Sardine named a Leader in The Forrester Wave™: Financial Crime Management Solutions, Q3 2026

Learn More
The Saturday Fraud Strategist

The Rise of Agentic Fraud Ops, part 3: Scaling Fraud Analytics

10 min

Risk leaders are under pressure right now to use AI to cut costs. Cutting costs usually means cutting headcount. In fraud operations specifically, that instinct creates a blind spot in teams.

The previous episodes in this series walked through what a transformation actually looks like moving from manual fraud operations to AI powered ones. What those episodes didn’t get into is why scaling fraud analytics has to happen alongside that shift. There’s a second order effect almost nobody plans for. One function doesn’t shrink when a team adopts AI, it has to grow. If a fraud team headcount planning doesn’t account for that, the result is a smaller team that isn’t actually equipped to govern the automated systems it just deployed.

That is fraud analytics. Skipping its growth is how AI rollout quietly turns into a bigger risk than the manual process it replaced.

What you’ll hear in this episode:

  • Why scaling fraud analytics matters more than any other staffing decision in an AI transformation, and most teams get this backwards.
  • Why most fraud teams break down into the four functions of fraud ops, fraud analytics, fraud strategy, and data science in fraud teams. And why almost none of them have all four fully staffed.
  • Why fraud ops vs fraud analytics respond in opposite directions to AI adoption.
  • The is a real difference between reviewing an individual agent decision and governing a fully automated pipeline at scale.
  • What silent pipeline failure actually looks like in practice, and why automated systems don’t announce when they’ve gone wrong.
  • Why rule writing automation still requires human review, and what that review has to catch.
  • How KPI monitoring for automated systems and root cause analysis in fraud systems are skills fraud teams already have, just aimed at a new target.
  • Where fraud team restructuring for AI usually breaks down in quarterly reviews. Why it happens when missing error thresholds, and because audits happen monthly instead of weekly.
  • Why fraud analysts, not investigators or engineers, are becoming the new AI team leaders.
  • How to think about fraud team budget planning during this shift, including funding analytics growth from fraud ops savings.

You should listen to this episode if you:

  • Lead a fraud team currently planning or mid-way through an AI transformation and haven't yet mapped what happens to your analytics function
  • Are under pressure to cut fraud team headcount and need a clear argument for where that logic breaks down
  • Have deployed or are about to deploy agentic AI for investigations, labeling, or rule writing and want to understand the governance gap most teams miss
  • Are building a fraud team budget case for your board and need language that connects cost savings to where they should actually be reinvested
  • Want a practical framework for fraud team org design that accounts for pipeline-level monitoring, not just individual case review
  • Are wondering whether your fraud analytics function is sized for the automation you're already running, or the automation you're about to add
Episode notes & key takeaways

Why scaling fraud analytics is the decision most teams get backwards

The default assumption going into an AI transformation is that every function shrinks. Investigation work, the thirty-minute tasks that become five-minute tasks, is exactly what agents are good at automating. That team naturally gets leaner. Applying the same logic to fraud analytics is the mistake worth flagging. Fraud ops vs fraud analytics isn’t a story about automation shrinking everything equally, it’s a story about work moving from one team to another.

The governance problem hiding behind “it’s working fine”

Reviewing an individual agent’s case recommendation is a skill fraud teams already have. It’s close to reviewing a junior analyst’s work. The real gap is pipeline-level governance, monitoring labeling systems, rule-recommendation engines, and model training processes that run continuously and were never built to be checked case by case. Silent pipeline failure is the risk worth taking seriously here, because these systems don’t raise a flag when something’s wrong. A mislabeling agent doesn’t pause. It keeps going until someone happens to notice the damage.

Root cause analysis doesn’t disappear, it just moves up a level

Fraud teams already know how to do this work. KPI monitoring for automated systems and root cause analysis in fraud systems are new skills. They’re the same instincts fraud analysts have always applied to a rule or model, just aimed at a new layer. Even in a best-case scenario where an agent writes a rule entirely on its own, a human still has to confirm it passed every test, doesn’t contradict existing business logic, and isn’t built on statistical coincidence. Multiply that across every automated system a team runs, and the question becomes whether anyone is tracking how often analysts have had to step in to correct something fundamental. If that number is climbing and nobody’s watching it, that’s exactly how a fraud program gets less safe while looking more automated on paper.

What failure actually looks like in practice

An agentic investigation system goes fully live, but the analytics team is still staffed for a world of quarterly rule reviews. This is the most common failure pattern. There’s no error rate threshold on the labeling pipeline. Rule audits happen monthly instead of weekly. The team ends up with more automation but no faster reaction cycle, and in some cases a system that’s genuinely less stable than before AI arrived. It’s a failure to scale governance at the same pace as automation, not a technology failure.

Funding this the right way

The savings from a leaner fraud ops team shouldn’t disappear into a general cost-cutting line item, they should directly fund scaling fraud analytics instead. Beyond the financial logic, this is also one of the more realistic paths to retaining institutional knowledge instead of losing experienced people entirely during a transformation. The number that eventually goes to a board may be higher than anyone expected going in, and it’s still worth bringing. Compressed into one line for that conversation is that fraud analysts are becoming the new AI team leaders. Not investigators, not engineers. And that is the role evolution this moment demands.

Final takeaway

Scaling fraud analytics isn't a nice-to-have that gets added if the budget allows it, it's the one staffing decision that determines whether an AI transformation actually works or quietly makes a fraud program less safe. Fraud ops shrinking is the easy, obvious part of this story. Fraud analytics growing is the part almost nobody plans for, and it's the part that decides whether the whole system holds together.

The teams that get this right won't be the ones that automated the fastest. They'll be the ones that scaled their oversight at the same pace as their automation, and funded that growth on purpose instead of discovering the gap after something already broke.

This is part of a series. If you landed here first, you may want to go back and listen to the previous episodes. We’ve already covered quite a lot that will make this one much easier to follow.

Catch up on The Rise of Agentic Fraud Ops, part 1
Catch up on The Rise of Agentic Fraud Ops, part 2

Not ready to stop the conversation about my, and hopefully your, favorite subject? Subscribe to The Saturday Fraud Strategist newsletter.

Connect with Chen Zamir | LinkedIn
Host of The Saturday Fraud Strategist
Helping fintechs build smarter fraud defenses
Co-author of “The Fraud Fighter’s AI Playbook

Episode transcript
Chen Zamir
Chen Zamir
00:06
We started this series by talking about the pressure all risk leaders are facing right now. Use AI to cut costs and by cutting cost I mean cutting headcount. But in fraud operations the push for automation also creates a risk. What happens when teams cut the very function needed to govern automated systems? In the previous episode in this series, we outlined what a transformation journey looks like when you move from mostly manual operations to AI powered ones. And as we've discussed, there's a lot of nuance to it, because it's not a switch you just flip. It's a journey with a specific sequence and dependencies. But one thing I didn't cover previously is how you establish AI governance as you implement more and more AI automation. Specifically, there's a second order effect almost nobody's planning. One function on your team doesn't shrink with AI adoption. On the contrary, it actually needs to grow. Because automation creates new oversight requirements that most teams do not have staff today. And if you don't account for it, you'll end up with a smaller team that isn't equipped to govern all the automated systems it runs. And let me tell you that would not end well. That function is fraud analytics. And without it, your system would break faster than you'd like to think. It is the control layer that catches drift, monitors automated decisions, and prevents silent pipeline failures. So in this video, I want to talk about how fraud teams usually look like, what AI governance really means, and what it means to your future organization.
Chen Zamir
Chen Zamir
01:43
In my experience, most fraud teams are built from four functions. Now, I will say in our industry, terms and definitions are very loose. Even the word fraud might mean different things to different people or even the same person when considering different contexts. So it might be that you've seen other names or other organizational structures to this. The point I'm trying to make is around co responsibilities and skill sets an organization holds, rather than how it's actually structured or named. So bear with me. Anyway, back to the four functions I usually see. The first is fraud ops which handles investigations. Reviewing alerts, making rulings, managing chargebacks, and so on. The second is fraud analytics which owns rules and monitoring. Writing detection logic, tracking performance, analyzing attack patterns and producing reports. The third is fraud strategy that sets the risk appetite, risk policies and are likely in charge of vendor selection and architecture. And the fourth and last is data science that builds and maintains machine learning and AI models. But as I mentioned, not every fraud organization has all four. And there are a few reasons for that. First, it might be that some of these responsibilities simply don't exist. Not every organization develops their own AI models, for example. In other cases, especially in smaller organizations, some responsibilities are simply held by the team leader. For example, fraud strategy. It doesn't have to be its own function. So in effect, the bare minimum for a fraud team and what you'll almost always say is just one function, fraud ops. Meaning you can run a fraud function even if probably inefficiently with nothing more than investigators reviewing alerts. At the same time, fraud analytics exists in a lot of midsize and larger teams, but it's often informal or undersized. And that creates a potential oversight gap when these teams begin using AI agents to label cases, suggest rules, cluster alerts, all the things we talked about in the previous episodes. Meaning, if you need analytical skills to monitor agentic powered fraud systems, most teams are behind where they should be. And if you're thinking of downsizing them even more, then you might be risking self-sabotage when adopting AI at the same time. Because here's the thing, the traditional fraud analyst role was already important, but in an AI powered fraud team, it becomes central. Why do I think we'll need a bigger fraud analytics function in the age of agentic AI? In one word, governance.
Chen Zamir
Chen Zamir
04:29
Not all agentic AI creates the same kind of work. And understand the difference is what explains why certain functions on your team grow while others shrink. When fraud teams first roll out Agentic AI, they typically start with investigation assistance. The agent assembles the case and proposes a resolution and the investigator reviews and approves. Which means that this workflow isn't so different from managing a junior analyst. The agent does the leg work and the investigator uses their judgment to validate. And that's the thing, your team already knows how to do that. Governing individual decisions over individual cases is something your team members already do today. But fully automated pipelines are different. Auto labeling uh case clustering, rule recommendations, model training, these decisions operate at scale. They run continuously and you cannot have humans running around after agents because that would slow you down. Exactly the opposite of what you want to achieve. But the problem is that these pipelines can still fail. And when they do, they fail silently. A labeling agent that starts misclassifying doesn't raise its hand. It keeps labeling until someone checks. A rule built on a coincidental correlation looks fine in the back test. This system fails silently. They fail at scale and they fail fast. Unlike a human investigator who notices when something uh feels off, an automated pipeline doesn't feel anything. It just continues to run and spew garbage. But the governance these pipelines need is the same kind of monitoring fraud teams already apply today. KPIs, monitoring, alerting, systematic performance review, and most importantly, being able to run a root cause analysis when something breaks so you are able to fix it. Not just say that it's wrong. Does any of that sound familiar? Observing system performance through data, noticing issues, understanding what causes them, and fixing them, that's the job of fraud analytics.
Chen Zamir
Chen Zamir
06:33
What is the takeaway from looking at those two governing approaches? The obvious assumption when you start rolling out Agentic AI is that you can downsize your fraud team. But that is only correct for one function, fraud ops. For another, fraud analytics, it's not that simple. In fact, for most teams, it'll have to be exactly the opposite. Why? Because investigators benefit most directly from what AI agents automate. The part of their day that consumed the most time pulling transaction details, running IP lookups, checking device history, cross reference accounts. That's exactly what agents handle, an investigation. Simply put, the efficiency gains are straightforward because what used to take 30 minutes now takes five. Naturally, the function needs fewer people. But fraud analytics on the other hand, and as we just discussed, is different. Right now the team observes data, compiles reports, write rules when new attacks emerge and tweak score cut offs when needed. But when agents take over those tasks, all the automated pipelines we just described become their responsibility as well. Now you might think, but wouldn't I be automating the analysts jobs too? And you'll be right thinking that. But you need to remember that while some of the work is now automated, all the new automation you deployed both in analytics and in operations will now fall under their responsibility as well. Let's take rule writing as an example. Even if we reach an ideal state where agents write rules from scratch completely autonomously, which is definitely a stretch goal, your human analysts still have to review them. They need to check that the rules proposed went through all the tests correctly, that they don't contradict your business logic, and that they are not based on shaky statistics. That's still work, and it's only the start because we're still making individual decisions over single rules. But we also need to monitor how well the agents are proposing rules as a whole. How many times have the analysts corrected something fundamental? Did this number grow since last month? And if so, why? And how can we fix it? And this is just one example of how tasks that don't exist today will land in fraud analytics. And take into account that by the time you'll get to monitor your rules recommendation agents, you probably implemented at least five to 10 other systems. So all of them would need monitoring as well.
Chen Zamir
Chen Zamir
09:01
Hopefully, the argument I've outlined for why you'd actually need more analysts when you start automating has been convincing thus far. But the sad reality is that many teams don't have a fully fledged analytics team and so are likely blind to their repercussions. If you don't manage existing automated pipelines today or if engineering does it for you, odds are you have a blind spot there. And so when such teams come under cost pressure, it's very easy to commit to cutting the function that you actually need to enable AI adoption. It's all too easy to get to a point where your agentic investigation systems goes live, cases are being assembled, labels are being generated, and rules are being proposed. But the analytics team is still sized for quarterly rule reviews. And then the labeling pipeline has no error rate thresholds. The rule recommendation audits happen once a month when it should be happening weekly. So your fraud system is more automated, but your reaction cycle isn't faster. Even worse, your system is less stable and less safe than it was before. Why? Because we scaled automation without scaling governance. And that's exactly the recipe for failed AI adoption projects. Because it's easy to forget that redesigning your system means also redesigning your team and not just cutting it.
Chen Zamir
Chen Zamir
10:23
In the first episode in this series, I stressed that redesigning your fraud prevention system will come at a cost and that you'd want to fund it through the cost cutting you achieve. Part of that cost and only one part is making sure your team is properly staffed in the fraud analytics department and that you can increase its size as you go through the transformation journey. To an extent, it means that the savings you make from the shrinking fraud ops team should fund the growth of fraud analytics. And this can also be a way to upscale and retain some of the headcount instead of losing all of the institutional knowledge entirely. Of course, it might be that the target budget figure you show your board is higher than what they or you anticipated at first, but it's mandatory to build the function the new system depends on most because we should expect fraud teams to have a new bare minimum makeup. Investigative capabilities will continue to be part of it, but not all of it. In addition to that, teams will have to include strong analytical functions to operate its agentic workers, monitor automated pipelines, evaluate recommendations, and maintain your system stability as a whole. Or to frame it simply, think of it like that. Fraud analysts will be your new AI team leaders. That's the framing your board would understand.