Sardine named a Leader in The Forrester Wave™: Financial Crime Management Solutions, Q3 2026

Learn More
FRAUDFORWARD
#119

Como criar um programa antifraude: a fraude na base

59 min

E aí, combatentes da fraude? Sejam bem-vindos de volta ao Fraud Forward!

Hoje sou eu quem está na cadeira do convidado.

Se você ouviu o episódio de The Saturday Fraud Strategist lançado junto com este, já sabe que Chen Zamir e eu decidimos trocar de papéis. Ele participou do Fraud Forward para me entrevistar, e eu fui ao programa dele para entrevistá-lo. Vamos juntos ao Money 20/20, em Las Vegas, e achamos que essa seria uma maneira divertida de começar.

Passo muito tempo fazendo perguntas. Estar do outro lado do microfone é uma experiência diferente, e Chen não faz perguntas fáceis. Esta conversa tomou rumos que eu não esperava totalmente. Acabámos por discutir como criar um programa de combate à fraude que funcione e, mais importante ainda, o que impede que isso aconteça.

Se você já entrou em uma organização que vinha combatendo fraudes há um ano, gastando dinheiro com fornecedores e contratações, e ainda estava no mesmo ponto de partida, este episódio é para você. A solução vai muito além de adicionar mais uma ferramenta.

O que você vai ouvir neste episódio:

  • Como elaborar uma avaliação do programa de prevenção a fraudes ao ingressar em uma organização que vem enfrentando dificuldades e ninguém sabe explicar o motivo
  • Por que a gestão de fraudes e riscos começa pelas pessoas, seguida pelos processos, pela tecnologia e pelos dados, nessa ordem — e por que a maioria das organizações começa pela tecnologia e acaba criando mais problemas
  • O modelo de planejamento de capacidade para prevenção a fraudes que desenvolvi como profissional da área para demonstrar aos executivos a necessidade de pessoal, incluindo o cálculo de três minutos por alerta e como criar um modelo de semana de 40 horas que leve em conta tudo o que sua equipe realmente faz
  • Por que a estrutura da equipe de prevenção a fraudes é importante antes de otimizar qualquer coisa e como decidir entre uma abordagem centralizada ou descentralizada antes de começar a contratar ou comprar
  • A estrutura de avaliação de risco de fraude que considero a ferramenta mais importante no programa de um responsável pela prevenção de fraudes, incluindo a diferença entre risco inerente e risco residual de fraude e por que a ausência de perdas não significa ausência de risco
  • Por que a sobreposição inadequada de tecnologias antifraude é como combinar medicamentos que interagem mal entre si e como é, na prática, uma análise de lacunas tecnológicas antifraude antes de uma demonstração de um fornecedor
  • Como a fraude de pagamento push autorizado compromete a estrutura antifraude criada em torno de uma única pergunta — este é realmente o nosso cliente? — e por que os sinais comportamentais para a detecção de golpes exigem uma abordagem completamente diferente
  • A estrutura bancária de intervenção contra golpes que usei como profissional, incluindo fricção direcionada, períodos de espera e a frase que considero meu momento de impacto
  • Como abordo a comunicação com executivos sobre fraudes e a defesa de programas antifraude quando a liderança vê as perdas num painel, mas não percebe os quinze milhões que a equipa evitou perder
  • O modelo de relatório de painel de fraude que eu gostaria de ver: tentativas de fraude, fraudes evitadas e perdas efetivas, normalizadas em relação ao volume de transações ou aos depósitos, e não apenas as perdas brutas decorrentes de fraudes
  • Por que a IA antifraude com intervenção humana não é escalável e o que a supervisão humana significa para o desenvolvimento de competências das equipes antifraude neste momento
  • Qual é o verdadeiro nível de maturidade dos programas de combate à fraude, com base no trabalho de benchmarking que venho realizando, e por que as equipes de combate à fraude estão se saindo melhor do que imaginamos

Você deveria ouvir este episódio se:

  • Está criando ou reformulando um programa de prevenção a fraudes e quer saber como eu realmente abordo esse processo desde o início — não com uma estrutura teórica de livro didático, mas com o processo real que usei na prática
  • Já precisaram justificar o quadro de pessoal, a tecnologia ou o orçamento para uma equipe de liderança que não compreende plenamente o que a prevenção a fraudes realmente envolve e querem um modelo que sustente essa necessidade com dados
  • Trabalha em um banco ou cooperativa de crédito, está sentindo a pressão da transição de fraudes não autorizadas para fraudes e golpes de pagamento autorizado por transferência e não sabe ao certo como adaptar sua estrutura de prevenção a fraudes
  • Quer o modelo de planejamento de capacidade para prevenção a fraudes que desenvolvi manualmente quando atuava na área, incluindo o cálculo de três minutos por alerta e o detalhamento da semana de 40 horas que finalmente fez a liderança dar atenção ao problema
  • Estão tentando entender como a IA se encaixa no seu programa de combate a fraudes sem perder os investigadores que vocês levaram anos para desenvolver
  • Lidera uma equipe de combate a fraudes e quer saber qual é o real nível de maturidade do programa de prevenção a fraudes com base no trabalho de benchmarking que venho realizando em instituições financeiras
  • Já entrou em uma sala e se deparou com olhares vazios ao perguntar à sua equipe o que realmente está causando as perdas por fraude, e percebeu que precisava de um ponto de partida melhor para essa conversa
Notas do episódio

Uma avaliação do programa de prevenção a fraudes quando a equipe não sabe o que está errado

Faça perguntas que ajudem a compreender a composição das fraudes, e não apenas as perdas decorrentes delas. A composição das fraudes mudou? As perdas migraram de fraudes com cartões para golpes? Foi lançado um novo produto digital sem que a equipe de prevenção a fraudes fosse informada? O volume de transações aumentou? O volume de alertas cresceu mais rapidamente do que as fraudes efetivamente ocorridas? Algum controle apenas desviou as fraudes para outro canal?

Na maioria das vezes, as equipas que estão a enfrentar dificuldades não conseguem responder a essas perguntas. E, se conseguissem, não estariam na situação em que se encontram. Isto não é uma crítica. É um diagnóstico. Antes de recomendar qualquer medida, procuro perceber se a estratégia de combate à fraude reflete efetivamente os tipos de fraude que a instituição enfrenta atualmente, e não os padrões de fraude de há três, quatro ou cinco anos, quando as regras foram originalmente definidas.

O modelo prático de planejamento da capacidade de combate a fraudes

Esta é uma das estruturas de que mais me orgulho, e eu a desenvolvi manualmente antes que a IA pudesse fazer isso por mim. O modelo começa com uma pergunta simples: quanto tempo sua equipe gasta por alerta? Não uma estimativa, mas uma medição real.

A minha equipa chegou aos três minutos como um meio-termo entre alertas simples, resolvidos em menos de um minuto, e alertas complexos, que exigiam cinco minutos de investigação. A partir daí, acompanhei quantos alertas foram analisados, quantos deram origem a um caso, quanto tempo foi despendido na investigação de cada caso, quantas chamadas telefónicas a equipa atendeu, quanto tempo foi dedicado a mensagens privadas e à comunicação interna, quanto tempo foi passado com vítimas de fraude e quanto tempo foi investido no desenvolvimento de processos e procedimentos.

Quando se calcula tudo isso com base em uma semana de 40 horas e se multiplica pelo número de pessoas na equipe, as lacunas ficam imediatamente evidentes. Também incluí requisitos anuais de formação profissional, créditos de educação profissional continuada (CPEs) e outras obrigações que a maioria dos modelos de capacidade ignora. O resultado é um documento que demonstra aos executivos não apenas que a equipe precisa de mais recursos, mas também exatamente por quê, com uma discriminação hora a hora. A defesa dos interesses da equipe de combate a fraudes por parte da liderança precisa ser orientada por dados. Dizer que estamos sobrecarregados não basta. É preciso apresentar os cálculos.

A estrutura de avaliação de riscos de fraude

Minha posição é que uma avaliação de risco de fraude é o elemento mais importante de que um programa antifraude precisa para justificar os recursos necessários. E a maioria das avaliações de risco de fraude é feita de forma incorreta.

O objetivo não é confirmar que a fraude em transferências bancárias representa um risco elevado. Todos no setor já sabem disso. O objetivo é responder a quatro perguntas específicas. Onde estamos expostos? Qual poderá ser a gravidade dessa exposição? Que controlos temos e qual é a sua eficácia? E o que vamos fazer em relação ao risco residual?

É nessa última pergunta que a maioria das avaliações falha. Se a avaliação for concluída, receber classificações em vermelho, amarelo e verde, for apresentada a um comitê uma vez por ano e nada mudar em termos operacionais, o exercício não terá servido para nada.

O risco inerente é o risco existente antes de se considerar qualquer controlo. O risco residual é o que permanece após a aplicação dos controlos. O erro que a maioria das equipas comete é avaliar o risco inerente com base nas perdas históricas. A ausência de perdas não significa ausência de risco. Pode significar que os seus controlos estão a funcionar. Também pode significar que os autores de fraude ainda não descobriram essa vulnerabilidade. O meu exemplo de fraude com cheques torna isto mais concreto. Se todos os cheques que a sua instituição alguma vez aceitou fossem fraudulentos e não existisse qualquer controlo, qual seria o seu grau de exposição por cheque? Esse é o seu risco inerente, não o seu histórico de perdas.

A fraude de pagamento push autorizado põe em causa tudo aquilo em que se baseia a estrutura de prevenção de fraudes

Durante anos, a minha infraestrutura de combate à fraude foi construída em torno da pergunta: trata-se realmente do nosso cliente? Dispositivo, palavra-passe, autenticação multifator, biometria e autenticação por endereço IP — tudo isto responde a essa pergunta. As burlas introduzem uma segunda questão à qual a autenticação não consegue responder: o nosso cliente compreende o que está a fazer? Posso provar, com um grau de certeza quase absoluto, que foi o cliente quem iniciou a transação. Isso não prova, de modo algum, que não o tenha feito por alguém o ter convencido de que o seu dinheiro estava em risco.

Os sinais comportamentais usados na deteção de fraudes funcionam de forma diferente. Este comportamento é normal para este cliente? O destinatário é novo? O cliente alterou recentemente os dados de contacto? Aumentou os limites de transferência? Adicionou um novo dispositivo? Transferiu dinheiro entre contas imediatamente antes da transação? Está a esvaziar uma conta que levou vinte anos a constituir? Cada sinal, por si só, pode não significar muito. Em conjunto, contam uma história. E essa história exige uma abordagem completamente diferente daquela que desenvolvi em torno da autenticação.

Comunicação com executivos sobre fraudes e como a IA pode transformar o combate às fraudes

Se o conselho de administração vir apenas as perdas decorrentes de fraude, estará vendo apenas as falhas. É preciso mostrar também o que o programa está conseguindo impedir. O modelo de painel de fraude que proponho inclui tentativas de fraude, fraudes evitadas e perdas efetivas, tudo normalizado com base em um indicador relevante, como volume de transações, crescimento da base de clientes ou depósitos. Uma perda de dois milhões de dólares tem um significado muito diferente em uma cooperativa de crédito com ativos de quinhentos milhões de dólares e em um banco com ativos de cinquenta bilhões de dólares. As perdas são fáceis de medir. A prevenção é difícil de mensurar. O painel precisa mostrar ambos; caso contrário, a liderança verá apenas metade da realidade.

Vou ser totalmente transparente. Não tenho uma resposta definitiva sobre como a IA muda o papel do investigador de fraudes. O que tenho é uma direção clara. O modelo human in the loop, no qual os investigadores analisam e validam cada decisão da IA, não é escalável. O modelo human on the loop, no qual minha equipe define as políticas e supervisiona os sistemas de IA, em vez de analisar resultados individuais, é o caminho que essa função está tomando. Meu conselho para as equipes de combate a fraudes é que comecem a aprender agora. Identifiquem de quais tecnologias seu programa provavelmente precisará daqui a dois anos e comecem a desenvolver as competências que tornarão os investigadores valiosos nesse ambiente. Não conseguiremos adotar uma abordagem preventiva e proativa contra fraudes contando apenas com pessoas. Precisamos começar a investir em nossas equipes agora, para que estejam preparadas quando esse momento chegar.

Principais conclusões
  • A criação de um programa de prevenção a fraudes começa pela compreensão dos motivos pelos quais as perdas estão ocorrendo, antes de se presumir que a solução seja investir em mais tecnologia ou aumentar a equipe. É preciso entender os tipos de fraude, o volume de alertas e o posicionamento dos controles antes de propor qualquer solução.
  • Meu modelo de planejamento de capacidade para prevenção a fraudes parte de três minutos por alerta e traça um panorama completo de uma semana de 40 horas, demonstrando aos executivos, com dados em vez de frustração, as lacunas de recursos.
  • A diferença entre risco inerente e risco residual de fraude é a parte mais frequentemente mal compreendida de uma avaliação de risco de fraude. A ausência de perdas históricas não significa ausência de risco inerente. Pode significar que os controles estão funcionando ou que os fraudadores ainda não encontraram a vulnerabilidade.
  • A adoção de tecnologias antifraude em camadas significa entender onde cada componente se encaixa e como se integra aos demais, em vez de adicionar outra ferramenta sempre que algo não funciona. A análise de lacunas nas tecnologias antifraude, realizada antes de uma demonstração do fornecedor, é o que diferencia uma estratégia eficaz em camadas de uma combinação de medicamentos com interações prejudiciais.
  • A fraude de pagamento push autorizado exige uma abordagem completamente diferente da fraude não autorizada. A autenticação comprova a identidade, mas não a intenção. São os sinais comportamentais de deteção de fraudes que colmatam essa lacuna.
  • Minha estrutura de comunicação sobre fraudes para executivos apresenta as fraudes evitadas juntamente com as perdas reais, normalizadas em relação a uma métrica relevante, como o volume de transações. A liderança precisa ver ambos os números para entender o que o programa está realmente fazendo.
  • A supervisão humana é a direção que o desenvolvimento das competências das equipes antifraude precisa tomar neste momento. Governar sistemas de IA no nível das políticas exige competências diferentes das necessárias para analisar alertas individuais, e a hora de desenvolver essa capacidade é agora.
Conclusão final

Chen fez-me perguntas difíceis nesta conversa, e ainda bem que o fez. A conversa que acabámos por ter é aquela que eu gostaria que mais responsáveis pela prevenção da fraude estivessem a ter dentro das suas organizações neste momento. Criar um programa de combate à fraude não é um exercício pontual. É um processo contínuo de avaliar em que ponto se encontra, compreender o que está a determinar os seus resultados e garantir que a sua estratégia reflete efetivamente a fraude que observa hoje, e não a que observava há cinco anos. Se esta conversa lhe deu algo para partilhar com a sua equipa esta semana, espero que tenha sido a liberdade de abrandar antes de comprar a próxima ferramenta e de se perguntar se sabe realmente qual é o problema que está a tentar resolver.

Se quiser me ouvir inverter os papéis com Chen, acesse o The Saturday Fraud Strategist para conferir a outra metade desta conversa.

Até a próxima. Mantenha-se vigilante, mantenha-se informado e continue impulsionando o combate à fraude.

Conecte-se com Chen Zamir | LinkedIn
Apresentador do The Saturday Fraud Strategist
Ajudando fintechs a criar defesas mais inteligentes contra fraudes
Coautor de “O Manual de IA do Combatente de Fraudes”

Conecte-se com Hailey Windham, CFCS | LinkedIn
Apresentadora do podcast Fraud Forward
Líder da comunidade bancária na Sardine
Especialista certificada em crimes financeiros (CFCS)
Destaque do setor de cooperativas de crédito em 2023, CU Magazine
Prêmio de Melhoria Contínua, SAFE Federal Credit Union, 2023
Uma das 20 principais profissionais com menos de 40 anos, The Sumter Item, 2022

Episode transcript
Chen Zamir
Chen Zamir
00:05
What's up, fraud fighters? I'm Hailey. No, you know what? I'm tired of this charade. Uh, the tokens cost me too much. Uh, being like a fake uh fake blonde with a fake southern accent. I cannot afford it any longer. And I want to admit it's been me all this time. Uh, Chen Zamir. No. Uh, just kidding. Hailey, it's so great to be uh on your show as a guest interviewer. How are you?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
00:34
I am doing so well and I'm I'm so glad that the the truth has finally come out and I mean come on.
Chen Zamir
Chen Zamir
00:40
Yes.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
00:41
It's really been you this entire time.
Chen Zamir
Chen Zamir
00:44
Yes. You know, well, uh I thought uh tokens would be cheaper than uh wigs, but apparently that's not the case. So, I'm done with that.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
00:53
I'm just so glad you agreed to to come in on my podcast as well. We just uh recorded the reverse interview on yours and now we're kind of uh flipping the script again and letting you take the lead on the podcast on on Fraud Forward.
Chen Zamir
Chen Zamir
01:09
Yes, absolutely. And if you didn't catch uh the episode of the Saturday Fraud Strategist, uh Hailey and I spoke about why we're doing all of that. And that is because I'm actually not exactly sure when this episode is going to drop, but probably a couple of weeks after you're listening to this, we are heading to Vegas uh to participate in Money20/20. Hailey, do you want to uh uh give the juice about it?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
01:34
Yeah, I am so stoked. Um last year I went to Money20/20 and um I got lost everywhere I went in the Venetian. Um so I'm really excited to do that again. Uh but this year I will have a partner in crime. Chen Zamir and I will be at uh the Sardine booth. We will be recording podcasts throughout uh the the days um of Money 20/20. And we'll also just kind of be floating around having great conversations with people, hosting a happy hour or two. And I'm just I'm really excited and looking forward to to that time where we can meet in person um and then people can experience the magic of us uh live in in Vegas.
Chen Zamir
Chen Zamir
02:12
It's just me. We just said it. It's just me. There's no Yeah. Yeah. There's no Hailey.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
02:17
There is no Hailey.
Chen Zamir
Chen Zamir
02:23
Yeah. You know, it's a funny thing because I I was just trying to think. I was in in Money 20/20 Vegas once and in my mind it was always like around 2018 2019 and I couldn't quite recall. But one thing that I like that really stuck to my memory is that I remember staying uh back then uh at the Trump Tower and I remember that being like just before the elections and I said well that doesn't make sense because in 2018 2019 Trump was already president and I was like going through my through my uh phone pictures uh like the other day and I realized that actually I've been there in 2016. It was two months before the elections. Yeah. And actually that would mean that I'm now returning to Money 20/20 Vegas after a full decade. So that's a bit of a mindblower.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
03:16
Yeah.
Chen Zamir
Chen Zamir
03:17
Yeah.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
03:17
You're showing your age there.
Chen Zamir
Chen Zamir
03:20
Uh yeah. Yeah. Uh okay. First question. No. Okay. So I'm super stoked about uh by the way we will meet for the first time uh in person in Vegas. So I'm I'm yeah I'm really looking forward to it and and a bunch of other uh Sardine folks. So yeah I hope to see you all there. Um I want to go uh directly into the topics that I wanted to speak about today Hailey and you know uh I speak a lot about fraud strategy and somehow we never got to talk about it. So I like I'm super curious because you know I had a lot of different conversations with a lot of different folks when it comes to you know fraud strategy and especially when you go into like a new organization. And you've said both you know wearing a hat of a practitioner wearing the hat of a consultant wearing the hat of uh of now a vendor um and you you kind of like you know you need to quite quickly understand what's the what's the state. Uh what is going well and maybe where are the gaps and and and try to kind of like you know give advice or you know like give some guidelines or you know like make your plan as to how best to go about it. And when I talk to like fraud strategists I always hear different answers but around the same principle. So you know I I wanted to start with that and kind of like hear where you stand and how you work. So let's say for the manner of the example let's say that you're you know you're going into organization and an executive tells you look we've you know we've invested in fraud a lot. We've hired more folks. We integrated a couple of vendors. We've been fighting it for a year. We're pretty much at the same place. What how would you go about it?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
05:20
Well, I think it's a matter of obviously understanding where they are. You have to look at, you know, we're going to talk a little bit more about risk assessments, but trying to understand fully holistically, right? What they have, what products and services they have, where their exposure could be. I'd also want to ask like if if nothing has changed or if if losses are increasing, right, and and your teams are overwhelmed and it's like do we throw more resources at it? Do we throw more money at tech? But I don't think that's where we need to do. That's what we need to do. I, you know, I I would never immediately assume that any organization needs another tool or another person. I want to understand what's driving whatever fraud increase that they may have. You know, did the the did the fraud mix change? Did losses move from card fraud into scams? Did a new digital product launch that you didn't tell your fraud team about? Did transaction volume grow? That never happens, right? Um,
Chen Zamir
Chen Zamir
06:17
Never.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
06:18
Did alert volume grow faster than like actual fraud? Did we introduce a control somewhere that just shifted fraud into another channel? Because that happens a lot too. Then I want to, you know, look at the program from different angles that from risk from people, process, technology, and data. A lot of organizations start with technology because that's the easiest thing to point to. We're losing money so we need a better fraud tool maybe. Or maybe the tool is generating perfectly good alerts and you don't have enough people to work them. Maybe you have enough people but they're spending 70% of their time clearing false positives. Maybe your rules were designed around fraud patterns from three, four, five, 10 years ago, right? And and maybe nobody has stepped up and asked whether your fraud strategy actually reflects the fraud that you're seeing today. And that's where I think, you know, good risk assessment becomes incredibly valuable.
Chen Zamir
Chen Zamir
07:15
You know my like I agree 100% with everything that you said. I would say that my general experience is that when you ask these smart questions to a team that is struggling usually the answers would be I don't know. Or the answer the singular answer would be I don't know because if they would be able to answer these questions most likely they wouldn't be in that hole. So, you know, what do you do in, you know, in this instance where, and I'm guessing that, you know, maybe maybe some of our listeners right now, you know, also have exactly the same thing that, you know, they they see the pressure, but they don't necessarily have the ability to really understand exactly what's going on. How like what would be the best piece of advice to such teams
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
08:05
In regards to like pressure testing?
Chen Zamir
Chen Zamir
08:08
Not necessarily pressure testing, but like you know, let's say, you know, they see that their fraud rates are up, but they don't necessarily know how many false positives they have. They don't necessarily know from which flow it arrives. They don't necessarily know, you know, how much of that was missed by the investigators versus how much of that was missed by rules. So because usually if you know if if they would have the foresight to ask and answer these questions usually they would also be able to kind of like optimize around these things. So what happens in the case where you know you you just get blank stares when you ask these kind of questions which which I'm guessing happens from time to time.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
08:51
Oh it definitely happens from time to time. That's why I always uh I think culture matters so much in whatever organization you're at. For me, whenever I was a practitioner, it was I didn't understand not only the infrastructure because I was new coming into that role to build a fraud program. So, I didn't understand the infrastructure completely for the organization, but I also didn't know anyone really in the organization. But they knew that I was the girl that was going to stop transactions because I was in fraud. So, I was going to implement rules. I was going to create processes that just made everyone hate their lives. Um, and I was basically going to come in like a bull in a china shop. It was the perceived uh notion of of what I was doing there, what my role was. So instead, I focused on number one making friends in the organization. And I don't mean by offering to take them out to lunch, but I mean by truly sitting down with the the workers. So, I would go to e-services and instead of going directly to the director, I went to the people hitting the button every day, the ones that were working in PIK um which was our um basically a digital channel for like check deposits um and they and ATM deposits. And so I went and sat with them and I said, "Hey, explain this process to me." And when they saw that I was somebody that actually wanted to not only understand the process first, but then help and make sure that we're creating process efficiencies as well. Which is what I think works really well for fraud uh programs. Anyways, if you kind of structure yourself with that operational hat in which the benchmark report that we have coming out um hopefully this week, hopefully it will be live before this uh this recording comes out. But what you'll see in in the benchmarking is that a lot of fraud professionals and financial institutions came from the operations uh department or operations side of the organization which is a great thing because they understand the payment method. They understand where in our infrastructure is the last point of interception before the fraud leaves right where's our last point of contact where we can say okay we don't want this to happen. So anyways, whenever you're you're going in and you're understanding the infrastructure, you're creating process efficiencies before you even look to say, "Hey, what things do we need to implement to prevent fraud?" That's where you're going to see a lot of good things happen for your organization as a whole. When it comes to preventing fraud, it's developing that culture and making sure that you understand the process yourself before trying to implement any kind of changes, even new tech. You know, you don't want to do that until you fully understand the tech that you currently have.
Chen Zamir
Chen Zamir
11:19
Yeah, I love that because it, you know, goes to show that, you know, nothing beats data and if you don't have data, nothing beats leg work, right? So,
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
11:29
Yeah, and I think I hope I answered that question for you.
Chen Zamir
Chen Zamir
11:33
No, no, definitely. Definitely. I think cuz in the end you you need to get this data right uh and going to the source, you know, in these kind of situations there there's nothing that can really replace that.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
11:45
Yeah.
Chen Zamir
Chen Zamir
11:46
And it takes time and effort, but it is what it is. Um I wonder you know we talked a lot about uh data and the product and the operations or processes side. I wonder when it comes to the organization itself what do you think like how do you how do you assess the organization itself? How it's built? How it is you know accounting for ownership? How it is measured? Um how um you know what kind of skill sets or how do you do hiring or train like how do you look at the organizational piece when it comes to fraud strategy is it part of fraud strategy in your mind or is it something completely different
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
12:31
No 100% I think also you have to answer the question are you a centralized fraud program or a decentralized fraud program. Centralized is all the fraud comes to you you handle all the disputes all the chargebacks everything like that that comes directly through you where decentralized is you're kind of sitting as this advisory level of here's how we should here's how I would here's what I'm learning from the industry and where we can improve this particular fraud scenario. Right? Or or however it happens in your organization. Um and once you have that answer then it makes it easier for you to basically figure out where where you are. If you're looking at um your staffing your current staffing you can't just say, "Hey, I need another fraud analyst." That's not going to work. You have to show the the data for why you need another analyst. Do a capacity planning model. What I did, um, and this was a very manual process back in my day before, um, before we had AI that could do these things for us, and which most organizations won't really allow you to, um, implement these things right now. Anyways, um what I would do is I literally pulled all of our alerts and I would say, "Okay, how often or how much time are you spending per alert?" And we came up with an average minute time frame. So, some some alerts you could go through really quickly, but be within a minute. There were others that you had to actually dive in and look at and they'd be five minutes. So, we came to a compromise of three minutes and we would go through and we'd see how many alerts we had, how many that were worked, right? And then we would compare that and put it in a timestamp of okay, we have 40 hours a week. Here's how much time is allocated to these alerts. Here's how many of those alerts actually produced a case. By the way, case investigation, how much time are we spending per case investigation? Then you have to consider how many phone calls are we getting each each month? How or week? Um how many uh times are we getting a private message on whether it's Teams or Slack or whatever your organization is using. How much time is spent answering those? How much time is spent on a phone call with a victim trying to deescalate a situation and talk them down? How much time is spent developing processes and procedures? And whenever you calculate all of those things and you put it in a 40-hour week and you times it by however many people you have on your staff, you quickly find out, hey, we're we we've got some big gaps here. If we don't fill it, this is how we can prove that. We also did it. We also included like our professional training. So if you're required to have a certain number of CPEs a year, we we did it as an annual total, not just a weekly total. But we're able to then prove to executives that even these things that we have to have factor into how much time is needed because we can't just assume, hey, guess what? We can turn on this new alert, but how many alerts is that going to create for your team to work? Run a test first. See how many if you're cutting it on, if it's got a particular parameter that you're wanting to use, go ahead and let that test run and see how many would have alerted. Check to make sure you have the capacity to fill that in before turning it on. Otherwise, you're just creating more um more instances where you are going to be drowning and it's because of your own demise.
Chen Zamir
Chen Zamir
15:46
Yeah, I love it how again it all comes back to you know how you can quantify different facets of your program whether these are the processes, the organization, uh the technology. And what I love about it is that you know it makes our domain right at least when you approach it in the right way. It makes it very unemotional right I mean there are no opinions here it's just you know what the data tells us and what we want to or how do we want to react to that? Uh and and I really like this approach. Um
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
16:24
Yeah, I I will say I love that you mentioned the opinion aspect. Um one of the things that I struggled with when building my fraud risk assessment, I was trying to understand it. I would go back to my risk officer, which she wasn't a lot of help. So I had to go to one of the associations and found me the most amazing mentor um who guided me through what a fraud risk assessment is. And one of my main questions that I brought up to my chief risk officer at the time was, okay, here's a here's a part on our risk assessment that says, um, the board receives fraud training. Well, the answer to that is yes, they do, but is it effective fraud training and how could I quantify what it was or or how effective it was or not? And so, for my opinion, and my opinion was a a selfish one at the time, I'll be honest with you. I was like, well, I'm not giving the fraud training, so clearly it must be subpar, right? No one can teach fraud like I can. Um, I know not in my organization. So, whoever is conducting that fraud training in my organization, they're not the fraud expert. They didn't even ask me to input into the fraud training. So, for me, I said, I haven't seen it. I don't think it's adequate because I haven't seen it and you're not showing me. But that was more of an opinion based on something that I didn't truly know. The question was, does the board receive fraud training? And the answer is yes. There are ways that we could improve, but again, the way that we would say, "Hey, it's not effective at all right now," is if people on the board were falling for fraud scams, they were mixed up in something um that you know, maybe it was some insider issues. Which I just reported on the Monday uh Fraud Fix newsletter where there was an instance where there was a board member who did misappropriate funds. Um, but if that situation wasn't happening in my organization, then I needed to say accurately that yes, there was fraud training and yes, it currently is effective. I couldn't use my opinion. I had to go off of the facts. And that was that was really hard for me because I knew in my heart of hearts I was like, but it could be better. And so I just used that, you know, residual risk response was board currently receives it. However, it's not given by the fraud leader of the organization. Um and there's no um uh there's no insights that are being provided by the fraud leader either. So this is a a situation that it could be improved.
Chen Zamir
Chen Zamir
18:50
You know, I I can relate so much to to what you just said. I think you know what like if you ever worked with me uh you know that you know I'm not uh I don't have the smallest ego in the world. Uh and when when it's like your team, when it's your organization, when you are the one building it, it's like it is very hard to separate your ego from the data that you're there. There are always like, you know, ways to tell stories with data and there are always ways to add these caveats and asterisks and say, "Yeah, the data shows XYZ, but actually ABC." Um, and honestly, this is a bit what I like about coming like into an organization from the outside where where I have no stakes is that it allows me to be like much more um, you know, impartial, but it also, you know, like I can definitely understand why people get defensive uh about these things. So, I I I really related uh uh to this to that story of yours. Tell me a bit. I know maybe that is something that you know would be like learning the ABC for you and your audience but I'm not you know I didn't grow up in uh in banking I grew up in fintech. And it it smells to me like fraud risk assessment is a loaded term that's an actual kind of like you know like a a specific process a specific artifact. What is it and and you know how would you approach a fraud risk assessment today knowing what you know and with your experience that maybe you haven't done the same when you just started.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
20:36
I I love that you asked this question. Um and I actually I have to tell you a funny story and then I'll answer your question. Um I did a presentation on fraud risk assessments um early this year. And um our our really good friend Eduardo I sent him the presentation to just review the slides. And he asked me he goes why would anybody want to do a fraud risk assessment? Now in my mind I was like what do you mean why wouldn't they want to do one? And the fraud risk assessment is the most important thing that you need for your fraud program in order to advocate for things that you need. And I went on this big passionate tangent with him and He goes, "Hailey, I was asking because you didn't answer that in the slides." He was like, "I'm not saying that they're not important. I just needed you to answer it in the slides." And I was like, "Oh, okay. I thought you were saying why would I present on fraud risk assessments when clearly it's the most important thing you could do." So, I I just wanted to share that little caveat. Whenever you asked that just now, it just reminded me of that. Um so for for like the general right a fraud risk assessment should not just tell you know you that you a particular fraud or payment type is is a high-risk fraud. Um you know for example wire fraud is high risk and debit card fraud is high risk. I can uh probably tell you that without spending three months building a a spreadsheet I could tell you that yes debit card fraud is is high risk. Right? I don't have to that's not the purpose of it. The purpose is not to say yes, this is a high-risk item. We know that. But what a fraud risk assessment should answer is where are we exposed? How severe could that exposure be? What controls do we have? How effective are those controls? Where is the residual risk? And and what are we going to do about it? That last question is where I think a lot of fraud risk assessments fall apart. You know, if we complete a fraud risk assessment, assign everything a a red, yellow, or green box, present it to a committee once a year, and nothing operational changes afterwards, then I'm not sure what you accomplish with that. But the assessment should influence where you're spending money, where you're adding controls, where you're monitoring more closely, and where you're accepting risk, and where you're putting people. So, you know, we there's a challenge that I would say, you know, we haven't experienced much fraud in this channel. So, we've rated the inherent risk as low. That's one of the biggest mistakes you can make. Inherent risk is the risk before you consider your controls. So, whenever you think about like check fraud, right? You're going to say, "Well, check fraud, we've done a great job and blah blah blah." No. Look at each check and that you've taken in that's fraudulent or taken in in general. What happens if that check was fraudulent? How exposed would you be if you had absolutely no controls? And you're doing this per scenario, not per uh product. And and that was another thing that I had to learn too because I was looking at like our check fraud losses in general. That doesn't work. You have to look per item, right? A lack of loss doesn't automatically mean that it's a a lack of risk. So maybe you haven't experienced losses uh precisely because your controls are working or maybe fraudsters simply haven't found that weakness yet. Um, but I want to look at things like transaction volume, dollar exposure, customer behavior, uh, product design, speed of funds, movement, authentication methods, external thread intelligence, and what we're seeing across the industry. Historical losses and is an input, but it cannot be the entire risk assessment. Otherwise, we're essentially saying, you know, nothing bad has happened yet, so we're fine. That that's not risk management. We have to look at it holistically. Look to see, okay, here's where we have a gap in our current process. This is something that that would help us going forward if we were to get and that's how you respond back with that residual risk, right? So the inherent risk is how big of a risk it is without any controls. You put your control effectiveness and then that uh residual risk is what you end up with. Um, so it's a really fun exercise for you to do to truly understand where you're where you are exposed, how well a product is performing. And that's the other thing people think that fraud risk and fraud reporting is just telling the bad story. It's like, all right, here's the we know this is where we're going to get our our deep minus, right? This is where we're going to look and see, oh, well, fraud happened. We don't want to ever read this part of the report. No, you've got to show the positive things that happened in it. How well are these controls working? We can see it monthly on our fraud report, but in this annual risk report, we're looking and saying, "Hey, okay, overall, our controls are doing a good job. They could be better, and here's how we how we can make those better, or here's here's where we need additional resource. Here's where we need another tool or something." But you can't automatically say it without providing that backup data.
Chen Zamir
Chen Zamir
25:27
Yeah. So, good. I mean it's uh it's such a great piece of advice and I think uh you know because again that maybe we use different terms but the principles are are the same. Uh many fraud teams that I encounter really fall in this trap of thinking that you know if we're good on this side it will continue to be good forever. Uh and we should not worry about it we should not pay attention. Uh and so on and in reality actually a lot of the times when you have these loss spikes a lot of the times they would come exactly from these points because like the the fronts that you usually pay attention to are also, you know, the fronts where it's harder to surprise you. Uh the fronts where you invested more, uh the fronts where you catch uh loss spikes earlier. And actually, it's the neglected parts of your system, the ones that usually are neglected because you think they are working well that you know many times end up uh biting you on your backside. So yeah, I think that's a great great great piece of advice. I want to circle back to you mentioned a couple of times technology. I kind of like, you know, got the sense in between the lines that you don't see technology as really a solution to fraud strategy gaps. That's that's the the sense that I got. Uh tell me tell me more.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
26:57
Uh yes, I I don't think that a solution is is always the the answer. I don't think that it's always that you have to buy a new technology. And I say that while working for a fraud technology company, uh technology can dramatically improve a strong fraud program. It can also help expose where a program is weak. What it cannot do is magically fix a strategy that doesn't understand the problem that it's trying to solve. You can buy the best fraud platform in the world and still have bad outcomes if your data is poor, your processes are broken, nobody owns the strategy, or your teams don't understand the tool, or you're measuring the wrong items. One of the questions I think every institution should answer before another vendor vendor demo is what problem are we actually trying to solve? Not oh god we need AI. Not hey we need we need real-time fraud detection. What is the problem? Is it account opening fraud? Is it scams? Is it checks, mules, alert volume? You know investigator efficiencies, false positives, data fragmentation. Those are very different problems. But I think like to answer the the other question right of like when does technology actually solve the problem. I think that's when you clearly connect the capability of that technology to the problem. If if analysts spend hours moving between five systems to investigate one case, technology may absolutely solve that. Right. Um I I've seen it myself Money 20/20 last year. I was very excited about Sardine's uh platform where the OSINT was available within the platform. That's the case management. That's something that I didn't have before and something that I struggled with our um chief information officer where or I couldn't go into, you know, the Google searches and and whatnot to use for my case data um and for my investigation. And so having that availability within that, yeah, that's that's a scenario where technology can solve it. If you're missing fraud because your current system can't connect signals across channels, technology could absolutely solve that. If you're generating 50,000 alerts and 49,000 of those are garbage, technology and better modeling may solve that. Yeah, it's so true. Um, if you have no fraud governance, no documented strategy, and nobody can tell me what the institution's highest fraud risk are, buying tool number seven probably isn't going to fix it. I heard um at a fraud conference that we misunderstand what layering is with our technology. Um layering doesn't mean that we simply add another and another and another. It means truly understanding where it fits where your technology piece is. And if a technology isn't working, you don't just buy one to to fix it. I think about um there was a probably I think it's Criminal Minds or NCIS, one of those uh shows where you dive into fraud, right? Or or dive into some kind of criminal case. And they the woman was she started with high blood pressure, took a high blood pressure pill, it caused her to have something else wrong, so she took another pill. Well, that caused another symptom, so she took another pill. And before long, she was taking like 12 pills a day and they were all doing something together that they didn't need to do. And it caused her to have kind of like this mental breakdown, which I feel like that's where we are with our our fraud technology is we just want to keep layering and layering and layering. But that's not what really layering is. Layering doesn't mean we're just adding more. Layering means that we have to understand where it all fits in the overall infrastructure and how well it integrates into those systems and communicates into those systems.
Chen Zamir
Chen Zamir
30:35
Do you can we can we like go one well layer deeper? Uh like I I think this is this is a very very important point. Can you maybe give like a concrete example of how you've seen layering done right in you know in a fraud stack context and you know what were the principles behind that? I think like hearing about that in a bit more detail would be like very enlightening.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
31:05
Yeah, absolutely. So we had a scenario with this was real time uh for us we did for those ATM and mobile banking deposits right we thought okay well we need to add in another product to prevent the fraud right now because what we're using that integrates with our core it's not exactly catching it in real time we're having to do all of this in batch processing. Okay. Well, that wasn't going to work in order to keep us in that proactive preventative fraud strategy, right? So, what we needed to do was first understand where the gaps were potentially within our current integration. Is there something that we're missing? Is there a plug that didn't happen? Is there a scenario where if we just had this one department connect this one piece of the data in, could we then turn this into real time? And by doing so, then do we need another layered partner or could we now allow for additional types of fraud to go through that we could stop? Meaning, could we increase our limit? So instead of saying okay the only capability we have right now is that we can look at one check per account per day and and that's how we can prevent fraud is just by signaling that one. No we can say they could do 10 and we can trust it because we know we're going to use check 21 return data. We're going to use image data analysis and we're going to compare it to all other deposits that have been made into this account. An example of how we would use this. Think about like lawn care companies that are using like they are DBA accounts. So doing business as it's a person's account that's it's tied to their social. They don't necessarily have a business account, but they're doing a side hustle. This is a a DBA lawn care service. When they get paid, they get paid on uh at the end of the week. They get, you know, five checks from different people. We know that any other consumer account we're going to look at and we're going to say I don't know if I trust that. This is this is odd. Why are we depositing so many checks on on this day for odd amounts? Like that doesn't make sense. We want to see how it ties in. And then being able to look at the account overall holistically. We're going to pull data not just from the checks, not just from check 21 return data. We're going to look at the core. We're going to look to see how they're onboarding for their online banking. Is it new? Can we see all of that in one thing? Can we get that holistic picture from one system versus having to go to three different systems in order to get that view? So, that's where for me that I've seen layering work. It's where we are combining it all into one platform versus having layered uh tech stacks that we have to go into the different tech systems in order to to get that full holistic understanding within an investigation. I hope that answered. I know I was kind of long long winded.
Chen Zamir
Chen Zamir
34:00
Yeah. No, no, no. That that was great. I think I mean it exemplifies the fact that actually, you know, going back to like entire theme is technology, you know, part of uh fraud strategy. Is it a tool? Is it a strategy? And I think that it really exemplifies this this example that you gave how much it's not about okay we need capability X. But it is really about doing a gap analysis of your own stack and understand which data points are missing. And are they missing in real time, or are they missing in core, or are they missing wherever. And what vendor can we find that can specifically solve this gap? And how we can weave that into our existing fraud stack? And many times that requires I mean first of of all, it it makes you ask very pointed, very smart questions when you do vendor assessment. And B, it also Go ahead. Go ahead.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
34:56
I was just going to say, yeah, I I think that it's really important too to understand that a good technology partner should be willing to understand your product, your problem before telling you how their product is the answer. They should understand, you know, if if we're talking specifically about bankers, right? They should understand banking operations. They should understand that fraud doesn't live neatly inside one channel. They should understand or they should be able to help you understand your data. Um should be transparent about what their technology can and cannot do. Um and then most importantly, the relationship shouldn't end when that contract is signed. Fraud changes constantly. Your technology partner should be able to help you adapt with it.
Chen Zamir
Chen Zamir
35:40
Yeah, I I absolutely agree. And I think it goes back to like you know the general theme of you cannot really take any shortcuts here. And throwing money at the problem whether this is more technology or whether this is more people in most cases in vast majority of cases would not do much. And you need to do the leg work, you need really to understand what is it that you need. So yeah I agree with this so much I want to ask you all of this sounds pretty straightforward and if you've been in fraud for a few years. Hopefully, you are familiar with these principles. And yeah, you can always learn and get better. But generally speaking, I think it is pretty straightforward. But in the last few years, we are, you know, we are faced with scams. And I think scams more so than the insane spike in losses that we're experiencing since 2022, 2023, it puts a whole different pressure on your fraud stack. It puts a whole different pressure on your fraud strategy. Let's start with why. How come? Like how like why are scams so difficult to deal with?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
36:48
Well, I think it's because um first of all, I'm I'm going to call you out because yeah, I gave you all the hard questions and now you're giving them back to me. So, I appreciate this. Um, I I think that you hit the nail on the head that, you know, this is one of the biggest changes and challenges that fraud programs are are having to make within their um, you know, fraud programs. For years, so much of our fraud infrastructure was built around answering just one question. Is this actually our customer? So, we've got device, password, MFA, biometrics, IP address authentication. Those things still matter tremendously. The problem is that scams introduce another question. Does our customer understand what they're doing? Those are completely different problems. A customer can authenticate perfectly and still be sitting on the phone with someone pretending to be, you know, uh the bank, uh law enforcement, Microsoft, the their grandchild or an investment adviser. The bank can prove with almost complete certainty that you know Haley initiated the transaction, but that doesn't tell you whether Hailey initiated it because somebody convinced her that her money was in danger. So what changes, right? We have to start layering intent and behavior context on top of identity. Is this normal behavior for this customer? Is the destination new? Did they suddenly change contact information? Did they increase limits? Transfer limits. Did they add a new device? Did they move money between accounts immediately before the transaction? Um, you know, are they even draining the account that they've spent 20 years building? Each signal by itself may not mean much, but together they tell a story. And that is where fraud teams have to get much better at looking beyond uh whether an authentication event passed. What? And and then the other thing that we struggle with is what if the customer is insisting this is where it can get really difficult. Uh you cannot completely eliminate scams without creating an incredible amount of friction for legitimate customers. There's always going to be tension between customer autonomy and protecting someone who may be under manipulation. I think the answer is a thoughtful intervention. Someone that or sometimes that means a a target targeted warning. Sometimes it means asking better questions. Sometimes it's a cooling off period. Sometimes it's escalating the transaction to someone trained specifically in scam intervention. And sometimes the customer is still going to say, "It's my money, send it." And then that's where my favorite quote comes in is, "We will not knowingly participate in fraudulent activity." Um, I used that line anytime I couldn't get through to a victim that was very insistent on sending the money. I when I would drop that line, it was it literally was a mic drop moment for me. Um, and and I hated to use it, but when I did, it gave them that cause for a pause that I've talked about before where if if you're trying to conduct a transaction, you've you've talked till you're blue in the face, your bank still won't do it. And then your bank looks at you and says, "We will not knowingly participate in fraudulent activity." you go, am I doing something I'm not supposed to be doing? Um, and when they're like, I'm not fraud. I I'm I know what I'm doing. This transaction follows a pattern of what we know to be fraud in the industry and in other accounts. We know this is fraud. We are not going to allow this to happen. Now, you can't stop them from getting the cash out because it's their money. They can come in and get it, but you can create some of that targeted friction where it's we want you to understand that as your financial institution, we believe this to be fraudulent because we've seen this pattern before. So, we're trying to do our part. Hopefully, whenever you go to leave and you're, you know, the difference between sending a $20,000 wire and walking out of the bank in 20 with $20,000 in cash, that does something to somebody. You know, it makes them pause and think.
Chen Zamir
Chen Zamir
40:49
Yeah, that's a it's a good one. Uh, for sure. I Yeah, I'm just thinking, you know, for us fraud fighters, you know, life would be so much simpler if there would just be no customers. I mean, maybe the business would not like it, but yeah, for us it it would be Yeah. A great a great day uh when businesses can make money without customers. Um,
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
41:12
Yeah. Now, I will say though, I I want to make sure that it's clear. I'm I'm not saying that authentication is becoming less valuable. That that's not the case at all. Authentication answers a very important question of who is doing this. It just doesn't always answer why are they doing it. The mistake is treating successful authentication as proof of intent. And that's where we've got to get better.
Chen Zamir
Chen Zamir
41:36
That's exactly the point where I wanted to go next. I think I see it in FinTech. I definitely see it in banks. Uh I always call it this addiction. Addiction to a binary risk assessment. Either this user is authenticated and good or they are not and we cannot trust uh put our trust in them. And I think scams specifically, not only scams, I think like everything that has to do with, you know, digital banking and e-commerce, like it forces us to be much more mindful to how we manage risk. But scams specifically and you know, authentication is is is a big part of that. And you know the one of the main issues here is that up until scams exploded, our fraud stacks were really geared toward um preventing unauthorized use. But now it's no longer unauthorized, right? It's authorized when you know like stripping back everything that you just outlined to cafe core pillars. Now I'm this, you know, I'm this exact that uh that uh asked you that question at the the beginning of our conversation, but instead of thinking about kind of like unauthorized fraud, I'm thinking about scams from a fraud strategy perspective. What are the pillars that I need to be minded to when I'm suddenly like completely shifting my my view on what fraud is?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
43:08
So the pillars as in what an executive needs to understand or just like the fraud leader?
Chen Zamir
Chen Zamir
43:14
The fraud leader
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
43:15
I think the fraud leader has to understand uh truly. I've always said I'm going to treat every customer like my grandmother, how would I want them, how do I want them to treat her. But at the same time I have to think about the overall business of the organization as well. So I can't just be, the full heart of hearts, I'm going to give them back all the money they've lost to scams, because that's not a good business idea, right? Because then you're going to have the problem that I think we're going to start seeing if we do see that push for scam repayment um from organizations is that we're going to see a lot of the first party fraud that we see currently but they're just going to get the money back. Um I think that we have to look at holistically um for each pillar we have to think about the customer experience. We have to think about the loss of the organization. We have to think about where we can prevent it and where we can get in front of it. Where the only option is truly to just react. Um, and then how do we react? How do we respond? I think that response is the most important part of the the pillar for fraud fighting. It's not just how do you have a conversation with a victim. That's not that's not the only thing that response means, but it's what do we do when we've exposed a gap? How quickly are we responding to that? Do we wait until there's a really big fraud? I I struggled with that as a fraud practitioner because I wanted to go into an executive's office, grab him by both sides of his head, and just shake until he listened to me, right? But you can't do that. Um I I wanted to say, "Hey, we've got a really big exposure." And I did. I tried. I I would write it in memos, and I'd say, "If we don't put this in place right now, we're really exposed." An example was credit card um payments. If we allowed for a credit card payment to go through ACH, we have 60 days that that payment is a vulnerability for us. 60 days that we could have a response back of saying, "Hey, nope. They now say that those were unauthorized. We got to send them back. We have no recourse on that except to go after the individual person." Well, what if you find out that was a synthetic identity? Okay, great. So right now I or at that time I was like, "Hey, there's 60 days that if we're allowing a card to be maxed out, paid off, maxed out, paid off, maxed out, paid off, and they do this consistently two times a week." That and and it's a $10,000 limit. So that's $20,000 a week that we're exposed with one card. If we don't put this particular fraud thing in place, we're we're going to we're really exposed. And it was you got to take a loss before you can make any changes. And that to me was so crazy. And so we lost a hundred and something thousands with one account because that wasn't put in. Now when I wrote up the memo again to then say I told you so. I unfortunately couldn't say I told you so in the memo. I did I did however say on you know this date I advised that this was a potential vulnerability that we should put something in place at the time leadership decided it was not a a priority. Um since then this has happened. This is how we were exposed. This is the loss we're currently sitting at now. Then they took it seriously. So the response, you can't think of the response as just a how do we talk to people, but it's how are we going to respond when we've noticed a gap, when we've noticed that there's a potential vulnerability, how do we ensure that we get that message over to leadership that they are going to be receptive of it? And then how do we move ahead going forward? Again, it's all about that fraud strategy. I'm going to bring in some of your your strategy uh comments.
Chen Zamir
Chen Zamir
46:57
Um I I wonder you know specifically when it comes to scam I think one of the bigger challenges is exactly what you uh just described. Is that sometimes it's very hard to convince the business to do things that supposedly hurt the business performance specifically in scams. Because many times the uh report uh like reporting rate is lower than an unauthorized fraud, right? There's a much higher chance that I will file a charge like if someone stole my credit card than if someone fooled me to be like a handsome marine officer uh stationed in Iraq. Um
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
47:34
Right
Chen Zamir
Chen Zamir
47:35
And I think one of the I mean I would guess that many of your conversations were actually internally not necessarily with leadership but with product folks. Because you know in the end you're not talking about a fraud account that you just block and no one cares about but this is a real customer. It's uh a a loyal customer and b so far a profitable customer and you know that even if you're right even if you are right and it is a scam there's a very high likelihood that the customer would never complain and there would never be a loss. And so it's very easy to product come to come and say you see nothing happened so you were wrong and we we shouldn't have uh put the friction in and so on. How do you manage these kind of conversations which are, you know, sometimes very very difficult and very nuanced.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
48:26
Yeah, I'd say that it starts there's two different ways that I approach it. One is obviously trying to sell the story of the the member or the customer friction. Like better be overprepared than underprepared. Um here's here's what this would look like if we took that loss. They're going to take the loss and then that's on us as their financial institution that we didn't do our part. Um so trying to tell that story. The other thing you mentioned was talking with the business unit owners. That was always a great way for me to get in in front of the executives um just through a third party. So I would go and I'd talk to the e-services director and I'd say, "Hey, this is where there's a potential gap. Your team doesn't like the current risk um analysis that's being performed. They don't trust it. Um they're doing manual reviews of this one parameter because again they don't understand what it means. Um, and so if we can adjust these parameters, give them those guidance, and then let executives say, "Yes, we will, we agree to take a loss, if it's $150 or less, they can automatically approve it. It'll be on us, and it won't count against them." That was a big win for that department that the next time I needed something or I saw a vulnerability, I could go directly to that business unit owner who had the ear of the COO and from there, we were able to make things happen. And it was it was a phenomenal experience. But it's all in how you have the conversation, how you're able to bring in different partners from the organization and allow them to also advocate for your program.
Chen Zamir
Chen Zamir
49:57
How do you, I mean I think this is honestly one of the aspects where I see a lot of fraud fighters struggle with. Because you know I think fraud fighters similarly to probably legal and probably to security are mostly the only functions in an organization that are you know that are the no sayers the nay sayers, right? The business excels marketing product operations customer service. Everybody's like geared towards growth and you know revenue and that's like in the end this is how you are measured. And fraud fraud fighters you know operate almost um it's not orthogonally it's yes it's it is orthogonally to the organization we care about losses supposedly. Um and and I see that many times there's a lot of frustration and a lot of incomprehension of how to even begin such conversations. How do like what's your best advice for fraud fighters that want to approach leadership teams and want to influence them to make a decision that they think is the right decision? How, what's your advice?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
51:16
First is to make sure that executives understand that fraud operations are not just a cost center. We are protecting customers, deposits, reputation, operational capacity, and sometimes people themselves from catastrophic financial harm. I I also think the leadership needs to understand capacity differently. If a fraud team says we're overwhelmed, the answer can't always be, we'll hire another investigator. Yeah, maybe we need another investigator, but also maybe our technology needs tuning. Maybe our processes are inefficient. Maybe we're generating unnecessary uh work upstream. Um or there's another department that's creating fraud exposure downstream. Capacity is is a symptom. I want to understand the the cause. Right? I think that the other thing um that I've learned from the benchmarking work that we've been doing is that fraud teams are doing a lot better than we sometimes give ourselves credit for. You know, we are doing formal fraud risk uh assessments. Institutions are tracking false positives. They are using riskbased queuing. They're investing in technology. There's a there's a level of maturity there that I don't think always gets recognized. Um at the same time, you have teams saying that they are at or beyond capacity. Scams continue again to be one of the biggest concerns. Many institutions still struggle to quantify scam losses accurately. You have fraud teams trying to tell their story to leadership while some of the most important work they do is incredibly difficult to put on a balance sheet. You know, if I stop a $100,000 fraud attempt, everybody agrees that is valuable. The problem is proving that the $100,000 would have actually left the institution without the intervention. You know, that creates like this weird problem where losses are easy to to measure and prevent um and prevention is is hard to measure.
Chen Zamir
Chen Zamir
53:09
Mhm.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
53:10
Then leadership looks at the fraud dashboard and sees $2 million in fraud losses. What they may not see is the $15 million the team prevented. Right.
Chen Zamir
Chen Zamir
53:20
So this needs to be exposed. You're saying?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
53:22
Yes. 100%.
Chen Zamir
Chen Zamir
53:23
In the dashboard. Yeah.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
53:24
Yes.
Chen Zamir
Chen Zamir
53:25
Yeah. Yeah.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
53:26
I I think in the dashboard, one of the things um like I'd want some version of a fraud exposure prevented alongside fraud losses incurred, right? No. And not just the gross fraud loss. Show me the attempted fraud. Show me the prevented fraud. Show me the actual loss. Then give me enough context to understand what happened. If the board only sees losses, we're only showing them the failures. They need to see what the program is stopping. Yes. I would also want that normalized against something meaningful like transaction volume, uh, customer growth, deposits, or whichever denominator makes sense for that institution. A $2 million loss means something very different at a $500 million credit union than it does at a $50 billion bank.
Chen Zamir
Chen Zamir
54:12
Yeah, 100%. I agree with that. I do want to challenge you on one thing. I think that today if you would come to a leadership team or to the board and it would say my investigators are overwhelmed. Their answer is unlikely to be hire another investigator. Their answer is likely to be fire them all and put a very cheap AI instead. What, like, that it works 24/7. Um, how would you like how would you manage this kind of challenge from the leadership team?
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
54:45
That's one that I'm still working on. I'll I'll be just completely transparent with you. You and I were actually working on a really cool project that I'm so excited to dive into, and that's really understanding the AI concept of of what can be done. Where is the investigator and the analyst still very valuable to an organization? Bottom line is we will at some point have to implement some type of AI that can help our organization. Fraud is too fast. It it's constantly changing. It's constantly evolving. We're going to have to put something in place to help us. That that's inevitable. That that's happening. What I would say is, um, and one concept that I'm becoming really familiar with, is, you know, we've talked about, um, human feedback in the loop, where it's, we're looking and making sure that the alerts worked and that it scored it the way we wanted it to. That still is not scalable. Instead, we're going to have to start looking at human on the loop where it's policy and governance of that AI system how it's working. So, I'll say to answer your question right now, I can't give you a definitive of what would work in order to help you keep your entire team. What I will say is that if you can go ahead and start looking now at what tech you think you may need in two years, do it. Do the research now. Start looking to see where your team might be more valuable. Maybe they need to develop a new skill that helps them become that person on the loop. Help them now. Point them in the right direction now to keep them as a valuable member of your organization. If you don't want to see uh their growth, you don't need to be in leadership anyways. Um so maybe maybe maybe this isn't the right place for you. But if if you're going to make sure that number one, your team is scalable, that you're going to be able to keep up with tech, they've got to start learning now. They've got to start looking now. I was one of those. I'll be honest, when I was the credit union practitioner, I said, um, we're always going to need the fraud investigator. Yeah, to an extent, yes, that is true. But we are teaching AI to do things a lot faster. And our whole uh thing with fraud is that we want to get to this preventative, proactive fraud uh strategy. We can't do that alone as humans. We are just humans, right? AI and scams and fraud, they move a lot faster. Payments move faster. You know that whenever I get that card alert on my card, if I tried to spend $500 at Walmart and it says, "Hey, did you do this?" A human is not going to be able to do that at scale for all their customers. We have to have these programs and systems in place. And so I the the answer to it today, I can't give you the definitive answer that I would say, but I would say definitely start pouring into your team to allow them to be useful and valuable whenever uh that time comes.
Chen Zamir
Chen Zamir
57:32
Yeah. Well, I said earlier fraud strategies uh can be quite straightforward. Uh but even if it is straightforward, it's still shifting and changing uh because fraud is changing, because the technology is changing, because the business landscape and the products are changing. And so there are always this kind of like these new fronts uh these new uncharted waters that you need to well to chart basically and that's part of the part of the job to an extent. Uh that's why we're risk managers. Uh I always say Hailey, it's been such an interesting conversation. Uh it feels like on one hand we covered a lot of ground and on the other hand we just skimmed the surface. So I uh I definitely love to do that again sometime. Uh but for today I would say it's it's uh it's been a pleasure and I uh can't thank you enough for uh letting me take over the pod for an hour.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
58:31
Yeah, I I'm so stoked that you were able to to be here uh to take over and to allow me to sit in the uh practitioner chair or or the guest chair today. I have I found myself asking, man, I'm doing a lot of interviews, but I I feel like there's an opportunity here where I can provide a little bit more insight. Um so, this was a a great opportunity, and I I appreciate you more than you know.
Chen Zamir
Chen Zamir
59:00
Uh goes Same goes back to you. So, uh yeah, I uh we should definitely do it again.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
59:06
Yes, for sure. Okay, so I'll take the I'll take the microphone back as the host and just say fraud fighters, uh you know, if you want to hear me turn the tables on him, um head over to The Saturday Fraud Strategist um for the other part of this conversation where I was able to turn the tables on him. Um until next time, stay vigilant, stay informed, and keep moving Fraud Forward.
Smiling blonde woman in a black blazer with arms crossed, standing in a room with a "LIVE ON AIR" neon sign.
Hailey Windham
59:33
Thanks for listening to Fraud Forward. Remember, every conversation, every connection, and every insight moves our industry one step closer to stronger fraud defenses. If today's episode sparked an idea, share it with your team or tag me on LinkedIn. I love hearing how you're moving Fraud Forward in your own organization. Until next time, stay curious, stay resilient, keep moving Fraud Forward