The Payment Expert Podcast

In this episode, Benjamin David from the Payments Association discusses the rapid evolution of financial crime, especially with AI's role in increasing fraud sophistication. We explore how firms can respond effectively through collaboration, better intelligence sharing, and responsible AI governance.

Key Topics
  • The impact of AI on fraud tempo and sophistication
  • The importance of collaboration and intelligence sharing in financial crime prevention
  • Challenges in AI governance and regulatory frameworks
  • The distributed and industrialised nature of modern financial crime
  • Strategies for effective threat prioritisation and resource allocation

Host: Louis Thompsett
Guest: Benjamin David
Producer: Anaya McDonald
Editor: Anaya McDonald

Learn more about the latest payments insights: https://paymentexpert.com

What is The Payment Expert Podcast?

Welcome to The Payment Expert weekly podcast, brought to you by SBC Media. Each week we analyse the news driving the global payments industry forward; the innovation, the infrastructure, and everything that has to happen to make it all possible.

Louis (00:00.728)
Hello and welcome back to the Payment Expert podcast, your source for the latest news, insights and analysis on the payments industry. I'm Lewis Tompsett, news editor at Payment Expert and with me today, I'm delighted to be joined by Benjamin David, head of intelligence at the Payments Association. Thanks for joining us, Benjamin.

Benjamin David (00:22.159)
It's a pleasure. Thank you for having me.

Louis (00:25.792)
Absolutely. Now you've worked, I know, on the payment association's UK finance crime pulse report for 2026. So that obviously came out this year, just as I suppose a general overview when it comes to financial crime, particularly in the UK. What's the mood been like among, I guess, some of the financial leaders you've spoke to for this year?

Benjamin David (00:53.071)
Honestly, I can describe the mood as concerned, certainly, but not pessimistic.

What I hear from our members is that there's a real recognition that the threat environment is moving really quickly. I think what makes this period particularly challenging is that firms aren't dealing with one dominant threat that they can isolate, investigate and solve. They're dealing with several things changing at the same time. You've got AI increasing the speed and sophistication of certain types of fraud. You've got, of course, APP fraud remaining asexual.

significant operational problem and there are continuing threats around identity, mule counts and insider risk. I'm sure we'll get into that as the podcast progresses and alongside all of that firms are trying to navigate changes in regulation and governance and that came through quite clearly in our financial crime post research that you mentioned. We surveyed 100 senior financial crime leaders against UK financial services and what struck me wasn't a lack of investment

investment or awareness actually quite the opposite, Firms know they need to respond and they are investing. the concern is whether the industry can respond at the same pace at which the threat is changing. I think there's another dimension to the mood as well, which is the growing recognition that firms can't solve all of this individually. We can see that in conversations with our members and through our financial crime working group. It's a much stronger discussion now about intelligent sharing.

collaboration and how the ecosystem can work together. So would say, yeah, the mood is alert and pragmatic. People understand the seriousness of the challenge, but there's also an acceptance that the next phase of the response can't simply be that every institution building a slightly better version of its own defenses.

Louis (02:51.231)
Yeah, a lot of themes to tap into, I suppose. And one of the biggest ones, as you've mentioned, Benjamin, AI, perhaps in how it's almost changed the tempo, the frequency or the rate of fraud. From what you've seen across the market and who you've spoke to, how much has that tempo shifted? And where do you think the speed of fraud, thanks to AI, know, where's it hurting firms?

and or even consumers the most depending on who fraudsters may be targeting.

Benjamin David (03:27.375)
That's a great question. Yeah, I think it has changed the tempo quite significantly. One of the clearest findings from our research was that 76 % of financial crime leaders said AI enabled fraud is outpacing their current response capabilities. And for me, the important word there is outpacing. I don't think that we should fall into the trap of suggesting that AI has suddenly invented financial crime. A lot of the underlying tech

techniques are course very familiar, social engineering, impersonation and attempts to manipulate people into making payments have been around of course for a really long time. What AI can change is the economics and speed of those activities. It can make certain techniques really quicker to execute, easier to scale and potentially much more convincing. And there's an asymmetry as well between attackers and

defenders, right? So a criminal, of course, can experiment very quickly. If something doesn't work, they change it and try something else. A regulated financial institution, quite rightly, has governance, compliance, testing and risk management requirements before deploying new technology. Now, I think that difference in speed really matters because for consumers, I think one of the biggest concerns is trust.

We are traditionally taught people to look for signals that something isn't genuine. Does this email look right? Does this person sound credible? Does this communication contain something suspicious? And AI potentially makes some of those judgments a lot harder. If an impersonation becomes more convincing, the burden on the individual consumer becomes far greater. I think the challenge for the industry is to avoid

turning this into a technological arms race where the answer to AI enabled fraud is simply more AI. Technology will be extremely important, but it has to sit alongside intelligence, really good governance, customer protection and collaboration. AI isn't just making some fraud more sophisticated. It's really compressing the amount of time that the industry has to identify.

Benjamin David (05:52.401)
and course respond.

Louis (05:57.824)
Yes, totally. I suppose the other consideration there, Benjamin, the threats aren't, you know, they're not localized, they're not in a small amount of, I suppose, fraudsters hands that they're widespread, almost systemic, some may say, do you think that's one of the, I guess, the biggest threats of AI. And obviously, you mentioned, you know, we don't want to get in an arms race of fighting AI with AI, because as new as it iterates, as it gets

more advanced, so too will the fraudsters will end up in a never-ending arms race. But to think it's the ease of access maybe, making fraud as a service so easily available to people and so accessible for people to commit fraud.

Benjamin David (06:45.411)
Yeah, I'd be slightly careful with the word systemic because obviously it has a particular meaning within financial services. But I do think there's a strong argument that financial crime is definitely becoming more distributed and in some areas more industrialized. And fraud as a service is an important part of that, right? So for me, one of the more concerning implications of AI isn't simply that the most sophisticated criminals become even more sophisticated.

Louis (06:53.741)
Hmm.

Benjamin David (07:15.345)
sophisticated, right? It's that capabilities that previously required more specialist knowledge or resources can potentially become available to a much wider group of people and

You could argue that really lowers the barrier to entry. So you can then start to get an ecosystem around financial crime. Different actors don't strictly have to possess every capability themselves. Tools, information, infrastructure and techniques can potentially be provided by different parts of a criminal network. And from a defensive perspective, that makes them...

how would you call it, the problem, much more difficult because you're no longer necessarily looking for a small number of highly capable actors using recognizable methods. The threat can become more fragmented and more adaptable. And I think that changes what intelligence needs to do, right? So one organization might see an account behaving really suspiciously. Another might see a particular fraud typology. Another part

of the ecosystem may have information about the infrastructure being used. And individually, none of those signals necessarily gives you the whole picture. But the opportunity comes from joining those pieces together, right? And that's one of the occurring themes in conversations with our members and in our financial crime working group. How do we move from simply understanding the threat within individual organizations to understand

the networks behind it. Because ultimately, criminals aren't organising themselves according to the boundaries of banks, fintechs or even payment service providers. Our response increasingly has to reflect that reality.

Louis (09:11.626)
Yeah, absolutely. And of course, I suppose no firm can can always defend against absolutely everything. There are different parts within the ecosystem from where fraudsters originate from. Maybe they come from a social media or whatever. So there's only so much I suppose the industry can do, particularly for payments firms.

How do they choose kind of what to protect and in other areas, where are they kind of falling into the arms race that you mentioned a bit earlier on?

Benjamin David (09:42.765)
regression. I think this is fundamentally...

and intelligence and prioritization question. I really do. No organization has unlimited resources. And actually trying to defend against every conceivable threat equally probably results in you defending against none of them particularly effectively. So firms need to understand the combination of threat, vulnerability and potential harm that apply specifically to them. And that's important because the threat landscape

really isn't uniform across financial services. Our research really illustrates that quite well. know, app fraud or authorized push payment fraud was the most commonly identified major operational challenge overall. 51 % identify as such. But when you look beneath the headline numbers, different types of organizations experience the threat very differently. For example, if you take digital identity and know your customer, KYC,

weaknesses. They were particularly pronounced among banks in our research, whereas fraud prevention created greater operational uncertainty among fintechs than in banks. And that makes sense really because these organizations have different business models, different infrastructure, customer relationships, and of course points of exposure. So good intelligence shouldn't simply tell you...

you know, a threat exists, right? It should help you understand what that threat means for your organization, you how exposed you are, how it's changing, and therefore where you should concentrate resources. And in terms of the, you know, the arms race point, AI is probably the most obvious example because both sides can use the technology. But I think we need to resist the assumption that

Benjamin David (11:38.185)
every new offensive capability requires an identical defensive technology because the objective

isn't to have more AI than the criminals. The objective is really to reduce the opportunities for successful financial crime. And sometimes technology, of course, will be the answer. And sometimes it will be about better identity control, better customer interventions, or even better intelligence sharing overall. That's why think intelligence is really becoming increasingly important. And its job is

turn an enormous and rapidly changing threat landscape into a manageable set of priorities that organizations can actually act upon.

Louis (12:30.219)
Yes, totally. you know, we mentioned obviously, AI being the one area where perhaps firms are getting pulled into that arms race, but obviously, being in a regulated industry, you need the right frameworks within place and the right governance for those firms that maybe say that

the practical guidance maybe for AI governance isn't there. Whose job is it to provide it? And does there need to be a bit more regulatory speed? Obviously, things do take their time and take their course and it's part and parcel with the industry. But what do you say to those firms that may say that?

Benjamin David (13:14.329)
So I don't think responsibility can sit entirely with one organization or one part of the ecosystem. really don't. I regulators obviously clearly have a very important role because firms, need that clarity around expectations. But I think industry has a responsibility as well, particularly when we're dealing with technology developing as quickly as AI.

Again, one of the findings from our research was that 41 % of organizations said they lacked the practical guidance needed to implement effective AI governance. And I think practical really is the important word here because at a principles level, there's probably quite a lot that people agree on. We, of course, we want appropriate accountability. We want effective oversight and we want technology

to deployed responsibly. But if you're actually responsible for financial crime or compliance within an organization, your questions become, of course, much more specific. don't like who owns the risk? What level of human oversight is really appropriate? How do we test these systems? How do we demonstrate that our controls are working? And also even what happens when a model changes and how do we use AI

quickly enough to respond to criminals without actually introducing risks elsewhere. That's where the principles need to become really like operational guidance.

required dialogue, Regulators, they understand their objectives and expectations. Firms understand the operational realities. Technology providers understand the capabilities and limitations of the systems. Industry bodies can help bring these perspectives together, like with the payment association. That's part of why, of what we try to facilitate through the payment association and our financial crime working group. And it will also

Benjamin David (15:23.025)
be in many ways an important part of the conversation at Financial Crime 360 in November, because these questions benefit from having regulators, financial institutions, technology companies, and other parts of the ecosystem in the same room. But ultimately, good governance should not prevent innovation. What it should do is give organizations enough confidence and clarity

to innovate and to innovate really responsibly.

Louis (15:58.644)
Yes, totally. Great stuff, Benjamin. I want to touch, obviously, you mentioned shared intelligence quite a bit and the value in that. But I suppose if you maybe look across what firms do in their anti-fraud models, it tends to be what they can, maybe they put the most into what they can, you know,

build alone, maybe that's where most of the investments perhaps go rather than on what they can do together, whether it's catching those mule accounts across the whole system. Obviously, it's not anything that a single firm could build. Why do think that's happening? Do you think there needs to be maybe a culture shift in more, I suppose, collaborative spending almost to kind of come together to create these kind of

mutual joint systems where the whole ecosystem can access it to fight the fraud.

Benjamin David (16:54.263)
Yeah, I think this gets to one of the fundamental structural problems we face. Financial crime operates across networks, but historically we've built a lot of our defence.

institution by institution. A bank can invest in better monitoring, a FinTech can strengthen its controls, a payment service provider can improve its detection capabilities, and all of these investments are valuable. But the criminal doesn't necessarily remain within any one of those institutions because what they do, and they do incredibly well, is they exploit the connections between them. Mule accounts are a really good example. In one organization,

may see a particular behaviour which, viewed in isolation, doesn't necessarily tell you very much.

Another organization might see another account or transaction connected to it. If somewhere else in the ecosystem, there may be another piece of intelligence. Now, once those signals are combined, you can potentially see a network that no single institution could see by itself. So the question is, is in many ways, why that intelligence doesn't move more easily. And some of the barriers are, of course, entirely legitimate. And there are questions around data protection, liability.

governance, what's the term, commercial sensitivity and technical interoperability. Organisations, of course, they need that confidence about what they can share, with whom, for what purpose and under what safeguards. But I also think we need to challenge ourselves really about whether every barrier we encounter is genuinely immovable.

Louis (18:20.788)
Mm.

Benjamin David (18:40.803)
Our members here at the Pavement Association have a significant role in that discussion and it's something our financial crime working group can help to address because it brings different parts of the ecosystem together. The important shift is from saying we need more collaboration, which course everybody can agree with, to identifying precisely what information needs to move, what currently prevents it moving, and what practical changes would remove

those obstacles because ultimately I financial crime is a network problem. Our intelligence capabilities need to become increasingly networked as well.

Louis (19:26.89)
Hmm. Yeah, totally. And you mentioned the collaboration. I mean, there is certain collaboration, but I tend to think maybe it tends to be domestic first when there is collaboration. And then obviously, as you mentioned, fraudsters aren't bound to a certain, whether it's in banks or if it's a payment service provider or what have you. And I think the same maybe applies to borders too. Obviously, fraud crosses borders just as freely, which maybe is...

One of the harder battles, both, I guess, when you're collaborating commercially and then obviously from a regulatory standpoint as well, that's when things can get slightly more complicated because each jurisdiction has different conditions, different regulations. From, guess, your perspective, the payment association perspective, what kind of steps can be taken to...

Benjamin David (20:06.457)
Exactly.

Louis (20:15.516)
address that collaboration to sort of spark more shared intelligence across different markets, different jurisdictions around the world.

Benjamin David (20:26.671)
That's a really good question. I actually think small steps.

is the right way to frame this. If we begin by saying that the solution is a perfect global financial crime intelligence network connecting every institution and every jurisdiction, the scale of the problem becomes overwhelming very, very quickly. Different markets have different regulatory frameworks. They have different data protection requirements. They have different payment systems and different approaches to

natural crime.

In many ways, you should start with specific problems where cooperation can make a measurable difference. Can we develop, for example, more consistent terminology for particular threats? Can we improve the way fraud typologies and indicators are communicated between trusted organizations? Can we create stronger relationships between existing networks in different markets? Can we identify situations where organizations

to collaborate but regulatory uncertainties making them reluctant to do so. And importantly, can we do more of that without assuming that intelligent sharing always means sharing large quantities of personal or customer data? Those are much manageable questions in my estimation.

Benjamin David (21:54.913)
The payments association has obviously an interesting role here because our members represent different parts of the payments ecosystem and payments themselves are of course increasingly international. It's also one of the reasons financial crime 360 in November is important. Bringing people together isn't valuable because we can all agree that financial crime is a serious problem. We already know that. The valuable conversation is about what happens next. What can banks do with

fintechs, what can payment providers do with tech companies, where do regulators need to provide greater certainty and where can industry move without waiting for somebody else. You fraud, to your point, fraud crosses institutional and national borders extremely, extremely easily and our response really needs to become better at crossing those boundaries too.

Louis (22:54.024)
Yeah, absolutely. And I think a great way to end there, Benjamin, with that message, think to everyone, to the industry, to regulators as well. That is, unfortunately, though, all we do have time today. But thank you very much for joining me. If you've been watching or listening and you're not already subscribed to the Payment Expert podcast, make sure to subscribe wherever you do get your podcasts with plenty more insight and analysis coming over the weeks and months ahead. And for the latest news as it happens, head over to

paymentexpert.com. We'll see you all next time.