Treat fraud as an ecosystem, experts urge regulators

Interpol warns AI-enhanced scams are 4.5x more profitable; experts call for an industry-wide, coordinated response to human-focused fraud.

Interpol warned that financial fraud is “one of the world’s most severe and rapidly evolving transnational crimes, with significant economic and human consequences,” and that AI-enhanced scams are 4.5 times more profitable than traditional methods. At a recent webinar hosted in association with Ecommpay, industry figures urged regulators and firms to treat fraud as an ecosystem rather than the responsibility of individual organisations.

Panelists pointed to a shift in fraud tactics away from exploiting technical weaknesses toward targeting human behaviour with automated tools and social-engineering techniques. They said the change makes many scams harder for consumers and firms to detect and that individual firms’ defenses are often insufficient when attacks move across institutions.

Speakers included Willem Wellinghoff, UK chair and chief compliance officer at Ecommpay, and Anne Leslie, head of cloud risk EMEA at IBM. Teresa Connors moderated the discussion. The session examined where responsibilities lie across regulators, firms and law enforcement, and highlighted gaps that limit coordinated responses.

Panelists identified overlapping regulatory mandates and unclear lines of authority between data protection, financial services and law enforcement agencies. They said privacy and competition rules can discourage or block timely intelligence sharing, and that fear of legal liability reduces cross-firm cooperation. Technical barriers include inconsistent data formats, differing fraud taxonomies and the cost of linking legacy systems to shared platforms. Smaller firms were noted as facing resource limits that make participation in complex information-sharing arrangements difficult.

Proposals discussed for a more unified approach included a common taxonomy for fraud types and indicators, standardized incident reporting formats, and anonymized intelligence-sharing platforms run by a neutral non-profit. Panelists also suggested legal safe harbors to allow controlled data exchange for fraud prevention while protecting privacy rights. They said such measures could speed detection of cross-border campaigns and reduce duplicated effort across firms.

Speakers flagged possible downsides of standardization: higher compliance costs for small and medium-sized businesses, reduced flexibility for firms with unique risk profiles, and the risk that a centralized system becomes an attractive target for attackers. Aligning national data-protection and financial-crime rules would require legal trade-offs that some jurisdictions may resist.

Regulatory reform options raised during the webinar included clarifying agency mandates to enable end-to-end oversight of fraud, setting interoperable reporting requirements, and creating limited legal protections to permit rapid intelligence sharing. Panelists said any framework would need flexibility to reflect differences in firm size, sector and geographic reach, and safeguards to limit systemic risk from centralization.

Panelists concluded that piecemeal, siloed responses will not keep pace with fraud that targets human behaviour and called for ongoing dialogue among industry, regulators and technology providers to develop practical standards and legal frameworks for scaled collaboration.

Articles by this author