You're showing your age there.
Chen Zamir
Chen Zamir
03:20
Uh yeah. Yeah. Uh okay. First question. No. Okay. So I'm super stoked about uh by the way we will meet for the first time uh in person in Vegas. So I'm I'm yeah I'm really looking forward to it and and a bunch of other uh Sardine folks. So yeah I hope to see you all there. Um I want to go uh directly into the topics that I wanted to speak about today Hailey and you know uh I speak a lot about fraud strategy and somehow we never got to talk about it. So I like I'm super curious because you know I had a lot of different conversations with a lot of different folks when it comes to you know fraud strategy and especially when you go into like a new organization. And you've said both you know wearing a hat of a practitioner wearing the hat of a consultant wearing the hat of uh of now a vendor um and you you kind of like you know you need to quite quickly understand what's the what's the state. Uh what is going well and maybe where are the gaps and and and try to kind of like you know give advice or you know like give some guidelines or you know like make your plan as to how best to go about it. And when I talk to like fraud strategists I always hear different answers but around the same principle. So you know I I wanted to start with that and kind of like hear where you stand and how you work. So let's say for the manner of the example let's say that you're you know you're going into organization and an executive tells you look we've you know we've invested in fraud a lot. We've hired more folks. We integrated a couple of vendors. We've been fighting it for a year. We're pretty much at the same place. What how would you go about it?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
05:20
Well, I think it's a matter of obviously understanding where they are. You have to look at, you know, we're going to talk a little bit more about risk assessments, but trying to understand fully holistically, right? What they have, what products and services they have, where their exposure could be. I'd also want to ask like if if nothing has changed or if if losses are increasing, right, and and your teams are overwhelmed and it's like do we throw more resources at it? Do we throw more money at tech? But I don't think that's where we need to do. That's what we need to do. I, you know, I I would never immediately assume that any organization needs another tool or another person. I want to understand what's driving whatever fraud increase that they may have. You know, did the the did the fraud mix change? Did losses move from card fraud into scams? Did a new digital product launch that you didn't tell your fraud team about? Did transaction volume grow? That never happens, right? Um,
Chen Zamir
Chen Zamir
06:17
Never.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
06:18
Did alert volume grow faster than like actual fraud? Did we introduce a control somewhere that just shifted fraud into another channel? Because that happens a lot too. Then I want to, you know, look at the program from different angles that from risk from people, process, technology, and data. A lot of organizations start with technology because that's the easiest thing to point to. We're losing money so we need a better fraud tool maybe. Or maybe the tool is generating perfectly good alerts and you don't have enough people to work them. Maybe you have enough people but they're spending 70% of their time clearing false positives. Maybe your rules were designed around fraud patterns from three, four, five, 10 years ago, right? And and maybe nobody has stepped up and asked whether your fraud strategy actually reflects the fraud that you're seeing today. And that's where I think, you know, good risk assessment becomes incredibly valuable.
Chen Zamir
Chen Zamir
07:15
You know my like I agree 100% with everything that you said. I would say that my general experience is that when you ask these smart questions to a team that is struggling usually the answers would be I don't know. Or the answer the singular answer would be I don't know because if they would be able to answer these questions most likely they wouldn't be in that hole. So, you know, what do you do in, you know, in this instance where, and I'm guessing that, you know, maybe maybe some of our listeners right now, you know, also have exactly the same thing that, you know, they they see the pressure, but they don't necessarily have the ability to really understand exactly what's going on. How like what would be the best piece of advice to such teams
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
08:05
In regards to like pressure testing?
Chen Zamir
Chen Zamir
08:08
Not necessarily pressure testing, but like you know, let's say, you know, they see that their fraud rates are up, but they don't necessarily know how many false positives they have. They don't necessarily know from which flow it arrives. They don't necessarily know, you know, how much of that was missed by the investigators versus how much of that was missed by rules. So because usually if you know if if they would have the foresight to ask and answer these questions usually they would also be able to kind of like optimize around these things. So what happens in the case where you know you you just get blank stares when you ask these kind of questions which which I'm guessing happens from time to time.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
08:51
Oh it definitely happens from time to time. That's why I always uh I think culture matters so much in whatever organization you're at. For me, whenever I was a practitioner, it was I didn't understand not only the infrastructure because I was new coming into that role to build a fraud program. So, I didn't understand the infrastructure completely for the organization, but I also didn't know anyone really in the organization. But they knew that I was the girl that was going to stop transactions because I was in fraud. So, I was going to implement rules. I was going to create processes that just made everyone hate their lives. Um, and I was basically going to come in like a bull in a china shop. It was the perceived uh notion of of what I was doing there, what my role was. So instead, I focused on number one making friends in the organization. And I don't mean by offering to take them out to lunch, but I mean by truly sitting down with the the workers. So, I would go to e-services and instead of going directly to the director, I went to the people hitting the button every day, the ones that were working in PIK um which was our um basically a digital channel for like check deposits um and they and ATM deposits. And so I went and sat with them and I said, "Hey, explain this process to me." And when they saw that I was somebody that actually wanted to not only understand the process first, but then help and make sure that we're creating process efficiencies as well. Which is what I think works really well for fraud uh programs. Anyways, if you kind of structure yourself with that operational hat in which the benchmark report that we have coming out um hopefully this week, hopefully it will be live before this uh this recording comes out. But what you'll see in in the benchmarking is that a lot of fraud professionals and financial institutions came from the operations uh department or operations side of the organization which is a great thing because they understand the payment method. They understand where in our infrastructure is the last point of interception before the fraud leaves right where's our last point of contact where we can say okay we don't want this to happen. So anyways, whenever you're you're going in and you're understanding the infrastructure, you're creating process efficiencies before you even look to say, "Hey, what things do we need to implement to prevent fraud?" That's where you're going to see a lot of good things happen for your organization as a whole. When it comes to preventing fraud, it's developing that culture and making sure that you understand the process yourself before trying to implement any kind of changes, even new tech. You know, you don't want to do that until you fully understand the tech that you currently have.
Chen Zamir
Chen Zamir
11:19
Yeah, I love that because it, you know, goes to show that, you know, nothing beats data and if you don't have data, nothing beats leg work, right? So,
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
11:29
Yeah, and I think I hope I answered that question for you.
Chen Zamir
Chen Zamir
11:33
No, no, definitely. Definitely. I think cuz in the end you you need to get this data right uh and going to the source, you know, in these kind of situations there there's nothing that can really replace that.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
11:45
Yeah.
Chen Zamir
Chen Zamir
11:46
And it takes time and effort, but it is what it is. Um I wonder you know we talked a lot about uh data and the product and the operations or processes side. I wonder when it comes to the organization itself what do you think like how do you how do you assess the organization itself? How it's built? How it is you know accounting for ownership? How it is measured? Um how um you know what kind of skill sets or how do you do hiring or train like how do you look at the organizational piece when it comes to fraud strategy is it part of fraud strategy in your mind or is it something completely different
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
12:31
No 100% I think also you have to answer the question are you a centralized fraud program or a decentralized fraud program. Centralized is all the fraud comes to you you handle all the disputes all the chargebacks everything like that that comes directly through you where decentralized is you're kind of sitting as this advisory level of here's how we should here's how I would here's what I'm learning from the industry and where we can improve this particular fraud scenario. Right? Or or however it happens in your organization. Um and once you have that answer then it makes it easier for you to basically figure out where where you are. If you're looking at um your staffing your current staffing you can't just say, "Hey, I need another fraud analyst." That's not going to work. You have to show the the data for why you need another analyst. Do a capacity planning model. What I did, um, and this was a very manual process back in my day before, um, before we had AI that could do these things for us, and which most organizations won't really allow you to, um, implement these things right now. Anyways, um what I would do is I literally pulled all of our alerts and I would say, "Okay, how often or how much time are you spending per alert?" And we came up with an average minute time frame. So, some some alerts you could go through really quickly, but be within a minute. There were others that you had to actually dive in and look at and they'd be five minutes. So, we came to a compromise of three minutes and we would go through and we'd see how many alerts we had, how many that were worked, right? And then we would compare that and put it in a timestamp of okay, we have 40 hours a week. Here's how much time is allocated to these alerts. Here's how many of those alerts actually produced a case. By the way, case investigation, how much time are we spending per case investigation? Then you have to consider how many phone calls are we getting each each month? How or week? Um how many uh times are we getting a private message on whether it's Teams or Slack or whatever your organization is using. How much time is spent answering those? How much time is spent on a phone call with a victim trying to deescalate a situation and talk them down? How much time is spent developing processes and procedures? And whenever you calculate all of those things and you put it in a 40-hour week and you times it by however many people you have on your staff, you quickly find out, hey, we're we we've got some big gaps here. If we don't fill it, this is how we can prove that. We also did it. We also included like our professional training. So if you're required to have a certain number of CPEs a year, we we did it as an annual total, not just a weekly total. But we're able to then prove to executives that even these things that we have to have factor into how much time is needed because we can't just assume, hey, guess what? We can turn on this new alert, but how many alerts is that going to create for your team to work? Run a test first. See how many if you're cutting it on, if it's got a particular parameter that you're wanting to use, go ahead and let that test run and see how many would have alerted. Check to make sure you have the capacity to fill that in before turning it on. Otherwise, you're just creating more um more instances where you are going to be drowning and it's because of your own demise.
Chen Zamir
Chen Zamir
15:46
Yeah, I love it how again it all comes back to you know how you can quantify different facets of your program whether these are the processes, the organization, uh the technology. And what I love about it is that you know it makes our domain right at least when you approach it in the right way. It makes it very unemotional right I mean there are no opinions here it's just you know what the data tells us and what we want to or how do we want to react to that? Uh and and I really like this approach. Um
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
16:24
Yeah, I I will say I love that you mentioned the opinion aspect. Um one of the things that I struggled with when building my fraud risk assessment, I was trying to understand it. I would go back to my risk officer, which she wasn't a lot of help. So I had to go to one of the associations and found me the most amazing mentor um who guided me through what a fraud risk assessment is. And one of my main questions that I brought up to my chief risk officer at the time was, okay, here's a here's a part on our risk assessment that says, um, the board receives fraud training. Well, the answer to that is yes, they do, but is it effective fraud training and how could I quantify what it was or or how effective it was or not? And so, for my opinion, and my opinion was a a selfish one at the time, I'll be honest with you. I was like, well, I'm not giving the fraud training, so clearly it must be subpar, right? No one can teach fraud like I can. Um, I know not in my organization. So, whoever is conducting that fraud training in my organization, they're not the fraud expert. They didn't even ask me to input into the fraud training. So, for me, I said, I haven't seen it. I don't think it's adequate because I haven't seen it and you're not showing me. But that was more of an opinion based on something that I didn't truly know. The question was, does the board receive fraud training? And the answer is yes. There are ways that we could improve, but again, the way that we would say, "Hey, it's not effective at all right now," is if people on the board were falling for fraud scams, they were mixed up in something um that you know, maybe it was some insider issues. Which I just reported on the Monday uh Fraud Fix newsletter where there was an instance where there was a board member who did misappropriate funds. Um, but if that situation wasn't happening in my organization, then I needed to say accurately that yes, there was fraud training and yes, it currently is effective. I couldn't use my opinion. I had to go off of the facts. And that was that was really hard for me because I knew in my heart of hearts I was like, but it could be better. And so I just used that, you know, residual risk response was board currently receives it. However, it's not given by the fraud leader of the organization. Um and there's no um uh there's no insights that are being provided by the fraud leader either. So this is a a situation that it could be improved.
Chen Zamir
Chen Zamir
18:50
You know, I I can relate so much to to what you just said. I think you know what like if you ever worked with me uh you know that you know I'm not uh I don't have the smallest ego in the world. Uh and when when it's like your team, when it's your organization, when you are the one building it, it's like it is very hard to separate your ego from the data that you're there. There are always like, you know, ways to tell stories with data and there are always ways to add these caveats and asterisks and say, "Yeah, the data shows XYZ, but actually ABC." Um, and honestly, this is a bit what I like about coming like into an organization from the outside where where I have no stakes is that it allows me to be like much more um, you know, impartial, but it also, you know, like I can definitely understand why people get defensive uh about these things. So, I I I really related uh uh to this to that story of yours. Tell me a bit. I know maybe that is something that you know would be like learning the ABC for you and your audience but I'm not you know I didn't grow up in uh in banking I grew up in fintech. And it it smells to me like fraud risk assessment is a loaded term that's an actual kind of like you know like a a specific process a specific artifact. What is it and and you know how would you approach a fraud risk assessment today knowing what you know and with your experience that maybe you haven't done the same when you just started.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
20:36
I I love that you asked this question. Um and I actually I have to tell you a funny story and then I'll answer your question. Um I did a presentation on fraud risk assessments um early this year. And um our our really good friend Eduardo I sent him the presentation to just review the slides. And he asked me he goes why would anybody want to do a fraud risk assessment? Now in my mind I was like what do you mean why wouldn't they want to do one? And the fraud risk assessment is the most important thing that you need for your fraud program in order to advocate for things that you need. And I went on this big passionate tangent with him and He goes, "Hailey, I was asking because you didn't answer that in the slides." He was like, "I'm not saying that they're not important. I just needed you to answer it in the slides." And I was like, "Oh, okay. I thought you were saying why would I present on fraud risk assessments when clearly it's the most important thing you could do." So, I I just wanted to share that little caveat. Whenever you asked that just now, it just reminded me of that. Um so for for like the general right a fraud risk assessment should not just tell you know you that you a particular fraud or payment type is is a high-risk fraud. Um you know for example wire fraud is high risk and debit card fraud is high risk. I can uh probably tell you that without spending three months building a a spreadsheet I could tell you that yes debit card fraud is is high risk. Right? I don't have to that's not the purpose of it. The purpose is not to say yes, this is a high-risk item. We know that. But what a fraud risk assessment should answer is where are we exposed? How severe could that exposure be? What controls do we have? How effective are those controls? Where is the residual risk? And and what are we going to do about it? That last question is where I think a lot of fraud risk assessments fall apart. You know, if we complete a fraud risk assessment, assign everything a a red, yellow, or green box, present it to a committee once a year, and nothing operational changes afterwards, then I'm not sure what you accomplish with that. But the assessment should influence where you're spending money, where you're adding controls, where you're monitoring more closely, and where you're accepting risk, and where you're putting people. So, you know, we there's a challenge that I would say, you know, we haven't experienced much fraud in this channel. So, we've rated the inherent risk as low. That's one of the biggest mistakes you can make. Inherent risk is the risk before you consider your controls. So, whenever you think about like check fraud, right? You're going to say, "Well, check fraud, we've done a great job and blah blah blah." No. Look at each check and that you've taken in that's fraudulent or taken in in general. What happens if that check was fraudulent? How exposed would you be if you had absolutely no controls? And you're doing this per scenario, not per uh product. And and that was another thing that I had to learn too because I was looking at like our check fraud losses in general. That doesn't work. You have to look per item, right? A lack of loss doesn't automatically mean that it's a a lack of risk. So maybe you haven't experienced losses uh precisely because your controls are working or maybe fraudsters simply haven't found that weakness yet. Um, but I want to look at things like transaction volume, dollar exposure, customer behavior, uh, product design, speed of funds, movement, authentication methods, external thread intelligence, and what we're seeing across the industry. Historical losses and is an input, but it cannot be the entire risk assessment. Otherwise, we're essentially saying, you know, nothing bad has happened yet, so we're fine. That that's not risk management. We have to look at it holistically. Look to see, okay, here's where we have a gap in our current process. This is something that that would help us going forward if we were to get and that's how you respond back with that residual risk, right? So the inherent risk is how big of a risk it is without any controls. You put your control effectiveness and then that uh residual risk is what you end up with. Um, so it's a really fun exercise for you to do to truly understand where you're where you are exposed, how well a product is performing. And that's the other thing people think that fraud risk and fraud reporting is just telling the bad story. It's like, all right, here's the we know this is where we're going to get our our deep minus, right? This is where we're going to look and see, oh, well, fraud happened. We don't want to ever read this part of the report. No, you've got to show the positive things that happened in it. How well are these controls working? We can see it monthly on our fraud report, but in this annual risk report, we're looking and saying, "Hey, okay, overall, our controls are doing a good job. They could be better, and here's how we how we can make those better, or here's here's where we need additional resource. Here's where we need another tool or something." But you can't automatically say it without providing that backup data.
Chen Zamir
Chen Zamir
25:27
Yeah. So, good. I mean it's uh it's such a great piece of advice and I think uh you know because again that maybe we use different terms but the principles are are the same. Uh many fraud teams that I encounter really fall in this trap of thinking that you know if we're good on this side it will continue to be good forever. Uh and we should not worry about it we should not pay attention. Uh and so on and in reality actually a lot of the times when you have these loss spikes a lot of the times they would come exactly from these points because like the the fronts that you usually pay attention to are also, you know, the fronts where it's harder to surprise you. Uh the fronts where you invested more, uh the fronts where you catch uh loss spikes earlier. And actually, it's the neglected parts of your system, the ones that usually are neglected because you think they are working well that you know many times end up uh biting you on your backside. So yeah, I think that's a great great great piece of advice. I want to circle back to you mentioned a couple of times technology. I kind of like, you know, got the sense in between the lines that you don't see technology as really a solution to fraud strategy gaps. That's that's the the sense that I got. Uh tell me tell me more.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
26:57
Uh yes, I I don't think that a solution is is always the the answer. I don't think that it's always that you have to buy a new technology. And I say that while working for a fraud technology company, uh technology can dramatically improve a strong fraud program. It can also help expose where a program is weak. What it cannot do is magically fix a strategy that doesn't understand the problem that it's trying to solve. You can buy the best fraud platform in the world and still have bad outcomes if your data is poor, your processes are broken, nobody owns the strategy, or your teams don't understand the tool, or you're measuring the wrong items. One of the questions I think every institution should answer before another vendor vendor demo is what problem are we actually trying to solve? Not oh god we need AI. Not hey we need we need real-time fraud detection. What is the problem? Is it account opening fraud? Is it scams? Is it checks, mules, alert volume? You know investigator efficiencies, false positives, data fragmentation. Those are very different problems. But I think like to answer the the other question right of like when does technology actually solve the problem. I think that's when you clearly connect the capability of that technology to the problem. If if analysts spend hours moving between five systems to investigate one case, technology may absolutely solve that. Right. Um I I've seen it myself Money 20/20 last year. I was very excited about Sardine's uh platform where the OSINT was available within the platform. That's the case management. That's something that I didn't have before and something that I struggled with our um chief information officer where or I couldn't go into, you know, the Google searches and and whatnot to use for my case data um and for my investigation. And so having that availability within that, yeah, that's that's a scenario where technology can solve it. If you're missing fraud because your current system can't connect signals across channels, technology could absolutely solve that. If you're generating 50,000 alerts and 49,000 of those are garbage, technology and better modeling may solve that. Yeah, it's so true. Um, if you have no fraud governance, no documented strategy, and nobody can tell me what the institution's highest fraud risk are, buying tool number seven probably isn't going to fix it. I heard um at a fraud conference that we misunderstand what layering is with our technology. Um layering doesn't mean that we simply add another and another and another. It means truly understanding where it fits where your technology piece is. And if a technology isn't working, you don't just buy one to to fix it. I think about um there was a probably I think it's Criminal Minds or NCIS, one of those uh shows where you dive into fraud, right? Or or dive into some kind of criminal case. And they the woman was she started with high blood pressure, took a high blood pressure pill, it caused her to have something else wrong, so she took another pill. Well, that caused another symptom, so she took another pill. And before long, she was taking like 12 pills a day and they were all doing something together that they didn't need to do. And it caused her to have kind of like this mental breakdown, which I feel like that's where we are with our our fraud technology is we just want to keep layering and layering and layering. But that's not what really layering is. Layering doesn't mean we're just adding more. Layering means that we have to understand where it all fits in the overall infrastructure and how well it integrates into those systems and communicates into those systems.
Chen Zamir
Chen Zamir
30:35
Do you can we can we like go one well layer deeper? Uh like I I think this is this is a very very important point. Can you maybe give like a concrete example of how you've seen layering done right in you know in a fraud stack context and you know what were the principles behind that? I think like hearing about that in a bit more detail would be like very enlightening.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
31:05
Yeah, absolutely. So we had a scenario with this was real time uh for us we did for those ATM and mobile banking deposits right we thought okay well we need to add in another product to prevent the fraud right now because what we're using that integrates with our core it's not exactly catching it in real time we're having to do all of this in batch processing. Okay. Well, that wasn't going to work in order to keep us in that proactive preventative fraud strategy, right? So, what we needed to do was first understand where the gaps were potentially within our current integration. Is there something that we're missing? Is there a plug that didn't happen? Is there a scenario where if we just had this one department connect this one piece of the data in, could we then turn this into real time? And by doing so, then do we need another layered partner or could we now allow for additional types of fraud to go through that we could stop? Meaning, could we increase our limit? So instead of saying okay the only capability we have right now is that we can look at one check per account per day and and that's how we can prevent fraud is just by signaling that one. No we can say they could do 10 and we can trust it because we know we're going to use check 21 return data. We're going to use image data analysis and we're going to compare it to all other deposits that have been made into this account. An example of how we would use this. Think about like lawn care companies that are using like they are DBA accounts. So doing business as it's a person's account that's it's tied to their social. They don't necessarily have a business account, but they're doing a side hustle. This is a a DBA lawn care service. When they get paid, they get paid on uh at the end of the week. They get, you know, five checks from different people. We know that any other consumer account we're going to look at and we're going to say I don't know if I trust that. This is this is odd. Why are we depositing so many checks on on this day for odd amounts? Like that doesn't make sense. We want to see how it ties in. And then being able to look at the account overall holistically. We're going to pull data not just from the checks, not just from check 21 return data. We're going to look at the core. We're going to look to see how they're onboarding for their online banking. Is it new? Can we see all of that in one thing? Can we get that holistic picture from one system versus having to go to three different systems in order to get that view? So, that's where for me that I've seen layering work. It's where we are combining it all into one platform versus having layered uh tech stacks that we have to go into the different tech systems in order to to get that full holistic understanding within an investigation. I hope that answered. I know I was kind of long long winded.
Chen Zamir
Chen Zamir
34:00
Yeah. No, no, no. That that was great. I think I mean it exemplifies the fact that actually, you know, going back to like entire theme is technology, you know, part of uh fraud strategy. Is it a tool? Is it a strategy? And I think that it really exemplifies this this example that you gave how much it's not about okay we need capability X. But it is really about doing a gap analysis of your own stack and understand which data points are missing. And are they missing in real time, or are they missing in core, or are they missing wherever. And what vendor can we find that can specifically solve this gap? And how we can weave that into our existing fraud stack? And many times that requires I mean first of of all, it it makes you ask very pointed, very smart questions when you do vendor assessment. And B, it also Go ahead. Go ahead.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
34:56
I was just going to say, yeah, I I think that it's really important too to understand that a good technology partner should be willing to understand your product, your problem before telling you how their product is the answer. They should understand, you know, if if we're talking specifically about bankers, right? They should understand banking operations. They should understand that fraud doesn't live neatly inside one channel. They should understand or they should be able to help you understand your data. Um should be transparent about what their technology can and cannot do. Um and then most importantly, the relationship shouldn't end when that contract is signed. Fraud changes constantly. Your technology partner should be able to help you adapt with it.
Chen Zamir
Chen Zamir
35:40
Yeah, I I absolutely agree. And I think it goes back to like you know the general theme of you cannot really take any shortcuts here. And throwing money at the problem whether this is more technology or whether this is more people in most cases in vast majority of cases would not do much. And you need to do the leg work, you need really to understand what is it that you need. So yeah I agree with this so much I want to ask you all of this sounds pretty straightforward and if you've been in fraud for a few years. Hopefully, you are familiar with these principles. And yeah, you can always learn and get better. But generally speaking, I think it is pretty straightforward. But in the last few years, we are, you know, we are faced with scams. And I think scams more so than the insane spike in losses that we're experiencing since 2022, 2023, it puts a whole different pressure on your fraud stack. It puts a whole different pressure on your fraud strategy. Let's start with why. How come? Like how like why are scams so difficult to deal with?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
36:48
Well, I think it's because um first of all, I'm I'm going to call you out because yeah, I gave you all the hard questions and now you're giving them back to me. So, I appreciate this. Um, I I think that you hit the nail on the head that, you know, this is one of the biggest changes and challenges that fraud programs are are having to make within their um, you know, fraud programs. For years, so much of our fraud infrastructure was built around answering just one question. Is this actually our customer? So, we've got device, password, MFA, biometrics, IP address authentication. Those things still matter tremendously. The problem is that scams introduce another question. Does our customer understand what they're doing? Those are completely different problems. A customer can authenticate perfectly and still be sitting on the phone with someone pretending to be, you know, uh the bank, uh law enforcement, Microsoft, the their grandchild or an investment adviser. The bank can prove with almost complete certainty that you know Haley initiated the transaction, but that doesn't tell you whether Hailey initiated it because somebody convinced her that her money was in danger. So what changes, right? We have to start layering intent and behavior context on top of identity. Is this normal behavior for this customer? Is the destination new? Did they suddenly change contact information? Did they increase limits? Transfer limits. Did they add a new device? Did they move money between accounts immediately before the transaction? Um, you know, are they even draining the account that they've spent 20 years building? Each signal by itself may not mean much, but together they tell a story. And that is where fraud teams have to get much better at looking beyond uh whether an authentication event passed. What? And and then the other thing that we struggle with is what if the customer is insisting this is where it can get really difficult. Uh you cannot completely eliminate scams without creating an incredible amount of friction for legitimate customers. There's always going to be tension between customer autonomy and protecting someone who may be under manipulation. I think the answer is a thoughtful intervention. Someone that or sometimes that means a a target targeted warning. Sometimes it means asking better questions. Sometimes it's a cooling off period. Sometimes it's escalating the transaction to someone trained specifically in scam intervention. And sometimes the customer is still going to say, "It's my money, send it." And then that's where my favorite quote comes in is, "We will not knowingly participate in fraudulent activity." Um, I used that line anytime I couldn't get through to a victim that was very insistent on sending the money. I when I would drop that line, it was it literally was a mic drop moment for me. Um, and and I hated to use it, but when I did, it gave them that cause for a pause that I've talked about before where if if you're trying to conduct a transaction, you've you've talked till you're blue in the face, your bank still won't do it. And then your bank looks at you and says, "We will not knowingly participate in fraudulent activity." you go, am I doing something I'm not supposed to be doing? Um, and when they're like, I'm not fraud. I I'm I know what I'm doing. This transaction follows a pattern of what we know to be fraud in the industry and in other accounts. We know this is fraud. We are not going to allow this to happen. Now, you can't stop them from getting the cash out because it's their money. They can come in and get it, but you can create some of that targeted friction where it's we want you to understand that as your financial institution, we believe this to be fraudulent because we've seen this pattern before. So, we're trying to do our part. Hopefully, whenever you go to leave and you're, you know, the difference between sending a $20,000 wire and walking out of the bank in 20 with $20,000 in cash, that does something to somebody. You know, it makes them pause and think.
Chen Zamir
Chen Zamir
40:49
Yeah, that's a it's a good one. Uh, for sure. I Yeah, I'm just thinking, you know, for us fraud fighters, you know, life would be so much simpler if there would just be no customers. I mean, maybe the business would not like it, but yeah, for us it it would be Yeah. A great a great day uh when businesses can make money without customers. Um,
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
41:12
Yeah. Now, I will say though, I I want to make sure that it's clear. I'm I'm not saying that authentication is becoming less valuable. That that's not the case at all. Authentication answers a very important question of who is doing this. It just doesn't always answer why are they doing it. The mistake is treating successful authentication as proof of intent. And that's where we've got to get better.
Chen Zamir
Chen Zamir
41:36
That's exactly the point where I wanted to go next. I think I see it in FinTech. I definitely see it in banks. Uh I always call it this addiction. Addiction to a binary risk assessment. Either this user is authenticated and good or they are not and we cannot trust uh put our trust in them. And I think scams specifically, not only scams, I think like everything that has to do with, you know, digital banking and e-commerce, like it forces us to be much more mindful to how we manage risk. But scams specifically and you know, authentication is is is a big part of that. And you know the one of the main issues here is that up until scams exploded, our fraud stacks were really geared toward um preventing unauthorized use. But now it's no longer unauthorized, right? It's authorized when you know like stripping back everything that you just outlined to cafe core pillars. Now I'm this, you know, I'm this exact that uh that uh asked you that question at the the beginning of our conversation, but instead of thinking about kind of like unauthorized fraud, I'm thinking about scams from a fraud strategy perspective. What are the pillars that I need to be minded to when I'm suddenly like completely shifting my my view on what fraud is?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
43:08
So the pillars as in what an executive needs to understand or just like the fraud leader?
Chen Zamir
Chen Zamir
43:14
The fraud leader
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
43:15
I think the fraud leader has to understand uh truly. I've always said I'm going to treat every customer like my grandmother, how would I want them, how do I want them to treat her. But at the same time I have to think about the overall business of the organization as well. So I can't just be, the full heart of hearts, I'm going to give them back all the money they've lost to scams, because that's not a good business idea, right? Because then you're going to have the problem that I think we're going to start seeing if we do see that push for scam repayment um from organizations is that we're going to see a lot of the first party fraud that we see currently but they're just going to get the money back. Um I think that we have to look at holistically um for each pillar we have to think about the customer experience. We have to think about the loss of the organization. We have to think about where we can prevent it and where we can get in front of it. Where the only option is truly to just react. Um, and then how do we react? How do we respond? I think that response is the most important part of the the pillar for fraud fighting. It's not just how do you have a conversation with a victim. That's not that's not the only thing that response means, but it's what do we do when we've exposed a gap? How quickly are we responding to that? Do we wait until there's a really big fraud? I I struggled with that as a fraud practitioner because I wanted to go into an executive's office, grab him by both sides of his head, and just shake until he listened to me, right? But you can't do that. Um I I wanted to say, "Hey, we've got a really big exposure." And I did. I tried. I I would write it in memos, and I'd say, "If we don't put this in place right now, we're really exposed." An example was credit card um payments. If we allowed for a credit card payment to go through ACH, we have 60 days that that payment is a vulnerability for us. 60 days that we could have a response back of saying, "Hey, nope. They now say that those were unauthorized. We got to send them back. We have no recourse on that except to go after the individual person." Well, what if you find out that was a synthetic identity? Okay, great. So right now I or at that time I was like, "Hey, there's 60 days that if we're allowing a card to be maxed out, paid off, maxed out, paid off, maxed out, paid off, and they do this consistently two times a week." That and and it's a $10,000 limit. So that's $20,000 a week that we're exposed with one card. If we don't put this particular fraud thing in place, we're we're going to we're really exposed. And it was you got to take a loss before you can make any changes. And that to me was so crazy. And so we lost a hundred and something thousands with one account because that wasn't put in. Now when I wrote up the memo again to then say I told you so. I unfortunately couldn't say I told you so in the memo. I did I did however say on you know this date I advised that this was a potential vulnerability that we should put something in place at the time leadership decided it was not a a priority. Um since then this has happened. This is how we were exposed. This is the loss we're currently sitting at now. Then they took it seriously. So the response, you can't think of the response as just a how do we talk to people, but it's how are we going to respond when we've noticed a gap, when we've noticed that there's a potential vulnerability, how do we ensure that we get that message over to leadership that they are going to be receptive of it? And then how do we move ahead going forward? Again, it's all about that fraud strategy. I'm going to bring in some of your your strategy uh comments.
Chen Zamir
Chen Zamir
46:57
Um I I wonder you know specifically when it comes to scam I think one of the bigger challenges is exactly what you uh just described. Is that sometimes it's very hard to convince the business to do things that supposedly hurt the business performance specifically in scams. Because many times the uh report uh like reporting rate is lower than an unauthorized fraud, right? There's a much higher chance that I will file a charge like if someone stole my credit card than if someone fooled me to be like a handsome marine officer uh stationed in Iraq. Um
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
47:34
Right
Chen Zamir
Chen Zamir
47:35
And I think one of the I mean I would guess that many of your conversations were actually internally not necessarily with leadership but with product folks. Because you know in the end you're not talking about a fraud account that you just block and no one cares about but this is a real customer. It's uh a a loyal customer and b so far a profitable customer and you know that even if you're right even if you are right and it is a scam there's a very high likelihood that the customer would never complain and there would never be a loss. And so it's very easy to product come to come and say you see nothing happened so you were wrong and we we shouldn't have uh put the friction in and so on. How do you manage these kind of conversations which are, you know, sometimes very very difficult and very nuanced.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
48:26
Yeah, I'd say that it starts there's two different ways that I approach it. One is obviously trying to sell the story of the the member or the customer friction. Like better be overprepared than underprepared. Um here's here's what this would look like if we took that loss. They're going to take the loss and then that's on us as their financial institution that we didn't do our part. Um so trying to tell that story. The other thing you mentioned was talking with the business unit owners. That was always a great way for me to get in in front of the executives um just through a third party. So I would go and I'd talk to the e-services director and I'd say, "Hey, this is where there's a potential gap. Your team doesn't like the current risk um analysis that's being performed. They don't trust it. Um they're doing manual reviews of this one parameter because again they don't understand what it means. Um, and so if we can adjust these parameters, give them those guidance, and then let executives say, "Yes, we will, we agree to take a loss, if it's $150 or less, they can automatically approve it. It'll be on us, and it won't count against them." That was a big win for that department that the next time I needed something or I saw a vulnerability, I could go directly to that business unit owner who had the ear of the COO and from there, we were able to make things happen. And it was it was a phenomenal experience. But it's all in how you have the conversation, how you're able to bring in different partners from the organization and allow them to also advocate for your program.
Chen Zamir
Chen Zamir
49:57
How do you, I mean I think this is honestly one of the aspects where I see a lot of fraud fighters struggle with. Because you know I think fraud fighters similarly to probably legal and probably to security are mostly the only functions in an organization that are you know that are the no sayers the nay sayers, right? The business excels marketing product operations customer service. Everybody's like geared towards growth and you know revenue and that's like in the end this is how you are measured. And fraud fraud fighters you know operate almost um it's not orthogonally it's yes it's it is orthogonally to the organization we care about losses supposedly. Um and and I see that many times there's a lot of frustration and a lot of incomprehension of how to even begin such conversations. How do like what's your best advice for fraud fighters that want to approach leadership teams and want to influence them to make a decision that they think is the right decision? How, what's your advice?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
51:16
First is to make sure that executives understand that fraud operations are not just a cost center. We are protecting customers, deposits, reputation, operational capacity, and sometimes people themselves from catastrophic financial harm. I I also think the leadership needs to understand capacity differently. If a fraud team says we're overwhelmed, the answer can't always be, we'll hire another investigator. Yeah, maybe we need another investigator, but also maybe our technology needs tuning. Maybe our processes are inefficient. Maybe we're generating unnecessary uh work upstream. Um or there's another department that's creating fraud exposure downstream. Capacity is is a symptom. I want to understand the the cause. Right? I think that the other thing um that I've learned from the benchmarking work that we've been doing is that fraud teams are doing a lot better than we sometimes give ourselves credit for. You know, we are doing formal fraud risk uh assessments. Institutions are tracking false positives. They are using riskbased queuing. They're investing in technology. There's a there's a level of maturity there that I don't think always gets recognized. Um at the same time, you have teams saying that they are at or beyond capacity. Scams continue again to be one of the biggest concerns. Many institutions still struggle to quantify scam losses accurately. You have fraud teams trying to tell their story to leadership while some of the most important work they do is incredibly difficult to put on a balance sheet. You know, if I stop a $100,000 fraud attempt, everybody agrees that is valuable. The problem is proving that the $100,000 would have actually left the institution without the intervention. You know, that creates like this weird problem where losses are easy to to measure and prevent um and prevention is is hard to measure.
Chen Zamir
Chen Zamir
53:09
Mhm.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
53:10
Then leadership looks at the fraud dashboard and sees $2 million in fraud losses. What they may not see is the $15 million the team prevented. Right.
Chen Zamir
Chen Zamir
53:20
So this needs to be exposed. You're saying?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
53:22
Yes. 100%.
Chen Zamir
Chen Zamir
53:23
In the dashboard. Yeah.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
53:24
Yes.
Chen Zamir
Chen Zamir
53:25
Yeah. Yeah.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
53:26
I I think in the dashboard, one of the things um like I'd want some version of a fraud exposure prevented alongside fraud losses incurred, right? No. And not just the gross fraud loss. Show me the attempted fraud. Show me the prevented fraud. Show me the actual loss. Then give me enough context to understand what happened. If the board only sees losses, we're only showing them the failures. They need to see what the program is stopping. Yes. I would also want that normalized against something meaningful like transaction volume, uh, customer growth, deposits, or whichever denominator makes sense for that institution. A $2 million loss means something very different at a $500 million credit union than it does at a $50 billion bank.
Chen Zamir
Chen Zamir
54:12
Yeah, 100%. I agree with that. I do want to challenge you on one thing. I think that today if you would come to a leadership team or to the board and it would say my investigators are overwhelmed. Their answer is unlikely to be hire another investigator. Their answer is likely to be fire them all and put a very cheap AI instead. What, like, that it works 24/7. Um, how would you like how would you manage this kind of challenge from the leadership team?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
54:45
That's one that I'm still working on. I'll I'll be just completely transparent with you. You and I were actually working on a really cool project that I'm so excited to dive into, and that's really understanding the AI concept of of what can be done. Where is the investigator and the analyst still very valuable to an organization? Bottom line is we will at some point have to implement some type of AI that can help our organization. Fraud is too fast. It it's constantly changing. It's constantly evolving. We're going to have to put something in place to help us. That that's inevitable. That that's happening. What I would say is, um, and one concept that I'm becoming really familiar with, is, you know, we've talked about, um, human feedback in the loop, where it's, we're looking and making sure that the alerts worked and that it scored it the way we wanted it to. That still is not scalable. Instead, we're going to have to start looking at human on the loop where it's policy and governance of that AI system how it's working. So, I'll say to answer your question right now, I can't give you a definitive of what would work in order to help you keep your entire team. What I will say is that if you can go ahead and start looking now at what tech you think you may need in two years, do it. Do the research now. Start looking to see where your team might be more valuable. Maybe they need to develop a new skill that helps them become that person on the loop. Help them now. Point them in the right direction now to keep them as a valuable member of your organization. If you don't want to see uh their growth, you don't need to be in leadership anyways. Um so maybe maybe maybe this isn't the right place for you. But if if you're going to make sure that number one, your team is scalable, that you're going to be able to keep up with tech, they've got to start learning now. They've got to start looking now. I was one of those. I'll be honest, when I was the credit union practitioner, I said, um, we're always going to need the fraud investigator. Yeah, to an extent, yes, that is true. But we are teaching AI to do things a lot faster. And our whole uh thing with fraud is that we want to get to this preventative, proactive fraud uh strategy. We can't do that alone as humans. We are just humans, right? AI and scams and fraud, they move a lot faster. Payments move faster. You know that whenever I get that card alert on my card, if I tried to spend $500 at Walmart and it says, "Hey, did you do this?" A human is not going to be able to do that at scale for all their customers. We have to have these programs and systems in place. And so I the the answer to it today, I can't give you the definitive answer that I would say, but I would say definitely start pouring into your team to allow them to be useful and valuable whenever uh that time comes.
Chen Zamir
Chen Zamir
57:32
Yeah. Well, I said earlier fraud strategies uh can be quite straightforward. Uh but even if it is straightforward, it's still shifting and changing uh because fraud is changing, because the technology is changing, because the business landscape and the products are changing. And so there are always this kind of like these new fronts uh these new uncharted waters that you need to well to chart basically and that's part of the part of the job to an extent. Uh that's why we're risk managers. Uh I always say Hailey, it's been such an interesting conversation. Uh it feels like on one hand we covered a lot of ground and on the other hand we just skimmed the surface. So I uh I definitely love to do that again sometime. Uh but for today I would say it's it's uh it's been a pleasure and I uh can't thank you enough for uh letting me take over the pod for an hour.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
58:31
Yeah, I I'm so stoked that you were able to to be here uh to take over and to allow me to sit in the uh practitioner chair or or the guest chair today. I have I found myself asking, man, I'm doing a lot of interviews, but I I feel like there's an opportunity here where I can provide a little bit more insight. Um so, this was a a great opportunity, and I I appreciate you more than you know.
Chen Zamir
Chen Zamir
59:00
Uh goes Same goes back to you. So, uh yeah, I uh we should definitely do it again.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
59:06
Yes, for sure. Okay, so I'll take the I'll take the microphone back as the host and just say fraud fighters, uh you know, if you want to hear me turn the tables on him, um head over to The Saturday Fraud Strategist um for the other part of this conversation where I was able to turn the tables on him. Um until next time, stay vigilant, stay informed, and keep moving Fraud Forward.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
59:33
Thanks for listening to Fraud Forward. Remember, every conversation, every connection, and every insight moves our industry one step closer to stronger fraud defenses. If today's episode sparked an idea, share it with your team or tag me on LinkedIn. I love hearing how you're moving Fraud Forward in your own organization. Until next time, stay curious, stay resilient, keep moving Fraud Forward