We started this series by talking about the pressure all risk leaders are facing right now. Use AI to cut costs and by cutting cost I mean cutting headcount. But in fraud operations the push for automation also creates a risk. What happens when teams cut the very function needed to govern automated systems? In the previous episode in this series, we outlined what a transformation journey looks like when you move from mostly manual operations to AI powered ones. And as we've discussed, there's a lot of nuance to it, because it's not a switch you just flip. It's a journey with a specific sequence and dependencies. But one thing I didn't cover previously is how you establish AI governance as you implement more and more AI automation. Specifically, there's a second order effect almost nobody's planning. One function on your team doesn't shrink with AI adoption. On the contrary, it actually needs to grow. Because automation creates new oversight requirements that most teams do not have staff today. And if you don't account for it, you'll end up with a smaller team that isn't equipped to govern all the automated systems it runs. And let me tell you that would not end well. That function is fraud analytics. And without it, your system would break faster than you'd like to think. It is the control layer that catches drift, monitors automated decisions, and prevents silent pipeline failures. So in this video, I want to talk about how fraud teams usually look like, what AI governance really means, and what it means to your future organization.
In my experience, most fraud teams are built from four functions. Now, I will say in our industry, terms and definitions are very loose. Even the word fraud might mean different things to different people or even the same person when considering different contexts. So it might be that you've seen other names or other organizational structures to this. The point I'm trying to make is around co responsibilities and skill sets an organization holds, rather than how it's actually structured or named. So bear with me. Anyway, back to the four functions I usually see. The first is fraud ops which handles investigations. Reviewing alerts, making rulings, managing chargebacks, and so on. The second is fraud analytics which owns rules and monitoring. Writing detection logic, tracking performance, analyzing attack patterns and producing reports. The third is fraud strategy that sets the risk appetite, risk policies and are likely in charge of vendor selection and architecture. And the fourth and last is data science that builds and maintains machine learning and AI models. But as I mentioned, not every fraud organization has all four. And there are a few reasons for that. First, it might be that some of these responsibilities simply don't exist. Not every organization develops their own AI models, for example. In other cases, especially in smaller organizations, some responsibilities are simply held by the team leader. For example, fraud strategy. It doesn't have to be its own function. So in effect, the bare minimum for a fraud team and what you'll almost always say is just one function, fraud ops. Meaning you can run a fraud function even if probably inefficiently with nothing more than investigators reviewing alerts. At the same time, fraud analytics exists in a lot of midsize and larger teams, but it's often informal or undersized. And that creates a potential oversight gap when these teams begin using AI agents to label cases, suggest rules, cluster alerts, all the things we talked about in the previous episodes. Meaning, if you need analytical skills to monitor agentic powered fraud systems, most teams are behind where they should be. And if you're thinking of downsizing them even more, then you might be risking self-sabotage when adopting AI at the same time. Because here's the thing, the traditional fraud analyst role was already important, but in an AI powered fraud team, it becomes central. Why do I think we'll need a bigger fraud analytics function in the age of agentic AI? In one word, governance.
Not all agentic AI creates the same kind of work. And understand the difference is what explains why certain functions on your team grow while others shrink. When fraud teams first roll out Agentic AI, they typically start with investigation assistance. The agent assembles the case and proposes a resolution and the investigator reviews and approves. Which means that this workflow isn't so different from managing a junior analyst. The agent does the leg work and the investigator uses their judgment to validate. And that's the thing, your team already knows how to do that. Governing individual decisions over individual cases is something your team members already do today. But fully automated pipelines are different. Auto labeling uh case clustering, rule recommendations, model training, these decisions operate at scale. They run continuously and you cannot have humans running around after agents because that would slow you down. Exactly the opposite of what you want to achieve. But the problem is that these pipelines can still fail. And when they do, they fail silently. A labeling agent that starts misclassifying doesn't raise its hand. It keeps labeling until someone checks. A rule built on a coincidental correlation looks fine in the back test. This system fails silently. They fail at scale and they fail fast. Unlike a human investigator who notices when something uh feels off, an automated pipeline doesn't feel anything. It just continues to run and spew garbage. But the governance these pipelines need is the same kind of monitoring fraud teams already apply today. KPIs, monitoring, alerting, systematic performance review, and most importantly, being able to run a root cause analysis when something breaks so you are able to fix it. Not just say that it's wrong. Does any of that sound familiar? Observing system performance through data, noticing issues, understanding what causes them, and fixing them, that's the job of fraud analytics.
What is the takeaway from looking at those two governing approaches? The obvious assumption when you start rolling out Agentic AI is that you can downsize your fraud team. But that is only correct for one function, fraud ops. For another, fraud analytics, it's not that simple. In fact, for most teams, it'll have to be exactly the opposite. Why? Because investigators benefit most directly from what AI agents automate. The part of their day that consumed the most time pulling transaction details, running IP lookups, checking device history, cross reference accounts. That's exactly what agents handle, an investigation. Simply put, the efficiency gains are straightforward because what used to take 30 minutes now takes five. Naturally, the function needs fewer people. But fraud analytics on the other hand, and as we just discussed, is different. Right now the team observes data, compiles reports, write rules when new attacks emerge and tweak score cut offs when needed. But when agents take over those tasks, all the automated pipelines we just described become their responsibility as well. Now you might think, but wouldn't I be automating the analysts jobs too? And you'll be right thinking that. But you need to remember that while some of the work is now automated, all the new automation you deployed both in analytics and in operations will now fall under their responsibility as well. Let's take rule writing as an example. Even if we reach an ideal state where agents write rules from scratch completely autonomously, which is definitely a stretch goal, your human analysts still have to review them. They need to check that the rules proposed went through all the tests correctly, that they don't contradict your business logic, and that they are not based on shaky statistics. That's still work, and it's only the start because we're still making individual decisions over single rules. But we also need to monitor how well the agents are proposing rules as a whole. How many times have the analysts corrected something fundamental? Did this number grow since last month? And if so, why? And how can we fix it? And this is just one example of how tasks that don't exist today will land in fraud analytics. And take into account that by the time you'll get to monitor your rules recommendation agents, you probably implemented at least five to 10 other systems. So all of them would need monitoring as well.
Hopefully, the argument I've outlined for why you'd actually need more analysts when you start automating has been convincing thus far. But the sad reality is that many teams don't have a fully fledged analytics team and so are likely blind to their repercussions. If you don't manage existing automated pipelines today or if engineering does it for you, odds are you have a blind spot there. And so when such teams come under cost pressure, it's very easy to commit to cutting the function that you actually need to enable AI adoption. It's all too easy to get to a point where your agentic investigation systems goes live, cases are being assembled, labels are being generated, and rules are being proposed. But the analytics team is still sized for quarterly rule reviews. And then the labeling pipeline has no error rate thresholds. The rule recommendation audits happen once a month when it should be happening weekly. So your fraud system is more automated, but your reaction cycle isn't faster. Even worse, your system is less stable and less safe than it was before. Why? Because we scaled automation without scaling governance. And that's exactly the recipe for failed AI adoption projects. Because it's easy to forget that redesigning your system means also redesigning your team and not just cutting it.
In the first episode in this series, I stressed that redesigning your fraud prevention system will come at a cost and that you'd want to fund it through the cost cutting you achieve. Part of that cost and only one part is making sure your team is properly staffed in the fraud analytics department and that you can increase its size as you go through the transformation journey. To an extent, it means that the savings you make from the shrinking fraud ops team should fund the growth of fraud analytics. And this can also be a way to upscale and retain some of the headcount instead of losing all of the institutional knowledge entirely. Of course, it might be that the target budget figure you show your board is higher than what they or you anticipated at first, but it's mandatory to build the function the new system depends on most because we should expect fraud teams to have a new bare minimum makeup. Investigative capabilities will continue to be part of it, but not all of it. In addition to that, teams will have to include strong analytical functions to operate its agentic workers, monitor automated pipelines, evaluate recommendations, and maintain your system stability as a whole. Or to frame it simply, think of it like that. Fraud analysts will be your new AI team leaders. That's the framing your board would understand.