What is up, fraud fighters? Welcome back to Fraud Forward, where banking comes together to challenge assumptions, pressure test controls, and move fraud forward. That was such a good one. That’s for the books. Okay, so for years, fraud teams operated in a world where there was still time to react. We kind of liked that, you know? Payments took days. Reviews happened manually. And if you needed fraud controls, compliance tooling, or transaction monitoring, there was a good chance you were building it yourself. Today, though, money moves instantly. APIs connect everything, and companies can launch financial products in days rather than months. But with faster payments comes faster fraud, new compliance challenges, and a growing need for infrastructure that can scale alongside risk. Today’s guest has had a front-row seat to that evolution. Matt Janiga from Modern Treasury has worked across some of the most influential companies in financial services and fintech, including roles touching Dodd-Frank, Square, Stripe, and Lithic. And today, he’s helping build the next generation of money movement infrastructure at Modern Treasury. So in this episode, we’re talking about what fraud teams don’t see inside modern payments, the hidden complexity behind one API, and how the industry evolved from building everything in-house to leveraging specialized partners. Matt, welcome to the show.
Thank you for having me. I’m thrilled to be here. We’re very happy Sardine customers, been a big fan of the company for a long time, and excited to chat about all our topics today.
Me too. I will tell you, this was one that I didn’t know you guys ahead of time. And then they were like, Hailey, I think you’re probably going to want to talk to Matt. And of course, from that first conversation, I was like, you’re exactly right. So I’m so excited to have you on. You’ve had a really unique career path that spans regulation, compliance, and fintech infrastructure. So I want to start by looking backward before we look ahead. You worked on Dodd-Frank early in your career. Looking back, what assumptions from that era no longer hold true today?
Yeah, I think that’s a really good call-out. There are two high-level things that I tell listeners to focus on or think about here. One, and this will sound crazy, but I realize now I’m getting old, so I can think of a pre-digital world, right? Corded phones and even the tiny flip cell phones and things like that.
Those are the best. You could hang up really quickly.
Yes, absolutely. And you had to think twice before texting because it took you longer to type all those things out on that nine- or ten-digit keypad.
And it cost you per text.
Cost you per text. That’s right. There was a lot there going on. When you think back to it, that’s the land that Dodd-Frank was created in. We talk a lot about the gerontocracy today, older legislators and so on, but legislators were just as old back then. So you had people in their 70s drafting, writing, voting on, and approving legislation, thinking about technology like the fax machine, flip-style cell phones, corded landlines, and human-staffed call centers that were probably onshore. Listeners may be listening to this today and saying, what are you talking about? That sounds like a different language. And it really was a different world. The laws were kind of rooted around that. So one thing I call out is that people did not contemplate the technology we’d have today when they were writing Dodd-Frank. And there’s a good and a bad to this. Legislators took this very high-level approach to all the statutes and punted a lot to the regulators, which is why you’re able to see now the CFTC go out and engage in things like events, prediction markets, contracts, futures hedging, and things like that, which, by the way, just happens to look like sports betting or enables a similar product experience. They’re able to do that because of the high-level rules of the road that were set by Congress. And Congress didn’t give a lot of guardrails around that. So some regulators are able to take advantage of this and be technology-forward. At the same point in time, as we’ve seen, and I think people would probably have complaints about Gary Gensler and some of the Biden administrators, because of the lack of those anchor points for new technology, regulators have also been able to close doors or keep certain doors closed over time. So one interesting thing is that technology wasn’t contemplated well. I think we are due for a refresh. We are seeing some of that now, right? The CLARITY Act, so many other great payments and fintech-related pieces of legislation sitting somewhere on Capitol Hill that may or may not pass. The other thing that I’d call out is the regulatory posture temperature. Regulators had been very permissive leading up to Dodd-Frank. That created the Great Financial Crisis. A lot of issues came with that. A lot of people lost their homes, a lot of people lost jobs. I know I was one of them. I constantly talked about outrunning the layoff fairy because everywhere I went, the business wasn’t stable, and I had to either hop or try to find that next thing that was a little bit more stable. Things now are certainly a lot better than they were back then. But regulators were firefighting. That was the first thing that happened. And then after firefighting, they went into punitive punishment mode. They were looking to make a point about things, pick fights with people, or do enforcement. I think we’ve had a regulatory window shift since Dodd-Frank. Today, regulators will still do policymaking via enforcement. Sometimes they will shoot first and ask questions later. That happens at both the federal and the state level. It doesn’t matter which political party is in charge or who is driving it. Somebody is going to be out to make a point somewhere. But the interesting thing is, if you take a look, by and large, regulators, and I think this includes both the state and the federal level, are looking to be more collaborative. They’re asking today, what can be, and how do we help safely enable it and bring the future to these new segments and areas, particularly financial services, versus asking what do we pick fights with? And the reason I want to hit on this for listeners is because this will not always be the case. I like to talk about these types of things like a regulatory pendulum. Take advantage. Enjoy this current framework and environment. It’ll probably last the next few years. That would be my guess. Or if my board were asking me these questions, this is what I would be telling them. Be prepared and think about what happens when that pendulum swings. It won’t swing back exactly where it used to be. It’ll probably swing in a new third direction. Be prepared for that change or that shift and what that may do for your business and certain business opportunities that you have. So I think those are probably the two biggest things to call out. One is the wildly different technology set because the laws were written for fax machines and corded landlines and all sorts of things that just don’t exist today or aren’t used. And the other thing is that regulatory pendulum shift because when Dodd-Frank went online and regulators had those powers, they used them differently than they’re using them today. And in a few years, they’re going to use them differently again. So those are key things for listeners out there to think about.
I truly love that perspective. In the beginning, maybe they did underestimate just how quickly payments would evolve. But now they’re saying, hey, we get it. We did kind of underestimate that, but we’re asking now for insights. Where do you think it’s going? So they can prepare us for going forward. I think that’s truly the way we should be operating anyway. But like you said, we’re just going to enjoy it for this short amount of time, and then we’re going to have our new guardrails. I am curious though, do you think Dodd-Frank indirectly helped create the fintech ecosystem that we know today?
Yes, absolutely. And I think there are two main drivers of it. One is the Durbin Amendment, which I know listeners have probably thought about and heard about ad nauseam, so I won’t spend too much time on this here. But basically, the idea of let’s cap interchange at the largest banks then allowed smaller banks, via partnerships, to use fintechs as a marketing layer. And the whole VC-fueled business of the business doesn’t need to be profitable, right? You can think about marketing spend equaling your net retained revenue. If you’re spending a dollar and earning a long-term dollar, that’s a good trade. So you had these businesses that could come in and think about building customer bases in a different way than the traditional industry. I think that’s why you saw the explosion in market share. And you see these large companies today in Cash App from Block, SoFi, and Chime. Recognize some of those have become traditional banks. Block owns an ILC. SoFi has a full bank charter. Chime has talked about exploring a charter in this current environment. And that’s not to touch on Venmo, Dave, MoneyLion, and all these other properties that are out there, even the SMB ones like Novo, Mercury, and Brex. Brex is now owned by Capital One. Those are there and allowed market share to kind of leave the banking system. Part of that really was related to, again, not just Durbin, but also banks being, I’ll say pardon my language, a little pissy about Durbin. I remember being inside of banking land, working for banks, being outside counsel to banks, and the bankers just being really angry about it. The business response was, we’re going to shut down our rewards programs for checking accounts and debit cards. I think the talking point was, we can’t afford them anymore. I don’t actually believe that because you look at the revenue lines for these largest banks, they could afford it. They just wanted to keep their margins in a certain profile where everyone was lifting the ladder at the same time, so they did. And they underestimated the Chimes and Cash Apps of the world, but no longer. Those properties, Cash App, SoFi, Venmo, et cetera, probably have over 100 million American adult consumers now using those programs because of the rewards and the other benefits and technology that they offer. It’s something where the banks purposefully pulling out of that market to try and, quote, teach a lesson to regulators, we’re going to punish consumers so hopefully they punish you at the voting box, that did not work. Instead, competition was allowed to flourish in this space. So Durbin was really interesting. Also interesting is debit routing. At the end of the day, Visa still maintains the lion’s share. I think 70% of debit card volume runs over Visa or runs on Visa rails. But if you look at it, it did give merchants a choice. And merchants who want to do low-cost routing, the largest of them, Walmart, Amazon, et cetera, have those opportunities. It’s been interesting as you saw those types of product sets pop up. They’re not as prevalent anymore. They’re harder to find, but they do exist and they’re out there. I think the other interesting thing, which is a driver that people forget about or don’t think about in addition to Durbin, is the capital rules and the tightening of the regulatory perimeter. This goes back to firefighting and then this enforcement and punishment that the regulators extracted, which I don’t think was wrong. So I’m not saying the regulators did anything too heavy-handed. Some of their approaches I might disagree with, but I think the overall direction was right. It caused large traditional banks that might have served certain lower-income consumers or might have served SMBs to look at it and say, I don’t want to spend that money anymore, or I don’t want to spend that effort. I’m going to redirect to higher-margin things, or I’m going to sell this segment of my business off. And the interesting thing when that happened, when that ladder got pulled up, is you had the smartphone come along. You had people looking at that and saying, well, let’s push this to cloud. Let’s push this to mobile. Let’s bring some of these services down that you would typically see, or let’s modernize some of these services in a way where, through new technology, we can drive the types of margins that banks are missing, and we can partner with banks to drive it. And of course, the big ones I’m talking about here are PayPal, which existed pre-crash but then I think got bigger and now sadly is going through some restructuring, but still, still really great product set. There are great people at PayPal. And then obviously Stripe and Square, two large behemoths. You could put Adyen in this boat as well, but obviously they were more European-focused around this time period, emerging, growing, serving those underserved markets because banks pushed it out. Either due to capital profiles or having to heal their balance sheet, they sold off their payments businesses. It’s crazy to think about Vantiv or Fifth Third had a version of Stripe or Adyen. It was Vantiv, and they sold it off. Now they’re rebuilding it with Newline. Things are kind of cyclical in banking. You see people jettison certain business lines or grow value in them, jettison them, sell them off, and then regrow them again, which I think is what we’re seeing in some things. And then you do see some folks like JPMorgan Chase with Paymentech. Fantastic people over there, really fantastic platform, able to kind of hold their own on capabilities and technology versus the Stripes and Adyens of the world, and obviously has JPMorgan’s distribution footprint. But by and large, the other banks got out of it. And that’s what led to this rise of fintech. If you look around today and say, where did all these companies come from? It’s from banks deciding, we actively don’t want to be in this business, and somebody launching the right product at the right time to take advantage of their product-market fit because the needs didn’t go away. They just got pushed out of the banking system. And then, interestingly, a lot of those companies, Adyen has a bank charter, Stripe has applied for multiple bank charters under its various subsidiary structure as well, and we’ve already touched on Block and their ILC. A lot of those companies are coming back in or dipping toes under the banking tent or back into the traditional banking financial system. I think we’ll see that trend continue over the next few years in this current regulatory environment.
I’m obviously a student, right? I’m literally sitting here taking notes, and that’s why we bring these conversations to Fraud Forward. I love that you ended that with the needs didn’t go away. The banks tried to push it off or to say, hey, this isn’t really something they’re going to want. It’s just like the people who didn’t believe in the laptop. Well, now we all have one. Unfortunately, for the banking world, they missed that boat. But I love how you framed it. I absolutely agree that the rise of fintech really did happen because they didn’t want to. Even now, I look at my 14-year-old, who has no want to walk into a brick-and-mortar building and open up an account. And I kind of hate to admit this out loud, but I also did not want to be inconvenienced with having to walk into the brick-and-mortar bank to open up her account. So it was much easier for me to use this other fintech provider that literally, she’s just a piece of my account now. She got a card with her name on it, and now I can transfer money when she needs it. I also don’t have to worry about her needing cash when she goes to her local sports game or whatever. She now has money that she can take with her. That’s not something my bank is currently equipped to do unless I walk in and do it. So I completely agree and love that perspective of the need was still there. Now we’ve got fintech companies, which I’m really grateful for. The whole innovative concept, I think unfortunately in some financial institutions, I won’t say all, but in some, there is that older mentality of a lot of CEOs are just waiting on retirement, so they’re not going to do anything crazy or innovative. But when we do get that 30-year-old or 40-year-old CEO, that’s where we will start to see some change, at least I think.
Absolutely. And not to paint everyone with an age brush because obviously I worked at Capital One and would still hear the stories about what Rich, the CEO, is doing there. And I think even though Rich is one of those older CEOs, he very much has his finger on the pulse of technology and drives his team to do the same. You’ve got these folks. Jamie Dimon and JPMorgan Chase are obviously doing very well. And Fifth Third, talking about younger CEOs, when did they start getting into things like Newline or some of these other new businesses and regrowing the things they had sold off or modernizing the bank? It was when they brought in Tim, and Tim started to be able to drive strategy and decision making at the bank. So I think you’re right. There is an interesting thing, just to springboard off of this, in banking, where I think you do have an older set of CEOs that are looking and saying, I don’t have the budget and I don’t have the venture-backed burn money to make money profile luxury that tech-enabled companies do or did, especially during ZIRP. And I need to wait until the cost of creating and ingesting technology comes down so I can compete with them. Now, it’s kind of like asking somebody if they’re rich and they always point upwards at somebody else who has more money than they do. So the banks will do this as well. They make plenty of money and have big technology budgets, but they’ll say, I don’t have the budget of JPMorgan Chase. And everybody points upward at them. Chase probably points at Google or Meta or others when they talk about those things as well. But today, with the rise of agentic coding, pick your tool. You can use Cursor. You can use Devin. Claude, Codex, anything like that. Those costs are really coming down. So it will be interesting, and it may take the younger CEO shift, folks who really understand this or are touching this deeply, to come and change that mindset within banking. But the funny thing is that day is here. So it will be interesting to see how quickly the bank CEOs recognize it, or if it does, to your point, take some of that age turnover to drive some of that. But we are way off topic. What else should we be chatting about in the world of fraud and payments?
I know, I know. I tend to go down the rabbit hole. [Ad Break (17:53):: Finally, I’m so happy to share with you all that The Saturday Fraud Strategist is now a podcast. What? Yeah. On top of my weekly newsletter, you can now listen to and watch me talk about my, and hopefully your, favorite topic: fraud strategy. And from time to time, I’ll be hosting operators and founders to discuss where the industry is headed and what we fraud fighters should pay attention to. I must say, I’m super excited, and if I’m being honest, a bit nervous about all of this. I’ve been debating with myself whether to start a podcast for ages, but kept putting it off. But now this is the result, so I guess there’s no turning back. So if you want to join me for the ride, head over to Sardine’s website and subscribe now. Are you ready? Am I ready? We’ll find out next Saturday.]
So I’ll shift us to our next segment, which is the pre-vendor world. You said something during our prep call that really stuck with me. You described the early days of fintech as the pre-vendor world and even joked that teams were basically banging sticks together. I think many fraud fighters would love to hear what that actually looked like. What did fraud and compliance infrastructure look like before companies like, shout out Sardine, existed?
Yeah, that’s a great question. And I’ve seen this both from the bank side and from the early fintech side at Square and Stripe. From the bank side, we had teams of people in cubicles with some version of landline phones, and they had some version of a PC computer, usually a laptop. They were accessing some type of, more likely than not, cloud-based database type of system. But you had people doing that, and it literally was like banging sticks together. The laptops were slow. The systems were clunky. You did not have a unified view, especially inside these larger banks, because so many of them have been cobbled together by M&A. And what that meant under the hood was they had different cores, sometimes different providers. You would have a TSYS core, Fiserv core, Jack Henry core, all living within the same large bank, and you may have anywhere from four to 18 different instances of that core. You have multiple BINs you need to look across, et cetera. And it wasn’t as easy as it is today to develop this bird’s-eye view. Things like Sardine, other glue kind of gap-filling things like Retool, or data lakes were not really a thing. You didn’t have Snowflake. You couldn’t go to Databricks. So if you were trying to knit all those individual data silos together, you had to have these very IT-intensive programs and projects and develop custom software. Sometimes you’d hire contracting teams to build it, and then you’d have some folks maintain it. Other times you’d try and buy something, but there wasn’t necessarily a magic bullet that you could fire if you were doing some of these things. And shout out to the folks, because there were a lot of efforts to modernize or transform where you could get those types of bird’s-eye views before this tooling existed. There were a lot of people that did Herculean work. I think the other thing is on-prem. I’m going to jump now both from the banking side and the fintech side. Everything was on-prem. You had server blades maintained by IT staff that were on site somewhere or maybe in an off-site data center. If you weren’t running your own data center, you still had to maintain your own hardware, power it with your own firmware, and run your own networking and other things. You’d go buy this from Cisco or Oracle or some of these other folks, and you’d put these pieces together and get this going. But on-prem was a big thing. I remember one of the big shifts for me going from Square to Stripe, I think it took me about three months to fully realize because eventually I asked people, so where are the server blades? And I’m walking around at Stripe, and they’re like, no, no, we’re entirely in the cloud. It was such a new and novel concept at the time that I think my brain was literally blown. I had a freak-out for about five minutes of, how am I going to explain this to the regulators? Because I got brought in to help deal with money transmission stuff. So you have to talk to the regulators and explain your stack, and they’re used to seeing on-prem. The first question is going to be, well, how did you get comfortable with this? How do you know it’s safe? And now it’s silly because you look and everybody’s in the cloud, right? The U.S. government is in the cloud. So it’s interesting to see that kind of shift. Down to the individual tooling, if you think about what that looked like, everything was built from scratch. Today, anyone building has this luxury. They can contact a company like Sardine and get this amazing battle-tested tooling that’s already been developed for hundreds, if not thousands, of features and use cases. The bugs have been worked out of it, and it’s cloud-based. So you can do multiplayer. You can have multiple people in there at a time, influencing things and driving things forward. And you have sandbox and production, and everything works beautifully. What it used to be was you would kind of do this iteration model. For those listeners out there who work in product land and are used to shipping, what’s your beta? What’s your alpha? What’s your MVP? What’s your V1? What’s your V2? What’s your ship train cadence? You were having to do that with your compliance and fraud tooling. Compliance is relatively easy. It’s kind of like baking a cake in my mind, at least setting up the framework and what the things need to be. Although, God, I never want to have to be at a company that’s investing resources to build our own compliance tooling again because it’s just silly. You should just go get that from a vendor. But you think about what you have to collect for KYC if you’re doing a consumer use case. You know the basic elements. You can set up your tooling, and you can run it. Then you can find the edge cases and develop some tooling for your internal teams to work with manual case intervention or to re-KYC things or other things like that. But if you think about fraud, fraud is ever evolving. So it’s something where you would build your system and the team would develop or figure out these new patterns. And if you didn’t have the right tools to address the patterns, you’d have to grab engineering resources, bring them on, bring them into the fold, and ask, hey, how quickly can you get something shipped here? How quickly can we push something to update or fix this gap or address the system? The other thing when you’re thinking about these types of businesses, you have these microservices that generally would live within the stack somewhere. And something else happening may impact and cause the microservice to break. So your microservice might be completely fine, but if something else was happening upstream or somewhere else in your technology stack in your product set, you’d have to figure out, is it this team or that team? And you have to have them all talk to each other. Now, what’s fantastic about these cloud-based vendors, and why we like using Sardine, is you have already seen and thought of literally every use case we could possibly think of. So it’s really about, hey, how do we turn that tool on? I think the other thing is the data set is so much richer. Yes, you can go direct to some of these data providers like LexisNexis, and there are a lot of great KYC companies out there that can help provide data sets like Trulioo. Data sets are great, but one of the things you didn’t have back in this older world that I grew up in was consortium data. Banks had it. Banks had consortium data for themselves in Early Warning. And on a limited basis, they would give selective access to certain fintechs. And that access was pendulum-swingy. It would come and go. You could have it this cycle, and then, sorry, we’re taking your contract away. So you couldn’t treat it as the bedrock foundation of your program. And one of the amazing things is now, I had a team member walk me through something the other day to say, what do you think about this? We’re seeing this pop up. What we saw was we were getting fantastic fraud data off of Sardine’s consortium. And that’s something that in the past, you’d have to start small and build your own internal consortium. I always had this pipe dream. Hey, we should have a fintech version of EWS. There’s got to be somebody to call PayPal and somebody at Square, but I could never figure it out and move the right needles. And it was never my core project. So it just never got done, at least not for me. But now it’s amazing where, if you think about it, you don’t have to have the size or the scale of a Cash App or a PayPal to get the fraud consortium power because you can use Sardine. You can get that from the network-wide effects. And I recognize there are other vendors out there as well that do that, but we’re very happy, and I think we’re seeing great results with what you all provide today.
I appreciate that perspective. I love that you mentioned wishing there was an EWS for fintech. At the same time, from the banking perspective, we wanted that same insight because we could share. I think specifically about my practitioner days, the X9 files. When those came in, we could look and determine, hey, this was sent back, this was returned for whatever reason, and we would use that whenever checks would come through on the teller line. We could tell the tellers in real time, hey, don’t accept this check, and here’s why. I loved that. But if we could do that same thing when we’re looking at debit card transactions at a merchant, that hey, we’ve had several vendors that have popped up and said that there’s a lot of fraud happening here. You might want to do a push notification or something to your customers. We would have loved to have that information, but we just didn’t. I think you’ve answered several of the questions that I had all in your answer, which is phenomenal. Thinking of bespoke fraud systems that you’re creating yourself and also just how long it would take to launch products like that back in those days. So I guess I’ll sum it up with this question, which is, what do fraud teams today take for granted that simply didn’t exist 15 years ago?
Yeah, I think honestly one of the biggest things is that orchestration layer. One of the things we’re seeing on the vendor side now is a lot of the vendors recognize their limits, or they recognize where another vendor partner may have a better superpower. So we’re seeing a lot of marketplaces, or we’re seeing the ability to plug in orchestration. That’s something that day-to-day fraud teams, maybe even some fraud managers or more recent fraud executives that didn’t live in this old world, take for granted. Obviously, folks like Soups did. We did. I see it now and I’m amazed. I’ve been seeing this now over, gosh, I think about six different fintechs and viewing all the different ways people did it. At one point, one fintech I was at was running everything through Salesforce because that was just the best bird’s-eye orchestration view to do it, which today sounds silly. Why would you pay $1,800 for a seat for all your fraud team when you can go get a much better orchestration layer and a vendor that can take you deep on any capability you need in your stack or need to supplement that you don’t have natively, using something like Sardine? So I would say orchestration and then the ability to pop at these other things by marketplaces. And I’ll take us a step further. I think something people will take for granted, let’s say three years from now, is going to be the ability of wrapping in agents and agent tooling. I see some of the features in my Sardine dashboard when I’m in there. I know it’s early days for all of us on this, but I’m very excited about what you guys have today. It’s very helpful for us, but I’m also very excited about where this is going to go in the future in terms of investigations, aiding and speeding up human investigators, making judgment calls, finding those needles in the haystack, and being able to see this overarching view that one human might miss. Or a heuristic forest trying to sniff out certain patterns may also miss. And now you’ve got this other way to go tackle this and dig in on certain things.
So true. And we also are very excited about our new agents that are coming out. I will say there’s one thing that you mentioned that I was looking back through my notes a second ago, about the new fraud person coming in. We’re not thinking about all the things that could potentially happen because maybe they haven’t happened yet to our organization. So being able to have a vendor or a solution that you can depend on that’s like, hey, we’ve seen it all. I like to use the Farmers Insurance, “We know a thing or two because we’ve seen a thing or two.” I think it’s a great little gimmick, but I feel like it’s kind of in that same wheelhouse that when you finally have that partner solution that has seen it and they can prepare you for it, it leads to great organizations who maybe haven’t even had a fraud department at all and are trying to establish one now. A lot of times, they’re pulling up a frontline employee who just happened to be really good at disputes to now head up a fraud program. Well, they don’t know every aspect of it. So being able to rely on these vendors just gives us a different leg up than what we would have had several years ago.
Absolutely. One other thing I’ll add is that what we’re talking about, or certainly I live in non-bank land, payments land, fintech land, these tools are for everybody. So if you are seeing fraud because you’re moving high-dollar consumer devices like phones, Birkin bags, or something else along those lines, or if you have a secondhand goods marketplace, just because you’re not a fintech by nature, or even if you happen to be a bank and you’re trying to figure out how do I compete with a company like Square or Stripe, the answer now is you can go buy these vendor tools. You can bring this technology into your bank or into your marketplace or into your other commerce platform, and it’ll help give you some of those superpowers. I think that’s a really amazing thing that not everyone has fully woken up to. Anyone can have these superpowers. You just need to go work with these vendors.
So true. So I’ll move us over to our next segment because you kind of teed it up perfectly. One of the phrases we hear constantly in fintech is “one API.” It sounds simple on the surface, but fraud teams know there is rarely anything simple about moving money. So Modern Treasury is now directly in the flow of funds. What changes when you’re actually moving money rather than enabling it?
I’m going to have a funny answer here, which is I’m going to say not much. And I can explain that for people who are watching or listening to this. Not much because if you look at what the core of our software is, we sit today like a payments enablement and orchestration layer over money center banks, fintech banks, any bank you could possibly think of. We’ve got dozens of bank connections into every bank that works with other customers, other platforms for payments purposes. People use our software to track, interact with, engage, and move funds today. But the difference is, when they do that API call to us, it’s poking their bank and telling their bank, if it’s a JPMorgan or Coastal or someone else along those lines, what to do. And the interesting thing, if you think about what we’ve done, we’ve moved over $400 billion lifetime for customers through that software product, and helped them track and ledger it and reconcile it. We’re doing now over a billion dollars a day in money movement just through the software platform. Historically, we’d done the $400 billion, and some people go, well, is that over eight years? The answer is, yes, it is over our eight years. We recently celebrated our eighth birthday at Modern Treasury. But the answer is, we’re going to do likely in the order of $350 to $370 billion in money movement just this year through the software. So if you think about it, you’re getting this battle-tested software. And what we changed was, rather than you go out and have to find your own bank, because some of the banks sometimes will say, we like your business, you’re too small, or we like your business, you need a regulatory license, we were able to bring our bank partner along. So if you don’t have your own bank, you can start on the PSP. You get all the same software superpowers. You get all the same battle testing. We’re used by several publicly traded companies, including many I’d love to name but we don’t have logo rights. They close their books and do SEC reporting off of this. They support millions of customers, millions of small businesses off of this. They are regulated, and they use Modern Treasury software to track all that. Customers who come to us can get all that same superpower rolled up in one API. The other thing for us is that we can give you multiple rails. We don’t touch cards, but we will do ACH debits and credits, RTP, FedNow, wire, and we’ve added check capabilities. So there are a lot of things under the hood. And obviously stablecoins. We’re still expanding the platform. By stablecoins, we can do on and off ramps. We will introduce you to custody partners. We have other products coming soon, which we’re very excited about, but I think my marketing team would kill me if I spoiled them and talked about them now. But lots of fun stuff. I’d love to come back. I think honestly we should send Dan Mottice back, who’s our stablecoin guru here at Modern Treasury. For us, that’s the reason why not much has changed because we’ve already been doing this for customers, including some stablecoin orchestration for our software customers today. We’re working with some of those custody providers and other things in a software capacity. They’re buying software from us. It’s something where we’ve seen so much of the industry, and we’ve mined very much like Sardine has mined all the edge cases in fraud and is always on the cutting edge, and is just as fast, if not faster, developing capabilities against new fraud patterns and rings and things like that. We’re doing the same thing for nuts-and-bolts payments. How does this move here? How do these banks connect? How does this bank connect to this crypto provider? How do these markets connect? That’s what folks can get when they come to the PSP.
Love that. So again, just talking about that one API, when people hear one API, what complexity are they missing?
There are a couple different things. One is there’s a lot of complexity to stitch all of these different features together or products, because some of them are products, some of them are just features. We have customers who come to us and say, I’m working with another company in your space, but they’re making me add one or two other companies to use their product. And we go, you can just use us for all two or three or four of those functions. So you can just come in and get everything. I think people who haven’t worked in this space will underestimate the complexity around sometimes the software isn’t good. Sometimes you do the API call and the thing doesn’t happen. Again, that doesn’t happen with us. You don’t move a billion dollars a day through your payment software unless it’s good, because people aren’t going to keep showing up and moving funds through those rails. I think the other thing is sometimes the underlying rail choice isn’t there. So that’s kind of what the one API complexity abstracts away. It allows you to have access to multiple different rails, multiple different timing options, multiple different markets and geos, and multiple partners under the hood. And we are abstracting away that complexity. You’re not going to need a bank partnership manager or the team to manage that because we’ve got you covered with that. We want customers to do their own fraud screening. We’re very happy if they also work with Sardine, but we’re going to have a goaltender back there trying to catch those things and keep the ball out of the net when it comes to fraud and fraudsters. That’s what we’re building on our platform. So we’re going to have that extra layer of protection and bird’s-eye view. I think those are some of the elements of complexity that people don’t think about or take for granted, in part because you can go to a provider, turnkey it, hit an API call, and output happens.
That’s when you’re like, really? That it’s as simple as that? So I’d love to ask, just to double-click about the operational realities that fraud teams often don’t see that are maybe behind the scenes. One in particular is maybe even the reversibility rules that change during fraud operations. So we’d just love your thoughts there.
Yeah. And it’s important to talk about that each rail has its own rules around how you adjudicate reversibility. Because that’s another big thing that folks who’ve worked in this space know well. But if you’ve just worked in one rail type, you might think everything kind of works like Visa or Mastercard. Because of that, everything has its own rules. Rules end up being able to be gamed. They can be gamed by fraudsters, or they can be optimized. I wouldn’t call it gaming, but optimized by companies. And so you do see companies under the hood develop these superpowers. I’m thinking actually of Lithic, where we were card-focused, but we had a couple of employees that were very good and their chargeback win rates were above market and above anybody else. If the average chargeback win rate on a card issuer side might be, the average win rate you could get if you outsource this to one of the networks or one of the other providers might be somewhere in the neighborhood of 50 or 60%, these folks were winning 80% of their chargebacks. And it wasn’t because they were lying or submitting faulty documentation. They knew all the rules so well that they could optimize for it. So I think that’s one thing to call out. If you are new to payments and you don’t have a fraud background, you’re going to want to investigate the rail type, the reversibility, and the rules around reversibility. And the reason I keep hammering this is because then you look at something like ACH, and there is no adjudication really in ACH. It’s bank wins. If the bank wants to say, I got a call from Matt as my customer. He’s diamond, platinum, whatever status. Matt doesn’t lie to us, and we’re just reversing the payment, the bank on the other side that originated that ACH debit has to refund. Then what NACHA says is you settle it out of band with the bank. So if you really wanted to, bank one could sue bank two, but it just doesn’t happen. Or if it was large enough, I suppose you might see something along those lines. Usually what happens is the third-party sender goes and sues the person they took the debit from and shows up with the authorization. But you can submit documentation until you’re blue in the face. My experience with that is that the bank says, we don’t care. We’re not interested in it. And because there’s no central network, NACHA doesn’t play that role that Visa or Mastercard would play. There’s no third-party arbiter that can take a neutral view and look at just the facts. So again, it goes back to your question around reversibility. What do people need to know? One is, what are the rules of the road, or really the rules of the rail? The other thing, then, is how that ties into it. Depending upon the rules of the rail, now you have to treat those customers more skeptically. You can really get granular with this. You can look at it and say, I am seeing a lot of fraud from these institutions. There were certain fintechs that were labeled as fraud magnets or fraud factories. So you saw some counterparties on the other side just say, I will not accept the transaction from this fintech, and kind of turn that off. I think those fintechs have largely cleaned up those issues. And it’s something that over time you want to do because fraud may be a quick drug in terms of boosting your revenue because you’re going to see that transaction volume go through, but it’s not sustainable long term. You yourself are going to have to turn these fraudsters, or eventually they’re going to rip you off, and it’ll eat into that revenue that you’re building. So most fintechs end up cleaning that up. I think the other thing is sometimes some banks are so large and they turn a blind eye to fraud that there will be certain banks that have big fraudster populations. And then there’s another complexity to it too, depending upon what the payment device or payment credential is that you’re getting. Because not only can the rail be reversible sometimes, but think about something like a virtual card. Or in open banking, there’s this concept called a tokenized account number. Some tokenized account numbers can be canceled by the consumer. Good consumers don’t cancel them. They don’t realize this can be done, but fraudsters know. And fraudsters cancel them and use it to hammer the counterparty on the other side to get out of the payment because they can do it without having to do an unauthorized transaction claim to their bank. They can just kill the token, and then the debit never occurs. Then the counterparty on their side is left holding the bag. So there’s a lot of complexity when it comes to reversibility. And I think too, the other thing around reversibility is people need to think about the durability or how stable that credential is that’s being presented. Again, going back to the virtual card, I’m sure most listeners, if they’ve worked with virtual cards, have used it to get a free trial and then not have to pay afterward. I know I’ve done that, and I’m sure lots of listeners have done that as well. I think that’s a fairly innocent practice because people set these things up, and you’re just guarding your bank account from it. And it keeps you from having to go in and officially cancel. But folks who do it not just for the free trial, but to skip out on payment because they’re canceling the virtual card before the payment comes due, or they’re canceling the tokenized account number before the payment comes due, that is fraud. And I think that is problematic.
One hundred percent. I wish we could get some updated Reg E. Reversibility is great, but I did a presentation a couple of years ago and was like, with Reg E, are we protecting consumers or enabling the fraudsters? I don’t know here.
No, it’s absolutely true. And unfortunately, I think that is something where if you’re going to mandate reversibility, you probably need to set up some kind of adjudication process. That way you can catch fraudsters, or some type of federally mandated fraud database or something like that. I know people get skittish about that, especially because then you start to involve privacy advocates who say, well, we shouldn’t be doing this. And there can be false positives. But we’ve worked in this space. I know listeners have worked in this space. Fraudsters have some of the biggest moxie you’ll ever see. I remember being at places where we would get regulatory complaints because we had money transmission licenses. We’d go look into it, and lo and behold, it was a fraudster. The fraudster had ripped us off, and we had all the facts to prove it, but they went to the regulator to try and get us into trouble. We’d go back to the regulator and be like, this is a fraudster. Here are the five reasons why. Here’s all the data that proves it. And they’d be like, works for us, we’re going to consider this closed. So it is one of those funny things where fraudsters have absolutely gamed the system, and we probably do need a refresh on some of those things. Unfortunately, I don’t think we’ll get them with CLARITY or some of these other areas, but maybe that’s something as Congress starts to get a little bit younger, a little more tech-forward, they can think about those things.
Fingers crossed. I appreciate all of that insight there, truly. But I also want to make sure we really highlight something that was recently announced. Modern Treasury recently announced global USD accounts spanning dozens of countries. That’s an incredible opportunity, but from a fraud and compliance perspective, it’s also incredibly complex. I’d love for you to speak on that for a second.
Yeah. We owe it to really great partners. The partners come on our KYC and fraud side, so folks like Sardine. We’re really grateful for the capabilities that you have all been able to help us with and deliver. The other thing is it goes to our great banking partners. I will not name them just because we have not cleared this with their marketing teams, but if folks want to find me online, happy to say who they are or other things. It’s the usual suspects of folks. But we do have some really thoughtful banking partners that are willing to look at us and say, hey, what’s possible here? And then the question is, okay, we’ve decided what’s possible. How do we make it safe? And we’re able to come to them and say, here’s what we think makes this safe and why we think this is reasonable. And they evaluate it on the merits, without any bias or preconceived notions. They obviously have their own frameworks, their own guardrails, their own walls of the house that we need to operate within. But I think it’s given us a lot of interesting capabilities to go launch these products. For folks who are wondering, how would you do this at home? The simple answer is you should, or the starting point is you should get a Delaware corporation. Don’t ever start any of these companies at home because that’ll make you a sole prop. That’s a legal joke, by the way. Once you have that aside, you can tackle these things by thinking about what is legally required. What’s my foundational footprint? When you look at it, you come back to something that centers around CIP, which is the basis of KYC. CIP is customer identification program for listeners who aren’t into the legal jargon or don’t have to be. God bless you if you don’t have to be. I’ve been trying to get out of it for 20 years, but here I am. CIP is a part of your KYC foundation because knowing your customer is more than just grabbing the customer identification information. It’s also understanding what the customer does. Then you’ll have customer due diligence around it. You may have enhanced due diligence, especially when you’re talking about all these countries and bringing all these people in. You’re going to be looking at other different signals. Now, one of the things I also like to wrap into this, and it’s not part of the CIP rules but can help inform KYC, is digital fingerprint, which is something that obviously partners like Sardine are really able to help us with. And this is where the consortium data is also very valuable. Digital fingerprint, in my mind, can be broken down a couple different ways. I tend to think of it as hard elements and soft elements. The hard elements are important because if you want to take a hard action against a customer, like freeze their funds, file a SAR, turn off an account, kick them off your platform, or blacklist them, you don’t want to do that against a soft element. You want to do that against a hard element. The hard elements in my mind are things like an SSN. Not necessarily a digital fingerprint, but something that should be unique. Now it can be purchased. I’ve been part of several data breaches myself because I used to work for the government. Thanks, OPM. But they’re out there. When you combine my SSN with my cell phone number, okay, you can SIM swap me. But now you start to get into my device ID. People who have seen me before, and I’m sure Sardine has me in the consortium somewhere because I bet I’ve interacted with other services, you start to form this picture of Matt that gets harder to change. Or now you’re going to layer in my ACH number or a PAN, a card number. So now you have enough elements starting to build up where a fraudster may be able to get one, but not all five of them. And you can layer in some other things around, for example, what type of device do I typically use? I typically bias toward one device set. I’m not going to give it away. I don’t want fraudsters to completely eat my lunch here. But if you’re seeing me and I pop up on the other device type, it’s probably not me. 99.9% odds that’s not me. Those are the types of things in the digital fingerprint that you can look at. Now, those factors around device, IP, et cetera, can be soft factors. Because if I’m home or I’m out, I’m on the Starbucks Wi-Fi, I’m going to get an IP address that could be used by somebody else. My IP is likely rotated at home, so my wife and I are probably sharing them. We both work from home. And my kids now are on their iPads or other things like that. So you could be seeing some of that. You need to break those things down. But as you think about the digital fingerprint, that also helps you layer in some levels of safety, including some bare-bones blocking and tackling. So some free advice for folks is, there’s an expectation that you will block IP addresses from fully sanctioned countries. You should never have anyone natively accessing from North Korea, Cuba, et cetera. There will be lots of companies that aren’t aware of that or forget about that. So I want to call that out. But those are some of the things you can look at and why getting that digital fingerprint can be really important. Work with PostHog or another type of vendor like that to help grab that out. Make sure you’re surfacing the proper privacy policies on your website or app, or binding customers to it if you’re bringing them into an official front door or funnel. Those are things that can help. And then as you’re thinking about it, you can start with CIP, what’s legally required. You can think about how you contain risk. You can feed in digital fingerprint. And then also, some of your controls can be on the back end around transaction monitoring. Some of them can be threshold-based. I think those of us who have worked in this space know there are a lot of tourists. There are a lot of looky-loos that come in and try a product once or twice. One of my funny favorite examples of this is every time we’d launch something new at Lithic, the Stripe issuing team would spin up a bunch of accounts from their Gmail addresses. And I used to work at Stripe with the Stripe issuing team, so I knew who they all were, and we’d all chuckle about it. It’s like, it’s really nice that 40 people from Stripe signed up for Lithic’s product today. Hopefully we’ll get some real customers too. You’d see them come in and run a few dollars through. But I should imagine most fintechs who have competitors would see that dynamic as well. Those folks aren’t going to be long term, so you don’t need to strangle them in process. They’re not a risk for you. They’re looky-loos. They’re going to come in, try a product once, end up effectively churning or going dormant. So I think when folks wonder what it takes to run these accounts or open up to this many markets, I think it’s really great partners, both on your regtech, compliance tech, and fraud tech side, but also from the institutional side. Making sure you’re working with someone who understands what’s possible and is up for exploring what’s reasonable. And then taking a reasonable package around the controls necessary to enable these types of products and services.
What would you say are the biggest misconceptions people have about global money movement?
I think I see a lot of people, particularly in the compliance space, and I suspect this is in the fraud space as well, and then in banking. So you kind of have this triangle that overlaps, or these Venn diagrams, where a bunch of people sit in the middle around international is risky. And yes, by default, especially looking at some of the AML principles or the country ratings and things like that, you’ll want to put certain things at higher risk. And that could be driven either by money laundering or by fraud. They’re both dual drivers there. But if you look at a lot of these consumer use cases and zoom out, wait a minute, companies like Western Union are multinational, if not as global as you can get, and they move money. There are banks that are in multiple geos and footprints. Or you look at somebody like Nubank coming up through LatAm. People would consider LatAm high risk, fraudy, money laundering, but here’s Nubank doing very well, doing it safely, and entering the U.S. market as well. So I think there are some interesting misconceptions or there’s a broad brush people paint with. What I would say is if you’re building in this space, you want to be able to help the folks who have a broad brush put it down and understand the nuance in this. There are high-risk markets. I’m not blind to that. There are high-risk use cases. And there are things where you’re going to want enhanced due diligence, extra information about folks. Ideally, you can get some of that up front. You can make it threshold-based, or you could do it on an RFI basis. But it’s understanding the nuance there and the complexity that I think can help drive some of these things forward as you’re building in these spaces.
So true. I can remember in my early practitioner days when I was sitting at the ACH desk manually reviewing the IAT report. Any international transactions that were ACH, I had to review and make sure they were usually like two or three dollars. They were small, one to two transactions per day. I remember thinking, why am I doing this? This is, first of all, manual. But second of all, what’s the big deal? And just remembering that that was part of the process. And now, even in my day-to-day with podcasts and editing and things like that, I needed to send payment. In order to send payment overseas, it took a week for my wire to get there. That was crazy to me that I had to wait that long. So the fact that this is now an opportunity where this is instant, that can happen and it’s being done safely, I think it’s a service that honestly has been well overdue.
Absolutely. There is some, some folks will call it regulatory arbitrage, but I think especially when it comes to IATs, they call it regulatory cruft. OFAC realized, especially after the 2001 attacks, my God, we can have people in foreign countries landing payments and we don’t have great visibility. We don’t have a great way to block it. We’re not sure how banks are tracking this, et cetera. They went to NACHA and said, fix it. There was this consultative process kind of back and forth. So they stood up the IAT framework, and then everybody said, okay, we’re done. So the IAT framework hasn’t really been touched. It’s been expanded to capture more permutations, but the actual nuts and bolts of it haven’t been touched in almost 20 years, I feel like. I think it was like the late 2000s when the IAT stuff really got baked, maybe around 2011, but the core of it really got baked, I think, in that early 2000s timeframe. And there’s been an expansion of what is an IAT. It’s fascinating because if you look at it, card networks don’t have these same limitations. Private networks, like cross-border networks, don’t have these same limitations. At the end of the day, they will comply with the travel rule, which is helpful. But you’re adding this complexity in where, since you touched on IATs, if you think about it, the sender is going to be running its own screening. Then the bank is going to be running its own screening. And because of the way fuzzy matching can work, you can have something hit on the front end but not hit on the back end, or vice versa. And now you’re introducing another layer where if there’s another bank involved in the clearing of it or pushing it out, they’re also obligated to run their own screening. And then the funny thing is the Fed runs screening, but they don’t block anything. So you have this extra layer of screening that’s just screening for screening’s sake. Back in the day, I think it made a ton of sense why the Fed doesn’t block, why you have all these different parties doing things, because it was so manual, to your point around looking at the IAT transactions coming through. But the silly thing now is you think about the advancements in technology, or you think about how this doesn’t apply to a cross-border transaction that’s funded with push-to-card or funded by a credit card. They don’t have the IAT rules, but you can still move money overseas. Or stablecoins. There’s no NACHA-like body. I guess OFAC could go to the issuers the way they went to NACHA, but there isn’t really a NACHA-type network adjudicating body. It’s just the blockchain. So it’s kind of interesting where this is kind of set and forget, and the forget is regrettable in this case because it’s kind of choking ACH from being an interesting factor. I think it’ll be interesting to see what happens with stablecoins because it probably won’t be IAT-related, cross-border, et cetera. But there will be things, as regulators are setting the rules under the GENIUS Act, that are set and forget, and they don’t grow. And it’s interesting, the card networks have, by and large, been able to navigate that or keep that from happening. They have fantastic people on the regulatory side of the card networks and really good lobbyists. Not to imply anything unseemly about it, but they do a good job educating regulators and keeping a clear path for the ecosystem. It’s not just for the networks themselves, but it’s for merchants and consumers, which is really important, and banks as issuers because they’re obviously part of that equation. But it’s something where the rest of the industry hasn’t organized or developed that muscle yet. Sorry, IATs are one of my favorite topics to hate on. The rules are crusty and silly, and they are, I think, impacting interesting products and lower-cost services that could be developed. Unfortunately, we’re likely to see similar things happen with stablecoins, other payment rails, faster payment rails, et cetera, as those come on.
I appreciate that. And I think it’s a great lead-in again to the next segment that I have for us, which is our final one, the future of fraud infrastructure. When we look ahead, fraud teams aren’t just adapting to new payment rails. They’re adapting to entirely new infrastructure models. So what capabilities will every fraud team need over the next five years, do you think?
I would say agent capabilities are going to be really key, and that’s going to evolve rapidly. I think every six months for the next three years, people probably need to pick their head up and think, have we sized this right? Do we have the right platform? Et cetera. One of the things, for example, we did at Lithic, and we’re happy to use the agentic capabilities that come embedded with our partners and service providers. Obviously, Sardine is one. I’ll give Notion another shout out. They have some really great agent capabilities in there. We have also built kind of what I’ll call an AI spinal column. So we’ve taken software tooling and created a central connective tissue, and we can plug company data sets in over here, and we can plug agentic tooling or agentic AI workflows in over here. If we find that, because I think people were on Codex, and then they were like, oh, I like Claude better, if you have to do that rip-and-switch piece, it’s easier for us now because of that AI spinal column that we’ve set up. And now you can tell I’m not very technical, so I’m probably calling it all the wrong things. But the way the team explained it to me, it’s like, oh, it’s like an AI spinal column. You’re plugging in different nerve centers that control different parts of the company and allow you to enable certain functions. Obviously, you can create controls around that. Today, we don’t have our Claude agents touching our Sardine layer, but we’re going to evaluate. We’ll look at some of those things and think about what does our back office look like? How do we contain it, make it safe? It’s not on-prem anymore, but it might be in our cloud bucket on a model that we roll or contain. And does it feed back to a mainline model system or something else like that? So I think AI agents are probably going to be the biggest thing. The reason I bring it up is because fraud will always be there. It will always be finding the cracks and seams in your products. It will always be finding the cracks and seams in your processes. Fraud is going to get better with deepfakes and things like that. We’re B2B distributed at Modern Treasury, so we don’t think too much about deepfakes, but our customers do. And because fraud is ever evolving, and especially for the U.S. market, you’ll see fraud overseas too. Sometimes it’ll happen when you’re sleeping. Or if it’s really smart, it’ll walk in through the front door during daylight hours, but it’ll happen overseas in market as you’re trying to track traffic or pound out fraud rings and things like that. The agentic capabilities of being able to identify weak points in your defenses and plug them with agents that don’t sleep, don’t require overhead, benefits, and office space, maybe you roll your own and get a Mac Mini, but a Mac Mini is a lot cheaper than either offshore or full-time FTE. It’s going to give superpowers to the teams that stay on top of this. And also, I think having a vendor that can support, facilitate, and work with those agents is also pretty key. That’s one of the superpowers we appreciate about Sardine.
Truly, it’s one of those really cool things. And for the record, Fraud Forward appreciates you talking in practical, non-technical terms because I also totally could visualize the spinal column. I was like, oh yeah, that makes total sense. I appreciate that. And I think you made a very valid point that I want to make sure we touch on here, which is, where should humans remain in the loop though, with all this really cool tech that we’re hopefully onboarding and will be able to use?
Yeah. There are a couple different models that we think about at Modern Treasury, and I think will continue to be deployed. They’ll make sense for folks who have been in this space and thought about human-in-the-loop. People get excited about AI, but we’ve had AI, especially in fraud and risk and compliance, for well over 20 years. We’ve been using heuristics. We’ve been using machine learning. That is a form of AI, but it’s just not sexy. It’s not the LLM people have come to think about. And they do slightly different jobs. So I think you still need both. We’ve been using humans in the loop with these machine learning models for a while. So what we’re thinking about and would generally recommend for folks until somebody comes up with a better model is to roll that forward and keep the human in the loop. Then you can do some after-the-fact. And this is something that will be familiar for QA teams, audit teams, compliance teams. You can do the quality assurance or quality control. You can do the testing and sampling and go in and check things. And if you’re having an independent assessment done on your AML piece, you might stretch it out over your fraud systems as well if you’re using some of these agents and you want to catch some stuff. Now, what I would recommend if you do that is to have a separate report just on fraud so it doesn’t blur into or foreclose the AML independent assessment if you share that, or when you share that with external audiences. But if you think about it, the teams that are going to run those assessments are looking at workflows that probably will be pretty similar to fraud workflows. They’re used to testing this type of input, output, result type of thing, and looking for failures in systems and consequences. So that’s something I think to call out for folks. The other way that I think about it is, I have this really great team of experts that I’m privileged to work with at Modern Treasury, and some of them report directly to me, so I really appreciate all of them. I view it as, hey, rather than us hire six FTEs underneath them, we can start with agents and see what we can do with the agents, fully aware, not to say we’re cutting X percent of our people. Klarna ranked every one of their customer support people out with agents, and then they kind of reversed course. So we’re aware at Modern Treasury that agents don’t fully replace humans. But if you think about augmenting a manager and making it where this manager just makes decisions now, because that’s really what management is, you’re making decisions that need escalation over certain things. You can have the AI do those rote, repeatable tasks that you look at and go, yeah, this is a no-brainer, and we just don’t have a good tool to handle it. Unfortunately, we have this output coming out of the system that needs clearing. You can have AI go in and do those things, things you used to hire maybe an offshore team, a contractor, or something else to absorb. I think more and more, we’ll see AI absorb more of the queue work coming from FTEs, and that will free people up to be managers. In other words, we today can benefit from taking high-performing individual contributors and turning them into managers with these types of tools. In the future, we’ll have to balance this, right? How do we make sure we’re training folks and putting them into the right things? Also, how do we make sure the queue and the agents are spotting one thing and that they’re spotting the emerging thing as well? Part of that is a good vendor structure or a good partner structure. Again, Sardine helps us with that. We appreciate all of that. Part of that is going to be humans going into that haystack and looking for potential needles before the company gets done.
Such an interesting perspective. And I love that you mentioned the part about training folks. One of the things that concerns me, for my own thoughts, is I do fear that any new people we are bringing on, if we’re getting rid of the older senior people who have been part of banking before it was so technologically advanced, we’re missing that industry knowledge. It’s like that’s going out without first being taught to the next generation. I was trained by someone who today, I think if technology fails, she’s literally going to be able to put us back on the map. Check 21, she can do all the scanning. She did the mailing of every check. It was crazy. But she’s the one that gave me that firsthand knowledge and holistic understanding I have today. So I do worry that industry knowledge is going to leave with that generation and we’re not educating the next generation effectively. Hopefully we’ll cross that bridge the right way.
Yeah. No, I think that’s fair. I’m optimistic that we will still have, especially as companies scale, because we’re not like, hey, we’re never going to hire heads. We have open roles right now at Modern Treasury. We’d love for listeners to come join us if they’re interested in that. And we’ll continue to hire. We’re going to continue to hire in sales, fraud, risk, compliance, engineering, marketing, finance, all the functions across the board. I think rather than see a 30-person team, we may see a 10-person team, if that makes any sense. The pressure is on us to be a little more selective, but there will still be growth and pathway opportunities. And I expect too, when we reach the same scale that an Adyen, a Stripe, or a Square has, it won’t just be a 10-person team. It’ll probably be closer to 100 or maybe even 1,000 or so. So I’m optimistic that we still will have those training opportunities. I’m with you though. I hope we don’t lose all that great knowledge as folks get ready to enjoy the next phases of their life.
Very true, very true. Okay, my final question for you. What infrastructure investment would you make first if you were building a fraud program today?
I think I would invest in my front door. And I really want to call out the front door because I’ve worked with so many product people now that I have taken for granted. I’ve worked with a lot of folks that are very experienced and tenured, and they naturally think about the front door. How do you introduce your product to your customers? That front door is important in legal because we want to make sure it has the right terms, conditions, and privacy policies. Because then everything you do once you’re in the house, down the hallway, or in the building, is wrapped with legal safety, and we’ve given you the rules of the road. So it lines up with UDAP. It lines up with privacy expectations. And then it also answers some of the questions later when the business comes to you and says, can we use the data for X? Well, what did we tell the customer at the front door? I’m going to tease the front door not for legal reasons, but for a different reason, which is the front door is the best time to capture information about your customer. Obviously, how you do it is a dance because you need to balance friction versus want. Customers that really want your product will sit through a lot of friction. There are some really fantastic products. One of my favorite ones, if I can name them, is Current. I did the onboarding flow for one of Current’s products. It felt like I was just being naturally pulled through the funnel. I couldn’t stop myself from entering the information. They weren’t doing anything sneaky or stealing anything from me. It was just such an easy experience that I was done and out the other side. And they had full CIP. I’m sure they had my full digital fingerprint. That’s something that, as people are thinking about their front door, get your front door right. Make sure it’s something that captures your customer’s digital fingerprint. Have them take their shoes off before they come in, and then look at their shoes. See what they’ve done. Obviously, have a privacy policy if you do that, so you’re not creating expectations or exposure for you or for your company. But I think the front door is really the most important thing. And digital fingerprint is the thing that people who haven’t worked in this space or haven’t had to encounter fraud before forget about. So those are the two key magic words I would say folks should invest in as they’re thinking about starting infrastructure from scratch.
I totally agree. I have no other comments. So Matt, I just want to thank you so much for coming on the podcast and sharing your insights with us. This has truly been a typical Fraud Forward conversation.
Hailey, it was so much fun. I hope we get to catch up soon in person, and I’m happy to come back anytime.
Absolutely. Thank you so much. So I think for our listeners today, one of my biggest takeaways is that the evolution of fraud hasn’t just been about faster payments or newer technologies. It’s been about infrastructure. The systems, vendors, and partnerships that exist today have fundamentally changed how financial institutions build, scale, and secure money movement. For fraud fighters listening, understanding what’s happening beneath the surface of modern payments isn’t just helpful. It’s becoming essential. And to everyone else out there, whether you’re building controls, investigating fraud, or designing the next generation of payment experiences, stay vigilant, stay informed, and keep moving Fraud Forward. Thanks for listening to Fraud Forward. Remember, every conversation, every connection, and every insight moves our industry one step closer to stronger fraud defenses. If today’s episode sparked an idea, share it with your team or tag me on LinkedIn. I love hearing how you’re moving fraud forward in your own organization. Until next time, stay curious, stay resilient, and keep moving fraud forward.
Thanks for listening to Fraud Forward. Remember, every conversation, every connection, and every insight moves our industry one step closer to stronger fraud defenses. If today’s episode sparked an idea, share it with your team, or tag me on LinkedIn. I love hearing how you’re moving fraud forward in your own organization. Until next time, stay curious, stay resilient, and keep moving fraud forward.