Sardine named a Leader in The Forrester Wave™: Financial Crime Management Solutions, Q3 2026

Learn More
FRAUDFORWARD
#119

不正対策プログラムの構築方法:基盤に潜む不正

59 min

不正対策に取り組む皆さん、こんにちは!「Fraud Forward」へおかえりなさい!

今日は私がゲスト席に座っています。

今回のエピソードと同時に公開された『The Saturday Fraud Strategist』をお聴きになった方は、Chen Zamirと私が役割を入れ替えることにしたのをご存じでしょう。彼がFraud Forwardに出演して私にインタビューし、私は彼の番組に出演して彼にインタビューしました。私たちは一緒にラスベガスで開催されるMoney 20/20に向かう予定で、その幕開けにぴったりの楽しい企画だと思ったのです。

私は普段、多くの時間を質問する側として過ごしています。マイクの反対側に座るのはまた違った経験ですし、Chenは簡単な質問をしてくれません。この対話は、私が予想していなかった方向へと展開しました。最後には、実効性のある不正対策プログラムをどう構築するか、そして何より、その妨げとなるものは何かについて議論しました。

1年にわたって不正対策に取り組み、ベンダーや人員に費用をかけてきたにもかかわらず、結局は振り出しに戻ったまま——そんな組織に足を踏み入れた経験があるなら、今回のエピソードはあなたのためのものです。解決策は、単にツールをもう一つ追加すればよいというほど単純ではありません。

このエピソードでお届けする内容:

  • 問題を抱えているにもかかわらず、その原因を誰も説明できない組織に着任した際、不正対策プログラムの評価をどのように構築するか
  • 不正対策とリスク管理では、まず人、次にプロセス、テクノロジー、データの順で取り組むべき理由と、多くの組織がテクノロジーから着手して問題をさらに増やしてしまう理由
  • 実務担当者として、必要な人員数を経営陣に示すために私が構築した不正対策のキャパシティ計画モデル。アラート1件あたり3分という計算や、チームが実際に行うすべての業務を考慮した週40時間のモデルを構築する方法も含みます
  • あらゆる最適化に着手する前に不正対策チームの体制が重要となる理由と、人材採用やツール導入を始める前に、中央集権型と分散型のどちらを選ぶべきかを判断する方法
  • 不正対策責任者のプログラムにおいて最も重要なツールだと私が考える、不正リスク評価のフレームワーク。固有リスクと残余リスクの違いや、損失が発生していないからといってリスクがないとは限らない理由も含みます
  • 不正対策テクノロジーを誤って重ね合わせることが、相互作用の悪い薬を併用するようなものになる理由と、ベンダーのデモを受ける前に実施すべき不正対策テクノロジーのギャップ分析とは実際にどのようなものか
  • 送金承認型詐欺が、「これは本当に当社の顧客なのか」という一つの問いを軸に構築された不正対策の仕組みをいかに機能不全に陥らせるのか、そして詐欺検知に用いる行動シグナルには、なぜまったく異なるアプローチが必要なのか
  • 私が実務家として用いていた銀行の詐欺介入フレームワーク。対象を絞った手続き上のハードルやクーリングオフ期間、そして私が「決め台詞」と呼ぶフレーズも含まれます
  • 経営陣がダッシュボード上の損失額だけを見て、チームが防いだ1,500万ドルを見落としている場合に、私が不正対策について経営層とどのようにコミュニケーションを取り、不正対策プログラムの重要性を訴えるか
  • 私が望む不正ダッシュボードのレポートモデル:不正の試行額、不正の防止額、実損失額を、単なる不正損失の総額ではなく、取引量または預金残高に対して正規化して示すもの
  • 不正検知AIにおけるヒューマン・イン・ザ・ループがスケールしない理由と、今、不正対策チームのスキル開発にとってヒューマン・オン・ザ・ループが意味すること
  • 私が取り組んできたベンチマーキング調査から見た不正対策プログラムの実際の成熟度と、不正対策チームが自分たちで思っている以上に成果を上げている理由

次のような方は、ぜひこのエピソードをお聴きください:

  • 不正対策プログラムを新たに構築、または再構築しており、教科書的なフレームワークではなく、私が実務家として実際に用いたプロセスを通じて、ゼロからどのように取り組むのかを知りたい方
  • 不正防止の実務を十分に理解していない経営陣に対して、人員、テクノロジー、予算の必要性を説明した経験があり、データに基づいてその妥当性を示せるモデルを求めている方
  • 銀行や信用組合に勤務し、不正利用の傾向が、本人の承認を伴わない不正から、本人が送金を承認してしまうプッシュペイメント詐欺やその他の詐欺へと移行する中でプレッシャーを感じており、不正対策システムをどのように適応させるべきか分からない方
  • 実務担当者として私が手作業で構築した不正対策のキャパシティ計画モデル、アラート1件あたり3分という計算、そして経営陣をようやく納得させた週40時間の内訳を知りたい
  • 長年かけて育成してきた調査担当者を失うことなく、不正対策プログラムにAIをどう組み込むべきか模索している
  • 不正対策チームを率いており、私が金融機関を対象に実施してきたベンチマーキング調査に基づいて、自社の不正対策プログラムの成熟度が実際にどの水準にあるのかを知りたい
  • チームに不正損失の真の要因を尋ねても誰も答えられず、その話し合いを始めるためのより良い切り口が必要だと感じたことがある
エピソードノート

チームが問題点を把握できていない場合の不正対策プログラム評価

不正損失だけでなく、不正の内訳を把握するための質問をしましょう。不正の内訳に変化はありましたか?損失の中心がカード不正から詐欺へ移りましたか?不正対策チームに知らされないまま、新しいデジタル商品がリリースされましたか?取引量は増加しましたか?アラート件数は実際の不正件数を上回るペースで増加しましたか?どこかの対策によって、不正が別のチャネルへ移っただけではありませんか?

多くの場合、苦境に陥っているチームは、そうした質問に答えることができません。もし答えられるのであれば、そもそも今のような窮地には陥っていないでしょう。これは批判ではなく、状況を診断するための指標です。私が何かを提案する前に確認したいのは、不正対策が、ルールが最初に策定された3年、4年、あるいは5年前の不正パターンではなく、その金融機関が現在直面している不正の実態を本当に反映しているかどうかです。

実務担当者向け不正対策キャパシティ計画モデル

これは、私が最も誇りに思っているフレームワークの一つで、AIが代わりに作ってくれるようになる前に、私自身が手作業で構築したものです。このモデルは、「チームがアラート1件あたりに費やす時間はどのくらいか?」というシンプルな問いから始まります。推定値ではなく、実測値です。

私のチームでは、1分未満で解決する簡単なアラートと、調査に5分を要する複雑なアラートの折衷案として、1件あたり3分と設定しました。そのうえで、対応したアラートの件数、そのうち案件化した件数、案件ごとの調査に費やした時間、チームが対応した電話の件数、個別メッセージや社内コミュニケーションに費やした時間、詐欺被害者への対応に費やした時間、そしてプロセスや手順の策定に費やした時間を記録しました。

これらすべてを週40時間の勤務時間に照らして計算し、スタッフの人数を掛け合わせると、リソースの不足がすぐに明らかになります。また、ほとんどのキャパシティモデルでは考慮されない、年間の専門研修要件やCPE(継続的専門教育)、その他の業務も組み込みました。その結果、チームにさらなるリソースが必要であることだけでなく、その理由を1時間単位で経営陣に証明できる資料が完成しました。不正対策チームのリーダーが支援を求める際には、データに基づく必要があります。単に「手が回らない」と訴えるだけでは不十分です。計算で示すことが重要なのです。

不正リスク評価のフレームワーク

私の考えでは、不正対策プログラムが必要なリソースや施策の必要性を訴えるうえで、不正リスク評価は最も重要なものです。しかし、ほとんどの不正リスク評価は適切に実施されていません。

目的は、電信送金詐欺のリスクが高いことを確認することではありません。業界関係者なら誰もがすでに知っていることです。目的は、次の4つの具体的な問いに答えることです。どこにリスクが存在するのか。そのリスクはどの程度深刻になり得るのか。どのような統制策があり、それらはどの程度有効なのか。そして、残余リスクにどう対処するのか。

最後の質問こそ、多くの評価が形骸化してしまうポイントです。評価を完了し、赤・黄・緑の判定を付け、年に一度委員会に報告しても、実務上何も変わらないのであれば、その取り組みには何の成果もありません。

固有リスクとは、統制を一切考慮する前のリスクです。残余リスクとは、統制を適用した後に残るリスクです。多くのチームが犯す間違いは、過去の損失実績に基づいて固有リスクを評価することです。損失が発生していないからといって、リスクがないとは限りません。統制が機能しているということかもしれませんし、詐欺を企てる者がまだその弱点を見つけていないだけかもしれません。小切手詐欺の例で考えると、より具体的に理解できます。もし、金融機関がこれまで受け付けた小切手がすべて不正なもので、しかも統制がまったくなかったとしたら、小切手1件当たりどの程度の損失にさらされるでしょうか。それが固有リスクです。過去の損失実績ではありません。

承認済みプッシュ型決済詐欺は、不正対策の仕組みが前提としてきたものを根底から覆す

長年にわたり、私の不正対策基盤は「操作しているのは本当に当社の顧客なのか?」という問いを中心に構築されてきました。デバイス、パスワード、多要素認証(MFA)、生体認証、IPアドレス認証は、いずれもこの問いに答えるものです。しかし詐欺では、認証では答えられないもう一つの問いが生じます。それは、「顧客は自分が何をしているのか理解しているのか?」という問いです。取引を開始したのが顧客本人であることは、ほぼ確実に証明できます。しかし、それだけでは、誰かに「あなたのお金が危険にさらされている」と信じ込まされた結果、その取引を開始したのかどうかは何も分かりません。

詐欺検知に用いる行動シグナルは、これとは異なる仕組みで機能します。これはこの顧客にとって通常の行動でしょうか?送金先は新規でしょうか?最近、連絡先情報を変更したでしょうか?送金限度額を引き上げたでしょうか?新しいデバイスを追加したでしょうか?取引の直前に口座間で資金を移動したでしょうか?20年かけて築いてきた口座の資金を使い果たそうとしているのでしょうか?個々のシグナルだけでは、大きな意味を持たないかもしれません。しかし、それらを組み合わせることで、一つのストーリーが浮かび上がります。そして、そのストーリーを読み解くには、私が認証を中心に構築してきたものとはまったく異なるアプローチが必要です。

不正対策責任者とのコミュニケーションと、AIが不正対策をどう変えるか

取締役会が不正による損失しか見ていないのであれば、目にしているのは失敗だけです。プログラムによってどれだけの不正を阻止できているのかも把握する必要があります。私が求める不正対策ダッシュボードのモデルには、不正の試行件数、未然に防いだ不正、実際の損失を含め、それらを取引量、顧客数の増加、預金残高などの意味のある指標に照らして標準化します。200万ドルの損失でも、資産規模5億ドルの信用組合と500億ドルの銀行とでは、その意味が大きく異なります。損失は簡単に測定できますが、未然防止の効果を測るのは困難です。ダッシュボードにはその両方を表示しなければなりません。そうでなければ、経営陣は全体像の半分しか見ていないことになります。

率直に申し上げます。AIによって不正調査担当者の役割がどう変わるのかについて、私にはまだ明確な答えがありません。ただし、進むべき方向ははっきりしています。調査担当者がAIの判断を一件ずつ確認・検証する「ヒューマン・イン・ザ・ループ」は、規模の拡大に対応できません。今後は、個々の出力を確認するのではなく、チームがAIシステムの方針策定と監督を担う「ヒューマン・オン・ザ・ループ」へと役割が移っていくでしょう。不正対策チームへの私からの助言は、今すぐ学び始めることです。2年後に自分たちのプログラムで必要になりそうなテクノロジーを見極め、その環境で調査担当者が価値を発揮するためのスキルを今から身につけてください。人間の力だけでは、予防的かつ先回りした不正対策には到達できません。その時が来たときに備えられるよう、今からチームの育成に力を注がなければなりません。

重要なポイント
  • 不正対策プログラムを構築するには、テクノロジーや人員を増やせば解決すると決めつける前に、なぜ損失が発生しているのかを理解することから始める必要があります。解決策を提案する前に、不正の内訳、アラートの件数、統制を設ける箇所をすべて把握しなければなりません。
  • 私の不正対策キャパシティ計画モデルでは、アラート1件あたり3分を起点に、週40時間の業務全体を可視化し、感情的に訴えるのではなく、データに基づいて経営陣にリソース不足を示します。
  • 不正リスク評価において最も誤解されやすいのが、不正に関する固有リスクと残余リスクの違いです。過去に損失が発生していないからといって、固有リスクが存在しないとは限りません。統制が有効に機能している可能性もあれば、不正を企てる者がまだ脆弱性を見つけていないだけかもしれません。
  • 不正対策テクノロジーのレイヤリングとは、何かがうまく機能しないたびに新たなツールを追加することではなく、各要素がどこに位置づけられ、どのように連携するかを理解することです。ベンダーのデモを受ける前に行う不正対策テクノロジーのギャップ分析こそが、効果的なレイヤリングと、相互作用に問題のある薬の併用とを分けるものです。
  • 承認済みプッシュ決済詐欺では、不正利用者による未承認の詐欺とはまったく異なる観点で考える必要があります。認証によって本人であることは確認できますが、その意思までは確認できません。そのギャップを埋めるのが、詐欺検知に用いる行動シグナルです。
  • 私が経営層向けに不正対策の成果を伝える際に用いるフレームワークでは、防止できた不正被害額と実際の損失額を並べ、取引量などの意味のある指標に対する比率として示します。プログラムが実際にどのような成果を上げているのかを理解するには、経営陣が両方の数値を把握する必要があります。
  • 今、不正対策チームのスキル開発で重視すべきなのは、ヒューマン・オン・ザ・ループです。AIシステムをポリシーレベルで統制するには、個々のアラートを確認するのとは異なるスキルが求められます。その能力を育成すべき時は、まさに今です。
最後に押さえておきたいポイント

今回、Chenは私に厳しい質問を投げかけてくれましたが、そうしてくれて本当によかったと思います。最終的に交わしたのは、まさに今、より多くの不正対策責任者が自社内で行うべきだと私が考えている対話でした。不正対策プログラムの構築は、一度きりで終わる取り組みではありません。現在地を評価し、何が成果を左右しているのかを理解し、自社の戦略が5年前に直面していた不正ではなく、今まさに起きている不正をきちんと反映しているかを確認し続ける継続的なプロセスです。この対話から、今週チームに持ち帰れることが一つでもあるとすれば、次のツールを購入する前にいったん立ち止まり、自分たちが解決しようとしている問題を本当に理解しているのかを問い直してもよいのだ、という気づきであってほしいと思います。

私がチェンに逆に質問を投げかける様子を聞きたい方は、The Saturday Fraud Strategistでこの対談の後半をお楽しみください。

次回まで、警戒を怠らず、常に情報を収集し、不正対策を前進させ続けましょう。

エピソードの参考資料とリンク:

Connect with Chen Zamirとつながる | LinkedIn
「The Saturday Fraud Strategist」ホスト
フィンテック企業による、よりスマートな不正対策の構築を支援
『The Fraud Fighter’s AI Playbook』共著者

つながる:Hailey Windham, CFCS | LinkedIn
Fraud Forward Podcast ホスト
Sardine バンキングコミュニティ責任者
認定金融犯罪スペシャリスト(CFCS)
2023年 Credit Union Rockstar(CU Magazine)
2023年 Continuous Improvement Award(SAFE Federal Credit Union)
2022年「40歳未満のプロフェッショナル トップ20」(The Sumter Item)

Episode transcript
Chen Zamir
Chen Zamir
00:05
What's up, fraud fighters? I'm Hailey. No, you know what? I'm tired of this charade. Uh, the tokens cost me too much. Uh, being like a fake uh fake blonde with a fake southern accent. I cannot afford it any longer. And I want to admit it's been me all this time. Uh, Chen Zamir. No. Uh, just kidding. Hailey, it's so great to be uh on your show as a guest interviewer. How are you?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
00:34
I am doing so well and I'm I'm so glad that the the truth has finally come out and I mean come on.
Chen Zamir
Chen Zamir
00:40
Yes.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
00:41
It's really been you this entire time.
Chen Zamir
Chen Zamir
00:44
Yes. You know, well, uh I thought uh tokens would be cheaper than uh wigs, but apparently that's not the case. So, I'm done with that.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
00:53
I'm just so glad you agreed to to come in on my podcast as well. We just uh recorded the reverse interview on yours and now we're kind of uh flipping the script again and letting you take the lead on the podcast on on Fraud Forward.
Chen Zamir
Chen Zamir
01:09
Yes, absolutely. And if you didn't catch uh the episode of the Saturday Fraud Strategist, uh Hailey and I spoke about why we're doing all of that. And that is because I'm actually not exactly sure when this episode is going to drop, but probably a couple of weeks after you're listening to this, we are heading to Vegas uh to participate in Money20/20. Hailey, do you want to uh uh give the juice about it?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
01:34
Yeah, I am so stoked. Um last year I went to Money20/20 and um I got lost everywhere I went in the Venetian. Um so I'm really excited to do that again. Uh but this year I will have a partner in crime. Chen Zamir and I will be at uh the Sardine booth. We will be recording podcasts throughout uh the the days um of Money 20/20. And we'll also just kind of be floating around having great conversations with people, hosting a happy hour or two. And I'm just I'm really excited and looking forward to to that time where we can meet in person um and then people can experience the magic of us uh live in in Vegas.
Chen Zamir
Chen Zamir
02:12
It's just me. We just said it. It's just me. There's no Yeah. Yeah. There's no Hailey.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
02:17
There is no Hailey.
Chen Zamir
Chen Zamir
02:23
Yeah. You know, it's a funny thing because I I was just trying to think. I was in in Money 20/20 Vegas once and in my mind it was always like around 2018 2019 and I couldn't quite recall. But one thing that I like that really stuck to my memory is that I remember staying uh back then uh at the Trump Tower and I remember that being like just before the elections and I said well that doesn't make sense because in 2018 2019 Trump was already president and I was like going through my through my uh phone pictures uh like the other day and I realized that actually I've been there in 2016. It was two months before the elections. Yeah. And actually that would mean that I'm now returning to Money 20/20 Vegas after a full decade. So that's a bit of a mindblower.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
03:16
Yeah.
Chen Zamir
Chen Zamir
03:17
Yeah.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
03:17
You're showing your age there.
Chen Zamir
Chen Zamir
03:20
Uh yeah. Yeah. Uh okay. First question. No. Okay. So I'm super stoked about uh by the way we will meet for the first time uh in person in Vegas. So I'm I'm yeah I'm really looking forward to it and and a bunch of other uh Sardine folks. So yeah I hope to see you all there. Um I want to go uh directly into the topics that I wanted to speak about today Hailey and you know uh I speak a lot about fraud strategy and somehow we never got to talk about it. So I like I'm super curious because you know I had a lot of different conversations with a lot of different folks when it comes to you know fraud strategy and especially when you go into like a new organization. And you've said both you know wearing a hat of a practitioner wearing the hat of a consultant wearing the hat of uh of now a vendor um and you you kind of like you know you need to quite quickly understand what's the what's the state. Uh what is going well and maybe where are the gaps and and and try to kind of like you know give advice or you know like give some guidelines or you know like make your plan as to how best to go about it. And when I talk to like fraud strategists I always hear different answers but around the same principle. So you know I I wanted to start with that and kind of like hear where you stand and how you work. So let's say for the manner of the example let's say that you're you know you're going into organization and an executive tells you look we've you know we've invested in fraud a lot. We've hired more folks. We integrated a couple of vendors. We've been fighting it for a year. We're pretty much at the same place. What how would you go about it?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
05:20
Well, I think it's a matter of obviously understanding where they are. You have to look at, you know, we're going to talk a little bit more about risk assessments, but trying to understand fully holistically, right? What they have, what products and services they have, where their exposure could be. I'd also want to ask like if if nothing has changed or if if losses are increasing, right, and and your teams are overwhelmed and it's like do we throw more resources at it? Do we throw more money at tech? But I don't think that's where we need to do. That's what we need to do. I, you know, I I would never immediately assume that any organization needs another tool or another person. I want to understand what's driving whatever fraud increase that they may have. You know, did the the did the fraud mix change? Did losses move from card fraud into scams? Did a new digital product launch that you didn't tell your fraud team about? Did transaction volume grow? That never happens, right? Um,
Chen Zamir
Chen Zamir
06:17
Never.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
06:18
Did alert volume grow faster than like actual fraud? Did we introduce a control somewhere that just shifted fraud into another channel? Because that happens a lot too. Then I want to, you know, look at the program from different angles that from risk from people, process, technology, and data. A lot of organizations start with technology because that's the easiest thing to point to. We're losing money so we need a better fraud tool maybe. Or maybe the tool is generating perfectly good alerts and you don't have enough people to work them. Maybe you have enough people but they're spending 70% of their time clearing false positives. Maybe your rules were designed around fraud patterns from three, four, five, 10 years ago, right? And and maybe nobody has stepped up and asked whether your fraud strategy actually reflects the fraud that you're seeing today. And that's where I think, you know, good risk assessment becomes incredibly valuable.
Chen Zamir
Chen Zamir
07:15
You know my like I agree 100% with everything that you said. I would say that my general experience is that when you ask these smart questions to a team that is struggling usually the answers would be I don't know. Or the answer the singular answer would be I don't know because if they would be able to answer these questions most likely they wouldn't be in that hole. So, you know, what do you do in, you know, in this instance where, and I'm guessing that, you know, maybe maybe some of our listeners right now, you know, also have exactly the same thing that, you know, they they see the pressure, but they don't necessarily have the ability to really understand exactly what's going on. How like what would be the best piece of advice to such teams
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
08:05
In regards to like pressure testing?
Chen Zamir
Chen Zamir
08:08
Not necessarily pressure testing, but like you know, let's say, you know, they see that their fraud rates are up, but they don't necessarily know how many false positives they have. They don't necessarily know from which flow it arrives. They don't necessarily know, you know, how much of that was missed by the investigators versus how much of that was missed by rules. So because usually if you know if if they would have the foresight to ask and answer these questions usually they would also be able to kind of like optimize around these things. So what happens in the case where you know you you just get blank stares when you ask these kind of questions which which I'm guessing happens from time to time.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
08:51
Oh it definitely happens from time to time. That's why I always uh I think culture matters so much in whatever organization you're at. For me, whenever I was a practitioner, it was I didn't understand not only the infrastructure because I was new coming into that role to build a fraud program. So, I didn't understand the infrastructure completely for the organization, but I also didn't know anyone really in the organization. But they knew that I was the girl that was going to stop transactions because I was in fraud. So, I was going to implement rules. I was going to create processes that just made everyone hate their lives. Um, and I was basically going to come in like a bull in a china shop. It was the perceived uh notion of of what I was doing there, what my role was. So instead, I focused on number one making friends in the organization. And I don't mean by offering to take them out to lunch, but I mean by truly sitting down with the the workers. So, I would go to e-services and instead of going directly to the director, I went to the people hitting the button every day, the ones that were working in PIK um which was our um basically a digital channel for like check deposits um and they and ATM deposits. And so I went and sat with them and I said, "Hey, explain this process to me." And when they saw that I was somebody that actually wanted to not only understand the process first, but then help and make sure that we're creating process efficiencies as well. Which is what I think works really well for fraud uh programs. Anyways, if you kind of structure yourself with that operational hat in which the benchmark report that we have coming out um hopefully this week, hopefully it will be live before this uh this recording comes out. But what you'll see in in the benchmarking is that a lot of fraud professionals and financial institutions came from the operations uh department or operations side of the organization which is a great thing because they understand the payment method. They understand where in our infrastructure is the last point of interception before the fraud leaves right where's our last point of contact where we can say okay we don't want this to happen. So anyways, whenever you're you're going in and you're understanding the infrastructure, you're creating process efficiencies before you even look to say, "Hey, what things do we need to implement to prevent fraud?" That's where you're going to see a lot of good things happen for your organization as a whole. When it comes to preventing fraud, it's developing that culture and making sure that you understand the process yourself before trying to implement any kind of changes, even new tech. You know, you don't want to do that until you fully understand the tech that you currently have.
Chen Zamir
Chen Zamir
11:19
Yeah, I love that because it, you know, goes to show that, you know, nothing beats data and if you don't have data, nothing beats leg work, right? So,
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
11:29
Yeah, and I think I hope I answered that question for you.
Chen Zamir
Chen Zamir
11:33
No, no, definitely. Definitely. I think cuz in the end you you need to get this data right uh and going to the source, you know, in these kind of situations there there's nothing that can really replace that.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
11:45
Yeah.
Chen Zamir
Chen Zamir
11:46
And it takes time and effort, but it is what it is. Um I wonder you know we talked a lot about uh data and the product and the operations or processes side. I wonder when it comes to the organization itself what do you think like how do you how do you assess the organization itself? How it's built? How it is you know accounting for ownership? How it is measured? Um how um you know what kind of skill sets or how do you do hiring or train like how do you look at the organizational piece when it comes to fraud strategy is it part of fraud strategy in your mind or is it something completely different
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
12:31
No 100% I think also you have to answer the question are you a centralized fraud program or a decentralized fraud program. Centralized is all the fraud comes to you you handle all the disputes all the chargebacks everything like that that comes directly through you where decentralized is you're kind of sitting as this advisory level of here's how we should here's how I would here's what I'm learning from the industry and where we can improve this particular fraud scenario. Right? Or or however it happens in your organization. Um and once you have that answer then it makes it easier for you to basically figure out where where you are. If you're looking at um your staffing your current staffing you can't just say, "Hey, I need another fraud analyst." That's not going to work. You have to show the the data for why you need another analyst. Do a capacity planning model. What I did, um, and this was a very manual process back in my day before, um, before we had AI that could do these things for us, and which most organizations won't really allow you to, um, implement these things right now. Anyways, um what I would do is I literally pulled all of our alerts and I would say, "Okay, how often or how much time are you spending per alert?" And we came up with an average minute time frame. So, some some alerts you could go through really quickly, but be within a minute. There were others that you had to actually dive in and look at and they'd be five minutes. So, we came to a compromise of three minutes and we would go through and we'd see how many alerts we had, how many that were worked, right? And then we would compare that and put it in a timestamp of okay, we have 40 hours a week. Here's how much time is allocated to these alerts. Here's how many of those alerts actually produced a case. By the way, case investigation, how much time are we spending per case investigation? Then you have to consider how many phone calls are we getting each each month? How or week? Um how many uh times are we getting a private message on whether it's Teams or Slack or whatever your organization is using. How much time is spent answering those? How much time is spent on a phone call with a victim trying to deescalate a situation and talk them down? How much time is spent developing processes and procedures? And whenever you calculate all of those things and you put it in a 40-hour week and you times it by however many people you have on your staff, you quickly find out, hey, we're we we've got some big gaps here. If we don't fill it, this is how we can prove that. We also did it. We also included like our professional training. So if you're required to have a certain number of CPEs a year, we we did it as an annual total, not just a weekly total. But we're able to then prove to executives that even these things that we have to have factor into how much time is needed because we can't just assume, hey, guess what? We can turn on this new alert, but how many alerts is that going to create for your team to work? Run a test first. See how many if you're cutting it on, if it's got a particular parameter that you're wanting to use, go ahead and let that test run and see how many would have alerted. Check to make sure you have the capacity to fill that in before turning it on. Otherwise, you're just creating more um more instances where you are going to be drowning and it's because of your own demise.
Chen Zamir
Chen Zamir
15:46
Yeah, I love it how again it all comes back to you know how you can quantify different facets of your program whether these are the processes, the organization, uh the technology. And what I love about it is that you know it makes our domain right at least when you approach it in the right way. It makes it very unemotional right I mean there are no opinions here it's just you know what the data tells us and what we want to or how do we want to react to that? Uh and and I really like this approach. Um
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
16:24
Yeah, I I will say I love that you mentioned the opinion aspect. Um one of the things that I struggled with when building my fraud risk assessment, I was trying to understand it. I would go back to my risk officer, which she wasn't a lot of help. So I had to go to one of the associations and found me the most amazing mentor um who guided me through what a fraud risk assessment is. And one of my main questions that I brought up to my chief risk officer at the time was, okay, here's a here's a part on our risk assessment that says, um, the board receives fraud training. Well, the answer to that is yes, they do, but is it effective fraud training and how could I quantify what it was or or how effective it was or not? And so, for my opinion, and my opinion was a a selfish one at the time, I'll be honest with you. I was like, well, I'm not giving the fraud training, so clearly it must be subpar, right? No one can teach fraud like I can. Um, I know not in my organization. So, whoever is conducting that fraud training in my organization, they're not the fraud expert. They didn't even ask me to input into the fraud training. So, for me, I said, I haven't seen it. I don't think it's adequate because I haven't seen it and you're not showing me. But that was more of an opinion based on something that I didn't truly know. The question was, does the board receive fraud training? And the answer is yes. There are ways that we could improve, but again, the way that we would say, "Hey, it's not effective at all right now," is if people on the board were falling for fraud scams, they were mixed up in something um that you know, maybe it was some insider issues. Which I just reported on the Monday uh Fraud Fix newsletter where there was an instance where there was a board member who did misappropriate funds. Um, but if that situation wasn't happening in my organization, then I needed to say accurately that yes, there was fraud training and yes, it currently is effective. I couldn't use my opinion. I had to go off of the facts. And that was that was really hard for me because I knew in my heart of hearts I was like, but it could be better. And so I just used that, you know, residual risk response was board currently receives it. However, it's not given by the fraud leader of the organization. Um and there's no um uh there's no insights that are being provided by the fraud leader either. So this is a a situation that it could be improved.
Chen Zamir
Chen Zamir
18:50
You know, I I can relate so much to to what you just said. I think you know what like if you ever worked with me uh you know that you know I'm not uh I don't have the smallest ego in the world. Uh and when when it's like your team, when it's your organization, when you are the one building it, it's like it is very hard to separate your ego from the data that you're there. There are always like, you know, ways to tell stories with data and there are always ways to add these caveats and asterisks and say, "Yeah, the data shows XYZ, but actually ABC." Um, and honestly, this is a bit what I like about coming like into an organization from the outside where where I have no stakes is that it allows me to be like much more um, you know, impartial, but it also, you know, like I can definitely understand why people get defensive uh about these things. So, I I I really related uh uh to this to that story of yours. Tell me a bit. I know maybe that is something that you know would be like learning the ABC for you and your audience but I'm not you know I didn't grow up in uh in banking I grew up in fintech. And it it smells to me like fraud risk assessment is a loaded term that's an actual kind of like you know like a a specific process a specific artifact. What is it and and you know how would you approach a fraud risk assessment today knowing what you know and with your experience that maybe you haven't done the same when you just started.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
20:36
I I love that you asked this question. Um and I actually I have to tell you a funny story and then I'll answer your question. Um I did a presentation on fraud risk assessments um early this year. And um our our really good friend Eduardo I sent him the presentation to just review the slides. And he asked me he goes why would anybody want to do a fraud risk assessment? Now in my mind I was like what do you mean why wouldn't they want to do one? And the fraud risk assessment is the most important thing that you need for your fraud program in order to advocate for things that you need. And I went on this big passionate tangent with him and He goes, "Hailey, I was asking because you didn't answer that in the slides." He was like, "I'm not saying that they're not important. I just needed you to answer it in the slides." And I was like, "Oh, okay. I thought you were saying why would I present on fraud risk assessments when clearly it's the most important thing you could do." So, I I just wanted to share that little caveat. Whenever you asked that just now, it just reminded me of that. Um so for for like the general right a fraud risk assessment should not just tell you know you that you a particular fraud or payment type is is a high-risk fraud. Um you know for example wire fraud is high risk and debit card fraud is high risk. I can uh probably tell you that without spending three months building a a spreadsheet I could tell you that yes debit card fraud is is high risk. Right? I don't have to that's not the purpose of it. The purpose is not to say yes, this is a high-risk item. We know that. But what a fraud risk assessment should answer is where are we exposed? How severe could that exposure be? What controls do we have? How effective are those controls? Where is the residual risk? And and what are we going to do about it? That last question is where I think a lot of fraud risk assessments fall apart. You know, if we complete a fraud risk assessment, assign everything a a red, yellow, or green box, present it to a committee once a year, and nothing operational changes afterwards, then I'm not sure what you accomplish with that. But the assessment should influence where you're spending money, where you're adding controls, where you're monitoring more closely, and where you're accepting risk, and where you're putting people. So, you know, we there's a challenge that I would say, you know, we haven't experienced much fraud in this channel. So, we've rated the inherent risk as low. That's one of the biggest mistakes you can make. Inherent risk is the risk before you consider your controls. So, whenever you think about like check fraud, right? You're going to say, "Well, check fraud, we've done a great job and blah blah blah." No. Look at each check and that you've taken in that's fraudulent or taken in in general. What happens if that check was fraudulent? How exposed would you be if you had absolutely no controls? And you're doing this per scenario, not per uh product. And and that was another thing that I had to learn too because I was looking at like our check fraud losses in general. That doesn't work. You have to look per item, right? A lack of loss doesn't automatically mean that it's a a lack of risk. So maybe you haven't experienced losses uh precisely because your controls are working or maybe fraudsters simply haven't found that weakness yet. Um, but I want to look at things like transaction volume, dollar exposure, customer behavior, uh, product design, speed of funds, movement, authentication methods, external thread intelligence, and what we're seeing across the industry. Historical losses and is an input, but it cannot be the entire risk assessment. Otherwise, we're essentially saying, you know, nothing bad has happened yet, so we're fine. That that's not risk management. We have to look at it holistically. Look to see, okay, here's where we have a gap in our current process. This is something that that would help us going forward if we were to get and that's how you respond back with that residual risk, right? So the inherent risk is how big of a risk it is without any controls. You put your control effectiveness and then that uh residual risk is what you end up with. Um, so it's a really fun exercise for you to do to truly understand where you're where you are exposed, how well a product is performing. And that's the other thing people think that fraud risk and fraud reporting is just telling the bad story. It's like, all right, here's the we know this is where we're going to get our our deep minus, right? This is where we're going to look and see, oh, well, fraud happened. We don't want to ever read this part of the report. No, you've got to show the positive things that happened in it. How well are these controls working? We can see it monthly on our fraud report, but in this annual risk report, we're looking and saying, "Hey, okay, overall, our controls are doing a good job. They could be better, and here's how we how we can make those better, or here's here's where we need additional resource. Here's where we need another tool or something." But you can't automatically say it without providing that backup data.
Chen Zamir
Chen Zamir
25:27
Yeah. So, good. I mean it's uh it's such a great piece of advice and I think uh you know because again that maybe we use different terms but the principles are are the same. Uh many fraud teams that I encounter really fall in this trap of thinking that you know if we're good on this side it will continue to be good forever. Uh and we should not worry about it we should not pay attention. Uh and so on and in reality actually a lot of the times when you have these loss spikes a lot of the times they would come exactly from these points because like the the fronts that you usually pay attention to are also, you know, the fronts where it's harder to surprise you. Uh the fronts where you invested more, uh the fronts where you catch uh loss spikes earlier. And actually, it's the neglected parts of your system, the ones that usually are neglected because you think they are working well that you know many times end up uh biting you on your backside. So yeah, I think that's a great great great piece of advice. I want to circle back to you mentioned a couple of times technology. I kind of like, you know, got the sense in between the lines that you don't see technology as really a solution to fraud strategy gaps. That's that's the the sense that I got. Uh tell me tell me more.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
26:57
Uh yes, I I don't think that a solution is is always the the answer. I don't think that it's always that you have to buy a new technology. And I say that while working for a fraud technology company, uh technology can dramatically improve a strong fraud program. It can also help expose where a program is weak. What it cannot do is magically fix a strategy that doesn't understand the problem that it's trying to solve. You can buy the best fraud platform in the world and still have bad outcomes if your data is poor, your processes are broken, nobody owns the strategy, or your teams don't understand the tool, or you're measuring the wrong items. One of the questions I think every institution should answer before another vendor vendor demo is what problem are we actually trying to solve? Not oh god we need AI. Not hey we need we need real-time fraud detection. What is the problem? Is it account opening fraud? Is it scams? Is it checks, mules, alert volume? You know investigator efficiencies, false positives, data fragmentation. Those are very different problems. But I think like to answer the the other question right of like when does technology actually solve the problem. I think that's when you clearly connect the capability of that technology to the problem. If if analysts spend hours moving between five systems to investigate one case, technology may absolutely solve that. Right. Um I I've seen it myself Money 20/20 last year. I was very excited about Sardine's uh platform where the OSINT was available within the platform. That's the case management. That's something that I didn't have before and something that I struggled with our um chief information officer where or I couldn't go into, you know, the Google searches and and whatnot to use for my case data um and for my investigation. And so having that availability within that, yeah, that's that's a scenario where technology can solve it. If you're missing fraud because your current system can't connect signals across channels, technology could absolutely solve that. If you're generating 50,000 alerts and 49,000 of those are garbage, technology and better modeling may solve that. Yeah, it's so true. Um, if you have no fraud governance, no documented strategy, and nobody can tell me what the institution's highest fraud risk are, buying tool number seven probably isn't going to fix it. I heard um at a fraud conference that we misunderstand what layering is with our technology. Um layering doesn't mean that we simply add another and another and another. It means truly understanding where it fits where your technology piece is. And if a technology isn't working, you don't just buy one to to fix it. I think about um there was a probably I think it's Criminal Minds or NCIS, one of those uh shows where you dive into fraud, right? Or or dive into some kind of criminal case. And they the woman was she started with high blood pressure, took a high blood pressure pill, it caused her to have something else wrong, so she took another pill. Well, that caused another symptom, so she took another pill. And before long, she was taking like 12 pills a day and they were all doing something together that they didn't need to do. And it caused her to have kind of like this mental breakdown, which I feel like that's where we are with our our fraud technology is we just want to keep layering and layering and layering. But that's not what really layering is. Layering doesn't mean we're just adding more. Layering means that we have to understand where it all fits in the overall infrastructure and how well it integrates into those systems and communicates into those systems.
Chen Zamir
Chen Zamir
30:35
Do you can we can we like go one well layer deeper? Uh like I I think this is this is a very very important point. Can you maybe give like a concrete example of how you've seen layering done right in you know in a fraud stack context and you know what were the principles behind that? I think like hearing about that in a bit more detail would be like very enlightening.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
31:05
Yeah, absolutely. So we had a scenario with this was real time uh for us we did for those ATM and mobile banking deposits right we thought okay well we need to add in another product to prevent the fraud right now because what we're using that integrates with our core it's not exactly catching it in real time we're having to do all of this in batch processing. Okay. Well, that wasn't going to work in order to keep us in that proactive preventative fraud strategy, right? So, what we needed to do was first understand where the gaps were potentially within our current integration. Is there something that we're missing? Is there a plug that didn't happen? Is there a scenario where if we just had this one department connect this one piece of the data in, could we then turn this into real time? And by doing so, then do we need another layered partner or could we now allow for additional types of fraud to go through that we could stop? Meaning, could we increase our limit? So instead of saying okay the only capability we have right now is that we can look at one check per account per day and and that's how we can prevent fraud is just by signaling that one. No we can say they could do 10 and we can trust it because we know we're going to use check 21 return data. We're going to use image data analysis and we're going to compare it to all other deposits that have been made into this account. An example of how we would use this. Think about like lawn care companies that are using like they are DBA accounts. So doing business as it's a person's account that's it's tied to their social. They don't necessarily have a business account, but they're doing a side hustle. This is a a DBA lawn care service. When they get paid, they get paid on uh at the end of the week. They get, you know, five checks from different people. We know that any other consumer account we're going to look at and we're going to say I don't know if I trust that. This is this is odd. Why are we depositing so many checks on on this day for odd amounts? Like that doesn't make sense. We want to see how it ties in. And then being able to look at the account overall holistically. We're going to pull data not just from the checks, not just from check 21 return data. We're going to look at the core. We're going to look to see how they're onboarding for their online banking. Is it new? Can we see all of that in one thing? Can we get that holistic picture from one system versus having to go to three different systems in order to get that view? So, that's where for me that I've seen layering work. It's where we are combining it all into one platform versus having layered uh tech stacks that we have to go into the different tech systems in order to to get that full holistic understanding within an investigation. I hope that answered. I know I was kind of long long winded.
Chen Zamir
Chen Zamir
34:00
Yeah. No, no, no. That that was great. I think I mean it exemplifies the fact that actually, you know, going back to like entire theme is technology, you know, part of uh fraud strategy. Is it a tool? Is it a strategy? And I think that it really exemplifies this this example that you gave how much it's not about okay we need capability X. But it is really about doing a gap analysis of your own stack and understand which data points are missing. And are they missing in real time, or are they missing in core, or are they missing wherever. And what vendor can we find that can specifically solve this gap? And how we can weave that into our existing fraud stack? And many times that requires I mean first of of all, it it makes you ask very pointed, very smart questions when you do vendor assessment. And B, it also Go ahead. Go ahead.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
34:56
I was just going to say, yeah, I I think that it's really important too to understand that a good technology partner should be willing to understand your product, your problem before telling you how their product is the answer. They should understand, you know, if if we're talking specifically about bankers, right? They should understand banking operations. They should understand that fraud doesn't live neatly inside one channel. They should understand or they should be able to help you understand your data. Um should be transparent about what their technology can and cannot do. Um and then most importantly, the relationship shouldn't end when that contract is signed. Fraud changes constantly. Your technology partner should be able to help you adapt with it.
Chen Zamir
Chen Zamir
35:40
Yeah, I I absolutely agree. And I think it goes back to like you know the general theme of you cannot really take any shortcuts here. And throwing money at the problem whether this is more technology or whether this is more people in most cases in vast majority of cases would not do much. And you need to do the leg work, you need really to understand what is it that you need. So yeah I agree with this so much I want to ask you all of this sounds pretty straightforward and if you've been in fraud for a few years. Hopefully, you are familiar with these principles. And yeah, you can always learn and get better. But generally speaking, I think it is pretty straightforward. But in the last few years, we are, you know, we are faced with scams. And I think scams more so than the insane spike in losses that we're experiencing since 2022, 2023, it puts a whole different pressure on your fraud stack. It puts a whole different pressure on your fraud strategy. Let's start with why. How come? Like how like why are scams so difficult to deal with?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
36:48
Well, I think it's because um first of all, I'm I'm going to call you out because yeah, I gave you all the hard questions and now you're giving them back to me. So, I appreciate this. Um, I I think that you hit the nail on the head that, you know, this is one of the biggest changes and challenges that fraud programs are are having to make within their um, you know, fraud programs. For years, so much of our fraud infrastructure was built around answering just one question. Is this actually our customer? So, we've got device, password, MFA, biometrics, IP address authentication. Those things still matter tremendously. The problem is that scams introduce another question. Does our customer understand what they're doing? Those are completely different problems. A customer can authenticate perfectly and still be sitting on the phone with someone pretending to be, you know, uh the bank, uh law enforcement, Microsoft, the their grandchild or an investment adviser. The bank can prove with almost complete certainty that you know Haley initiated the transaction, but that doesn't tell you whether Hailey initiated it because somebody convinced her that her money was in danger. So what changes, right? We have to start layering intent and behavior context on top of identity. Is this normal behavior for this customer? Is the destination new? Did they suddenly change contact information? Did they increase limits? Transfer limits. Did they add a new device? Did they move money between accounts immediately before the transaction? Um, you know, are they even draining the account that they've spent 20 years building? Each signal by itself may not mean much, but together they tell a story. And that is where fraud teams have to get much better at looking beyond uh whether an authentication event passed. What? And and then the other thing that we struggle with is what if the customer is insisting this is where it can get really difficult. Uh you cannot completely eliminate scams without creating an incredible amount of friction for legitimate customers. There's always going to be tension between customer autonomy and protecting someone who may be under manipulation. I think the answer is a thoughtful intervention. Someone that or sometimes that means a a target targeted warning. Sometimes it means asking better questions. Sometimes it's a cooling off period. Sometimes it's escalating the transaction to someone trained specifically in scam intervention. And sometimes the customer is still going to say, "It's my money, send it." And then that's where my favorite quote comes in is, "We will not knowingly participate in fraudulent activity." Um, I used that line anytime I couldn't get through to a victim that was very insistent on sending the money. I when I would drop that line, it was it literally was a mic drop moment for me. Um, and and I hated to use it, but when I did, it gave them that cause for a pause that I've talked about before where if if you're trying to conduct a transaction, you've you've talked till you're blue in the face, your bank still won't do it. And then your bank looks at you and says, "We will not knowingly participate in fraudulent activity." you go, am I doing something I'm not supposed to be doing? Um, and when they're like, I'm not fraud. I I'm I know what I'm doing. This transaction follows a pattern of what we know to be fraud in the industry and in other accounts. We know this is fraud. We are not going to allow this to happen. Now, you can't stop them from getting the cash out because it's their money. They can come in and get it, but you can create some of that targeted friction where it's we want you to understand that as your financial institution, we believe this to be fraudulent because we've seen this pattern before. So, we're trying to do our part. Hopefully, whenever you go to leave and you're, you know, the difference between sending a $20,000 wire and walking out of the bank in 20 with $20,000 in cash, that does something to somebody. You know, it makes them pause and think.
Chen Zamir
Chen Zamir
40:49
Yeah, that's a it's a good one. Uh, for sure. I Yeah, I'm just thinking, you know, for us fraud fighters, you know, life would be so much simpler if there would just be no customers. I mean, maybe the business would not like it, but yeah, for us it it would be Yeah. A great a great day uh when businesses can make money without customers. Um,
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
41:12
Yeah. Now, I will say though, I I want to make sure that it's clear. I'm I'm not saying that authentication is becoming less valuable. That that's not the case at all. Authentication answers a very important question of who is doing this. It just doesn't always answer why are they doing it. The mistake is treating successful authentication as proof of intent. And that's where we've got to get better.
Chen Zamir
Chen Zamir
41:36
That's exactly the point where I wanted to go next. I think I see it in FinTech. I definitely see it in banks. Uh I always call it this addiction. Addiction to a binary risk assessment. Either this user is authenticated and good or they are not and we cannot trust uh put our trust in them. And I think scams specifically, not only scams, I think like everything that has to do with, you know, digital banking and e-commerce, like it forces us to be much more mindful to how we manage risk. But scams specifically and you know, authentication is is is a big part of that. And you know the one of the main issues here is that up until scams exploded, our fraud stacks were really geared toward um preventing unauthorized use. But now it's no longer unauthorized, right? It's authorized when you know like stripping back everything that you just outlined to cafe core pillars. Now I'm this, you know, I'm this exact that uh that uh asked you that question at the the beginning of our conversation, but instead of thinking about kind of like unauthorized fraud, I'm thinking about scams from a fraud strategy perspective. What are the pillars that I need to be minded to when I'm suddenly like completely shifting my my view on what fraud is?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
43:08
So the pillars as in what an executive needs to understand or just like the fraud leader?
Chen Zamir
Chen Zamir
43:14
The fraud leader
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
43:15
I think the fraud leader has to understand uh truly. I've always said I'm going to treat every customer like my grandmother, how would I want them, how do I want them to treat her. But at the same time I have to think about the overall business of the organization as well. So I can't just be, the full heart of hearts, I'm going to give them back all the money they've lost to scams, because that's not a good business idea, right? Because then you're going to have the problem that I think we're going to start seeing if we do see that push for scam repayment um from organizations is that we're going to see a lot of the first party fraud that we see currently but they're just going to get the money back. Um I think that we have to look at holistically um for each pillar we have to think about the customer experience. We have to think about the loss of the organization. We have to think about where we can prevent it and where we can get in front of it. Where the only option is truly to just react. Um, and then how do we react? How do we respond? I think that response is the most important part of the the pillar for fraud fighting. It's not just how do you have a conversation with a victim. That's not that's not the only thing that response means, but it's what do we do when we've exposed a gap? How quickly are we responding to that? Do we wait until there's a really big fraud? I I struggled with that as a fraud practitioner because I wanted to go into an executive's office, grab him by both sides of his head, and just shake until he listened to me, right? But you can't do that. Um I I wanted to say, "Hey, we've got a really big exposure." And I did. I tried. I I would write it in memos, and I'd say, "If we don't put this in place right now, we're really exposed." An example was credit card um payments. If we allowed for a credit card payment to go through ACH, we have 60 days that that payment is a vulnerability for us. 60 days that we could have a response back of saying, "Hey, nope. They now say that those were unauthorized. We got to send them back. We have no recourse on that except to go after the individual person." Well, what if you find out that was a synthetic identity? Okay, great. So right now I or at that time I was like, "Hey, there's 60 days that if we're allowing a card to be maxed out, paid off, maxed out, paid off, maxed out, paid off, and they do this consistently two times a week." That and and it's a $10,000 limit. So that's $20,000 a week that we're exposed with one card. If we don't put this particular fraud thing in place, we're we're going to we're really exposed. And it was you got to take a loss before you can make any changes. And that to me was so crazy. And so we lost a hundred and something thousands with one account because that wasn't put in. Now when I wrote up the memo again to then say I told you so. I unfortunately couldn't say I told you so in the memo. I did I did however say on you know this date I advised that this was a potential vulnerability that we should put something in place at the time leadership decided it was not a a priority. Um since then this has happened. This is how we were exposed. This is the loss we're currently sitting at now. Then they took it seriously. So the response, you can't think of the response as just a how do we talk to people, but it's how are we going to respond when we've noticed a gap, when we've noticed that there's a potential vulnerability, how do we ensure that we get that message over to leadership that they are going to be receptive of it? And then how do we move ahead going forward? Again, it's all about that fraud strategy. I'm going to bring in some of your your strategy uh comments.
Chen Zamir
Chen Zamir
46:57
Um I I wonder you know specifically when it comes to scam I think one of the bigger challenges is exactly what you uh just described. Is that sometimes it's very hard to convince the business to do things that supposedly hurt the business performance specifically in scams. Because many times the uh report uh like reporting rate is lower than an unauthorized fraud, right? There's a much higher chance that I will file a charge like if someone stole my credit card than if someone fooled me to be like a handsome marine officer uh stationed in Iraq. Um
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
47:34
Right
Chen Zamir
Chen Zamir
47:35
And I think one of the I mean I would guess that many of your conversations were actually internally not necessarily with leadership but with product folks. Because you know in the end you're not talking about a fraud account that you just block and no one cares about but this is a real customer. It's uh a a loyal customer and b so far a profitable customer and you know that even if you're right even if you are right and it is a scam there's a very high likelihood that the customer would never complain and there would never be a loss. And so it's very easy to product come to come and say you see nothing happened so you were wrong and we we shouldn't have uh put the friction in and so on. How do you manage these kind of conversations which are, you know, sometimes very very difficult and very nuanced.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
48:26
Yeah, I'd say that it starts there's two different ways that I approach it. One is obviously trying to sell the story of the the member or the customer friction. Like better be overprepared than underprepared. Um here's here's what this would look like if we took that loss. They're going to take the loss and then that's on us as their financial institution that we didn't do our part. Um so trying to tell that story. The other thing you mentioned was talking with the business unit owners. That was always a great way for me to get in in front of the executives um just through a third party. So I would go and I'd talk to the e-services director and I'd say, "Hey, this is where there's a potential gap. Your team doesn't like the current risk um analysis that's being performed. They don't trust it. Um they're doing manual reviews of this one parameter because again they don't understand what it means. Um, and so if we can adjust these parameters, give them those guidance, and then let executives say, "Yes, we will, we agree to take a loss, if it's $150 or less, they can automatically approve it. It'll be on us, and it won't count against them." That was a big win for that department that the next time I needed something or I saw a vulnerability, I could go directly to that business unit owner who had the ear of the COO and from there, we were able to make things happen. And it was it was a phenomenal experience. But it's all in how you have the conversation, how you're able to bring in different partners from the organization and allow them to also advocate for your program.
Chen Zamir
Chen Zamir
49:57
How do you, I mean I think this is honestly one of the aspects where I see a lot of fraud fighters struggle with. Because you know I think fraud fighters similarly to probably legal and probably to security are mostly the only functions in an organization that are you know that are the no sayers the nay sayers, right? The business excels marketing product operations customer service. Everybody's like geared towards growth and you know revenue and that's like in the end this is how you are measured. And fraud fraud fighters you know operate almost um it's not orthogonally it's yes it's it is orthogonally to the organization we care about losses supposedly. Um and and I see that many times there's a lot of frustration and a lot of incomprehension of how to even begin such conversations. How do like what's your best advice for fraud fighters that want to approach leadership teams and want to influence them to make a decision that they think is the right decision? How, what's your advice?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
51:16
First is to make sure that executives understand that fraud operations are not just a cost center. We are protecting customers, deposits, reputation, operational capacity, and sometimes people themselves from catastrophic financial harm. I I also think the leadership needs to understand capacity differently. If a fraud team says we're overwhelmed, the answer can't always be, we'll hire another investigator. Yeah, maybe we need another investigator, but also maybe our technology needs tuning. Maybe our processes are inefficient. Maybe we're generating unnecessary uh work upstream. Um or there's another department that's creating fraud exposure downstream. Capacity is is a symptom. I want to understand the the cause. Right? I think that the other thing um that I've learned from the benchmarking work that we've been doing is that fraud teams are doing a lot better than we sometimes give ourselves credit for. You know, we are doing formal fraud risk uh assessments. Institutions are tracking false positives. They are using riskbased queuing. They're investing in technology. There's a there's a level of maturity there that I don't think always gets recognized. Um at the same time, you have teams saying that they are at or beyond capacity. Scams continue again to be one of the biggest concerns. Many institutions still struggle to quantify scam losses accurately. You have fraud teams trying to tell their story to leadership while some of the most important work they do is incredibly difficult to put on a balance sheet. You know, if I stop a $100,000 fraud attempt, everybody agrees that is valuable. The problem is proving that the $100,000 would have actually left the institution without the intervention. You know, that creates like this weird problem where losses are easy to to measure and prevent um and prevention is is hard to measure.
Chen Zamir
Chen Zamir
53:09
Mhm.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
53:10
Then leadership looks at the fraud dashboard and sees $2 million in fraud losses. What they may not see is the $15 million the team prevented. Right.
Chen Zamir
Chen Zamir
53:20
So this needs to be exposed. You're saying?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
53:22
Yes. 100%.
Chen Zamir
Chen Zamir
53:23
In the dashboard. Yeah.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
53:24
Yes.
Chen Zamir
Chen Zamir
53:25
Yeah. Yeah.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
53:26
I I think in the dashboard, one of the things um like I'd want some version of a fraud exposure prevented alongside fraud losses incurred, right? No. And not just the gross fraud loss. Show me the attempted fraud. Show me the prevented fraud. Show me the actual loss. Then give me enough context to understand what happened. If the board only sees losses, we're only showing them the failures. They need to see what the program is stopping. Yes. I would also want that normalized against something meaningful like transaction volume, uh, customer growth, deposits, or whichever denominator makes sense for that institution. A $2 million loss means something very different at a $500 million credit union than it does at a $50 billion bank.
Chen Zamir
Chen Zamir
54:12
Yeah, 100%. I agree with that. I do want to challenge you on one thing. I think that today if you would come to a leadership team or to the board and it would say my investigators are overwhelmed. Their answer is unlikely to be hire another investigator. Their answer is likely to be fire them all and put a very cheap AI instead. What, like, that it works 24/7. Um, how would you like how would you manage this kind of challenge from the leadership team?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
54:45
That's one that I'm still working on. I'll I'll be just completely transparent with you. You and I were actually working on a really cool project that I'm so excited to dive into, and that's really understanding the AI concept of of what can be done. Where is the investigator and the analyst still very valuable to an organization? Bottom line is we will at some point have to implement some type of AI that can help our organization. Fraud is too fast. It it's constantly changing. It's constantly evolving. We're going to have to put something in place to help us. That that's inevitable. That that's happening. What I would say is, um, and one concept that I'm becoming really familiar with, is, you know, we've talked about, um, human feedback in the loop, where it's, we're looking and making sure that the alerts worked and that it scored it the way we wanted it to. That still is not scalable. Instead, we're going to have to start looking at human on the loop where it's policy and governance of that AI system how it's working. So, I'll say to answer your question right now, I can't give you a definitive of what would work in order to help you keep your entire team. What I will say is that if you can go ahead and start looking now at what tech you think you may need in two years, do it. Do the research now. Start looking to see where your team might be more valuable. Maybe they need to develop a new skill that helps them become that person on the loop. Help them now. Point them in the right direction now to keep them as a valuable member of your organization. If you don't want to see uh their growth, you don't need to be in leadership anyways. Um so maybe maybe maybe this isn't the right place for you. But if if you're going to make sure that number one, your team is scalable, that you're going to be able to keep up with tech, they've got to start learning now. They've got to start looking now. I was one of those. I'll be honest, when I was the credit union practitioner, I said, um, we're always going to need the fraud investigator. Yeah, to an extent, yes, that is true. But we are teaching AI to do things a lot faster. And our whole uh thing with fraud is that we want to get to this preventative, proactive fraud uh strategy. We can't do that alone as humans. We are just humans, right? AI and scams and fraud, they move a lot faster. Payments move faster. You know that whenever I get that card alert on my card, if I tried to spend $500 at Walmart and it says, "Hey, did you do this?" A human is not going to be able to do that at scale for all their customers. We have to have these programs and systems in place. And so I the the answer to it today, I can't give you the definitive answer that I would say, but I would say definitely start pouring into your team to allow them to be useful and valuable whenever uh that time comes.
Chen Zamir
Chen Zamir
57:32
Yeah. Well, I said earlier fraud strategies uh can be quite straightforward. Uh but even if it is straightforward, it's still shifting and changing uh because fraud is changing, because the technology is changing, because the business landscape and the products are changing. And so there are always this kind of like these new fronts uh these new uncharted waters that you need to well to chart basically and that's part of the part of the job to an extent. Uh that's why we're risk managers. Uh I always say Hailey, it's been such an interesting conversation. Uh it feels like on one hand we covered a lot of ground and on the other hand we just skimmed the surface. So I uh I definitely love to do that again sometime. Uh but for today I would say it's it's uh it's been a pleasure and I uh can't thank you enough for uh letting me take over the pod for an hour.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
58:31
Yeah, I I'm so stoked that you were able to to be here uh to take over and to allow me to sit in the uh practitioner chair or or the guest chair today. I have I found myself asking, man, I'm doing a lot of interviews, but I I feel like there's an opportunity here where I can provide a little bit more insight. Um so, this was a a great opportunity, and I I appreciate you more than you know.
Chen Zamir
Chen Zamir
59:00
Uh goes Same goes back to you. So, uh yeah, I uh we should definitely do it again.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
59:06
Yes, for sure. Okay, so I'll take the I'll take the microphone back as the host and just say fraud fighters, uh you know, if you want to hear me turn the tables on him, um head over to The Saturday Fraud Strategist um for the other part of this conversation where I was able to turn the tables on him. Um until next time, stay vigilant, stay informed, and keep moving Fraud Forward.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
59:33
Thanks for listening to Fraud Forward. Remember, every conversation, every connection, and every insight moves our industry one step closer to stronger fraud defenses. If today's episode sparked an idea, share it with your team or tag me on LinkedIn. I love hearing how you're moving Fraud Forward in your own organization. Until next time, stay curious, stay resilient, keep moving Fraud Forward