What's up, fraud fighters, and welcome back to Fraud Forward. I feel like I haven't actually sat still in about 2 weeks. I got home from Las Vegas at 4:00 in the morning uh on Friday morning after starting the week in Washington DC. And I'm home for just a few days before I turn around and leave again. So, today there is no guest. It's just me, my microphone, and a notebook full of things I wrote down over the last week that I have been dying to talk about. Some I've already shared a little bit on the LinkedIn. Uh but I kind of want to dive in a little bit deeper uh in this episode. So, and again, um you know, some of the the thoughts and comments are directly related to banking, some of them aren't, which is exactly why I think they're worth talking about. So, I started the week in Washington at HHS for the AERO program um integrity forum and then I flewed from DC to Vegas for ACAMS um the assembly. And let me tell you, if that doesn't already let you know that those are two very different rooms, they were. At Arrow we were talking about, you know, public funds, federal programs, grants, audits, oversight, program integrity, fraud, waste, and abuse. Then I get to ACAMS and we're talking about financial institutions, AML, fraud, payment, stable coins, real-time money movement, AI, information sharing, different money, different systems, different oversight. Yet I kept writing down versions of the same thing. Culture, data, accountability, collaboration, speed, technology. Um, and then one sentence from Washington ended up framing the entire week for me, and it's that fraud follows money. Well, yeah, that goes without saying, of course it does. Um, it sounds almost too simple. Uh, yet the more I thought about it, the more I realized how much of what we are dealing with in financial crimes comes back to that one statement, where the money goes, fraud follows. When the money changes, fraud changes. When the way we move money gets faster, fraud gets faster. When we create a new project uh product, somebody figures out how to exploit it. When we close one vulnerability, they look for another one. So, and I'm going to come back to that. Uh first, let me tell you where I'm going next. Uh because October is apparently the month where I decided I don't need to sleep. Um so, on October 6th, I'll be in Pennsylvania with ACF speaking about fraud risk assessments.
Then October 12th and 13th, I'm heading to Ohio for NASCUS Fraud School with Critical Ops, where I will also be talking about fraud risk assessments and giving a sneak peek into the benchmark report data. Uh, if you've followed me for any amount of time, you know, this is a topic that I care a lot about. A fraud risk assessment should not be something you complete, put it in a folder, and pull back out next year so somebody can say you did it. This is not a checkbox item. This is something that should tell you something about your program. It should tell you, you know, where you're exposed, where controls aren't keeping up, what's what's changed in your environment and where you need to put your attention. Funny enough, after the conversations I've had this past week, I have even more I want to say about that. Then October 18th through the 21st, I'm going back to Vegas for Money 2020. Chen Zamir and I are going to be together live and in person recording podcasts. Um, if you've listened to the recent episode where Chen interviewed me for Fraud Forward and I interviewed him for the Saturday Fraud Strategist, you already know what happens when you put the two of us behind the microphones. Um, and we've done all of that remotely, but now we're actually going to be sitting across from each other. Um, we also have a special announcement that'll be coming that week, but I'm not telling you what it is. I know that is so annoying, isn't it? You're just going to have to wait. Uh, so Fraud Forward is basically going mobile for the full month of October. There will be microphones, there will be conference floors, there will probably be questionable airport food and at least one moment where I ask myself, why have I scheduled my life this way? Most importantly, there are going to be a lot of conversations with fraud fighters. I want to bring as much of that back here as I possibly can because one of the biggest things this past week reinforced for me is how valuable it can be to get outside of our little corner of financial crime and Washington was probably the best example of that. So I'll start with explaining why Arrow was so interesting to me. This wasn't a banking fraud conference. You know, I wasn't sitting in a room full of fraud investigators talking about check fraud, account takeover, and scams. The conversation was much broader. Public money, federal grants, oversight, auditing, you know, program integrity, fraud, waste, and abuse. One of the first things I wrote down, which I've already mentioned, was that fraud follows money. My brain immediately went to banking, right? Because fraudsters don't care what we call the product.
They don't care which product or which department owns it. They don't care whether we are talking about a government program, a checking account, a wire, an instant payment, or a stable coin. They care about opportunity. Where is the money? How do I get access to it? How quickly can I move it? What controls stand between me and the money? Where are the gaps? That's the fraudster's risk assessment. Sometimes I think theirs might be a little bit more current than ours are. So, one of the early conversations at Arrow was about audits and the amount of time that can pass before an audit occurs. I wrote in my notebook that a law allows 9 months before the audit. And I remember, you know, thinking, do you know what a fraudster could do in 9 months? Forget 9 months. Do you know what they could do in 9 minutes? That is where the government conversation suddenly felt very, you know, familiar to me. The longer the gap between an event occurring and someone identifying the problem, the more exposure you can create. We see that in banking constantly. Think about how often we investigate something and discover afterward that pieces of information existed across the institution before the loss. You know, maybe the branch knew something. Uh maybe another account had already been flagged. Maybe there was a device connection. Maybe the customer had already called it in. Maybe an alert fired and was dispositioned. Maybe another department saw something completely unrelated that suddenly becomes very relevant once you're looking backward. The data existed, we just didn't connect it at the time. One phrase that I wrote down from Arrow uh was systemic and structured approach. That matters. If the only way you identify something is because one really good investigator happens to recognize the pattern, that's great investigative work, but it's not necessarily a great control. What happens when that investigator leaves? What happens when the volume doubles? What happens when the scheme changes slightly? You have to figure out how to take what your best people know and make it repeatable. So, are we finding problems or or fixing them? There was another conversation at Arrow that I I don't know. I guess it really just felt like it mattered a little more to me. Uh, and it made me really appreciate the people in the room because someone described audit as a finding versus a relationship with the recipient. I loved that distinction if I'm being honest and don't think that I'm suddenly going to become an auditor. Don't don't don't worry that that's not happening. Um, but I loved it because I immediately thought about fraud investigations. If I find the fraud, document what happened, calculate the loss, and close the case, did I succeed? From an investigative standpoint, yes.
But from a fraud program standpoint, maybe not because what happened next? And that was all over my notes from Washington. Corrective action. You know, what are the findings? What caused them? What are we doing about them? Who owns the fix? Does the fix actually work? Think about how many times this happens inside a financial institution. Fraud identifies a vulnerability. We send an email, there's a meeting, everybody agrees, yep, that's a problem. Then everybody goes back to work. Three months later, somebody exploits the exact same vulnerability. Now we're sitting in another meeting discussing the same issue. At what point do we stop calling that a fraud problem and start calling it an accountability problem? Finding the weaknesses is only half of it. There has to be ownership on the other side. That was one thing that I really liked about the corrective action discussion. Somebody has to own what happens next. There has to be follow through. There has to be a way to determine whether what we changed actually fixed the problem. Otherwise, we're just documenting vulnerabilities for the next fraudster. Culture also came up over and over again at Arrow. I have written it throughout my my notebook several times. You know, culture must change uh the culture of spending, cultural shift. There was a discussion around this idea that if the incentive is to spend allocated money, people behave according to that incentive. That immediately made me think about financial institutions. What do we incentivize? If I measure an investigator primarily on how many alerts they close, I shouldn't be shocked when they become really good at closing alerts. That doesn't necessarily mean we're becoming really good at preventing fraud. If the business is measured on growth and fraud is measured on losses, then those two teams can very quickly become, you know, adversaries instead of partners. If the front line believes escalating something to fraud means creating more work for themselves, what behavior have we created? If somebody identifies a weakness and raising their hands means that they become responsible for fixing the entire problem, how excited are they going to be to raise their hand the next time? We tend to talk about culture as this softer thing that sits somewhere outside of the fraud program. I'm not sure it does. Culture can be a control. It can also defeat every control you build.
That connects to something else from Washington that I wrote down. Hire good people who believe in what they're doing. That sounds simple, too. Yet, fraud programs depend enormously on people who are willing to ask questions. People willing to say this doesn't make sense. People willing to challenge a process that's been around for 15 years. You know, people willing to lead or tell leadership something isn't working. You cannot technology your way out of a culture where nobody is willing to do that. And I think I said that on the episode with Chen and I love that. The other thing was listening to some of the people in the room who again at one point, I'll be honest with you, I felt like I was more of an American consumer in the room than a fraud person just because of the caliber of people who were on the panels. I thoroughly enjoyed listening to them and their governmental backgrounds who, you know, are handling the most grants given, you know, than any other program in the world. And I'm sitting there just in awe of these people who actually care, right? And one of the things they talked about was stewardship versus spending. So again, that conversation around stewardship, one line in my notes that was a dollar saved is worth more than a dollar recovered. And I can't get that out of my head. We understand that concept in fraud. Preventing the loss is is better than trying to recover it, right? Yet, when we're trying to prove the value of fraud programs, prevention becomes difficult to quantify. It's easy to show someone a $500,000 fraud loss. It's much harder to show them that the $500,000 loss never happened. That is a challenge. I think fraud leaders need to get better at it. We can't only tell the story of what we lost. We need to get better at telling the story of what we prevented, where controls changed outcomes, what investigator interventions saved, and where our investments are actually producing value. Especially when we're asking leadership for resources. If you're asking for another investigator, another tool, or another million dollars in fraud technology, leadership is going to ask, "What are we getting it for?" And that's a fair question. We should be able to answer it. And there's a lot more where that came from as far as community banks and credit unions go when the benchmark report releases. And I can't wait because there's a lot of things that are are making sense between the two that are consistent with saying we have the data. We're not doing a good enough job telling the story. Okay, so moving on. Uh the other thing that we talked about was technology. I think it was probably one of my favorite things because they mentioned start with the outcome you're trying to get to. Do not buy a solution before doing that. Fraud fighters, please. Can we put that on a wall somewhere or a sticker? I know we are all obsessed with stickers at this point.
Because we do this backwards all the time. A new technology comes along, AI, behavioral biometrics, device intelligence, consortium data, graph, machine learning, whatever it is, we watch the demo and we think, "Oh, we need that." Okay, why? What are we trying to fix? I work for a fraud technology company. I am obviously not going to sit here and tell you that technology doesn't matter. It matters tremendously. What I'm saying is that you need to understand what the hell you're trying to fix before you start buying things to fix it. What is happening? Where is it happening? Why is the existing control failing? What data do we have? What outcomes do we want? How will we know whether the solution worked? Then let's talk technology. I had literally just talked about this on Fraud Forward before I went to Washington. The solution isn't always new tech. Sometimes you need to back up and understand the problem first. Another note I wrote down was test small data sets against policies. And I really like that approach. We get caught in the analysis paralysis. We think transformation has to mean ripping everything out and starting over. Sometimes you can take one problem, one data set, or one process and test something. Did it work? Great. Learn from it. Move forward. You don't always have to boil the ocean. Then, of course, we got into AI. Fraud fighters, if you're anything like me, your list of things to read keeps growing. Your time to read them, though, probably not so much. That's why I write the Monday Fraud Fix. It's the newsletter companion to Fraud Forward. So, every Monday I'm sharing fraud trends that made me pause, what I'm reading, conversations happening in our community, and the fraud fighters that I think you should know. I also bring my take, you know, what it means for the people doing this work, and the questions we need to be asking. Every now and again, I might leave you a little Scooby snack to start your week. You know, I just can't help myself. You can find the Monday fraud fix on Substack or tap the link in the episode show notes and subscribe. I'll see you in your inbox, fraud fighters. So AI came up in Washington. AI came up at ACAMS. AI comes up basically everywhere I go now. One of the discussions at Arrow was about using new tools to enforce old laws and using models to identify things that humans cannot reasonably identify across massive amounts of data. There is enormous potential there. I also wrote something else down in my notebook and it is how do we make this permanent? Um which I think that might be the most important question. We are really good at pilots. We are really good at innovation projects. We are really good at finding one person inside of an organization who's excited about something and letting them build it. But what happens when that person leaves? What happens when leadership changes?
What happens when priorities shift? How do you institutionalize the thing that worked? That applies to AI. It applies to fraud controls. It applies to collaboration. It applies to basically everything we're talking about. If your fraud program depends on one person remembering how something works, you don't have a process. You have a person. That is a vulnerability. AI doesn't fix that. In fact, AI can make it worse if we automate something nobody actually understands. If you automate a bad process, you now have a faster bad process. If your data is bad, AI doesn't magically make the underlying data trustworthy. If nobody owns the decision, AI doesn't create accountability. If departments aren't sharing information, guess what? AI doesn't fix the culture. The fundamentals still matter. Okay. So then I got on a plane and I went to Vegas. This is where the week got really interesting. So I leave Washington after talking about government programs, audit, stewardship, fraud, waste, and abuse. I fly to Vegas. Now I'm at ACAMS talking about banks and payments, AML, stable coins, AI, and financial crime. Yet I kept hearing echoes of the same exact conversation. The biggest difference speed. So at a camps there's a lot of conversation around real time information sharing and real-time money movement. That changes everything. You know for years fraud teams have been taught follow the money. Okay. But what happens when the money moves faster than you can follow it? That's the problem that we're having today. Money can move through multiple institutions, platforms, and potentially different forms of value before somebody even knows the original transaction was fraudulent. The old model of discovering the fraud, investigating it, calling another institution and trying to recover the money starts breaking down when the money is moving in seconds. That means our controls have to move differently. Our intelligence has to move differently and our partners partnerships have to work differently. So stable coins made this especially interesting. So they came up a lot at ACAMS. One of the questions I wrote in my notebook was are stable coins actually money? There was the discussion around stable coins as digital representation of money and their ability to make payments move faster and cheaper. There was also discussion about their role in fraud and financial crime. I don't think the fraudster cares what we decide to call them. They care whether they can move uh value. That's it. Can I move it? Can I convert it? Can I exploit a gap between systems? Can I move faster than the people trying to stop me? That's why financial institutions cannot look at something like stable coins and say, "We don't offer that, so it's not our problem." Your customer might interact with it. Your business customer might. The recipient of the funds might interact with it. Another institution in the transaction chain might. Fraud doesn't stop at your organizational boundary. So then we think about the the whole picture, right? Uh nobody has the whole picture which again just leads into this whole other theme that came up repeatedly and that's partnerships and it could be the biggest connection between Washington and Vegas that I saw.
Nobody has the entire picture. One financial institution sees the sending account another sees the receiving account. A fintech may see the device. A payment provider sees something else. Law enforcement also may see you know multiple victims. The customer knows the social engineering story. A government agency may see another part of the activity entirely. Everybody has a piece of this puzzle. The fraudster is often the only person who understands the whole puzzle and that's a really big advantage. So the other thing that I wrote down from Arrow was the uh cooperative approach at ACAMS. I'm having and hearing conversations about public private partnerships, information sharing, and the need to collaborate. Same problem, right? Different room. We say collaboration constantly in this industry. The question is whether we actually operationalize it. Do your investigators know who to call at another institution? Can information move fast enough to matter? Are we sharing intelligence before something becomes a $5 million problem? Are we waiting until after the fraud to compare notes? The criminals are collaborating and most of the time they're doing it better than we are. Um there's another thing, right, that comes up. Um it's another uh aspect that I think probably perfectly sums up financial crime in 2026. Uh you know, we're sitting in Las Vegas talking about AI, stable coins, digital assets, and real-time payments. Um, then somebody starts talking about paper checks. Of course, we're building the future of money while simultaneously trying to stop someone from stealing a piece of paper out of a mailbox, washing it, and depositing it. That is the reality of fraud. We don't get to choose one area. Checks don't didn't disappear when cards came along. Cards didn't disappear when digital banking came along. ACH didn't disappear when instant payments came along. The fraud teams gets to deal with all of it. Um, so when we say fraud teams need to keep up, think about what we're actually asking them to keep up with. Old fraud, new fraud, old payment rails, new payment rails, new technology, legacy systems, new regulations, old controls, customer expectations, and criminals who do not have to wait for a budget cycle before they change tactics. That's a lot, don't you think? It is also why I keep coming back to fraud risk assessments. I think I'm just going to say it till I'm blue in the face. You cannot manage that environment based entirely on what happened last year. So, by the time I left Vegas and was, you know, reading back through my notes from Washington and Vegas, I started to realize there was a lot of the same conversation. These were completely different environments, but we're struggling with, you know, the same things. We have a ton of data. Are we using it? We can find problems, but are we fixing them? We know collaboration matters. Are we sharing information in a way that's useful and fast enough to make a difference? Same thing with implementing technology. Did we know what problem we were trying to solve before we implemented one? Uh that last one is probably going to continue uh to be a soapbox for me. I I work for a technology company. I see what good technology can do. This isn't me saying that we we don't need better tools. I'm saying I don't want us to buy technology to compensate for the fact that we haven't taken the time to understand the problem. And that's one of the things that again came up in Washington and then I heard the different versions of it again in Vegas. The same thing is true with AI. There were some really interesting conversations about what AI can do with data. How it can identify things we can't reasonably identify manually and how it can help us move faster. Great. I want all of that. I also wrote in huge letters in my notebook results. I want you to see it. Results.
Uh what did it actually do? Did we save money? Did we prevent something? Did we make the process better? Did we, you know, find something we weren't uh finding before? That's that's what I care about, not whether we can say we're using AI. I also wrote down um an arrow that I talked about a second ago that I think is probably going to really stay with me for a while and it's how do we make this permanent? You find something that works, great, but now what? Does it become part of how the organization operates or does it disappear when the person championing it leaves? That happens in banking all the time. We have that one investigator who knows everything about a particular fraud scheme, that one person who knows who to call at another institution, the other person who knows the weird work around the core. Then we have someone who we can look at something and immediately tell you that it doesn't make sense and then they leave. How much knowledge walks out of the door with them? That isn't just a staffing issue. That's a that's a broad risk. And I think that's probably where I'm landing after all this week. After this week, I I don't have some profound answer for you. I honestly I'm sorry. I have more questions than than I did before I went, which frankly is one of the reasons I like going to these things. I I don't want to leave a conference with 10 quotes for LinkedIn and a bunch of vendor swag because honestly, I love my swag. But, you know, whatever. We'll we'll we'll leave that where it is. Um, but I want to leave questioning something. Washington did that for me. ACAMS did that for me. That that was one of the things I I talked to, you know, my team at Sardine about. They were like, "Hailey, do you want to go to ACAMS?" And I said, "Yeah, but selfishly, it's because I want to attend the um the sessions. I I want to learn. I want to make sure that when I go to these things, it's not just for the hype of the conference, right? It's to actually take back something tangible that I can give back to you guys on what I learned, how we can move it into a practical conversation that that we take back to our organizations and we say, "This is this is what they discussed. These are things that we weren't thinking about and things that we need to to consider going forward. So now I'm going to spend probably the next few weeks talking to even more people about fraud risk assessments, controls, payments, and where all of this is going. Uh I mentioned it earlier, but I'll tell you again. I'm going to be in Pennsylvania on October 6th, Ohio for NASCUS Fraud School October 12th and 13th. And then Chen and I will be back in Vegas for Money 2020 October 18th through the 21st. And I'm really excited about it.
Last time I went to Vegas, I got married again to my husband of 15 years. Uh I don't know what's going to happen this time, but it's going to be fun. Um and yes, again, I do have we do have a surprise coming at Money 2020, and I'm still not telling you yet because I like to leave a cliffhanger. I like to leave you wanting more, and that's the way to do it. Um, so again, you'll just have to stick around or come back for that one, right? Okay. So, for now, I'm going to enjoy being back home again for just uh two more sleeps and then um again, I'm going to have to probably unpack a suitcase, repack a suitcase, wash some clothes, you know, um and pack snacks. I don't know about you guys, but I have decided that I am the worst traveler in the world because when I get to a new city, I I get so inspired by all these wonderful people on LinkedIn who go, I go for a run. I do not. I'm I'm a hermit. I get in my hotel room and then I go, "Oh my god, I'm so hungry. I'm so hungry and I don't want to go out by myself. This is a strange new place and I haven't been there before." You would you guys would be surprised. I am more of a hermit than you realize. You think I'm this extrovert and I am at conferences and I am on my podcast because it's my one time that this middle child who's been starved for attention her whole life gets to talk and no one tells her to be quiet because I can't hear you. And I mean you tune in every week so I'm assuming you like my tangents. But anyways, I digress. What I was trying to say was but I've decided that I have to start packing snacks or else I'm going to starve when I go to these places. So, if you see me at a conference, ask me if I've eaten anything. And if I haven't, maybe we can go get something together so I don't have to go by myself. Okay, that was my that was me asking for help. I hope you guys realize that. You know how hard that is to ask for help? Now, I did it. Okay, anyways, I hope you enjoyed that. Um, that was my last little tangent. I promise. Um, the one sentence I This is how I'm going to end the end our episode today. Um, the one sentence that I'm going to circle back to from the beginning. Um of the week and it still feels right. Uh the right place to end today's episode is that fraud follows money. Our job is to make sure we're paying attention to where the money is going next. Stay vigilant, stay informed, keep moving fraud forward.
Thanks for listening to Fraud Forward. Remember, every conversation, every connection, and every insight moves our industry one step closer to stronger fraud defenses. If today's episode sparked an idea, share it with your team or tag me on LinkedIn. I love hearing how you're moving fraud forward in your own organization. Until next time, stay curious, stay resilient, keep moving fraud forward.