Fraud defence – do silos still work?

0
53
Fraud defence

The Financial Sector Conduct Authority’s (FSCA) call for a centralised anti-fraud hub at its 2026 conference reflects a timely recognition that South Africa’s financial institutions (FIs) cannot successfully fight financial crime in isolation. However, centralisation alone is not enough.

The real opportunity lies in turning shared intelligence into real-time, coordinated prevention across the entire ecosystem. A siloed fraud defence, where each institution relies only on its own intelligence, detection systems and response protocols, will not keep pace with financial criminals.

These criminals are becoming more agile, sophisticated and AI-driven every day. Even well-resourced institutions are structurally outmatched when they operate in isolation. Criminals collaborate, automate, and improve their methods at machine speed.

The AI-driven fraud challenge

Agentic AI systems can autonomously plan and execute complete fraud campaigns. These campaigns range from reconnaissance to monetisation.

According to Mastercard research, payments executives identify synthetic identity fraud as the fastest-growing threat over the next year. In addition, the 2026 INTERPOL Global Financial Fraud Threat Assessment warns that AI-enhanced fraud is 4.5 times more profitable than traditional methods.

Deepfake technologies, synthetic identities and automated attack methods allow criminals to test and refine their techniques faster than ever before. As a result, they overwhelm the defences of financial institutions. These systems can generate hundreds of thousands of synthetic identities. They can also test onboarding systems across multiple institutions simultaneously. Furthermore, they adapt dynamically according to which controls succeed or fail.

This represents a structural shift in the economics of fraud. Attackers benefit from network effects, while defenders remain largely linear and institution-bound. Fraud patterns are no longer isolated events. Instead, they have become shared playbooks within criminal ecosystems.

From shared intelligence to real-time prevention

A successful synthetic identity technique identified in one market can spread across multiple institutions within hours. It also makes fraud effectively free to commit. Consequently, the barrier to entry drops significantly, allowing many more criminals to participate at scale. This is precisely why a siloed fraud defence is no longer sustainable.

We are therefore seeing the emergence of a system that rewards the speed of criminal learning over institutional resilience. Unless legitimate participants coordinate their defences, financial criminals will continue to outpace them. Sharing information is an important first step. However, the true value of a centralised hub lies in enabling real-time, automated intelligence exchange across institutions, regulators and adjacent sectors such as telecommunications and payments.

For example, if one bank detects a suspicious pattern, an automated alert shared with regulators and other institutions could prevent the same attack elsewhere.

Much of the required technical infrastructure already exists. Banks, fintechs, mobile operators and regulators hold complementary data. If they pool and analyse this information, they can significantly improve fraud detection and prevention. Signals such as device fingerprint anomalies, SIM-swap activity and reused biometric patterns can be linked across institutions. This enables organisations to identify coordinated fraud attempts before financial losses occur.

The barriers to this type of data sharing are cultural and regulatory rather than technological. Many financial institutions still regard fraud intelligence as a competitive asset. In addition, concerns surrounding the Protection of Personal Information Act (POPIA) create hesitation about sharing information. However, organisations must distinguish between sharing customer data and sharing fraud typology intelligence.

The latter reveals criminal methods rather than personal information. Privacy-preserving technologies, such as federated learning and secure multiparty computation, now enable collaboration without exposing customer data. Replacing a siloed fraud defence with collaborative intelligence will strengthen the entire financial system.

Regulatory collaboration gains momentum

It is therefore encouraging to see industry associations and regulators embrace cross-sector fraud intelligence sharing as a regulatory norm.

The FSCA has signed a memorandum of understanding with SABRIC and the Southern African Fraud Prevention Service. This agreement enables the sharing of real-time fraud data to support more coordinated action against financial crime.

The FSCA has also strengthened collaboration with the Independent Communications Authority of South Africa. Together, they aim to combat the growing misuse of SIM swaps in financial fraud.

Regulatory clarity is now a critical enabler

Another major constraint is the absence of consistent regulatory frameworks for AI-driven risk management. South African financial regulation currently lacks a unified definition of AI governance and AI risk. Consequently, oversight practices differ significantly across institutions.

Many organisations still operate without formal AI governance frameworks or model explainability standards. This creates systemic blind spots in areas such as model auditability, decision transparency and accountability. AI-enabled fraud actors increasingly exploit these weaknesses.

Explainability standards are particularly important because they help regulators and financial institutions understand not only what a model flags but also why it reaches that conclusion. Auditability is equally important. It ensures organisations can trace, review and independently verify model decisions over time. The FSCA’s growing focus on AI oversight, including sandbox experimentation and supervisory engagement, is an important step towards addressing these challenges.

Modern Regulatory Technology (RegTech) is another essential part of the solution. It enables regulators, financial institutions and fintechs to use AI as effectively as criminals do. AI-powered transaction monitoring, behavioural analytics and federated learning models provide a collaborative technical architecture while preserving privacy.

South Africa’s fintech sector is already well-positioned to adopt these capabilities. According to FSCA survey data, AI adoption has already exceeded the halfway mark. However, organisations must ensure these systems remain explainable and auditable. Financial institutions often hesitate to adopt them fully because uncertainty remains about whether regulators will accept AI-generated outputs. As a result, meaningful deployment continues to progress more slowly than necessary.

Towards a real-time prevention network

South Africa worked hard to secure its removal from the Financial Action Task Force grey list. Sustaining that achievement requires a shift from periodic compliance to continuous, real-time financial crime prevention.

Organisations must treat fraud intelligence as a shared utility rather than a proprietary advantage. They must also embed AI expertise within regulatory bodies, align governance frameworks across institutions and establish standardised definitions for AI risk, explainability and auditability.

The FSCA has started an important conversation. The next step is execution. South Africa now needs a real-time, privacy-preserving intelligence network that detects and stops fraud as it emerges rather than after it spreads. In an era where autonomous AI systems increasingly drive financial crime, only equally intelligent, equally connected and collaborative defences will be sufficient.


Bradley Elliott | CEO | RelyComply |  mail me |


 



LEAVE A REPLY

Please enter your comment!
Please enter your name here