Synthetic identity fraud is no longer a discrete onboarding problem. It is an AI- accelerated, lifecycle-based threat exploiting fragmentation across systems, teams, and controls. As generative AI enables fraudsters to create, scale, and manage synthetic identities with unprecedented realism and persistence, traditional identity verification approaches are breaking down.
This type of fraud is now one of the fastest-growing financial crimes globally. AI has collapsed the cost and time to create convincing identities at scale. Fraud is becoming industrialized, lifecycle-driven, and cross-channel. The upshot: The industry is moving from fraud as a transaction problem to fraud as a persistent identity problem. The issue is not just losses—it's false growth, mispriced risk, and balance sheet distortion.
The panel discussion will explore how leading financial institutions are reframing identity trust—from a moment of verification to a continuous, multi-signal discipline—and what banks must do now to close the gaps where fraud is monetized.
LEADERS is a flagship channel that spotlights C-level executives and top experts as they discuss transformative topics for an audience of key decision-makers. We deliver thought leadership on the most pressing issues driving the future of financial services. The LEADERS series is made possible by the support from top industry collaborators including Mitek.
Transcription:
Transcripts are generated using a combination of speech recognition software and human transcribers, and may contain errors. Please check the corresponding audio for the authoritative record.
Holly Sraeel (00:20):
Hi, I'm Holly Sorell, Senior Vice President of American Banker Live Media. Welcome to Leaders. Synthetic identity fraud, now one of the fastest growing financial crimes globally, is no longer a discreet onboarding problem. It's an AI accelerated threat exploiting fragmentation across systems, teams, and controls. Generative AI has collapsed the cost and time to create identities with unprecedented realism at scale. Fraud is becoming industrialized, lifecycle driven, and cross-channel. The upshot, the issue is not just losses. It's false growth, mispriced risk, and balance sheet distortion. The industry must take steps to move from viewing fraud as a transaction problem to viewing it as a persistent identity problem. Here today to speak with me about synthetic identity fraud in the AI era from point in time risk to persistent identity threat are Patricia Voight, Chief Information Security Officer and Head of Tech Risk at Webster Bank, Raul Oseguera, Head of Risk and Compliance, Piermont Bank, and Shyam Menon, Senior Director Product Management at MiTek.
(01:30):
Welcome to this great panel of experts. This is a big topic, so let's get started. Okay, Patty, I'm going to toss it to you. The AI acceleration of synthetic identity fraud, what it means. Generative AI automation and data availability have transformed synthetic identity fraud from a niche threat into an industrialized operation. With this in mind, for years, synthetic identity fraud was viewed as a credit problem. How has AI transformed it into a broader enterprise risk affecting fraud payments, deposits, lending, and customer acquisition?
Patricia Voight (02:05):
Well, I think AI has changed the environment quite significantly from a scale and a speed perspective. And so when you think about synthetic identities, there's now this capability from the threat actors out there to be able to ramp it up and accelerate the amount of volume of activity that we're seeing as organizations and institutions. So I think from that perspective is changed from an element of just, again, like you mentioned, that credit loss perspective that we've seen in recent years to being more of an enterprise-wide threat from an identity and trust perspective. And I think when you step back and look at it, the industry is kind of estimating that around synthetic identities, the cost is around six billion annually to financial institutions. And so it's quite a significant amount of risk out there that organizations are working with.
Holly Sraeel (02:55):
Six billion, that's a huge number and it's only going to get larger. Sham, you had thoughts on this?
Shyam Menon (03:00):
Yeah, so AI has not just allowed the production of synthetic identities. It also allows for maintenance of those identities over time. So that allows fraudsters to remain within the system for a longer time than they were able to previously. So what that allows is it allows them time to access other product lines within your infrastructure. So that's why losses have gone from just onboarding and an immediate bust out to people staying within your ecosystem for a longer period of time, accessing other products that you may be offering where that trust verification is not happening because you have been on the platform for some time. And so that exposes that threat across the entire product portfolio and not just on the onboarding journey.
Holly Sraeel (03:52):
And I have a follow-up question to that. Relatedly, the longer they remain within the system bouncing around to different silos, is that identity getting more sophisticated?
Shyam Menon (04:06):
Yes. From an operational perspective, that is correct. And part of it is because the signal set around that identity is so fragmented. So generally in financial institutions, and I know Patricia and Raul can probably talk to this more than I can, different groups have their own siloed system of how they operate, how they onboard somebody. So the lines of businesses have their own kind of infrastructure. So you're defending multiple systems while the fraudster is a single system going through the process. So that's absolutely correct because over time what is happening is your systems internally are vouching for that identity the longer that identity exists within your ecosystem. So what would have been a red flag when a new customer comes in the door wouldn't necessarily translate to being a red flag for a customer who has been on the platform for, let's say one year.
(05:03):
So clearly I don't think it's the sophistication of the fraudster itself, but the way the structures are set up, it kind of disincentivizes us looking especially at somebody who has been our customer for a year or 16 months or 18 months, whatever the case may.
Holly Sraeel (05:20):
Okay. Let's talk about specific capabilities of GenAI and what concerns you most today. Synthetic documents, deep fake identities generally, voice cloning, automated application generation, or something else.
Patricia Voight (05:35):
I'll jump in here. So I think what bothers me and concerns me the most is not any one of them individually, but rather the orchestration of them together. So I think the challenge that we're seeing, and I go back to what was said already is the challenge that we're having is the fraud actors that are out there, they're using AI to create these synthetic identities and they're getting better at the different components within. So while you may start with a component that is real, so something like a child's social security number, and then add additional components into that that are fake or created and not real when they are created when you think about deep fakes and what we're seeing about voice cloning and even around biometrics with the use of AI, this is starting to become even more real and hard to detect as being fake.
(06:28):
And so what happens is the fraud actors, they're using AI capabilities, some of the cutting edge models that we have out there to be able to create these identities that they expect and they understand the onboarding process into financial institutions. So they're expecting them to get through that process undetected. And then they are sophisticated enough that they're playing a very patient game of waiting and investing into these long-term strategies of being able to take these identities that could sit there and look really very much like ideal customers, real customers in the way that they're set up and the activities that they're doing. They're making their payments, they're maintaining their balances. They look like great customers. And so these accounts just sit there and operate for maybe six to 12 months. They can be a longer period of time before they start to then move with them and start to go across product lines, which was what's mentioned, businesses and others to really enable them to become this much broader enterprise risk.
Holly Sraeel (07:31):
Right. So how has AI changed the economics of fraud? Can you talk a little bit about that? Anybody have a take on how the AI has changed the economics itself?
Raul Oseguera (07:47):
Well, in our institution, it has required us to invest a lot more in trying to identify and trying to not just identify it onboarding, but identify through the entire life cycle. So we've always had systems to identify regulatory BSA. Now we've had to adjust it to include more of the fraud that comes along with it because BSA is more attuned toward money laundering. This is not that. This is individuals out there trying to exploit the financial institution itself.
Holly Sraeel (08:36):
Sean, any follow-up to that?
Shyam Menon (08:38):
Yeah. So not only the internal investment that Raul is talking about for institutions, for people like me who are more focused on building the tools that prevent this, just the scale of the operation is just massive. And if you ask me what the biggest challenge for my team would be is the speed with which some of these patterns evolve. Previously in my career when I first started, it would take year and a half, two years for you to see a new pattern. You're seeing new patterns every quarter
(09:20):
If not more. And so the problem is structurally, institutions are not set up to respond to that kind of pace and agility that the fraudsters have. Because they have no governance structures, no org structures, no procurement process they have to go through. Even for people like the team at iTech, when we have to build something, our legal and compliance has a say in, hey, is this something that you can build? Fraudsters have no such controls. So they can adapt any capability that's out there in the wild and deploy it against you. Now, do we have equally smart people, if not smarter people on our side? Absolutely. But we are hamstrung by just the structure of how we respond to it. So that itself is a significant difference and it's happening at such a scale. It's so cheap for them to do it and they can do it at massive industrial scale, which makes it incredibly difficult to protect against.
(10:27):
Staying in the system like we were talking about, that's from their perspective, kind of a capital investment because it's worth their time to be patient. So to what Patty mentioned, they're basically biding their time. They look like the best customer. It doesn't cost them a lot from an economic perspective. So all of that together, the speed, the time investment, all of that has become the scale. All of that has become cheaper, which makes it much harder for loaded financial institutions and solution providers to tackle that issue.
Holly Sraeel (11:04):
Yeah. And I would argue that the banks still lack enough talent. The industrialized crime complex out there globally. They have really smart people that are just working on this 24 hours a day, seven days a week. And you're right that the regulation and various other constrictions that banks face, but talent is one thing that they need to play catch-up on. Wouldn't you agree that you need more people with more deep skillsets in AI?
Raul Oseguera (11:37):
I agree. The challenge though is always economic factor. In a small institution like ours, there's only so much that you can spend on the people. So a lot of times we will have to look at outsource options that we can't build ourselves.
Holly Sraeel (11:57):
Patty, how do you see the talent?
Patricia Voight (11:59):
Yeah, I think as you're seeing the talent in the industrial fraud complexes, they are very much focused and they only have to be right once to be able to reap the benefits. Whereas when you think about institutions, financial institutions specifically, they have to be able to cover a lot more ground and they have to be able to look at things holistically. They also have to be in better coordination across the broader ecosystem as well. And that takes having the right talent, having the right technology, having that collaborative effort across the organization, but out there into the broader financial ecosystem as well.
Holly Sraeel (12:34):
All right. Let's talk a little bit about moving the industry, seeing the movement from event to lifecycle in terms of synthetic fraud and how it's working today. It's a major shift. So if I could, Pay, many institutions still think of fraud as a transaction or onboarding event. Why is that mindset increasingly dangerous when dealing with synthetic identities?
Patricia Voight (13:01):
And I think I just kind of touched upon that, which is it's broader than just the onboarding process. I think during that many of the fraud actors, they're well aware of what controls that we already have in place. So they've gotten very good at being able to get through that onboarding process without being detected. And then they invest in this longer-term strategy. And where this starts to become a catch is when it goes acros business lines or product areas, they start to move around a bit more. And because typically in organizations you have different teams focused on different areas, whether it's your cyber team, your fraud team, your customer trust teams, your consumer monitoring teams, not sharing that information holistically, not being able to look broader across the organization and out into the broader financial ecosystem. This becomes a challenge because that is something that the fraud actors are much more sophisticated at doing and looking at and assessing and that's where they make their moves.
Holly Sraeel (13:54):
Okay. Sean Oro, whoever feels most comfortable, what signals are institutions missing that they shouldn't be missing?
Shyam Menon (14:04):
I don't think they're necessarily missing signals. They're missing the correlation between signals and the insights that tell you. So the idea always was like a bouncer at a nightclub. You check the person when they're coming in. And until the club closes, that person is fine inside. That's not the case anymore. The evaluation of trust is actually not an event. It's more an ongoing relationship. So you literally have to be checking in whenever there is a signal that is slightly different from what you expect. So that can be as simple as somebody has logged in from a device that they have never logged in from. Now that doesn't necessarily mean that's a fraudster, but that tells you it could be as simple as a person has changed the device, but there has to be some assessment of, okay, this within the context of everything that's happened in whatever context window you're looking at, what does that tell me?
(15:08):
And so an example would be if that person just logged in 30 minutes before from the original device and then 30 minutes later from another device, then maybe that tells you something more than over an extended period of time they just changed device. So I think it's not that they're... Because there are very good point of time solutions that exist that tell you what you need to know at that point of time. But that's not what synthetic identities do. They live between the gaps of the points of time. Correct.
(15:43):
And so it's the linkage between those points and the signals that come out of those points that are actually what the institutions, and especially the larger the institution, the harder it is to correlate those signals, which make them bigger targets than what would be a small or medium-sized institution. We
Holly Sraeel (16:00):
Talked about the patience of fraudsters. Could they wait beyond 12 months even to take action?
Raul Oseguera (16:10):
We have seen that. A lot of what we do is work with embedded banking and we have noticed that a lot in our third parties that we work with that a lot of accounts get opened up and in a bank you have a time limit that you put a hold on account if it's not being used. In embedded finance, there's a lot of accounts that are not used and all of a sudden are used 12 months, 18 months, two years later, and they're part of the fraud ecosystem.
Holly Sraeel (16:44):
So you're going to have to pay more attention to that because embedded finance is going to grow. Exactly.
Raul Oseguera (16:48):
And
Holly Sraeel (16:49):
So you're going to have that risk exposure. It's interesting. I wonder if the partners will have to at some point change the way they operate in order to help keep pace with you if you have a relationship.
Raul Oseguera (17:03):
They will. Part of the difficulty though is that a lot of the partners we deal with are commercial customers and the regulation is much more favorable to consumers than it is commercial. So a lot of time the commercial customers will pass the risk onto the businesses that they work with.
Holly Sraeel (17:24):
Right. Okay. If a synthetic identity survives onboarding and behaves normally for six, 12 or more months, how difficult does it become to detect later in the lifecycle? So if they've been -
Raul Oseguera (17:42):
For us, it's very difficult. We don't have the tools that Shreyas is talking about because if it reacts like a normal account, then it does build a trust and our employees are more inclined to trust the requests that they get.
Holly Sraeel (18:06):
Are you doing more education with the employees to try to train them? Constantly.
Raul Oseguera (18:10):
Yes.
Holly Sraeel (18:11):
Yeah. We provide -
Raul Oseguera (18:12):
Same
Holly Sraeel (18:12):
For you, Patty.
Patricia Voight (18:13):
Yeah, I think it's important to have more interaction, more training, more awareness, because again, what's going to matter is the context, the relationships, looking at the behaviors that you're seeing, and also this kind of partnership across the various diferent silos in an organization.
Holly Sraeel (18:31):
So Sean, question for you. Any post-onboarding behaviors that institutions should be monitoring today that they're not?
Shyam Menon (18:42):
I can't specifically speak to what institutions have in place because I just don't have this way to some of the controls. But generally to Raul's point, I think it's incredibly difficult post-onboarding to monitor exactly what somebody's up to. But there are certain tellsBecause we do notice that in some cases the profile is grown within the platform in almost a near perfect way, which is not realistic in terms of what a normal human being would be. Because generally, human behavior will exhibit some flaws, whether that is in terms of missing a particular payment. And when you see over time that somebody is building up their profile, accessing additional products in almost a perfect way where they build up the profile just enough to bypass the next trust check for a next product, that is generally what tells you. But the overall point being it is extremely hard.
(19:46):
Okay. And so even if you did an incredibly good job of monitoring and you had all the resources to do it, some of these highly sophisticated operations will probably be a challenge for you the way it stands today unless we come up with some new way of detecting that.
Holly Sraeel (20:04):
So here's a tough question that you guys struggle with on a daily basis. The friction and fair treatment trade-off. What happens when you assess a good customer and get it wrong? How do you do continuous trust without debanking legitimate customers or penalizing normal life changes?
Shyam Menon (20:23):
So the life piece is what I was mentioning earlier. Every signal is not a suspicious event. It's more of one another data point which put in its totality tells you something, hopefully. But as a product person, one of the things that we focus on specifically at MiTek is the ability to make sure that balance is right between fraud and friction. And in addition to that, it's the ability to explain our decisions. So the explainability piece, both from a regulatory perspective is becoming incredibly relevant. I am asked questions about why a Mitech model, for example, did what it did all the time, probably three times a week now. And I never used to get asked those kinds of questions five years ago. And part of the reason is because of this AI thing, people do want to know that, hey, is the model performing the way it should and is it rejecting people for lending applications and things like that?
(21:32):
So on our side, we pay a lot of attention to that trade-off and making sure that we are able to explain our decisions. We do get it wrong. All models do. They're probabilistic by nature. So you are going to have mistakes, but it falls within our model governance and what the expectations are right at the outset. So that's a challenge that we take very seriously. You have a number of EU regulations that have come out recently that require very significant explainability and auditability trails. So that's basically what we keep in forefront to address that fair lending, fair access discussion.
Raul Oseguera (22:14):
One of the problems with that is also it's helping the fraudsters become more sophisticated. While the regulations require us to provide as much clarity to the customer, a lot of times the customer could be a fraudster and they're learning how to get around all of your controls.
Holly Sraeel (22:34):
Right. Okay. So let's dive a little bit deeper into fragmentation and the structural weaknesses around that. Is fragmentation the greatest advantage for fraudsters right now or is it something more?
Shyam Menon (22:54):
I would say yes. I think both organizationally as an organizational structure within banking and technology-wise, data-wise, both sides of the ledger are fragmented and that's where the operation happens. So if you could combine the organizational structure into one singular view or ownership and then combine that with a combined holistic data view, it would become much harder for some of these rings to operate. Now, fragmentation doesn't just exist within organizations. It exists across organizations too, because some of these industrial scale, to really look at a ring, you need to look across institutions because each fragment of that identity is living in different institutions. But obviously there are legal issues with sharing that data. There are regulatory issues. There are competitive sensitivity even between banks to share information. So all of those are where they thrive. So yeah, fragmentation across the board.
Holly Sraeel (24:12):
So I've had many of these conversations in the past couple of months and the issue that keeps coming up with bankers is that they would like some sort of consortium to share data around this. So do you think that's something in the offering in the near term?
Raul Oseguera (24:32):
I'm not sure if it's in near term. There's a lot of barriers to that, a lot of privacy rules, regulations. I know even within our organization with the FinTech partners we have, we've gotten around it into being able to share some information across the platforms, especially about problem actors. But it's something that in other organizations I've worked with, we've tried to do and it's just been very difficult because of the compliance concerns, regulatory concerns around it.
Holly Sraeel (25:10):
Patty, would that go down to even cross-institution signal sharing?
Patricia Voight (25:15):
Yeah, I think the model that when you look at bankers are looking at is also within the cybersecurity industry. And when you look across the financial services, there's often been these groups such as FSISAC that have been built around this threat intelligence information sharing. And I think it's a very similar model that you'll see banker associations looking for, which is around that integration between fraud, cyber and identity trust. And I think that is kind of a thing as we go into the future, it's going to be something that it's what the fraud actors already are enabled to leverage themselves. And if we don't as a broader financial ecosystem find a way to work together, I think the model's already there and we just need to work through that because that is going to be a piece. The fraud actors looked for the seams. And so that's where they're looking at getting their advantage.
(26:06):
And we have to, as larger organizations, be again, focused on breaking down these silos in our own organizations and across the broader ecosystem through collaboration.
Shyam Menon (26:15):
Holly, I could tell you a personal experience of what you just described. In one of my previous roles, my team attempted to build a fraud consortium data set across large US banks. At the same time, in the same company, our counterparts in Canada attempted the same thing. We failed in the US, they succeeded in Canada. Part of the reason was the banks in Canada were just more collaborative in terms of the competitive sensitivity was not raised to the level that it is here. Here it was every conversation I had was one of those Spider-Man memes where they're pointing at each other like, "You first, no, you first, you first." And finally we just gave up because it just was not worth the time and fort. And by the way, this idea was proposed by the Atlanta Fed. And so the regulatory aspect of it is valid, but I don't think there's willingness or the comfort level there to really get into that kind of sharing.
(27:17):
And now especially with biometric data and a lot of more sensitive data, I think the barriers have become a little bit higher in terms of sharing of that data between institutions.
Holly Sraeel (27:27):
Well, so here's a sticky issue. As identities move across banks, fintechs, payment providers and digital ecosystems, who owns the responsibility ultimately for identifying synthetic behavior? We talked a little bit about it earlier with your relationships with the embedded finance providers.
Raul Oseguera (27:45):
Yeah. And we look at it as a shared responsibility because we own all a piece of the customer onboarding or lifecycle process. So we look at when we're partnering with our FinTech partners, we work as much as we can to share the information, share the fraud information so that we can each help each other.
Holly Sraeel (28:10):
All right, so shared responsibility. Patty, do you see it as shared or ultimately it doesn't rest with you?
Patricia Voight (28:16):
I see it ultimately as a shared responsibility.
Holly Sraeel (28:19):
Okay. All right. What role should consortium intelligence network level visibility and ecosystem collaboration play in the next generation of fraud defense? So assume you could get players to cooperate, regulation doesn't pose a challenge, you take a page from the EU. Would it be most effective to rise to that level of collaboration to fight this?
Patricia Voight (28:50):
I think absolutely. I would definitely agree with that. And I think it's definitely something that we should all be aspiring to across the industry.
Holly Sraeel (28:56):
And do you have private conversations with your peers across institutions about this kind of stuff? I mean, I would imagine you guys occasionally swap notes on what you're facing.
Shyam Menon (29:11):
Yes. And that's a consistent conversation at least from product teams about how can we get as much data as we can to provide the insights we want to provide to customers. One of the things that will help is just technology because there are things that are being worked on that will allow for training of data together and extracting shared signals without exposing raw data. Correct. Yeah. So confidential computing and things like that where we can do things in the future that we weren't able to do two years ago. So technology is an answer to that. But in addition to that, we do need the cooperation and... And willingness and some regulatory guidelines around the value of this kind of work and how that helps and regulatory mechanisms that allow for that kind of data exchange.
Holly Sraeel (30:14):
So we talked about talent, we talked about technology, we talked about collaboration. What about culturally within the institution? How much more talking are you doing with peers that sit in other parts of the institution in order to collectively work on this?
Raul Oseguera (30:35):
At our institution, we've actually created cross-functional groups to look at fraud. I see. And we've tried to pull in some of our FinTech partners. It's a little more difficult. They're focused on their business, but it's that shared responsibility we talked about earlier. We're trying to ensure that message gets across throughout the institution.
Holly Sraeel (31:01):
Pat, you spend a lot of time with business unit heads and stuff working together on this and sharing?
Patricia Voight (31:05):
Yeah, so I think you're seeing a much more partnerships across organizations coming from the appropriate business customer-facing teams as well as the cyber team as well as identity team and also the fraud team. And so really collaborating, sharing tools and information and getting to a point where we break down those silos and have more integration and cross-collaboration.
Holly Sraeel (31:28):
Here's kind of a tough question, but I'm going to ask it anyway because I think it's important. If you could eliminate one organizational or data silo tomorrow, which one would have the biggest impact on reducing synthetic identity fraud?
Shyam Menon (31:44):
My analysis of this, and it's not an empirical one, it's more of an observational anecdotal one, would be the linkage between identity data and transaction data. If you could break that silo down, it probably will be the biggest lift you can get. Interesting. Okay. Again, like I said, I don't have empirical evidence to this, but as somebody who looks at these things on a day-to-day basis, that's anecdotally and observationally what I think. So yeah, if I had to pick one, that's probably where it is because you are looking at transactional data all the time because transaction monitoring is generally one of the point of time controls that you have, but it tells you a lot more about the identity as it's happening. So it's kind of a behavioral clue in addition. So if you bridge that gap, that probably will allow for a more holistic view of continuous trust and continuous verification than what we have today at how it goes.
Holly Sraeel (32:46):
Agree, disagree?
Raul Oseguera (32:50):
No, I agree. Okay.
Holly Sraeel (32:52):
All right. All right, we're going to look a little bit toward the future by examining the present. Traditional controls and why they fail. Why are traditional KYC identity verification and document-based controls increasingly ineffective against sophisticated synthetic identities?
Raul Oseguera (33:15):
The way I look at it is that I think the traditional KYCs are still important. You still need it for regulatory requirements. I think that what we really need to do is add more of the technology to it. It has to be expanded. It's a good start. It can't be what we consider the end result. So it's the beginning of a process.
Holly Sraeel (33:37):
Okay. Pai?
Patricia Voight (33:40):
Yeah, I have to agree. I think they're still very important, but they're kind of at a point in time versus looking at it over time. And I think that kind of continuous assurance is what's needed. And I think that comes from the context, the relationships, and the behavioral analytics that can be happening over time.
Holly Sraeel (33:57):
Okay. I have a sort of a related question to how organizations set for the future. Many institutions continue to add more controls when fraud increases. Is the issue insufficient controls or is it really the wrong architecture?
Shyam Menon (34:12):
Wrong architecture. That's an easy answer for you. So it's kind of like point of time solutions, more controls. It's like you buying locks for an open floor plan house.
Holly Sraeel (34:25):
Okay. So just go on the record. We've got a bar metaphor. We've got an open floor plan metaphor. All right, so continue.
Shyam Menon (34:32):
No, because all it does is it increases friction. It doesn't give you the linked insights that we were talking about earlier. It's just one more set of signals. The only person experiencing that one set of signals really is the legitimate customer in the forms of friction. So if somebody asks me tomorrow, "Hey, what should I do to strengthen my fraud prevention posture?" My answer always 100% of the time would be architectural related. "Hey, what are your systems? How are they aligned? Are they linked and layered? Those kinds of things. And so yeah, from my perspective, at least from a product lens, it's an easy answer. I don't know if that's true operationally, but clearly from a product.
Raul Oseguera (35:21):
No, I completely agree with you. A lot of times there's a knee-jerk reaction. You tighten controls and you're right. What does it affect affects your legitimate customers? The fraud's already done. They've already moved on to something else, fraudster.
Holly Sraeel (35:36):
Okay. Couple of questions and then we're going to be done. What signals do fraud teams trust less today than they did three years ago because of the advances in the technology AI?
Shyam Menon (35:54):
I would say the underlying artifacts. So if somebody submitted a document, I trust it les today than I did three years ago because I got to really evaluate whether it's actually a real document, a selfie. So all those singular artifacts that were considered to be proof of identity or authenticity, you have to look at it with a bit more of a granular lens to make sure. And I think we started off the conversation by saying the quality of the fakes and things like that. And we see that every day. In our client base, we see customer base. We see a number of examples of highly, highly sophisticated fakes, whether those be documents or biometrics and voice cloning, which is something that you wouldn't have thought of four or five years ago, even a couple of years ago. I mean, the quality of some of these things have become so good.
(36:59):
So
Holly Sraeel (36:59):
It's ridiculously
Shyam Menon (37:00):
Good. I mean, even experienced manual reviewers who have been doing this for decades have a hard time looking at it and making a judgment about one, whether it's actually authentic or not. So that's what I would trust less from a fraud team perspective.
Holly Sraeel (37:18):
Okay. Let's talk a little bit about what a modern identity trust framework looks like in a world where any individual signal can be manipulated or manufactured. So what do you think it looks like?
Patricia Voight (37:32):
I think you have to be continuously reviewing your identity assurance to make sure that over time, instead of just looking at any one point in time, it's continuously evolving. Over a long extended period, you have to be looking at the behaviors of what's happening. You have to be able to look at the networks and the relationships and focus on what's changing and evolving there. And it's a bit more sophisticated in what you're needing to look at and the volume that we're having to look at too as well at the same scale and speed. And so I think as we go into the future, this is a bit of a challenge for all firms and institutions.
Holly Sraeel (38:10):
Do you think that the signals that will be most important might change? And if so, what do you anticipate would become more or less important from a signal point of view?
Patricia Voight (38:24):
I think the signals that are important are having them from multiple areas and across the broader ecosystem as a whole. So there's got to be correlation outside of individual business line product areas to be able to correlate all that data together to find some of these patterns. Because again, the fraud actors are looking at the themes in between and they're also playing a longer game and a longer strategy. So you're not talking about looking at it over a smaller period of time. It could be months, years that you're looking at this data and doing the analysis. And of course that's where I think AI is really going to come in because it can handle the volume and the scale and the speed that's going to be needed to counteract those fraud actors using the same AI for nefarious purposes.
Holly Sraeel (39:07):
Okay. Let's talk a little bit about governance and explainability. How does today's era and the needed controls hold up under model governance, adverse action and EU AI Act and GDPR stuff? What are the forward-looking expectations?
Shyam Menon (39:26):
I think Raul mentioned about explainability being kind of a double-edged sword. Now from my perspective, that has become an integral part of product design. Anything you do, you have to be able to explain the decision, the logic behind it, the flow. But what that allows fraudsters to do is to understand exactly how the backend systems potentially work. Now we are very careful from a product build perspective about what we actually expose even from an explainability perspective. We do what's necessary from a regulation perspective and nothing beyond it because we just don't want to show our cards there. But it is a double-edged sword. And so getting that balance right is basically where you're going to see the impact of these regulations. If institutions don't get that balance right, if product builders don't get that balance right, then you're basically opening the door to how your controls work and then that's an additional layer of information then that bad actors can use to target your institution.
Holly Sraeel (40:41):
Okay. Patty or Raul or both five years from now, what capabilities will distinguish institutions that successfully manage synthetic identity risk from those that struggle to combat it?
Patricia Voight (40:58):
I think those are able to look over continuously instead of point in time. So continuous identity assurance. I think those that have built out and collaborated across the broader ecosystem so that you're looking at more channels of information, more signals coming in and having that kind of intelligent sharing and collaboration across both the public and private communities. And I think finally, those that are also investing in the AI-driven technologies that are built around analytics and also risk confidence scoring and that are doing this in near real time.
Raul Oseguera (41:41):
I agree with everything Patty says. I also think that in five years, those that haven't gotten to that point will be in such bad shape that they will have to invest to get to that point because this is real and it's only going to keep getting worse.
Holly Sraeel (41:57):
And I would imagine that the smaller institutions are going to have to look to a partner in this. They just don't have the internal resources or the capital to make these investments.
Raul Oseguera (42:06):
Completely agree with you. Okay.
Patricia Voight (42:08):
And that's where that leaning into that broader ecosystem is going to become relevant for all across that community and spectrum to survive.
Raul Oseguera (42:15):
And I'm a firm believer that in order for this to work, it has to be embedded into the whole process. Technology is nice, but it's hard to overlay technology under a process. You have to embed review process. The whole fraud review into the process of everything you do from the account opening to the transaction monitoring to decisions to close account as to all be. It just has to be embedded in there.
Holly Sraeel (42:48):
Okay. Final question, Shav, I'm starting with you. If you were advising a bank CEO today and you could direct investment toward only one identity related capability over the next 24 months, what would it be and why do you believe it would matter more than any other fraud initiative competing for that budget?
Shyam Menon (43:09):
The capability to continuously verify identity at all points of time and any time. So that's the capability. And what that means from an investment perspective is consolidation of data and making sure that the insights are being drawn from a central source that brings in all the signals. It's not an additional set of signals. It is the ability to draw insights from the signals you already have on a continuous basis. So that would be my guidance in terms of the first thing. And it touches everything that we just said, that people operating within seams, the insights, the continuous intelligence sharing. So the control the CEO has internal intelligence sharing between lines of businesses, for example. So that's where the biggest lift would be in terms of just the posture in terms of fraud prevention. That would be my advice.
Holly Sraeel (44:06):
Fatty, what would you tell a bank CEO that you haven't already told your bank CEO?
Patricia Voight (44:11):
I would invest in a continuous enterprise-wide identity trust platform that's built around AI-driven analytics and risk scoring.
Holly Sraeel (44:20):
Okay. Raul?
Raul Oseguera (44:22):
I agree. The one thing for a smaller institution, it just has to be cost-effective. So we have to look at that continuous monitoring, ensure that it's cost-effective because a CEO of a smaller institution always has that bottom line and doesn't have as much resources.
Holly Sraeel (44:40):
Okay. We're at time, so I'd like to thank my guests, Patricia, Raul and Sham for a wonderful session. I'm Holly Srail. Please join us again for another American Banker Leaders. Thank you all.
Patricia Voight (44:54):
Thank you.



