Sardine named a Leader in The Forrester Wave™: Financial Crime Management Solutions, Q3 2026

Learn More
The Saturday Fraud Strategist

El auge de las operaciones de fraude agénticas, parte 3: cómo escalar el análisis del fraude

10 min

Los responsables de riesgos están sometidos actualmente a una gran presión para utilizar la IA con el fin de reducir costes. Reducir costes suele implicar recortar plantilla. En las operaciones de prevención del fraude, en particular, ese impulso genera un punto ciego en los equipos.

Los episodios anteriores de esta serie explicaron cómo es realmente la transformación de unas operaciones antifraude manuales a otras impulsadas por IA. Lo que no abordaron es por qué la analítica del fraude debe ampliarse en paralelo a ese cambio. Hay un efecto de segundo orden que casi nadie tiene en cuenta: cuando un equipo adopta la IA, hay una función que no se reduce, sino que debe crecer. Si la planificación de la plantilla de un equipo antifraude no contempla este aspecto, el resultado será un equipo más pequeño que, en realidad, no estará preparado para supervisar los sistemas automatizados que acaba de implementar.

Eso es el análisis del fraude. No ampliar esta función es lo que hace que la implementación de la IA se convierta silenciosamente en un riesgo mayor que el proceso manual al que sustituyó.

Lo que escucharás en este episodio:

  • Por qué ampliar la capacidad de análisis del fraude es más importante que cualquier otra decisión de dotación de personal en una transformación con IA, y por qué la mayoría de los equipos lo plantea al revés.
  • Por qué la mayoría de los equipos antifraude se dividen en cuatro funciones: operaciones antifraude, análisis del fraude, estrategia antifraude y ciencia de datos aplicada al fraude. Y por qué casi ninguno cuenta con personal suficiente en las cuatro áreas.
  • Por qué las operaciones antifraude y el análisis del fraude responden de manera opuesta a la adopción de la IA.
  • Existe una diferencia real entre revisar una decisión individual de un agente y supervisar un proceso totalmente automatizado a gran escala.
  • Cómo se manifiesta realmente en la práctica un fallo silencioso en un flujo de trabajo y por qué los sistemas automatizados no avisan cuando algo ha salido mal.
  • Por qué la automatización de la redacción de reglas sigue requiriendo revisión humana y qué debe detectar dicha revisión.
  • Cómo la monitorización de KPI en sistemas automatizados y el análisis de causas raíz en sistemas de fraude son competencias que los equipos antifraude ya poseen, pero aplicadas a un nuevo objetivo.
  • En qué aspectos suele fallar la reestructuración de los equipos antifraude para la IA durante las revisiones trimestrales. Por qué ocurre cuando no se establecen umbrales de error y cuando las auditorías se realizan mensualmente en lugar de semanalmente.
  • Por qué los analistas de fraude, y no los investigadores ni los ingenieros, se están convirtiendo en los nuevos líderes de los equipos de IA.
  • Cómo abordar la planificación del presupuesto del equipo de fraude durante esta transición, incluido el financiamiento del crecimiento del área de analítica con los ahorros generados en las operaciones antifraude.

Deberías escuchar este episodio si:

  • Lideras un equipo de prevención del fraude que está planificando o ya se encuentra inmerso en una transformación basada en IA, pero aún no has definido qué ocurrirá con la función de análisis de datos
  • Están bajo presión para reducir la plantilla del equipo de fraude y necesitan un argumento claro que demuestre por qué esa lógica no se sostiene
  • Han implementado o están a punto de implementar IA agéntica para investigaciones, etiquetado o redacción de reglas, y quieren comprender la brecha de gobernanza que la mayoría de los equipos pasa por alto
  • Están preparando para el consejo una propuesta presupuestaria para el equipo de fraude y necesitan argumentos que vinculen el ahorro de costes con las áreas en las que realmente debería reinvertirse
  • Buscan un marco práctico para diseñar la estructura organizativa del equipo antifraude que contemple la supervisión de todo el flujo de trabajo, no solo la revisión de casos individuales
  • Se preguntan si su función de análisis de fraude tiene la capacidad adecuada para la automatización que ya utilizan o para la que están a punto de incorporar
Notas del episodio y conclusiones clave

Por qué la mayoría de los equipos se equivoca al decidir cuándo escalar el análisis del fraude

La suposición habitual al emprender una transformación con IA es que todas las funciones se reducen. El trabajo de investigación —esas tareas de treinta minutos que pasan a hacerse en cinco— es precisamente lo que los agentes automatizan bien. Como es natural, ese equipo se vuelve más reducido. El error que conviene señalar es aplicar la misma lógica al análisis del fraude. La comparación entre las operaciones antifraude y el análisis del fraude no trata de cómo la automatización reduce todo por igual, sino de cómo el trabajo se traslada de un equipo a otro.

El problema de gobernanza que se esconde tras el «funciona bien»

Revisar la recomendación de un agente sobre un caso concreto es una habilidad que los equipos antifraude ya poseen. Es similar a revisar el trabajo de un analista júnior. La verdadera carencia está en la gobernanza a nivel de pipeline: supervisar los sistemas de etiquetado, los motores de recomendación de reglas y los procesos de entrenamiento de modelos que funcionan de forma continua y que nunca se diseñaron para revisarse caso por caso. El fallo silencioso del pipeline es el riesgo que realmente debe tomarse en serio, porque estos sistemas no emiten ninguna alerta cuando algo va mal. Un agente que etiqueta incorrectamente no se detiene, sino que sigue funcionando hasta que alguien acaba detectando el daño.

El análisis de la causa raíz no desaparece, simplemente pasa a un nivel superior

Los equipos de fraude ya saben cómo hacer este trabajo. La supervisión de los KPI de los sistemas automatizados y el análisis de las causas raíz en los sistemas de fraude son competencias nuevas. Se basan en los mismos instintos que los analistas de fraude siempre han aplicado a una regla o un modelo, solo que ahora se enfocan en una nueva capa. Incluso en el mejor de los casos, cuando un agente redacta una regla de forma totalmente autónoma, una persona debe confirmar que ha superado todas las pruebas, que no contradice la lógica de negocio existente y que no se basa en una coincidencia estadística. Si esto se multiplica por cada sistema automatizado que utiliza un equipo, la cuestión pasa a ser si alguien está haciendo un seguimiento de la frecuencia con la que los analistas han tenido que intervenir para corregir algo fundamental. Si esa cifra aumenta y nadie la vigila, así es precisamente como un programa de prevención del fraude se vuelve menos seguro mientras que, sobre el papel, parece estar más automatizado.

Cómo se manifiesta realmente el fracaso en la práctica

Se pone en marcha por completo un sistema de investigación basado en agentes, pero el equipo de analítica sigue dimensionado para un entorno en el que las reglas se revisan trimestralmente. Este es el patrón de fracaso más habitual. No se ha establecido ningún umbral de tasa de error para el proceso de etiquetado. Las reglas se auditan mensualmente en lugar de semanalmente. El equipo acaba teniendo más automatización, pero no un ciclo de respuesta más rápido y, en algunos casos, un sistema realmente menos estable que antes de la llegada de la IA. No se trata de un fallo tecnológico, sino de no haber ampliado la gobernanza al mismo ritmo que la automatización.

Financiar esto de la manera adecuada

Los ahorros derivados de un equipo de operaciones antifraude más reducido no deberían diluirse en una partida general de recorte de costes, sino destinarse directamente a ampliar las capacidades de analítica de fraude. Más allá de la lógica financiera, esta es también una de las vías más realistas para conservar el conocimiento institucional, en lugar de perder por completo a profesionales con experiencia durante una transformación. La cifra que finalmente se presente al consejo de administración puede ser más alta de lo que nadie esperaba al principio, y aun así merece la pena plantearla. En una sola frase para esa conversación: los analistas de fraude se están convirtiendo en los nuevos líderes de los equipos de IA. No los investigadores ni los ingenieros. Y esa es la evolución de funciones que exige este momento.

Conclusión final

Ampliar el equipo de analítica de fraude no es algo opcional que se añade si el presupuesto lo permite; es la decisión de dotación de personal que determina si una transformación con IA funciona de verdad o si, silenciosamente, hace que un programa de prevención del fraude sea menos seguro. Reducir el equipo de operaciones de fraude es la parte fácil y evidente de esta historia. Ampliar el equipo de analítica de fraude es la parte que casi nadie planifica, y es la que determina si todo el sistema se mantiene en pie.

Los equipos que lo hagan bien no serán los que hayan automatizado más rápido. Serán los que hayan ampliado su capacidad de supervisión al mismo ritmo que su automatización y hayan financiado ese crecimiento de forma deliberada, en lugar de descubrir la carencia después de que algo ya haya fallado.

Recursos y enlaces

Esto forma parte de una serie. Si has llegado aquí primero, quizá te convenga volver atrás y escuchar los episodios anteriores. Ya hemos tratado bastantes temas que harán que este episodio sea mucho más fácil de seguir.

Ponte al día con El auge de las operaciones de fraude agéntico, parte 1
Ponte al día con El auge de las operaciones de fraude agéntico, parte 2

¿Aún no quieres dejar de hablar de mi tema favorito y, espero, también del tuyo? Suscríbete al boletín The Saturday Fraud Strategist.

Conecta con Chen Zamir | LinkedIn
Presentador de The Saturday Fraud Strategist
Ayudo a las fintech a crear defensas contra el fraude más inteligentes
Coautor de «The Fraud Fighter’s AI Playbook»

Episode transcript
Chen Zamir
Chen Zamir
00:06
We started this series by talking about the pressure all risk leaders are facing right now. Use AI to cut costs and by cutting cost I mean cutting headcount. But in fraud operations the push for automation also creates a risk. What happens when teams cut the very function needed to govern automated systems? In the previous episode in this series, we outlined what a transformation journey looks like when you move from mostly manual operations to AI powered ones. And as we've discussed, there's a lot of nuance to it, because it's not a switch you just flip. It's a journey with a specific sequence and dependencies. But one thing I didn't cover previously is how you establish AI governance as you implement more and more AI automation. Specifically, there's a second order effect almost nobody's planning. One function on your team doesn't shrink with AI adoption. On the contrary, it actually needs to grow. Because automation creates new oversight requirements that most teams do not have staff today. And if you don't account for it, you'll end up with a smaller team that isn't equipped to govern all the automated systems it runs. And let me tell you that would not end well. That function is fraud analytics. And without it, your system would break faster than you'd like to think. It is the control layer that catches drift, monitors automated decisions, and prevents silent pipeline failures. So in this video, I want to talk about how fraud teams usually look like, what AI governance really means, and what it means to your future organization.
Chen Zamir
Chen Zamir
01:43
In my experience, most fraud teams are built from four functions. Now, I will say in our industry, terms and definitions are very loose. Even the word fraud might mean different things to different people or even the same person when considering different contexts. So it might be that you've seen other names or other organizational structures to this. The point I'm trying to make is around co responsibilities and skill sets an organization holds, rather than how it's actually structured or named. So bear with me. Anyway, back to the four functions I usually see. The first is fraud ops which handles investigations. Reviewing alerts, making rulings, managing chargebacks, and so on. The second is fraud analytics which owns rules and monitoring. Writing detection logic, tracking performance, analyzing attack patterns and producing reports. The third is fraud strategy that sets the risk appetite, risk policies and are likely in charge of vendor selection and architecture. And the fourth and last is data science that builds and maintains machine learning and AI models. But as I mentioned, not every fraud organization has all four. And there are a few reasons for that. First, it might be that some of these responsibilities simply don't exist. Not every organization develops their own AI models, for example. In other cases, especially in smaller organizations, some responsibilities are simply held by the team leader. For example, fraud strategy. It doesn't have to be its own function. So in effect, the bare minimum for a fraud team and what you'll almost always say is just one function, fraud ops. Meaning you can run a fraud function even if probably inefficiently with nothing more than investigators reviewing alerts. At the same time, fraud analytics exists in a lot of midsize and larger teams, but it's often informal or undersized. And that creates a potential oversight gap when these teams begin using AI agents to label cases, suggest rules, cluster alerts, all the things we talked about in the previous episodes. Meaning, if you need analytical skills to monitor agentic powered fraud systems, most teams are behind where they should be. And if you're thinking of downsizing them even more, then you might be risking self-sabotage when adopting AI at the same time. Because here's the thing, the traditional fraud analyst role was already important, but in an AI powered fraud team, it becomes central. Why do I think we'll need a bigger fraud analytics function in the age of agentic AI? In one word, governance.
Chen Zamir
Chen Zamir
04:29
Not all agentic AI creates the same kind of work. And understand the difference is what explains why certain functions on your team grow while others shrink. When fraud teams first roll out Agentic AI, they typically start with investigation assistance. The agent assembles the case and proposes a resolution and the investigator reviews and approves. Which means that this workflow isn't so different from managing a junior analyst. The agent does the leg work and the investigator uses their judgment to validate. And that's the thing, your team already knows how to do that. Governing individual decisions over individual cases is something your team members already do today. But fully automated pipelines are different. Auto labeling uh case clustering, rule recommendations, model training, these decisions operate at scale. They run continuously and you cannot have humans running around after agents because that would slow you down. Exactly the opposite of what you want to achieve. But the problem is that these pipelines can still fail. And when they do, they fail silently. A labeling agent that starts misclassifying doesn't raise its hand. It keeps labeling until someone checks. A rule built on a coincidental correlation looks fine in the back test. This system fails silently. They fail at scale and they fail fast. Unlike a human investigator who notices when something uh feels off, an automated pipeline doesn't feel anything. It just continues to run and spew garbage. But the governance these pipelines need is the same kind of monitoring fraud teams already apply today. KPIs, monitoring, alerting, systematic performance review, and most importantly, being able to run a root cause analysis when something breaks so you are able to fix it. Not just say that it's wrong. Does any of that sound familiar? Observing system performance through data, noticing issues, understanding what causes them, and fixing them, that's the job of fraud analytics.
Chen Zamir
Chen Zamir
06:33
What is the takeaway from looking at those two governing approaches? The obvious assumption when you start rolling out Agentic AI is that you can downsize your fraud team. But that is only correct for one function, fraud ops. For another, fraud analytics, it's not that simple. In fact, for most teams, it'll have to be exactly the opposite. Why? Because investigators benefit most directly from what AI agents automate. The part of their day that consumed the most time pulling transaction details, running IP lookups, checking device history, cross reference accounts. That's exactly what agents handle, an investigation. Simply put, the efficiency gains are straightforward because what used to take 30 minutes now takes five. Naturally, the function needs fewer people. But fraud analytics on the other hand, and as we just discussed, is different. Right now the team observes data, compiles reports, write rules when new attacks emerge and tweak score cut offs when needed. But when agents take over those tasks, all the automated pipelines we just described become their responsibility as well. Now you might think, but wouldn't I be automating the analysts jobs too? And you'll be right thinking that. But you need to remember that while some of the work is now automated, all the new automation you deployed both in analytics and in operations will now fall under their responsibility as well. Let's take rule writing as an example. Even if we reach an ideal state where agents write rules from scratch completely autonomously, which is definitely a stretch goal, your human analysts still have to review them. They need to check that the rules proposed went through all the tests correctly, that they don't contradict your business logic, and that they are not based on shaky statistics. That's still work, and it's only the start because we're still making individual decisions over single rules. But we also need to monitor how well the agents are proposing rules as a whole. How many times have the analysts corrected something fundamental? Did this number grow since last month? And if so, why? And how can we fix it? And this is just one example of how tasks that don't exist today will land in fraud analytics. And take into account that by the time you'll get to monitor your rules recommendation agents, you probably implemented at least five to 10 other systems. So all of them would need monitoring as well.
Chen Zamir
Chen Zamir
09:01
Hopefully, the argument I've outlined for why you'd actually need more analysts when you start automating has been convincing thus far. But the sad reality is that many teams don't have a fully fledged analytics team and so are likely blind to their repercussions. If you don't manage existing automated pipelines today or if engineering does it for you, odds are you have a blind spot there. And so when such teams come under cost pressure, it's very easy to commit to cutting the function that you actually need to enable AI adoption. It's all too easy to get to a point where your agentic investigation systems goes live, cases are being assembled, labels are being generated, and rules are being proposed. But the analytics team is still sized for quarterly rule reviews. And then the labeling pipeline has no error rate thresholds. The rule recommendation audits happen once a month when it should be happening weekly. So your fraud system is more automated, but your reaction cycle isn't faster. Even worse, your system is less stable and less safe than it was before. Why? Because we scaled automation without scaling governance. And that's exactly the recipe for failed AI adoption projects. Because it's easy to forget that redesigning your system means also redesigning your team and not just cutting it.
Chen Zamir
Chen Zamir
10:23
In the first episode in this series, I stressed that redesigning your fraud prevention system will come at a cost and that you'd want to fund it through the cost cutting you achieve. Part of that cost and only one part is making sure your team is properly staffed in the fraud analytics department and that you can increase its size as you go through the transformation journey. To an extent, it means that the savings you make from the shrinking fraud ops team should fund the growth of fraud analytics. And this can also be a way to upscale and retain some of the headcount instead of losing all of the institutional knowledge entirely. Of course, it might be that the target budget figure you show your board is higher than what they or you anticipated at first, but it's mandatory to build the function the new system depends on most because we should expect fraud teams to have a new bare minimum makeup. Investigative capabilities will continue to be part of it, but not all of it. In addition to that, teams will have to include strong analytical functions to operate its agentic workers, monitor automated pipelines, evaluate recommendations, and maintain your system stability as a whole. Or to frame it simply, think of it like that. Fraud analysts will be your new AI team leaders. That's the framing your board would understand.