The opinions expressed here are those of the authors. They do not necessarily reflect the views or positions of UK Finance or its members.

UK Finance’s annual fraud report showed fraud increased to £1.28 billion, an increase of 4%. Fraud prevented stood at 70p in every pound, suggesting the consistent scale of attack banking systems are subject to. Banking fraud losses have remained stubbornly high despite successive generations of investment in detection and prevention. Each cycle has brought sharper analytics, more sophisticated models and greater visibility into digital behaviour. Yet fraud persists, and the nature of the problem continues to evolve. The explanation is not purely technical. It is operational. 

The visibility paradox

Modern fraud operations succeed by finding the gaps between technical controls. Most institutions already collect vast amounts of information about customers, devices, sessions and transactions. The harder problem is turning that information into timely, consistent decisions. The relevant data often exists, but it is distributed across systems, teams and moments in time in ways that make it difficult to assemble under operational pressure. An analyst reviewing a suspicious transaction may have minutes to decide. The attacker had days to prepare.

The decision problem 

The traditional response to growing complexity has been to collect more data, more telemetry and more signals. While the logic is understandable, the outcome is less straightforward. The volume of information available to fraud teams now exceeds what can realistically be processed and assessed in depth. That creates a trade-off: teams can review more cases with less scrutiny, or fewer cases with greater scrutiny. Neither is especially attractive. The deeper constraint is attention: human judgement is not an unlimited resource. The quality of a decision made after dozens of alerts is rarely identical to the one made after hundreds. Sustained exposure to high alert volumes affects concentration, pattern recognition and risk assessment. The result is a predictable consequence of asking people to absorb more information than they can reasonably process. Missed cases carry direct financial burdens/costs to banks. Delayed interventions allow attackers to move laterally. The burden drives colleague attrition, which compounds the talent problem. 

The adversarial dimension 

What makes this qualitatively harder than other operational challenges is that the workload is shaped by an opponent that adapts. Fraud syndicates test controls, retire patterns that create friction, and continuously probe systems to arrive at new variants. AI tools are as available to attackers as to defenders. Synthetic identities, AI-generated social engineering, and deepfake-assisted account takeover are operational realities in European markets today. An attacker can iterate on methodology in hours. A fraud team, meanwhile, updates detection rules and operational workflows in days. That gap does not close by adding more of the same. 

Where human capacity is being spent 

The institutions navigating this most effectively share one characteristic: they are precise about where human judgement creates the most value. Fraud operations have two distinct demands. The first is assembling context: retrieving account history, correlating device signals, and building a coherent picture of activity across channels. Essential work, but often mechanical. The second is decision-making: determining whether risk is genuine, what intervention is appropriate, and what action should follow. In many fraud operations, experienced analysts unfortunately spend a significant portion of their time on the former. The most valuable asset in fraud operations is often consumed by preparation rather than decisions. 

Protecting the judgement that matters 

Fraud analysts remain the indispensable link in the process. The pressures they face today are the consequence of operating models built for a very different environment. The strongest fraud operations will not be defined by the quality of their tools or the size of their teams. They will be defined by how effectively they protect and deploy human judgement. Fraud has always rewarded the side that adapts faster. Increasingly, the question is where that adaptation occurs: in the investigation workflow or in the attacker's playbook.

Area of expertise: